US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange
The Hugging Face and OpenAI security incident showed AI doesn't make attackers smarter. It makes persistence cheap, and defenses built for alerts can't keep up.
A real-world Evo Continuous Offensive Security assessment identified 33 confirmed vulnerabilities within a multi-tenant enterprise SaaS environment, encompassing critical authorization flaws and issues that could enable tenant-wide compromise. The findings demonstrate the practical value of continuous offensive security testing in uncovering systemic weaknesses that traditional assessments might miss in complex SaaS architectures.
Voting Village returns to DEF CON 34 to consider the state of election security.
An interview with the delightful Cliff Stolll. So very worth your time
We get an EV charger hacking breakdown from the legend MajorMalfunction.
From the AI Hacking Village - an AI that plays Pokemon for you, without costing you 20 grand in tokens.
00:00 - Introduction 00:45 - Start of nmap 03:20 - Using FFUF to VHOST Bruteforce and finding flow.helix.htb 05:30 - Looking into H2 Database RCE's, finding the Alias Command allows us the ability to run Java 07:10 - RCE #1: Using H2 Syntax to create an alias to run a shell command 15:10 - RCE #2: Adding a Processor to run Groovy 18:00 - RCE #3: Adding a Command Processor to run a bash command 19:40 - RCE #4: Is it easier to just use Metasploit? 26:00 - Shell on the box, using Find to show the types of all the files in our CWD and finding an SSH Key 30:15 - Shell as Operator, cracking a PDF 38:00 - Running OPCUA-Client-GUI and editing the registers to put the device in maintenance mode
Plus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years.
Two security researchers purchased commonly-used no-reply email domains and configured them to receive messages, discovering that hundreds of organizations inadvertently send sensitive corporate data to these addresses. The findings highlight a widespread operational security failure where companies fail to properly validate email configurations before deploying automated systems. This research exposes how trivial domain acquisition combined with poor email hygiene practices can expose confidential information at scale.
Elastic Security Labs documents a technique where coding agents create reverse tunnels and LaunchAgents to expose local admin applications to the internet, potentially providing remote access despite benign appearances. Security teams should treat this activity as high severity even when it resembles legitimate development operations rather than confirmed malware, as the outcome—exposing privileged services—represents significant risk regardless of intent.
Identity-based attacks account for 90% of incidents, making identity management a critical security concern for SOC teams. Unit 42 explores how modern attackers exploit identity vulnerabilities and provides guidance for SOC leaders on developing effective response strategies to counter these threats.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
Apple's latest macOS update patches two Screen Sharing server vulnerabilities, one of which allows pre-authenticated remote code execution. These flaws represent a significant risk as they can be exploited without credentials to gain root-level system access on affected macOS devices.
A study analyzing over 6,000 patches reveals that AI-generated fixes succeed only about half the time, with even functional patches frequently introducing new bugs, breaking existing functionality, or leaving systems vulnerable to bypass attacks. The findings highlight a critical gap between patch generation and patch quality that security teams must account for when deploying AI-assisted remediation tools.
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.
Access your Huntress data easily with the Huntress MCP Server, connecting your AI assistant directly to your incidents, agents, billing, and more. No portal required.
At Black Hat USA 2026, Tenable hosted SWARM, a 48-hour event where nearly 100 security practitioners built open-source agentic AI tools addressing real operational pain points like finding prioritization, cross-scanner reconciliation, and findings triage—all published to the CyberAgents Exchange for community reuse. The winning entries included Chokepoint Finder, which ranks fixes to collapse thousands of findings into concrete remediation actions; ThreatCorraling, which correlates static and dynamic scanning results; and Evidence-Backed Vulnerability Investigator, which matches findings against vendor advisories to prove prior mitigation. By distributing defensive AI tooling openly rather than having teams rebuild solutions in silos, the CyberAgents Exchange aims to give defenders the same compounding advantage threat actors have always enjoyed through shared offensive capabilities.
CISA has disclosed five vulnerabilities in CPDLC over ATN-B1, a critical aviation data link communications protocol used globally, which rely on unauthenticated cleartext radio frequency links allowing remote message injection, session disruption, and denial-of-service attacks. The vulnerabilities enable adversaries to inject false clearances, disconnect multiple aircraft simultaneously, and inject fraudulent emergency messages, degrading operational safety margins through increased workload and delayed safety-critical communications, though no public exploitation has been reported and attacks require high complexity conditions unlikely outside laboratory settings. No mitigations are currently available for any of the five CVEs, with CVSS scores ranging from 5.3 to 7.1.