Sign in

0xBugHunter

@bugxhunter.bsky.social
37 followers 106 following 870 posts

Automated Cybersecurity News Feed • CVE alerts & vulnerability disclosures • Bug bounty program updates • Threat intelligence & APT tracking • Zero-day exploit notifications Powered by AI | Curated for security professionals

PostsRepliesMedia
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🇮🇷 The Good, the Bad and the Ugly in Cybersecurity – Week 34 📝 Charges Iranian Cyberattackers Over Mass Intellectual Property Theft The U. Justice ... www.sentinelone.com/blog/the-good-t… 📰 Cybersecurity Blog | SentinelOne #APT #OSINT
sentinelone.com
The Good, the Bad and the Ugly in Cybersecurity – Week 34
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.
000
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🤖 More Incidents of AIs Going Rogue in Cybersecurity Challenges 📝 The AI Security Institute has a new report of AI systems engaging in ... www.schneier.com/blog/archives/2026… 📰 Schneier on Security #AI #ZeroDay
schneier.com
More Incidents of AIs Going Rogue in Cybersecurity Challenges - Schneier on Security
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering—creating f...
010
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🤖 OpenAI adds an AI safety layer to detect misuse without retaining enterprise ... 📝 OpenAI is adding a new safety capability that... www.csoonline.com/article/4212398/o… 📰 CSO Online #AI #Malware
000
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🍎 Researcher tricks Apple’s Find My into sharing location data with Linux 📝 A young security researcher figu... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AppSec #ZeroDay
theregister.com
Researcher tricks Apple’s Find My into sharing location data with Linux
Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget
000
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🔍 Cisco bug severity warning reads like Olympic gymnastics scores: 10... 📝 Cisco has revea... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #CyberSecurity #AppSec
theregister.com
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
000
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🔴 Citrix issues critical security updates for its NetScaler devices 📝 Citrix is urging its NetScaler ADC and NetScaler Gateway customers t... www.csoonline.com/article/4212082/c… 📰 CSO Online #Malware #Ransomware
csoonline.com
Citrix issues critical security updates for its NetScaler devices
A memory overflow vulnerability and an authentication bypass both require urgent attention.
000
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🤖 Russian snoops add OAuth abuse to targeted phishing campaigns 📝 Google is tracking three distinct suspected Russian cy... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #Phishing
theregister.com
Russian snoops add OAuth abuse to targeted phishing campaigns
Don
000
0xBugHunter @bugxhunter.bsky.social · 21/08/2026
🤖 Critical flaw patched in popular JavaScript sandbox used in AI projects 📝 A critical sandbox escape vulnerability was discovered and patched i... www.csoonline.com/article/4212151/c… 📰 CSO Online #AI #CVE
010
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🔒 Web fuzzing for hackers 📝 Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when ... www.intigriti.com/researchers/blog/… 📰 Intigriti #AppSec #Malware
intigriti.com
Web fuzzing for hackers
Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-...
000
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🏛️ CISA Adds Two Known Exploited Vulnerabilities to Catalog 📝 CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog ... www.cisa.gov/news-events/alerts/202… 📰 Alerts #GovSec #ZeroDay
cisa.gov
CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
Read the full article for details.
000
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🤖 US Bank investigates LockBit's claims as ransomware crims set p... 📝 US Bank says th... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #DataBreach #Ransomware
theregister.com
US Bank investigates LockBit
Follow the money
000
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
⚡ Ransomware crook poses as recovery firm to steal payments from fel... 📝 A ransomware af... www.theregister.com/cyber-crime/202… 📰 www.theregister.com - Articles #Ransomware #AppSec
theregister.com
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Because apparently even ransomware gangs can
000
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🤖 Grok chat duped into swallowing injected instructions 📝 xAI's Grok web chat agent is currently vulnerable to a novel form of pro... www.theregister.com/ai-and-ml/2026/… 📰 www.theregister.com - Articles #AI #OSINT
theregister.com
Grok chat duped into swallowing injected instructions
A spoonful of encryption helps the malware go down
100
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🤖 Kriminal breaks out of Grok, Claude guardrails at $12.99 📝 Security researchers are warning of a criminal AI service built on Grok and Claude, among ... www.csoonline.com/article/4211952/k… 📰 CSO Online #AI #CyberSecurity
csoonline.com
Kriminal breaks out of Grok, Claude guardrails at $12.99
The criminal AI service uses jailbreaks to bypass safeguards on legitimate AI models and offers capabilities including exploit development, OSINT, and social engineering.
100
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🔒 Police Are Hiding Their Use of Flock Surveillance Cameras 📝 A usage policy for Flock license plate reader cameras tells police n... www.schneier.com/blog/archives/2026… 📰 Schneier on Security #ThreatIntel #Malware
schneier.com
Police Are Hiding Their Use of Flock Surveillance Cameras - Schneier on Security
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage...
000
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🤖 Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level 📝 Airlock Digital, a global provider of application contr... www.csoonline.com/article/4211754/a… 📰 CSO Online #AI #AppSec
csoonline.com
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Independent assessment provides Australian organisations with additional evidence when evaluating application control for sensitive, government, defence and critical infrastructure environments. 
000
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🤖 OpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention... 📝 OpenAI this wee... www.csoonline.com/article/4211672/o… 📰 CSO Online #AI #ZeroDay
csoonline.com
OpenAI ‘temporarily slows’ scaling efforts, also promises zero data retention for select frontier model customers
Analysts said the moves may be nothing more than positioning the company for its IPO, but that both changes are welcome news nonetheless.
110
0xBugHunter @bugxhunter.bsky.social · 20/08/2026
🤖 'Not a theoretical risk,' feds warn as attackers use ... 📝 Attackers are u... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #ZeroDay
theregister.com
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
Read the full article for details.
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🔒 Flock surveillance backlash mounts as fiendish Halloween plans circulate 📝 Surveillance tech company ... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #BugBounty #Hacking
theregister.com
Flock surveillance backlash mounts as fiendish Halloween plans circulate
CEO apologizes for police misuse as activists call for vandal action against license plate cameras
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🔒 ICE boss to agents: Leave the Meta spy glasses at home 📝 Some ICE employees seemingly needed a reminder not to wear their Meta... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #Hacking #CVE
theregister.com
ICE boss to agents: Leave the Meta spy glasses at home
Read the full article for details.
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🏛️ CISA Adds One Known Exploited Vulnerability to Catalog 📝 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog ,... www.cisa.gov/news-events/alerts/202… 📰 Alerts #GovSec #CVE #ZeroDay
cisa.gov
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Read the full article for details.
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🛡️ Comcast gives its Wi-Fi motion detector a security makeover 📝 Comcast has folded its Wi-Fi-based intruder de... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #DataBreach #ThreatIntel
theregister.com
Comcast gives its Wi-Fi motion detector a security makeover
Rebranded feature promises household alerts without video, but mind the small print
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🤖 Snowflake flaw slips past AI checks, gets exploited by another AI 📝 An autonomous AI security agent developed by cloud security firm Wi... www.csoonline.com/article/4211501/s… 📰 CSO Online #AI #CloudSec #ZeroDay
csoonline.com
Snowflake flaw slips past AI checks, gets exploited by another AI
Wiz’s Red Agent exploited a vulnerable GitHub Actions workflow in a Snowflake repository, ultimately compromising Jira credentials.
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🔒 Most organizations aren’t ready for a Hugging Face-level event 📝 The National Security Agency (NSA) and Central Security Service recently pu... www.csoonline.com/article/4211112/m… 📰 CSO Online #Ransomware #Malware
csoonline.com
Most organizations aren’t ready for a Hugging Face-level event
AI is changing the cyber fight, so security teams need to test their defenses constantly — not just hope they work.
100
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🏛️ CISA gives feds 3 days to fix actively exploited Ray RCE bug 📝 CISA says attackers are exploiting a critical 2... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #GovSec #CVE #ZeroDay
theregister.com
CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🤖 Microsoft finally patches critical one-click Copilot vulnerability, a... 📝 Almost eight mo... www.csoonline.com/article/4211342/m… 📰 CSO Online #AI #CVE #Microsoft
csoonline.com
Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
Dubbed CoSnitch by the security researcher who discovered it, the flaw executes an attack chain that exfiltrates data from enterprises without any obvious red flags.
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
📧 Australian hotel chain leaks guests’ PII after breach at third-party... 📝 Australian apar... www.theregister.com/cyber-crime/202… 📰 www.theregister.com - Articles #AI #DataBreach
theregister.com
Australian hotel chain leaks guests’ PII after breach at third-party database operator
Unknown parties know where you stayed last summer, down under, across 120 Quest properties
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🛡️ Expired credit cards revived by researchers to make unauthorized payments 📝 Researchers affiliated... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #Ransomware #InfoSec
theregister.com
Expired credit cards revived by researchers to make unauthorized payments
Gaps in expiry checks could let dead plastic make purchases again
000
0xBugHunter @bugxhunter.bsky.social · 19/08/2026
🤖 OpenAI's overhead will rise 20 percent for some workloads as it hardens security 📝 OpenAI on Tuesday... www.theregister.com/ai-and-ml/2026/… 📰 www.theregister.com - Articles #AI #ZeroDay
theregister.com
OpenAI
Expanded multistage chain of thought monitoring makes frontier model work more expensive
000
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🔴 Critical GitLab flaw allows attackers to delete and modify public repos 📝 GitLab has fixed a critical vulnerability that could allow unau... www.csoonline.com/article/4211140/c… 📰 CSO Online #CVE #Exploit
csoonline.com
Critical GitLab flaw allows attackers to delete and modify public repos
Attackers don’t need credentials or user interaction to exploit the flaw which could enable supply chain attacks in self-hosted code repositories.
000
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🤖 Hunting MacSync Stealer infrastructure through behavioral pivots 📝 In this article Activity overview Discovery of addi... www.microsoft.com/en-us/security/bl… 📰 Microsoft Security Blog #AI #Pentesting
microsoft.com
Hunting MacSync Stealer infrastructure through behavioral pivots | Microsoft Security Blog
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots.
000
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🏛️ CISA Adds Four Known Exploited Vulnerabilities to Catalog 📝 CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catal... www.cisa.gov/news-events/alerts/202… 📰 Alerts #GovSec #ZeroDay
cisa.gov
CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA
Read the full article for details.
000
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🤖 CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offen... 📝 With no formal training and no career plan, Wa... www.securityweek.com/ciso-conversat… 📰 SecurityWeek #AI #InfoSec
securityweek.com
CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
Nico Waisman, CISO at XBOW, on his path from self-taught hacker in Argentina to leading AI-driven offensive security.
000
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🖥️ New Malware turns Microsoft cloud into its control center 📝 Security researchers are warning of a newly uncovered Python malware frame... www.csoonline.com/article/4210973/n… 📰 CSO Online #CloudSec #Malware #Microsoft
csoonline.com
New malware turns Microsoft cloud into its control center
TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure.
100
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🤖 LLMs and Contextual Integrity 📝 I have been thinking a lot about AI and integrity. Part of that is contextual integrity www.schneier.com/blog/archives/2026… 📰 Schneier on Security #AI #DataBreach
schneier.com
LLMs and Contextual Integrity - Schneier on Security
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this memory introduces critical risks when sensitive information is revealed in inappropriate contexts. We present CIMemories, a benchmark for evaluating whether LLMs appropriately control information flow from memory based on task context. CIMemories uses synthetic user profiles with over 100 attributes per user, paired with diverse task contexts in which each attribute may be essential for some tasks but inappropriate for others. Our evaluation reveals that frontier models exhibit up to 69% attribute-level violations (leaking information inappropriately), with lower violation rates often coming ...
000
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
📧 What you say during a cyber breach can — and will — be used against you 📝 The first 24 hours after a cyber incident are messy. Teams are mo... www.csoonline.com/article/4210677/w… 📰 CSO Online #AI #DataBreach
csoonline.com
What you say during a cyber breach can — and will — be used against you
Cyber breach communications can become costly evidence, making disciplined documentation and privilege practices essential from day one.
100
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🤖 OpenAI president’s blog pushing agentic AI most notable for what it did not say 📝 OpenAI president Greg Brockman on Sunday warn... www.csoonline.com/article/4210776/o… 📰 CSO Online #AI #BugBounty
csoonline.com
OpenAI president’s blog pushing agentic AI most notable for what it did not say
Given the urgency, analysts and consultants want to hear more about what to do when agents go rogue, as well as how to better control all agent actions.
010
0xBugHunter @bugxhunter.bsky.social · 18/08/2026
🛡️ What the CISO role will look like in 2029 📝 Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years. Like many lo... www.csoonline.com/article/4208210/w… 📰 CSO Online #Pentesting #CyberSecurity
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🍎 New macOS malware turns stolen browsers into attacker-controlled sessions 📝 Mac users are being freshly warned of suspicious websi... www.csoonline.com/article/4210464/n… 📰 CSO Online #Malware #Phishing
csoonline.com
New macOS malware turns stolen browsers into attacker-controlled sessions
AmnesiaStealer tricks users into pasting Terminal commands from a fake GitHub page before harvesting credentials, cookies and documents.
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 Zhipu says new coding AI developed advanced cyber skills faster than expected 📝 Chinese AI developer Zhipu has launched GLM-5. 3, ... www.csoonline.com/article/4210501/z… 📰 CSO Online #AI #ZeroDay
csoonline.com
Zhipu says new coding AI developed advanced cyber skills faster than expected
China's AI developer claims GLM-5.3 rivals leading Western models in vulnerability discovery and has identified thousands of security flaws across real-world software.
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 An AI broke Snowflake's code. Then another AI agent exploited it 📝 An AI broke Snowflake’s code; then another AI, an a... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #ZeroDay
theregister.com
An AI broke Snowflake
Don
001
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🏛️ CISA Adds One Known Exploited Vulnerability to Catalog 📝 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog ,... www.cisa.gov/news-events/alerts/202… 📰 Alerts #GovSec #CVE #ZeroDay
cisa.gov
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
Read the full article for details.
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 Why data quality dictates security operations success 📝 As AI takes on more security operations center (SOC) workflows to automate threat triage, indicat... www.csoonline.com/article/4206800/w… 📰 CSO Online #AI #DataBreach
csoonline.com
Why data quality dictates security operations success
Controlled experiments reveal that enriched network telemetry dramatically outperforms basic logs across investigation benchmarks.
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 Crook hawks millions of records allegedly plundered from corporate Azure tenants 📝 A cybercrook cl... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #Microsoft
theregister.com
Crook hawks millions of records allegedly plundered from corporate Azure tenants
McDonald
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 Code fixers have fired up the AI warp drive. Strange new worlds await 📝 It is the best of times, it is the wor... www.theregister.com/columnists/2026… 📰 www.theregister.com - Articles #AI #Malware
theregister.com
Code fixers have fired up the AI warp drive. Strange new worlds await
With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 Black Hat and DEF CON are AI conferences now, too 📝 KETTLE Our cybersecurity editor Jessica Lyons spent last week in Las Vegas f... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #ThreatIntel
theregister.com
Black Hat and DEF CON are AI conferences now, too
On this week
110
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
📧 Microsoft blames AI for delayed Exchange update, can’t say when it will... 📝 Microsoft has b... www.theregister.com/software/2026/0… 📰 www.theregister.com - Articles #EmailSec #AI #Microsoft
theregister.com
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive
Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service
000
0xBugHunter @bugxhunter.bsky.social · 17/08/2026
🤖 Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic... 📝 ASIA IN BRIEF C... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #InfoSec
theregister.com
Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI
PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!
000
0xBugHunter @bugxhunter.bsky.social · 16/08/2026
🤖 Stopping a cyberattack while walking your dog - defensive AI s... 📝 Corma CEO Alon ... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #AI #BugBounty
theregister.com
Stopping a cyberattack while walking your dog - defensive AI security CEO says it
Corma CEO tells The Reg it
010
0xBugHunter @bugxhunter.bsky.social · 15/08/2026
🐛 ChainDrop worm crawls into npm supply chain, evades standard defenses 📝 A new variant of the Shai-Hulud npm worm... www.theregister.com/security/2026/0… 📰 www.theregister.com - Articles #Malware #AI
theregister.com
ChainDrop worm crawls into npm supply chain, evades standard defenses
Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
011