@ktirdad@eric_seufert Yeah..... once the agent rides the user’s laptop or a residential proxy, the retailer never gets a clean agent host to ban. Blocking by IP stops being the control.
@LoganTeix Yes, Amazon’s security points about Muse are fair, and the Amazon-block / Shopify-partner pattern seems like a fight over who controls checkout.
On September 24, GreyNoise observed zero-day exploitation attempts against Citrix NetScaler Gateway, now tracked as CVE-2026-88771. Existing GreyNoise detections flagged the source IP as malicious within seconds, three days before the vulnerability was publicly disclosed.
The attacker's post-exploitation payload and IOCs: https://t.co/8E2AWwepXN
#GreyNoise #Citrix #Netscaler #CVE202688771 #Cybersecurity #0day #Vuln
@teamcymru has been a partner in FT3’s development, and I’m glad to see them speak publicly about that work.
Thank you for recognizing FT3 in Fraud Defense Intelligence, and for the engineering resources and infrastructure intelligence as FT3 evolves into 2.0.
That kind of support matters. FT3 needs to be shaped by the people working with fraud intelligence every day, and by partners willing to contribute to the work behind the framework.
https://t.co/dUizExgh3a
https://t.co/i1URjlJhkD
@PandaRE__ Enable resolution selection under settings and pick one for ultra wide? Default it will go potato mode if the laptop is opme unless your override the resolution
PHL Flagship Lounge today: packed. Barely a seat.
That’s supposed to be the elite product. Exec Platinum, Million Miler, 20+ years on AA — and the room still felt like everyone and their boarding pass got waved in.
Status only means something if the product still distinguishes people who earned it. Right now it doesn’t.
@AmericanAir
@GencoLaw Fascinating take. Once agents can run while you sleep, the interesting fight is how the legal process handles the illegal acts you never explicitly barred.
@srinatar Yeah. Browser access is just technical reach. The part Amazon made clear is that the merchant still has a vote: recognize the agent, confirm you authorized it, and decide what it's allowed to do.
@shunhewang This is the part of delegated authority that people skip when they only talk about payments.
If an agent can bind you to a deal, then the mandate and the dispute path must be explicit as well.
I never got around to my post-trip notes from Black Hat (RSA: Summer Camp Edition).
Instead, I was building this.
FT3 2.0 isn't a bigger list—it's a different shape.
Flat fraud taxonomies force one label to carry three separate facts: where the behavior sits in the lifecycle, who or what was authorized to act, and what was actually abused. Pick one; the other two never get written down. That shows up downstream as duplicate techniques, false coverage confidence, and crosswalks that don't translate.
FT3 2.0 records all three independently.
261 techniques, 119 analytics, 105 detection strategies, 69 controls, 3,100+ relationships.
You can walk from behavior to the telemetry that exposes it, to the analytics, to the control. That turns FT3 from a catalog into an operating layer, one agents can reason over rather than a framework analysts just read.
Full writeup: https://t.co/mTP3BNzFVz
Black Hat notes: pending. Possibly forever.
#FT3 #FraudTaxonomy #FraudPrevention
The useful tell isn’t “AI made it faster.” Hundreds of agents still hit countries on the operator’s own avoid-list. That’s an unconstrained loop — GreyNoise caught the deviation in the telemetry.
If you missed it: 395 organizations compromised across 48 countries. Hundreds of AI agents. One campaign against PaperCut NG/MF.
We mapped the attack flow below⬇️
Read Agents Gone Wild: https://t.co/bMHnIZvNYD
The US government recently required Anthropic to withdraw Fable 5 and Mythos 5 from all customers due to a reported "jailbreak."
The jailbreak involved prompting the model to review a codebase and address flaws, which revealed several minor, previously known vulnerabilities that GPT-5.5 and other public models also detect.
From my perspective as a security practitioner, these findings do not represent a significant vulnerability; they are a common occurrence in the field.
The core issue is that recalling a model deployed to hundreds of millions of users over a narrow, non-universal jailbreak with no model-specific impact sets a precedent that could prevent future frontier models from being released.
https://t.co/K88JdEcDLq