Urgent.News

What's breaking now, across thousands of outlets.

Tech

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in Tech

Allowlists Are Not Spending Caps: Two Different Security Properties, Often Confused

If you've ever configured a delegated signer, a session key, or a bot's wallet permissions, you've probably reached for two knobs: an allowlist of assets it's allowed to touch, and a cap on how much…

  • Allowlists limit interactions to a predefined set of token contracts
  • Spending caps restrict the amount of value that can be moved
  • Allowlists and caps address different security failure modes

Handoff is Where the Agent Dies: 3 Patterns That Fix It

Your multi_agent pipeline works fine in testing. Then you deploy it and watch it fail: Agent A finishes its task and "passes" to Agent B.

  • Artifact Chaining shares evidence of agent's work during handoff
  • Contract Testing validates received artifacts against defined contract
  • Shared Memory Repository enables agents to maintain shared knowledge base

More from Thursday 3 September →