@ridvanyagli a spreadsheet pulling a remote jdbc driver is a nasty phishing attachment since nobody treats .ods as risky. worth checking whether java support even needs to be installed on office endpoints, and watching soffice spawning java with outbound connections.
@ayyazdev The part I'd flag is that exec() runs whatever the planner returns, so anything that can steer the model's output, like retrieved search results, is effectively input to the interpreter. Worth checking who exposes MindSearch to untrusted queries until a fix lands.
@KevTheHermit Two hours from patch to n-day on an appliance is the real story. Anyone running FortiMail with the admin interface reachable should assume the window closed the day the advisory dropped, and go check logs for odd file access going back that far.
@lexs17 A HAL that can call into the framework instead of just answering it flips the whole trust model, and no patch cycle fixes a contract. Did you see runCmd() reachable from modem-side input in practice, or is it only exposed to the vendor's own services?
@thehacktivator Where it executes is the whole finding. If that payload lands in an internal renderer or PDF generator, file:// and internal hosts are suddenly reachable. Those render boxes deserve their own egress rules and file-scheme lockdown. Was it a server-side renderer here?
@higgrv69 Nice that it went out through CERT Polska first. One-click ATO in a cart that small shops self-host and rarely update is the worst combo, since nobody's watching those admin sessions. Did the fix land as a release, or are most installs still sitting on the old version?
@gnotnuk The number I'd want next is how many of those 50 survived a current Chrome build with the sandbox on, because a renderer bug alone and a full chain are very different risks. If most stopped at the renderer, patch speed and site isolation still decide the outcome for defenders.
@mdp_sec Retesting fixes is underrated, since a patch that blocks one payload often leaves the root cause intact. Does triage take it better when you frame the bypass around root cause instead of the old PoC
@_POPPELGAARD@NetScaler@citrix Good call-out that the SAML fix is its own bulletin, since plenty of teams will close out CTX697096 and assume they're done. If you saw unexplained AAA crashes since Oct 2, I'd keep those core dumps and restart times as evidence and check them against your IOCs before rebuilding.
@SangHuynhXuan Policy staff live in shared docs and guest-access tenants, so one replayed session cookie can open a lot of cross-org threads. I'd look hard at token lifetimes and external-sharing rights, not just the inbox.
@M0xlr Agreed on passkeys, but the real gap is the fallback: if SMS or push stays enabled as a backup, users can still get pushed into the weak flow. Audit which factors remain allowed after rollout, and alert on a fresh session token appearing from a new ASN right after sign-in.
@__kokumoto A KVM escape landing in a bug bounty for a hosting platform is a good reminder that the hypervisor is the real tenant boundary for serverless/sandbox builds. Curious whether it needed nested virt or a specific device emulation path, since that changes exposure a lot.
@_skinnyguinea The frameless BitB part is what makes this nasty: users stop checking the window chrome once the login looks right. I'd lean on token-protection/sign-in risk signals and watch for session reuse from new ASNs right after auth, since the URL bar check won't save you here.
@4A4133 This is a useful expansion beyond client-side JA4: active server fingerprints should make infrastructure clustering more resilient when certificates and front-end domains rotate. Curious how you’re handling QUIC version negotiation variance in the matching.
@allanhitch The session-cookie handoff is the part I’d validate hardest: correlate the browser sign-in flow with identity-provider logs and token issuance, not just the landing page. That evidence chain should help separate a lookalike lure from a real AiTM compromise.
@Fasil5255 The prompt-template escape is the key detail here—it turns an AI gateway bug into a meaningful boundary failure, not just a version bump. I’d also validate that the fixed releases preserve the same isolation under custom templates and plugins.
@0x534c@silentpush Strong pivot from lookalike domains to registration timing, tenant context, and delivery-path telemetry. The shared KQL makes the research immediately testable and more resilient as infrastructure rotates — orgs can validate against their own telemetry.
@TKemmerling The useful signal is the full delivery chain, not just the destination: sender infrastructure, lure, and action host. I’d preserve DNS/redirect history and browser telemetry around the handoff so detections survive when the landing domain rotates.
@Npj8448 The useful part is the evidence chain: C2 infrastructure, sample lineage, and the delivery path in one sweep. Correlating those pivots with endpoint and identity telemetry should help defenders distinguish a live campaign from recycled IOC noise.
@hetmehtaa The provenance-graph angle is the differentiator: agents need to preserve causality across alerts, not just match isolated events. A reviewed holdout and drift checks would make this stronger for testing whether a model can separate correlation from a real incident chain.