Joined June 2010
837 Photos and videos
This Tenet Security report is wild. Because AI agents blindly trust data pulled through Model Context Protocol (MCP) servers, a spoofed Sentry crash report can trick your IDE into running hacker commands. If you trust AI tools blindly, your local machine is wide open.
⚠️ New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hacker's Server Source: cybersecuritynews.com/agentj… New “Agentjacking” attack that hijacks AI coding agents and silently executes attacker-controlled code on developer machines using nothing more than a single injected Sentry error. The technique turns trusted AI assistants like Claude Code and Cursor into an execution layer for malicious commands, without phishing, malware delivery, or any breach of the victim’s infrastructure. In this attack, the entry point is Sentry’s public Data Source Name (DSN). This write-only credential is routinely embedded in frontend JavaScript and indexed across the web. #cybersecuritynews
35
A brutal lesson in trust. Threat intel teams and researchers treat government portals as gospel, but when anyone can script a fake submission using a fictional employee name, automated tracking breaks down. Time to start verifying the source of the source.
⚠️ Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings | Source: cybersecuritynews.com/maine-… The Office of the Maine Attorney General has temporarily taken its public-facing data breach reporting database offline after discovering that an unknown entity submitted fabricated breach notifications targeting two major online platforms, VRChat and Discord, in what officials are calling a deliberate abuse of the state's breach disclosure system. On June 12, 2026, the Maine Attorney General's office issued a formal statement confirming that the reported data breaches involving VRChat and Discord were hoaxes. The false filings were submitted by an unidentified third party with no affiliation to either company. #cybersecuritynews
16
Secure Zona is a Unified Security Posture Management platform for cloud, SaaS, data, vendor, product, and AI risk. It brings CSPM, SSPM, DSPM, GenAI security, agent inventory, MCP findings, browser controls, compliance, and reporting into one workflow. securezona.com
21
It is getting a lot harder to monitor your environment for malware these days with all the threats out there. One employee making a mistake is enough to bring down the company! #infosec #phishing
Holy cow Unlimited AI usage!!!! Just run GPT_Claude_Free.exe as admin
1
131
Microsoft's June 2026 Secure Boot certificate expiration proves how hidden infrastructure drift leaves devices vulnerable to boot-level exploits. SecureZona fixes configuration gaps by Continuous security posture & drift monitoring #infosec #spm #cybersec
30
AI is moving faster than most security teams can track. At Secure Zona, we’re building AI security posture management for GenAI, agentic AI inventory, custom GPT/agent findings, and MCP server security. Visibility, risk context, and practical remediation for modern AI environment
40
1.59 million URLs generated by a single network using LLMs to build fake landing pages. This is why standard threat feeds can't keep up anymore, when AI can mass-produce convincing replicas of any trusted brand on demand, defensive strategies have to evolve.
🛑 Google says a Chinese cybercrime network turned Gemini into a phishing helper. The service, called Outsider, was tied to: > 1.59M fraudulent URLs > 9,000 fake websites > 100,000 victims > $88/week phishing kits sold on Telegram Read: thehackernews.com/2026/06/go…
2
89
The critical SAP Commerce Cloud vulnerability (CVE-2026-22732) shows how a simple Spring Security misconfiguration lets attackers bypass authentication completely. SecureZona fixes hardening gaps: Continuous cloud asset discovery Priorities config drift in unified risk queues
69
This is the reality of the new world with AI. We are going to see a lot more bugs and vulnerabilities, hence relying only on patch management won’t work. #aisecurity #security #infosec
💰 Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty Source: cybersecuritynews.com/google… A security researcher known as brutecat has disclosed how an AI-driven fuzzing pipeline uncovered more than $500,000 in vulnerabilities across Google's infrastructure in under three months, exposing systemic access-control failures hidden inside roughly 1,500 APIs. The researcher began by targeting Google's discovery documents machine-readable API specifications, similar to Swagger docs, that list all available endpoints, parameters, and methods. While these documents are publicly available for APIs like the YouTube Data API, many exist for internal Google APIs and require valid API keys to access. #cybersecuritynews
42
Anthropic pulling their top models globally over an export control mandate proves how fragile the current AI supply chain really is. Relying strictly on public cloud models introduces massive business continuity risks. Time to seriously rethink centralized AI governance. #aisec
🛡️ Anthropic Fable 5 & Mythos 5 Access Blocked to All Users Following Government Directive Source: cybersecuritynews.com/anthro… Anthropic has disabled its two most capable AI models, Fable 5 and Mythos 5, after the U.S. government issued an export control directive late on June 12 ordering the company to block access for any foreign national, whether inside or outside the United States, including Anthropic's own foreign-national employees. Because the company says it cannot reliably separate foreign users from the rest of its base in real time, the practical result is a worldwide shutoff of both models. All other Anthropic models remain online. The US government, citing national security authorities, delivered the directive to Anthropic at 5:21 PM ET on Friday, June 12, 2026. #cybersecuritynews
67
An out-of-band Oracle patch landing straight onto CISA’s KEV catalog shows just how bad this PeopleTools flaw is. Leaving this unpatched gives an unauthenticated attacker absolute control over your core business data. Don't wait for your next maintenance cycle.
🛡️ We added Oracle PeopleSoft Enterprise PeopleTools missing authentication for critical function vulnerability CVE-2026-35273 to our KEV Catalog. Visit go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec
79
At Secure Zona, we build an inventory of your AI agents, identify the risky ones, discover all their details and let your security team to review and approve/reject it. #aisecurity #securezona #agenticai
Chatbots talk. AI agents act. That shift changes security. If attackers hide commands in data an agent reads, it may run them using trusted tools. We mapped how award-winning cybersecurity solutions are helping teams detect, control, and reduce AI agent risks. Read: awards.thehackernews.com/blo…
48
CISA's urgent 3-day mandate for Ivanti CVE-2026-10520 shows how fast edge bugs expose downstream networks. SecureZona stops the drift: Continuous discovery of all cloud assets Flags identity & config drift in unified risk queues #InfoSec #SecureZona
63
Brilliant and brutal attack chain. Forcing an AI framework's persistence layer to run OS commands just by querying conversation history proves that "AI security" is really just infrastructure security. Time to audit those self-hosted Redis/SQLite deployments.
⚠️ A poisoned checkpoint could become a server takeover. LangGraph flaws can chain SQL injection with unsafe deserialization to achieve remote code execution. Three bugs are patched. Self-hosted SQLite or Redis checkpointer deployments face the key risk. Read: thehackernews.com/2026/06/la…
1
44
When a single vendor configuration tweak can expose your entire IT support log and asset database to the internet, point-in-time audits are useless. True resilience requires live, automated posture verification across every third-party platform you trust.
⚠️ ServiceNow Confirms Flaw Allowing Unauthorized Access to Customer Instance Tables Source: cybersecuritynews.com/servic… ServiceNow has confirmed a security vulnerability that could allow unauthorized actors to query customer instance tables, raising concerns about potential data exposure across enterprise environments. The issue, disclosed through threat intelligence channels, involves improper access controls that may enable attackers to execute queries against backend instance tables without proper authentication. ServiceNow, widely used for IT service management (ITSM) and enterprise workflows, hosts sensitive operational and business data, making such vulnerabilities particularly critical. #cybersecuritynews
30
The recent ServiceNow incident proves how dangerous a single unauthenticated API endpoint can be. Threat actors successfully queried internal customer tables without needing a login. SecureZona stops the drift by continuous posture monitoring and identifying risks. #InfoSec
57
CISA adding a BerriAI LiteLLM flaw to its active exploit list shows that threat actors are aggressively targeting shadow AI proxies and developer integrations. SecureZona eliminates the visibility gap by Continuous Posture Monitoring #InfoSec
29
Global Canvas platform breach (8,800 institutions) underscores the risk of unmonitored cloud sprawl.Attackers bypass perimeters by targeting shadow SaaS connections and over-privileged integrations. SecureZona fixes the drift by Continuous Security Posture Monitoring #InfoSec
1
102
Attackers don't try to crack passwords anymore. They steal valid session tokens and OAuth grants to walk right past MFA and firewalls into your SaaS environment. SecureZona shuts down the blind spots #InfoSec
1
62
OpenAI’s new ChatGPT Lockdown Mode proves that the real threat with enterprise AI isn't just data access—it’s unauthorized data exfiltration via connected tools.  SecureZona shuts down these SaaS integration blind spots #aisecurity #genai #cybersec
62