Live Detection Feed
200 reports with real, generated multi-format detection content — refreshed automatically as new intelligence is ingested.
This live feed aggregates real detection content (Sigma, KQL, Splunk, osquery, Suricata) generated alongside individual intelligence reports as they are published. For the 8 hand-curated flagship Sigma rules covering major CISA KEV vulnerabilities, see the Detection Engineering hub.
2026-07-29 · MEDIUMHugging Face built an interactive replay of the OAl agent that breached them
netfoil: Incorrect block responses could lead to localhost traffic
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
Style Dictionary - Prototype Pollution in convertTokenData utility function
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-28 · MEDIUMFlying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
PoCumentary, an agent-friendly tool for recording PoCs
Update: Thank you guys so much for all the help!
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-25 · MEDIUMReverse Engineering Windows Data Deduplication: From Research to an Open-Source Recovery Tool
CVE-2026-16632: A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib
Announcing the External Penetration Testing Program Pack
@fastify/static vulnerable to route guard bypass via path traversal
js-yaml: Exponential parsing time in flow collections leads to denial of service
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-24 · HIGHClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-24 · HIGHelectron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
CVE-2026-12688 - ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery
Critical: Cal.com before 5.9.9 Remote Code Execution via RSC (CVE-2025-55182)
CVE-2025-71389 - Cal.com before 5.9.9 Remote Code Execution via RSC
Amplitude customers using domain proxies should update their configuration immediately.
A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
Cybersecurity statistics of the week (July 13th - July 19th)
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-22 · MEDIUMI ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn't make money, so here's the code, the model and 13k real bypass attempts
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-21 · HIGHfast-uri vulnerable to host confusion via failed IDN canonicalization
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-21 · HIGHMicrosoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-21 · HIGHMicrosoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-21 · HIGHMicrosoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
NotCVE registry index — public records of vulnerabilities that shipped without a CVE
XSSer v.1.9 - "Bl4ck Swarm!" released
New Release: UFONet v2.0 - "R3DST4R!"...
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-20 · HIGHComposer: Arbitrary file write outside vendor via malicious transitive package name
vLLM denial of service via prompt embeds on M-RoPE models
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-19 · MEDIUMRecovering from a malicious APK installation on CMF Phone. HELP!
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-19 · HIGHCVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner
From 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign
Prompty: Arbitrary file read via file reference expansion
CVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out
CVE-2026-50147: Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
AI security project: PromptShield
If you've given an AI agent real credentials, how are you scoping what it can reach?
Published research article on IEEE about supply chain attacks and preventive security measures
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-17 · MEDIUMdeberíaa pagar por esto?
Is ast_grep_cli 0.44.1 on PyPI compromised? Windows Defender detected Trojan:Win64/Lazy!MTB during install
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-17 · MEDIUMAlerts on Server Loopback Traffic?
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-17 · MEDIUMAdvice on Detection Engineering
The Invisible Guardians of the Internet: An Introduction to Content Moderation & Trust & Safety
cybersec VS data science
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
Beta BIOS/UEFI
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
Pheditor has an authenticated terminal command whitelist bypass
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-16 · MEDIUMApple Sued Over Reported 'Hide My Email' Flaw
New Exploitable BOLA Found in Immich (self-hosted media platform)
With AI, Your Entire Internet History is Attributable to you Personally
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-16 · MEDIUMTeen hackers jailed after live-streaming the 16-hour TfL attack
Open-sourced my Claude Code team kit for secure multi-agent development and governance. Feedback welcome.
This might be a dumb question
How to Measure the Revenue Impact of Security Hardening Projects with a Simple Formula
SOC Analyst platforms and lacks
Preciso de ajuda
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
Top 10 Data Center and AI Infrastructure Security Risks
The British teenager who hacked into Vegas casinos from an east London flat
Critical NGINX vulnerability discovered: hackers can attempt to crash servers or even gain code execution
Proof of concept for CVE-2026-58635 LPE in Windows Braille Narrator service
Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach
Please Stop Making Me Opt Out of AI
Moroccan intelligence insider reveals widespread use of Pegasus hacking software | Morocco
Learning DevSecOps - Week 2
When Inclusive Language ends in phishing
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-16 · MEDIUMAI Agent for reconaissasion
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
i get stuck
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)
Greene County, Georgia, cybersecurity incident disrupts services
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
Getting mitre techniques a customer raw detection rule covers
MantisBT: Stored XSS in print_all_bug_page_word.php
File-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion
Sophos: The State of Ransomware 2026: Payments are dropping but encryption is climbing
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-15 · MEDIUMCoverage-First SOC: why domains and telemetry matter as much as threat intel
Runtime detection for ECS/EC2, what are people actually using?
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-15 · MEDIUMKQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'
Need help reverse engineering an Android APK used in a UPI fraud
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-15 · MEDIUMHN Security - My Semgrep C/C++ ruleset is ready for prime time again
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)
ISC2 Board of Directors Election is open.
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUMHochul halts new data center approvals via executive order
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
MITRE ATT&CK: [object Object], [object Object]
View full report + detection content → 2026-07-14 · HIGHAnyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · HIGHEch0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · HIGHFedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
AsyncAPI Supply Chain Compromise via GitHub Actions
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUM"Windows event log monitoring" the event IDs that actually matter vs the ones gets ignored
MITRE ATT&CK: [object Object], [object Object], [object Object]
View full report + detection content → 2026-07-14 · MEDIUMESET discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass Secure Boot by exploiting decade-old vulnerabilities
Source-reviewing 200+ self-hosted multi-tenant AI/SaaS apps for tenant isolation: 78 leaked across tenants (the "un-retrofitted read sibling")
Cybersecurity projects
Smashing the ServiceNow Sandbox – Pre Authentication RCE
When LLMs do more than they have to
RFC8555 ACME servers and DNS auth reusal
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist
@asyncapi/specs (2.7M weekly downloads) got compromised today via a malicious CI commit
The US government warns that Russia state hackers are coming after your router
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUMAddressing the state-layer gap in autonomous actor architectures: Byzantine fault tolerance without consensus
Nightmare Eclipse could be dropping his big promised exploit today
Writing an Evasive .NET Shellcode Loader
Enhancing the Threat Intelligence AI Model with Technical Knowledge About Windows Kernel Mode Malware
Zimbra Classic Web Client has a critical stored XSS, patched in ZCS 10.1.19 (reported by Google TAG, no CVE yet, not flagged as exploited in the wild)
Digital twins are becoming security infrastructure - not just monitoring tools
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-14 · MEDIUMEnhancing IIoT Security Using Digital Twins in Industry
ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)
AXON Body camera 3 of 4 hardware reverse cracking output video!
ExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers"
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMContext Bombs: Using AI Guardrails as a defensive mechanism
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
Im taking ec council cct exam
DIRAC: Pilot code downloaded over unverified HTTPS connection
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · HIGHDIRAC: SQL injection and lack of access control in PilotManager service
Every AI coding agent writes the secrets you paste straight to a plaintext history file — and nobody scans it
Stolen from
Official jscrambler npm package compromised: malicious versions 8.14, 8.16, 8.17, and 8.20
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMNow, defenders are embracing the prompt injection, too
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection
I vibed an Application Inventory Service
SOC homelab with 16gb RAM
What's your pre-deployment security checklist for a web app before going live?
RELATÓRIOS
July 14th Nightmare Eclipse
Can recon workflow get any easier and smarter than this ?
How the TLS handshake works, and why half of it is gone
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMDemande d'avis
Presales Engineer (Cybersecurity)
Balbooa Forms Joomla Flaw Lets Hackers Hijack Sites With a Single Upload
The way forward
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-13 · MEDIUMTotal Isolation of legacy Control System is valid option to ….
A hardware security AI assistant that checks chips for hidden backdoors
Passed OSCP from Rajasthan things nobody told me about preparation
Large-scale exploitation campaign targeting website content management systems (CMS)
LIEF 1.0.0 is out featuring a brand-new Runtime API
Participants Needed: Master's Research on AI Governance & the EU AI Act
ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)
Been building my own edr; today it operates in ring 0
Data Sharing With Vendors
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
IT Governance vs AI Governance
Artlist.io appears to have been compromised by a ClickFix attack
CVE-2026-47291: Windows Critical Unauthenticated Remote Code Execution in HTTP.sys
Passive security measurement of 10,020 .it domains: CSP, cookies, TLS and email authentication
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-12 · MEDIUMWhat's stopping big orgs to replicate those AI Security startups themselves?
Hacking Apple - SQL Injection to Remote Code Execution
Can gamification actually improve security awareness?
Anonymity + security
Microsoft is rewriting Windows patch guidance because of AI - Help Net Security
Looking for Cybersecurity Contributors – Building an Open-Source AI Bot Detection Project
Ransomware negotiator hired to represent victims was working for the attackers
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMThoughts on Aikido.dev?
Freelancing on cybersec/ai
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
BloodBash Feedback Needed Before DEF CON 34 Red Team Village Talk - AD/hybrid Recon Tool
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMHow does insider threat software fit into your security workflow?
DarkLayer — Ransomware Tower Defense. Free, in your browser.
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMCTO at NCSC Summary: week ending July 12th
Precision Vs Accuracy
Physical security work and research with NASA and DARPA
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-11 · MEDIUMA degree in CS or AI engineering & robotics
How do you keep archived firewall logs usable during a threat hunt?
Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
Closing the Timing Gap: Defensive Temporal Observability
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-10 · MEDIUMHow are you handling SSL inspection without constantly breaking developer tooling?
Uptick in email bombing
MITRE ATT&CK: [object Object]
View full report + detection content → 2026-07-10 · MEDIUM