Groups
Groups
Sign in
Groups
Groups
Technical - Application Security
Conversations
About
Send feedback
Help
Group path
Technical - Application Security
Contact owners and managers
1–30 of 4819
Mark all as read
Report group
0 selected
Eyal Estrin
Jul 23
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/ Eyal Estrin Author | Cloud Architect
unread,
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/ Eyal Estrin Author | Cloud Architect
Jul 23
Eyal Estrin
Jul 23
When Your AI Reviewer Works for the Attacker: A Confused-Deputy Bug in Microsoft's Azure DevOps MCP Server
https://www.manifold.security/blog/azure-devops-mcp-server-vulnerability Eyal Estrin Author | Cloud
unread,
When Your AI Reviewer Works for the Attacker: A Confused-Deputy Bug in Microsoft's Azure DevOps MCP Server
https://www.manifold.security/blog/azure-devops-mcp-server-vulnerability Eyal Estrin Author | Cloud
Jul 23
Eyal Estrin
Jul 21
Smashing the ServiceNow Sandbox – Pre Authentication RCE
https://slcyber.io/research-center/smashing-the-servicenow-sandbox-pre-authentication-rce/ Eyal
unread,
Smashing the ServiceNow Sandbox – Pre Authentication RCE
https://slcyber.io/research-center/smashing-the-servicenow-sandbox-pre-authentication-rce/ Eyal
Jul 21
Eyal Estrin
Jul 18
The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem
https://arxiv.org/pdf/2607.06141 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
The Masks We (Think We) Wear: Privacy Threats of Browser-Extension Wallets in the Web3 Ecosystem
https://arxiv.org/pdf/2607.06141 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Jul 18
Eyal Estrin
Jul 18
New North Korean campaign uses fake coding interviews to steal developer credentials
https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography Eyal Estrin
unread,
New North Korean campaign uses fake coding interviews to steal developer credentials
https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography Eyal Estrin
Jul 18
Eyal Estrin
Jul 18
Prismata: Confining Cross-Site Prompt Injection in Web Agents
https://arxiv.org/pdf/2607.08147 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
Prismata: Confining Cross-Site Prompt Injection in Web Agents
https://arxiv.org/pdf/2607.08147 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Jul 18
Eyal Estrin
Jul 18
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to-rce.html Eyal Estrin Author | Cloud
unread,
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to-rce.html Eyal Estrin Author | Cloud
Jul 18
Eyal Estrin
Jul 18
wp2shell: Pre Authentication RCE in WordPress Core
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core Eyal Estrin
unread,
wp2shell: Pre Authentication RCE in WordPress Core
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core Eyal Estrin
Jul 18
Eyal Estrin
Jul 16
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-
unread,
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-
Jul 16
Eyal Estrin
Jul 15
Malicious GitHub Campaign: Fake "Arctic Wolf" and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer
https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer
unread,
Malicious GitHub Campaign: Fake "Arctic Wolf" and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer
https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer
Jul 15
Eyal Estrin
Jul 15
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left Eyal
unread,
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left Eyal
Jul 15
Eyal Estrin
Jul 15
ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail
https://www.manifold.security/blog/claude-for-chrome-extension-bypass Eyal Estrin Author | Cloud
unread,
ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail
https://www.manifold.security/blog/claude-for-chrome-extension-bypass Eyal Estrin Author | Cloud
Jul 15
Eyal Estrin
Jul 14
Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension
https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-
unread,
Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension
https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-
Jul 14
Eyal Estrin
Jul 14
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators
https://blog.lexfo.fr/opendir-to-phishing-operator.html Eyal Estrin Author | Cloud Architect | AWS •
unread,
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators
https://blog.lexfo.fr/opendir-to-phishing-operator.html Eyal Estrin Author | Cloud Architect | AWS •
Jul 14
Eyal Estrin
Jul 12
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html https://medium.com/@
unread,
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html https://medium.com/@
Jul 12
Eyal Estrin
Jul 12
Unfit to Boot: Breaking U-Boot's FIT Signature Verification
https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification https://docs.u-
unread,
Unfit to Boot: Breaking U-Boot's FIT Signature Verification
https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification https://docs.u-
Jul 12
Eyal Estrin
Jul 11
Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution
https://ainowinstitute.org/publications/friendly-fire-exploit-brief Eyal Estrin Author | Cloud
unread,
Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution
https://ainowinstitute.org/publications/friendly-fire-exploit-brief Eyal Estrin Author | Cloud
Jul 11
Eyal Estrin
Jul 11
npm install-time security and GAT bypass2fa deprecation
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
unread,
npm install-time security and GAT bypass2fa deprecation
https://github.blog/changelog/2026-07-08-npm-install-time-security-and-gat-bypass2fa-deprecation/
Jul 11
Eyal Estrin
Jul 11
Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed
https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/ Eyal Estrin Author | Cloud Architect |
unread,
Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed
https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/ Eyal Estrin Author | Cloud Architect |
Jul 11
Eyal Estrin
Jul 11
Coordinated GitHub API enumeration and access token abuse
https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/ Eyal Estrin Author |
unread,
Coordinated GitHub API enumeration and access token abuse
https://securitylabs.datadoghq.com/articles/coordinated-github-api-enumeration/ Eyal Estrin Author |
Jul 11
Eyal Estrin
Jul 11
Open Source Is Not One Thing: A Typology of Open-Source Software Sub-Genres
https://arxiv.org/pdf/2607.01750 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
unread,
Open Source Is Not One Thing: A Typology of Open-Source Software Sub-Genres
https://arxiv.org/pdf/2607.01750 Eyal Estrin Author | Cloud Architect | AWS • Azure • GCP Insights
Jul 11
Eyal Estrin
Jul 11
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/
unread,
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/
Jul 11
Eyal Estrin
Jul 4
Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL
https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-
unread,
Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL
https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-
Jul 4
Eyal Estrin
Jul 4
Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations
https://labs.zenity.io/p/bring-your-own-agent-hijacking-exposed-ai-backends-to-power-offensive-
unread,
Bring Your Own Agent: Hijacking Exposed AI Backends to Power Offensive Operations
https://labs.zenity.io/p/bring-your-own-agent-hijacking-exposed-ai-backends-to-power-offensive-
Jul 4
Eyal Estrin
Jul 4
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ Eyal Estrin Author |
unread,
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ Eyal Estrin Author |
Jul 4
Eyal Estrin
Jul 2
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/ Eyal Estrin Author |
unread,
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/ Eyal Estrin Author |
Jul 2
Eyal Estrin
Jul 2
The Most Dangerous Code in Your Stack Is Code You Never Wrote
https://awards.thehackernews.com/blog/the-danger-in-your-dependencies/ Eyal Estrin Author | Cloud
unread,
The Most Dangerous Code in Your Stack Is Code You Never Wrote
https://awards.thehackernews.com/blog/the-danger-in-your-dependencies/ Eyal Estrin Author | Cloud
Jul 2
Eyal Estrin
Jul 2
Nissan staff hacked via Oracle zero-day bug
https://solcyber.com/nissan-staff-hacked-via-oracle-zero-day-bug/ Eyal Estrin Author | Cloud
unread,
Nissan staff hacked via Oracle zero-day bug
https://solcyber.com/nissan-staff-hacked-via-oracle-zero-day-bug/ Eyal Estrin Author | Cloud
Jul 2
Eyal Estrin
Jul 1
Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI
https://checkmarx.com/zero-post/operation-navy-ghost-pyrogram-telegram-supplychain-attack/ Eyal
unread,
Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI
https://checkmarx.com/zero-post/operation-navy-ghost-pyrogram-telegram-supplychain-attack/ Eyal
Jul 1
Eyal Estrin
Jun 30
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/ Eyal Estrin Author | Cloud
unread,
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/ Eyal Estrin Author | Cloud
Jun 30