‼️ WARNING - A new critical cPanel flaw could let shared hosting customers run SQL as database root, bypassing database privilege boundaries.
CVE-2026-58048 (CVSS 9.4) affects supported cPanel & WHM versions and WP Squared. In some configurations, impact may extend to OS-level compromise.
Details: https://t.co/7RyYdMlKII
Microsoft Entra makes Passkeys the default authentication method and retires Microsoft-provided SMS and voice authentication!
Passkeys will become the default authentication experience in Microsoft Entra on September 1, 2026. Telecom-based methods (SMS and voice) will transition to customer-configured providers through the Microsoft Security Store.
𝗥𝗼𝗹𝗹𝗼𝘂𝘁 𝘀𝗰𝗵𝗲𝗱𝘂𝗹𝗲:
September 1, 2026:
• Rollout begins. Changes may take time to reach all tenants and will be deployed gradually.
• Passkeys will be automatically enabled for users currently enabled for SMS or voice.
• Registration Campaign will be set to Microsoft-Managed targeting passkeys for all users in eligible tenants.
• Users will be prompted to register a passkey during MFA sign-in; users will be able to skip.
September 18th, 2026:
• Review the telecom providers and related information available through the Microsoft Security Store to evaluate which option best meets your regional and compliance requirements.
October 30, 2026:
• Customers who need to continue to use SMS or voice will be able to choose from a list of telecom providers available through the Microsoft Security Store.
February 1, 2027:
• Microsoft-provided SMS and voice authentication will be retired.
• Only customer-configured telecom providers will support SMS and voice going forward.
• Passkeys become the default, recommended authentication method.
• If no action is taken, tenants relying only on Microsoft-provided SMS or voice may experience sign-in disruptions after February 1, 2027.
Read more:
https://t.co/QDcJfatgaI
Passkeys are included in all Microsoft Entra plans, so making this critical security change comes at NO ADDITIONAL COST for you.
#MicrosoftEntra #Microsoft365 #Cybersecurity
Ya se observa explotación activa de la vulnerabilidad CVE-2026-42945 (CVSS 9.2) en Nginx #nginxrift
Se recomienda aplicar las actualizaciones a Nginx y F5 de inmediato.
https://t.co/0JbzFkgJdT
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
@LunaGitana0333 También lo he visto en vivo con George Michael y trabajó con Janet Jackson (bueno con la familia Jackson en general ) , temendo baterista
🆕 Broadcom KB regarding the upcoming expirations of Microsoft Secure Boot 2011 Certificates 🔑 and how to handle them in a vSphere-based environment https://t.co/1Ejw6bJlf0
Guillermo, CEO de Vercel, da detalles técnicos del ataque que sufrió la empresa afectando las claves de algunos proyectos aunque recomiendan a todos los clientes cambiarlas.
Esas claves son las que permiten que muchas apps se conecten con apps de terceros, como bases de datos, servicios de IA, servicios para envío de email y otros, lo cual puede ser crítico si llega a manos de ciberdelincuentes.
La recomendación es que todos los proyectos en Vercel roten esas claves (keys): hay que ir a cada proveedor externo crítico, generar una nueva clave, cambiarla en Vercel, verificar que todo funciona luego de publicar y recién ahí borrar la clave posiblemente afectada. Para muchos proyectos hablamos de un trabajo de buen rato, dado que puede requerir la participación de muchas personas y múltiples mecanismos de autenticación.
OWASP just dropped its top 10 risks for agentic applications for 2026.
Let’s debrief.
➡️ Get the key findings from the report
➡️ Learn practical ways to mitigate these risks—grounded in Agent 365 capabilities in Microsoft Copilot Studio
For teams using agents, having the right controls in place is necessary if behavior takes a turn from expected boundaries.
Learn more: https://t.co/8xaZfxMHIm
💾 Ayer fue el Día Mundial del Backup y os expliqué cómo proteger vuestros datos correctamente usando la regla 3-2-1-1-0
➡️ https://t.co/QA2ECcQMc5
Aproveché para explicaros que ya no hay limitación de discos en @Synology
Me llamo Chema y soy dibujante tradicional. Desde que llegó la IA casi no tengo trabajo, pero yo seguiré dibujando mientras pueda.
¿Me ayudas a difundir mis obras? Por cada retuit ayudas a compartir el arte generado por las personas y Skynet pierde una batalla. ¡Gracias!
Si trabajas con evidencia electrónica de Microsoft 365, este libro es para ti.
Explica paso a paso cómo analizar correos, validar integridad y documentar hallazgos.
Disponible gratis
#forenseDigital#ciberseguridad#Office365#eDiscovery
https://t.co/XrGRlrYoOv
Another Learning Opportunity! 8 Best Practices To Secure Domain Controller https://t.co/h89uePteIH #Microsoft#Azure#Blog > Please RP if you like it!
Happy New Year! 🎉
I’ve made an entire penetration testing course I previously created for a training platform (now defunct after an acquisition) freely available on YouTube. If you’re interested in hands-on, practical security training, you can watch the full course here:
👉 https://t.co/0n8TqaCb3y
If you find the material useful and want to support more free, high-quality cybersecurity content, you can do so here:
☕ https://t.co/ez2YbndPDx
This weekend learn Cryptography for beginners with this FREE 1-hour Python course 🐍. Here are this week's five freeCodeCamp resources that are worth your time:
1. Learn how cryptography works, and how developers use it to secure both data and communication. freeCodeCamp just published a course that will teach you Python functions for symmetric and asymmetric encryption. You'll learn about SHA-256, AES, RSA, and public / private keys as well. You'll even code your own command-line cryptography tool. (1 hour YouTube course): https://t.co/BG3Rn1awFn
2. freeCodeCamp also published a course on building your own 3D games that run in a browser using Three.js and Blender. You'll learn how to model characters, design levels, detect collisions, and make the camera follow your playable character. You'll even deploy your game to the cloud so your friends can play it. (6 hour YouTube course): https://t.co/4bGk9WNfGZ
3. On this week's podcast I interview a self-taught developer with nearly a decade of software engineering experience. Patrick Hartley had to drop out of college to provide for his family. He taught himself programming while working at a thrift store, getting experience by freelancing and building his own apps. After 10 years as a dev, he turned down opportunities at big tech companies so he could continue working remotely from Oklahoma City. He shares tips for building foundational Python and JavaScript skills, surviving meetings as an introvert, and landing remote roles – even when you're competing with the global developer talent pool. (1 hour watch or listen in your favorite podcast app): https://t.co/hNnODCg332
4. Learn Event-Driven Architecture. freeCodeCamp published this advanced JavaScript handbook that will teach you about Event Loops, Task Queues, Call Stacks, Backpressure, Websockets, Pub/Sub, and more. Take your full stack development skills to the next level and be sure to share this with your developer friends. (full length handbook): https://t.co/vLEeKRLMax
5. freeCodeCamp also published our first ever guitar course. You'll learn beginner music theory concepts like chords and scales. You'll then map them to the guitar fretboard. You'll also learn guitar-specific techniques like barre chords. I learned guitar during the pandemic and am having an absolute blast with it. I hope you will, too. (1 hour YouTube course): https://t.co/60XImF7F38
For 11 years now, freeCodeCamp has built open source courses on math, programming, and computer science. Those will always be our main focus, but I hope you dig that we're also gradually adding topics like music, world languages, and even chess. If you want to help our charity ensure that the future of education is open, please support our mission: https://t.co/PJXlqTfhI9
Quote of the Week:
“I'd be happy sitting in a basement coding 8 hours a day. But I'm growing a lot faster trying to be an extrovert.” — Self-taught Software Engineer Patrick Hartley on this week's freeCodeCamp podcast
Happy coding!
The Microsoft Digital Defense Report 2025 shows how threats are evolving faster than ever, fueled by AI. https://t.co/rILMDbTHj5
Key insights from report include:
-More than 50% of cyberattacks with known motives had financial objectives such as extortion or ransom, while only 4% were motivated solely by espionage.
-For initial access, attacks targeted well-known exposure footprint, including web-facing assets (18%), external remote services (12%), and supply chains (3%).
-Meanwhile, identity-based attacks rose by 32%. More than 97% of identity attacks are password spray or brute force attacks.
-There has been an 87% increase in campaigns aimed at disrupting customer cloud environments through ransomware, mass deletion, or other destructive actions.
-Threat actors have begun using AI in malicious activities, including automated vulnerability discovery, phishing, malware or deepfake generation, data analysis, and crafting highly convincing fraudulent messages.
The report is rich with findings and observations like these on a wide range of topics, including cybercrime, identity attacks, ransomware, fraud, social engineering, cloud threats, and nation-state threat actors.
At @Microsoft, we’re taking action against these threats by disrupting cybercriminal ecosystems, sharing threat intelligence, and investing in proactive defenses to protect people, data, and critical systems.
AI is reshaping both threats and defenses. With responsible AI and cross-sector collaboration, organizations can reduce risk, safeguard identities, and build resilient systems. Read the Microsoft Digital Defense Report 2025 for more insights and defense guidance.