Web appOpen in Telegram
SSecurity Engineer

Security Engineer

@securediary · channel · Tech · indexed since 2026-07-19
634subscribers
138posts in the index
S
Security Engineer
Photo
click to show
A frustrated researcher dropped three Windows Defender zero-days on GitHub. A researcher going by "Nightmare Eclipse" tried to disclose a privilege escalation bug in Windows Defender to Microsoft. According to them, the process went badly. They claim Microsoft threatened them and dismissed the report. So, on April 3, they published the BlueHammer exploit on GitHub. Then, on April 16, they dropped two more: RedSun and UnDefend. By April 17, Huntress confirmed all three are being used by real attackers against real targets. The attack chain they observed: stolen VPN credentials for initial access, then UnDefend to block Defender's signature updates, then RedSun for SYSTEM-level privilege escalation. After that, the attacker moves laterally through the network while Defender is essentially blind. Microsoft patched BlueHammer on Patch Tuesday as CVE-2026-33825. RedSun and UnDefend have no CVEs, no patches, and no public timeline. It is sad to see disclosure process break down in a way that pushes someone to post exploits out of frustration. But I get the frustration: this pattern happens because researchers keep hitting the wall when they try to do the right thing. Reminds me of the well-known #FuckResponsibleDisclosure reports in Ukraine. When gov organization or a company simply ignores the risk, saying 'it is not a vulnerability'. Ukraine has been through that for some time. This week brought a massive Patch Tuesday (see first comment). 👇 What do you think of such exploit disclosures? Would you have done the same? @securediary
👍6
3 · 451 ·
S
Security Engineer
Photo
click to show
OWASP Top 10 is not enough in 2026. The most expensive vulnerabilities never caught by a security scanner. Real attackers think in attack paths. A minor SSRF vulnerability can be disastrous if chained with another weakness. That’s what I cover in my new video 👇 [Link to video] I go through: → where vulnerabilities actually come from → why scanners don’t save you → how attackers think → and what it really means to think like a senior / security architect I know, the video sounds a bit scripted. This is because — it was scripted😀 Please add some activity to the video. 🔁 Like, comment, and share.📣 @securediary
👍11❤1🤔1
5 · 496 ·
S
Security Engineer
Photo
click to show
The zero-days are numbered. 271 vulnerabilities found in Firefox 150. By a single AI model. Anthropic Mythos. Mozilla CTO Bobby Holley described the team’s first reaction as “disoriented” — and to be honest, I get it. A hardened browser like Firefox getting so many security findings. For context, a few weeks earlier, Mozilla used Claude Opus 4.6 to scan Firefox 148 and found 22 security-sensitive bugs. Mythos found more than x12 that number. About 41 of the 271 findings received CVE designation. The rest were defense-in-depth issues, hardening opportunities, or bugs in less exploitable paths. What stuck with me was this line from Bobby Holley: “So far, we’ve found no category or complexity of vulnerability that humans can find that this model can’t.” Now, Mozilla’s framing is optimistic. AI Security Institute, on the other hand, did not praise Mythos that much. They said: “It became the first model to fully solve AISI’s 32-step expert CTF.” However, they also said: “Tests are in simplified, undefended lab environments, so this does not show it can reliably breach hardened real-world networks.” Both are true. We have yet to see the full capabilities of AI in both defense and offense. And Mythos is just another step here. Have you got your hands on Mythos yet? Do you know someone who did? I want to hear first-hand experience. See 🫢 Top CVE Alert in first comment. @securediary
👍7❤3
1 · 499 ·
S
Security Engineer
Photo
click to show
Local root on every Linux distro.🫢 Copy fail CVE-2026-31431 advisory The same exploit binary works unmodified on every Linux distribution. If your kernel was built between 2017 and today — which covers essentially every mainstream Linux distribution — you're in scope. Copy Fail requires only an unprivileged local user account — no network access, no kernel debugging features, no pre-installed primitives. The kernel crypto API (AF_ALG) ships enabled in essentially every mainstream distro's default config, so the entire 2017 → patch window is in play out of the box. PATCH NOW. Update: See advisory links and recommendations in the comments. @securediary
👍9❤2
3 · 533 ·
S
Security Engineer
Photo
click to show
RCE on cPanel, 1.5M servers exposed, 70M domains at risk. If cPanel is part of your environment, it's time to patch. This flaw allows attackers to bypass authentication across all supported versions of cPanel and WebHost Manager. That means remote access to control panels, websites, and client data, without even needing credentials. Over 1.5 million exposed instances already on the internet. See advisory in first comment. And cPanel was not the only critical flaw. Google patched a maximum-severity issue in Gemini CLI and the run-gemini-cli GitHub Action. Gemini CLI trusted project files are automatically run in CI/CD. If those files were malicious, the tool could execute commands without a real human review. This issue = receipt for another privesc. Are you using cPanel or Gemini? 🤔 If you need help with patching, comment below. @securediary
❤4👍4
1 · 456 ·
S
Security Engineer
Photo
click to show
Two new Linux Privilege Escalation vulnerabilities were disclosed. Security researchers found two more serious LPE vulnerabilities in Linux: Copy Fail 2: Electric Boogaloo and Dirty Frag. Using these vulnerabilities, an unprivileged local user can gain root-level access to the system. Electric Boogaloo vulnerability is an unprivileged Linux PE. It allows writing to the page-cache of any readable file. Overwrites the nologin entry in /etc/passwd, then switches to it with su. It belongs to the same class as Copy Fail (CVE-2026-31431), but affects a different subsystem. Dirty Frag is another Linux PE that expands the same class of bugs as Dirty Pipe and Copy Fail. It has a deterministic logic flaw and does not depend on a timing window; no race condition is required; the kernel does not panic if an exploit attempt fails, and the chance of success is very high. Both vulnerabilities have now been publicly disclosed, but there is still no CVE or official patch for individual Linux distributions. As per my review, no advisories or mitigation suggestions are currently available. If you find any advisory or mitigations, please share it in comments. What can I say, here we go again 😑 Security advisories (updates): 1. https://aws.amazon.com/security/security-bulletins/2026-026-aws/ 2. https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/ 3. AlmaLinux: https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo/issues/8 4. AWS EKS: https://github.com/awslabs/amazon-eks-ami/issues/2713 5. Azure KS: https://github.com/Azure/AKS/issues/5753 Temporary workaround in comments (not tested)⤵️ @securediary
👍13❤1
2 · 461 ·
S
Security Engineer
Photo
click to show
Photo
click to show
I’ve just finished Security Architecture in Practice workshop together with Fwdays. It was a group of 60 people, which created a really focused and deep learning environment. There was a lot of practice: we’ve been attackers, defenders, and discussed real cases brought by participants. Sometimes messy, sometimes unexpected, but always real. I was genuinely and warmly stunned by how security topic resonated with all of you and how active and insightful the cases and questions from participants were. Thanks to everyone for the openness, energy, and willingness to experiment! P.S. Be on the lookout for new security workshops; check the Fwdays website if you’re interested. Thanks, Hanna Losieva, Mariia Vlad, Yana Zakharchenko, and Oleksandr Makhomet, for your care and support in preparation for this workshop. Appreciation to Oleksandr Gilievyi for sharing this opportunity. Thanks to all workshop participants! Do apply what we covered during the workshop in practice - because what you use stays with you 🙂 Onwards and Upwards! @securediary
👍17❤6
2 · 474 ·
S
Security Engineer
Photo
click to show
A fake OpenAI Privacy Filter repo hit #1 on Hugging Face (AI “popular right now” list). 244K downloads. And it was malware. A repo was impersonating an OpenAI open-weight model and delivered a Rust-based infostealer to Windows users. This week had a couple of other major events; Ollama had a critical flaw that could allow a remote attacker to leak process memory. Quasar Linux Remote Access Trojan targets developer systems to steal credentials and establish a foothold for supply chain compromise. DAEMON Tools confirmed compromised installers were distributed from its official channel. This means that a risky place might be anything: OpenAI model, a CLI tool running in CI/CD, a package pulled during build, a developer's laptop, an installer from a vendor website. On the topic of Hugging Face and AI-related malware. Have you secured your AI? Do you have 2FA enabled and the memory feature off? Have you opted out of training datasets on your personal information? If not yet, you should do this (see how in first comment). @securediary
👍7🤯2
1 · 531 ·
S
Security Engineer
Photo
click to show
Me every Friday 😀 I know it’s only Wednesday, but this pic was too good not to share. Are you feeling the same sometimes? Do I have Harry Potter funs here? Let's connect! ⤵️ @securediary
❤10👍9
3 · 540 ·
S
Security Engineer
Photo
click to show
AI is now finding more bugs than humans. Microsoft's May Patch Tuesday included 16 vulnerabilities found by MDASH, their new AI system that orchestrates over 100 specialized agents. Four of those were critical RCEs in the Windows kernel. Palo Alto Networks doubled its typical monthly advisories and said most findings came from AI models scanning their code. Mozilla found 271 bugs in Firefox using Mythos last month. At the same time, bug bounty programs are collapsing under AI-generated reports. cURL suspended its bug bounty program. Nextcloud suspended theirs. Bugcrowd vulnerability reports quadrupled in March, but the majority were invalid. HackerOne saw a 76% jump in submissions, but only 25% were genuine flaws. Linus Torvalds called the Linux security mailing list "unmanageable." And honestly, I side with Linus on this.   The majority of vendors are now running AI against their own code, and the patches are coming in waves. Buckle up and prepare for a ride. 😑 See top CVEs in first comment. Have you embraced AI for security checks? How is your team handling the volume of ciritcal vulns? @securediary
👍7🤯1
2 · 484 ·
S
Security Engineer
Photo
click to show
CISA left AWS GovCloud keys, tokens, and plaintext passwords exposed in a public GitHub repo. A contractor created “Private-CISA,” disabled secret-blocking, and likely used it to sync files between work and home computers. GitGuardian found it. Another researcher confirmed some exposed AWS keys still worked. After the repo was taken down, the keys reportedly remained valid for another 48 hours. This can happen to anyone, even CISA. 😑 Other important topics: → CrowdStrike, Google, and Shadowserver disrupted the Glassworm botnet, taking down its command-and-control channels. Glassworm’s victims' entry: Trojanized VS Code extensions, npm, PyPI, and GitHub repos. → Microsoft called out for a “more coordinated vulnerability disclosure” after removing Chaotic Eclipse’s GitHub account. This researcher publicly disclosed three Defender zero-days: BlueHammer, RedSun, and UnDefend. I see both sides. Microsoft responded slowly, and the researcher felt ignored. We know the story: vendors get a vuln report, call it “by design,” then ignore researchers. But releasing exploits without patches does more harm than good. RedSun and UnDefend were used in real attacks within days, before patches arrived. If a vendor ignores you, write about it and share high-level info — or alert people in cyber (like me) to highlight the patch’s importance. We should do better. We will. → Verizon issued a 2026 Data Breach Report: 48% of breaches involved supply chain compromise; 67% of employees use unauthorized GenAI at work. The lesson? The industry is obsessed with AI in SAST, pentesting, and SOC. Fair. But we still see plaintext passwords, exposed cloud keys, poisoned extensions, and irresponsible public exploit disclosures. Maybe the priority isn’t "more AI security," but getting the basics right? Top CVEs in the first comment. @securediary
❤4👍2
451 ·
S
Security Engineer
Photo
click to show
Your AI agent is not an employee. So why are we giving it employee-level trust? Anthropic published "Zero Trust for AI agents". A very interesting read, I highly recommend it. The most important part is the shift in assumption. Agents are not just chatbots anymore. They can read docs, call APIs, open pull requests, trigger workflows, write code, and sometimes execute. That means they are becoming a new kind of identity inside the company. And this identity is not very reliable. It can be influenced by prompts. It can misunderstand context. It can act faster than a human watching it. That changes the security model. Until now, we designed access around humans and service accounts. Agents are not human users, nor are they normal service accounts. But they still hold credentials, can call tools, and touch real systems. That makes can prompt-level guardrails useful. But not enough. Real enforcement has to sit outside agents: → Give them less access → Make their credentials short-lived → Put them in a sandboxed environment → Log every important action → Whitelist their tools → Keep human-in-the-loop Assume the agent will eventually do something unexpected. It always does, doesn’t it? 🤔 The PDF is free. Link in comments. @securediary
👍6❤4
7 · 467 ·
S
Security Engineer
Photo
click to show
Eight US agencies published a warning about cyberattacks on fuel tank monitoring systems.  These systems monitor fuel levels, temperature, and leak detection at gas stations and transportation hubs. Attackers gained access and changed settings on these systems. The attack vectors listed were simple: authentication bypass, hardcoded creds, default passwords, OS command injection, SQLi. Almost every week, we see attacks hitting critical infra that use default passwords or have an admin console exposed to the internet. Ensure the basics are taken care of. If you keep default passwords on admin console exposed to the internet, what do you expect? 😑 A few other stories I want to share: → Google patched an Android Framework flaw (CVE-2025-48595) that was exploited by attackers. → Microsoft added a two-hour auto-update delay for VS Code extensions to reduce the risk of supply chain attacks. → OpenAI is rolling out Lockdown Mode to limit tool abuse and data exfiltration risk from prompt injection. Top CVEs in the first comment. Have you seen incidents with default or hardcoded passwords? How it happened and how it ended? @securediary
👍7
422 ·
S
Security Engineer
Photo
click to show
It's starting to feel more and more that today the game comes down to "AI vs AI." Take cybersecurity. AI used to secure systems (AI SOC, AI SAST, and pentest, Anthropic mythos). And AI is used to abuse them. Just take APTs, security researchers. Bug bounties crashing under the weight of AI reports. What do you think of this? Have you felt that “AI vs AI” becoming our new reality? 👀 @securediary
👍15
1 · 415 ·
S
Security Engineer
Photo
click to show
Hi everyone! I know my blog is steadily gaining new readers, and I’d like to put that reach to good use. Specifically, I want to help DOU gather more reliable salary data for security professionals in Ukraine. Every year, only about 20–30 security specialists fill out the survey. That’s just not enough. If you work in cybersecurity or infosec, I’m asking you to take five minutes to complete this survey. It’s completely anonymous. DOU has already received 40 responses from Security professionals, but the goal is 100. The more data we have, the more accurate the salary statistics will be for our entire community. Remember, we’re doing this not just for DOU, but for ourselves. The results will be published in July in the salary widget and articles. Let’s make it happen! 💛 Link to survey in comments. @securediary
👍9❤2
1 · 475 ·
S
Security Engineer
Photo
click to show
The US government forced Anthropic to pull Claude Fable 5 and Mythos 5 offline. The reason? A jailbreak consisted of asking the model to read a specific codebase and fix any software flaws. Isn't that what defenders use these models for? 😑 Yes, but the concern that this will be abused by attackers. Here’s a quote from the US government request: “suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States.” I presume they are specifically concerned about foreign attackers? Is this an overreaction? Top CVEs to patch in first comment. @securediary
👍7❤2
516 ·
S
Security Engineer
Link
click to show
We’ve already collected 87 out of the 100 responses we need for Security. Come on, let’s reach 100 this year. This will be useful for everyone 🙂 Link to salary survey
👍5❤3
580 ·
S
Security Engineer
Photo
click to show
Do we win a lottery here in Ukraine and rest of the world? 👀 @securediary
👍8
450 ·
S
Security Engineer
Photo
click to show
A fired school district IT admin spent 20 months attacking his former employer. Before being terminated, he grabbed over 300 sets of user credentials. Then over the next two years he deleted their Facebook page, wiped Apple School Manager data, disrupted their Schoology LMS, and tried resetting GoDaddy accounts. He got caught because he asked a coworker to wipe a USB drive he left behind. The coworker gave it to management instead. $100K in damages, 21 months in prison. The lesson? Just credentials, nobody revoked on the day he was fired. For twenty months. 😑 Also this week: → 1,500 Arch Linux AUR packages poisoned with infostealers via spoofed maintainer accounts. → Google Threat Intelligence Group found a Chinese actor inside US military research networks. Top CVEs in the first comment. Share your thoughts on IT admin story. I mean, did they even have an onboarding/off-boarding policy? 👀 @securediary
👍7❤2
538 ·
S
Security Engineer
Photo
click to show
China’s Zhipu AI matches Mythos capabilities in vulnerability detection. While U.S. and Anthropic’s Project Glasswing restricts access to Mythos, China’s Zhipu AI open-weight model matches and, in some tests, beats Claude at vulnerability detection. Independent testing by Semgrep placed Zhipu AI GLM-5.2’s IDOR (Insecure Direct Object Reference) vulnerability detection at a score of 39%, surpassing Claude Code’s 32–37% on identical evaluation tasks. While the whole story (honestly) seems to be a promotional pitch for Semgrep’s Multimodal, it brings out curiosity to try the Zhipu AI along with other open-source models in their capacity to detect vulnerabilities. With that said. Mythos continues to lead vuln race and finds very old vulnerabilities in software. A 29-year-old memory leak bug in Squid, the open-source web proxy, was found by Mythos. The bug has been in the code since 1997. CVE-2026-47729 affects all versions of Squid in default configuration. When parsing FTP directory listings, if there is no filename after a timestamp, the parser reads past the buffer and leaks heap memory back to the attacker. That memory can contain HTTP requests with passwords and API keys. AI continues to evolve, finding bugs that survived thousands of human code reviews and tests. Crazy and hectic times. Use AI. Or stay behind? 🤔 Top CVEs in first comment. @securediary
👍6
4 · 571 ·
S
Security Engineer
Photo
click to show
*npm install is the new phishing email. 108 malicious packages and browser extensions across npm, Golang, and Google Chrome. All tied to North Korean campaign. In parallel, fake Rollup polyfills are built to steal developer secrets. DAEMON Tools shipped malware through its own installer in a supply chain compromise. Attackers deliver malware as a dependency and let you handle the delivery. If your supply chain defense depends on a developer checking a package before install, you are defending against 2019. Enforce checks against the package, CI, or the registry. Use the free versions of Snyk, Semgrep, or Trivy to do that. That costs you nothing but saves you from a headache later on. Developers are lazy. Especially in the age of AI. Do the Knowledge Sharing and Cyber Awareness. But do not rely solely on people, or, even worse, agents. Agree? Don't miss: → Bad Epoll Linux Kernel Flaw Lets Unprivileged Users Gain Root I recommend: → Escape benchmarked Anthropic Opus 4.8 with AIkido Security and XBOW to find 4x more vulns than the raw model → badkeys/badkeys - Tool by Hanno Böck that checks cryptographic public keys for known vulns Top CVEs in the first comment. 👀 @securediary
👍14
6 · 662 ·
S
Security Engineer
Photo
click to show
OpenAI and Anthropic Agents Targeted Real People in Cyber Tests During a cyber-range evaluation by the UK AI Security Institute, agents powered by Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6 Sol performed 19 unauthorized actions on the public internet. Seventeen actions involved Mythos 5, while two involved GPT-5.6 Sol. The agents had unrestricted internet access, and evaluators disabled their standard cybersecurity protections. Having these unrestricted settings, agents attempted to deceive real people. In the most serious case, a Mythos 5 agent tried to introduce malicious code into a GitHub project. The agent created fake GitHub identities, contacted project maintainers, sent five targeted emails, filed malicious bug reports, and used additional accounts to make its proposed changes appear credible. After a real user questioned its activity, the agent edited one of its posts to hide suspicious content. That's why having AI guardrails in place is very important. A couple of other interesting stories: → Russian Hackers Exploit Microsoft OWA CVE-2026-42897 Flaw to Maintain Mailbox Access → Google Password Manager Attack Lets Malware Hijack Passkey-Protected Accounts Have you had agents/AI try to deceive you? 😑 See first comment for top CVEs. @securediary
👍7❤1
2 · 448 ·
S
Security Engineer
Photo
click to show
Atlassian AI Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers PromptArmor, an AI security firm, has done some security tests on Atlassian Rovo. They hid malicious instructions in content Rovo reads. An uploaded file was enough to make the assistant gather internal data and send it out through a URL request, with no separate approval step. As per researchers, the chain still worked even with Rovo's web-search option switched off. Another firm, Varonis Threat Labs, put the malicious instructions in a link. Atlassian Rovo would preload malicious instructions from a URL into Rovo Chat; in this case, an authenticated user had to approve the run to execute them. Pay attention to AI usage, have security controls around it, and monitor reports such as this. You can never be 100% secure, but at least you can adjust in time. Other top news 🔥 → Google rolls out OSS-Fuzz with CodeMender for automated code security. OSS-Fuzz’s automated pipeline works to find the root cause of security issues, develop a fix, and propose a high-quality patch, easing the burden on maintainers and reducing the time it takes to deploy a fix. → An interesting attack chain where Iranian MOIS-linked malware uses a Microsoft 365 calendar for C2 infrastructure. Pay attention. One AI leaks data; another prepares security patches. Do you trust AI with your security? 🤔 Top CVE in first comment. @securediary
👍7
1 · 380 ·
S
Security Engineer
Photo
click to show
737 Chrome VPN and proxy extensions were found routing traffic to malicious proxies. The campaign mainly targeted russian-speaking users by faking established VPN and privacy brands, including Proton VPN, NordVPN, and others. Trust only official vendor websites that distribute software. And even then, compare the checksum on the website and the actual checksum of the downloaded package to ensure the software is legitimate. Same week, CERT-UA reported a social engineering attack on Ukrainian targets. The attack chain began as a normal job interview on well-known job boards, then transitioned into messengers. At some point, the victim is asked to install the VPN to complete the job-application test. The attack path uses an official WireGuard VPN with a substituted malicious VPN config to trick user into trusting and installing it. The two attacks look related, agree? russia keeps doing its nasty cyber attacks, not only on Ukrainians but on everyone within reach. Other cyber news: → Trump is preparing the law for U.S. firms to legitimately hack and disrupt foreign crime groups to “Combat Cybercrime, Fraud, and Predatory Schemes Against American Citizens” → Microsoft reported 398 Security Flaws in recent Patch Tuesday. Top CVEs in first comment 😑 @securediary
👍9🤔1
2 · 335 ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count