SANS Stormcast Tuesday, April 8th:

SANS Stormcast Tuesday, April 8th:

Update: 2025-04-08
Share

Description



XORsearch: Searching With Regexes

Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.

https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834

MCP Security Notification: Tool Poisoning Attacks

Invariant labs summarized a critical weakness in the Model Context Protocol (MCP) that allows for "Tool Poisoning Attacks." Many major providers such as Anthropic and OpenAI, workflow automation systems like Zapier, and MCP clients like Cursor are susceptible to this attack

https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks

Making :visited more private

Google Chrome changed how links are marked as visited . This new partitioning scheme was introduced to improve privacy. Instead of marking a link as visited on any page where it is displayed, it is only marked as visited if the user clicks on the link while visiting the particular site where the link is displayed.

https://developer.chrome.com/blog/visited-links
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Tuesday, April 8th:

SANS Stormcast Tuesday, April 8th:

Dr. Johannes B. Ullrich