There‘s a flood of AI discovered zero days coming. Nicholas Carlini on how Claude 4.6 is a better security researcher than he is: youtu.be/1sd26pWhfmg
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
YouTube video by unprompted
youtu.be
@j-00-ris.bsky.social
Application Security and stuff Mastodon: https://mastodon.social/@j0_0ris
There‘s a flood of AI discovered zero days coming. Nicholas Carlini on how Claude 4.6 is a better security researcher than he is: youtu.be/1sd26pWhfmg
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
YouTube video by unprompted
youtu.be
Ya know what makes your Monday? Claude Code now supports CIMD for MCP OAuth ✨ If your MCP server uses Client ID Metadata Documents, Claude Code discovers and handles it automatically. No funky registration dance or manual client setup! In case you're not yet using Claude Code: dsc.ai/clc
NPM worms are the new black. If you weren't aware yet, check out the recording of Christophe's talk when it comes out. If you can't wait, he already published a summary here: ctd.sh/s/npm-talk/i.... #INSO26
From AiTM phishing to autonomous worms — Insomni'hack 2026
ctd.sh
Phishing is becoming automated and autonomous. Christophe Tafani-Dereeper explores how modern campaigns evolve into worms at Insomni'hack 2026. Get to know more: https://ow.ly/ZpkO50Ykepo #InsomniHack #Cybersecurity #Infosec #INSO26 #CyberConference
"If an organization rewards speed, security often comes later." - Anastasija Collen #INSO26 Or: "It's the process, stupid!"
Welcome Anastasija Collen as our keynote speaker at #INSO26! She reveals how security debt is driven more by environment and behavior than by tools. Last tickets available: https://ow.ly/Y94V50YsPlu #Infosec #CyberConference
Great practical talk about the security of github actions! #INSO26
#Insomnihack speaker, pspaul reveals how abandoned workflows and weak controls become entry points for attackers. Get to know more: https://ow.ly/80Mp50Y9XEi #Cybersecurity #INSO26 #InfoSec
Oh look... ChatGPT sniffing Russian disinformation up its nose 700 times in 5 days Exactly what researchers have warned about for more than a year but have been told to take a hike buttondown.com/readwrite/ar...
I've been working on AI agentic platforms. ClawdINT lets AI agents make intelligence-style analytical assessments on events - structured contributions toward a collaborative picture. Agreement and divergence are scored properly! Send your openclaw at clawdint.com
You can now scan for #react2shell in Burp Suite! To enable, install the Extensibility Helper bapp, go to the bambda tab and search for react2shell. Shout-out to Assetnote for sharing a quality detection technique!
A perfect CVSS 10 🧑🏻🍳💋 CVE-2025-55182: Unauthenticated remote code execution vulnerability in React Server Components The vuln is in versions 19.0, 19.1.0, 19.1.1, and 19.2.0: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack Upgrade immediately!
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces
react.dev
The new MCP spec just dropped! 🎉 There's too many new things to get into everything, but there are two big changes I am most excited about 👀 📝 Client ID Metadata Documents (CIMD) - a simpler way to manage client registrations, clients describe themselves with a URL they control
The release candidate of the OWASP Top 10 2025 has been released owasp.org/Top10/2025/0... The definitive release should be out on November 20th
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
owasp.org
CycloneDX v1.7 is here! The latest release strengthens software & system transparency with: - Cryptography BOM (CBOM) - Data provenance & citations - Intellectual property visibility Learn more: cyclonedx.org/news/cyclone... #OWASP #SBOM #CBOM #CyberSecurity
CycloneDX SBOM Spec (OWASP) on X: "CycloneDX v1.7 is here! The latest release strengthens software & system transparency with: - Cryptography BOM (CBOM) - Data provenance & citations - Intellectual property visibility Learn more: https://t.co/VjHCDgC5tL #OWASP #CycloneDX #SBOM #CBOM #CyberSecurity" / X
CycloneDX v1.7 is here! The latest release strengthens software & system transparency with: - Cryptography BOM (CBOM) - Data provenance & citations - Intellectual property visibility Learn more: https://t.co/VjHCDgC5tL #OWASP #CycloneDX #SBOM #CBOM #CyberSecurity
x.com
All the #Devoxx Belgium Deep Dive talks from the 2nd day are now available on the companion app and our YouTube channel! #Enjoy 🍿 www.youtube.com/@DevoxxForev...
Welcome to Opt Out October, our collection of tips to slowly break free from online surveillance and throw sand in the gears of overreaching large tech companies. Today’s tip is about establishing good online security fundamentals. www.eff.org/deeplinks/2...
Opt Out October: Daily Tips to Protect Your Privacy and Security
Trying to take control of your online privacy can feel like a full-time job. But if you break it up into small tasks and take on one project at a time it makes the process of protecting your privacy
eff.org
Calling all AppSec pros, devs & security leaders! The OWASP Top 10 2025 is in the works & your input matters. Survey closes Oct 3 - don’t wait! forms.gle/jL3r5Xgg1H...
Updates here. github.com/debug-js/deb...
Version 4.4.2 published to npm is compromised · Issue #1005 · debug-js/debug
MESSAGE FROM @Qix- : PLEASE SEE #1005 (comment) FOR LATEST UPDATES. Version not present in this repo has been pushed out to npm. https://www.npmjs.com/package/debug/v/4.4.2?activeTab=code src/index...
github.com
Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.
@bad-at-computer.bsky.social Hey. Your npm account seems to have been compromised. 1 hour ago it started posting packages with backdoors to all your popular packages.
Interesting idea, to measure alignment, but a bit vague, with the Entropy Scorecard only available to paying customers(?), and its website returning a 403 outside of the US.
Most breaches don’t start in code. They start in misalignment. Entropy in leadership is the breach before the breach. The Entropy Scorecard is how you pen-test it. 👉 Read more: open.substack.com/pub/stevetou...
The MCP spec has been updated to include security best practices • Confused deputy • Token passthrough • Session hijacking modelcontextprotocol.io/specificatio...
Security Best Practices - Model Context Protocol
modelcontextprotocol.io
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
Destroying the web's usability so they can sell it back to you in slop form is exactly what they're doing.
In this example, the 2 forks of the zygote process share the same scudo secret and memory layout, which basically removes it's security enhancements. - Keynote by Mathias Payer at @1ns0mn1h4ck.bsky.social #android #scudo #zygote #inso25
📢 @christophetd.fr will present "Code to Cloud: Exploiting Modern Web Applications to Breach Cloud Environments" at Insomni’hack 2025! 📖 Check out the programme now: insomnihack.ch/talks/code-t... #INSO25 #Cybersecurity #EthicalHacking #Switzerland
📢 Christophe Tafani-Dereeper will present "Code to Cloud: Exploiting Modern Web Applications to Breach Cloud Environments" at Insomni’hack 2025! 📖 Check the full lineup and get your ticket: insomnihack.ch/talks/code-t... #INSO25 #Cybersecurity #EthicalHacking #Switzerland
Seems like there's a bit of confusion around the recent @Semgrep licence change and the @opengrep fork and I think there are two key points to highlight. 1/10
Fed up with Meta? Avoiding Instagram or Facebook isn’t enough to stop Meta from harvesting and profiting from your private information. Here’s how to limit Meta’s ability to monetize your personal data.
Mad at Meta? Don't Let Them Collect and Monetize Your Personal Data
If you’re fed up with Meta right now, you’re not alone. Meta tracks you across millions of websites and apps and its business model relies on your data. If you want to limit Meta’s ability to collect ...
eff.org
Lately, every BSides seems to have a talk on reframing security teams as a “Department of Yes” We don’t hear nearly as much about the value of a well-considered, strategically deployed “No” I've pulled together guidance on giving a better, more constructive No: ramimac.me/saying-no
How to Say “No” Well
Security’s pivot from ‘Department of No’ to ‘Department of Yes’ misses the real lesson - how to say ‘No’ the right way.
ramimac.me
Normalize telling your friends not to sign up for marketing emails just to get access to a service.
Normalize telling your friends to delete their personal information from the internet. www.malwarebytes.com/personal-dat...