What the Black Hat NOC Taught Me About MCP & Agentic SOCs (Chapter 3 of 4)
The first time an MCP (Model Context Protocol) server felt real to me, it wasn’t because of a clean demo. It was because of the noise.
The first time an MCP (Model Context Protocol) server felt real to me, it wasn’t because of a clean demo. It was because of the noise.
Introduction June 2026 marked a significant escalation in hostile internet activity observed by honeynet sensors, with overall attack volume increasing by 55.5% month over month after three consecutive months of…
TL;DR HashJack is a newly discovered indirect prompt injection technique that conceals malicious instructions after the # in legitimate URLs. When AI browsers send the full URL (including the fragment)…
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within…
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and…
The F5 Labs Weekly Threat Bulletin The F5 Labs Weekly Threat Bulletin is a weekly report designed to be your earliest warning system, condensing the overwhelming threat landscape into a…
Executive Summary On July 14, 2026, attackers compromised release processes connected to the AsyncAPI open- source project and published malicious versions of four widely used npm packages with a combined…
Active Exploitation of CVE-2025-55182 Critical RCE in React Server Components and Next.js CVE-2025-55182 represents a critical pre-authentication Remote Code Execution (RCE) vulnerability, rated with a CVSS score of 10.0, affecting…
On November 18, 2025, a single configuration file change at Cloudflare disrupted access to large parts of the web. Around 11:20 UTC, Cloudflare’s network began returning a surge of HTTP…
TAMECAT PowerShell Backdoor Targets Edge and Chrome: Login Credentials at Risk TAMECAT is a sophisticated PowerShell-based backdoor attributed to APT42, an Iranian state-sponsored hacking group, designed to steal login credentials…