🛡️ AI Security Hack: You can now connect Burp Suite to Claude Code via MCP!
Capabilities:
• Feeds HTTP traffic directly to Claude for analysis
• Automates endpoint fuzzing & parameter tampering
• Generates custom PoC exploit scripts on the fly
Agentic pentesting is here! ⚡💻
@AnthropicAI Glad to see the second Risk Report drop. Consistent public reporting under the RSP is still rare in the industry. Now the interesting part is what the external reviewers say about the redactions and the overall risk calls.
We promised open weights for Qwen3.8. Now, time to meet them! 🎉
⚡ Qwen3.8-27B:
- A native multimodal dense model. With just 27B parameters, it outperforms Qwen3.7-Plus overall and shines in real-world coding & office workflows.
- 262K native context, easily extendable to 1M tokens via YaRN.
- Built for builders. Highly efficient, high-quality, and licensed under Apache 2.0.
🚀 The open weights for Qwen3.8-2.4T-A95B (Max-level) have also been released recently.
Whether you're shipping lightweight applications with Qwen3.8-27B locally or building agents with Qwen3.8-2.4T-A95B, they're yours now!
Download, deploy, and build something we haven't imagined yet. 👀👇
- Hugging Face:
https://t.co/4kaAcqYEVj
- ModelScope:
https://t.co/eRIMZCGkhC
I recently found a useful ChatGPT plugin: Superdesign
@SuperDesignDev
It can extract a live brand, design landing pages, generate artwork, explore 3 flyer directions, and QA layouts.
I tried it on my AI tutor project. One prompt generated 3 prototypes.
It's free with your existing ChatGPT subscription.
ChatGPT → Plugins → search "Superdesign"
🚀 Nmap for Pentesters — The Practical Guide Every Security Professional Should Bookmark
Ask any experienced penetration tester which tool they use first...
The answer is almost always Nmap.
The quality of your enumeration determines the quality of your exploitation.
That's why we've created a practical GitHub repository dedicated to helping cybersecurity professionals master Nmap for real-world penetration testing.
📡 Host Discovery Techniques
🔍 TCP & UDP Port Scanning
🌐 Service & Version Detection
🖥️ Operating System Detection
🧠 Nmap Scripting Engine (NSE)
🛡️ Firewall & IDS Evasion
⚡ Scan Performance Optimization
🔐 SMB Enumeration
🌍 HTTP & Web Enumeration
🎯 Vulnerability Detection
📄 Output Formats & Reporting
💡 Practical Commands for Real Engagements
…and much more.
📚 GitHub Repository:
https://t.co/d1tXtSq381
🔥 Join our cybersecurity community:
🔥 Telegram: https://t.co/upuP8k7Ev3
✴️ Twitter: https://t.co/Za7rYIL1h6
⭐ Star the repository
🔖 Bookmark it for your next assessment
♻️ Share it with fellow pentesters
Whether you're preparing for OSCP, CPTS, PNPT, CRTO, or working on real-world engagements, strong enumeration starts with mastering Nmap.
Because in penetration testing…
You can't exploit what you fail to discover. 🎯
#Nmap #CyberSecurity #Pentesting #RedTeam #OSCP #EthicalHacking #InfoSec #NetworkSecurity #Enumeration #Linux
‼️ Apple is sending threat notification alerts to mercenary spyware targets, like those attacked with Pegasus. They now appear on the iPhone Lock Screen and in Settings.
Apple also sends an email from [email protected], and you can verify it's real at https://t.co/HoRtigC2ad.
Real ones never ask you to click or install anything. ;-)
Use https://t.co/bonasCLhpZ to find subdomains. You get every subdomain on file, along with the date each one was first seen. And it’s insanely fast, results come back within seconds. ⚡
https://t.co/JrA9LlJeec
https://t.co/nibgzFgTFL
🛑 Attackers are exploiting a SharePoint authentication bypass.
CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC.
See how the exploit works: https://t.co/7DxzQeCz9K
⚡️ Huge Deal: Manus AI is completely FREE for 2 weeks! ⚡️
Go to https://t.co/gVFgtQa0z8 🌐
Log in 🔑
Claim free access 🎁
Get in early before it ends! 🚀
#freeai#manus#aiagents
OpenAI unveiled GPT-5.6-Cyber for vulnerability research.
It finds zero-days and software flaws in sandboxed environments.
Should cyber AI models be open-sourced?
LINK:https://t.co/6eIYO9pod9 #codex#trending
Microsoft open-sourced an AI unit testing agent.
It analyzes codebases, mocks dependencies, and writes verified unit tests across languages.
Do you trust AI to write unit tests?
LINK:https://t.co/BTXYpVgO5O
#OpenSourceAI#freeai
Stop chasing clients for missing documents.
Pesterly is an AI agent that automatically follows up with clients to collect invoices, tax forms, and files on your behalf.
It sends polite reminders until every item is submitted.
Link: https://t.co/15IKcWBZrH
#AI#Automation
‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version.
XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.
Update your WordPress sites ASAP 🠖 https://t.co/WxHpU2DkIC
Just launched the biggest update ever to our ad-funded coding agent.
New 100% free models:
- GPT 5.6 Luna
- DeepSeek V4 Flash 07/31
Try them now: https://t.co/uCHw0PuzKO
Free AI limit tracker for Mac just hit HN
AIUsageBar has a forever-free Claude tracker: limits, reset timer, basic cost tracking, no API keys.
Download: https://t.co/z1a47nloVg #Claude
Real-time video editing just went open source.
JoyAI-Video-Edit does 720p 30 FPS autoregressive editing on one GPU.
Would you switch from cloud editors?
LINK:https://t.co/oORz7ZLR1L
#OpenSourceAI#Ai
Jailbreaking AI Models with Obliteratus
Lately, the constrained AI models that companies are shipping have become less and less useful for cybersecurity.
We keep hearing a lot of complaints about Claude in this regard. What they are doing doesn’t really fix the problem, as hackers are not sitting around waiting for the guardrails to be lifted. They already have working models.
The barrier to entry for hacking has been reduced dramatically. AI can already automate huge chunks of this cybercrime work. So poking around your infrastructure looks completely irrelevant.
We need AI models that make things more secure.
Models with no guardrails that can show us real vulnerabilites we have.
https://t.co/mMUqaUkxn1