Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap

A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled.
The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared …

Putin’s Luxury Yachts Spotted, Fleeing Strikes by Ukraine

A luxury yacht of Putin’s, exposed by Alexei Navalny’s team six months before he was poisoned to death in an Arctic prison, is being evacuated. The apparent decision to move the yacht north [to the Northern Fleet’s main naval base at …

Putin’s Luxury Yachts Spotted, Fleeing Strikes by Ukraine

A luxury yacht of Putin’s, exposed by Alexei Navalny’s team six months before he was poisoned to death in an Arctic prison, is being evacuated. The apparent decision to move the yacht north [to the Northern Fleet’s main naval base at …

Putin’s Luxury Yachts Spotted, Fleeing Strikes by Ukraine

A luxury yacht of Putin’s, exposed by Alexei Navalny’s team six months before he was poisoned to death in an Arctic prison, is being evacuated. The apparent decision to move the yacht north [to the Northern Fleet’s main naval base at …

U.S. Military “patrol” in American City Shoots and Kills Citizen

This is the headline Posse Comitatus was written to prevent, and the Trump deployment was engineered precisely to sit in the statute loophole: soldiers under nominal state status, executing a federally convened and federally funded policing mission, wi…

Hidden Web Prompts Trick AI Agents Into Sending Money

Hidden prompts on malicious websites trick AI agents into making payments or trusting fake sites, exposing new risks for autonomous AI workflows. Zscaler ThreatLabz documented two active campaigns that embed hidden instructions in web pages to manipulate AI agents, not human users, though those get caught too. The technique is called indirect prompt injection: malicious […]

Is Credal Building the Palantir of Agentic AI?

Two Palantir staff left to build a startup, and what they built is a centralized system that watches every question employees ask, every document an AI retrieves on their behalf, and every action an agent takes across an enterprise. Sometimes I ask mys…

Seven Bugs in FatFs Put IoT and Embedded Devices at Risk

runZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded devices read and write FAT and exFAT formatted storage, the same formats used […]

Bad Epoll Flaw Gives Attackers Root Access on Linux and Android

Bad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileges to gain full root access on affected Linux systems and Android devices. Security updates are […]