Acabo de recibir el certificado del RTCP y no puedo estar más orgulloso. Gracias a los cracks @jdaanial y @lawwait. Esta formación es espectacular.
Ya puedo decir que soy IRCP + RTCP.
Cadena de ataque hecha por LLM. En cuestión de minutos:
CVE-2025-3248 en Langflow
Volcado PostgreSQL local
Pivote hacia MySQL
Cifrado
https://t.co/YIIpOMFQUY
be part of a broader, multi-vendor initial access operation….breach Synology NAS, Sophos firewalls, RDWeb portals, Citrix SSL-VPNs, and MS-SQL servers using automated brute-forcing since February 28, 2026.
https://t.co/n9vPU2uEc7
Azure CLI password spray attacks have increased 2000% in the last 90 days.
80% originate from three ASNs:
53667 (FranTech)
32167 (RHOISLAND)
6939 (Hurricane Electric LLC has prior Azure CLI spray abuse: https://t.co/u9ecllNdvp
53667 ASN prior abuse: https://t.co/oU4Vu8w0hk
‼️FortiBleed Leak Linked to Massive Fortinet Credential Harvesting Campaign
Security researcher Bob Diachenko discovered the FortiBleed leak, exposing Fortinet/FortiGate VPN credentials for 73,932 firewall URLs across 21,632 domains in 194 countries.
A Russian-speaking threat actor allegedly conducted a large-scale credential harvesting campaign involving 1.16 billion attacks against 320,777 FortiGate devices and 2.1 billion attempts against 163,650 Microsoft SQL Server systems.
Source: https://t.co/qXnFd7sx7y
We can already confidently state that an autonomous SOC is highly unlikely to bring any improvements for organizations burdened by significant technical and operational debt in areas like data collection and enrichment or standardized IR workflows.
https://t.co/e8ApaZsdmG
“The more urgent question is whether security professionals actually understand what they are dealing”
Why Agentic AI Is Security's Next Blind Spot https://t.co/o5rtvfFqmV
Lectura rápida sobre el solapamiento de víctimas en la primera parte del informe de Bitdefender. Afiliados compartidos y Comercialización de accesos
https://t.co/nQKXt2ZaIU
Even when each artifact is small on its own, the combination can turn a pile of disconnected facts into a timeline you can defend.
https://t.co/vEuywNqbyG
51% of organizations don’t gather feedback on the effectiveness of their CTI
A CTI team should make every other team look as good as they can because when they look good, they'll come back to you for more
https://t.co/sroEob3a10
NEW: malware developers added nuclear & biological weapons text to to their spyware.
Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner.
Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky.
When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit.
We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted.
In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation.
H/T to colleagues that shared this with me https://t.co/f3Aj9TYxU4
"the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims"
https://t.co/EUeE3JNJnQ