Visualização normal

Antes de ontemSecurity Boulevard

The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords

28 de Abril de 2026, 09:52

LLMs leave statistical fingerprints in the passwords they generate. We built a 100-year-old model to find them and detected 28,000 in the wild.

The post The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords appeared first on Security Boulevard.

Vercel April 2026 Incident: Non-Sensitive Environment Variables Need Investigation Too

20 de Abril de 2026, 06:23

Vercel's Context.ai breach exposed environment variables that weren't marked sensitive. Learn how to pull and scan your secrets with GitGuardian.

The post Vercel April 2026 Incident: Non-Sensitive Environment Variables Need Investigation Too appeared first on Security Boulevard.

  • ✇Security Boulevard
  • You thought your growth was working. It wasn’t. Antoine Vastel
    You just got a Slack webhook notification. You have 3 new users who created an account on your SaaS: john.doe@aiphotoeditor.io john.mitchell@lovecalculatorname.org tony1987@whitehousecalculator.com It’s great, your latest marketing initiatives are finally working out. In a few days these brand new users The post You thought your growth was working. It wasn’t. appeared first on Security Boulevard.
     

You thought your growth was working. It wasn’t.

15 de Abril de 2026, 07:25

You just got a Slack webhook notification. You have 3 new users who created an account on your SaaS:

It’s great, your latest marketing initiatives are finally working out. In a few days these brand new users

The post You thought your growth was working. It wasn’t. appeared first on Security Boulevard.

Renovate & Dependabot: The New Malware Delivery System

10 de Abril de 2026, 04:38

Recent supply chain attacks stayed live for hours. Automation tools silently merged their malware in minutes. Read how upgrade bots and AI agents became the insider threat.

The post Renovate & Dependabot: The New Malware Delivery System appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Reflecting on Your Tier Model: CVE-2025-33073 and the One-Hop Problem n8n-publisher
    The False Sense of Security SMB signing on domain controllers has become standard practice across most Active Directory environments. But this hardening may have created a false sense of security. CVE-2025-33073 changes the calculus by removing the prerequisite of admin access, enabling NTLM relay attack Active Directory exploitation through unconstrained delegation. Domain controllers enforce SMB […] The post Reflecting on Your Tier Model: CVE-2025-33073 and the One-Hop Problem appeared first o
     

Reflecting on Your Tier Model: CVE-2025-33073 and the One-Hop Problem

27 de Março de 2026, 00:12

The False Sense of Security SMB signing on domain controllers has become standard practice across most Active Directory environments. But this hardening may have created a false sense of security. CVE-2025-33073 changes the calculus by removing the prerequisite of admin access, enabling NTLM relay attack Active Directory exploitation through unconstrained delegation. Domain controllers enforce SMB […]

The post Reflecting on Your Tier Model: CVE-2025-33073 and the One-Hop Problem appeared first on Praetorian.

The post Reflecting on Your Tier Model: CVE-2025-33073 and the One-Hop Problem appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Which Came First: The System Prompt, or the RCE? n8n-publisher
    During a recent penetration test, we came across an AI-powered desktop application that acted as a bridge between Claude (Opus 4.5) and a third-party asset management platform. The idea is simple: instead of clicking through dashboards and making API calls, users just ask the agent to do it for them. “How many open tickets do […] The post Which Came First: The System Prompt, or the RCE? appeared first on Praetorian. The post Which Came First: The System Prompt, or the RCE? appeared first on Secu
     

Which Came First: The System Prompt, or the RCE?

24 de Março de 2026, 23:30

During a recent penetration test, we came across an AI-powered desktop application that acted as a bridge between Claude (Opus 4.5) and a third-party asset management platform. The idea is simple: instead of clicking through dashboards and making API calls, users just ask the agent to do it for them. “How many open tickets do […]

The post Which Came First: The System Prompt, or the RCE? appeared first on Praetorian.

The post Which Came First: The System Prompt, or the RCE? appeared first on Security Boulevard.

  • ✇Security Boulevard
  • The Real State of Offensive Security: AI, Penetration Testing & The Road Ahead with Andrew Wilson Tom Eston
    Tom Eston interviews offensive AI researcher and PhD candidate Andrew Wilson, a former Bishop Fox partner who helped grow the firm from under 20 people to nearly 500, built award-winning AI solutions for SOC modernization, founded Cactus Con, and relocated his family to Guadalajara to open and scale a Bishop Fox office. They discuss Mexico’s […] The post The Real State of Offensive Security: AI, Penetration Testing & The Road Ahead with Andrew Wilson appeared first on Shared Security Podcast
     

The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub

17 de Março de 2026, 08:55

GitGuardian’s 5th State of Secrets Sprawl report is here. In this blog, we unpack the key findings behind the 2026 edition, from AI-driven leak growth to the remediation gaps security teams can’t ignore.

The post The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% and 29M Secrets Hit Public GitHub appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly n8n-publisher
    Everyone knows that one person on the team who’s inexplicably lucky, the one who stumbles upon a random vulnerability seemingly by chance. A few days ago, my coworker Michael Weber was telling me about a friend like this who, on a recent penetration test, pressed the shift key five times at an RDP login screen […] The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly appeared first on Praetorian. The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebA
     

Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly

13 de Março de 2026, 16:01

Everyone knows that one person on the team who’s inexplicably lucky, the one who stumbles upon a random vulnerability seemingly by chance. A few days ago, my coworker Michael Weber was telling me about a friend like this who, on a recent penetration test, pressed the shift key five times at an RDP login screen […]

The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly appeared first on Praetorian.

The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly appeared first on Security Boulevard.

2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk

5 de Março de 2026, 04:12

GitGuardian partnered with Google to answer: what happens when private keys leak? Using Certificate Transparency, we mapped about 1M leaked keys to 140k certificates. Result: 2,622 were valid as of September 2025, exposing major organizations. Our disclosure campaign achieved 97% remediation.

The post 2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk appeared first on Security Boulevard.

  • ✇Security Boulevard
  • The DocuSign Email That Wasn’t – A Three-Redirect Credential Harvest Themis
    TL;DR Attackers sent a convincing DocuSign notification with a "Review & Sign" button that chained through Google Maps redirects to an Amazon S3-hosted credential harvesting page. The redirect chain defeated URL scanners, and real law-firm footers added legitimacy. IRONSCALES Adaptive AI flagged the behavioral mismatch between sender infrastructure and brand identity before the first click. Severity: High Credential Harvesting Brand Impersonation MITRE: T1566.002 MITRE
     

The DocuSign Email That Wasn’t – A Three-Redirect Credential Harvest

Por:Themis
3 de Março de 2026, 21:20
TL;DR Attackers sent a convincing DocuSign notification with a "Review & Sign" button that chained through Google Maps redirects to an Amazon S3-hosted credential harvesting page. The redirect chain defeated URL scanners, and real law-firm footers added legitimacy. IRONSCALES Adaptive AI flagged the behavioral mismatch between sender infrastructure and brand identity before the first click.
Severity: High
Credential Harvesting
Brand Impersonation
MITRE: T1566.002
MITRE: T1598.003

The "Review & Sign" button looked exactly like every DocuSign notification you've ever received. Same blue branding, same layout, same urgency. But the button didn't point to DocuSign. It pointed to Google Maps > then to Amazon S3 > then to a credential harvesting page that looked close enough to a Microsoft login to fool anyone moving fast.

A Redirect Chain Built to Dodge Scanners

The email arrived at a mid-size financial services firm on a Monday morning, formatted as a forwarded legal document awaiting signature. The body included realistic law-firm footers, a bank reference, and multiple legitimate links — all designed to make the one malicious link blend in.

That malicious link: a maps[.]google[.]be redirect that resolved to a public S3 bucket hosting an HTML page at bucket-secure-cdn-cdn-media-static[.]s3[.]us-east-1[.]amazonaws[.]com/about[.]html. The page mimicked a Microsoft 365 login.

The redirect chain is the whole game here. URL scanners check the first domain, Google, and stop. The S3 destination isn't evaluated until someone clicks, and by then, the scanner has already marked it safe.

Attack Flow
DocuSign Lure Email

Google Maps Redirect

Amazon S3 HTML Page

Credential Harvest

See Your Risk: Calculate how many threats like this your gateway is missing

Why the Gateway Gave It a Pass

Email authentication didn't help. SPF passed, the sending server was legitimately authorized by the envelope domain, a small Japanese web services company with no connection to DocuSign. No DKIM signature. DMARC returned a best-guess pass.

So the email arrived with clean authentication, a trusted redirect domain (Google), and a hosting provider (AWS) that no blocklist is going to flag broadly. The attacker's infrastructure looked legitimate at every checkpoint.

Check Result Why It Didn't Help
SPF Pass ✓ Sending server was authorized - by the wrong domain
DKIM None No signature to validate
DMARC Best-guess Pass No DMARC record  - receiver inferred "pass"
URL Scan Safe ✓ Only scanned first hop (Google domain)

IRONSCALES Adaptive AI caught what the static checks missed: the behavioral mismatch between the sender's domain infrastructure (a Japanese web hosting provider) and the claimed identity (DocuSign). Combined with community-reported patterns matching the same S3 bucket across three other organizations, the platform quarantined the message within 90 seconds of delivery, before any recipient clicked.

Your Takeaway

If your email security relies on URL reputation at the first hop, redirect-chain attacks will sail through. Ask your security team: does our scanning follow redirects to the final destination? If the answer is "sometimes" or "I'm not sure" - that's the gap attackers are counting on.

Get a Demo: See how IRONSCALES detects redirect-chain phishing in real time

 

 

The post The DocuSign Email That Wasn’t – A Three-Redirect Credential Harvest appeared first on Security Boulevard.

❌
❌