Live Detection Feed
200 reports with real, generated multi-format detection content — refreshed automatically as new intelligence is ingested.
This live feed aggregates real detection content (Sigma, KQL, Splunk, osquery, Suricata) generated alongside individual intelligence reports as they are published. For the 8 hand-curated flagship Sigma rules covering major CISA KEV vulnerabilities, see the Detection Engineering hub.
2026-07-21 · MEDIUMNotCVE registry index — public records of vulnerabilities that shipped without a CVE
XSSer v.1.9 - "Bl4ck Swarm!" released
New Release: UFONet v2.0 - "R3DST4R!"...
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-20 · HIGHComposer: Arbitrary file write outside vendor via malicious transitive package name
vLLM denial of service via prompt embeds on M-RoPE models
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-19 · MEDIUMRecovering from a malicious APK installation on CMF Phone. HELP!
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-19 · HIGHCVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner
From 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign
Prompty: Arbitrary file read via file reference expansion
CVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out
CVE-2026-50147: Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
AI security project: PromptShield
If you've given an AI agent real credentials, how are you scoping what it can reach?
Published research article on IEEE about supply chain attacks and preventive security measures
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-17 · MEDIUMdeberíaa pagar por esto?
Is ast_grep_cli 0.44.1 on PyPI compromised? Windows Defender detected Trojan:Win64/Lazy!MTB during install
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-17 · MEDIUMAlerts on Server Loopback Traffic?
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-17 · MEDIUMAdvice on Detection Engineering
The Invisible Guardians of the Internet: An Introduction to Content Moderation & Trust & Safety
cybersec VS data science
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
Beta BIOS/UEFI
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
Pheditor has an authenticated terminal command whitelist bypass
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-16 · MEDIUMApple Sued Over Reported 'Hide My Email' Flaw
New Exploitable BOLA Found in Immich (self-hosted media platform)
With AI, Your Entire Internet History is Attributable to you Personally
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-16 · MEDIUMTeen hackers jailed after live-streaming the 16-hour TfL attack
Open-sourced my Claude Code team kit for secure multi-agent development and governance. Feedback welcome.
This might be a dumb question
How to Measure the Revenue Impact of Security Hardening Projects with a Simple Formula
SOC Analyst platforms and lacks
Preciso de ajuda
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
Top 10 Data Center and AI Infrastructure Security Risks
The British teenager who hacked into Vegas casinos from an east London flat
Critical NGINX vulnerability discovered: hackers can attempt to crash servers or even gain code execution
Proof of concept for CVE-2026-58635 LPE in Windows Braille Narrator service
Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach
Please Stop Making Me Opt Out of AI
Moroccan intelligence insider reveals widespread use of Pegasus hacking software | Morocco
Learning DevSecOps - Week 2
When Inclusive Language ends in phishing
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-16 · MEDIUMAI Agent for reconaissasion
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
i get stuck
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)
Greene County, Georgia, cybersecurity incident disrupts services
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
Getting mitre techniques a customer raw detection rule covers
MantisBT: Stored XSS in print_all_bug_page_word.php
File-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion
Sophos: The State of Ransomware 2026: Payments are dropping but encryption is climbing
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-15 · MEDIUMCoverage-First SOC: why domains and telemetry matter as much as threat intel
Runtime detection for ECS/EC2, what are people actually using?
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-15 · MEDIUMKQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'
Need help reverse engineering an Android APK used in a UPI fraud
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-15 · MEDIUMHN Security - My Semgrep C/C++ ruleset is ready for prime time again
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)
ISC2 Board of Directors Election is open.
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUMHochul halts new data center approvals via executive order
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-14 · HIGHAnyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · HIGHEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · HIGHFedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
AsyncAPI Supply Chain Compromise via GitHub Actions
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUM"Windows event log monitoring" the event IDs that actually matter vs the ones gets ignored
MITRE ATT&CK: [object Object], [object Object], [object Object]
View full report + detection content → 2026-07-14 · MEDIUMESET discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass Secure Boot by exploiting decade-old vulnerabilities
Source-reviewing 200+ self-hosted multi-tenant AI/SaaS apps for tenant isolation: 78 leaked across tenants (the "un-retrofitted read sibling")
Cybersecurity projects
Smashing the ServiceNow Sandbox – Pre Authentication RCE
When LLMs do more than they have to
RFC8555 ACME servers and DNS auth reusal
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist
@asyncapi/specs (2.7M weekly downloads) got compromised today via a malicious CI commit
The US government warns that Russia state hackers are coming after your router
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUMAddressing the state-layer gap in autonomous actor architectures: Byzantine fault tolerance without consensus
Nightmare Eclipse could be dropping his big promised exploit today
Writing an Evasive .NET Shellcode Loader
Enhancing the Threat Intelligence AI Model with Technical Knowledge About Windows Kernel Mode Malware
Zimbra Classic Web Client has a critical stored XSS, patched in ZCS 10.1.19 (reported by Google TAG, no CVE yet, not flagged as exploited in the wild)
Digital twins are becoming security infrastructure - not just monitoring tools
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUMEnhancing IIoT Security Using Digital Twins in Industry
ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)
AXON Body camera 3 of 4 hardware reverse cracking output video!
ExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers"
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMContext Bombs: Using AI Guardrails as a defensive mechanism
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
Im taking ec council cct exam
DIRAC: Pilot code downloaded over unverified HTTPS connection
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · HIGHDIRAC: SQL injection and lack of access control in PilotManager service
Every AI coding agent writes the secrets you paste straight to a plaintext history file — and nobody scans it
Stolen from
Official jscrambler npm package compromised: malicious versions 8.14, 8.16, 8.17, and 8.20
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMNow, defenders are embracing the prompt injection, too
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection
I vibed an Application Inventory Service
SOC homelab with 16gb RAM
What's your pre-deployment security checklist for a web app before going live?
RELATÓRIOS
July 14th Nightmare Eclipse
Can recon workflow get any easier and smarter than this ?
How the TLS handshake works, and why half of it is gone
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMDemande d'avis
Presales Engineer (Cybersecurity)
Balbooa Forms Joomla Flaw Lets Hackers Hijack Sites With a Single Upload
The way forward
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMTotal Isolation of legacy Control System is valid option to ….
A hardware security AI assistant that checks chips for hidden backdoors
Passed OSCP from Rajasthan things nobody told me about preparation
Large-scale exploitation campaign targeting website content management systems (CMS)
LIEF 1.0.0 is out featuring a brand-new Runtime API
Participants Needed: Master's Research on AI Governance & the EU AI Act
ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)
Been building my own edr; today it operates in ring 0
Data Sharing With Vendors
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
IT Governance vs AI Governance
Artlist.io appears to have been compromised by a ClickFix attack
CVE-2026-47291: Windows Critical Unauthenticated Remote Code Execution in HTTP.sys
Passive security measurement of 10,020 .it domains: CSP, cookies, TLS and email authentication
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-12 · MEDIUMWhat's stopping big orgs to replicate those AI Security startups themselves?
Hacking Apple - SQL Injection to Remote Code Execution
Can gamification actually improve security awareness?
Anonymity + security
Microsoft is rewriting Windows patch guidance because of AI - Help Net Security
Looking for Cybersecurity Contributors – Building an Open-Source AI Bot Detection Project
Ransomware negotiator hired to represent victims was working for the attackers
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMThoughts on Aikido.dev?
Freelancing on cybersec/ai
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
BloodBash Feedback Needed Before DEF CON 34 Red Team Village Talk - AD/hybrid Recon Tool
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMHow does insider threat software fit into your security workflow?
DarkLayer — Ransomware Tower Defense. Free, in your browser.
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMCTO at NCSC Summary: week ending July 12th
Precision Vs Accuracy
Physical security work and research with NASA and DARPA
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMA degree in CS or AI engineering & robotics
How do you keep archived firewall logs usable during a threat hunt?
Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
Closing the Timing Gap: Defensive Temporal Observability
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-10 · MEDIUMHow are you handling SSL inspection without constantly breaking developer tooling?
Uptick in email bombing
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-10 · MEDIUMTraining recommendations for SOC teams in the age of AI?
CISA KEV Threat Intel Orchestrator
Who is interested in digital forensics
Crypto Investigations using AI
Can AI imitate APT behavior well enough to confuse attribution?
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
Towards CSI: What's the best harness? (arXiv 2026)
'HalluSquatting' Turns AI Hallucinations Into Botnet Delivery Mechanism
New research: Why no single AI agent harness wins every cybersecurity task
Network of 200 GitHub Repositories Used for Malware Infection
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-10 · MEDIUMNeed help with my project
ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
SIEM Solution Recommendations
SOC analyst (1 YOE) doing full investigations/remediation — what practical IR skills should I actually be building?
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-09 · MEDIUMA Puerto Rico Government Agency Exposed 1 Million Social Security Numbers
MOD REQUEST: Can you ban the excessive AI posters please?
Why the HTTP QUERY Method Is a Bad Idea, and Accept-Query Is Why
Seeking Refferals
[REVIVE-SA-2026-003] Revive Adserver Vulnerabilities
ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)
FABLE 5 AND OPUS
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
AI agents went from "cool demo" to "exploiting CVEs in 10 hours"
Are companies thinking about insurance/liability for AI tool usage, or is that not on the radar yet?
1 in 2 devices sold in Africa exfiltrate data to China
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-08 · MEDIUMBTL1 done, now what?
Meta Glasses
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
Researchers Find New GhostApproval Bug in Many AI Coding Assistants
CISSP Exam
The teenage millionaire hacker from Tower Hamlets who took down TfL
Internal web app testing
ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th)
Bad Epoll: The bug missed by Mythos
2026 Chainanalysis Crime Report
Open-source AI security risk register mapped to MITRE ATLAS, OWASP LLM/Agentic Apps, and NIST AI 100-2
Safer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-07 · MEDIUM