Detecting Agentic AI Threats in Claude: Sigma Rules and Correlation Detections for the Execution Layer
https://ift.tt/3Jdx7MO
Submitted July 1, 2026 at 11:02PM by TheAlphaBravo
via reddit https://ift.tt/cYvFfuA
https://ift.tt/3Jdx7MO
Submitted July 1, 2026 at 11:02PM by TheAlphaBravo
via reddit https://ift.tt/cYvFfuA
PaperMtn
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
Detections for Claude on the execution layer: Sigma rules and a correlation runner that catch permission bypasses, rogue MCP servers, and more.
/r/netsec's Q3 2026 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted July 2, 2026 at 01:02PM by netsec_burn
via reddit https://ift.tt/OoTmaVK
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted July 2, 2026 at 01:02PM by netsec_burn
via reddit https://ift.tt/OoTmaVK
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
https://ift.tt/nXJsQE2
Submitted July 2, 2026 at 10:10PM by dx7r__
via reddit https://ift.tt/xoN3FfV
https://ift.tt/nXJsQE2
Submitted July 2, 2026 at 10:10PM by dx7r__
via reddit https://ift.tt/xoN3FfV
watchTowr Labs
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working.
Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to…
Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to…
FIFA was saved this time
https://ift.tt/nxPuGXb
Submitted July 2, 2026 at 09:44PM by scorp100n
via reddit https://ift.tt/gvpikw3
https://ift.tt/nxPuGXb
Submitted July 2, 2026 at 09:44PM by scorp100n
via reddit https://ift.tt/gvpikw3
Bobdahacker
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling…
Windows Service - Playbook & Detection Strategies
https://ift.tt/QmFYOXR
Submitted July 6, 2026 at 01:47PM by netbiosX
via reddit https://ift.tt/Vap0vqm
https://ift.tt/QmFYOXR
Submitted July 6, 2026 at 01:47PM by netbiosX
via reddit https://ift.tt/Vap0vqm
Purple Team
Windows Service
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …
Playing Around With ADIDNS RPC Internals
https://ift.tt/CZXD2F4
Submitted July 6, 2026 at 02:55PM by luke-paradoxis
via reddit https://ift.tt/H1swEn8
https://ift.tt/CZXD2F4
Submitted July 6, 2026 at 02:55PM by luke-paradoxis
via reddit https://ift.tt/H1swEn8
Medium
Playing Around With ADIDNS RPC Internals
TL;DR: I ported the functionality of dnscmd.exe into (slightly) more OPSEC safe Beacon Object Files (BOFs) so you can get domain admin…
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
https://ift.tt/lenSwgj
Submitted July 6, 2026 at 08:00PM by OpenSecurityTraining
via reddit https://ift.tt/O3EuZps
https://ift.tt/lenSwgj
Submitted July 6, 2026 at 08:00PM by OpenSecurityTraining
via reddit https://ift.tt/O3EuZps
p.ost2.fyi
Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!
Understanding emulation and fuzzing from scratch!
Call Stack Spoofing via Runtime .pdata Parsing to Evade RtlVirtualUnwind
https://ift.tt/eWyO4Gw
Submitted July 7, 2026 at 04:52PM by Important_Map6928
via reddit https://ift.tt/GsZCvWY
https://ift.tt/eWyO4Gw
Submitted July 7, 2026 at 04:52PM by Important_Map6928
via reddit https://ift.tt/GsZCvWY
sibouzitoun.tech
SindriKit 1.3.0: Defeating EDR Telemetry with Dynamic Stack Spoofing
How SindriKit implements dynamic Fat Frame discovery and JMP-Trampolines to defeat RtlVirtualUnwind and call-stack telemetry.
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
https://ift.tt/ZEKX8jg
Submitted July 7, 2026 at 08:46PM by Aureliand
via reddit https://ift.tt/qTwM4Sh
https://ift.tt/ZEKX8jg
Submitted July 7, 2026 at 08:46PM by Aureliand
via reddit https://ift.tt/qTwM4Sh
noma.security
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging…
A rule mapped to MITRE is not the same as real coverage
https://ift.tt/FloneTN
Submitted July 7, 2026 at 08:39PM by Ok_Attitude9264
via reddit https://ift.tt/uG2mbHE
https://ift.tt/FloneTN
Submitted July 7, 2026 at 08:39PM by Ok_Attitude9264
via reddit https://ift.tt/uG2mbHE
Socauthority
MITRE ATT&CK Detection Coverage: How to Map Your Rules and Find Real Gaps | SOCAuthority
How to map your existing detection rules to MITRE ATT&CK, find the gaps that actually matter, and prioritize what to build next. A practical guide from 10 years of SOC operations.
Bad Epoll: The bug missed by Mythos
https://ift.tt/U1xr4ZW
Submitted July 8, 2026 at 06:41AM by sanxiyn
via reddit https://ift.tt/OZSdTA6
https://ift.tt/U1xr4ZW
Submitted July 8, 2026 at 06:41AM by sanxiyn
via reddit https://ift.tt/OZSdTA6
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
https://byteray-ai.github.io/drift-corpus
Submitted July 8, 2026 at 09:54PM by Emergency_Stable_923
via reddit https://ift.tt/oRVDqWN
https://byteray-ai.github.io/drift-corpus
Submitted July 8, 2026 at 09:54PM by Emergency_Stable_923
via reddit https://ift.tt/oRVDqWN
Reddit
From the netsec community on Reddit: Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
Posted by Emergency_Stable_923 - 5 votes and 3 comments
1 in 2 devices sold in Africa exfiltrate data to China
https://ift.tt/462UpD0
Submitted July 8, 2026 at 11:19PM by AdTemporary2475
via reddit https://ift.tt/QaGRTCh
https://ift.tt/462UpD0
Submitted July 8, 2026 at 11:19PM by AdTemporary2475
via reddit https://ift.tt/QaGRTCh
Nowsecure
What the Transsion Telemetry Research Means for Mobile Security - NowSecure
1-in-2 phones sold in Africa ship a hidden telemetry framework that encrypts whole-device activity to shalltry.com Transsion is the world's fourth-largest
Why the HTTP QUERY Method Is a Bad Idea, and Accept-Query Is Why
https://ift.tt/yUvS6ip
Submitted July 9, 2026 at 02:36PM by theMiddleBlue
via reddit https://ift.tt/l6qzy0j
https://ift.tt/yUvS6ip
Submitted July 9, 2026 at 02:36PM by theMiddleBlue
via reddit https://ift.tt/l6qzy0j
Sicuranext Blog
Why the HTTP QUERY Method Is a Bad Idea, and Accept-Query Is Why
In June 2026 the IETF published RFC 10008 and gave HTTP a new method: QUERY. New HTTP methods are rare. Most engineers have not seen one added in about twenty years, so this is worth understanding before it shows up in your stack.
At first, when I saw this…
At first, when I saw this…
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
https://ift.tt/lNBgUGn
Submitted July 9, 2026 at 07:58PM by CyberMasterV
via reddit https://ift.tt/abmovyU
https://ift.tt/lNBgUGn
Submitted July 9, 2026 at 07:58PM by CyberMasterV
via reddit https://ift.tt/abmovyU
Blogspot
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
Author(s): Vlad Pasca Executive Summary Threat actor distributes malicious cryptocurrency wallets (Anchor, Zec, Iota, Onto, Dark, and Stella...
Inside an AI coal mine security camera network powered by plaintext passwords
https://ift.tt/HeqkS4V
Submitted July 8, 2026 at 10:50PM by EatonZ
via reddit https://ift.tt/plmnPNF
https://ift.tt/HeqkS4V
Submitted July 8, 2026 at 10:50PM by EatonZ
via reddit https://ift.tt/plmnPNF
Eaton-Works
Inside an AI coal mine security camera network powered by plaintext passwords
Coal India’s intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.
Towards CSI: What's the best harness? (arXiv 2026)
https://ift.tt/0lDG82i
Submitted July 10, 2026 at 03:19PM by Obvious-Language4462
via reddit https://ift.tt/5Fxepsv
https://ift.tt/0lDG82i
Submitted July 10, 2026 at 03:19PM by Obvious-Language4462
via reddit https://ift.tt/5Fxepsv
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
https://ift.tt/0vxnsbB
Submitted July 10, 2026 at 05:20PM by Obvious-Language4462
via reddit https://ift.tt/mhDpvrT
https://ift.tt/0vxnsbB
Submitted July 10, 2026 at 05:20PM by Obvious-Language4462
via reddit https://ift.tt/mhDpvrT
Closing the Timing Gap: Defensive Temporal Observability
https://ift.tt/EblsGwR
Submitted July 11, 2026 at 02:16AM by Standard-964
via reddit https://ift.tt/L8Wmvsr
https://ift.tt/EblsGwR
Submitted July 11, 2026 at 02:16AM by Standard-964
via reddit https://ift.tt/L8Wmvsr
arXiv.org
A Systematic Survey of Security Threats and Defenses in LLM-Based...
Agentic AI systems introduce a security surface that is qualitatively different from that of stateless LLMs. They persist memory, invoke external tools, coordinate with peer agents, and operate...
Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
https://ift.tt/EuPZ0zA
Submitted July 11, 2026 at 03:46AM by SpectreTv
via reddit https://ift.tt/Gmga2KO
https://ift.tt/EuPZ0zA
Submitted July 11, 2026 at 03:46AM by SpectreTv
via reddit https://ift.tt/Gmga2KO
Decodalabs
Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
Static analysis of a .NET RAT that ships browser credential theft, Discord token harvesting, cryptocurrency wallet draining, and a Jigsaw-inspired ransomware module in a single 2.5 MB executable.
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
https://ift.tt/TOC4fiB
Submitted July 11, 2026 at 09:43PM by moonlightelite
via reddit https://ift.tt/ZTJiyoU
https://ift.tt/TOC4fiB
Submitted July 11, 2026 at 09:43PM by moonlightelite
via reddit https://ift.tt/ZTJiyoU
Substack
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 2)
(Part 1 here)