I built SecURL: a passive outside-in security posture scanner for websites.
Paste a URL. Get a grade, score, score drivers, and evidence-backed fixes.
No login. No credentials. No invasive probing.
https://t.co/JSlJq1Z3JS
A password stolen in 2020 still worked on Snowflake 3.5 years later. That is the service-account debt behind the 165-org breach. Snowflake now kills the password option entirely. But swapping it for an unrotated key clears the deadline and changes nothing. #ServiceAccounts
CVE-2026-18963: a Keycloak flaw let anyone reset any account's password, admins included, without proving they owned the email. No MFA defeated, no credential stolen. You harden the front door for years. Account recovery is the second door nobody audits. #IdentitySecurity
SecURL 1.5 is out on iOS and Android.
Share any link and it traces where it really goes: every redirect, the final destination, the HTTPS state. On iPhone the answer appears in the share sheet.
It never opens the page, and never says a link is "safe".
https://t.co/9rGdrSzPhs
CVE-2026-69836: a CVSS 10.0 unauthenticated RCE in Entra ID, patched before most teams read the bulletin. No IOCs, no timeline, no way to check your own tenant. Cloud identity took the patching burden and quietly took the investigation with it. #IdentitySecurity
CVE-2026-69836: a CVSS 10.0 unauthenticated RCE inside Entra ID, the service that authenticates your whole org. The fix came with one line: nothing for you to do. You can't patch it, inspect it, or prove it was clean. Trust in the provider is now the control. #EntraID
CVE-2026-18577 exists only because the patch for CVE-2026-18556 was incomplete. Same N-able N-central auth bypass, still exploitable, now used to take over RMM servers and reach every managed endpoint. Your dashboard went green. The bypass never did.
#MSPSecurity
CVE-2026-65400, rescored to 9.8 on 18 Aug: root on a Mac over port 5900, no password, no account. Every corporate Mac ships this remote-access service, yet it sits in no SSO catalogue and no Conditional Access. Nothing was watching that door.
#macOSSecurity
A researcher tested credentials a major US tech firm swore it had rotated after the LiteLLM dump. Almost every one still worked. The leak was never just AI keys, it was anything the process could read. Rotation you never verify isn't rotation. #SecretsManagement
A QR code is just a link you cannot read.
SecURL 1.4 lets you scan it, see the decoded destination and trace redirects before deciding whether to open it.
No "safe" promise. Just useful evidence.
Try it: https://t.co/QX9wKUeXIP
npm just stripped account-admin powers from tokens built to skip 2FA. For years, one leaked CI token meant full account takeover. That bypass-2FA setting was never a bug, it was a feature. Machines can't answer MFA, so we handed them a permanent exemption. #NonHumanIdentity
CVE-2026-59115: a 9.9 in Microsoft's Entra Provisioning Service. The engine that creates and deprovisions accounts across your whole estate has more reach than any admin, yet sits in no access review. We govern the accounts it creates, never the machine. #IdentityGovernance
CVE-2026-18577: attackers bypassed auth on N-able N-central, then used its own Take Control feature to reach every managed endpoint. No stolen passwords needed. Your RMM is standing privileged access into everything, and hardly anyone governs it. #PrivilegedAccessManagement
Got a link you do not quite trust?
SecURL can inspect its public security posture without opening it in your browser. It checks redirects, TLS, headers, DNS trust and visible third parties.
Not a malware verdict. Useful evidence before you click.
https://t.co/N6BQlsaDQq
CVE-2026-55040, exploited this week: send SharePoint a token with alg:none, point it at its own signing cert, and become any admin. The flaw sits in service-to-service auth, the machine-to-machine trust no identity programme ever governs. #MachineIdentity
SecURL is live on Product Hunt today.
Scan public posture once. Know when it changes. Passive checks, no credentials, no invasive probing.
If that sounds useful, take a look and tell me what is missing:
https://t.co/NUqYXcC9ux
A one-off security scan ages the moment it finishes.
SecURL CLI now asks: watch this site for security drift?
Opt-in. No result upload. Silent in CI.
npx securl scan https://t.co/T1gRtvq5Hw
https://t.co/8IqEjtnByV
Deepfake detection is a $3bn market, aimed almost entirely at customer onboarding. But enterprise credentials get compromised at the help desk, on the MFA reset call. Real-time voice deepfakes land there next, and no identity team owns that step. #DeepfakeDetection
CVE-2026-59309: an auth bypass in vCenter's own Directory Service. Your domain controllers are just VMs sitting on top of it. Own the hypervisor and you don't beat the DC, you clone it and read the credential database offline. No MFA, no sign-in log. #IdentitySecurity
Dependabot now ingests OpenSSF malicious-package advisories, expanding malware alerts beyond npm to PyPI and more.
Useful—if malware alerts are enabled. Detection after publication still isn’t provenance.
Check dependencies, then verify the public edge: https://t.co/tMTK7l3hkb
Security dashboards can be confidently wrong.
We found one identity family at 100% activation and another at 0%—both by construction.
So we retired the metric instead of optimising a funnel against fiction.
Check your public edge: https://t.co/2bXdaSqAih