Football remains the beautiful game but the men who run it are managing to severely damage its reputation and it looks like they will be pressing the accelerator throughout this World Cup. It is incredibly sad.
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use.
Its capabilities exceed those of any model we’ve ever made generally available.
Over the next few months, we'll be gradually publishing some of our internal security research.
Starting with a bug chain that turns Nginx-Rift + Nginx-PoolSlip into full RCE.
More to come.
#Nginx#1day#RCE
https://t.co/tqQMFAoX9P
You interested in hacking and want to red team the government? CISA’s red team has an opening! Our assessments are typically 90 days and we’re performing actual red team work here. Check out the opening, and let me know if you have any questions!
https://t.co/DMX5zqbdgr
‼️🚨 A new npm supply-chain attack compromised 57 packages across over 286 malicious versions in under 2 hours. The attackers used self-replicating malware, a new version of the Miasma worm, which also used evasion techniques to stay under the radar.
The payload targets CI/CD and developer credentials, including GitHub Actions secrets, cloud credentials, Vault tokens, SSH keys, npm and GitHub tokens, and password-manager stores. This variant also injects AI coding assistant config files at `.claude`, `.cursor`, `.gemini`, and `.vscode` paths, a separate persistence and repo-poisoning angle.
Welp, that happened faster than I predicted. Thought it would be end of 2027, then early 2027, but agentic traffic growing so fast that bots have now passed human traffic online for the first time in the Internet's history. https://t.co/2zX5bHdhsa
You’ll see random pictures of Arshavin supporting Arsenal every year since he left. Dude never gave any interviews, just kept supporting the club like a proper fan. Top guy.
Tools like Snaffler are great, but crawling SMB shares creates a telemetry nightmare. You instantly light up the SIEM with :
- 5140 / 5145 (Network Share Access)
- 4656 / 4663 (Object & File Access)
So I built Invoke-WindowsSearch to query the native Windows Search DB (OLE DB) directly via WinRM/RPC, It extracts the targets without touching the actual files, completely bypassing the 4663 and 5145 detection footprint.
Trade-offs: Requires the WSearch service (disabled by default on Server OS) and lacks complex regex capabilities. Know your environment before execution.
#RedTeam #ActiveDirectory #OPSEC #ThreatHunting #PowerShell
Who knew a really long string could make an Entra ID login disappear from the logs entirely? In our #blog, @nyxgeek breaks down how overflowing #Azure's sign-in logging mechanism allowed access tokens to be issued without a single log entry. Read it now! https://t.co/2joOibx3Ia
We’re continuing to work with Microsoft and GitHub to investigate the impact of the malicious Nx Console version 18.95.0. I'll share any updates on X (@jeffbcross and @NxDevTools) as well as in our security advisory: https://t.co/szBoQ3doaX.
Initially, Microsoft indicated to us that there were 28 installs of the malicious version 18.95.0. Based on our own analytics for the compromised version, we currently believe the number of users who received the malicious package may be significantly higher; potentially over 6k installs.
We’ll keep working to determine the actual impact and exposure, and I don’t want to speculate beyond the facts we have right now. But I also don’t want to minimize the situation.
This is my top priority right now. Our team has been, and continues to be focused on understanding exactly what happened, helping affected users, hardening our systems and release processes, and being as transparent as possible throughout the investigation.
Arsenal academy products to have won a Premier League winners medal with the club
Adams (1998, 2002)
Keown (1998, 2002, 2004)
Parlour (1998, 2002, 2004)
Hughes (1998)
Cole (2002, 2004)
Taylor (2002)
Aliadiere (2004)
Saka (2026)
Lewis-Skelly (2026)
Nwaneri (2026)
Dowman (2026)