Search
Are you still stuck in that old school of getting VAPT done for network and servers
Stop, that is mostly a complete waste of time.
Talk to Castellum Labs, for a contextual, deep & meaningful VAPT.
reach@castellumlabs.com
Link in Bio
#vapt #pentest #vulnerabilities #owasp
36
Most MSSPs audit their #RMM stack for direct #vulnerabilities but never map the #AI gateways their client-facing tools route through. Your liability starts when the middleware you can't see steals credentials you're responsible for protecting. #mssp #supplychain #soc #threatintel
65
SSRF, prompt injection, & auth bypass, 200x higher rate than LangChain or Ollama in lifetimes. CVE-2026-27001 shows the root cause: the working directory path embedded as a plain string in... #CyberSecurity #Vulnerabilities
1
31
⚡️ NEW: Ripple is rolling out AI-driven security upgrades for the XRP Ledger.
This includes AI-assisted testing and a dedicated red team to catch vulnerabilities before they hit production.
53
Critical NVIDIA Vulnerabilities Enable RCE and DoS Attacks cyberpress.org/critical-nvidi… #CyberSecurity #Vulnerabilities #CSCIS
Critical NVIDIA Vulnerabilities Enable RCE and DoS Attacks
The disclosure highlights growing risks in machine learning environments, where widely used frameworks and inference tools
From cyberpress.org 4
32% of exploited vulns are 10+ years old.
Attackers don’t forget - and orgs don’t patch.
Meanwhile, new flaws get weaponized instantly.
What’s the bigger risk: legacy or zero-days?
Follow @TechNadu
#Cybersecurity #Infosec #Vulnerabilities
1
36
Crunchyroll confirms data breach after hacker claims unauthorized access #DataBreach #Vulnerabilities #Hackers #UnauthorizedAccess #InternalSystems #SupportTicket #StolenData #Cyberattack techcrunch.com/2026/03/24/cru…
Crunchyroll confirms data breach after hacker claims unauthorized access | TechCrunch
Crunchyroll said it continues to investigate the data breach involving its users' personal information.
From techcrunch.com 54
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse thehackernews.com/2026/03/device… #CyberSecurity #Vulnerabilities #CSCIS
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
Device code phishing targets 340+ Microsoft 365 orgs since Feb 2026 via OAuth abuse, enabling persistent token hijacking and account takeover.
From thehackernews.com 5
17
#CISA ordered USA government agencies to patch three #iOS #vulnerabilities targeted in #cryptocurrency theft and #cyberespionage #cyberattacks using the #DarkSword exploit kit.
#CyberSecurity #InfoSec
ift.tt/hAzk1lm
33
Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems cybersecuritynews.com/netscaler-adc-… #CyberSecurity #Vulnerabilities #CSCIS
Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems
Cloud Software Group has released urgent security patches for NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), addressing two significant vulnerabilities that...
From cybersecuritynews.com 26
Recent #vulnerabilities like the critical flaw in #QuestKACE systems show hackers exploiting weaknesses to hijack #systems & steal data. Meanwhile, #hate speech & #antisemitism spread unchecked, fueling #violence & division.
3
Open-source software has an invisible vulnerability. Hackers have found it #OpenSourceSoftware #Vulnerabilities #Hackers #MaliciousPrograms #TrojanSource #SharedInfrastructure #WebBrowser #Extensions scientificamerican.com/article/glassw…
GlassWorm malware hides in invisible open-source code
A cybercrime campaign called GlassWorm is hiding malware in invisible characters and spreading it through software that millions of developers rely on
From scientificamerican.com 19
#Microsoft's March update includes 83 #CVE s, with 8 Critical flaws and 6 #vulnerabilities Microsoft expects attackers to exploit. Patch now. #threatintel #mssp #cybersecurity
95
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover thehackernews.com/2026/03/magent… #CyberSecurity #Vulnerabilities #CSCIS
20





