InfoSec Planet

A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.

Command Injection via Unsanitized Bundling Options in `aws-cdk-lib/aws-lambda-nodejs`

on 11/06/2026

AWS VDP disclosed a bug submitted by inkerton: https://hackerone.com/reports/3558713 [...]

See full content

Firecracker Out-of-bounds Read/Write Local Privilege Escalation Vulnerability

on 11/06/2026

AWS VDP disclosed a bug submitted by terrynini38514: https://hackerone.com/reports/3738654 [...]

See full content

CRLF Injection via Custom HTTP Headers

on 11/06/2026

curl disclosed a bug submitted by bugthiru: https://hackerone.com/reports/3741744 [...]

See full content

heap-use-after-free in state.referer when CURLOPT_REFERER replaced or cleared after perform

on 11/06/2026

curl disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3774279 [...]

See full content

RCE + PAT Exfiltration via pull_request_target in privacy-configuration/auto-respond-pr.yml Direct Supply Chain to All DDG Browsers

on 11/06/2026

DuckDuckGo disclosed a bug submitted by 6r1ff1n: https://hackerone.com/reports/3619288 [...]

See full content

RCE + Supply Chain Attack via pull_request_target in content-scope-scripts/semver-label.yml Affects All DuckDuckGo Browsers

on 11/06/2026

DuckDuckGo disclosed a bug submitted by 6r1ff1n: https://hackerone.com/reports/3619287 [...]

See full content

SSRF via Improper Redirect Validation in Rocket.Chat oEmbed Function

on 11/06/2026

Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3383079 [...]

See full content

SSRF via improper validation after DNS name resolution in the link-preview feature

on 11/06/2026

Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3393664 [...]

See full content

Enhanced License Plate Tracking

on 11/06/2026

The surveillance company Leonardo wants more data: A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phones, wearables, and other Bluetooth-enabled devices in those cars, potentially letting law enforcement identify specific dr [...]

See full content

LIVE: đŸ•”ïž CTF Prize Draw | Cybersecurity

on 11/06/2026

See full content

Securing the uncharted territories of AI systems. A discussion with Leo Racanelli

by Eleanor Barlow on 11/06/2026

The intersection of AI and cybersecurity is reshaping how we find, fix, and think about vulnerabilities. Yet for all the headlines, few conversations cut through the noise to ask what AI means for those on the ground: the hunters, the security engineers, and the organizations trying to secure their data. In this blog, we open up that discussion, with insights from Leo Racanelli for an unflinching [...]

See full content

Entra Agent ID: The blueprint blast radius

on 11/06/2026

Entra Agent ID is an extension of Entra's application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) to multiple identities and their associated privileges, increasing the potential blast radius of a compromised agent. [...]

See full content

curl-ipv4-percent-normalization-SSRF

on 10/06/2026

curl disclosed a bug submitted by monk17: https://hackerone.com/reports/3791168 [...]

See full content

Trailing-Dot Hostname in Redirect Silently Strips Client Certificate and Auth Credentials

on 10/06/2026

curl disclosed a bug submitted by azraelxuemo: https://hackerone.com/reports/3791191 [...]

See full content

curl/libcurl vulnerable to TLS truncation attacks

on 10/06/2026

curl disclosed a bug submitted by nyymi: https://hackerone.com/reports/1826392 [...]

See full content

Payload Podcast 008 - Ryan Hausknecht

on 10/06/2026

See full content

Who Runs the Ransomware Group ‘The Gentlemen?’

by BrianKrebs on 10/06/2026

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group. A graphic create [...]

See full content

NSO Group Hacking WhatsApp Despite Court Order

on 10/06/2026

WhatsApp has caught the NSO Group phishing its users, in violation of a court order. [...]

See full content

A Record-Breaking Patch Tuesday for June 2026

by BrianKrebs on 09/06/2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available. The s [...]

See full content

GPS As a Key Distribution Platform

on 09/06/2026

This is interesting: The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch… That means every device that uses GPS has been receiving hidden government information for years, and nobody outside the military knew it until [...]

See full content

Secrets to PNPT Debrief Success

on 09/06/2026

See full content

SSH/SFTP connection reuse can bypass SSH key identity after ssh_config_matches removal

on 09/06/2026

curl disclosed a bug submitted by byteray_ltd: https://hackerone.com/reports/3788506 [...]

See full content

SOCKS5 no-auth accepted despite username/password-only authentication

on 09/06/2026

curl disclosed a bug submitted by kalfkinen: https://hackerone.com/reports/3786077 [...]

See full content

Action Text ReDoS (Ruby 3.1 or lower)

on 09/06/2026

Ruby on Rails disclosed a bug submitted by ooooooo_q: https://hackerone.com/reports/2389431 [...]

See full content

Intigriti named Best Security Company of 2026 at the SC Awards

by Eleanor Barlow on 09/06/2026

We are delighted to share that Intigriti has won Best Security Company (under 250 employees), at this year’s SC Awards Europe.   What it means to be an SC Award winner For over 25 years, the SC Awards Europe have defined what excellence looks like in cybersecurity, recognizing the organizations, technologies, and leaders shaping the future of the industry. On the 3rd of June 2026, Intigriti met wi [...]

See full content

Critical Zcash Vulnerability Found and Fixed

on 08/06/2026

If you’re a user—owner?—of this cryptocurrency, this is important: On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind of issue. He found one fast enough to be embarrassing. The Orchard pool is the newest and most advanced shielded transa [...]

See full content

your future awaits hackers

on 08/06/2026

See full content

Content creations was both a blessing and a curse. #bugbounty

on 08/06/2026

See full content

This Hacker Made $7,000 Hacking AI With One Email

on 08/06/2026

See full content

Anthropic’s Project Glasswing Update

on 08/06/2026

In April, Anthropic initated Project Glasswing. The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic’s claims that it’s now common wisdom that Mythos is better at finding software vulnerabilities than other models. Which is just not true. In any [...]

See full content

libcurl: HTTP/1.x bare LF byte in response header value enables cookie jar pollution and POST body/credential exfiltration via redirect RC=0, curl 8

on 08/06/2026

curl disclosed a bug submitted by torkd1: https://hackerone.com/reports/3785919 [...]

See full content

DNS domain search list followed for extant domain missing A or AAAA records

on 08/06/2026

curl disclosed a bug submitted by maxhearnden: https://hackerone.com/reports/3780733 [...]

See full content

OpenSSL TLS 1.2 session resumption accepts expired server certificates in libcurl

on 07/06/2026

curl disclosed a bug submitted by awofjawofjfawf: https://hackerone.com/reports/3781305 [...]

See full content

curl cross-origin HTTPS redirect reuses TLS client certificate for unintended second-origin mTLS authentication

on 07/06/2026

curl disclosed a bug submitted by fanhua: https://hackerone.com/reports/3749428 [...]

See full content

curl External-Controlled Filename in `--url @file` Leads to Arbitrary File Overwrite

on 07/06/2026

curl disclosed a bug submitted by alphalaab: https://hackerone.com/reports/3766392 [...]

See full content

Valid share tokens allow to access tempory upload files of share owner

on 07/06/2026

Nextcloud disclosed a bug submitted by pirikara: https://hackerone.com/reports/3483708 [...]

See full content

Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC

on 07/06/2026

Nextcloud disclosed a bug submitted by priyanka010: https://hackerone.com/reports/3489490 - Bounty: $2500 [...]

See full content

PIN bypass in PassCodeActivity via back button

on 07/06/2026

Nextcloud disclosed a bug submitted by alper_ozturk: https://hackerone.com/reports/3625210 [...]

See full content

Superbacked helps the right people recover what matters

on 06/06/2026

See full content

JHT Course Launch! Windows Maldev 6

on 06/06/2026

See full content

Why CAPIE[M] is the best API hacking certificate in the API Hacking industry

on 06/06/2026

See full content

TCM Security CTF Walkthrough

on 05/06/2026

See full content

GnuTLS OCSP stapling accepts unrelated SingleResponse (no cert-ID binding)

on 05/06/2026

curl disclosed a bug submitted by argus-systems: https://hackerone.com/reports/3784125 [...]

See full content

AI Worm

on 05/06/2026

Researchers have prototyped an AI-powered internet worm. The coolest thing about the prototype is that it carries its own LLM with it, and runs it on computers that have been broken into. This is the closest to John Brunner’s original 1975 conception of a computer worm that I’ve seen. [...]

See full content

CURLOPT_PROXY_CRLFILE / CURLOPT_PROXY_ISSUERCERT / CURLOPT_PROXY_ISSUERCERT_BLOB silently ignored on backends that don't support them

on 05/06/2026

curl disclosed a bug submitted by bagder: https://hackerone.com/reports/3717552 [...]

See full content

Shared HSTS cache accessed without lock

on 05/06/2026

curl disclosed a bug submitted by bagder: https://hackerone.com/reports/3718265 [...]

See full content

RTSP Digest auth state leaks across origins on reused libcurl easy handle

on 05/06/2026

curl disclosed a bug submitted by hamaowo: https://hackerone.com/reports/3776535 [...]

See full content

TFTP upload ignores --continue-at / CURLOPT_RESUME_FROM and leaks skipped local file prefix

on 05/06/2026

curl disclosed a bug submitted by bowen111: https://hackerone.com/reports/3776433 [...]

See full content

libcurl 8.20.0 ignores HTTP Digest domain protection space and preemptively leaks Digest auth outside the declared scope

on 05/06/2026

curl disclosed a bug submitted by skksndk: https://hackerone.com/reports/3774977 [...]

See full content

CURLOPT_COOKIE leaked to cross-origin redirect target CURLOPT_UNRESTRICTED_AUTH bypass for the STRING_COOKIE path

on 05/06/2026

curl disclosed a bug submitted by azraelxuemo: https://hackerone.com/reports/3766065 [...]

See full content

Try these bug bounty tips ↓

on 05/06/2026

See full content

BIG SHOW TODAY & AI vibes

on 04/06/2026

See full content

Introducing the Wallarm AI Control Platform: One closed loop for AI security and API security.

by Tim Erlin on 04/06/2026

TL;DR- AI deployment has outpaced AI governance. Most enterprises running AI on AWS cannot answer four basic security questions about what's running, what it's doing,how to stop it, and how to prove it's under control.- The Wallarm AI Control Platform closes this gap: one platform for Discover, Observe,Enforce, and Govern — running natively in your AWS environment.- Infrastructure Discovery maps [...]

See full content

Hacking Meta’s AI Chatbot

on 04/06/2026

Hackers are convincing Meta’s AI support chatbot to let them take over other peoples’ accounts: A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to spoof the targets’ presumed location to avoid triggering Instagram’s automated account protections. Then, the hacker opened a chat with Meta AI Suppor [...]

See full content

The AI Slop Era: Do Most Vulnerabilities Actually Matter?

on 03/06/2026

See full content

Bugmageddon: When AI Breaks the Security Model | Live with Bugcrowd

on 03/06/2026

See full content

Missing access control when linking banners or campaigns to zones

on 03/06/2026

Revive Adserver disclosed a bug submitted by darky_os: https://hackerone.com/reports/3650504 [...]

See full content

Missing access control when linking trackers to campaigns

on 03/06/2026

Revive Adserver disclosed a bug submitted by darky_os: https://hackerone.com/reports/3650582 [...]

See full content

Blind SQL injection via clientid parameter in zoneinclude.php

on 03/06/2026

Revive Adserver disclosed a bug submitted by titanrain: https://hackerone.com/reports/3653196 [...]

See full content

Reflected XSS via clientid parameter in zoneinclude.php

on 03/06/2026

Revive Adserver disclosed a bug submitted by titanrain: https://hackerone.com/reports/3653316 [...]

See full content

PHP code injection via delivery limitation logical

on 03/06/2026

Revive Adserver disclosed a bug submitted by 0x4c616e: https://hackerone.com/reports/3656781 [...]

See full content

Stored XSS via Full Name field in userlog email entries

on 03/06/2026

Revive Adserver disclosed a bug submitted by 3l4: https://hackerone.com/reports/3669623 [...]

See full content

Session ID reuse allowing XMLRPC API authentication bypass

on 03/06/2026

Revive Adserver disclosed a bug submitted by 0x4c616e: https://hackerone.com/reports/3672641 [...]

See full content

Missing access control when modifying parent entities via XMLRPC

on 03/06/2026

Revive Adserver disclosed a bug submitted by 3l4: https://hackerone.com/reports/3677576 [...]

See full content

Banner status override by advertiserlevel users

on 03/06/2026

Revive Adserver disclosed a bug submitted by v3rtical: https://hackerone.com/reports/3678828 [...]

See full content

Stored XSS via malicious usernames in audit log details + Username validation bypass in XMLRPC addUser

on 03/06/2026

Revive Adserver disclosed a bug submitted by 3l4: https://hackerone.com/reports/3680090 [...]

See full content

PHP code injection via unexpected delivery limitation parameter

on 03/06/2026

Revive Adserver disclosed a bug submitted by rajib_mahmud: https://hackerone.com/reports/3744200 [...]

See full content

Are ANY hacking scenes actually good?

on 03/06/2026

See full content

AI Used to Decrypt Medieval Ciphers

on 03/06/2026

Researchers are using machine learning algorithms to decrypt historical pencil-and-paper ciphers. [...]

See full content

The sorry state of skill distribution

on 03/06/2026

Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of tools designed to detect malicious skills before they’re installed. But we tested them, and they don’t work. We recently bypassed ClawHub’s malicious skill detector, Cisco’s agent skill [...]

See full content

PRE_PROXY change leaks stale Proxy Digest state across proxy-chain boundary

on 03/06/2026

curl disclosed a bug submitted by hungly09: https://hackerone.com/reports/3777381 [...]

See full content

curl/libcurl 8.20.0 NOPROXY bypass via uppercase-hex IPv4 aliases leaks off-proxy Basic credentials to the configured proxy

on 03/06/2026

curl disclosed a bug submitted by arkss: https://hackerone.com/reports/3773293 [...]

See full content

SMTP connection reuse ignores --ssl-reqd / CURLOPT_USE_SSL and reuses a clear-text STARTTLS session on current master

on 03/06/2026

curl disclosed a bug submitted by hualuo: https://hackerone.com/reports/3770979 [...]

See full content

Proxy CONNECT response poisoning via authentication retry in cf-h1-proxy.c (libcurl)

on 03/06/2026

curl disclosed a bug submitted by lvtable: https://hackerone.com/reports/3767963 [...]

See full content

Top 5 Active Directory Pentesting Tools

on 02/06/2026

See full content

Incomplete fix for CVE-2022-35406: meta-redirect content-type check bypassable via parameter injection

on 02/06/2026

PortSwigger Web Security disclosed a bug submitted by hacker-kartel: https://hackerone.com/reports/3775183 [...]

See full content

A Hacker's Way of Thinking (with Ted Harrington)

on 02/06/2026

See full content

H1 Platform: Agentic Continuous Threat Exposure Management That Closes the Discovery-Remediation Gap

on 02/06/2026

See full content

The Intersection of Encryption and AI

on 02/06/2026

As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the topic today. This is my section. Renowned technologist and author Bruce Schneier contributed a column on June 20, 2010, warning about cryptography’s inability to secure modern [...]

See full content

Microsoft Threatening Security Researcher

on 02/06/2026

An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth. [...]

See full content

page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token Compromise

on 02/06/2026

LY Corporation disclosed a bug submitted by imnotr3al: https://hackerone.com/reports/3423013 - Bounty: $1000 [...]

See full content

The case for GitHub Actions security after recent supply chain attacks

on 02/06/2026

GitHub Actions workflows are vulnerable to pwn requests, script injection, and compromised credentials. Here's what's going wrong and what's changing. [...]

See full content

Missing HMAC validation on /uninstall webhook in Shopify/sample-django-app reference template

on 01/06/2026

Shopify disclosed a bug submitted by cipher-kid: https://hackerone.com/reports/3697491 [...]

See full content

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

by BrianKrebs on 01/06/2026

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into resetting account passwords. A screenshot from a video released on Telegram claiming to show h [...]

See full content

A Linux Backdoor is For Sale on the Dark Web

on 01/06/2026

See full content

How I Found My First $3,000 AI Vulnerability

on 01/06/2026

See full content

Mentioned unites are at the same time .Then we have to increase the bounty.

on 01/06/2026

curl disclosed a bug submitted by karthiktp1810: https://hackerone.com/reports/3761789 [...]

See full content

TLS conn reuse and session cache ignore fsslctx callback and ssl_config_data flags ( incomplete fix variant of 7541ae569 )

on 01/06/2026

curl disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3761647 [...]

See full content

lib/ldap.c follows attacker-controlled LDAP referrals and binds to a second server; WinLDAP builds leak current logon credentials (confirmed on Window

on 01/06/2026

curl disclosed a bug submitted by tpfeng: https://hackerone.com/reports/3756699 [...]

See full content

Use-after-free in `curl_easy_duphandle()` with HTTP/2 stream-dependency tree

on 01/06/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3751701 [...]

See full content

Low priority HSTS bypass in curl_easy_duphandle()

on 01/06/2026

curl disclosed a bug submitted by ajohnston3825: https://hackerone.com/reports/3769293 [...]

See full content

Marketer by day, bug hunter by night. Interview with Stefan Goossens (G0053)

by Eleanor Barlow on 01/06/2026

Based in the Netherlands, Stefan Goossens, otherwise known as G0053, is both an independent security researcher and a partner for a marketing and web development company. As someone who loves nothing more than building and breaking web applications, Stefan is perfectly placed at the intersection of these two careers. While his day job is spent focusing on devising, guiding, and realizing user-frie [...]

See full content

Marketer by day, bug hunter by night. Interview with Stefan Goossens (G0053)

by Eleanor Barlow on 01/06/2026

Based in the Netherlands, Stefan Goossens, otherwise known as G0053, is both an independent security researcher and a partner for a marketing and web development company. As someone who loves nothing more than building and breaking web applications, Stefan is perfectly placed at the intersection of these two careers. While his day job is spent focusing on devising, guiding, and realizing user-frie [...]

See full content

Blind POST SSRF via Web Push Notification Endpoint

on 30/05/2026

phpBB disclosed a bug submitted by misop00p: https://hackerone.com/reports/3608558 [...]

See full content

ContinuumCon Teaser: solst/ice, Zack Korman, & Spencer Alessi!!

on 30/05/2026

See full content

Intigriti Bug Bytes #236 - May 2026 🚀

by Ayoub on 30/05/2026

Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Earning $148K via RCE in Google Cloud How public Google API keys became Gemini credentials Our first official Burp Suite extension Two new bypasses for Chrome's Sanitizer API One-click account takeover from a sanitized name field And so much more! Let's dive in! CEO insights: beyond the AI mode [...]

See full content

AI is changing how fast security issues can be discovered

on 29/05/2026

See full content

Payload Podcast 007 with Andy Piazza (klrgrz)

on 29/05/2026

See full content

V1Plugin.Decrypt panics on empty ciphertext (Remote DoS)

on 28/05/2026

AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620748 [...]

See full content

V2Plugin.Decrypt panics on empty ciphertext (Remote DoS)

on 28/05/2026

AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620753 [...]

See full content

Sources

The content of this page is fetched from the following sources:

  1. Datadog Security Labs
  2. The Trail of Bits Blog
  3. Schneier on Security
  4. Krebs on Security
  5. Google Online Security Blog
  6. $BLOG_TITLE
  7. Agarri : Sécurité informatique offensive
  8. Alex Chapman's Blog
  9. www.alphabot.com
  10. ziot
  11. Bug Bounty Reports Explained
  12. Bugcrowd
  13. cat ~/footstep.ninja/blog.txt
  14. Ezequiel Pereira
  15. HackerOne
  16. surajdisoja.me
  17. InsiderPhD
  18. Intigriti
  19. John Hammond
  20. LiveOverflow
  21. NahamSec
  22. PortSwigger Blog
  23. Rana Khalil
  24. Richard’s Infosec blog
  25. Ron Chan
  26. ropnop blog
  27. STÖK
  28. Sun Knudsen
  29. The Cyber Mentor
  30. The unofficial HackerOne disclosure timeline
  31. The XSS Rat
  32. TomNomNom
  33. Wallarm