Aggregator
☠️ picoCTF 2024 — “Bookmarklet” Web Exploitation Challenge
Authorization Bypass: The Simple SSO Mistake
Authorization Bypass: The Simple SSO Mistake
The Emoji That Broke the AI (into 27 Pieces)
Tooling via Browser Automation
Tooling via Browser Automation
Terrier Cyber Quest 2025 — Brief Write-up
Terrier Cyber Quest 2025 — Brief Write-up
“The Registration Flaw That Almost Got Missed: Hunting Weak Authentication Links”
“The Registration Flaw That Almost Got Missed: Hunting Weak Authentication Links”
c0c0n CTF 2025 Writeup
Delinea releases free open-source MCP server to secure AI agents
AI agents are becoming more common in the workplace, but giving them access to sensitive systems can be risky. Credentials often get stored in plain text, added to prompts, or passed around without proper oversight. Delinea wants to fix that problem with its new open source Model Context Protocol (MCP) Server. How the Delinea MCP Server works The MCP Server connects AI agents to the Delinea Platform, allowing them to securely retrieve and use credentials. … More →
The post Delinea releases free open-source MCP server to secure AI agents appeared first on Help Net Security.
HackornCTF 2025 Quals
Date: Sept. 25, 2025, midnight — 25 Sept. 2025, 23:59 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.secpen.org/
Rating weight: 0
Event organizers: Hackorn
ZDI-CAN-27394: IceWarp
The $40,000-an-Hour Outage That Changed How We Think About AI
New Phishing Attack Targeting PyPI Maintainers to Steal Login Credentials
A sophisticated phishing campaign has emerged targeting maintainers of packages on the Python Package Index (PyPI), employing domain confusion tactics to steal authentication credentials from unsuspecting developers. The attack leverages fraudulent emails designed to mimic official PyPI communications, directing recipients to malicious domains that closely resemble the legitimate PyPI infrastructure. The phishing operation utilizes carefully […]
The post New Phishing Attack Targeting PyPI Maintainers to Steal Login Credentials appeared first on Cyber Security News.