Ask Gemini for a "Walmart MCP" and the first result is malware. try it.
https://ift.tt/EsworSh
Submitted July 22, 2026 at 03:48AM by XSSpresso
via reddit https://ift.tt/ORZ4YBQ
https://ift.tt/EsworSh
Submitted July 22, 2026 at 03:48AM by XSSpresso
via reddit https://ift.tt/ORZ4YBQ
Island.io
AgentBaiting: How Fake AI Skills Deliver Malware at Scale
Island researchers uncover 7,600+ malicious GitHub repos, over 800 posing as AI Skills and MCP servers, that trick AI agents into recommending malware.
Found a decade of financial sector procurement data sitting on a former employee's home NAS
https://ift.tt/JLga5Yn
Submitted July 22, 2026 at 03:33PM by CybelAngel_official
via reddit https://ift.tt/LQjfc60
https://ift.tt/JLga5Yn
Submitted July 22, 2026 at 03:33PM by CybelAngel_official
via reddit https://ift.tt/LQjfc60
CybelAngel
How a personal NAS device exposed 10 years of bank data
CybelAngel analysts found a decade of confidential financial sector data exposed on a personal NAS device, a huge third-party risk.
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
https://ift.tt/54vpIl9
Submitted July 22, 2026 at 08:16PM by unknownhad
via reddit https://ift.tt/H6gPY5I
https://ift.tt/54vpIl9
Submitted July 22, 2026 at 08:16PM by unknownhad
via reddit https://ift.tt/H6gPY5I
Himanshu Anand :: Security & Other Notes
Reporter 11: 10 people found the WPForms PayPal bug before me (CVE-2026-4986)
TLDR WPForms Lite is a WordPress form plugin with 5 million plus active installations. Public advisory data identifies versions 1.10.0.1 through 1.10.0.4 as affected by CVE-2026-4986: the PayPal Commerce webhook processed incoming events without first verifying…
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
Submitted July 23, 2026 at 12:38AM by Internal-Key64
via reddit https://ift.tt/nAM8uvC
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
Submitted July 23, 2026 at 12:38AM by Internal-Key64
via reddit https://ift.tt/nAM8uvC
Rotce’s Blog
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at…
I ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn't make money, so here's the code, the model and 13k real bypass attempts
https://ift.tt/ANlUSMY
Submitted July 22, 2026 at 11:41PM by BordairAPI
via reddit https://ift.tt/zC0JN62
https://ift.tt/ANlUSMY
Submitted July 22, 2026 at 11:41PM by BordairAPI
via reddit https://ift.tt/zC0JN62
huggingface.co
Bordair/bordair-detector · Hugging Face
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
GitHub issues $100,000 bounty for critical RCE vulnerability
https://ift.tt/kj41l0y
Submitted July 23, 2026 at 03:51AM by ryanmerket
via reddit https://ift.tt/bXhal6z
https://ift.tt/kj41l0y
Submitted July 23, 2026 at 03:51AM by ryanmerket
via reddit https://ift.tt/bXhal6z
RuntimeWire
GitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_
Researcher @sagitz_ disclosed a remote code execution vulnerability in GitHub, earning a $100,000 bounty—the largest payout in the platform's bug bounty program.
PE OopsSec: Mind your PE, guard your OPSEC
https://ift.tt/Af1KzbT
Submitted July 23, 2026 at 05:42AM by Cold-Dinosaur
via reddit https://ift.tt/rEKh26S
https://ift.tt/Af1KzbT
Submitted July 23, 2026 at 05:42AM by Cold-Dinosaur
via reddit https://ift.tt/rEKh26S
Zerosalarium
PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE
https://ift.tt/KorT0vl
Submitted July 23, 2026 at 01:15PM by No_Zookeepergame7552
via reddit https://ift.tt/NkXMpfd
https://ift.tt/KorT0vl
Submitted July 23, 2026 at 01:15PM by No_Zookeepergame7552
via reddit https://ift.tt/NkXMpfd
Uphack
WP2Shell: Pre Authentication RCE in WordPress Core | Uphack
Reproduce the wp2shell unauth WP RCE that combines REST batch-route confusion (CVE-2026-63030) and WP_Query SQL injection (CVE-2026-60137).
Open Evaluation Framework for AI Pentesting Agents on Real-World Targets
https://ift.tt/4RN2d0G
Submitted July 23, 2026 at 06:54PM by ZealousidealHunter80
via reddit https://ift.tt/6LvwPEA
https://ift.tt/4RN2d0G
Submitted July 23, 2026 at 06:54PM by ZealousidealHunter80
via reddit https://ift.tt/6LvwPEA
arXiv.org
From Controlled to the Wild: Evaluation of Pentesting Agents for...
AI pentesting agents are increasingly credible as offensive security systems, but current benchmarks still provide limited guidance on which will perform best in real-world targets. Existing...
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
https://ift.tt/d4VunxK
Submitted July 23, 2026 at 06:45PM by scamdrill
via reddit https://ift.tt/LyzpPRc
https://ift.tt/d4VunxK
Submitted July 23, 2026 at 06:45PM by scamdrill
via reddit https://ift.tt/LyzpPRc
ScamDrill
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
It needs no password and breaks no MFA. How device code phishing hijacks Microsoft 365 with a single code, and the one Entra setting that blocks it.
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
https://ift.tt/JO2fXkz
Submitted July 24, 2026 at 12:03AM by Straight-Practice-99
via reddit https://ift.tt/Rew9ijl
https://ift.tt/JO2fXkz
Submitted July 24, 2026 at 12:03AM by Straight-Practice-99
via reddit https://ift.tt/Rew9ijl
hunt.io
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
https://ift.tt/OmUfSoh
Submitted July 24, 2026 at 03:41AM by fede_k
via reddit https://ift.tt/qjpXmEo
https://ift.tt/OmUfSoh
Submitted July 24, 2026 at 03:41AM by fede_k
via reddit https://ift.tt/qjpXmEo
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
https://ift.tt/7gpL4l2
Submitted July 24, 2026 at 11:23AM by natcoba
via reddit https://ift.tt/N1DK5HC
https://ift.tt/7gpL4l2
Submitted July 24, 2026 at 11:23AM by natcoba
via reddit https://ift.tt/N1DK5HC
Accomplish
SharedRoot; Escaping the Claude Cowork sandbox — Accomplish Blog
Untrusted content in a Claude Cowork session can escape the VM it's sandboxed in and read and write files anywhere on your Mac. The kernel bug that makes it possible isn't the interesting part. Four design decisions are, and they'd have stopped the next kernel…