Overcoming LLM limitations in vulnerability research. This approach integrates with Brave for efficient web searches, unlocking new levels of security analysis. #Cybersecurity#AI#LLMs
Francesco Cipollone reveals a tool for quick vulnerability understanding. Get automatic summaries and snippets from this free, open-source project. #OpenSource#Cybersecurity#DevTools
β οΈ SANDWORM_MODE is an active npm supply chain worm targeting DevSecOps and AI toolchains.
19 malicious packages.
CI poisoning.
AI MCP injection.
Credential exfiltration on import.
If installed, assume breach.
#DevSecOps#AppSec#SupplyChainSecurity#npm
Phoenix Security recognized as a Management Leader in the 2026 Latio AppSec Report.
Enterprise vuln programs break when ownership, reachability, and remediation arenβt aligned.
Attribution.
Tool-agnostic reachability.
AI-driven remediation.
From ownership β executable fix.
Together, we raised Β£556,414 for NSPCC.
Proof that when the security community comes together, real impact happens.
Proud to be part of this. See you next year. π€π₯
Weβll be at these events showing how Phoenix Security | ASPM helps security teams focus on what actually matters in production β not just dashboards.
π Book a live demo here: https://t.co/3xbu9FGExb
hashtag#CTEM hashtag#AppSec hashtag#VulnManagement hashtag#SecurityTeams
Join Phoenix in 2026 π
Weβll be at VulnCon, OWASP EU & Global, LASCON, Black Hat USA and more.
Letβs talk real vulnerability exposure, remediation, and security that works in practice.
See you there π
#AppSec#CyberSecurity#InfoSec#SecurityCommunity
π¨ Sha1-Hulud 3.0 isnβt a CVE β itβs install-time execution on trust.
Runs inside dev machines & CI
Steals npm/GitHub tokens
Spreads using your own pipelines
One package is enough.
#Sha1Hulud#SupplyChainSecurity#AppSec#DevSecOps#npm
MongoDB vulnerability that leaks memory before auth β and behaves like RCE without executing code.
MongoBleed (CVE-2025-14847) is a trust-boundary failure in zlib compression that turns memory disclosure into full compromise via stolen credentials.
#MongoBleed#PhoenixSecurity
Curious what weβve been building this year?
From AI security agents to new platform features focused on context, prioritization, and real remediation outcomes β weβve been busy.
π See the platform in action: https://t.co/3xbu9FGExb
#VulnerabilityManagement#SecurityTeams
Wrapping up 2025 with momentum π
β£ 2β3Γ ARR
β£ 200% growth
β£ New teams, new locations
β£ Trusted by top global security teams
Onward to 2026 π
#CyberSecurity#SaaS#PhoenixSecurity#CTEM
87,000+ MongoDB instances are exposed.
Public PoC exists.
This isnβt RCE β but itβs how attackers get there.
Full technical breakdown π
https://t.co/yAhCNEN1ab
Your MongoDB might be leaking memory β silently.
MongoBleed (CVE-2025-14847) allows unauthenticated attackers to extract heap memory over the network.
No crash. No logs. Just data exposure.
#MongoBleed#CVE202514847#MongoDB#AppSec#DevSecOps