Major AI Clients Shipping With Broken OAuth Implementations
https://ift.tt/1GgY5Ud
Submitted May 1, 2026 at 09:18PM by mhat
via reddit https://ift.tt/YPWKi04
https://ift.tt/1GgY5Ud
Submitted May 1, 2026 at 09:18PM by mhat
via reddit https://ift.tt/YPWKi04
SecureCoders
MCP CLI Clients Are Shipping Without Refresh-Token Support
The MCP OAuth specification mandates OAuth 2.1 with PKCE, but as of April 2026 not a single MCP client fully implements the refresh-token flow. Server teams are forced to issue dangerously long-lived access tokens as a workaround.
Every incident public companies have disclosed to the SEC, in one searchable database
https://ift.tt/iNO51nS
Submitted May 2, 2026 at 04:12AM by LordKittyPanther
via reddit https://ift.tt/JMNOmxX
https://ift.tt/iNO51nS
Submitted May 2, 2026 at 04:12AM by LordKittyPanther
via reddit https://ift.tt/JMNOmxX
Duke Security
SEC Cybersecurity Incidents Database | Duke Security
SEC-disclosed cybersecurity incidents, AI-tagged with Duke's breach taxonomy.
For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
https://ift.tt/Wf5D2l1
Submitted May 2, 2026 at 05:00AM by EliteRaids
via reddit https://ift.tt/zf8gWq9
https://ift.tt/Wf5D2l1
Submitted May 2, 2026 at 05:00AM by EliteRaids
via reddit https://ift.tt/zf8gWq9
Hacktron AI
Why Mythos doesn't matter (for us)
Benchmarking Hacktron's scanning pipeline shows that for most applications, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
How to exfiltrate data using only numeric outputs
https://ift.tt/BFZkPou
Submitted May 2, 2026 at 08:09PM by DrAdalbbert
via reddit https://ift.tt/7eq24aW
https://ift.tt/BFZkPou
Submitted May 2, 2026 at 08:09PM by DrAdalbbert
via reddit https://ift.tt/7eq24aW
Spirit Airlines Liquidation: An Active Azure Endpoint, An Exposed Booking Flow, and $11.48 Domains
https://bte.ink/spirit
Submitted May 3, 2026 at 05:27AM by BTheEPIC
via reddit https://ift.tt/4vlBCn7
https://bte.ink/spirit
Submitted May 3, 2026 at 05:27AM by BTheEPIC
via reddit https://ift.tt/4vlBCn7
Substack
Spirit Airlines Liquidation: An Active Azure Endpoint, An Exposed Booking Flow, and $11.48 Domains
A look at Spirit Airlines' abandoned but active web infrastructure after their sudden liquidation, and 3 defensive registrations that received immediate traffic.
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate)
https://ift.tt/BzbXGcv
Submitted May 3, 2026 at 06:03PM by pwnguide
via reddit https://ift.tt/Ve3vuMK
https://ift.tt/BzbXGcv
Submitted May 3, 2026 at 06:03PM by pwnguide
via reddit https://ift.tt/Ve3vuMK
pwn.guide
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone
Train a small CNN to recover 85% of keystrokes from audio captured by a laptop's built-in microphone.
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
https://ift.tt/YKHbzh8
Submitted May 4, 2026 at 09:54AM by Agitated-Alfalfa9225
via reddit https://ift.tt/Dsjd1gv
https://ift.tt/YKHbzh8
Submitted May 4, 2026 at 09:54AM by Agitated-Alfalfa9225
via reddit https://ift.tt/Dsjd1gv
guard.io
"AccountDumpling" – The Google-Sent Phishing Wave Hijacking 30k Facebook Accounts
Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
Lateral Movement - Cross-Session Activation
https://ift.tt/oeJFbgc
Submitted May 4, 2026 at 07:46PM by netbiosX
via reddit https://ift.tt/eE7dirY
https://ift.tt/oeJFbgc
Submitted May 4, 2026 at 07:46PM by netbiosX
via reddit https://ift.tt/eE7dirY
Purple Team
Cross-Session Activation
Traditional lateral movement techniques are no longer applicable in the modern era due to developments in the detection capability by most of the EDR vendors. Techniques that abuse legitimate Windo…
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
https://ift.tt/jp7AFwx
Submitted May 5, 2026 at 10:34AM by Most_Ad_394
via reddit https://ift.tt/eifaOZB
https://ift.tt/jp7AFwx
Submitted May 5, 2026 at 10:34AM by Most_Ad_394
via reddit https://ift.tt/eifaOZB
securityscanner.dev
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother.
A fake Stripe event in a curl one-liner. No Stripe-Signature header. 1,542 of the apps we scanned this week returned a 200. That means anyone can forge payment events on those endpoints. Here is what we found and the six-line fix.
Proton Pass: Second-Password Bypass Through Emergency Access
https://ift.tt/ya8xtqn
Submitted May 5, 2026 at 01:47PM by rikvduijn
via reddit https://ift.tt/Q5CrGw7
https://ift.tt/ya8xtqn
Submitted May 5, 2026 at 01:47PM by rikvduijn
via reddit https://ift.tt/Q5CrGw7
Zolder
Proton Pass: Second-Password Bypass Through Emergency Access - Zolder
Proton Pass' second password is supposed to keep your vault safe even if your main account falls. Emergency Access with a wait time of None walks right past it.
The Danger of Multi-SSO AWS Cognito User Pools
https://ift.tt/qSfhLlw
Submitted May 5, 2026 at 04:09PM by nibblesec
via reddit https://ift.tt/NP086qr
https://ift.tt/qSfhLlw
Submitted May 5, 2026 at 04:09PM by nibblesec
via reddit https://ift.tt/NP086qr
Doyensec
The Danger of Multi-SSO AWS Cognito User Pools
After a small detour, the CloudSecTidbits series is back with new episodes. We had the opportunity to present them at the first DEFCON in Singapore few days ago during our DemoLabs sessions. Meeting Singapore’s community was indeed amazing - thanks again…
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
https://ift.tt/TlWD5H2
Submitted May 5, 2026 at 04:35PM by Mempodipper
via reddit https://ift.tt/UoDWqnE
https://ift.tt/TlWD5H2
Submitted May 5, 2026 at 04:35PM by Mempodipper
via reddit https://ift.tt/UoDWqnE
Searchlight Cyber
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud › Searchlight Cyber
Have you noticed that almost every marketing email you receive looks somewhat similar, or has functionality that seems centralised? This is because most corporations have moved to some form of marketing cloud to facilitate sending mass email campaigns. This…
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
https://ift.tt/PxUtVlH
Submitted May 5, 2026 at 06:06PM by 0xdea
via reddit https://ift.tt/qFXub64
https://ift.tt/PxUtVlH
Submitted May 5, 2026 at 06:06PM by 0xdea
via reddit https://ift.tt/qFXub64
HN Security
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 - Articles
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
Major AI Clients Shipping With Broken OAuth Implementations
https://ift.tt/ZNSJwzq
Submitted May 5, 2026 at 09:21PM by mhat
via reddit https://ift.tt/vrhTwWB
https://ift.tt/ZNSJwzq
Submitted May 5, 2026 at 09:21PM by mhat
via reddit https://ift.tt/vrhTwWB
Redcaller
MCP Client OAuth Refresh-Token Support Matrix | RedCaller Docs
A compatibility matrix tracking OAuth refresh-token support across 14 MCP clients. Covers status, root causes, SDK layers, and server-side workarounds.
DigiCert: Misissued code signing certificates
https://ift.tt/WbgNGk7
Submitted May 5, 2026 at 10:45PM by overandoutage
via reddit https://ift.tt/kxaQuvj
https://ift.tt/WbgNGk7
Submitted May 5, 2026 at 10:45PM by overandoutage
via reddit https://ift.tt/kxaQuvj
bugzilla.mozilla.org
2033170 - DigiCert: Misissued code signing certificates
ASSIGNED (dcbugzillaresponse) in CA Program - CA Certificate Compliance. Last updated 2026-05-04.
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
https://ift.tt/tiNeSuT
Submitted May 5, 2026 at 03:09PM by rkhunter_
via reddit https://ift.tt/zPjgCpT
https://ift.tt/tiNeSuT
Submitted May 5, 2026 at 03:09PM by rkhunter_
via reddit https://ift.tt/zPjgCpT
Scan. Secure. Simplify. — Free Web Tools Platform
https://ift.tt/Xetd896
Submitted May 6, 2026 at 01:37AM by Awkward_Republic5784
via reddit https://ift.tt/CbAFIEH
https://ift.tt/Xetd896
Submitted May 6, 2026 at 01:37AM by Awkward_Republic5784
via reddit https://ift.tt/CbAFIEH
7AZZANI
7AZZANI - Free Security Scanner, Speed Test & Developer Tools
100% free online tools: Website Security Scanner, Speed Test, URL Shortener (ShrinkIt), Database Converter, QR Code Generator, Encryption & more.
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
https://ift.tt/bFLBQW8
Submitted May 6, 2026 at 01:16AM by we-we-we
via reddit https://ift.tt/rZdPUDh
https://ift.tt/bFLBQW8
Submitted May 6, 2026 at 01:16AM by we-we-we
via reddit https://ift.tt/rZdPUDh
Cyera
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama | Cyera Research
Cyera's research team discovered a critical memory-leak vulnerability in Ollama, the world's most popular platform for running large language models (LLMs) locally.
Salesforce pentesting novel techniques- how to be an apex predator
https://ift.tt/AmzCkZS
Submitted May 6, 2026 at 01:09AM by lowlandsmarch
via reddit https://ift.tt/87tGKTw
https://ift.tt/AmzCkZS
Submitted May 6, 2026 at 01:09AM by lowlandsmarch
via reddit https://ift.tt/87tGKTw
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
https://clearbluejar.github.io/posts/pyghidra-mcp-meets-ghidra-gui-drive-project-wide-re-with-local-ai/
Submitted May 6, 2026 at 07:04PM by onlinereadme
via reddit https://ift.tt/UomwzMZ
https://clearbluejar.github.io/posts/pyghidra-mcp-meets-ghidra-gui-drive-project-wide-re-with-local-ai/
Submitted May 6, 2026 at 07:04PM by onlinereadme
via reddit https://ift.tt/UomwzMZ
clearbluejar
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
pyghidra-mcp v0.2.0 ships a GUI-backed mode that lets a local LLM drive a live Ghidra CodeBrowser at full project scope. Renames, plate comments, and cross-binary pivots land in real time, with every edit tagged in Ghidra’s undo history while the session…
Vulnerability Garden
https://vulnerability.garden
Submitted May 6, 2026 at 06:36PM by mk3s
via reddit https://ift.tt/GSMLbAV
https://vulnerability.garden
Submitted May 6, 2026 at 06:36PM by mk3s
via reddit https://ift.tt/GSMLbAV
Vulnerability Garden 🪴
Vulnerability Garden
A growing list of named vulnerabilities, attack techniques and exploits.