Microsoft patched the platform. Customers still own the exposure.
8 critical cloud CVEs disclosed this week. Five CVSS 10s. Zero requiring customer action — and that's exactly why security teams should care.
https://t.co/634cudPowg via @SecPoBr
#iGaming fraud isn’t just bonus abuse & fake accounts anymore. Organized crime groups are treating online gaming platforms like business opportunities — account takeovers, money laundering, synthetic identities and fraud at scale https://t.co/YpQ0ElZ9Ug
#iGaming#Fraud#FinCrime
Microsoft Security Research releases Dynamic Threat Detection Agent #DTDA data tied to agentic-SOC. Kudos to #microsoft for putting its #'s where its marketing mouth is.
https://t.co/Wrvnf0jB4c via @SecPoBr#AIAgents#Microsoft#Cybersecurity#SOC
AI is creating a new traffic security risk: AI agents talking to APIs, tools & other systems moving at machine speed. @F5's network guru @lmacvittie reminds us invisible plumbing has a habit of becoming tomorrow’s attack surface.
https://t.co/b6aPoOY8EY
#AISecurity#AIAgents
I clicked in for the zero-days and exploit chains.
Stayed for the weird plot twist: AI may be changing the speed of bug hunting itself.
Not the Pwn2Own story I expected to write 👇
EXCLUSIVE: Asked ZDI how many vuln submissions surged at #Pwn2Own Berlin.
The answer: 450% year-over-year. Rejected researchers are now dropping 0-days publicly.
https://t.co/eP4SdlQxSp @thezdi@orange_8361@briankrebs@SwiftOnSecurity
Interesting snapshot of where the cyber market is actually putting money and attention right now.
A lot of identity.
A lot of AI governance.
A lot of “how do we reduce analyst pain and operational chaos?”
Good SPB team effort on this one. 👇
2026 top 30 cybersecurity startups?
@notablecap's list is less hype cycles & more where CISOs are actually feeling pain right now.
@OrcaSecurity, @1Password, @AbnormalAI, @Tines, @ProjectDiscovery, @TorqHQ
https://t.co/vWwwRLzhFn
2026 top 30 cybersecurity startups?
@notablecap's list is less hype cycles & more where CISOs are actually feeling pain right now.
@OrcaSecurity, @1Password, @AbnormalAI, @Tines, @ProjectDiscovery, @TorqHQ
https://t.co/vWwwRLzhFn
One of the more grounded security reads I’ve seen lately.
Configuration drift doesn’t sound exciting until you realize how many breaches and exposures start with tiny forgotten changes nobody revisits.
Really sharp work here by @danraywood for @SecPointBreak 👇
Configuration drift may be the least sexy problem in cybersecurity… until it blows a hole in your environment.
Sharp piece from @DanRaywood on how forgotten configs and “temporary” exceptions quietly become real exposure.
https://t.co/GszZ7SLy2J
I wrote this one because consumers are walking around with the same token/OAuth mess enterprises have been struggling with for years… they just don’t realize it yet.
Worth occasionally checking what still has access to your inbox.
#Cybersecurity#OAuth#Privacy
Most people worry about passwords. Meanwhile, the app you authorized in 2019 may still be quietly reading your email.
#OAuth/token sprawl isn’t just an enterprise problem anymore.
New from Security Point Break:
https://t.co/ob8j0o2uxX
#Cybersecurity#Privacy#OAuth
The “CISA exploited vulnerabilities list” is basically the cybersecurity version of hearing glass break downstairs at 2 a.m.
Worth paying attention to this one from @shaundnichols -- #Cybersecurity#CISA
Palo Alto firewall flaw hits CISA’s exploited bugs list.
Not great. Not random noise, either.
@shaundnichols has the latest:
Palo Alto Firewall Flaw Lands on CISA Exploited-vulnerability List https://t.co/OAGNYpjm6f via @SecPoBr#Cybersecurity#CISA
Utah just dragged VPNs into the age-verification wars.
The goal is protect kids. The messy part is turning a privacy tool into a compliance headache.
This isn’t just a porn-site fight. It's much more!
#VPN#Privacy#AgeVerification
https://t.co/NsrstGzZii via @SecPoBr
Public shaming is the new payload.
Ransomware crews aren’t just locking files—they’re naming names and turning up the heat.
Ransomware Attacks Surge 22% in Q1 2026, #ReliaQuest Report https://t.co/tQAuhxJSI6 via @SecPoBr
🚨 Anthropic's own team just showed how to actually use Claude Code properly.
30 minutes. free. the person who created Claude Code.
Watch the workshop. bookmark it.
Think before you click! 🖱️💥 #Microsoft warns that malicious files are hitching a ride on your #WhatsApp chats. 📱@shaundnichols digs in & unpacks the threat & how to stay WhatsApp safe:https://t.co/m5kDoDh4zY
Cybersecurity’s hiring gap may not be a people problem at all. @sans_isc argues it’s a skills problem — and that has major implications for employers, job seekers & training programs. https://t.co/KxYIF7y8vd #cybersecurity#infosec#cybercareers#workforce
Survey scams are getting smarter-and more dangerous. Researchers warn phishing campaigns are now using fake surveys to steal credentials, payment data, and trust in one click. New @ Security Point Break by @shaundnichols https://t.co/0g72ncAAp5 #cybersecurity#phishing#infosec
This is not “Made in America” theater.
Apple is putting $400 million into U.S. suppliers as tech giants rethink supply-chain resilience, tariff pressure and geopolitical risk.
New from Security Point Break:
https://t.co/edUs8CxFU0
#Manufacturing#SupplyChain#Apple