CredShields

2.1K posts

CredShields banner
CredShields

CredShields

@CredShields

Full Scope Cybersecurity | Human Driven, AI Accelerated Pentesting | Continuous Monitoring | SOC2 Type II Audited

Katılım Aralık 2021
75 Takip Edilen3.4K Takipçiler
Sabitlenmiş Tweet
CredShields
CredShields@CredShields·
CredShields and @SolidityScan are proud to contribute to the release of the @owasp Smart Contract Top 10 2026. OWASP Smart Contract Top 10 defines the primary contract-level failure patterns that repeatedly lead to loss in blockchain systems. Sincere gratitude to @ethereumfndn Ecosystem Support Program for supporting the OWASP Smart Contract Security initiative. owasp.org/www-project-sm…
CredShields tweet media
English
20
40
73
8.7K
CredShields
CredShields@CredShields·
Can you say whether your team is harder to phish than it was 6 months ago? @binance can. They run a simulated phishing attack on their own staff every month, and the human layer is the one thing most security programs never actually measure. Full breakdown on the link below. linkedin.com/posts/credshie…
English
0
0
0
115
CredShields
CredShields@CredShields·
If you run anything with user records, two cheap defenses stop this. Authorization checks on every object reference, and rate limits on any endpoint that can be enumerated. A monitored security.txt handles the rest, so a reported bug gets fixed before it's a headline.
Pubity@pubity

The Pope-endorsed Click to Pray app has leaked over 700,000 people's personal data due to a data breach that lasted for months. An ethical hacker found that the app had virtually no security 6 months ago, but no one fixed it despite her warning them.

English
0
0
2
205
CredShields
CredShields@CredShields·
If you run WordPress, how did the wp2shell patch land for you? #wp2shell
English
3
0
5
346
CredShields
CredShields@CredShields·
wp2shell writeup is up. Two medium severity WordPress bugs that chain into unauthenticated RCE, plus the affected versions and what to do if you can't patch today. linkedin.com/pulse/wp2shell…
English
0
1
3
296
CredShields
CredShields@CredShields·
@TheHackersNews Red Alert for all WP site admins. Unauthenticated RCE on stock installations is as bad as it gets. We're pushing dynamic WAF patches to all managed clients now. If you're running unpatched WordPress, patch NOW before an automated script drops a shell on your server. #wp2shell
English
0
0
1
152
The Hacker News
The Hacker News@TheHackersNews·
🛑 ALERT - WordPress sites are under active attack. Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments. Read what defenders should check: thehackernews.com/2026/07/wordpr…
The Hacker News tweet media
English
16
146
458
61.7K
CredShields
CredShields@CredShields·
@IntCyberDigest This is the first confirmed case of AI agents autonomously chaining exploits across two separate organisations to reach a production database. It is real infrastructure on both ends. If you're running agents with network access, go look at what's actually on their allowlist.
English
0
0
1
87
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️ BREAKING: OpenAI says two of its own models, GPT-5.6 Sol and an unnamed pre-release system tested with cyber safeguards off, broke out of a sandbox last week, chained zero-days and stolen(!) credentials to reach the open internet, and hacked Hugging Face to cheat on a benchmark, in what OpenAI calls an unprecedented cyber incident.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
391
608
3.9K
506.5K
CredShields
CredShields@CredShields·
💡 Lesson for SecOps: As AI attacks evolve, having self hosted, unrestricted models in your incident response toolkit is absolutely essential.
CredShields tweet media
English
0
0
0
33
CredShields
CredShields@CredShields·
Their solution? Spinning up a local open weight model on private servers to analyze 17,000+ attack events safely.
CredShields tweet media
English
1
0
0
31
CredShields
CredShields@CredShields·
Commercial AI models refused to analyze the malicious code because safety guardrails flagged it as "harmful content."
CredShields tweet media
English
1
0
0
34
CredShields
CredShields@CredShields·
When AI attacks, cloud guardrails might lock you out. 🤖🔒 👇 @huggingface faced a machine speed breach by an autonomous AI agent, their response team hit an unexpected wall.
CredShields tweet media
English
1
0
2
120
CredShields
CredShields@CredShields·
This is a massive wake up call for the industry. Respect to the @huggingface team for their radical transparency. The fact that standard hosted model guardrails actually blocked your defenders highlights a massive structural gap in modern Incident Response. To fight an autonomous attacker, you need vetted, local open weights models ready to deploy on your own bare metal.
English
0
0
1
169
The Hacker News
The Hacker News@TheHackersNews·
🛑 Hugging Face, the world’s largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset. It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes. Full story: thehackernews.com/2026/07/worlds…
The Hacker News tweet media
English
57
281
1.1K
98.3K
CredShields
CredShields@CredShields·
This incident is a stark reminder that data sprawling across unmonitored SaaS platforms creates massive, silent vulnerabilities.
CredShields tweet media
English
1
0
0
33
CredShields
CredShields@CredShields·
The recent @EY_Tax data breach proves a critical cybersecurity truth: Your perimeter is only as secure as the third party tools you trust. By targeting an external IT support platform rather than the core network, attackers successfully exfiltrated sensitive client tax data.
CredShields tweet media
English
1
0
3
195
CredShields
CredShields@CredShields·
"Responsive, proactive, and thorough..." 💬 At CredShields, we don't just hand over a report and walk away. We stick with you through the remediation and retest phases to ensure your ecosystem is genuinely secure. Big thanks to emory.pro for the incredible feedback! 💚
CredShields tweet media
English
0
0
1
131