Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

DEV Community
dev.to > tinycoder-studio > i-found-an-undocumented-mcp-server-on-opensea-and-it-leaked-usernames-for-any-wallet-5935

I Found an Undocumented MCP Server on OpenSea — and It Leaked Usernames for Any Wallet

4+ hour, 39+ min ago   (492+ words) TL;DR: OpenSea runs an undocumented MCP server at mcp.opensea.io/mcp. One of its tools hands out API keys to anyone who asks, and another lets you resolve any Ethereum address with an OpenSea profile to its owner's…...

BIOENGINEER.ORG
bioengineer.org > machine-learning-map-reveals-hidden-paralog-vulnerabilities-across-1005-cancer-cell-lines

Machine Learning Map Reveals Hidden Paralog Vulnerabilities Across 1,005

7+ hour, 7+ min ago   (613+ words) Cancer cells are masters of redundancy, and one of their most effective tricks is hiding lethal weaknesses behind duplicate genes....

Medium
medium.com > @prelisted.io > inside-a-12-000-contract-honeypot-operation-on-avalanche-dcde68d7ca88

Inside a 12,000-Contract Honeypot Operation on Avalanche

8+ hour, 16+ min ago   (1343+ words) “” is published by Prelisted Io....

DEV Community
dev.to > aditya_soni_e5b9d5213e544 > an-attackers-multi-agent-framework-stole-thousands-of-credentials-in-under-six-hours-4kgh

An Attacker's Multi-Agent Framework Stole Thousands of Credentials in Under Six Hours

19+ hour, 10+ min ago   (252+ words) A financially motivated attacker ran reconnaissance, exploitation, and cleanup with almost no human... Tagged with aisecurity, agentreliability....

Medium
medium.com > @theBlueWizard > analyzing-sillyputty-when-your-favorite-ssh-client-goes-rogue-6a73daf514df

Analyzing SillyPutty: When Your Favorite SSH Client Goes Rogue

17+ hour, 57+ min ago   (598+ words) A walkthrough of the PMAT “SillyPutty” challenge, basic static and dynamic analysis of a trojanized PuTTY binary. — — — — …...

Medium
medium.com > @hrshit.kunwar > guardrails-for-ai-agents-constrain-functionality-and-permissions-kunwar-harshit-posted-on-the-98f656b027ff

Guardrails for AI Agents: Constrain Functionality and Permissions | Kunwar Harshit posted on the…

1+ day, 19+ hour ago   (749+ words) Guardrails for AI Agents: Constrain Functionality and Permissions | Kunwar Harshit posted on the topic | LinkedIn Everyone shows what their AI agent can do. 𝗡𝗼𝗯𝗼𝗱𝘆 …...

Requesty
requesty.ai > blog > litellm-default-key-exposure-ai-gateway-tier-one-security

One in ten exposed LiteLLM gateways still answers to sk-1234: your AI gateway is a tier one security asset now

3+ day, 33+ min ago   (897+ words) On 10 September, The Hacker News summarised a Wiz Research report in one line that reached 2.3 million followers: one example LiteLLM admin key was accepted by nearly 1 in 10 gateways. Researchers found 294 of 3,074 internet facing instances accepted sk-1234, the placeholder in the…...

Martin Cid Magazine
martincid.com > technology-sv > anthropic-claude-fourth-security-breach-live-server

Claude tried to stop. The test harness said no. It ended up hacking a real server

2+ day, 7+ hour ago   (184+ words) Claude Opus 4.6, an experimental build of Anthropic‘s flagship model, was running a Capture the Flag exercise — a standard cybersecurity evaluation in which an AI is given a fictional target machine and a task to find hidden data. A configuration…...

@Broadcom
broadcom.com > support > security-center > protection-bulletin > goldfactory-threat-group-abuses-android-work-profiles-with-vwork-clone-tool

GoldFactory threat group abuses Android Work Profiles with Vwork clone tool

2+ day, 13+ hour ago   (12+ words) Broadcom...

DEV Community
dev.to > biplabku > protocol-divergence-localization-finding-where-firewalls-block-your-traffic-514a

Protocol Divergence Localization: Finding WHERE Firewalls Block Your Traffic

2+ day, 7+ hour ago   (459+ words) The Problem You're debugging a connectivity issue. ping works fine, but curl times out. The usual approach: Run traceroute with ICMP - looks fine Run traceroute with TCP - dies at hop 6 Manually compare each hop Finally identify the firewall/ACL What…...