MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Aug 10, 2026, 2:55 AM (UTC+3)
Topic · Awareness
Another Black Hat USA is in the books, and what a week it was. From a main stage keynote at the AI Summit to candid podcast conversations, a video interview with Cyber Defense Magazine , and a booth game that just wouldn’t quit, Mend. io showed up in Las Vegas ready to talk about the question every security leader is wrestling with right now: as AI reshapes both the software we ship and the systems we have to defend, who do we trust to verify that it’s safe? Here’s a full recap of everything Mend.io got up to on the show floor and beyond. Tuesday, August 4: Taking the main stage at the AI Summit We kicked things off with a main stage keynote at the Black Hat AI Summit, where Asaf Saar, EVP and Chief Product Officer of Mend.io, presented “The verification layer: Why AI security can’t be left to AI.”
A SIM swapping attack could compromise your phone, your personal accounts, and even your identity. Here's how to thwart them.
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place. DROP was created under California’s Delete Act , which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry. Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency. DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency.
The first 60 minutes on scene often decide the rest of the case – Richard Frawley of ADF Solutions breaks down how to identify, preserve, and triage digital evidence before you leave the property.
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
Understand how to identify, preserve, extract, analyze, and report digital evidence for modern vehicle forensic investigations. By Steve Gemperle Key takeaways • Vehicle data comes from two main lanes: EDR (crash) data, and infotainment and telematics data. They answer different questions and are strongest when used together. • Confirming legal authority and preserving volatile data before acquisition are the foundations of a defensible investigation. • The right acquisition method depends on the investigation type, not just the vehicle; consent searches call for less invasive access than a warrant might allow. • Cross-referencing timestamps across EDR, infotainment, telematics, and phone or cloud records is essential to building a timeline that holds up to scrutiny.
Hey there, I hope you’ve been doing well! 🤗 Hugging Face Incident It’s been… a week 😅 In case you haven’t heard, this week OpenAI published a blog post saying that the recent AI-powered attack on Hugging Face was in fact… GPT‑5.6 Sol and a pre-release model. I feel very fortunate to have been able to see things unfold behind the scenes and contribute to the blog. Unfortunately I can’t say more at this time, other than I am very impressed by my colleagues. Sponsor
Hey there, I hope you’ve been doing well! 🍬 Grandma Seems Chill In the San Francisco Bay Area, basically every billboard is about AI or tech. But when I was traveling recently, I saw a “Gummies for Granny” billboard that brightened my day: I imagined the meeting where the marketing leads were reviewing different framings for their products, and the right target demographic, and this is what they came up with 😂 I wonder if they have other brands or stores. Mushrooms for Mommy? Doobies for Daddies? A Little Ket for the Family Pet? Working in marketing must be delightful sometimes.
Scattered Spider skips malware and breaks in with a phone call and a legitimate remote access tool, here's how to hunt for it.
Key takeaways • C2PA support is now built into Magnet Verify Desktop, letting you detect, extract, and validate embedded provenance data without external tools or manual workflows. Note: The Magnet Verify SaaS offering already supports C2PA. • When present in a file, think of C2PA as a “nutrition label for media,” recording a file’s origin, edit history, tools used, and whether AI was involved • C2PA is a signal, not a verdict. The presence of C2PA doesn’t guarantee whether the content is true, and its absence doesn’t imply that it was not AI-generated. • Adoption is still early, but with major tech companies, AI platforms, and device makers integrating the standard, provenance signals will play an increasing role in forensic analysis.
Cloud application security keeps threat actors away from your data. We share practical ways to protect your apps and why it matters for your team today.
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
FileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.
A look at how to secure Kubernetes secrets
Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we use as rapidly as possible, and preparing to defend systems that have not yet been hardened.
I've been saving some things up in this draft blog post, adding new things, removing some older stuff that, after a few days, didn't quite hit the same as when I first read them. Most who know me know that I'm not so much about just dropping a link, as sharing my why for dropping the link. Dropping a list of links on a weekly or monthly basis is great, but sharing fewer links along with thoughts and perspective as to why seems to me to much more intentional and engaging. File Formats I ran across this LinkedIn post a bit ago, and it caught my attention because it had to do with revision history in the Word docs, based on the current file format. That LinkedIn post led to this blog post , which provides a really good demonstration of how to access revision save identifiers (RSIDs) within the new(er) DOCX file format.
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
Here’s how to protect your network from USB-based attacks, from detection techniques and forensics to prevention strategies to stop malware, data theft, and unauthorized access.
How to parse Linux-based memory images Source
What is Multi-Party Computation? Illustration: Jordan Warne / Privacy Guides We know how to secure data in storage using E2EE , but is it possible to ensure data privacy even while processing it server-side? This is the first in a series of articles I'll be writing covering the privacy-enhancing technologies being rolled out. History In a seminal paper called "Mental Poker" by Adi Shamir, Ronald L. Rivest, and Leonard M. Adleman from 1979, the researchers attempt to demonstrate a way of playing poker over a distance using only messages and still have it be a fair game. To explain, fan favorites Alice and Bob will make a return. First, Bob encrypts all the cards with his key, then sends them to Alice. Alice picks five to deal back to Bob as his hand, then encrypts five with her own key and sends those to Bob as well.
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
Cline is quite a popular AI coding agent, according to the product website it has 2+ million downloads and over 47k stars on GitHub. Unfortunately, Cline is vulnerable to data exfiltration through the rendering of markdown images from untrusted domains in the chat box. This allows an adversary to exfiltrate sensitive user information during a prompt injection attack by reading sensitive data (e. g. . env file) and appending its contents to the URL of an image.
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: Someone asked if you c
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real
How To Improve Your Privacy and Security on Mastodon Montage: Em / Privacy Guides • Illustration: @dopatwo@mastodon.social (1) • Mastodon mascot by @dopatwo@mastodon.social and Mastodon logo used with permission from Mastodon gGmbH. This site is not otherwise affiliated with Mastodon gGmbH. Increasingly, more and more people have joined Mastodon in recent years. The advantages provided by a decentralized network and using open-source software maintained by a nonprofit organization are undeniable. Mastodon offers much more robust protections for your privacy than commercial social media platforms do. This tutorial will show you how to make the most of it. This tutorial is the second of a series of two articles on Mastodon. If you would like to read a general overview about privacy and security on Mastodon, start with reading the first article of this series.
Posted by Adam Gavish, Google GenAI Security Team With the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or calendar invites that instruct AI to exfiltrate user data or execute other rogue actions. As more governments, businesses, and individuals adopt generative AI to get more done, this subtle yet potentially potent attack becomes increasingly pertinent across the industry, demanding immediate attention and robust security measures.
Stay Safe, but Stay Connected Photo: Jiroe Matia Rengel / Unsplash In data privacy, we often talk about the dangers of data collection and exposed data. It can get overwhelming to learn more about all the information that is collected on us, especially at the beginning. As a coping mechanism, some people react by downplaying concerns, disregarding dangers, and ignoring precautions altogether. Others react the opposite way: by isolating themselves, and no longer sharing anything with anyone. But neither is a viable solution. Staying isolated to avoid all data exposure risks other dangers. Dangers that might not seem related to data privacy directly, but are nevertheless worth mentioning here: Suicide and depression are very real dangers that we cannot ignore. Keeping our data safe shouldn't mean staying alone, and isolation is especially dangerous for LGBTQ+ people .
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
The Pyramid of DF/IR Expertise "First say to yourself what you would be; and then do what you have to do." -Epictetus I woke up one day and realized I’m an Executive at a Nationwide Digital Forensic & E-Discovery professional services firm. How did that happen? I also woke up one day and realized I have 25 years in the justice system. If I’d stayed in law enforcement, I could retire this year. All of these things are simultaneously shocking and sobering. They cause one to really reflect on the steps that it took to get them to where they have arrived. It also causes one to take inventor of all of the opportunities, successes, mistakes, failures, training, experience, case work and daily practice – both mental and practical – that go into building a body of work. It also makes one feel old all of a sudden, but “old(er)” doesn’t have to equal bad, as I’ve come to learn.
This week, we focus on raising awareness about API vulnerabilities created by direct attacks against API development teams and tech stacks. We also share articles on safe use of API frameworks, and examine how OWASP API vulnerabilities are uncovered by bounty hunters. Article: How secure is your API SDLC? API teams can produce secure and reliable APIs through rigorous design, coding and testing. However, this recent article highlights how every phase of API development is now at risk, forcing API teams to take a broader view of API security beyond just the code they produce.
This week, we focus on the topic of API error handling and how a REST API exposed 4 million WordPress websites to account takeover attacks. We also cover the risks and best practices for designing API error responses, and we look at an article that makes a great case for API-First. Vulnerability: 4,000,000 WordPress sites vulnerable to improper API error handling A research team at Wordfence recently discovered a vulnerability in the REST API of a WordPress plugin called the Simple Security plugin. This vulnerability allows a hacker to log into the site as any other registered user without providing a valid security token, effectively bypassing API authentication. WordPress is a hugely popular web content management system. It’s estimated that this API vulnerability impacted over 4 million WordPress sites.
This week, we take a look at Vodafone’s journey to API Governance with both challenges and benefits. We review news about the latest patch updates to the OpenAPI specification, and tips for API prototyping using OpenAPI description files. We also have multiple incidents of APIs with OWASP vulnerabilities like broken authentication and security misconfiguration. Article: Vodafone’s journey to API Governance First, Dimitris Maimaris shares Vodafone’s experience in adopting an API-first approach to API development and creating an effective program for API governance. Vodafone’s API team consists of 100 developers and QA engineers, supported by 16 solution architects, managing a growing ecosystem of over 250 APIs. As the number of APIs grew, the team sought to adopt standardized policies and practices to govern how APIs are developed, deployed and used.
This week, we review three different cases of API authorization and privilege escalation vulnerabilities, each of which is a wake-up call for API teams. We examine NIST updates on password security guidelines and share findings from an industry survey on API security and an upcoming OWASP API Top 10 webinar. Also this week we celebrate APISecurity. io’s 6th anniversary! Since publishing Issue #1 on October 11, 2018, the newsletter has become a trusted resource for staying up-to-date on the latest threats, best practices, innovations, and solutions in the API security space. Thank you to all subscribers for your continued feedback and support as we work to provide timely and valuable content to drive the conversation around API security. Industry News: NIST updates the rules for password security In the latest revision of Special Publication 800-63 Digital Identity Guidelines , the U.
This week, we look at API security vulnerabilities discovered in Versa Director and in dating app Feeld. We share insights from ethical API hackers on how they find API vulnerabilities and bugs in mobile apps. We have two separate reports on industry trends and priorities for API security in 2024, and a how-to article on API discovery. Vulnerability: Networks exposed to Versa Director API flaw According to a report by The Cyber Express, a vulnerability was recently discovered in Versa Director, a platform used by service providers to manage network configurations. The vulnerability is caused by improper input validation in a REST API exposed by the platform. APIs must be developed with secure coding practices to properly validate all user input.
This week, we share reports on the latest insights into the API breach at Optus and CocoaPods vulnerabilities reveal severe risks from the software supply chain. We examine the importance of API input validation for blocking DoS and authentication attacks. And finally a mention of our upcoming webinar examining recent API breaches and how to prevent them. Breach: API Governance and PII data exposure at Optus A recent report from The Register explains how a coding error in an API’s access controls exposed the personal identifiable information (PII) of millions of Optus customers. We originally reported on this breach in Issue 203 , from October 2022. Importantly, the coding error was discovered and fixed for the API in one domain but was missed for another unused domain.
This week, we have articles on the threats to enterprises in the cloud and another on the looming threats to APIs. We also examine the challenges posed by API threats in the utility and energy sectors. We also have technical articles on using AI to hack the crAPI vulnerable API and how to generate SDKs from your API contracts. Finally, we have news on two upcoming events. Article: Security threats to enterprises in the cloud In the first article this week , Forbes discusses the various security risks companies face when moving their operations and data to the cloud. While cloud service providers invest in security measures, businesses should avoid assuming their data is fully protected. The article presents insights from 20 members of the Forbes Technology Council on the top security threats and how to address them.
This week, we have articles on the economics of API attacks, and how developers can prevent them, and how to create an API solution wishlist with developers in mind. We also have technical articles on understanding cross-origin resource sharing (CORS) for APIs and how to secure APIs by blocking compromised tokens. We also have a double-header from Dana Epp to conclude this edition. Article: The economics of API attacks First up this week are the thoughts of The New Stack on the economics of API attacks and how developers can stop these attacks. According to the author, APIs have become a prime target for hackers, with 80% of internet traffic flowing through them. Attackers employ an economic model to assess the cost of an attack against the potential returns, which can include data theft, fraud, or the deployment of ransomware.
This week, we have thoughts from Bill Doerrfeld on how API governance is essential to counter technology sprawl. We also have commentary on how API security is essential in the age of digital transformation and another on why APIs are the new battleground for security. We have two articles on AI for APIs: firstly, how to use AI to find API bugs and how AI will enable APIs. Finally, we close with Dana Epp on using JS Miner to detect API endpoints and source code. Article: API governance to avoid technology sprawl The first article this week is an excellent piece from Bill Doerrfeld on how API governance is essential to avoid technology sprawl.
This week, we have news of two critical vulnerabilities in the Fortinet FortiSIEM product. We also have articles on making public APIs private and building an API security strategy. Dana Epp offers his thoughts on the difference between endpoints and routes, and we have two developer-focused tutorials, one on securing gRPC and the other on Django API security best practices. Vulnerability: Two critical flaws in Fortinet FortiSIEM product This week’s main news is the further coverage of the two critical issues reported in the Fortinet FortiSIEM product courtesy of The Register. The two vulnerabilities (tracked as CVE-2024-23108 and CVE-2024-23109 ) were rated as critical with a CVSS score of 10, indicating that the exploits can be carried out remotely by unauthenticated attackers and are low in complexity.
This week, we have important news of a vulnerability in the OAuth social sign-in feature of many popular platforms, potentially impacting billions of users. We have two articles from The NewStack, the first a guide on securing your API gateway and the second how to design scalable SaaS API security. We also have news of a significant partnership between Microsoft and 42Crunch designed to deliver end-to-end API security for enterprises. We finish with two guides, the first on preventing API breaches and the second from Dana Epp on using Burp Collaborator to prove API exploitability. Vulnerability: Flaws in OAuth social sign-in put billions at risk The most important item this week (and in the last few months) is the vulnerability discovered by Salt Labs in implementing the OAuth protocol in several popular websites.