another liberapay member team twitter account broken Link Hijacking via Expired Twitter Account Link on 09/05/2026
Liberapay disclosed a bug submitted by rox-11: https://hackerone.com/reports/3723002 [...]
Liberapay disclosed a bug submitted by rox-11: https://hackerone.com/reports/3723002 [...]
Liberapay disclosed a bug submitted by rox-11: https://hackerone.com/reports/3721519 [...]
Evidence of them has been found by analyzing DNA in the seawater. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
Insider trading is rife on Polymarket: Analysis by the Anti-Corruption Data Collective, a non-profit research and advocacy group, found that long-shot bets—Âdefined as wagers of $2,500 or more at odds of 35 percent or less—Âon the platform had an average win rate of around 52 percent in markets on military and defense actions. That compares with a win rate of 25 percent across all poli [...]
Nextcloud disclosed a bug submitted by vidang04: https://hackerone.com/reports/3511998 - Bounty: $150 [...]
Nextcloud disclosed a bug submitted by 0x0doteth: https://hackerone.com/reports/3304830 [...]
Nextcloud disclosed a bug submitted by yoyomiski: https://hackerone.com/reports/3521434 [...]
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions. A sc [...]
A look at how to secure Kubernetes secrets [...]
curl disclosed a bug submitted by shecantcode2: https://hackerone.com/reports/3717365 [...]
Ruby on Rails disclosed a bug submitted by ksw9722: https://hackerone.com/reports/3580511 [...]
ICE is developing its own version of smart glasses, with facial recognition tied to various databases. [...]
Monero disclosed a bug submitted by rorkh: https://hackerone.com/reports/3307874 [...]
Monero disclosed a bug submitted by yulge: https://hackerone.com/reports/3185083 [...]
curl disclosed a bug submitted by p4p3r_hak: https://hackerone.com/reports/3708482 [...]
A new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia’s Ampere generation that take GPU rowhammering into new—Âand potentially much more consequential—Âterritory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system comprom [...]
PortSwigger Web Security disclosed a bug submitted by bereza4321: https://hackerone.com/reports/3625600 - Bounty: $200 [...]
We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples: a deceptively simple Linux ping program and a Windows driver registry handler. If you found the inet_ntoa global buffer gotcha or the missing RTL_QUERY_REGISTRY_TYPECHECK flag, nice work. If not, here’s a full walkthrough of both challenges, plus a deep dive into [...]
DarkSword is a sophisticated piece of malware—probably government designed—that targets iOS. Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has [...]
curl disclosed a bug submitted by ravindrasl2026: https://hackerone.com/reports/3710209 [...]
curl disclosed a bug submitted by codexxxx: https://hackerone.com/reports/3707747 [...]
curl disclosed a bug submitted by orelbn7: https://hackerone.com/reports/3712343 [...]
As part of our recent AI blog series, and in addition to content on ‘How AI is leveraged to enhance the Intigriti platform’, we have provided multiple insights from the Intigriti team on the development and future of AI, how it impacts programs, and the Bug Bounty community. So far, we have explored:  ‘How AI is changing vulnerability discovery’, with COO, Ed Parsons. ‘Common AI misconceptions [...]
Polymarket is a platform where people can bet on real-world events, political and otherwise. Leaving the ethical considerations of this aside (for one, it facilitates assassination), one of the issues with making this work is the verification of these real-world events. Polymarket gamblers have threatened a journalist because his story was being used to verify an event. And now, gamblers are takin [...]
As API and AI adoption grows across the Middle East, so do the expectations around how data is handled. For many organizations operating in this region, it’s not just about securing applications. It’s about doing it in a way that keeps data in-country and aligned with local requirements. Today, we’re introducing the Wallarm Middle East Cloud Point of Presence (POP), giving organizations a n [...]
Nextcloud disclosed a bug submitted by khoof: https://hackerone.com/reports/3399016 [...]
Someone pleaded guilty to secretly working for a ransomware gang as he negotiated ransomware payments for clients. [...]
Senior pentesters have a deeply refined intuition about what is vulnerable in an environment. The problem? That expertise is often siloed with an individual and trapped in their notes or Python scripts. [...]
PlayStation disclosed a bug submitted by slidybat: https://hackerone.com/reports/3320669 - Bounty: $10000 [...]
A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm’s chief executive says the malicious activity resulted from a security breach and was likely the work of a compet [...]
Researchers have reverse-engineered a piece of malware named Fast16. It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet: “…the Fast16 malware was designed to carry out the most subtle form of sabotage ever seen in an in-the-wild malware tool: By automatically spreading across networks and then silently manipulating com [...]
Most assume that SQL injection is a solved problem in today's application landscape, especially with increased awareness of secure coding practices (such as resorting to prepared statements or parameterized queries) and the widespread adoption of NoSQL databases. However, in practice, SQLi vulnerabilities continue to surface in modern applications, often hiding in legacy code components, custom qu [...]
curl disclosed a bug submitted by fxv_ray_st: https://hackerone.com/reports/3702718 [...]
LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode. Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing techniques, and libFuzzer compatibility. For these reasons, I set out to add LibAFL support to Ruzzy, our coverage-guided fuzzer for pure Ruby code and Ruby C extensions. This gives R [...]
That’s a lot. No, it’s an extraordinary number: Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6, which led to fixes for 22 security-sensitive bugs in Firefox 148. As part of our continued col [...]
curl disclosed a bug submitted by nadsec42: https://hackerone.com/reports/3591956 [...]
curl disclosed a bug submitted by anonymous_237: https://hackerone.com/reports/3646072 [...]
curl disclosed a bug submitted by sdainard: https://hackerone.com/reports/3666576 [...]
curl disclosed a bug submitted by xkilua: https://hackerone.com/reports/3697719 [...]
curl disclosed a bug submitted by 3lcarry: https://hackerone.com/reports/3694390 [...]
curl disclosed a bug submitted by joesephdiver: https://hackerone.com/reports/3669637 [...]
curl disclosed a bug submitted by quaccws: https://hackerone.com/reports/3642555 [...]
curl disclosed a bug submitted by arkss: https://hackerone.com/reports/3671818 [...]
curl disclosed a bug submitted by nobcoderr: https://hackerone.com/reports/3677759 [...]
curl disclosed a bug submitted by bonaire: https://hackerone.com/reports/3621851 [...]
curl disclosed a bug submitted by osama-hamad: https://hackerone.com/reports/3650689 [...]
curl disclosed a bug submitted by m1llie: https://hackerone.com/reports/3682666 [...]
curl disclosed a bug submitted by h3zh3z: https://hackerone.com/reports/3684614 [...]
curl disclosed a bug submitted by wi110w: https://hackerone.com/reports/3684603 [...]
PlayStation disclosed a bug submitted by gezine: https://hackerone.com/reports/3452696 - Bounty: $2500 [...]
Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have m [...]
Most organizations treating AI security as a model problem are defending the wrong layer. Security teams filter prompts, patch jailbreaks, and tune model behavior, which is all necessary work, while the actual attack surface sits largely unexamined underneath. That surface is the API layer: the endpoints AI systems use to retrieve data, call tools, and take action on behalf of users. This isn' [...]
We’re proud to announce that PortSwigger recently won the Overall Judges’ Award at the Northern Tech Awards 2026. The Northern Tech Awards are run by GP Bullhound, the tech advisory and investment fir [...]
IBM disclosed a bug submitted by jhon1231248e: https://hackerone.com/reports/3340797 [...]
Mozilla disclosed a bug submitted by icecream_23: https://hackerone.com/reports/3279441 - Bounty: $500 [...]
pixiv disclosed a bug submitted by aaqibhussain: https://hackerone.com/reports/3100570 - Bounty: $200 [...]
pixiv disclosed a bug submitted by lainkusanagi: https://hackerone.com/reports/3183520 - Bounty: $3000 [...]
Weblate disclosed a bug submitted by alexb_616: https://hackerone.com/reports/3518571 [...]
Shopify disclosed a bug submitted by 0xd0ff9: https://hackerone.com/reports/3679660 [...]
Your legal team just handed you a 400-page document and said "figure out compliance." The EU AI Act is live, your organization falls under its scope, which is broader than many expect. Even non‑EU companies must comply if their AI systems are used, deployed, or produce effects within the European Union. In practice, that means that global organizations building or integrating AI models cannot tre [...]
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring:  Compromising an NPM package with 40M weekly downloads Bypassing Cloudflare WAF for a full ATO 20-part series on exploiting JWT vulnerabilities First Intigriti Bug Bounty Meetup And so much more! Let's dive in! Common misconceptions about bug bounty, debugged Bug bounty still gets misundersto [...]
Node.js disclosed a bug submitted by mbarbs: https://hackerone.com/reports/3556769 [...]
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise A [...]
We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude skills can call directly. Install it now: uv pip install trailmark “Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.” John [...]
Rocket.Chat disclosed a bug submitted by arccode: https://hackerone.com/reports/3589551 [...]
What you will learn How vulnerability research and security testing may evolve in the future, based on expert insights and reflections from Intigriti COO Ed Parsons. How AI is reshaping vulnerability discovery, including the major trends and developments security teams should understand today. The ‘vulnpocalypse’, and what it signals about the future of AI-assisted hacking. The risks, oppor [...]