Groups
Groups
Sign in
Groups
Groups
Technical - Application Security
Conversations
About
Send feedback
Help
Group path
Technical - Application Security
Contact owners and managers
1–30 of 4866
Mark all as read
Report group
0 selected
Eyal Estrin
12:50 AM
91 Spring CVEs Highlight the Growing AI Vulnerability Consumption Problem
https://www.sonatype.com/blog/91-spring-cves-highlight-the-growing-ai-vulnerability-consumption-
unread,
91 Spring CVEs Highlight the Growing AI Vulnerability Consumption Problem
https://www.sonatype.com/blog/91-spring-cves-highlight-the-growing-ai-vulnerability-consumption-
12:50 AM
Eyal Estrin
Aug 24
AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting
https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Eyal Estrin Author |
unread,
AliExpress webpage keeping multipoint Bluetooth headphones active with WebAudio fingerprinting
https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Eyal Estrin Author |
Aug 24
Eyal Estrin
Aug 22
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
https://www.endorlabs.com/learn/ghsa-864f-rcv7-6rh4-critical-type-confusion-vulnerability-in-isolated
unread,
GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm
https://www.endorlabs.com/learn/ghsa-864f-rcv7-6rh4-critical-type-confusion-vulnerability-in-isolated
Aug 22
Eyal Estrin
Aug 22
The AI-Era Software Assembly Line
https://www.sonatype.com/hubfs/1-2025_Website-Assets/resource_files/Whitepaper-AI_Era/AI-Era-
unread,
The AI-Era Software Assembly Line
https://www.sonatype.com/hubfs/1-2025_Website-Assets/resource_files/Whitepaper-AI_Era/AI-Era-
Aug 22
Eyal Estrin
Aug 22
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/redc2-ai-powered-linux
unread,
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/redc2-ai-powered-linux
Aug 22
Eyal Estrin
Aug 22
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-
unread,
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-
Aug 22
Eyal Estrin
Aug 21
Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments
https://www.usenix.org/system/files/usenixsecurity26-anwar.pdf Eyal Estrin Author | Cloud Architect |
unread,
Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments
https://www.usenix.org/system/files/usenixsecurity26-anwar.pdf Eyal Estrin Author | Cloud Architect |
Aug 21
Eyal Estrin
Aug 21
CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks
https://arxiv.org/html/2607.26589v1 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks
https://arxiv.org/html/2607.26589v1 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Aug 21
Eyal Estrin
Aug 21
Analyzing Stripe Vendors Breach: Confirmed Vendor Exposure and Claims of 20,000 Compromised APIs
https://www.infostealers.com/article/analyzing-stripe-breach-confirmed-vendor-exposure-and-claims-of-
unread,
Analyzing Stripe Vendors Breach: Confirmed Vendor Exposure and Claims of 20,000 Compromised APIs
https://www.infostealers.com/article/analyzing-stripe-breach-confirmed-vendor-exposure-and-claims-of-
Aug 21
Eyal Estrin
Aug 21
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-
unread,
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-
Aug 21
Eyal Estrin
Aug 20
The “City-Forum” Campaign - An advanced attacker is targeting Salesforce and ServiceNow instances worldwide
https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow Eyal Estrin Author | Cloud
unread,
The “City-Forum” Campaign - An advanced attacker is targeting Salesforce and ServiceNow instances worldwide
https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow Eyal Estrin Author | Cloud
Aug 20
Eyal Estrin
Aug 20
Hacking SAML with Claude Code
https://oblique.security/blog/hacking-saml/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP
unread,
Hacking SAML with Claude Code
https://oblique.security/blog/hacking-saml/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP
Aug 20
Eyal Estrin
Aug 18
Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials
https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-
unread,
Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials
https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-
Aug 18
Eyal Estrin
Aug 14
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-
unread,
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-
Aug 14
Eyal Estrin
Aug 14
Anti-Vibe Vibe Coding: Why AI Agents Need the SDLC
https://www.cybrsecmedia.com/anti-vibe-vibe-coding-why-ai-agents-need-the-sdlc/ Eyal Estrin Author |
unread,
Anti-Vibe Vibe Coding: Why AI Agents Need the SDLC
https://www.cybrsecmedia.com/anti-vibe-vibe-coding-why-ai-agents-need-the-sdlc/ Eyal Estrin Author |
Aug 14
Eyal Estrin
Aug 13
AI Sidebar Extension Monetizes Its Own Updates
https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates Eyal Estrin Author |
unread,
AI Sidebar Extension Monetizes Its Own Updates
https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates Eyal Estrin Author |
Aug 13
Eyal Estrin
Aug 13
2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines Eyal Estrin
unread,
2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines Eyal Estrin
Aug 13
Eyal Estrin
Aug 13
CopyEscape: Taking Over Docker Hosts with docker cp (CVE-2026-17106)
https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp/ Eyal Estrin Author |
unread,
CopyEscape: Taking Over Docker Hosts with docker cp (CVE-2026-17106)
https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp/ Eyal Estrin Author |
Aug 13
Eyal Estrin
Aug 12
Chrome adopts what may be the best protection yet against account takeovers
https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-
unread,
Chrome adopts what may be the best protection yet against account takeovers
https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-
Aug 12
Eyal Estrin
Aug 9
Three AI Coding Agents, One GitHub Issue: CI/CD Secrets Exposed
https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/08/
unread,
Three AI Coding Agents, One GitHub Issue: CI/CD Secrets Exposed
https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/08/
Aug 9
Eyal Estrin
Aug 8
I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository
https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-
unread,
I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository
https://www.pillar.security/blog/ill-just-call-you-agent-to-agent-privilege-boundary-failures-in-ci-
Aug 8
Eyal Estrin
Aug 8
Atlassian Rovo Exfiltrates Data, Bypassing Controls
https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data Eyal Estrin Author | Cloud
unread,
Atlassian Rovo Exfiltrates Data, Bypassing Controls
https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data Eyal Estrin Author | Cloud
Aug 8
Eyal Estrin
Aug 8
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows
https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf Eyal Estrin Author | Cloud Architect
unread,
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows
https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf Eyal Estrin Author | Cloud Architect
Aug 8
Eyal Estrin
Aug 8
Can AI do novel security research? Meet the HTTP Terminator
https://portswigger.net/research/can-ai-do-novel-security-research Eyal Estrin Author | Cloud
unread,
Can AI do novel security research? Meet the HTTP Terminator
https://portswigger.net/research/can-ai-do-novel-security-research Eyal Estrin Author | Cloud
Aug 8
Eyal Estrin
Aug 8
CSS:the bomb inside your inbox
https://portswigger.net/research/css-the-bomb-inside-your-inbox Eyal Estrin Author | Cloud Architect
unread,
CSS:the bomb inside your inbox
https://portswigger.net/research/css-the-bomb-inside-your-inbox Eyal Estrin Author | Cloud Architect
Aug 8
Eyal Estrin
Aug 6
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
https://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/ Eyal Estrin Author |
unread,
The Software Supply Chain Is Under Siege. Devs Are Still the First Line of Defense
https://www.docker.com/blog/software-supply-chain-security-omdia-2026-report/ Eyal Estrin Author |
Aug 6
Eyal Estrin
Aug 6
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-
unread,
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-
Aug 6
Eyal Estrin
Aug 6
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-
unread,
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-
Aug 6
Eyal Estrin
Aug 6
OVSwrap: another Linux local root vulnerability
https://heyitsas.im/posts/ovswrap/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
OVSwrap: another Linux local root vulnerability
https://heyitsas.im/posts/ovswrap/ Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Aug 6
Eyal Estrin
Aug 6
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
https://blog.gitguardian.com/n8n-security-encryption-key-compromise/ Eyal Estrin Author | Cloud
unread,
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
https://blog.gitguardian.com/n8n-security-encryption-key-compromise/ Eyal Estrin Author | Cloud
Aug 6