How We Hacked McKinsey's AI Platform
https://ift.tt/if1ohIG
Submitted March 9, 2026 at 07:14PM by eth0izzle
via reddit https://ift.tt/cw1NZQI
https://ift.tt/if1ohIG
Submitted March 9, 2026 at 07:14PM by eth0izzle
via reddit https://ift.tt/cw1NZQI
codewall.ai
How We Hacked McKinsey's AI Platform
An autonomous AI agent found a SQL injection in McKinsey's Lilli AI platform. What it extracted was worse than we expected.
Unpinched - Instant point-in-time detection of PinchTab and agentic browser bridge artifacts.
https://ift.tt/B56FTpb
Submitted March 9, 2026 at 07:02PM by dalugoda
via reddit https://ift.tt/env5LT7
https://ift.tt/B56FTpb
Submitted March 9, 2026 at 07:02PM by dalugoda
via reddit https://ift.tt/env5LT7
Helixar.ai
Helixar Labs — Open-Source AI Security Tools
MCP Security Checklist, Sentinel MCP scanner, and Unpinched PinchTab detector. Three open-source tools for securing AI agent pipelines and agentic browser infrastructure.
InferShield v1.0 – Zero-Custody OAuth Proxy: Client-Side Token Encryption for AI Workflows
https://ift.tt/LepQGcm
Submitted March 9, 2026 at 06:57PM by Alex-Hosein
via reddit https://ift.tt/8m6lCf4
https://ift.tt/LepQGcm
Submitted March 9, 2026 at 06:57PM by Alex-Hosein
via reddit https://ift.tt/8m6lCf4
blog.infershield.io
InferShield Blog
InferShield: Secure OAuth authentication for AI workflows
Using cookies to hack into a tech college's admission system
https://ift.tt/tSC0nhM
Submitted March 9, 2026 at 07:29PM by EatonZ
via reddit https://ift.tt/Rlq9aKC
https://ift.tt/tSC0nhM
Submitted March 9, 2026 at 07:29PM by EatonZ
via reddit https://ift.tt/Rlq9aKC
Eaton-Works
Using cookies to hack into a tech college’s admission system
The Sri Krishna College of Engineering and Technology (SKCET) in India made elementary mistakes in web app security.
Sign in with ANY password into Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework
https://ift.tt/p6HRsgL
Submitted March 9, 2026 at 09:47PM by ulldma
via reddit https://ift.tt/sBIFcU7
https://ift.tt/p6HRsgL
Submitted March 9, 2026 at 09:47PM by ulldma
via reddit https://ift.tt/sBIFcU7
The GitHub Blog
How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework
GitHub Security Lab Taskflow Agent is very effective at finding Auth Bypasses, IDORs, Token Leaks, and other high-impact vulnerabilities.
Autonomous agent traffic as an emerging attack surface
https://www.usevigil.dev
Submitted March 10, 2026 at 02:30AM by SenseOk976
via reddit https://ift.tt/8g6KWOf
https://www.usevigil.dev
Submitted March 10, 2026 at 02:30AM by SenseOk976
via reddit https://ift.tt/8g6KWOf
Agent Auth
Agent Auth — Identity for AI Agents
DID-based cryptographic identity for AI agents. Register once, authenticate everywhere.
Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
https://ift.tt/owh0Xeb
Submitted March 10, 2026 at 02:29AM by bagaudin
via reddit https://ift.tt/1NmxdjC
https://ift.tt/owh0Xeb
Submitted March 10, 2026 at 02:29AM by bagaudin
via reddit https://ift.tt/1NmxdjC
Acronis
Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
Acronis Threat Research Unit (TRU) has identified a targeted campaign distributing a trojanized version of the Red Alert rocket warning Android app to Israeli users via SMS messages impersonating official Home Front Command communications
Beware! Fake CleanMyMac Website can steal your credential through malicious infostealers.
https://ift.tt/PYRWnIQ
Submitted March 10, 2026 at 09:21AM by NeuraCyb-Intel
via reddit https://ift.tt/0CQEOUn
https://ift.tt/PYRWnIQ
Submitted March 10, 2026 at 09:21AM by NeuraCyb-Intel
via reddit https://ift.tt/0CQEOUn
NeuraCyb Intelligence
Fake CleanMyMac Website Spreads SHub Stealer Through ClickFix Terminal Trick
Mac users searching for a trusted system optimization tool are being targeted in a new malware campaign that impersonates the popular macOS utility CleanMyMac. Security researchers warn that a...
Dutch Intelligence Warns of Russian-Linked Campaign Targeting Signal and WhatsApp Accounts
https://ift.tt/SYV0lri
Submitted March 10, 2026 at 10:19AM by NeuraCyb-Intel
via reddit https://ift.tt/qBRAO6X
https://ift.tt/SYV0lri
Submitted March 10, 2026 at 10:19AM by NeuraCyb-Intel
via reddit https://ift.tt/qBRAO6X
NeuraCyb Intelligence
Dutch Intelligence Warns of Russian-Linked Campaign Targeting Signal and WhatsApp Accounts
Dutch intelligence agencies have issued a warning about an ongoing cyber campaign in which Russia-linked hackers are attempting to compromise accounts on popular encrypted messaging platforms....
Trojanized Red Alert App Spreads Spyware Through Smishing Campaign Targeting Israeli Users
https://ift.tt/Zu9QXjd
Submitted March 10, 2026 at 10:16AM by NeuraCyb-Intel
via reddit https://ift.tt/D68Fsjf
https://ift.tt/Zu9QXjd
Submitted March 10, 2026 at 10:16AM by NeuraCyb-Intel
via reddit https://ift.tt/D68Fsjf
NeuraCyb Intelligence
Trojanized Red Alert App Spreads Spyware Through Smishing Campaign Targeting Israeli Users
Security researchers have uncovered a sophisticated mobile spyware campaign targeting Israeli users through fraudulent SMS messages impersonating Israel’s Home Front Command. The operation...
Hackers Exploit .arpa and IPv6 Infrastructure to Evade Phishing Defenses
https://ift.tt/ufJYXqm
Submitted March 10, 2026 at 12:10PM by NeuraCyb-Intel
via reddit https://ift.tt/iQlf5ke
https://ift.tt/ufJYXqm
Submitted March 10, 2026 at 12:10PM by NeuraCyb-Intel
via reddit https://ift.tt/iQlf5ke
NeuraCyb Intelligence
Hackers Exploit .arpa and IPv6 Infrastructure to Evade Phishing Defenses
Cybersecurity researchers have uncovered a sophisticated phishing campaign that exploits a rarely monitored part of the internet’s core infrastructure. Threat actors are abusing the special-use…
Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No
https://ift.tt/jywEXBA
Submitted March 10, 2026 at 01:09PM by AdTemporary2475
via reddit https://ift.tt/wW1TYvP
https://ift.tt/jywEXBA
Submitted March 10, 2026 at 01:09PM by AdTemporary2475
via reddit https://ift.tt/wW1TYvP
Buchodi's Threat Intel
Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No
This is Part 2 of my Pangle SDK research. Part 1 covered how I broke the encryption. This post covers what I found when I started comparing the decrypted data across apps.
In Part 1, I decrypted 694 Pangle SDK payloads and documented what ByteDance collects:…
In Part 1, I decrypted 694 Pangle SDK payloads and documented what ByteDance collects:…
Electric Eye – a Rust/WASM Firefox extension to detect AitM proxies via DOM analysis, TLS fingerprinting and HTTP header inspection
https://ift.tt/L0yOeQo
Submitted March 10, 2026 at 01:13PM by Reversed-Engineer-01
via reddit https://ift.tt/JU0CtdL
https://ift.tt/L0yOeQo
Submitted March 10, 2026 at 01:13PM by Reversed-Engineer-01
via reddit https://ift.tt/JU0CtdL
How We Hacked McKinsey's AI Platform
https://ift.tt/if1ohIG
Submitted March 10, 2026 at 03:32PM by pheexio
via reddit https://ift.tt/8Ch7vqK
https://ift.tt/if1ohIG
Submitted March 10, 2026 at 03:32PM by pheexio
via reddit https://ift.tt/8Ch7vqK
codewall.ai
How We Hacked McKinsey's AI Platform
An autonomous AI agent found a SQL injection in McKinsey's Lilli AI platform. What it extracted was worse than we expected.
Trust no one: are one-way trusts really one way?
https://ift.tt/Zds8ot9
Submitted March 10, 2026 at 06:17PM by AlmondOffSec
via reddit https://ift.tt/iWrjvOS
https://ift.tt/Zds8ot9
Submitted March 10, 2026 at 06:17PM by AlmondOffSec
via reddit https://ift.tt/iWrjvOS
Chrome Extension Sold to New Operators Became a Full Malware Chain — Caught via Console Logs, Google Pulled It, THN Covered It (ShotBird)
https://monxresearch-sec.github.io/shotbird-extension-malware-report/
Submitted March 10, 2026 at 05:59PM by TheReedemer69
via reddit https://ift.tt/0hO1Z2V
https://monxresearch-sec.github.io/shotbird-extension-malware-report/
Submitted March 10, 2026 at 05:59PM by TheReedemer69
via reddit https://ift.tt/0hO1Z2V
ShotBird Extension Malware Report
From a Sophisticated Browser-Extension Supply-Chain Compromise to a VibeCoded Twist: A Chrome Extension as the Initial Access Vector…
Independent technical analysis of a Chrome extension compromise, fake update chain, and Windows-stage malware activity.
After the $82K Gemini API key incident — here's why GCP billing alerts won't protect you in real-time
https://ift.tt/m26DBkV
Submitted March 10, 2026 at 09:08PM by daudmalik06
via reddit https://ift.tt/A8BiDpu
https://ift.tt/m26DBkV
Submitted March 10, 2026 at 09:08PM by daudmalik06
via reddit https://ift.tt/A8BiDpu
cloudsentinel.dev
CloudSentinel - Zero-Liability GCP Protection
Monitor your Google Cloud API usage in real-time and auto-revoke keys before they breach your threshold.
Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities Including Two Public Zero-Days
https://ift.tt/Zoj87px
Submitted March 10, 2026 at 11:59PM by Far_Mycologist4839
via reddit https://ift.tt/iIN3qpy
https://ift.tt/Zoj87px
Submitted March 10, 2026 at 11:59PM by Far_Mycologist4839
via reddit https://ift.tt/iIN3qpy
NeuraCyb Intelligence
Microsoft Patch Tuesday March 2026 Fixes 79 Vulnerabilities Including Two Public Zero-Days
Microsoft has released its March 2026 Patch Tuesday security updates addressing 79 vulnerabilities across its software ecosystem, including two publicly disclosed zero-day vulnerabilities. The…
Classifying email providers of 2000+ Swiss municipalities via DNS, looking for feedback on methodology
https://mxmap.ch
Submitted March 11, 2026 at 02:00AM by dfhsr
via reddit https://ift.tt/fZomrdb
https://mxmap.ch
Submitted March 11, 2026 at 02:00AM by dfhsr
via reddit https://ift.tt/fZomrdb
MXmap
MXmap — Email Providers of Swiss Municipalities
Interactive map showing where Swiss municipalities host their official email. DNS analysis of all ~2,100 municipalities.
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
https://ift.tt/yVtIDls
Submitted March 11, 2026 at 03:04AM by _PentesterLab_
via reddit https://ift.tt/O4uveUz
https://ift.tt/yVtIDls
Submitted March 11, 2026 at 03:04AM by _PentesterLab_
via reddit https://ift.tt/O4uveUz
Pentesterlab
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...
CVE-2026-28292: RCE in simple-git via case-sensitivity bypass (CVSS 9.8)
https://ift.tt/eh25jcE
Submitted March 11, 2026 at 12:32PM by WatugotOfficial
via reddit https://ift.tt/xsaUEGZ
https://ift.tt/eh25jcE
Submitted March 11, 2026 at 12:32PM by WatugotOfficial
via reddit https://ift.tt/xsaUEGZ
www.codeant.ai
CVE-2026-28292: simple-git Remote Code Execution - Case-Sensitivity Bypass (CVSS 9.8)
CVE-2026-28292 is a CVSS 9.8 remote code execution in simple-git (12.4M+ weekly npm downloads). A missing regex flag bypasses two prior CVE fixes (CVE-2022-25912, CVE-2022-25860). Full PoC, root cause analysis, and fix. Discovered by CodeAnt AI.