433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (656) 236-3022

Fake OAuth client IDs are helping attackers slip past sign-in logs

Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in an authentication request. Microsoft Entra ID records that value as the application ID in its sign-in logs, and the way it handles unfamiliar identifiers opens a gap that operators have started to work through. Entra … More → The post Fake OAuth client IDs are helping attackers slip past sign-in logs appeared first on Help Net Security.
http://news.poseidon-us.com/TTW5wH

Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers

A “credible external security threat” targeting Progress Software’s ShareFile Storage Zone Controllers (SZC) – the on-premises, customer-managed server components where organizations store files shared via this popular enterprise platform – has spurred the company to disable access to ShareFile accounts that are using them. The warning was sent to customers via email on July 10, urging them to manually shut down the server that is hosting their Storage Zone Controllers. The initial email alert from … More → The post Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers appeared first on Help Net Security.
http://news.poseidon-us.com/TTW5vN

FastNetMon eliminates third-party bgp lookups with Netomics

FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Exchange Points (IXPs) and enterprises operating large IP networks, Netomics provides complete visibility into global internet routing without relying on third-party lookup services. Network engineers often need to consult multiple public tools to investigate routing incidents, validate prefix … More → The post FastNetMon eliminates third-party bgp lookups with Netomics appeared first on Help Net Security.
http://news.poseidon-us.com/TTVwjY

Claude Code users keep 50% higher limits until July 19

Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing. The promotion is available to Pro, Max, and Team plans, as well as legacy seat-based users on Enterprise plans. Free plans and consumption-based Enterprise seats are not eligible. What’s included … More → The post Claude Code users keep 50% higher limits until July 19 appeared first on Help Net Security.
http://news.poseidon-us.com/TTVwhP

Why SBOMs, signing, and provenance still don’t tell you if software is safe

We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signing and provenance. All of that matters, but it is not enough. The current software trust model still stops short of the question that determines risk at execution: What is this code capable of doing if … More → The post Why SBOMs, signing, and provenance still don’t tell you if software is safe appeared first on Help Net Security.
http://news.poseidon-us.com/TTVmFT

Cynative: Open-source deep research agent

Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an open-source security research agent, answers that hazard by refusing to write anything by default, and by checking that refusal on every single call it … More → The post Cynative: Open-source deep research agent appeared first on Help Net Security.
http://news.poseidon-us.com/TTVgWl

Microsoft demystifies how Windows updates work

Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly security updates, released on the second Tuesday of each month. Windows also provides optional non-security preview updates, which give IT teams and early adopters an opportunity to validate upcoming fixes before they’re included in the … More → The post Microsoft demystifies how Windows updates work appeared first on Help Net Security.
http://news.poseidon-us.com/TTVgWh

A hardware security AI assistant that checks chips for hidden backdoors

Chip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each written by a company the buyer may never deal with directly. A malicious supplier can bury a hidden circuit in a working design, and that circuit can stay quiet until a specific input wakes it up. Researchers at the University of Florida built a tool aimed at this … More → The post A hardware security AI assistant that checks chips for hidden backdoors appeared first on Help Net Security.
http://news.poseidon-us.com/TTVgWW