CTM360 Exposes Global GovTrap Campaign With 11,000+ Fake Government Portals Targeting Citizens Worldwide

Government impersonation scams have evolved into a large, highly coordinated global fraud ecosystem that exploits public trust in official institutions. CTM360’s GovTrap research shows attackers replicate entire government service environments across thousands of disposable domains and use multi-channel distribution to harvest credentials and payment data #GovTrap #CTM360

Read More
Blue Teaming Active Directory: EVENmonitor

EVENmonitor streams Domain Controller Security logs in real time and decodes Windows events to reveal Active Directory attacks the moment they occur. This guide maps common AD attack techniques to their definitive Windows Event IDs, provides example commands and distinguishing forensic fields for detecting DCSync, AS‑REP Roasting, password spraying, Pass‑the‑Hash, Kerberoasting, privilege manipulation, and account lifecycle abuse #EVENmonitor #ActiveDirectory

Read More
Privacy & Cybersecurity #68

This briefing summarizes major 2026 developments in cybersecurity and data governance, including ENISA’s new Technology and Innovation Radar methodology, EU–US biometric-sharing talks, multiple state and national AI and privacy laws, and updated guidance from national DPAs and the NCSC. It also highlights a tactical shift in China-linked cyber operations toward large covert networks of compromised devices exemplified by Raptor Train and noted campaigns like Volt Typhoon, raising detection and attribution challenges. #RaptorTrain #VoltTyphoon

Read More
Is Claude Code Secretly Installing Spyware?

Anthropic’s week of incidents shows a recurring pattern: Claude Desktop silently installs a Native Messaging manifest into seven Chromium-based browser profiles, pre-authorizing extension IDs, while the MCP STDIO design and a predictable Mythos URL exposed critical supply-chain and access risks. Though no mass data exfiltration has been proven, the pre-positioned bridge and protocol design enable downstream prompt-injection and remote command execution scenarios that security researchers call a dangerous dark pattern and an architectural flaw. #ClaudeDesktop #ModelContextProtocol

Read More
GPO Abuse: Exploiting Vulnerable Group Policy Objects

This article demonstrates a full GPO-abuse attack chain in the ignite.local lab where a low-privilege user with delegated edit rights on a domain-linked GPO is used to push malicious scheduled tasks and scripts to reach the Domain Controller. Using BloodHound to discover writable GPOs and tools like pyGPOAbuse, SharpGPOAbuse, and StandIn, the attacker creates persistent local administrators and interactive reverse shells, while defenders are advised to treat GPO write access as Tier 0 and monitor SYSVOL/LDAP for tampering. #pyGPOAbuse #SharpGPOAbuse

Read More
Token-Level AI Security: The Opus 4.7 Tokenizer Graveyard

Anthropic’s Claude Opus 4.7 introduced a new tokenizer that increased token counts by roughly 1.0–1.35× (and higher in the wild), changing how inputs are sliced and triggering pricing and compatibility concerns. The change also creates fresh untrained “glitch” tokens and a widened attack surface for token-level filter bypasses, special-token smuggling, and classifier desyncs, with no comprehensive sweep of the new vocabulary yet. #ClaudeOpus4.7 #SolidGoldMagikarp

Read More
TCP 129: Vercel Breach, Mythos Leak, the SIEM arms race, and 3 Defender 0 days

Darwin Salazar’s The Cybersecurity Pulse covers this week’s major security events, including the Vercel OAuth-based compromise that led to Lumma Stealer token abuse, Anthropic Mythos access allegations, Lovable’s BOLA exposure, and three Microsoft Defender zero-days. It also highlights acquisitions and AI security startup launches, offers practical detection guidance for OpenAI Enterprise audit logs, and promotes webinars and events for security operators. #Vercel #LummaStealer

Read More
Privacy Vulnerability in Firefox and TOR Browsers

Security firm Fingerprint discovered a vulnerability in Firefox that allowed websites to track users by exploiting uniquely ordered retrieval of non-sensitive database metadata, enabling fingerprinting even in private browsing and the Tor browser. Mozilla patched the issue in Firefox 150 on April 21, 2026 after Fingerprint’s responsible disclosure, and researchers warn similar entropy-related flaws may surface as new AI models like Anthropic’s Claude Mythos emerge. #Firefox150 #Fingerprint

Read More
Bypassing WDAC and AppLocker Using Ligolo

This article demonstrates how attackers bypass AppLocker and Windows Defender Application Control (WDAC) by abusing trusted binaries, living-off-the-land techniques, in-memory payloads, and tunneling tools such as Ligolo-NG. It outlines preparing Ligolo and a reflective loader, converting payloads to shellcode with Donut, hosting artifacts, and executing them via trusted binaries (InstallUtil, MSBuild) or PowerShell memory injection to establish a Ligolo reverse TLS tunnel and bypass Constrained Language Mode. #AppLocker #WDAC #LigoloNG #MSBuild

Read More
AWS CloudGoat EC2 SSRF Exploitation

This article walks through a CloudGoat ec2_ssrf lab that demonstrates how an attacker can exploit a Server-Side Request Forgery (SSRF) in an EC2-hosted web application to access the AWS Instance Metadata Service and steal IAM credentials. The step-by-step walkthrough covers lab setup, enumeration of Lambda, EC2, and S3, credential pivoting to escalate privileges, and recommendations such as enforcing IMDSv2 and least-privilege IAM to mitigate the risk. #CloudGoat #SSRF

Read More
Why Your Backups Might Not Save You When Ransomware Hits

Most organizations believe backups and DR plans make them resilient, but ransomware actors routinely target and compromise backup systems so recovery often fails when it matters most. True resilience requires immutable, isolated backups, integrated security and recovery automation, and routine testing to ensure fast, reliable restoration under attack conditions. #Acronis #ActiveDirectory

Read More
Ethical Bug Bounty Field Guide for AI Systems

Anthropic released Claude Opus 4.7 with Mythos-derived cyber guardrails, including deliberate training suppression of cyber capabilities and an inference-time classifier that auto-blocks high-risk prompts, creating a new alignment layer and fresh attack surface. The write-up maps five jailbreak families, the mature tooling bounty hunters use (PyRIT, Garak, Promptfoo), and the red team mindset needed to convert classifier close-calls into reproducible bounties. #Anthropic #ClaudeOpus4.7

Read More
Why Threat Intelligence Is the Missing Link in CTEM Prioritization and Validation

Continuous Threat Exposure Management (CTEM) only delivers real risk reduction when structured threat intelligence is used to prioritize exposures by asset criticality, exploitability, and adversary relevance. Integrating OpenCTI and OpenAEV within Filigran’s XTM enables intelligence-driven prioritization, continuous adversary-aligned validation, and evidence-based remediation to close the gap between knowing about threats and proving you can stop them. #Filigran #OpenCTI

Read More