FashionProof
@fashionproof.bsky.social
infosec - no one of consequence https://medium.com/@markmotig
Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets. https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets.
wired.com
"Skin in the game keeps human hubris in check" N.N.T - skin in the game
This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea. Use a separate password manager.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
unit42.paloaltonetworks.com
SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability https://isc.sans.edu/podcastdetail/10034
According to Ransomware.live, CRPxO ransomware group has added JOHNSON & JOHNSON (🇺🇸) to its victims.
The latest episode of The Phillip Wylie Show features Casey Smith aka Subtee! youtu.be/x5x0UzLq-Qg
Casey Smith (SubTee): Living Off the Land, Deception Tech, and the Evolution of Offensive Security
YouTube video by Phillip Wylie
youtu.be
A lot of it reads like The Smartest Guys In The Room. Booking profits for next 'industrial revolution' without checking if any of the pleb customers even want it, or will pay for it. It's fascinating to see. Companies need diversity of thought more than ever, but execs are investing in mirrors.
A Big Month for Ransomware.live: Four New Features in July 2026 www.julien.io/en/post/a-bi...
Ransomware.live 👀
Ransomware.live tracks ransomware groups and their activity. It was created by Julien Mousqueton, a security researcher. The website provides information on the groups' infrastructure, victims, and pa...
ransomware.live
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit https://isc.sans.edu/podcastdetail/10028
SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update https://isc.sans.edu/podcastdetail/10026
According to Ransomware.live, shinyhunters ransomware group has added Ernst & Young (🇺🇸) to its victims.
Presenting Sparkle A fake LLM that leaks secrets Like an SSH or RDP, or SMB Honeypot Sparkle allows attackers to interact with it, make API calls, but its all fake. It’s actually not even connected to an LLM. 😎😀 More refinement, but this is our v1 Enojoy github.com/AlloySecureG...
Super quick BADBOOL update: I added instructions for opting out of Unite4 Heritage and OpenDataUSA (which has political donations), and to remove the now-defunct Neighbor Report. github.com/yaelwrites/B...
GitHub - yaelwrites/Big-Ass-Data-Broker-Opt-Out-List
Contribute to yaelwrites/Big-Ass-Data-Broker-Opt-Out-List development by creating an account on GitHub.
github.com
In today's this.weekinsecurity.com: OpenAI admits to hacking Hugging Face, millions of cars with hidden alarms vulnerable to hacking, Iran's hacking water and energy systems, Russia's targeting nuclear scientists with an email zero-day, a healthcare hack sparks data theft fears, and much more.
this week in security — july 26 2026 edition
OpenAI models hacked Hugging Face, flawed alarm exposes millions of cars to hacks, healthcare software maker breached, Russia exploiting email zero-day, residential proxy crackdown, Iran hacking water...
this.weekinsecurity.com
I would like to propose some formal definitions. AI slop is software whose structure has degraded through repeated AI-assisted modifications until it exceeds the team's ability to confidently understand, verify, or safely maintain it. 1/2
In this episode of The Phillip Wylie Show, I sat down with Alex Hurtado to discuss detection engineering. 🎧 Listen: YouTube: youtu.be/N7lVqUNpv88 Spotify: spotifycreators-web.app.link/e/Bu0kxFKbZ4b Apple: podcasts.apple.com/us/podcast/p...
SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix https://isc.sans.edu/podcastdetail/10018
According to Ransomware.live, coinbasecartel ransomware group has added Caterpillar (🇺🇸) to its victims.
I just want to say it's getting harder and harder to include daily AI developments that cyber folks should know without writing original, extensive summaries. Today's Metacurity will kick off with a nearly 1,800-word summary of the most important AI developments, just from Friday morning until now.
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files.
securityaffairs.com