Penetration Testing and AppSec Microsoft paid $20M in bug bounties as AI boosts report volume
Microsoft's annual review lists 2,531 eligible reports and 562 rewarded researchers. We examine what the numbers mean for VDPs, AI and triage.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Penetration Testing and AppSec Microsoft's annual review lists 2,531 eligible reports and 562 rewarded researchers. We examine what the numbers mean for VDPs, AI and triage.
Cloud, Infrastructure and DevSecOps Forescout disclosed hardcoded keys, weak certificate validation and a device-adoption race in Omada zero-touch provisioning. Here is the risk and response plan.
Threats and Incidents A new loader-as-a-service combines fake CAPTCHAs, steganography, browser cache and in-memory execution. We break down the chain and defenses.
Human Security A campaign impersonates the popular Roblox scripting tool. We analyse the Java chain, theft scope and practical signals for users and SOC teams.
Vulnerabilities and CVEs N-able issued an urgent hotfix after attacks on N-central servers. We cover affected versions, MSP risk, Cloudflared traces and response priorities.
Identity and Access Unit 42 documented three attacks on Google Password Manager in Chrome for Windows. We explain the prerequisites, user-verification flag and defenses.
Threats and Incidents PNLD confirmed publication of names, organisations and work email addresses. We separate the official notice from ExfilSquad claims and explain response steps.
Vulnerabilities and CVEs An RNG integration defect reduced entropy in some COLDCARD seeds. We explain the affected firmware, technical mechanism and safe fund migration.
Threats and Incidents A macOS campaign starts with an ad and fake update, then resolves C2 through Ethereum. We analyse the chain, detection signals and defence.
Threats and Incidents Kaspersky documented an espionage campaign using OctLurk, SilkLurk and LurkProxy. We examine memory execution, credential theft and detection.
AI Security Links from ChatGPT, Claude, Gemini and other assistants may be public and archived. We explain the threat model and enterprise data controls.
Vulnerabilities and CVEs Every TeamCity On-Premises release is affected by a critical authentication bypass and RCE. Here are the fixes, containment and investigation plan.
Supply Chain Security Malicious JavaScript from Adform's advertising domain could replace BTC, ETH and TRON addresses in clipboards and forms. We analyse the supply-chain risk.
Vulnerabilities and CVEs Adobe fixed a CVSS 10.0 RCE and an SQL-injection file disclosure in Campaign Classic. We explain which deployments need urgent patching and investigation.
Threats and Incidents Amgen reported data exfiltration from third-party-hosted cloud environments, including potential patient PHI. We analyse shared responsibility and response.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.