> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
XtraderFX used fake celeb endorsements to lure novice investors
Glitch meant 5000 developers continued to receive user information
Amazon Bug Bounty! Great news: Amazon is now offering bounties via a security vulnerabiltiy research program
Bad news: AWS is out of scope!
When I read this I remembered that a few years ago I found persistent Cross-Site-Scripting on the AWS Console.
This post is a write up on how I found the XSS ba...
Security firm seeks to expand presence and capabilities in the country
RagingWire promoted itself as compliant with the Privacy Shield framework even when it wasn't, the FTC said. Now it has promised not to do that again
I’m excited that Feedspot ranked this blog (Embrace the Red) the number #10 pentest blog out there.
Subscribe and check-in regularly for new content related to offensive security engineering, penetration testing and red teaming.
You can also follow me on Twitter @wunderwuzzi23.
Cheers.
California is enforcing its consumer privacy protection law after a six-month grace period
Online criminals are hijacking celebrity names and media brands in a complex multi-stage fraud—but where are they getting their victim data?
A few months ago we discussed the importance of performing active credential hunting for your organization.
This is to ensure clear text credentials in widely accessible locations and source code are identified before an adversary gets a hold of them.
In this post we will explore using built-in oper...
Remote workers are becoming more aware of good cybersecurity practices
The awards recognize outstanding early-stage tech companies worldwide
Les marqueurs techniques suivants sont associés au groupe cybercriminel TA505 (voir la publication CERTFR-2020-CTI-006). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques ou de détection. Mise à jour du 10 février 2021 : un nouveau rapport détaillant...
Malware uses postal app lure to steal user details and send SMS messages
Awards recognize and reward companies and individuals across the security sector
The Shadowbunny TTP in the PenTest Magazine The latest edition of the PenTest Magazine features an article of mine about using virtual machines (VMs) during lateral movement to establish persistence and evade detections.
A few years back when I came up with the idea of using VMs for lateral movement...
Designation means telcos can’t use USF to buy Chinese tech
Venafi claims that many underestimate how many are running in their organization
As a company, we believe Black lives matter. In the face of continued police brutality, racial disparities in law enforcement, and limited accountability, we demand an end to systemic racism, endorse restrictions on police use of force, and seek greater accountability for police actions. We believe...
Lords warn of a “pandemic of misinformation”
Third-party drivers are rendering ATMs and point of sale systems vulnerable to attack, according to new research