Visualização normal

Antes de ontemSecurity Boulevard

Benchmarking AI Pentesting Tools: A Practical Comparison

30 de Abril de 2026, 08:31

We benchmarked 4 AI pentesting tools: Escape, Shannon, Strix, PentAGI, and Claude against a modern vulnerable application. Learn more about their detection rates, false positive rates, and scanning speed.

The post Benchmarking AI Pentesting Tools: A Practical Comparison appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products NSFOCUS
    Overview On April 15, NSFOCUS CERT detected that Microsoft released the April Security Update patch, fixing 165 security issues involving Windows, Microsoft Office, Microsoft SQL Server, Microsoft Visual Studio, Microsoft .NET Framework, Widely used products such as Azure, including high-risk vulnerability types such as privilege escalation and remote code execution. Among the vulnerabilities fixed by […] The post Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple P
     

Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products

24 de Abril de 2026, 05:33

Overview On April 15, NSFOCUS CERT detected that Microsoft released the April Security Update patch, fixing 165 security issues involving Windows, Microsoft Office, Microsoft SQL Server, Microsoft Visual Studio, Microsoft .NET Framework, Widely used products such as Azure, including high-risk vulnerability types such as privilege escalation and remote code execution. Among the vulnerabilities fixed by […]

The post Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products appeared first on NSFOCUS.

The post Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products appeared first on Security Boulevard.

Julius v0.2.0: From 33 to 63 Probes — Now Detecting Cloud AI, Enterprise Inference, and RAG Pipelines

24 de Março de 2026, 22:13

TL;DR: Julius v0.2.0 nearly doubles LLM fingerprinting probe coverage from 33 to 63, adding detection for cloud-managed AI services (AWS Bedrock, Azure OpenAI, Vertex AI), high-performance inference servers (SGLang, TensorRT-LLM, Triton), AI gateways (Portkey, Helicone, Bifrost), and self-hosted RAG platforms (PrivateGPT, RAGFlow, Quivr). This release also hardens the scanner itself with response size limiting and […]

The post Julius v0.2.0: From 33 to 63 Probes — Now Detecting Cloud AI, Enterprise Inference, and RAG Pipelines appeared first on Praetorian.

The post Julius v0.2.0: From 33 to 63 Probes — Now Detecting Cloud AI, Enterprise Inference, and RAG Pipelines appeared first on Security Boulevard.

  • ✇Security Boulevard
  • CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability Deepak Kumar Choudhary
    Microsoft SharePoint, a core platform for enterprise collaboration, is facing active exploitation through a newly confirmed vulnerability, tracked as CVE-2026-20963. Rooted in unsafe deserialization of user-controlled data, this vulnerability allows remote. The post CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability appeared first on Indusface. The post CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability appeared first on Security Boulevard.
     

CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability

24 de Março de 2026, 04:30

Microsoft SharePoint, a core platform for enterprise collaboration, is facing active exploitation through a newly confirmed vulnerability, tracked as CVE-2026-20963. Rooted in unsafe deserialization of user-controlled data, this vulnerability allows remote.

The post CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability appeared first on Indusface.

The post CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability appeared first on Security Boulevard.

  • ✇Security Boulevard
  • The Real State of Offensive Security: AI, Penetration Testing & The Road Ahead with Andrew Wilson Tom Eston
    Tom Eston interviews offensive AI researcher and PhD candidate Andrew Wilson, a former Bishop Fox partner who helped grow the firm from under 20 people to nearly 500, built award-winning AI solutions for SOC modernization, founded Cactus Con, and relocated his family to Guadalajara to open and scale a Bishop Fox office. They discuss Mexico’s […] The post The Real State of Offensive Security: AI, Penetration Testing & The Road Ahead with Andrew Wilson appeared first on Shared Security Podcast
     
  • ✇Security Boulevard
  • RSAC 2026 Innovation Sandbox | ZeroPath: From Alarm Accumulation to Executable Fixes NSFOCUS
    Company Profile ZeroPath is an AI-native application security startup founded in 2024, and its core products also use the eponymous brand ZeroPath. The company focuses on using AI to automatically discover, verify and fix code vulnerabilities, trying to break through the limitations of traditional SAST, SCA, Secrets scanning and IaC scanning that are fighting each […] The post RSAC 2026 Innovation Sandbox | ZeroPath: From Alarm Accumulation to Executable Fixes appeared first on NSFOCUS, Inc., a
     

RSAC 2026 Innovation Sandbox | ZeroPath: From Alarm Accumulation to Executable Fixes

22 de Março de 2026, 00:05

Company Profile ZeroPath is an AI-native application security startup founded in 2024, and its core products also use the eponymous brand ZeroPath. The company focuses on using AI to automatically discover, verify and fix code vulnerabilities, trying to break through the limitations of traditional SAST, SCA, Secrets scanning and IaC scanning that are fighting each […]

The post RSAC 2026 Innovation Sandbox | ZeroPath: From Alarm Accumulation to Executable Fixes appeared first on NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks..

The post RSAC 2026 Innovation Sandbox | ZeroPath: From Alarm Accumulation to Executable Fixes appeared first on Security Boulevard.

  • ✇Security Boulevard
  • CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive Tom Abai
    On March 20, 2026 at 20:45 UTC, Aikido Security detected an unusual pattern across the npm registry: dozens of packages from multiple organizations were receiving unauthorized patch updates, all containing the same hidden malicious code. What they had caught was CanisterWorm, a self-spreading npm worm deployed by the threat actor group TeamPCP. We track this […] The post CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive appeared first on Security Boulevar
     

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

21 de Março de 2026, 17:37

On March 20, 2026 at 20:45 UTC, Aikido Security detected an unusual pattern across the npm registry: dozens of packages from multiple organizations were receiving unauthorized patch updates, all containing the same hidden malicious code. What they had caught was CanisterWorm, a self-spreading npm worm deployed by the threat actor group TeamPCP. We track this […]

The post CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly n8n-publisher
    Everyone knows that one person on the team who’s inexplicably lucky, the one who stumbles upon a random vulnerability seemingly by chance. A few days ago, my coworker Michael Weber was telling me about a friend like this who, on a recent penetration test, pressed the shift key five times at an RDP login screen […] The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly appeared first on Praetorian. The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebA
     

Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly

13 de Março de 2026, 16:01

Everyone knows that one person on the team who’s inexplicably lucky, the one who stumbles upon a random vulnerability seemingly by chance. A few days ago, my coworker Michael Weber was telling me about a friend like this who, on a recent penetration test, pressed the shift key five times at an RDP login screen […]

The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly appeared first on Praetorian.

The post Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Claude Code Security: The AI Shockwave Hitting Cybersecurity Tom Eston
    Anthropic’s Claude Code Security research preview promises AI-powered code analysis and vulnerability detection at scale. The announcement triggered strong reactions across the cybersecurity community and sent several vendor stocks lower. In this episode, we break down what the tool actually does, where it fits in modern AppSec, and whether AI automation threatens traditional security products […] The post Claude Code Security: The AI Shockwave Hitting Cybersecurity appeared first on Shared Secu
     

Claude Code Security: The AI Shockwave Hitting Cybersecurity

2 de Março de 2026, 02:00

Anthropic’s Claude Code Security research preview promises AI-powered code analysis and vulnerability detection at scale. The announcement triggered strong reactions across the cybersecurity community and sent several vendor stocks lower. In this episode, we break down what the tool actually does, where it fits in modern AppSec, and whether AI automation threatens traditional security products […]

The post Claude Code Security: The AI Shockwave Hitting Cybersecurity appeared first on Shared Security Podcast.

The post Claude Code Security: The AI Shockwave Hitting Cybersecurity appeared first on Security Boulevard.

💾

  • ✇Security Boulevard
  • Is Your AppSec Program Truly Mature?  Bala Thripura Akasam
    Learn how to build a high-maturity Application Security program with secure SDLC, developer-first practices, automated AppSec controls, practical threat modeling, runtime API protection, and meaningful security metrics. The post Is Your AppSec Program Truly Mature?  appeared first on Security Boulevard.
     

Is Your AppSec Program Truly Mature? 

26 de Fevereiro de 2026, 05:00

Learn how to build a high-maturity Application Security program with secure SDLC, developer-first practices, automated AppSec controls, practical threat modeling, runtime API protection, and meaningful security metrics.

The post Is Your AppSec Program Truly Mature?  appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Prompt Control is the New Front Door of Application Security  Lori MacVittie
    Discover how AI-driven systems are redefining application security. Research highlights the importance of focusing on inference layers, prompt control, and token management to effectively secure AI inference services and minimize risks associated with cost, latency, and data leakage. The post Prompt Control is the New Front Door of Application Security  appeared first on Security Boulevard.
     

Prompt Control is the New Front Door of Application Security 

18 de Fevereiro de 2026, 08:00
Run Security, security,

Discover how AI-driven systems are redefining application security. Research highlights the importance of focusing on inference layers, prompt control, and token management to effectively secure AI inference services and minimize risks associated with cost, latency, and data leakage.

The post Prompt Control is the New Front Door of Application Security  appeared first on Security Boulevard.

❌
❌