Sen. Sanders Talks to Claude About AI and Privacy on 10/04/2026
Claude is actually pretty good on the issues. [...]
Claude is actually pretty good on the issues. [...]
Rocket.Chat disclosed a bug submitted by soohyun: https://hackerone.com/reports/3418031 [...]
Mozilla disclosed a bug submitted by adilnbabras: https://hackerone.com/reports/3020021 [...]
Mozilla disclosed a bug submitted by adilnbabras: https://hackerone.com/reports/3325582 [...]
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to co [...]
RubyGems disclosed a bug submitted by mclaren650sspider: https://hackerone.com/reports/3079931 [...]
We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code. We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases and organized them into sections covering Linux, Windows, and seccomp. Whereas other handbook chapters focus on static and dynamic analysis, this chapter offers a strong basis for manu [...]
ProPublica has a scoop: In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings. The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an i [...]
curl disclosed a bug submitted by adityasunny_06: https://hackerone.com/reports/3658049 [...]
A look at how Kubernetes CVE-2020-8562 allows attackers to bypass API server proxy protections using DNS rebinding [...]
Glassdoor disclosed a bug submitted by auxilus: https://hackerone.com/reports/909084 [...]
Glassdoor disclosed a bug submitted by amakki: https://hackerone.com/reports/970763 [...]
Glassdoor disclosed a bug submitted by z3ron3: https://hackerone.com/reports/818094 [...]
This is news: A malicious supply chain compromise has been identified in the Python Package Index package litellm version 1.82.8. The published wheel contains a malicious .pth file (litellm_init.pth, 34,628 bytes) which is automatically executed by the Python interpreter on every startup, without requiring any explicit import of the litellm module. There are a lot of really boring things we need t [...]
AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an application on demand—a spreadsheet, for example—and delete it when you’re done using it than to buy one commercially. Future systems could i [...]
Hackers linked to Russia’s military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks without deploying any malicious software or code. Micros [...]
AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620761 [...]
Nextcloud disclosed a bug submitted by shiva2550: https://hackerone.com/reports/3518758 [...]
More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We’re excited to announce a new partnership with Meta [...]
WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such as message summarization. To make this possible, Meta built a system that processes encrypted user messages inside trusted execution environments (TEEs), secure hardware enclaves designed so that not even Meta can access the plaintext. Our now [...]
According to a new law, the Hong Kong police can demand that you reveal the encryption keys protecting your computer, phone, hard drives, etc.—even if you are just transiting the airport. In a security alert dated March 26, the U.S. Consulate General said that, on March 23, 2026, Hong Kong authorities changed the rules governing enforcement of the National Security Law. Under the revised fra [...]
curl disclosed a bug submitted by mzfr: https://hackerone.com/reports/3650443 [...]
curl disclosed a bug submitted by mzfr: https://hackerone.com/reports/3650473 [...]
curl disclosed a bug submitted by cutiapretaa: https://hackerone.com/reports/3650435 [...]
The content of the Cyber Security & Resilience Bill (CSRB) recently introduced to Parliament contained few surprises. Having spent a significant amount of time working with European cyber-security frameworks, particularly NIS2, I see the Bill as both a continuation of the trend towards common approaches, and a signal of how seriously governments now take cyber risk. From my perspective, there are [...]
Glassdoor disclosed a bug submitted by downgrade: https://hackerone.com/reports/2516237 [...]
Glassdoor disclosed a bug submitted by zorixu: https://hackerone.com/reports/2682538 [...]
Glassdoor disclosed a bug submitted by imtheking: https://hackerone.com/reports/1820146 [...]
Mike Masnick points out that the recent New Mexico court ruling against Meta has some bad implications for end-to-end encryption, and security in general: If the “design choices create liability” framework seems worrying in the abstract, the New Mexico case provides a concrete example of where it leads in practice. One of the key pieces of evidence the New Mexico attorney general used [...]
Monero disclosed a bug submitted by jehrenhofermagicgrants: https://hackerone.com/reports/3241102 [...]
Monero disclosed a bug submitted by jehrenhofermagicgrants: https://hackerone.com/reports/3240792 [...]
Glassdoor disclosed a bug submitted by avielt: https://hackerone.com/reports/881118 [...]
Google says that it will fully transition to post-quantum cryptography by 2029. I think this is a good move, not because I think we will have a useful quantum computer anywhere near that year, but because crypto-agility is always a good thing. Slashdot thread. [...]
curl disclosed a bug submitted by spiderchan26: https://hackerone.com/reports/3645415 [...]
curl disclosed a bug submitted by divsz: https://hackerone.com/reports/3651975 [...]
An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021. Shchukin was n [...]
curl disclosed a bug submitted by spichanlio76: https://hackerone.com/reports/3646914 [...]
curl disclosed a bug submitted by intrax: https://hackerone.com/reports/3645361 [...]
curl disclosed a bug submitted by rougerseven7: https://hackerone.com/reports/3648199 [...]
Here’s a fossil of a 150-million year old fish that choked to death on a belemnite rostrum: the hard, internal shell of an extinct, squid-like animal. Original paper. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
curl disclosed a bug submitted by intrax71: https://hackerone.com/reports/3640932 [...]
curl disclosed a bug submitted by calaba_zas: https://hackerone.com/reports/3641893 [...]
WebinarTV searches the internet for public Zoom invites, joins the meetings, secretly records them, and publishes (alternate link) the recordings. It doesn’t use the Zoom record feature, so Zoom can’t do anything about it. [...]
Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and software protectors rely on it because no standard simplification technique covers both domains simultaneously; algebraic simplifiers don’t understand bitwise logic, and Boolean minimizers can’t handle arithmetic. We’re releasing CoBRA, an [...]
This is for new routers; you don’t have to throw away your existing ones: The Executive Branch determination noted that foreign-produced routers (1) introduce “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and (2) pose “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U [...]
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This ma [...]
Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures execution, not verification. Test suites with high coverage can obfuscate the fact that critical functionality is untested as software develops over time. We saw this when mutation testing uncovered a high-severity Arkis protocol vulnerabi [...]
In March 2026, we ran BugQuest, a 31-day campaign covering everything you need to know about finding and exploiting broken access control vulnerabilities. From understanding the basics of authentication and authorization to spotting subtle authorization bypasses in real code, we broke down one of the most critical vulnerability classes in modern web applications. Broken access controls have consis [...]
curl disclosed a bug submitted by whitehat411: https://hackerone.com/reports/3639277 [...]
curl disclosed a bug submitted by h3xb1tx: https://hackerone.com/reports/3638715 [...]
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under [...]
Sony disclosed a bug submitted by resurrect20: https://hackerone.com/reports/3355766 [...]
Nextcloud disclosed a bug submitted by eclipse07077: https://hackerone.com/reports/3479692 [...]
This post is adapted from a talk I gave at [un]prompted, the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or download the slides. Most companies hand out ChatGPT licenses and wait for the productivity numbers to move. We built a system instead. A year ago, about 5% of Trail of Bits was on board with our AI initiat [...]
curl disclosed a bug submitted by ankitsingh131225: https://hackerone.com/reports/3636244 [...]
curl disclosed a bug submitted by m42kl33: https://hackerone.com/reports/3636044 [...]
curl disclosed a bug submitted by ok3y: https://hackerone.com/reports/3632427 [...]
arkadiyt-projects disclosed a bug submitted by tipsen: https://hackerone.com/reports/3634400 [...]
arkadiyt-projects disclosed a bug submitted by tipsen: https://hackerone.com/reports/3634571 [...]
An attacker hijacked an axios maintainer's npm account to publish malicious releases that deliver a cross-platform RAT. [...]
Node.js disclosed a bug submitted by sharp_edged: https://hackerone.com/reports/3511792 [...]
Node.js disclosed a bug submitted by stif: https://hackerone.com/reports/3480841 [...]
Node.js disclosed a bug submitted by x_probe: https://hackerone.com/reports/3533945 [...]
Node.js disclosed a bug submitted by xavlimsg: https://hackerone.com/reports/3559715 [...]
Node.js disclosed a bug submitted by yushengchen: https://hackerone.com/reports/3560402 [...]
Node.js disclosed a bug submitted by wooseokdotkim: https://hackerone.com/reports/3449392 [...]
Node.js disclosed a bug submitted by galbarnahum: https://hackerone.com/reports/3531737 [...]
Dimitris Georgiou has been a self-professed computer geek since the early 80s. At university, he studied the convergence of educational technology with computer science as part of his psychology MA – finding, to his disbelief, that systems were perilously insecure. Since then, he’s always worked in and around cybersecurity. He’s had roles as a computer science teacher, a technology manager, a [...]
curl disclosed a bug submitted by sakthi02_sk: https://hackerone.com/reports/3633534 [...]
curl disclosed a bug submitted by xkiluar: https://hackerone.com/reports/3630310 [...]
Tucows (VDP) disclosed a bug submitted by 2026: https://hackerone.com/reports/3523703 [...]