Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
9,300 Leaked AWS Keys Still Active, 768 Admin [2026]
11+ hour, 43+ min ago (442+ words) Security teams reading these numbers should treat them as a prompt to audit their own environment rather than assume the risk belongs to someone else. AWS’s IAM console can generate a full credential report showing every access key’s age and…...
Portal Drop — TryHackMe Write Up
2+ hour, 33+ min ago (786+ words) A spoiler free SOC investigation using web access logs EDR telemetry and MITRE ATTACK By Emir Kılıçer A WAF alert reports a scan against a public CRM portal …...
I Found an Undocumented MCP Server on OpenSea — and It Leaked Usernames for Any Wallet
8+ hour ago (492+ words) TL;DR: OpenSea runs an undocumented MCP server at mcp.opensea.io/mcp. One of its tools hands out API keys to anyone who asks, and another lets you resolve any Ethereum address with an OpenSea profile to its owner's…...
Machine Learning Map Reveals Hidden Paralog Vulnerabilities Across 1,005
10+ hour, 28+ min ago (613+ words) Cancer cells are masters of redundancy, and one of their most effective tricks is hiding lethal weaknesses behind duplicate genes....
Why “Claimable” Doesn’t Always Mean “Exploitable”: A Subdomain Takeover That Wasn’t
10+ hour, 56+ min ago (150+ words) A dangling CNAME, a claimable Mailgun domain, and a rejection that taught me more than an acceptance would have. Subdomain takeover checklists all say some version of the same thing: find a CNAME pointing to a service, confirm the target…...
From Domain Admin to Enterprise Admin: How Weak LDAP Signing Enabled Forest-Level Privilege…
12+ hour, 35+ min ago (614+ words) From Domain Admin to Enterprise Admin: How Weak LDAP Signing Enabled Forest-Level Privilege Escalation Introduction Active Directory privilege escalation is rarely caused by a single vulnerability …...
Google Workspace migration tool imports Microsoft 365 users and data – 4sysops
17+ hour, 40+ min ago (23+ words) Google Workspace’s native migration tool is now generally available for small businesses and educational institutions moving from Microsoft 365. It can copy use...
Your App Works Everywhere Except the Corporate Network
17+ hour, 55+ min ago (1383+ words) You ship something. It works on your machine, in CI, in staging, and for every user who tries it. Then one customer opens a ticket: it doesn't work for them. Same version, same config, same everything. It just hangs, or…...
RubyGems Shut Off Signups for Four Days, and Nobody Told Them Who Was Attacking
16+ hour, 51+ min ago (33+ words) In May 2026, volunteers running a package registry watched more than 2,000 malicious packages arrive in roughly two …...
How to Use CloudTrail to Check Whether You Were Affected by the AWS SSM Agent Vulnerability (CVE-2026-89049)
1+ day, 42+ min ago (499+ words) In this post, I examine what is recorded in AWS CloudTrail when someone attempts to exploit... Tagged with aws, cloudtrail, security....