Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Active Exploitation Alert: Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign
8+ hour, 43+ min ago (367+ words) Rescana Technical Analysis of Malware/TTPs The attack chain began with the automated mass-download of 1.8 million Android APKs from multiple app stores using a distributed pipeline orchestrated on ten AWS EC2 instances. The APKs were decompiled and scanned for hardcoded secrets…...
Zoom has become a must use, despite downsides -
10+ hour, 45+ min ago (571+ words) In the tool box that political reporters drag to work each day, the most important one is the chance to ask politicians questions, on behalf of you, especially at election time. So what’s the worst thing that has happened to…...
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
13+ hour, 10+ min ago (997+ words) This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven cyberattacks, browser and firewall zero-days, and…...
LTM Collaborates with IBM and Red Hat on AI-Driven Open-Source Software Remediation
14+ hour, 25+ min ago (556+ words) LTM, the Business Creativity partner to the world's largest enterprises, has announced a collaboration with IBM and Red Hat on Lightwell to help organisations strengthen open-source software supply chains through AI-driven vulnerability remediation. The collaboration is aimed at helping enterprises…...
GitLab Multiple Vulnerabilities
14+ hour, 32+ min ago (110+ words) TYPE: Servers - Other Servers Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, remote code execution, cross-site scripting, denial of service condition and security restriction bypass on the targeted…...
Bitcoin Lightning Development Kit v0.2.6 Fixes Fund Theft and Restart Bugs
1+ day, 7+ min ago (333+ words) Lightning Development Kit, a toolkit for building Bitcoin Lightning applications, released v0.2.6 on Sept. 9 with fixes for bugs that could divert small amounts of a node’s funds or prevent saved channel state from loading. LDK packages a Lightning implementation as a…...
FFXIV Beastmaster Bug Could Crash Servers
1+ day, 20+ min ago (346+ words) Petra Valkenburg has spent over a decade navigating the world of online gambling, from classic casino table games to the rapidly evolving space of crypto betting and blockchain-based wagering platforms. She approaches the subject with a sharp eye for odds,…...
One Overlooked Query Parameter: How a Single Line of Unsanitized Input Can Undo a Platform’s Entire…
14+ hour, 22+ min ago (483+ words) A field note from a penetration tester on discovering — and responsibly disclosing — a reflected XSS vulnerability on a live job-search platform. Every once in a while, you stumble onto a vulnerability while doing absolutely nothing sophisticated. No custom tooling, no…...
Top 43 AI Security Skills, MCP Servers & GitHub Repos Every Bug Hunter Needs
14+ hour, 22+ min ago (35+ words) Top 43 AI Skills, MCP Servers & GitHub Repos Every Bug Hunter Needs The AI-security corner of GitHub is moving too fast for its own good. Half the tools worth using didn’t exist eighteen months …...
Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys
18+ hour, 43+ min ago (433+ words) Bitcoin payment processor BTCPay Server has warned that bots are probing exposed Lightning nodes for a potential route to administrative control. The activity follows a separate critical BTCPay vulnerability that attackers exploited a month ago to obtain credentials protecting LND…...