#SafeBreach
Fundamentally. Unsecurable.

You can't rid yourself of this vulnerability in LLMs.
Exploiting Gemini via Prompt Injection | SafeBreach Original Research
See how SafeBreach Labs researchers uncovered a way to hijack Google Gemini via WhatsApp and Slack using a novel indirect prompt injection technique.
www.safebreach.com
June 3, 2026 at 5:56 PM
LDAPNightmare: SafeBreach Labs Publishes First Proof-of-Concept Exploit for
CVE-2024-49112
www.safebreach.com/blog/ldapnig...
LDAPNightmare: SafeBreach Publishes First PoC Exploit (CVE-2024-49113)
See how SafeBreach researchers developed a zero-click PoC exploit for LDAPNightmare (CVE-2024-49113) that crashes unpatched Windows Servers.
www.safebreach.com
January 3, 2025 at 5:26 PM
The latest update for #SafeBreach includes "SafeBreach Coverage for CVE-2025-53770: ToolShell Exploits Targeting Microsoft SharePoint" and "#ZeroTrust Isn't Enough: Here's How to Validate It and Prove Resilience".

#Cybersecurity https://opsmtrs.com/41NWGuQ
SafeBreach
SafeBreach is the pioneer in breach-and-attack simulation (BAS) and is the most widely used platform for continuous security validation.
opsmtrs.com
July 22, 2025 at 12:33 AM
SafeBreach researchers Or Yair and Shahak Morag revealed at DEF CON 33 that a new attack technique, dubbed Win-DDoS, could exploit public domain controllers to form a massive botnet for DDoS attacks. #CyberSecurity #DEFCON33 thehackernews.com/2025/08/new-...
New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAP
SafeBreach found four Windows DoS flaws via RPC and LDAP, enabling stealth DDoS botnets. Microsoft patched in 2025.
thehackernews.com
August 13, 2025 at 5:29 AM
SafeBreach is hiring for Frontend Developer. Join a talented team using cutting-edge technologies to tackle daily security threats (Tel Aviv, Israel)
Senior Frontend Developer - SafeBreach - Remote
SafeBreach is hiring a Frontend Developer | Find your next frontend developer job at Frontend Jobs.
www.getfrontendjobs.com
January 22, 2025 at 10:37 AM
Windows sicuro dopo gli updates?
Anche no.

#WindowsDowndate, così è stato ribattezzato l'attacco da Alon Leviev di @safebreach, sfrutta due #0day (CVE-2024-38202 e CVE-2024-21302) per rimuovere silenziosamente le ultime patch dalle macchine che montano Windows 10, Windows 11 e Windows Server 😱

>>>
August 8, 2024 at 8:34 AM
LDAPNightmare : First Proof-of-Concept Exploit for CVE-2024-49112 : www.safebreach.com/blog/ldapnig... credits @oryair1999 @ShahakMo

LdapNightmare : a PoC tool that tests a vulnerable Windows Server against CVE-2024-49112 : github.com/SafeBreach-L...
January 2, 2025 at 3:15 PM
The latest update for #SafeBreach includes "SafeBreach Coverage for US CERT AA25-050A [Ghost (Cringe) Ransomware]" and "The Next Evolution of SafeBreach is Here: Meet the SafeBreach Exposure Validation Platform".

#Cybersecurity https://opsmtrs.com/41NWGuQ
SafeBreach
SafeBreach is the pioneer in breach-and-attack simulation (BAS) and is the most widely used platform for continuous security validation.
opsmtrs.com
February 21, 2025 at 5:21 AM
Discovery & Analysis of CVE-2025-29969 | SafeBreach
Discovery & Analysis of CVE-2025-29969 | SafeBreach
Learn more about SafeBreach Labs discovery of CVE-2025-29969, a critical RCE vulnerability in the MS-EVEN RPC protocol in Microsoft Windows.
buff.ly
March 11, 2026 at 10:51 AM
The latest update for #SafeBreach includes "SafeBreach Coverage for CISA Analysis Report AR25-261A: Malicious Listener for Ivanti Endpoint Mobile Management Systems" and "Proving DORA Requirements with the SafeBreach Platform".

#Cybersecurity https://opsmtrs.com/41NWGuQ
SafeBreach
SafeBreach is the pioneer in breach-and-attack simulation (BAS) and is the most widely used platform for continuous security validation.
opsmtrs.com
September 19, 2025 at 10:28 PM
The Prince of Persia (Infy) APT went silent for 16 days during Iran's internet outage

Group resumed activity a day before the blackout was lifted, showing a strong connection to the Iranian state

www.safebreach.com/blog/prince-...
An Update on the Prince of Persia Threat Actor | SafeBreach
Get SafeBreach Labs’s latest update on the Price of Persia APT, including new activity that indicates a definitive connection to the Iranian government.
www.safebreach.com
February 5, 2026 at 4:32 PM
LDAPNightmare: SafeBreach Publishes First PoC Exploit (CVE-2024-49113)
LDAPNightmare: SafeBreach Publishes First PoC Exploit (CVE-2024-49113)
www.safebreach.com
January 11, 2025 at 6:39 PM
🚨 Win-DDoS: Windows DCs weaponized into DDoS botnets

SafeBreach researchers unveiled Win-DDoS, a new zero-click exploit leveraging LDAP and RPC flaws to hijack public Windows Domain Controllers into stealthy DDoS botnets, impacting thousands of systems globally. Microsoft has issued patches.
August 11, 2025 at 11:37 AM
New infosec products of the week: February 7, 2025

Here’s a look at the most interesting products from the past week, featuring releases from Dynatrace, Nymi, Qualys, SafeBreach, and Satori. Qualys TotalAppSec enables organizations to address risks across web applications and AP…

#hackernews #news
New infosec products of the week: February 7, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Dynatrace, Nymi, Qualys, SafeBreach, and Satori. Qualys TotalAppSec enables organizations to address risks across web applications and APIs Qualys TotalAppSec unifies API security, web application scanning, and web malware detection across on-premises to hybrid and multi-cloud environments, providing companies with a comprehensive view of their application security risk and posture. SafeBreach exposure validation platform identifies security gaps SafeBreach launched SafeBreach …
www.helpnetsecurity.com
February 8, 2025 at 3:13 AM
here is the researchers' website explaining in more detail: sites.google.com/view/invitat...
August 6, 2025 at 11:01 PM
The latest update for #SafeBreach includes "Proving #ZeroTrust in Practice: Continuous Validation for Segmentation and Lateral Movement Defense" and "SafeBreach's Evolution into an AI-First Development Team: Part II".

#Cybersecurity https://opsmtrs.com/41NWGuQ
SafeBreach
SafeBreach is the pioneer in breach-and-attack simulation (BAS) and is the most widely used platform for continuous security validation.
opsmtrs.com
March 14, 2026 at 5:38 AM
Fake Context Alignment: The Attack That Made Gemini Obey Strangers Through Your Notifications
Fake Context Alignment: The Attack That Made Gemini Obey Strangers Through Your Notifications - Security Affairs
SafeBreach tricked Gemini into obeying attackers via WhatsApp notifications, using hidden foreign-language text to bypass Google's defenses.
securityaffairs.com
June 5, 2026 at 9:11 AM
SafeBreach releases 2026 State of the Breach Report 

SafeBreach has released its 2026 State of the Breach Report, analyzing results from millions of real-world attack simulations conducted by large, global enterprises over a 12-month period using the SafeBreach Exposure Validation Platform. The…
SafeBreach releases 2026 State of the Breach Report 
SafeBreach has released its 2026 State of the Breach Report, analyzing results from millions of real-world attack simulations conducted by large, global enterprises over a 12-month period using the SafeBreach Exposure Validation Platform. The report provides never-before-seen insights about how enterprises fared against 2025's high-profile threats by examining how security controls actually performed under real attack conditions, moving beyond traditional metrics such as alerts generated, patches applied, or tools deployed.
itnerd.blog
January 14, 2026 at 5:23 PM
The latest update for #SafeBreach includes "The Convergence Crisis: How Continuous Validation is Redefining Resilience for Critical Infrastructure" and "SafeBreach Coverage for Updated CISA AR25-338A: BRICKSTORM Backdoor".

#Potatosecurity https://opsmtrs.com/41NWGuQ
December 23, 2025 at 5:18 AM
SafeBreach Labs researchers discovered a new security vulnerability
that allows attackers to exploit Google Gemini through notification-based
indirect prompt injections from messaging apps like WhatsApp, Slack, and SMS.
www.safebreach.com/blog/gemini-... #infosec
Exploiting Gemini via Prompt Injection | SafeBreach Original Research
See how SafeBreach Labs researchers uncovered a way to hijack Google Gemini via WhatsApp and Slack using a novel indirect prompt injection technique.
www.safebreach.com
June 6, 2026 at 1:13 AM
SafeBreach launches AI-driven CTEM to close the execution gap 

SafeBreach today announced the launch of its AI-powered Continuous Threat Exposure Management (CTEM) solution. This solution is designed to help organizations move beyond siloed security activities toward a complete, closed-loop CTEM…
SafeBreach launches AI-driven CTEM to close the execution gap 
SafeBreach today announced the launch of its AI-powered Continuous Threat Exposure Management (CTEM) solution. This solution is designed to help organizations move beyond siloed security activities toward a complete, closed-loop CTEM program that continuously identifies, prioritizes, and remediates cyber risk at scale. As enterprises struggle with challenges like AI-generated threats, tool fatigue, and alert overload, traditional reactive security measures are no longer sufficient.
itnerd.blog
April 22, 2026 at 12:37 PM