⚠️ Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
Source: https://t.co/nyaOOtouZa
The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026.
All users running version 2.4.66 or earlier are strongly urged to upgrade immediately. The most severe of the five vulnerabilities is CVE-2026-23918, rated High with a CVSS base score of 8.8.
The flaw is a double-free memory corruption bug triggered within Apache's HTTP/2 protocol implementation during an "early stream reset" sequence.
#cybersecuritynews #vulnerability
A bunch of folks have asked for the #ClaudeForBlueTeam posts to live in one place, and I'm happy to oblige!
They're now live on: https://t.co/vTAPVCsx7X
Audit your Active Directory in minutes with ADPulse. This open-source tool runs 35 automated security checks via LDAP(S) to uncover critical misconfigurations.
https://t.co/ERpAL9HPsJ
🔴BEWARE: Malicious skills on ClawHub are still live and *very* malicious.
For instance, this one, 'zaycv/clawhub', contains direct download instructions for external binaries in the introduction.
Some patterns we have noticed, monitoring the situation 👇
🥷Microsoft Incident Response Ninja Hub
This is a compilation of guides and resources that the Microsoft Incident Response team has developed on threat hunting, case studies, incident response guides, and more. 🫡
#cybersecurity#MicrosoftIRhub
https://t.co/5l93JYP22K
We got a new Ninja Training, now for MSEM (Microsoft Security Exposure Management). This is v1 and we will continue to grow and later add certificate of accomplishment, just like other Defender Ninja Trainings.
https://t.co/NJZluhznvZ
🚀 The Phishing Triage Agent is officially in Public Preview! This autonomous Security Copilot agent handles reports of user-submitted phish—streamlining a repetitive task in the SOC. Learn more: https://t.co/yXFz7VRBKO
This is what it takes to work in JUST Entra and Purview alone. LLMs cannot teach you this. Context matters.
What is Entra? 491 pages
https://t.co/1Dn8jEZZfd
Entra Authentication: 1356 pages
https://t.co/fQMq3a0gqk
Entra Application Management: 897 pages
https://t.co/fQMq3a0gqk
Entra RBAC: 581 pages
https://t.co/WNc3ZnNqxA
Entra User Management: 623 pages
https://t.co/vGI1703FOD
Entra Conditional Access: 424 pages
https://t.co/ziZ9ZMd7Wy
Entra Device Identity: 399 pages
https://t.co/MWGtmdgoPz
Entra Hybrid Identity: 2546 pages
https://t.co/TCepteXy5H
Entra Application Provisioning: 742 pages
https://t.co/I8AZJelNil
Entra Application Proxy: 350 pages
https://t.co/E5IabbRC8H
Entra Managed Identities for Azure Resources: 210 pages
https://t.co/pvv3XMEpMS
Application Integrations: 12741 pages - but a reference
https://t.co/DLIVtw5oiu
Entra Monitoring and Health: 438 Pages
https://t.co/hozqciI1bX
Entra Multitenant: 214 pages
https://t.co/5xHGbOn6gH
Entra Domain Services: 458 pages
https://t.co/O7gxFVcDLD
it goes on and on and on...
Then you have a separate documentation repository for B2C, probably a few thousand more pages: https://t.co/WnzlifV96G
Microsoft Identity Platform: 2182 pages
https://t.co/seWtGOAWRn
Purview Documentation: 8876 pages
https://t.co/HwJNMYUpaR
🚨 UPDATE: Full Post-Mortem On Cursor Security Incident
In yesterday’s thread I explained how I got drained after installing a malicious extension in @cursor_ai.
This is the deeper dive into what I found, what I did, and how you can avoid it.
🧵 👇
hashcat v7.0.0 released!
After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had.
Detailed writeup is available here: https://t.co/fxAIXNXsEr
Update: Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771.
🚨Today, the NCSC is revealing that Russian military intelligence has been responsible for deploying a sophisticated malware dubbed AUTHENTIC ANTICS as part of its operations.
https://t.co/aCQ1fhJ0Oc
New episode alert!
Ep 161: MG
In this episode we talk with @_MG_, the brilliant (and notorious) hacker and hardware engineer behind the OMG Cable. A seemingly ordinary USB cable with extraordinary offensive capabilities.
https://t.co/NvBWV8Ww5b