Создатели известной программы экстренно закрывают опасную брешь.
1 час назад @ securitylab.ru
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
The weird part isn't that it works.
The weird part is how damn easy it still is.
Most breaches still start with trust abuse, stale configs, lazy access controls, or users getting socially engineered by someone sounding vaguely competent over the phone.
Stop assuming signed software, MFA prompts, or "internal-only" tooling means safe.
Might be time defenders stop pretending those shortcuts don't exist.
6 часов назад @ thehackernews.com