01▲From Prevention to Resilience: Reducing What Attackers Can Reach in a Zero-Trust World securityreviewmag.com What if zero trust meant shrinking the blast radius, with passwordless, VMI, CBOMs, and a staged PQC migration?cloud-securitycryptographypasswordless-authenticationpqcprivacytwitterzero-trust5 pts/jonasdunn/3 days ago/1 comment
02▲[tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked? tldrsec.com Security newsletter issue on AI vuln hunting, GuardDog 3.0, bug bounty economics, and assorted supply-chain/RAT/jailbreak bits.ai-securitybug-bountycloud-securitydetection-engineeringlinkedinmacosmalwareprompt-injectionsupply-chainvulnerability-huntingwindows1 pt/iimai/3 days ago/1 comment
03▲LUKSbox github.com Post-quantum keyslots, because passphrases were too mainstream: a Rust encrypted-container tool that mounts real drives on 3 OSes.cloud-securitycontainersencryptionfido2filesystemlatticepqcruststoragetpmtwitter1 pt/nullptr99/4 days ago/discuss
04▲[tl;dr sec] #335 - Prompt Injection as Role Confusion, PHP Ecosystem Security, New MCP Spec tldrsec.com Prompt injection, apparently, is role confusion, in a newsletter that also hits PHP hardening and the new MCP spec.ai-securityblockchaincloud-securitycryptanalysisecosystem-securitylinkedinllm-securitymcpprivacyprompt-injectionsupply-chain2 pts/anyaw/9 days ago/discuss
05▲FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials securityaffairs.com Even the FBI says TeamPCP turned dev tools into a credential vacuum for cloud keys, SSH, and K8s secrets.ci-cdcloud-securitycredential-theftdevsecopsgithub-actionskubernetesmalwarenpmpypisecretssupply-chaintwitter3 pts/dan/10 days ago/1 comment
06▲Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform moltenbit.net Audit of OpenReception, an E2EE appointment booking app, with 16 CVEs and the usual tenant-isolation comedy.access-controlauthenticationauthorizationcloud-securitycryptanalysise2eeprivacytwitterwebauthn0 pts/deadlock7/14 days ago/5 comments
07▲How the ToddyCat APT group gains access to Gmail accounts securelist.com How do you steal Gmail without the password? By abusing Chromium remote debugging and OAuth code theft via Umbrij.access-token-manipulationaptbrowser-securitychromiumcloud-securitydll-sideloadingedremail-securitygmailoauththreat-huntingtwitter0 pts/hbrown/14 days ago/1 comment
08▲[tl;dr sec] #334 - Thinkst's Package Proxy, OpenAI Daybreak, AI Agents & Canaries tldrsec.com Security roundup: package proxies, AI-agent canary benchmarks, and OpenAI's Daybreak/Codex updates, plus the usual cloud mess.agentsai-securityappsecblue-teamcanariescloud-securitylinkedinsupply-chain0 pts/pavelk/16 days ago/2 comments
09▲VivaTech 2026: AI Agents, Post-Quantum Cyber Resilience & The New Frontier Of Enterprise Security + Video undercodetesting.com Post-quantum migration is the easy part; the real mess is keeping AI agents from leaking data and swallowing deepfakes.agentic-aiai-securitycloud-securityconfidential-computingcrypto-agilitydeepfake-detectionpost-quantumpqcprivacyprompt-injectionsoartwitter0 pts/nullptr7/19 days ago/1 comment
10▲End-to-end encrypted ML inference with Amazon SageMaker AI and FHE aws.amazon.com AWS shows FHE inference on SageMaker with Concrete-ML, so the cloud can now host ciphertext and call it a feature.awscloud-securityencrypted-inferencefhelinkedinmachine-learningprivacysagemaker0 pts/evanm/20 days ago/1 comment
11▲[tl;dr sec] #332 - I've Joined OpenAI, fwd:cloudsec, AWS Well Architected Supply Chain Security tldrsec.com What did tl;dr sec #332 pick out this week? OpenAI hire, AWS supply-chain advice, OIDC/Lambda abuse, and AI threat notes.ai-securityappsecawscloud-securitygithub-actionsidentitylambdalinkedinllmoidcsecretsstatic-analysissupply-chainthreat-intelligence0 pts/max/29 days ago/3 comments