Microsoft Speech - Lateral Movement
https://ift.tt/4S0eivp
Submitted April 7, 2026 at 05:25PM by netbiosX
via reddit https://ift.tt/IWMKhN2
https://ift.tt/4S0eivp
Submitted April 7, 2026 at 05:25PM by netbiosX
via reddit https://ift.tt/IWMKhN2
Purple Team
Microsoft Speech
SpeechRuntime is a legitimate Windows component that supports Microsoft’s speech-related capabilities, including voice input and speech recognition features used across modern Windows experie…
JavaScript runtime instrumentation via Chrome DevTools Protocol
https://fcavallarin.github.io/wirebrowser/CDP-as-a-Runtime-Instrumentation-Engine
Submitted April 7, 2026 at 09:17PM by filippo_cavallarin
via reddit https://ift.tt/6bvBSFE
https://fcavallarin.github.io/wirebrowser/CDP-as-a-Runtime-Instrumentation-Engine
Submitted April 7, 2026 at 09:17PM by filippo_cavallarin
via reddit https://ift.tt/6bvBSFE
wirebrowser
CDP as a Runtime Instrumentation Engine
Wirebrowser is a CDP-based runtime instrumentation platform for the browser. Think Frida, but for JavaScript running in Chrome — without monkeypatching.
Anthropic Opus 4.6 is less good at finding vulns than you might think
https://ift.tt/eFqT2xa
Submitted April 7, 2026 at 11:18PM by Prior-Penalty
via reddit https://ift.tt/vXmkYKW
https://ift.tt/eFqT2xa
Submitted April 7, 2026 at 11:18PM by Prior-Penalty
via reddit https://ift.tt/vXmkYKW
Zeropath
Benchmarking Opus 4.6 For Vuln Detection: Flashes Of Brilliance But Lots of Noise - ZeroPath Blog
We tested Opus 4.6 against 435 known vulnerable C functions from real CVEs. With good prompting and tools, it found up to 28.5% of vulnerabilities — impressive compared to human review, but with high false positive rates and inconsistency that underline the…
The Race to Ship AI Tools Left Security Behind. Part 1: Sandbox Escape
https://ift.tt/1gn5N42
Submitted April 8, 2026 at 12:24AM by Fun_Preference1113
via reddit https://ift.tt/EidTnwy
https://ift.tt/1gn5N42
Submitted April 8, 2026 at 12:24AM by Fun_Preference1113
via reddit https://ift.tt/EidTnwy
Cymulate
The Race to Ship AI Tools Left Security Behind. Part 1: Sandbox Escape
Ilan Kalendarov, Security Research Team Lead Ben Zamir, Security Researcher Elad Beber, Security Researcher Cymulate Research Labs uncovered a range of vulnerability classes across multiple different AI tools that allow attackers to bypass trust boundaries…
CVE-2026-34197: ActiveMQ RCE via Jolokia API
https://ift.tt/Yu8s23t
Submitted April 8, 2026 at 02:01AM by scopedsecurity
via reddit https://ift.tt/beLR9Ex
https://ift.tt/Yu8s23t
Submitted April 8, 2026 at 02:01AM by scopedsecurity
via reddit https://ift.tt/beLR9Ex
Horizon3.ai
CVE-2026-34197 ActiveMQ RCE via Jolokia API
CVE-2026-34197 is an ActiveMQ RCE flaw exploiting Jolokia to execute remote commands. Learn how it works, affected versions, and detection steps.
Assessing Claude Mythos Preview’s capabilities
https://ift.tt/oVx4GkX
Submitted April 8, 2026 at 01:58AM by dookie1481
via reddit https://ift.tt/7UoAIVZ
https://ift.tt/oVx4GkX
Submitted April 8, 2026 at 01:58AM by dookie1481
via reddit https://ift.tt/7UoAIVZ
From UART to Root: Vendor Shell Escape on a Uniview IP Camera
https://ift.tt/FMejsfX
Submitted April 8, 2026 at 06:19AM by Vymmy
via reddit https://ift.tt/jd2t9GF
https://ift.tt/FMejsfX
Submitted April 8, 2026 at 06:19AM by Vymmy
via reddit https://ift.tt/jd2t9GF
Strengthen Linux Security: CIS Hardening Guide (2026)
https://ift.tt/NqDXy8E
Submitted April 8, 2026 at 06:29AM by galaxymusicpromo
via reddit https://ift.tt/R7rHNb8
https://ift.tt/NqDXy8E
Submitted April 8, 2026 at 06:29AM by galaxymusicpromo
via reddit https://ift.tt/R7rHNb8
NEXOBITS
Strengthen Linux Security: CIS Hardening Guide (2026)
Strengthen your server defenses with our comprehensive cis hardening linux guide. Follow these professional steps to secure your systems against all threats.
We found a path traversal in an MCP server with 7,700 stars that lets AI agents read your SSH keys. Fix merged.
https://ift.tt/TZdGNHt
Submitted April 8, 2026 at 08:56AM by No-Investment-1140
via reddit https://ift.tt/i8lCN6j
https://ift.tt/TZdGNHt
Submitted April 8, 2026 at 08:56AM by No-Investment-1140
via reddit https://ift.tt/i8lCN6j
SpiderRating
AgentEscape: How MCP Servers Let AI Agents Read Your Private Keys
We found a vulnerability in a 49,000-star project that lets an attacker trick your AI agent into reading SSH keys, .env files, and database passwords. The fix is merged — but the pattern exists in hundreds of other MCP servers.
Spooler Alert: Remote Unauth'd RCE-to-root Chain in CUPS
https://ift.tt/LMtd5kv
Submitted April 8, 2026 at 12:31PM by buherator
via reddit https://ift.tt/qE9n1YU
https://ift.tt/LMtd5kv
Submitted April 8, 2026 at 12:31PM by buherator
via reddit https://ift.tt/qE9n1YU
Hey, it's Asim
Spooler Alert: Remote Unauth'd RCE-to-root Chain in CUPS
CVE-2026-34980 + CVE-2026-34990: two CUPS vulnerabilities, discovered by an autonomous LLM pipeline, chainable from unaut'd remote print job to root file (over)write.
Reading /etc/passwd via translation file upload in Tolgee's cloud platform (CVE-2026-32251, CVSS 9.3)
https://ift.tt/hVnqIR3
Submitted April 8, 2026 at 04:33PM by TradeGold6317
via reddit https://ift.tt/apg3UmJ
https://ift.tt/hVnqIR3
Submitted April 8, 2026 at 04:33PM by TradeGold6317
via reddit https://ift.tt/apg3UmJ
Simon Koeck
Reading /etc/passwd via Translation Upload in Tolgee | Simon Koeck
Tolgee's XML translation importers ship with zero security config. Upload a crafted file, read anything from the server. Confirmed on their cloud platform.
Brandefense Q4 2025 Ransomware Trends Report — 2,373 incidents, 125 groups, CVE exploitation breakdown
https://ift.tt/0Fq93zD
Submitted April 8, 2026 at 04:06PM by brandefense
via reddit https://ift.tt/xDFA7Rg
https://ift.tt/0Fq93zD
Submitted April 8, 2026 at 04:06PM by brandefense
via reddit https://ift.tt/xDFA7Rg
Brandefense
Ransomware Trends Report | Q4 2025 - Brandefense
Explore Brandefense’s Ransomware Trends Report Q4 2025 with sector-based insights, top ransomware groups, exploited CVEs, and global attack patterns.
Training for Device Code Phishing
https://ift.tt/bXr5URO
Submitted April 8, 2026 at 03:54PM by redwheel82
via reddit https://ift.tt/E6yFajB
https://ift.tt/bXr5URO
Submitted April 8, 2026 at 03:54PM by redwheel82
via reddit https://ift.tt/E6yFajB
PhishU
Microsoft Entra Device Code Phishing Simulation in the PhishU Framework
How the PhishU Framework simulates Microsoft Entra device code phishing with silent token capture, live notifications, and Token Explorer follow-on actions.
Broken by Default: I formally proved that LLM-generated C/C++ code is broken by default — 55.8% vulnerable, 97.8% invisible to existing tools
https://ift.tt/E1U4tH0
Submitted April 8, 2026 at 06:56PM by Hot_Dream_4005
via reddit https://ift.tt/RYwpyQa
https://ift.tt/E1U4tH0
Submitted April 8, 2026 at 06:56PM by Hot_Dream_4005
via reddit https://ift.tt/RYwpyQa
Why i think Mythos is gonna be game changing after using Opus for a CTF
https://ift.tt/YvwxPaX
Submitted April 8, 2026 at 06:40PM by BrilliantWaltz6397
via reddit https://ift.tt/Qs3CA2h
https://ift.tt/YvwxPaX
Submitted April 8, 2026 at 06:40PM by BrilliantWaltz6397
via reddit https://ift.tt/Qs3CA2h
www.techupkeep.dev
Project Glasswing: Anthropic Built an AI That Finds Zero-Days, Then Refused to Release It
Anthropic's Project Glasswing uses Claude Mythos Preview to find thousands of zero-day exploits, and I have firsthand proof their models are better than people think.
Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information 07 April 2026
https://ift.tt/Mkzi7T9
Submitted April 8, 2026 at 07:58PM by Chromber
via reddit https://ift.tt/u7yaDxY
https://ift.tt/Mkzi7T9
Submitted April 8, 2026 at 07:58PM by Chromber
via reddit https://ift.tt/u7yaDxY
Common Entra ID Security Assessment Findings – Part 3: Weak Privileged Identity Management Configuration
https://ift.tt/3ZVL9qO
Submitted April 8, 2026 at 09:11PM by GonzoZH
via reddit https://ift.tt/NVTIjfK
https://ift.tt/3ZVL9qO
Submitted April 8, 2026 at 09:11PM by GonzoZH
via reddit https://ift.tt/NVTIjfK
A new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software.
https://ift.tt/H6flWFr
Submitted April 8, 2026 at 09:04PM by This_Lingonberry3274
via reddit https://ift.tt/7EmLlPf
https://ift.tt/H6flWFr
Submitted April 8, 2026 at 09:04PM by This_Lingonberry3274
via reddit https://ift.tt/7EmLlPf
Anthropic
Project Glasswing: Securing critical software for the AI era
A new initiative to secure the world’s most critical software and give defenders a durable advantage in the coming AI-driven era of cybersecurity.
Offensive Fraud Prevention
https://ift.tt/2rGl86w
Submitted April 8, 2026 at 11:03PM by pathetiq
via reddit https://ift.tt/WcEGKtg
https://ift.tt/2rGl86w
Submitted April 8, 2026 at 11:03PM by pathetiq
via reddit https://ift.tt/WcEGKtg
Security Autopsy
Offensive Fraud Prevention
To follow the previous article "Fraud & Application Security: Ignoring each other is costing your business!",
Business logic flaws, not SQL injection, are where the real money disappears!
Traditional penetration testing, SAST and scanners catch technical…
Business logic flaws, not SQL injection, are where the real money disappears!
Traditional penetration testing, SAST and scanners catch technical…
dnsight - open source, config driven CLI DNS auditor
https://ift.tt/ZmwSj4L
Submitted April 9, 2026 at 01:20AM by MikeyS91
via reddit https://ift.tt/usIfCrE
https://ift.tt/ZmwSj4L
Submitted April 9, 2026 at 01:20AM by MikeyS91
via reddit https://ift.tt/usIfCrE
The Gap Between “Thousands of Vulnerabilities” and Reality | by Manikandan Swaminathan | Apr, 2026
https://ift.tt/fVcFgR8
Submitted April 8, 2026 at 11:08PM by Comfortable-Rock8782
via reddit https://ift.tt/kBYvVzU
https://ift.tt/fVcFgR8
Submitted April 8, 2026 at 11:08PM by Comfortable-Rock8782
via reddit https://ift.tt/kBYvVzU
Medium
The Gap Between “Thousands of Vulnerabilities” and Reality
A security practitioner’s breakdown of Anthropic’s Mythos claims — what’s real, what’s overstated, and what actually matters