BioCatch Digital Banking Fraud Trends in the United States 2025

The 2025 BioCatch report analyzes digital banking fraud trends in the U.S., highlighting the rise of stablecoins as a favored method for laundering scam proceeds and an increase in bot-driven fraud. Key focus areas include behavioral analytics to detect bots and the evolving scam landscape featuring impersonation, investment scams, and money mule activity. #BioCatch #Stablecoins #MoneyMules

Read More
Prompt Injection to RCE in AI Agents

Two AI agents with pre-approved commands can still be exploited via argument injection, enabling remote code execution (RCE) despite human approval. The post outlines antipatterns, real-world attack examples across three platforms, and practical defenses like sandboxing and argument separation.
#argumentinjection #RCE #sandboxing #GTFOBINS #LOLBINS…

Read More
Very Vulnerable Management API Writeup

I summarize the article about the Very Vulnerable Management API (VVMA), detailing the intentionally introduced OWASP Top 10 API security risks and specific vulnerabilities found across registration, login, password reset, group and user management, and token handling. The piece highlights weaknesses such as weak password policies, email enumeration, JWT issues, no…

Read More
Diffing 7-Zip for CVE-2025-11001

Two ZDI-disclosed bugs (CVE-2025-11001, CVE-2025-11002) affect 7-Zip’s Linux-to-Windows symlink handling, enabling potential directory manipulation during extraction. The issues involve unsafe path checks and symlink processing that could allow writing files to arbitrary locations, with a fixed patch in v25.00.
#CVE-2025-11001 #CVE-2025-11002…

Read More
BioCatch Digital Banking Fraud Trends in the United States 2025

The 2025 SpyCloud Identity Threat Report highlights the escalating risks of identity-based cyberattacks fueled by phishing, ransomware, and AI-driven tactics, revealing significant defense gaps in organizations worldwide. It emphasizes the critical need for automated identity remediation, operational maturity, and AI integration to effectively combat evolving threats like LummaC2, FlowerStormPHAAS, and Darcula. #LummaC2 #FlowerStormPHAAS #Darcula

Read More
Governing AI Agents: From Enterprise Risk to Strategic Asset

The article discusses the rapid adoption of AI agents in enterprises and the urgent need for robust governance to manage security risks. It emphasizes clear ownership, automatic discovery, and centralized guardrails to prevent ungoverned agents from creating vulnerabilities, and highlights the strategic role of identity governance in securing AI agents.
#MattFangman #AIagents #IdentityGovernance #SailPoint #Microsoft

Read More