pnut
1.7K posts

pnut
@torrell
Founder @overspacehq | solving cyber resilience | cardiac cats @panthers

🚨Citrix NetScaler CVE-2026-3055 is being actively exploited in the wild Attackers send crafted SAMLRequest payloads to /saml/login omitting the AssertionConsumerServiceURL field, triggering the appliance to leak memory contents via the NSC_TASS cookie. Our honeypot data shows exploitation activity from the same payload structure as the @watchtowrcyber PoC. Track exploitation of our Citrix honeypots 👉 console.defusedcyber.com/capabilities


🚨 Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data Attackers can smuggle SQL statements through the "Site"-header inside an HTTP request According to Shodan, close to 1000 instances of Forticlient EMS are publicly exposed. Track exploitation of this and other Fortinet honeypots 👉 console.defusedcyber.com/capabilities


Engineering job openings are at the highest levels we’ve seen in over 3 years There are over 67,000 (!!!) eng openings at tech companies globally right now, with 26,000 just in the U.S. We don’t know if there would have been more open roles if not for AI or if AI is actually leading to more open roles, but since the start of this year, the increase in open eng roles is accelerating even more.


Okay let's see who can reply to this

You can now enable Claude to use your computer to complete tasks. It opens your apps, navigates your browser, fills in spreadsheets—anything you'd do sitting at your desk. Research preview in Claude Cowork and Claude Code, macOS only.

Token mining malware will replace crypto mining malware.

I want to make /init more useful- what do you think it should do to help setup Claude Code in a repo?




A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…







