Command Injection via Unsanitized Bundling Options in `aws-cdk-lib/aws-lambda-nodejs` on 11/06/2026
AWS VDP disclosed a bug submitted by inkerton: https://hackerone.com/reports/3558713 [...]
AWS VDP disclosed a bug submitted by inkerton: https://hackerone.com/reports/3558713 [...]
AWS VDP disclosed a bug submitted by terrynini38514: https://hackerone.com/reports/3738654 [...]
curl disclosed a bug submitted by bugthiru: https://hackerone.com/reports/3741744 [...]
curl disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3774279 [...]
DuckDuckGo disclosed a bug submitted by 6r1ff1n: https://hackerone.com/reports/3619288 [...]
DuckDuckGo disclosed a bug submitted by 6r1ff1n: https://hackerone.com/reports/3619287 [...]
Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3383079 [...]
Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3393664 [...]
The surveillance company Leonardo wants more data: A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phones, wearables, and other Bluetooth-enabled devices in those cars, potentially letting law enforcement identify specific dr [...]
The intersection of AI and cybersecurity is reshaping how we find, fix, and think about vulnerabilities. Yet for all the headlines, few conversations cut through the noise to ask what AI means for those on the ground: the hunters, the security engineers, and the organizations trying to secure their data. In this blog, we open up that discussion, with insights from Leo Racanelli for an unflinching [...]
Entra Agent ID is an extension of Entra's application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) to multiple identities and their associated privileges, increasing the potential blast radius of a compromised agent. [...]
curl disclosed a bug submitted by monk17: https://hackerone.com/reports/3791168 [...]
curl disclosed a bug submitted by azraelxuemo: https://hackerone.com/reports/3791191 [...]
curl disclosed a bug submitted by nyymi: https://hackerone.com/reports/1826392 [...]
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group. A graphic create [...]
WhatsApp has caught the NSO Group phishing its users, in violation of a court order. [...]
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available. The s [...]
This is interesting: The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch… That means every device that uses GPS has been receiving hidden government information for years, and nobody outside the military knew it until [...]
curl disclosed a bug submitted by byteray_ltd: https://hackerone.com/reports/3788506 [...]
curl disclosed a bug submitted by kalfkinen: https://hackerone.com/reports/3786077 [...]
Ruby on Rails disclosed a bug submitted by ooooooo_q: https://hackerone.com/reports/2389431 [...]
We are delighted to share that Intigriti has won Best Security Company (under 250 employees), at this yearâs SC Awards Europe.  What it means to be an SC Award winner For over 25 years, the SC Awards Europe have defined what excellence looks like in cybersecurity, recognizing the organizations, technologies, and leaders shaping the future of the industry. On the 3rd of June 2026, Intigriti met wi [...]
If you’re a user—owner?—of this cryptocurrency, this is important: On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind of issue. He found one fast enough to be embarrassing. The Orchard pool is the newest and most advanced shielded transa [...]
In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic’s claims that it’s now common wisdom that Mythos is better at finding software vulnerabilities than other models. Which is just not true. In any [...]
curl disclosed a bug submitted by torkd1: https://hackerone.com/reports/3785919 [...]
curl disclosed a bug submitted by maxhearnden: https://hackerone.com/reports/3780733 [...]
curl disclosed a bug submitted by awofjawofjfawf: https://hackerone.com/reports/3781305 [...]
curl disclosed a bug submitted by fanhua: https://hackerone.com/reports/3749428 [...]
curl disclosed a bug submitted by alphalaab: https://hackerone.com/reports/3766392 [...]
Nextcloud disclosed a bug submitted by pirikara: https://hackerone.com/reports/3483708 [...]
Nextcloud disclosed a bug submitted by priyanka010: https://hackerone.com/reports/3489490 - Bounty: $2500 [...]
Nextcloud disclosed a bug submitted by alper_ozturk: https://hackerone.com/reports/3625210 [...]
curl disclosed a bug submitted by argus-systems: https://hackerone.com/reports/3784125 [...]
Researchers have prototyped an AI-powered internet worm. The coolest thing about the prototype is that it carries its own LLM with it, and runs it on computers that have been broken into. This is the closest to John Brunner’s original 1975 conception of a computer worm that I’ve seen. [...]
curl disclosed a bug submitted by bagder: https://hackerone.com/reports/3717552 [...]
curl disclosed a bug submitted by bagder: https://hackerone.com/reports/3718265 [...]
curl disclosed a bug submitted by hamaowo: https://hackerone.com/reports/3776535 [...]
curl disclosed a bug submitted by bowen111: https://hackerone.com/reports/3776433 [...]
curl disclosed a bug submitted by skksndk: https://hackerone.com/reports/3774977 [...]
curl disclosed a bug submitted by azraelxuemo: https://hackerone.com/reports/3766065 [...]
TL;DR- AI deployment has outpaced AI governance. Most enterprises running AI on AWS cannot answer four basic security questions about what's running, what it's doing,how to stop it, and how to prove it's under control.- The Wallarm AI Control Platform closes this gap: one platform for Discover, Observe,Enforce, and Govern â running natively in your AWS environment.- Infrastructure Discovery maps [...]
Hackers are convincing Meta’s AI support chatbot to let them take over other peoples’ accounts: A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to spoof the targets’ presumed location to avoid triggering Instagram’s automated account protections. Then, the hacker opened a chat with Meta AI Suppor [...]
Revive Adserver disclosed a bug submitted by darky_os: https://hackerone.com/reports/3650504 [...]
Revive Adserver disclosed a bug submitted by darky_os: https://hackerone.com/reports/3650582 [...]
Revive Adserver disclosed a bug submitted by titanrain: https://hackerone.com/reports/3653196 [...]
Revive Adserver disclosed a bug submitted by titanrain: https://hackerone.com/reports/3653316 [...]
Revive Adserver disclosed a bug submitted by 0x4c616e: https://hackerone.com/reports/3656781 [...]
Revive Adserver disclosed a bug submitted by 3l4: https://hackerone.com/reports/3669623 [...]
Revive Adserver disclosed a bug submitted by 0x4c616e: https://hackerone.com/reports/3672641 [...]
Revive Adserver disclosed a bug submitted by 3l4: https://hackerone.com/reports/3677576 [...]
Revive Adserver disclosed a bug submitted by v3rtical: https://hackerone.com/reports/3678828 [...]
Revive Adserver disclosed a bug submitted by 3l4: https://hackerone.com/reports/3680090 [...]
Revive Adserver disclosed a bug submitted by rajib_mahmud: https://hackerone.com/reports/3744200 [...]
Researchers are using machine learning algorithms to decrypt historical pencil-and-paper ciphers. [...]
Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of tools designed to detect malicious skills before theyâre installed. But we tested them, and they donât work. We recently bypassed ClawHubâs malicious skill detector, Ciscoâs agent skill [...]
curl disclosed a bug submitted by hungly09: https://hackerone.com/reports/3777381 [...]
curl disclosed a bug submitted by arkss: https://hackerone.com/reports/3773293 [...]
curl disclosed a bug submitted by hualuo: https://hackerone.com/reports/3770979 [...]
curl disclosed a bug submitted by lvtable: https://hackerone.com/reports/3767963 [...]
PortSwigger Web Security disclosed a bug submitted by hacker-kartel: https://hackerone.com/reports/3775183 [...]
As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the topic today. This is my section. Renowned technologist and author Bruce Schneier contributed a column on June 20, 2010, warning about cryptography’s inability to secure modern [...]
An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth. [...]
LY Corporation disclosed a bug submitted by imnotr3al: https://hackerone.com/reports/3423013 - Bounty: $1000 [...]
GitHub Actions workflows are vulnerable to pwn requests, script injection, and compromised credentials. Here's what's going wrong and what's changing. [...]
Shopify disclosed a bug submitted by cipher-kid: https://hackerone.com/reports/3697491 [...]
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into resetting account passwords. A screenshot from a video released on Telegram claiming to show h [...]
curl disclosed a bug submitted by karthiktp1810: https://hackerone.com/reports/3761789 [...]
curl disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3761647 [...]
curl disclosed a bug submitted by tpfeng: https://hackerone.com/reports/3756699 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3751701 [...]
curl disclosed a bug submitted by ajohnston3825: https://hackerone.com/reports/3769293 [...]
Based in the Netherlands, Stefan Goossens, otherwise known as G0053, is both an independent security researcher and a partner for a marketing and web development company. As someone who loves nothing more than building and breaking web applications, Stefan is perfectly placed at the intersection of these two careers. While his day job is spent focusing on devising, guiding, and realizing user-frie [...]
Based in the Netherlands, Stefan Goossens, otherwise known as G0053, is both an independent security researcher and a partner for a marketing and web development company. As someone who loves nothing more than building and breaking web applications, Stefan is perfectly placed at the intersection of these two careers. While his day job is spent focusing on devising, guiding, and realizing user-frie [...]
phpBB disclosed a bug submitted by misop00p: https://hackerone.com/reports/3608558 [...]
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sanitized name field And so much more! Let's dive in! CEO insights: beyond the AI mode [...]
AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620748 [...]
AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620753 [...]