Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read - Exploited Within 24 Hours
10+ hour, 14+ min ago (543+ words) Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons The AI Supply Chain Has a Security Problem, and Much of It Is Sitting…...
6 Decisions CISOs Must Make Before the Microsoft Sentinel Defender Portal Transition
5+ hour, 34+ min ago (344+ words) Six decisions CISOs must make to protect RBAC, detections, automation, integrations, and SOC operations during Microsoft Sentinel’s portal transition....
Repository Agent-Security Gap Study — v2h baseline
11+ hour, 21+ min ago (178+ words) Generated 2026-09-13T10:25:40.362Z.... Tagged with ai, agents, javascript, security....
AI Security Scanning Needs Evidence, Not Just More Agents
13+ hour, 46+ min ago (994+ words) Google’s Mantis caught my attention because it points to a problem most AI security demos quietly walk around: finding a vulnerability is not the same as proving one exists. That distinction matters. Security teams already live with noisy scanners, half-useful…...
I built a ReDoS scanner that proves each bug offline — and hands you a verified fix
1+ day, 1+ hour ago (442+ words) A regular-expression denial-of-service bug is a regex whose backtracking engine can be pushed into super-linear (often exponential) time by a short, hand-crafted input. The textbook shape is a quantifier inside a quantifier: The scary part is that these patterns look…...
How to Lock Down Public Projects on Self-Managed GitLab
1+ day, 3+ hour ago (53+ words) Why Public Projects Widen the Attack Surface That matters because the API surface for a public project is large. Repository files, commits …...
Testing AI Agent Guardrails: Why ALLOW Is Not a Safety Signal
1+ day, 10+ hour ago (1447+ words) Building governance for an AI agent — and then proving it actually runs Here is a log line from a governed AI agent: POST_EXECUTION …...
How to Use CloudTrail to Check Whether You Were Affected by the AWS SSM Agent Vulnerability (CVE-2026-89049)
1+ day, 15+ hour ago (499+ words) In this post, I examine what is recorded in AWS CloudTrail when someone attempts to exploit... Tagged with aws, cloudtrail, security....
The Real Cybersecurity Issues That Should Keep Every CEO Awake at Night
1+ day, 14+ hour ago (32+ words) For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership …...
One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours
1+ day, 19+ hour ago (170+ words) A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA gave agencies until September 14 to patch. watchTowr saw exploitation attempts starting six hours after disclosure. The vulnerability was reported…...