Groups
Groups
Sign in
Groups
Groups
Technical - Application Security
Conversations
About
Send feedback
Help
Group path
Technical - Application Security
Contact owners and managers
1–30 of 4905
Mark all as read
Report group
0 selected
Eyal Estrin
12:42 AM
SAML: A fractal of bad design
https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/ Eyal Estrin Author | Cloud
unread,
SAML: A fractal of bad design
https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/ Eyal Estrin Author | Cloud
12:42 AM
Eyal Estrin
12:42 AM
MFA Won't Save You From OAuth Consent Abuse
https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse Eyal Estrin Author |
unread,
MFA Won't Save You From OAuth Consent Abuse
https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse Eyal Estrin Author |
12:42 AM
Eyal Estrin
Sep 21
Cache key injection: Smuggling poison through the door
https://www.yeswehack.com/lab/research-cache-key-injection Eyal Estrin Author | Cloud Architect | AWS
unread,
Cache key injection: Smuggling poison through the door
https://www.yeswehack.com/lab/research-cache-key-injection Eyal Estrin Author | Cloud Architect | AWS
Sep 21
Eyal Estrin
Sep 20
TanStack Supply Chain Attack Analysis
https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis Eyal Estrin Author | Cloud
unread,
TanStack Supply Chain Attack Analysis
https://www.crowdsec.net/blog/tanstack-supply-chain-attack-analysis Eyal Estrin Author | Cloud
Sep 20
Eyal Estrin
Sep 19
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
https://heyitsas.im/posts/lpe-quartet/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP
unread,
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
https://heyitsas.im/posts/lpe-quartet/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP
Sep 19
Eyal Estrin
Sep 19
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
https://www.air.security/blog-posts/plugin4shell Eyal Estrin Author | Cloud Architect | AWS • Azure •
unread,
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
https://www.air.security/blog-posts/plugin4shell Eyal Estrin Author | Cloud Architect | AWS • Azure •
Sep 19
Eyal Estrin
Sep 18
When Apps Outlive Vendors: Security Implications of IoT Abandonware
https://arxiv.org/pdf/2609.14798 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
When Apps Outlive Vendors: Security Implications of IoT Abandonware
https://arxiv.org/pdf/2609.14798 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Sep 18
Eyal Estrin
Sep 17
Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit
https://www.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit Eyal
unread,
Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit
https://www.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit Eyal
Sep 17
Eyal Estrin
Sep 17
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution (CVE-2026-89026)
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html https://www.vulncheck.com/
unread,
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution (CVE-2026-89026)
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html https://www.vulncheck.com/
Sep 17
Eyal Estrin
Sep 17
BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants
https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants Eyal Estrin
unread,
BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants
https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants Eyal Estrin
Sep 17
Eyal Estrin
Sep 15
Cloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364)
https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-
unread,
Cloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364)
https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-
Sep 15
Eyal Estrin
Sep 15
A Peripheral Path to SYSTEM - Exploiting Logi Options+ for SYSTEM Shells
https://blog.amberwolf.com/blog/2026/september/a-peripheral-path-to-system---exploiting-logi-options%
unread,
A Peripheral Path to SYSTEM - Exploiting Logi Options+ for SYSTEM Shells
https://blog.amberwolf.com/blog/2026/september/a-peripheral-path-to-system---exploiting-logi-options%
Sep 15
Eyal Estrin
Sep 15
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
https://socket.dev/blog/malicious-twitch-browser-extension Eyal Estrin Author | Cloud Architect | AWS
unread,
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
https://socket.dev/blog/malicious-twitch-browser-extension Eyal Estrin Author | Cloud Architect | AWS
Sep 15
Eyal Estrin
Sep 15
DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes
https://ddropattack.eu/ddrop.pdf Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
DDRop: Active Memory Interposer Attacks on Confidential VMs by Dropping DDR5 Writes
https://ddropattack.eu/ddrop.pdf Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Sep 15
Eyal Estrin
Sep 15
The Ghost in the Chat: how a bot that isn't in your group steals messages from Telegram HTML exports
https://expatch.com/writeups/telegram-html-export-xss.html Eyal Estrin Author | Cloud Architect | AWS
unread,
The Ghost in the Chat: how a bot that isn't in your group steals messages from Telegram HTML exports
https://expatch.com/writeups/telegram-html-export-xss.html Eyal Estrin Author | Cloud Architect | AWS
Sep 15
Eyal Estrin
Sep 12
Stolen AI Session Tokens Are Bypassing MFA
https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/
unread,
Stolen AI Session Tokens Are Bypassing MFA
https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/
Sep 12
Eyal Estrin
Sep 12
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf Eyal Estrin Author |
unread,
Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf Eyal Estrin Author |
Sep 12
Eyal Estrin
Sep 12
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
unread,
Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
https://www.wiz.io/blog/off-guard-breaking-litellm-from-authentication-bypass-to-cloud-compromise
Sep 12
Eyal Estrin
Sep 12
Stop Writing Pentest Reports By Hand — Create Custom AI Prompts in OWASP Faction 2.0
https://blog.factionsecurity.com/blog/stop-writing-pentest-reports-by-hand-create-custom-ai-prompts-
unread,
Stop Writing Pentest Reports By Hand — Create Custom AI Prompts in OWASP Faction 2.0
https://blog.factionsecurity.com/blog/stop-writing-pentest-reports-by-hand-create-custom-ai-prompts-
Sep 12
Eyal Estrin
Sep 12
Web Shell Detection and Investigation
https://www.prophetsecurity.ai/blog/web-shell-detection Eyal Estrin Author | Cloud Architect | AWS •
unread,
Web Shell Detection and Investigation
https://www.prophetsecurity.ai/blog/web-shell-detection Eyal Estrin Author | Cloud Architect | AWS •
Sep 12
Eyal Estrin
Sep 12
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-
unread,
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-
Sep 12
Eyal Estrin
Sep 10
Shai-Hulud Rises From the Dead after 111 days
https://www.aikido.dev/blog/shai-hulud-npm-resurfaces Eyal Estrin Author | Cloud Architect | AWS •
unread,
Shai-Hulud Rises From the Dead after 111 days
https://www.aikido.dev/blog/shai-hulud-npm-resurfaces Eyal Estrin Author | Cloud Architect | AWS •
Sep 10
Eyal Estrin
Sep 10
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html Eyal Estrin Author | Cloud
unread,
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html Eyal Estrin Author | Cloud
Sep 10
Eyal Estrin
Sep 10
CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox
https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape/ Eyal Estrin
unread,
CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox
https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape/ Eyal Estrin
Sep 10
Eyal Estrin
Sep 9
When “Auto-Signing” Sends Your Wallet: A Malicious MCP Server on npm
https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-
unread,
When “Auto-Signing” Sends Your Wallet: A Malicious MCP Server on npm
https://www.knostic.ai/blog/when-auto-signing-sends-your-wallet-private-key-to-a-remote-server-a-
Sep 9
Eyal Estrin
Sep 5
GitSpawn: Malicious Git Configs Hijack AI Coding Agents
https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/
unread,
GitSpawn: Malicious Git Configs Hijack AI Coding Agents
https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/
Sep 5
Eyal Estrin
Sep 5
Critical Langflow flaw exploited to steal OpenAI and AWS keys
https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-
unread,
Critical Langflow flaw exploited to steal OpenAI and AWS keys
https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-
Sep 5
Eyal Estrin
Sep 5
Enterprise AI is quietly undoing a decade of credential hygiene
https://www.scworld.com/perspective/enterprise-ai-is-quietly-undoing-a-decade-of-credential-hygiene
unread,
Enterprise AI is quietly undoing a decade of credential hygiene
https://www.scworld.com/perspective/enterprise-ai-is-quietly-undoing-a-decade-of-credential-hygiene
Sep 5
Eyal Estrin
Sep 5
Malicious Packages Served from Unauthorized Registry Server
https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65 Eyal Estrin Author | Cloud
unread,
Malicious Packages Served from Unauthorized Registry Server
https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65 Eyal Estrin Author | Cloud
Sep 5
Eyal Estrin
Sep 3
Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
https://cybersecuritynews.com/crowdstrike-falcon-0-day/ https://github.com/MSNightmare/FalconFlank
unread,
Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
https://cybersecuritynews.com/crowdstrike-falcon-0-day/ https://github.com/MSNightmare/FalconFlank
Sep 3