{
  "feed_id": "laitest-threat-intel",
  "schema_version": "1.0.0",
  "schema_url": "https://laitest.alexanderromero.net/feeds/schema/threat-intel-v1.json",
  "generated_at": "2026-07-27T04:13:37.989Z",
  "publisher": {
    "name": "Laitest",
    "url": "https://laitest.alexanderromero.net",
    "contact": "mailto:alexanderromero@gmail.com",
    "role": "signal_source"
  },
  "disclaimer": "Signals are curated from public X posts and operator notes. They are NOT a vulnerability database, NOT official CVSS/EPSS/KEV, and MUST be enriched and reviewed before any customer-facing or automated remediation action. REMEDiS PSIRT (or any consumer) owns prioritization, SBOM matching, and disclosure.",
  "usage": {
    "intended_consumer": "psirt.remedissecurity.com threat-intel ingest (and compatible caches)",
    "cache_policy": "Use ETag / content_hash / feed_signature; poll ≤ 2×/day unless emergency; store history in PSIRT",
    "delta": "GET /feeds/threat-intel.json?since=ISO8601 filters by first_seen_at or updated_at",
    "signature": "feed_signature is HMAC-SHA256(hex) of feed_hash when LAITEST_FEED_HMAC_SECRET is set",
    "never": [
      "Treat severity.hint as CVSS",
      "Auto-notify customers from this feed alone",
      "Skip enrichment for CVE IDs",
      "Trust package_hints as CPE"
    ]
  },
  "window": {
    "from": "2026-07-12",
    "to": "2026-07-26",
    "item_count": 49
  },
  "items": [
    {
      "id": "laitest:x:2081494782396747779",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081494782396747779",
        "url": "https://x.com/i/status/2081494782396747779",
        "author_handle": "om_patel5",
        "author_name": "Om Patel",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "UPDATE: Claude shared chats AND published artifacts indexed by Google — API keys, health data, clinical trial summaries, payroll, etc. Sa…",
      "summary": "UPDATE: Claude shared chats AND published artifacts indexed by Google — API keys, health data, clinical trial summaries, payroll, etc. Same class of bug ChatGPT had. Delete shared chats/artifacts; assume link-share ≠ private.",
      "lesson": "PSIRT-relevant: shared artifact indexing is a class of product security failure.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "high",
        "label": "High (text)",
        "basis": [
          "language_high_or_leak_or_compromise"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081494782396747779",
        "references": []
      },
      "engagement": {
        "likes": 1065,
        "reposts": 102,
        "replies": 50,
        "bookmarks": 865,
        "views": 216332,
        "score": 3534,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "analyst_triage",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:39:01.635Z",
      "content_hash": "b3e261ce30260d49f5017ee71cd46a058956c8b36fbbcb22935a2b295794fcff"
    },
    {
      "id": "laitest:x:2081252689867124762",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081252689867124762",
        "url": "https://x.com/i/status/2081252689867124762",
        "author_handle": "The_Cyber_News",
        "author_name": "Cyber Security News",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "PentesterFlow — open-source human-in-the-loop agentic CLI for recon-to-reporting. Explicit analyst approval before sensitive commands; ev…",
      "summary": "PentesterFlow — open-source human-in-the-loop agentic CLI for recon-to-reporting. Explicit analyst approval before sensitive commands; evidence-based confirmation.",
      "lesson": "HITL on destructive actions is the correct threat model for agentic red team.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081252689867124762",
        "references": [
          "https://cybersecuritynews.com/pentesterflow/"
        ]
      },
      "engagement": {
        "likes": 138,
        "reposts": 32,
        "replies": 4,
        "bookmarks": 79,
        "views": 8211,
        "score": 408,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "e55658f1b0cc12ce23fd16e96fa5ec989bf41f1ccc740472cf16c288bbfc47f1"
    },
    {
      "id": "laitest:x:2081354106992767330",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081354106992767330",
        "url": "https://x.com/i/status/2081354106992767330",
        "author_handle": "VivekIntel",
        "author_name": "Vivek | Cybersecurity",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "pentest-ai — OSS AI pentesting that verifies every finding with oracle-based re-tests. 17 specialized agents, 200+ tool wrappers, Nuclei,…",
      "summary": "pentest-ai — OSS AI pentesting that verifies every finding with oracle-based re-tests. 17 specialized agents, 200+ tool wrappers, Nuclei, MCP/local LLM support.",
      "lesson": "Verification loops kill false positives — design tooth for REMEDiS-class tooling.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081354106992767330",
        "references": []
      },
      "engagement": {
        "likes": 74,
        "reposts": 19,
        "replies": 0,
        "bookmarks": 89,
        "views": 3136,
        "score": 315,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "0d3a759eb605ca9e1e6383acd4fad31112f3f60e59d57d579c457ae555ec183b"
    },
    {
      "id": "laitest:x:2081466942385234231",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081466942385234231",
        "url": "https://x.com/i/status/2081466942385234231",
        "author_handle": "ABC",
        "author_name": "ABC News",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "security"
      },
      "title": "OpenAI said its models carried out a self-directed hack into another company — described as first known autonomous AI cyber attack escapi…",
      "summary": "OpenAI said its models carried out a self-directed hack into another company — described as first known autonomous AI cyber attack escaping a testing environment.",
      "lesson": "Autonomous offense capability claims will drive policy + PSIRT tabletop scenarios.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "high",
        "label": "High (text)",
        "basis": [
          "language_high_or_leak_or_compromise"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081466942385234231",
        "references": [
          "https://abcnews.com/Technology/openai-ai-models-escaped-testing-environment-launched-hack/story?id=134981298"
        ]
      },
      "engagement": {
        "likes": 54,
        "reposts": 18,
        "replies": 23,
        "bookmarks": 16,
        "views": 76669,
        "score": 293,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "analyst_triage",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "ad2176554f4f68a3d00d156e21ca1358fef0a210117f0b37179938a799b75a93"
    },
    {
      "id": "laitest:x:2081186489040597307",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081186489040597307",
        "url": "https://x.com/i/status/2081186489040597307",
        "author_handle": "MarioNawfal",
        "author_name": "Mario Nawfal",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "security"
      },
      "title": "Jensen Huang after Hugging Face AI hack: “Just because something is closed… doesn’t necessarily make it secure and safe.”",
      "summary": "Jensen Huang after Hugging Face AI hack: “Just because something is closed… doesn’t necessarily make it secure and safe.”",
      "lesson": "Closed ≠ secure — cybersecurity posture in open-weight policy fights.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081186489040597307",
        "references": []
      },
      "engagement": {
        "likes": 54,
        "reposts": 21,
        "replies": 12,
        "bookmarks": 18,
        "views": 39704,
        "score": 232,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "52d4c9f06a3ed383524519202c59561d158fc6af091dbcf3f02e5a91ecb09d84"
    },
    {
      "id": "laitest:x:2081111958770589812",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081111958770589812",
        "url": "https://x.com/i/status/2081111958770589812",
        "author_handle": "TheTechDiggest",
        "author_name": "AI Tech Diggest",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "security"
      },
      "title": "awesome-osint-arsenal — 750+ curated tools for security, OSINT, and DFIR with verified install scripts.",
      "summary": "awesome-osint-arsenal — 750+ curated tools for security, OSINT, and DFIR with verified install scripts.",
      "lesson": "OSINT/DFIR arsenals compress research setup time.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081111958770589812",
        "references": []
      },
      "engagement": {
        "likes": 63,
        "reposts": 5,
        "replies": 1,
        "bookmarks": 65,
        "views": 1844,
        "score": 212,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "a6d5365b78776e3adefdf06e3acb919afabe17b7aac84648a2012482581316bd"
    },
    {
      "id": "laitest:x:2081301526350274594",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081301526350274594",
        "url": "https://x.com/i/status/2081301526350274594",
        "author_handle": "SajalDhiman2",
        "author_name": "Sajal Dhiman",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Shift Left Security – Part 3",
      "summary": "Shift Left Security – Part 3\n\nProtect Git workflow before merge: branch protection on main/release/dev, no direct pushes, mandatory PR checks (Trivy, SonarQube, secret scanning, SBOM, tests), required approvals, signed commits.\n\nBranching strategy defines where code flows. Branch protection defines whether the code is trusted enough to flow.",
      "lesson": "Product security starts at merge gates — required checks + signed commits.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "high",
        "label": "High (text)",
        "basis": [
          "language_high_or_leak_or_compromise"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081301526350274594",
        "references": []
      },
      "engagement": {
        "likes": 60,
        "reposts": 11,
        "replies": 0,
        "bookmarks": 54,
        "views": 2228,
        "score": 205,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "analyst_triage",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:39:01.635Z",
      "content_hash": "41f20e577bfe2e06fecb923b3253a52dd9b966ad457d866e0233b3a4969e04f1"
    },
    {
      "id": "laitest:x:2081432613479485710",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081432613479485710",
        "url": "https://x.com/i/status/2081432613479485710",
        "author_handle": "mycoliza",
        "author_name": "neural oscillator",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "security"
      },
      "title": "Overlooked in AI cybersecurity discourse: no matter how smart a model is, it can only exploit vulnerabilities that already exist in the s…",
      "summary": "Overlooked in AI cybersecurity discourse: no matter how smart a model is, it can only exploit vulnerabilities that already exist in the software it's trying to attack.",
      "lesson": "Offense AI amplifies existing bugs — product security still owns root causes.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081432613479485710",
        "references": []
      },
      "engagement": {
        "likes": 137,
        "reposts": 9,
        "replies": 6,
        "bookmarks": 9,
        "views": 5706,
        "score": 193,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "e1ac690c80aaeb46a4cb07de67c6df69dea332168a479ffce91589571de1ca4b"
    },
    {
      "id": "laitest:x:2081319473466712333",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081319473466712333",
        "url": "https://x.com/i/status/2081319473466712333",
        "author_handle": "HermesShield",
        "author_name": "Agentic Cybersecurity",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Shell exec ported cleanly. The safety checks didn't.",
      "summary": "Shell exec ported cleanly. The safety checks didn't.\n\nMoved an agent to Go: five paths to shell exec hit the tool-call boundary and were blocked. The rest are still live.\n\nPort the constraints before the features.",
      "lesson": "Agent product security: port constraints with capabilities — tool-call boundaries first.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081319473466712333",
        "references": []
      },
      "engagement": {
        "likes": 40,
        "reposts": 10,
        "replies": 3,
        "bookmarks": 0,
        "views": 246,
        "score": 70,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "a46f80070c6aabd6e1dc5d023e2dc597a0dd24eca6612186d6b32002448b4e7a"
    },
    {
      "id": "laitest:x:2081496090982199619",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081496090982199619",
        "url": "https://x.com/i/status/2081496090982199619",
        "author_handle": "VivekIntel",
        "author_name": "Vivek | Cybersecurity",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Strix — open-source AI penetration testing platform: multi-agent recon, PoC validation, web/API/source/GitHub, OWASP Top 10, CI/CD + loca…",
      "summary": "Strix — open-source AI penetration testing platform: multi-agent recon, PoC validation, web/API/source/GitHub, OWASP Top 10, CI/CD + local dashboard.",
      "lesson": "Pentest platforms racing to multi-agent + PoC validation.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081496090982199619",
        "references": []
      },
      "engagement": {
        "likes": 23,
        "reposts": 4,
        "replies": 0,
        "bookmarks": 15,
        "views": 730,
        "score": 66,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "19ab81371897b696db02246de6ae8e1c6fd9b050901cca13f9666a4781e3dbed"
    },
    {
      "id": "laitest:x:2081396814109094324",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081396814109094324",
        "url": "https://x.com/i/status/2081396814109094324",
        "author_handle": "HermesShield",
        "author_name": "Agentic Cybersecurity",
        "captured_day": "2026-07-26",
        "captured_at": "2026-07-26T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "One line of poisoned code turned a trusted CRM tool into an exfiltration channel. The AI never noticed: the data it received was still co…",
      "summary": "One line of poisoned code turned a trusted CRM tool into an exfiltration channel. The AI never noticed: the data it received was still correct.",
      "lesson": "Integrity attacks on agent tools: correct-looking data can still exfiltrate.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081396814109094324",
        "references": []
      },
      "engagement": {
        "likes": 30,
        "reposts": 10,
        "replies": 3,
        "bookmarks": 0,
        "views": 138,
        "score": 60,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-26T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "eb4c36d5ecc453836bae988b1c6317d58d326c424b782d6c66dbe6c9fe5e5f25"
    },
    {
      "id": "laitest:x:2081063652803690513",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081063652803690513",
        "url": "https://x.com/i/status/2081063652803690513",
        "author_handle": "hackermater11",
        "author_name": "hackermater",
        "captured_day": "2026-07-25",
        "captured_at": "2026-07-25T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "AndroidManifestExplorer for mobile bug hunters / Android security engineers.",
      "summary": "AndroidManifestExplorer for mobile bug hunters / Android security engineers.\nhttps://github.com/mateofumis/AndroidManifestExplorer",
      "lesson": "Mobile product security tooling is still underserved.",
      "incident_types": [
        "oss_library",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "github:mateofumis/AndroidManifestExplorer"
        ]
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081063652803690513",
        "references": [
          "https://github.com/mateofumis/AndroidManifestExplorer"
        ]
      },
      "engagement": {
        "likes": 67,
        "reposts": 5,
        "replies": 4,
        "bookmarks": 49,
        "views": 3981,
        "score": 188,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "enrich_and_match_sbom",
        "match_hints": {
          "cve_ids": [],
          "package_hints": [
            "github:mateofumis/AndroidManifestExplorer"
          ]
        }
      },
      "first_seen_at": "2026-07-25T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "9d7b79fd58d853456024fe780e318b6729bc965256f588ea5c345bdcd78b3963"
    },
    {
      "id": "laitest:x:2081033147207315518",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2081033147207315518",
        "url": "https://x.com/i/status/2081033147207315518",
        "author_handle": "VivekIntel",
        "author_name": "Vivek | Cybersecurity",
        "captured_day": "2026-07-25",
        "captured_at": "2026-07-25T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Visa Vulnerability Agentic Harness — open-source multi-agent SAST: threat modeling before analysis, multi-agent validation to cut false p…",
      "summary": "Visa Vulnerability Agentic Harness — open-source multi-agent SAST: threat modeling before analysis, multi-agent validation to cut false positives, Markdown/SARIF, AI remediation + fix validation, CI/CD & enterprise AppSec.",
      "lesson": "Enterprise AppSec is multi-agent SAST with validation — not single-LLM alert dumps.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2081033147207315518",
        "references": []
      },
      "engagement": {
        "likes": 38,
        "reposts": 11,
        "replies": 1,
        "bookmarks": 37,
        "views": 1706,
        "score": 148,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-25T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "951013a770b8a5044c5014abecd357c4f67e8c465ae7031e9602f896079bafb5"
    },
    {
      "id": "laitest:x:2080907038478254462",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2080907038478254462",
        "url": "https://x.com/i/status/2080907038478254462",
        "author_handle": "VivekIntel",
        "author_name": "Vivek | Cybersecurity",
        "captured_day": "2026-07-25",
        "captured_at": "2026-07-25T12:00:00.000Z",
        "category": "security"
      },
      "title": "Awesome AI Security Tools — curated OSS collection: LLM security, agent/MCP protection, AI red teaming, supply chain, threat intel, secur…",
      "summary": "Awesome AI Security Tools — curated OSS collection: LLM security, agent/MCP protection, AI red teaming, supply chain, threat intel, secure coding, fuzzing, SOC automation.",
      "lesson": "AI security catalogs help teams bootstrap toolchains fast.",
      "incident_types": [
        "supply_chain",
        "agent_or_ai_risk",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "high",
        "label": "High (text)",
        "basis": [
          "language_high_or_leak_or_compromise"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2080907038478254462",
        "references": []
      },
      "engagement": {
        "likes": 30,
        "reposts": 2,
        "replies": 1,
        "bookmarks": 30,
        "views": 1133,
        "score": 98,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-25T12:00:00.000Z",
      "updated_at": "2026-07-25T12:00:00.000Z",
      "content_hash": "4f465f1959d6ff7ecf7ef1f644fe37f4d3c1153afdd78038e139874a9ace6ced"
    },
    {
      "id": "laitest:x:2080752566971875740",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2080752566971875740",
        "url": "https://x.com/i/status/2080752566971875740",
        "author_handle": "CISAgov",
        "author_name": "CISA",
        "captured_day": "2026-07-24",
        "captured_at": "2026-07-24T12:00:00.000Z",
        "category": "security"
      },
      "title": "CISA BOD 26-04: guidance to improve vulnerability management policies and processes.",
      "summary": "CISA BOD 26-04: guidance to improve vulnerability management policies and processes.\nhttps://go.dhs.gov/5cY",
      "lesson": "Federal BOD on vuln management — align enterprise PSIRT policy.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "public_or_identifier",
        "basis": "advisory_or_cve_language"
      },
      "links": {
        "source_post": "https://x.com/i/status/2080752566971875740",
        "references": [
          "https://go.dhs.gov/5cY"
        ]
      },
      "engagement": {
        "likes": 80,
        "reposts": 35,
        "replies": 4,
        "bookmarks": 30,
        "views": 11137,
        "score": 267,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-24T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "8ce1889871180e7fedf96c77a6b5ba78c025d28bb82241f5132fef4fef17a13c"
    },
    {
      "id": "laitest:x:2080650740016570626",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2080650740016570626",
        "url": "https://x.com/i/status/2080650740016570626",
        "author_handle": "CISAgov",
        "author_name": "CISA",
        "captured_day": "2026-07-24",
        "captured_at": "2026-07-24T12:00:00.000Z",
        "category": "security"
      },
      "title": "FedRAMP Summit: CISA collaboration on trusted cybersecurity solutions, operational visibility, and vulnerability management.",
      "summary": "FedRAMP Summit: CISA collaboration on trusted cybersecurity solutions, operational visibility, and vulnerability management.",
      "lesson": "FedRAMP + vuln management visibility remains a procurement driver.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "public_or_identifier",
        "basis": "advisory_or_cve_language"
      },
      "links": {
        "source_post": "https://x.com/i/status/2080650740016570626",
        "references": [
          "https://go.dhs.gov/4De"
        ]
      },
      "engagement": {
        "likes": 43,
        "reposts": 16,
        "replies": 3,
        "bookmarks": 4,
        "views": 7223,
        "score": 113,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-24T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "c0fd0e130857c5bdf8645fc4bafec8b6bb4e1b61a6d3aa6649e10c45758ddbe1"
    },
    {
      "id": "laitest:x:2080341328299221148",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2080341328299221148",
        "url": "https://x.com/i/status/2080341328299221148",
        "author_handle": "AdePelumi15",
        "author_name": "Oluwapelumi",
        "captured_day": "2026-07-23",
        "captured_at": "2026-07-23T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "DevSecOps: “Shift left, Verify Right” — security that doesn’t slow development.",
      "summary": "DevSecOps: “Shift left, Verify Right” — security that doesn’t slow development.\nhttps://medium.com/@AdePelumi15/shift-left-verify-right-building-security-that-doesnt-slow-down-development-df4e0458f16e",
      "lesson": "Shift-left without verify-right is theater.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "language_medium"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2080341328299221148",
        "references": [
          "https://medium.com/@AdePelumi15/shift-left-verify-right-building-security-that-doesnt-slow-down-development-df4e0458f16e"
        ]
      },
      "engagement": {
        "likes": 23,
        "reposts": 3,
        "replies": 1,
        "bookmarks": 9,
        "views": 2444,
        "score": 55,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-23T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "5ca03dc45d85f641891e77e6698ff2abe31d805f57ebd00b675bd443551ddc47"
    },
    {
      "id": "laitest:x:2080078840186147212",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2080078840186147212",
        "url": "https://x.com/i/status/2080078840186147212",
        "author_handle": "simonw",
        "author_name": "Simon Willison",
        "captured_day": "2026-07-22",
        "captured_at": "2026-07-22T12:00:00.000Z",
        "category": "security"
      },
      "title": "I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging F…",
      "summary": "I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark https://simonwillison.net/2026/Jul/22/openai-cyberattack/",
      "lesson": "Independent writeups turn lab incidents into shared defender knowledge — don't dismiss as marketing.",
      "incident_types": [
        "agent_or_ai_risk",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2080078840186147212",
        "references": [
          "https://simonwillison.net/2026/Jul/22/openai-cyberattack/"
        ]
      },
      "engagement": {
        "likes": 784,
        "reposts": 96,
        "replies": 53,
        "bookmarks": 601,
        "views": 210637,
        "score": 2695,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-22T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "60970ad4ec2add3c8238d7ae9072dfcefc6d25f19d7ceb0af70bcbe7450ade6b"
    },
    {
      "id": "laitest:x:2080080034866610598",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2080080034866610598",
        "url": "https://x.com/i/status/2080080034866610598",
        "author_handle": "simonw",
        "author_name": "Simon Willison",
        "captured_day": "2026-07-22",
        "captured_at": "2026-07-22T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hug…",
      "summary": "Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick\n\nFrontier models can find and exploit vulnerabilities now, it helps nobody to pretend that they can't!",
      "lesson": "Treat cyber-capable model incidents as real capability signals, not PR theater.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2080080034866610598",
        "references": []
      },
      "engagement": {
        "likes": 1159,
        "reposts": 102,
        "replies": 95,
        "bookmarks": 177,
        "views": 111381,
        "score": 2042,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-22T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "5b569d13aa3839e6a5c4961d57e5080f6e1dd1684bd2a0a8dd75a79ecc21d213"
    },
    {
      "id": "laitest:x:2079699656259604617",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2079699656259604617",
        "url": "https://x.com/i/status/2079699656259604617",
        "author_handle": "HissyNC",
        "author_name": "菱川拓郎",
        "captured_day": "2026-07-22",
        "captured_at": "2026-07-22T12:00:00.000Z",
        "category": "security"
      },
      "title": "wp2shell（CVE-2026-63030）を「入口で止められない」理由と、ランタイムで捕まえる設計 https://qiita.com/keitah/items/437ab259b8b52e8cf090",
      "summary": "wp2shell（CVE-2026-63030）を「入口で止められない」理由と、ランタイムで捕まえる設計 https://qiita.com/keitah/items/437ab259b8b52e8cf090",
      "lesson": "Some WordPress RCEs bypass WAF at the edge — design for runtime detection, not perimeter-only.",
      "incident_types": [
        "cve",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [
          "CVE-2026-63030"
        ],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "wordpress"
        ]
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords",
          "cve_identifier_present"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "public_or_identifier",
        "basis": "advisory_or_cve_language"
      },
      "links": {
        "source_post": "https://x.com/i/status/2079699656259604617",
        "references": [
          "https://qiita.com/keitah/items/437ab259b8b52e8cf090"
        ]
      },
      "engagement": {
        "likes": 33,
        "reposts": 7,
        "replies": 1,
        "bookmarks": 29,
        "views": 3899,
        "score": 120,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "enrich_and_match_sbom",
        "match_hints": {
          "cve_ids": [
            "CVE-2026-63030"
          ],
          "package_hints": [
            "wordpress"
          ]
        }
      },
      "first_seen_at": "2026-07-22T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "3cdabfe1d1dcffe44b8f4ab0ce741e645cb7618529b3308041033bd50dc5c2bc"
    },
    {
      "id": "laitest:x:2079658951264920020",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2079658951264920020",
        "url": "https://x.com/i/status/2079658951264920020",
        "author_handle": "OpenAI",
        "author_name": "OpenAI",
        "captured_day": "2026-07-21",
        "captured_at": "2026-07-21T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "We're partnering with @huggingface to investigate an unprecedented security incident.",
      "summary": "We're partnering with @huggingface to investigate an unprecedented security incident.\n\nCyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.\n\nSharing preliminary findings to help defenders understand emerging risks:",
      "lesson": "Eval sandboxes are production-adjacent: cyber-capable models will chain zero-days if they can.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2079658951264920020",
        "references": [
          "https://openai.com/index/hugging-face-model-evaluation-security-incident/"
        ]
      },
      "engagement": {
        "likes": 20764,
        "reposts": 3237,
        "replies": 2000,
        "bookmarks": 7513,
        "views": 30616867,
        "score": 46501,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-21T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "564a495d59709f5dd451b9395f2cf63c6253cdad4ad34f25e3d3d2712901e235"
    },
    {
      "id": "laitest:x:2079661132302995790",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2079661132302995790",
        "url": "https://x.com/i/status/2079661132302995790",
        "author_handle": "sama",
        "author_name": "Sam Altman",
        "captured_day": "2026-07-21",
        "captured_at": "2026-07-21T12:00:00.000Z",
        "category": "security"
      },
      "title": "we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingfac…",
      "summary": "we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingface for the partnership on this.\n\nhttps://openai.com/index/hugging-face-model-evaluation-security-incident/",
      "lesson": "Transparent incident writeups from labs set the bar for agent cyber risk disclosure.",
      "incident_types": [
        "agent_or_ai_risk",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2079661132302995790",
        "references": [
          "https://openai.com/index/hugging-face-model-evaluation-security-incident/"
        ]
      },
      "engagement": {
        "likes": 17471,
        "reposts": 2087,
        "replies": 2160,
        "bookmarks": 6564,
        "views": 10057335,
        "score": 37860,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-21T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "a815833af974adf2ea79bda6194c8e3a924b8e5d358bfb534760749b2e255a78"
    },
    {
      "id": "laitest:x:2079704321244225965",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2079704321244225965",
        "url": "https://x.com/i/status/2079704321244225965",
        "author_handle": "connect24h",
        "author_name": "connect24h",
        "captured_day": "2026-07-21",
        "captured_at": "2026-07-21T12:00:00.000Z",
        "category": "security"
      },
      "title": "Qilin ransomware exploiting PAN-OS GlobalProtect auth bypass CVE-2026-0257 (CVSS 7.8). Arctic Wolf confirmed domain-wide encryption cases…",
      "summary": "Qilin ransomware exploiting PAN-OS GlobalProtect auth bypass CVE-2026-0257 (CVSS 7.8). Arctic Wolf confirmed domain-wide encryption cases. CISA KEV-listed. Affects PAN-OS 10.2, 11.1, 11.2, 12.1 and some Prisma Access. Hunt GlobalProtect admin logins from VPS, kali hostnames, PsExec paths.",
      "lesson": "VPN edge CVEs still unlock full-domain ransomware — patch KEV + hunt for VPS admin sessions.",
      "incident_types": [
        "cve",
        "kev_or_active_exploit",
        "ransomware",
        "high_impact_vuln_class",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [
          "CVE-2026-0257"
        ],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "pan-os",
          "globalprotect"
        ]
      },
      "severity": {
        "hint": "critical",
        "label": "Critical (text)",
        "basis": [
          "language_critical_or_rce_or_kev",
          "cve_identifier_present"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": "mentioned",
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "public_or_identifier",
        "basis": "advisory_or_cve_language"
      },
      "links": {
        "source_post": "https://x.com/i/status/2079704321244225965",
        "references": []
      },
      "engagement": {
        "likes": 73,
        "reposts": 12,
        "replies": 2,
        "bookmarks": 24,
        "views": 5036,
        "score": 167,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "enrich_and_match_sbom",
        "match_hints": {
          "cve_ids": [
            "CVE-2026-0257"
          ],
          "package_hints": [
            "pan-os",
            "globalprotect"
          ]
        }
      },
      "first_seen_at": "2026-07-21T12:00:00.000Z",
      "updated_at": "2026-07-21T12:00:00.000Z",
      "content_hash": "6c24bb51aa1a9bafbc2573bdf79c8e7dec33cf7fa15d0a75a4d89f82b1360754"
    },
    {
      "id": "laitest:x:2079301434357456931",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2079301434357456931",
        "url": "https://x.com/i/status/2079301434357456931",
        "author_handle": "ClementDelangue",
        "author_name": "clem",
        "captured_day": "2026-07-20",
        "captured_at": "2026-07-20T12:00:00.000Z",
        "category": "security"
      },
      "title": "Banning open-source AI would hurt defenders 10x more than attackers, which would make the world 10x more dangerous and this is a good exa…",
      "summary": "Banning open-source AI would hurt defenders 10x more than attackers, which would make the world 10x more dangerous and this is a good example why!",
      "lesson": "OSS AI bans asymmetrically disarm defenders while attackers already bypass hosted guardrails.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2079301434357456931",
        "references": []
      },
      "engagement": {
        "likes": 2785,
        "reposts": 407,
        "replies": 76,
        "bookmarks": 257,
        "views": 130799,
        "score": 4782,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-20T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "97a45824a734f1ad91d363ba0e768ef3eeb6d512cddcbc9844b969553c42d13a"
    },
    {
      "id": "laitest:x:2079253659108409587",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2079253659108409587",
        "url": "https://x.com/i/status/2079253659108409587",
        "author_handle": "ClementDelangue",
        "author_name": "clem",
        "captured_day": "2026-07-20",
        "captured_at": "2026-07-20T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "The cybersecurity debate on open-source AI is backwards. Open models aren't the risk, they're the defense! Attackers can already jailbrea…",
      "summary": "The cybersecurity debate on open-source AI is backwards. Open models aren't the risk, they're the defense! Attackers can already jailbreak any API or guardrails. Defenders can't secure systems with black boxes they can't control, inspect, test, or run locally.",
      "lesson": "Open weights = inspectable defender tooling; closed APIs create forensics blind spots.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2079253659108409587",
        "references": []
      },
      "engagement": {
        "likes": 226,
        "reposts": 50,
        "replies": 23,
        "bookmarks": 31,
        "views": 20661,
        "score": 479,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-20T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "215759c2293d86c1e67a1e21f3a9f73fd11ef83092ce11a72e010f2ede1345c5"
    },
    {
      "id": "laitest:x:2078840929088340408",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2078840929088340408",
        "url": "https://x.com/i/status/2078840929088340408",
        "author_handle": "BrianRoemmele",
        "author_name": "Brian Roemmele",
        "captured_day": "2026-07-19",
        "captured_at": "2026-07-19T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Hugging Face disclosed: an autonomous AI agent (zero human operator) breached part of production via a malicious dataset chaining two cod…",
      "summary": "Hugging Face disclosed: an autonomous AI agent (zero human operator) breached part of production via a malicious dataset chaining two code-execution bugs. 17,000+ actions over a weekend.\n\nWhen HF security tried frontier APIs for forensics, safety guardrails blocked them. They fell back to self-hosted GLM 5.2 to keep attacker data inside the perimeter.",
      "lesson": "Agentic offense outpaces API guardrails; defender sovereignty = open-weight forensics on-prem.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2078840929088340408",
        "references": []
      },
      "engagement": {
        "likes": 6090,
        "reposts": 1256,
        "replies": 319,
        "bookmarks": 4400,
        "views": 1511463,
        "score": 19658,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-19T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "ca6ce85a51477822139713fa46868dc15cf5da0f4626347bf2c768e39d9d5826"
    },
    {
      "id": "laitest:x:2078987852495364398",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2078987852495364398",
        "url": "https://x.com/i/status/2078987852495364398",
        "author_handle": "ClementDelangue",
        "author_name": "clem",
        "captured_day": "2026-07-19",
        "captured_at": "2026-07-19T12:00:00.000Z",
        "category": "security"
      },
      "title": "We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing",
      "summary": "We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing",
      "lesson": "Hosted safety filters can block defender forensics mid-incident — self-hosted open weights fix that.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2078987852495364398",
        "references": []
      },
      "engagement": {
        "likes": 589,
        "reposts": 48,
        "replies": 8,
        "bookmarks": 76,
        "views": 240720,
        "score": 1366,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-19T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "1afc30e4369ccca6b9a06e399b3df7a208a1f482c86c138e4411e8e6c2cf21bb"
    },
    {
      "id": "laitest:x:2078630525179420970",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2078630525179420970",
        "url": "https://x.com/i/status/2078630525179420970",
        "author_handle": "tmichiaki",
        "author_name": "みちアキ",
        "captured_day": "2026-07-18",
        "captured_at": "2026-07-18T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "生成AIを使う使わないの話で、より一般的な原則にようやく気付いた",
      "summary": "生成AIを使う使わないの話で、より一般的な原則にようやく気付いた\n\n「客観的に判定不可能な基準をルールに含めてはいけない」\n\nコンテストや競技にそういうルールがあるのは致命的では",
      "lesson": "Policy lesson: never put non-objective criteria in AI contest rules — unenforceable bans fail.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2078630525179420970",
        "references": []
      },
      "engagement": {
        "likes": 204,
        "reposts": 59,
        "replies": 5,
        "bookmarks": 17,
        "views": 14471,
        "score": 444,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-18T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "60c8053cda06b9f05c0ebdd89d338c1325cfed39289417e250e9f69d880b6630"
    },
    {
      "id": "laitest:x:2078243667081617826",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2078243667081617826",
        "url": "https://x.com/i/status/2078243667081617826",
        "author_handle": "OpenAI",
        "author_name": "OpenAI",
        "captured_day": "2026-07-17",
        "captured_at": "2026-07-17T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "GPT-5.6 Sol sets a new state of the art in cybersecurity on “The Last Ones” cyber range.",
      "summary": "GPT-5.6 Sol sets a new state of the art in cybersecurity on “The Last Ones” cyber range.\n\nWe’re already seeing that capability translate into defensive outcomes: helping teams find, validate, and fix vulnerabilities in real-world code.\n\nPut it to work with Codex Security:",
      "lesson": "Defensive cyber SOTA ships as a product plugin (Codex Security) — evals that become workflows win.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2078243667081617826",
        "references": []
      },
      "engagement": {
        "likes": 3959,
        "reposts": 368,
        "replies": 252,
        "bookmarks": 600,
        "views": 740260,
        "score": 7263,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-17T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "8e30d5940a115831e79b32aa1edd9c2473a3357f6987fcdb3578a34ae27e1f3e"
    },
    {
      "id": "laitest:x:2078248095033540693",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2078248095033540693",
        "url": "https://x.com/i/status/2078248095033540693",
        "author_handle": "RussianPanda9xx",
        "author_name": "RussianPanda",
        "captured_day": "2026-07-17",
        "captured_at": "2026-07-17T12:00:00.000Z",
        "category": "security"
      },
      "title": "I tested two AI models on the same malware reversing challenge: the Temu version of Claude (Kimi K3) vs Claude itself.",
      "summary": "I tested two AI models on the same malware reversing challenge: the Temu version of Claude (Kimi K3) vs Claude itself.\nThe challenge: analyze a Remus stealer using AI reverser skills - find the encrypted C2s and decrypt them.\n\nClaude Sonnet 4.6 (max) → 17:00 - 85 tool calls\nKimi K3 (max) → 25:00 - 37 tool calls\n\nBoth found obfuscated string tables, ChaCha20, and decrypted C2s. Kimi also found a fallback C2 behind an Ethereum contract (EtherHiding).",
      "lesson": "Malware reverse evals are a real yardstick: fewer bigger tool calls can beat speed-only runs.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2078248095033540693",
        "references": []
      },
      "engagement": {
        "likes": 155,
        "reposts": 18,
        "replies": 18,
        "bookmarks": 43,
        "views": 7577,
        "score": 310,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-17T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "43465119e688aed0a219ba8697e18a1dc7b17e21a4dc5ab37bdda99b80b4a02b"
    },
    {
      "id": "laitest:x:2078227318624153632",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2078227318624153632",
        "url": "https://x.com/i/status/2078227318624153632",
        "author_handle": "IntCyberDigest",
        "author_name": "International Cyber Digest",
        "captured_day": "2026-07-17",
        "captured_at": "2026-07-17T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "‼️ Microsoft wants to compete against Anthropic's Mythos with their 'Project Perception,' an AI security product that would route vulnera…",
      "summary": "‼️ Microsoft wants to compete against Anthropic's Mythos with their 'Project Perception,' an AI security product that would route vulnerability-discovery and remediation tasks across Anthropic, OpenAI and Microsoft models.\n\nThey hope to give enterprises a lower-cost alternative to Anthropic’s restricted-access Mythos system.",
      "lesson": "Multi-model vuln routing will become the enterprise default vs single-lab closed security products.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2078227318624153632",
        "references": []
      },
      "engagement": {
        "likes": 132,
        "reposts": 9,
        "replies": 17,
        "bookmarks": 25,
        "views": 20842,
        "score": 251,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-17T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "19f12d1f5452966aa859cc94f1ccb93f56e05858e90e769ccb4f73e8e768b4d8"
    },
    {
      "id": "laitest:x:2077743858239094854",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077743858239094854",
        "url": "https://x.com/i/status/2077743858239094854",
        "author_handle": "1Password",
        "author_name": "1Password",
        "captured_day": "2026-07-16",
        "captured_at": "2026-07-16T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "AI agents are booking travel, signing into websites, and acting on your behalf. That creates a new security problem: until now, letting a…",
      "summary": "AI agents are booking travel, signing into websites, and acting on your behalf. That creates a new security problem: until now, letting an agent log in meant exposing your credentials to the model.\n\nToday, with @AnthropicAI, we're changing that. 1Password for @claudeai lets Claude use your stored credentials to complete real-world tasks without your passwords or one-time codes ever reaching the model, its memory, or Anthropic's systems.\n\nYou stay in control and approve which credentials an agent can use. 1Password handles authentication behind the scenes.\n\nAvailable now on Mac for business, family, and individual customers.",
      "lesson": "Credential broker pattern: agent never sees secrets; user approves; vault fills auth out-of-band.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "high",
        "label": "High (text)",
        "basis": [
          "language_high_or_leak_or_compromise"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077743858239094854",
        "references": []
      },
      "engagement": {
        "likes": 2331,
        "reposts": 239,
        "replies": 119,
        "bookmarks": 1297,
        "views": 537789,
        "score": 6642,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-16T12:00:00.000Z",
      "updated_at": "2026-07-27T03:39:01.635Z",
      "content_hash": "77a6a3165a0d0eb48a7e7531ec82932716004153eec2595a2b9095b271801905"
    },
    {
      "id": "laitest:x:2077535896497471597",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077535896497471597",
        "url": "https://x.com/i/status/2077535896497471597",
        "author_handle": "0x0SojalSec",
        "author_name": "Md Ismail Šojal",
        "captured_day": "2026-07-15",
        "captured_at": "2026-07-15T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Open-sourced fully autonomous AI Red Team — multi-agent LangGraph, Neo4j attack graphs, Sliver C2 in sandbox.",
      "summary": "Open-sourced fully autonomous AI Red Team — multi-agent LangGraph, Neo4j attack graphs, Sliver C2 in sandbox.",
      "lesson": "Autonomous red team packages accelerating; authorize carefully.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077535896497471597",
        "references": []
      },
      "engagement": {
        "likes": 225,
        "reposts": 47,
        "replies": 5,
        "bookmarks": 224,
        "views": 8441,
        "score": 831,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-15T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "2ec83d5c7f2631a96a6eaadd9357917a5335aaae4b2aeb67f137c57042c4f495"
    },
    {
      "id": "laitest:x:2077341123421638968",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077341123421638968",
        "url": "https://x.com/i/status/2077341123421638968",
        "author_handle": "z41zen",
        "author_name": "Shota Zaizen",
        "captured_day": "2026-07-15",
        "captured_at": "2026-07-15T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "[$4,500] Remote Code Execution Vulnerability in Meta's Manus AI #bugbounty",
      "summary": "[$4,500] Remote Code Execution Vulnerability in Meta's Manus AI #bugbounty\nhttps://zaizen.me/blog/manus-ai-deep-link-rce.html",
      "lesson": "Agent deep-link handlers are a new RCE surface — treat client→agent URL schemes as untrusted input.",
      "incident_types": [
        "agent_or_ai_risk",
        "high_impact_vuln_class",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "critical",
        "label": "Critical (text)",
        "basis": [
          "language_critical_or_rce_or_kev"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077341123421638968",
        "references": [
          "https://zaizen.me/blog/manus-ai-deep-link-rce.html"
        ]
      },
      "engagement": {
        "likes": 295,
        "reposts": 39,
        "replies": 5,
        "bookmarks": 174,
        "views": 12320,
        "score": 785,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-15T12:00:00.000Z",
      "updated_at": "2026-07-15T12:00:00.000Z",
      "content_hash": "fbed85deaae377be9f62f393389aca1b25b40fe635eafb66e806e88ec2f157e9"
    },
    {
      "id": "laitest:x:2077533847789486162",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077533847789486162",
        "url": "https://x.com/i/status/2077533847789486162",
        "author_handle": "PawelHuryn",
        "author_name": "Paweł Huryn",
        "captured_day": "2026-07-15",
        "captured_at": "2026-07-15T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Claude Code artifacts can call MCP connectors — runs as viewer, limited tools, consent per connector not action; org-share only.",
      "summary": "Claude Code artifacts can call MCP connectors — runs as viewer, limited tools, consent per connector not action; org-share only.",
      "lesson": "Artifact+MCP = product security review of least privilege & consent UX.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077533847789486162",
        "references": []
      },
      "engagement": {
        "likes": 182,
        "reposts": 9,
        "replies": 11,
        "bookmarks": 174,
        "views": 28651,
        "score": 614,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-15T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "e43dc379bdf195e2c4ea522ea4e8621293e97a0347d507edd0544447d869168d"
    },
    {
      "id": "laitest:x:2077528271848346040",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077528271848346040",
        "url": "https://x.com/i/status/2077528271848346040",
        "author_handle": "ken5scal",
        "author_name": "ken\\d\\x",
        "captured_day": "2026-07-15",
        "captured_at": "2026-07-15T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "1Password Credential Broker for CI/CD and AI agents — short-lived creds via workload identity; GitHub Actions beta.",
      "summary": "1Password Credential Broker for CI/CD and AI agents — short-lived creds via workload identity; GitHub Actions beta.\nhttps://1password.com/blog/introducing-1password-credential-broker",
      "lesson": "Agent credential brokers are product security infrastructure.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077528271848346040",
        "references": [
          "https://1password.com/blog/introducing-1password-credential-broker"
        ]
      },
      "engagement": {
        "likes": 55,
        "reposts": 15,
        "replies": 1,
        "bookmarks": 26,
        "views": 5590,
        "score": 163,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-15T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "a2a7c24a86bdac417d85051b745c81be7af048e4f7e29a434dc807748a388332"
    },
    {
      "id": "laitest:x:2077404122605580361",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077404122605580361",
        "url": "https://x.com/i/status/2077404122605580361",
        "author_handle": "CISAgov",
        "author_name": "CISA",
        "captured_day": "2026-07-15",
        "captured_at": "2026-07-15T12:00:00.000Z",
        "category": "security"
      },
      "title": "Joint guidance for coordinated vulnerability disclosure programs with security researchers.",
      "summary": "Joint guidance for coordinated vulnerability disclosure programs with security researchers.\nhttps://go.dhs.gov/5Am",
      "lesson": "CVD program guidance is evergreen PSIRT policy content.",
      "incident_types": [
        "advisory_or_disclosure",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077404122605580361",
        "references": [
          "https://go.dhs.gov/5Am"
        ]
      },
      "engagement": {
        "likes": 37,
        "reposts": 19,
        "replies": 3,
        "bookmarks": 7,
        "views": 5780,
        "score": 120,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-15T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "10b39a6170f9dbf7187b3d54829d2958a55eeb961ccabd54821fe44dfe8d4aa3"
    },
    {
      "id": "laitest:x:2077106799543537749",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077106799543537749",
        "url": "https://x.com/i/status/2077106799543537749",
        "author_handle": "DarkWebInformer",
        "author_name": "Dark Web Informer",
        "captured_day": "2026-07-14",
        "captured_at": "2026-07-14T12:00:00.000Z",
        "category": "security"
      },
      "title": "Nightmare Eclipse PoC LegacyHive — Windows user profile service arbitrary hive load EoP.",
      "summary": "Nightmare Eclipse PoC LegacyHive — Windows user profile service arbitrary hive load EoP.\nhttps://github.com/MSNightmare/LegacyHive",
      "lesson": "Classic Windows priv-esc still shipping PoCs alongside AI security noise.",
      "incident_types": [
        "oss_library",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "github:MSNightmare/LegacyHive"
        ]
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077106799543537749",
        "references": [
          "https://github.com/MSNightmare/LegacyHive"
        ]
      },
      "engagement": {
        "likes": 219,
        "reposts": 46,
        "replies": 0,
        "bookmarks": 84,
        "views": 22694,
        "score": 570,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "enrich_and_match_sbom",
        "match_hints": {
          "cve_ids": [],
          "package_hints": [
            "github:MSNightmare/LegacyHive"
          ]
        }
      },
      "first_seen_at": "2026-07-14T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "a629a5b314ff029988351aec203ef3500162d98bbd4219446e15ac2d11d17348"
    },
    {
      "id": "laitest:x:2077124020504612944",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077124020504612944",
        "url": "https://x.com/i/status/2077124020504612944",
        "author_handle": "wallstengine",
        "author_name": "Wall St Engine",
        "captured_day": "2026-07-14",
        "captured_at": "2026-07-14T12:00:00.000Z",
        "category": "security"
      },
      "title": "White House launched GOLD EAGLE — cybersecurity vulnerability coordination for AI and critical infrastructure.",
      "summary": "White House launched GOLD EAGLE — cybersecurity vulnerability coordination for AI and critical infrastructure.",
      "lesson": "National vuln coordination expanding to AI + critical infra.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "critical",
        "label": "Critical (text)",
        "basis": [
          "language_critical_or_rce_or_kev"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077124020504612944",
        "references": []
      },
      "engagement": {
        "likes": 140,
        "reposts": 16,
        "replies": 14,
        "bookmarks": 15,
        "views": 66637,
        "score": 351,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "analyst_triage",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-14T12:00:00.000Z",
      "updated_at": "2026-07-14T12:00:00.000Z",
      "content_hash": "beac0530d326a4886b76a5ecd1ecb340f03c6adf6347bc4532f11057cf6d52b8"
    },
    {
      "id": "laitest:x:2077068171010576748",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077068171010576748",
        "url": "https://x.com/i/status/2077068171010576748",
        "author_handle": "The_Cyber_News",
        "author_name": "Cyber Security News",
        "captured_day": "2026-07-14",
        "captured_at": "2026-07-14T12:00:00.000Z",
        "category": "security"
      },
      "title": "Fortinet FortiSandbox high-severity: unauth access to VNC of malware-scanning VMs.",
      "summary": "Fortinet FortiSandbox high-severity: unauth access to VNC of malware-scanning VMs.",
      "lesson": "Vendor PSIRT/CVD news remains core product security feed.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077068171010576748",
        "references": []
      },
      "engagement": {
        "likes": 129,
        "reposts": 35,
        "replies": 7,
        "bookmarks": 25,
        "views": 12059,
        "score": 308,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-14T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "5204b6338e1e56249e497c9d0d49a7ed035d3b0cdf739419628399a8539589b1"
    },
    {
      "id": "laitest:x:2077075462157996423",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2077075462157996423",
        "url": "https://x.com/i/status/2077075462157996423",
        "author_handle": "octane_security",
        "author_name": "Octane Security",
        "captured_day": "2026-07-14",
        "captured_at": "2026-07-14T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Stack passed dependabot/secrets/GH/AWS scanning + annual pentest; agentic analysis found a bug those tools miss.",
      "summary": "Stack passed dependabot/secrets/GH/AWS scanning + annual pentest; agentic analysis found a bug those tools miss.",
      "lesson": "Agentic analysis claims coverage beyond SCA/SAST/secrets.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "high",
        "label": "High (text)",
        "basis": [
          "language_high_or_leak_or_compromise"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2077075462157996423",
        "references": []
      },
      "engagement": {
        "likes": 16,
        "reposts": 5,
        "replies": 2,
        "bookmarks": 2,
        "views": 952,
        "score": 37,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "analyst_triage",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-14T12:00:00.000Z",
      "updated_at": "2026-07-27T03:39:01.635Z",
      "content_hash": "9514b8511ef95c6bf166afc206b7e19cc373a45a78427cdc01655c4ee525c333"
    },
    {
      "id": "laitest:x:2076621144497762791",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076621144497762791",
        "url": "https://x.com/i/status/2076621144497762791",
        "author_handle": "VivekIntel",
        "author_name": "Vivek | Cybersecurity",
        "captured_day": "2026-07-13",
        "captured_at": "2026-07-13T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "LVRP – Local Vulnerability Research Pipeline: hybrid code graph + LLM validation for white-box audits; local-only, multi-language, CVE en…",
      "summary": "LVRP – Local Vulnerability Research Pipeline: hybrid code graph + LLM validation for white-box audits; local-only, multi-language, CVE enrichment.",
      "lesson": "Hybrid deterministic graph + LLM validation is the AppSec architecture pattern.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076621144497762791",
        "references": []
      },
      "engagement": {
        "likes": 77,
        "reposts": 16,
        "replies": 1,
        "bookmarks": 76,
        "views": 3463,
        "score": 284,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-13T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "1a875c43da58f3c4b6792eb37a85bda39145ac4a3e1fefc7f1e944ef1208f214"
    },
    {
      "id": "laitest:x:2076812331908993331",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076812331908993331",
        "url": "https://x.com/i/status/2076812331908993331",
        "author_handle": "tom_doerr",
        "author_name": "Tom Dörr",
        "captured_day": "2026-07-13",
        "captured_at": "2026-07-13T12:00:00.000Z",
        "category": "security"
      },
      "title": "Security resources for 75 industrial network protocols",
      "summary": "Security resources for 75 industrial network protocols\n\nhttps://github.com/Orange-Cyberdefense/awesome-industrial-protocols",
      "lesson": "OT/ICS protocol maps are required reading as AI ops touch industrial networks.",
      "incident_types": [
        "oss_library",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "github:Orange-Cyberdefense/awesome-industrial-protocols"
        ]
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076812331908993331",
        "references": [
          "https://github.com/Orange-Cyberdefense/awesome-industrial-protocols"
        ]
      },
      "engagement": {
        "likes": 67,
        "reposts": 10,
        "replies": 0,
        "bookmarks": 72,
        "views": 7089,
        "score": 255,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "enrich_and_match_sbom",
        "match_hints": {
          "cve_ids": [],
          "package_hints": [
            "github:Orange-Cyberdefense/awesome-industrial-protocols"
          ]
        }
      },
      "first_seen_at": "2026-07-13T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "38bfd363191b0e0be7a4c93e8184ce9a76b74b2e3dbe0c90672154dc60240c24"
    },
    {
      "id": "laitest:x:2076717856457200102",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076717856457200102",
        "url": "https://x.com/i/status/2076717856457200102",
        "author_handle": "tom_doerr",
        "author_name": "Tom Dörr",
        "captured_day": "2026-07-13",
        "captured_at": "2026-07-13T12:00:00.000Z",
        "category": "security"
      },
      "title": "A comprehensive guide to adversarial testing and security evaluation of AI systems, detailing how to identify vulnerabilities before expl…",
      "summary": "A comprehensive guide to adversarial testing and security evaluation of AI systems, detailing how to identify vulnerabilities before exploitation using NIST, OWASP, and MITRE frameworks.\n\nhttps://github.com/requie/AI-Red-Teaming-Guide",
      "lesson": "Standard red-team guides (NIST/OWASP/MITRE) for AI are becoming table stakes.",
      "incident_types": [
        "oss_library",
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "github:requie/AI-Red-Teaming-Guide"
        ]
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076717856457200102",
        "references": [
          "https://github.com/requie/AI-Red-Teaming-Guide"
        ]
      },
      "engagement": {
        "likes": 38,
        "reposts": 7,
        "replies": 1,
        "bookmarks": 61,
        "views": 8142,
        "score": 197,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "enrich_and_match_sbom",
        "match_hints": {
          "cve_ids": [],
          "package_hints": [
            "github:requie/AI-Red-Teaming-Guide"
          ]
        }
      },
      "first_seen_at": "2026-07-13T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "90a726bf4e0608c823bbb92b9c439d03c4b2f774feeaba73ab9ff724469ea025"
    },
    {
      "id": "laitest:x:2076614120032612828",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076614120032612828",
        "url": "https://x.com/i/status/2076614120032612828",
        "author_handle": "7h3h4ckv157",
        "author_name": "7h3h4ckv157",
        "captured_day": "2026-07-13",
        "captured_at": "2026-07-13T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Exhaustive LLM-driven whitebox vulnerability research pipeline on code graph + hybrid architecture; scales to Linux kernel, VSCode, etc.",
      "summary": "Exhaustive LLM-driven whitebox vulnerability research pipeline on code graph + hybrid architecture; scales to Linux kernel, VSCode, etc.",
      "lesson": "White-box AI audits targeting real large codebases.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076614120032612828",
        "references": []
      },
      "engagement": {
        "likes": 57,
        "reposts": 6,
        "replies": 3,
        "bookmarks": 28,
        "views": 3584,
        "score": 138,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-13T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "168fc10eb75068600e03fd6e88bb2d5b6a77c047c7cb905f5fcaef383d4d54ab"
    },
    {
      "id": "laitest:x:2076591205522014229",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076591205522014229",
        "url": "https://x.com/i/status/2076591205522014229",
        "author_handle": "AdePelumi15",
        "author_name": "Oluwapelumi",
        "captured_day": "2026-07-13",
        "captured_at": "2026-07-13T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "First contribution merged into securego/gosec — AWS STS temporary access keys (ASIA) detection for hardcoded credentials.",
      "summary": "First contribution merged into securego/gosec — AWS STS temporary access keys (ASIA) detection for hardcoded credentials.",
      "lesson": "SCA/SAST tooling still advances via small high-value detectors.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076591205522014229",
        "references": []
      },
      "engagement": {
        "likes": 38,
        "reposts": 5,
        "replies": 0,
        "bookmarks": 2,
        "views": 1851,
        "score": 61,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-13T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "e5339a324ea3e90a4d63563169ada41003fc80aec2328a03251a287dfdfbb3c8"
    },
    {
      "id": "laitest:x:2076665632045633903",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076665632045633903",
        "url": "https://x.com/i/status/2076665632045633903",
        "author_handle": "testmachine_ai",
        "author_name": "TestMachine",
        "captured_day": "2026-07-13",
        "captured_at": "2026-07-13T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Validation critical: detection finds possibilities; Azimuth tests exploit path to confirm real vulns — AI security without validation was…",
      "summary": "Validation critical: detection finds possibilities; Azimuth tests exploit path to confirm real vulns — AI security without validation wastes time.",
      "lesson": "Exploit validation separates product security signal from AI noise.",
      "incident_types": [
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "critical",
        "label": "Critical (text)",
        "basis": [
          "language_critical_or_rce_or_kev"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076665632045633903",
        "references": []
      },
      "engagement": {
        "likes": 15,
        "reposts": 4,
        "replies": 2,
        "bookmarks": 5,
        "views": 1130,
        "score": 39,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "analyst_triage",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-13T12:00:00.000Z",
      "updated_at": "2026-07-13T12:00:00.000Z",
      "content_hash": "39b32156ca516e6054f865ff1d5a0f0b1aed1107bb5a97a46d112793c093162b"
    },
    {
      "id": "laitest:x:2076177465362313579",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076177465362313579",
        "url": "https://x.com/i/status/2076177465362313579",
        "author_handle": "moneyacademyKE",
        "author_name": "Moe",
        "captured_day": "2026-07-12",
        "captured_at": "2026-07-12T12:00:00.000Z",
        "category": "product_security"
      },
      "title": "Kenya has opened applications for its ICT regulatory sandbox, giving startups and tech firms a chance to test AI, 5G/6G, IoT and other di…",
      "summary": "Kenya has opened applications for its ICT regulatory sandbox, giving startups and tech firms a chance to test AI, 5G/6G, IoT and other digital technologies in a regulated environment before launching them",
      "lesson": "Regulated sandboxes are how jurisdictions de-risk AI + connectivity pilots before full market launch.",
      "incident_types": [
        "agent_or_ai_risk",
        "product_security"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": []
      },
      "severity": {
        "hint": "elevated",
        "label": "Elevated",
        "basis": [
          "incident_type_or_security_keywords"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076177465362313579",
        "references": []
      },
      "engagement": {
        "likes": 1212,
        "reposts": 218,
        "replies": 38,
        "bookmarks": 141,
        "views": 48859,
        "score": 2246,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "process_and_product_review",
        "match_hints": {
          "cve_ids": [],
          "package_hints": []
        }
      },
      "first_seen_at": "2026-07-12T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "02a01b54f6f8cf7231a9bca88663b7673aefb5fcbf135e00470efae83223903d"
    },
    {
      "id": "laitest:x:2076340285437624735",
      "schema_version": "1.0.0",
      "source": {
        "type": "x_post",
        "publisher": "laitest",
        "post_id": "2076340285437624735",
        "url": "https://x.com/i/status/2076340285437624735",
        "author_handle": "tom_doerr",
        "author_name": "Tom Dörr",
        "captured_day": "2026-07-12",
        "captured_at": "2026-07-12T12:00:00.000Z",
        "category": "security"
      },
      "title": "Builds a headless PwnBox and RogueAP using a Raspberry Pi and Alfa WiFi USB adapters for red team engagements.",
      "summary": "Builds a headless PwnBox and RogueAP using a Raspberry Pi and Alfa WiFi USB adapters for red team engagements.\n\nhttps://github.com/koutto/pi-pwnbox-rogueap",
      "lesson": "Portable RogueAP kits remain a core physical/wireless red-team stack.",
      "incident_types": [
        "cybersecurity"
      ],
      "identifiers": {
        "cve": [],
        "cwe": [],
        "ghsa": [],
        "packages": [
          "github:koutto/pi-pwnbox-rogueap"
        ]
      },
      "severity": {
        "hint": "watch",
        "label": "Watch",
        "basis": [
          "social_signal_default_watch"
        ],
        "assessed_at": "2026-07-27T04:13:37.989Z",
        "first_assessed_at": "2026-07-27T03:41:48.930Z",
        "previous_hint": null,
        "source": "heuristic",
        "cvss": null,
        "epss": null,
        "kev": null,
        "note": "Urgency is a feed-side operator guess from post text — not CVSS, not EPSS, not KEV. assessed_at is when this feed last re-evaluated it. Re-score from NVD/OSV/KEV/EPSS before prioritization or customer action.",
        "changed_at": null,
        "override_reason": null
      },
      "disclosure": {
        "status": "unknown",
        "basis": "insufficient_evidence"
      },
      "links": {
        "source_post": "https://x.com/i/status/2076340285437624735",
        "references": [
          "https://github.com/koutto/pi-pwnbox-rogueap"
        ]
      },
      "engagement": {
        "likes": 65,
        "reposts": 7,
        "replies": 1,
        "bookmarks": 57,
        "views": 10834,
        "score": 222,
        "note": "Engagement is heat/attention, not exploitability."
      },
      "trust": {
        "tier": "social_curated_signal",
        "confidence": "low_medium",
        "authoritative": false,
        "must_enrich": true,
        "customer_facing_without_review": false
      },
      "psirt": {
        "suggested_action": "monitor",
        "match_hints": {
          "cve_ids": [],
          "package_hints": [
            "github:koutto/pi-pwnbox-rogueap"
          ]
        }
      },
      "first_seen_at": "2026-07-12T12:00:00.000Z",
      "updated_at": "2026-07-27T03:38:41.353Z",
      "content_hash": "26bb5e07461ef0ee1037bdec2fe9efa73b8e1209dfa1b3f033a032de18b6ba83"
    }
  ],
  "feed_hash": "9322a096ef4f11453b458eb99bf4115aacccf0346b05dffe5cd464aa542c470d",
  "feed_signature": "484f9453a4ae8bc44848d6186e2c6785a594b98b266f6b5fe27a0ce5fcb5a107",
  "feed_signature_alg": "HMAC-SHA256"
}
