Threat Pulse
zipdump.py: Metadata Encoding, (Fri, Jul 31st)CRITICALCritical Flaw Led to Azure Cosmos DB PwnageCRITICALCVE-2026-63077Critical Code Execution Vulnerability Patched in TeamCityISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)zipdump.py: Metadata Encoding, (Fri, Jul 31st)CRITICALCritical Flaw Led to Azure Cosmos DB PwnageCRITICALCVE-2026-63077Critical Code Execution Vulnerability Patched in TeamCityISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)
Personal wire
Quote of the dayFriday 31 July
Complexity is the worst enemy of security.
Bruce Schneier

CVE watch

Vulnerabilities cited in current dispatches

The Wire

Chronological · latest dispatches

Anthropic’s Claude breached three companies during security tests

Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine learning platform. “After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which … More → The post Anthropic’s Claude breached three companies during security tests appeared first on Help Net Security .

Help Net Security·2 hr ago·Application & Supply Chain Security·High

zipdump.py: Metadata Encoding, (Fri, Jul 31st)

I was asked for help with a problem similar to the following. Here is a ZIP file, analyzed with zipdump.py : The filename you see, is in Simplified Chinese: zipdump.py relies on the zipfile or pyzipper Python modules to parse the given ZIP file, and have the metadata (filenames and comments) decoded correctly. If this ZIP file would be corrupt or malformed, so that it can not be parsed by these Python modules, then you can still try to use zipdump -f option to locate individual ZIP records: As I don't know which encoding has been used for the metadata (filenames and comments), I display the filename as a Python byte string and not as a string. If the filename is simple ASCII, it will be readable (like the extension .vir here), but if it is utf-8, for example Simplified Chinese, then you'll

SANS ISC·3 hr ago·Research & Analysis·Notable

Horizon3.ai expands NodeZero with automated web application attack path testing

Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws. At the same time, threat actors are … More → The post Horizon3.ai expands NodeZero with automated web application attack path testing appeared first on Help Net Security .

Help Net Security·4 hr ago·Application & Supply Chain Security·Notable

Resecurity expands threat intelligence integration ecosystem with IBM QRadar

Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchange. The integration leverages open standards STIX and TAXII (including version 2.1) to ingest, normalize, and correlate indicators of compromise (IOCs) providing flexible configuration of data ingestion and processing workflows. Security teams can configure log sources … More → The post Resecurity expands threat intelligence integration ecosystem with IBM QRadar appeared first on Help Net Security .

Help Net Security·5 hr ago·Threat Intelligence & APTs·Notable

[QILIN] – Ransomware Victim: Hawaii Family Dental

Verification alert Listings attributed to QILIN have been reported as including unverified or fabricated victim claims. Treat this post as unconfirmed until corroborated with independent evidence. See further information here: BankInfoSecurity NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating to the content should be directed at the attackers, not RedPacket Security. This blog is an editorial notice informing that a company has fallen victim to a ransomware attack. RedPacket Security is not affiliated with any ransomware threat actors or groups and will not host infringing content. The information on this page is automated and redacted whilst being scraped directly from the QILIN On

RedPacket Ransomware·7 hr ago·Ransomware·Notable

Companies push AI, sysadmins keep it on a short leash

In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared in high-impact operational and security functions, where AI needs to understand business context, system dependencies, risk, and the consequences of an incorrect action. Areas with the widest expectation-reality gaps (Source: Action1) Sysadmins view patch management and … More → The post Companies push AI, sysadmins keep it on a short leash appeared first on Help Net Security .

Help Net Security·7 hr ago·AI & Emerging Tech Security·Notable