Mastodon Digest
for the past
scorer
threshold
Posts

OpenAI are criminally negligent when it comes to cybersecurity, and are very good at viral marketing to executives via poor and uncritical media coverage.

RE: infosec.exchange/@wdormann/116

This vuln (CVE-2026-50522) will see mass exploitation. It's out of the box unauth RCE in SharePoint, a mass exposed internet technology.

My take on the story about OpenAI's model going rogue and hacking a competitor's systems, why it matters.

Also probably the fastest turnaround time for a video that I've managed so far. I'd just got off a 12h flight when the story dropped.

youtu.be/GB8gaeI0fLs?si=ss3hD7

UPDATE: Critical Vulnerabilities in Microsoft SharePoint (CERT-EU Security Advisory 2026-009)

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644.
CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.

cert.europa.eu/publications/se

Boosts

John C. Dvorak, a pioneering technology journalist, podcaster, and cultural commentator, passed away peacefully on the morning of Monday, July 20, 2026. He was 80 years old. For tech journalists of a certain age, there was a time when everyone knew him.