InfoSec Planet
A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.
Banning VPNs
on 01/12/2025
This is crazy. Lawmakers in several US states are contemplating banning VPNs, because…think of the children!
As of this writing, Wisconsin lawmakers are escalating their war on privacy by targeting VPNs in the name of “protecting children” in A.B. 105/S.B. 130. It’s an age verification bill that requires all websites distributing material that could conceivably be deemed “s [...]
See full content
PortSwigger x TryHackMe: Supporting Advent of Cyber
on 01/12/2025
Every December, TryHackMe’s Advent of Cyber brings the security community together around a simple idea: learn something new by getting hands-on. Each day during the festive season reveals a beginner- [...]
See full content
[my.stripo.email] Blind SSRF Vulnerability in Stripo App Export via Missing Endpoints Export Email Message to Zapier
on 01/12/2025
Stripo Inc disclosed a bug submitted by odaysec: https://hackerone.com/reports/2932960 [...]
See full content
Path Traversal in file:// protocol allows Arbitrary File Read
on 01/12/2025
curl disclosed a bug submitted by quello_stanco: https://hackerone.com/reports/3445174 [...]
See full content
Heap Buffer Overflow in TFTP
on 01/12/2025
curl disclosed a bug submitted by helspy: https://hackerone.com/reports/3444904 [...]
See full content
How AI is leveraged to enhance the Intigriti platform
by Eleanor Barlow on 01/12/2025
What is Intigriti’s stance on AI?
At Intigriti, we believe AI is a powerful ally to, not a replacement of, our community of security researchers. We will use AI to empower our researchers to hunt for bugs smarter, faster, and more efficiently, while recognizing the value of human creativity and ingenuity that machines cannot replicate. By creating AI-powered tools informed by researcher and cust [...]
See full content
Bypassing Content Security Policy (CSP)
by Ayoub on 30/11/2025
Content Security Policies (CSPs) are often deployed as the last line of defense against client-side attacks such as cross-site scripting (XSS) and clickjacking. Since their first introduction in 2012, they've enabled developers to control which and what resources are allowed to load and evaluate within a given DOM context.
However, it still commonly occurs that developers rely on this countermeasu [...]
See full content
ServiceUI Trick
on 29/11/2025
See full content
NPM malware now has multiple targets!
on 29/11/2025
See full content
WE DID IT ❤️❤️❤️❤️🥲🍀🍀
on 29/11/2025
See full content
My alter ego got the best of me 😳
on 29/11/2025
See full content
Friday Squid Blogging: Flying Neon Squid Found on Israeli Beach
on 28/11/2025
A meter-long flying neon squid (Ommastrephes bartramii) was found dead on an Israeli beach. The species is rare in the Mediterranean.
[...]
See full content
Prompt Injection Through Poetry
on 28/11/2025
In a new paper, “Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models,” researchers found that turning LLM prompts into poetry resulted in jailbreaking the models:
Abstract: We present evidence that adversarial poetry functions as a universal single-turn jailbreak technique for Large Language Models (LLMs). Across 25 frontier proprietary and open-w [...]
See full content
Learn Cybersecurity: Advent of Cyber 2025 (TryHackMe!)
on 28/11/2025
See full content
Community!
on 27/11/2025
See full content
Cybersecurity AMA with Heath Adams
on 27/11/2025
See full content
HackerOne on AI-Driven Security: Community, Risk, and Innovation
on 26/11/2025
See full content
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
by BrianKrebs on 26/11/2025
A prolific cybercriminal group that calls itself “Scattered LAPSUS$ Hunters” has dominated headlines this year by regularly stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for “Rey,” the moniker chosen by the technical operator and public face of the hacker group: Earlier this week, Rey confirmed his r [...]
See full content
Username Validation Bypass
on 26/11/2025
Revive Adserver disclosed a bug submitted by kassem_s94: https://hackerone.com/reports/3434156 [...]
See full content
The State of Cybercrime in 2025 Part 2 (with Nick Ascoli!)
on 26/11/2025
See full content
Huawei and Chinese Surveillance
on 26/11/2025
This quote is from House of Huawei: The Secret History of China’s Most Powerful Company.
“Long before anyone had heard of Ren Zhengfei or Huawei, Wan Runnan had been China’s star entrepreneur in the 1980s, with his company, the Stone Group, touted as “China’s IBM.” Wan had believed that economic change could lead to political change. He had thrown his support be [...]
See full content
When your AI Assistant Becomes the Attacker’s Command-and-Control
by Tim Erlin on 26/11/2025
Earlier this month, Microsoft uncovered SesameOp, a new backdoor malware that abuses the OpenAI Assistants API as a covert command-and-control (C2) channel. The discovery has drawn significant attention within the cybersecurity community. Security teams can no longer focus solely on endpoint malware. Attackers are weaponizing public and legitimate AI assistant APIs and defenders must adjust.
W [...]
See full content
Infinite loop issue in the state machine of the curl project
on 26/11/2025
curl disclosed a bug submitted by kak1: https://hackerone.com/reports/3442060 [...]
See full content
runs javascript on powershell when it shouldnt
on 26/11/2025
curl disclosed a bug submitted by lim_e: https://hackerone.com/reports/3442024 [...]
See full content
November CTF Challenge: Exploiting JWT vulnerabilities to achieve RCE
by Ayoub on 26/11/2025
At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security research community. This month, we've decided to take on a challenge ourselves as a way to give back to the community. In response to one of our recent articles, we decided to focus on JSON Web Token (JWT) vulnerabilities.
This article provides a step-by-step walkthrough for solving Novem [...]
See full content
Why is RAG Dangerous?
on 25/11/2025
See full content
Trusted Installer Shell
on 25/11/2025
See full content
Keylogger Malware Analysis
on 25/11/2025
See full content
Four Ways AI Is Being Used to Strengthen Democracies Worldwide
on 25/11/2025
Democracy is colliding with the technologies of artificial intelligence. Judging from the audience reaction at the recent World Forum on Democracy in Strasbourg, the general expectation is that democracy will be the worse for it. We have another narrative. Yes, there are risks to democracy from AI, but there are also opportunities.
We have just published the book Rewiring Democracy: How AI will Tr [...]
See full content
Understanding signal-to-noise for vulnerability management success
by Eleanor Barlow on 25/11/2025
A common worry for IT and security teams is that, when operating an effective vulnerability management model, they will be flooded with potential vulnerability reports they likely don’t have the capacity to work through.
But the real issue here is not volume; it’s noise. Invalid or low-quality submissions can drain resources, cover up, or deprioritize critical signals that have real business imp [...]
See full content
The Shai-Hulud 2.0 npm worm: analysis, and what you need to know
on 25/11/2025
Learn more about the Shai-Hulud 2.0 npm worm. [...]
See full content
High resource consumption by insufficient sanitization of forum threads pagination
on 24/11/2025
Flickr disclosed a bug submitted by maskopatol: https://hackerone.com/reports/1916400 - Bounty: $479 [...]
See full content
[SFTP] TOCTOU Race Condition in Upload Resume Logic Leads to Arbitrary File Append
on 24/11/2025
curl disclosed a bug submitted by cainvsilf: https://hackerone.com/reports/3432833 [...]
See full content
Is Your Android TV Streaming Box Part of a Botnet?
by BrianKrebs on 24/11/2025
On the surface, the Superbox media streaming devices for sale at retailers like BestBuy and Walmart may seem like a steal: They offer unlimited access to more than 2,200 pay-per-view and streaming services like Netflix, ESPN and Hulu, all for a one-time fee of around $400. But security experts warn these TV boxes require intrusive software that forces the user’s network to relay Internet tra [...]
See full content
2025 Black Friday Deals
on 24/11/2025
See full content
Start 'em young
on 24/11/2025
See full content
HTML Injection in Emails on login.mtb.com via givenName parameter leads to phishing attacks
on 24/11/2025
M&T Bank Vulnerability Disclosure disclosed a bug submitted by ozgun32: https://hackerone.com/reports/3426761 [...]
See full content
Wazuh gives visibility to EVERYTHING
on 24/11/2025
See full content
Free Post Recon Course and Methodology For Bug Bounty Hunters
on 24/11/2025
See full content
IACR Nullifies Election Because of Lost Decryption Key
on 24/11/2025
The International Association of Cryptologic Research—the academic cryptography association that’s been putting conferences like Crypto (back when “crypto” meant “cryptography”) and Eurocrypt since the 1980s—had to nullify an online election when trustee Moti Yung lost his decryption key.
For this election and in accordance with the bylaws of the IACR, the [...]
See full content
I Make The BEST FREE Labs In CyberSecurity Education - Come Check Them Out!
on 23/11/2025
See full content
Arbitrary free in curl's config file parsing.
on 23/11/2025
curl disclosed a bug submitted by letshack9707: https://hackerone.com/reports/3434543 [...]
See full content
hacking twitch chat
on 23/11/2025
See full content
Mostly Stupid Hacks
on 22/11/2025
See full content
AI Jailbreaks That Made Me Go WTF
on 22/11/2025
See full content
RAW videos from REAL hackers
on 22/11/2025
See full content
Career Questions with Rob Fuller @mubix!
on 22/11/2025
See full content
Friday Squid Blogging: New “Squid” Sneaker
on 21/11/2025
I did not know Adidas sold a sneaker called “Squid.”
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
[...]
See full content
Improper bot-authentication allows to impersonate any user when sending messages in a room
on 21/11/2025
Basecamp disclosed a bug submitted by stackered: https://hackerone.com/reports/3329310 - Bounty: $2000 [...]
See full content
More on Rewiring Democracy
on 21/11/2025
It’s been a month since Rewiring Democracy: How AI Will Transform Our Politics, Government, and Citizenship was published. From what we know, sales are good.
Some of the book’s forty-three chapters are available online: chapters 2, 12, 28, 34, 38, and 41.
We need more reviews—six on Amazon is not enough, and no one has yet posted a viral TikTok review. One review was published i [...]
See full content
Path traversal via archive.extract - CVE 2021-3281 incomplete patch
on 21/11/2025
Django disclosed a bug submitted by stackered: https://hackerone.com/reports/3328367 [...]
See full content
Top 5 WTF Prompt Injections
on 21/11/2025
See full content
hacker final boss
on 21/11/2025
See full content
AI as Cyberattacker
on 21/11/2025
From Anthropic:
In mid-September 2025, we detected suspicious activity that later investigation determined to be a highly sophisticated espionage campaign. The attackers used AI’s “agentic” capabilities to an unprecedented degree—using AI not just as an advisor, but to execute the cyberattacks themselves.
The threat actor—whom we assess with high confidence was a Chinese state-sponso [...]
See full content
APIs Are the Retail Engine: How to Secure Them This Black Friday
by Tim Erlin on 21/11/2025
Can you ever imagine the impact on your business if it went offline on Black Friday or Cyber Monday due to a cyberattack?
Black Friday is the biggest day in the retail calendar. It’s also the riskiest. As you gear up for huge surges in online traffic, ask yourself: have you protected the APIs on which the business runs?
The Black Friday API Boom
When you think about Black Fri [...]
See full content
Intigriti Bug Bytes #230 - November 2025 🚀
by Ayoub on 21/11/2025
Hi hackers,
Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring:
Finding an RCE using AI in GitHub
CORS exploitation cheat sheet
Scanning codebases with AI
Bypassing paywalls
SSTIs in AI models
And so much more! Let’s dive in!
Company News
Intigriti wins 2025 UK IT Industry Awards
We are thrilled to announce that Intigriti has won Security Innovation [...]
See full content
Mozilla Says It’s Finally Done With Two-Faced Onerep
by BrianKrebs on 20/11/2025
In March 2024, Mozilla said it was winding down its collaboration with Onerep — an identity protection service offered with the Firefox web browser that promises to remove users from hundreds of people-search sites — after KrebsOnSecurity revealed Onerep’s founder had created dozens of people-search services and was continuing to operate at least one of them. Sixteen months later [...]
See full content
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
on 20/11/2025
Posted by Dave Kleidermacher, VP, Platforms Security & Privacy, Google
Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy regardless of the phone they use. That’s why Android has been building experiences that help you stay connected across platforms.
As part of our efforts to continue to make cross-pla [...]
See full content
Scam USPS and E-Z Pass Texts and Websites
on 20/11/2025
Google has filed a complaint in court that details the scam:
In a complaint filed Wednesday, the tech giant accused “a cybercriminal group in China” of selling “phishing for dummies” kits. The kits help unsavvy fraudsters easily “execute a large-scale phishing campaign,” tricking hordes of unsuspecting people into “disclosing sensitive information like passwords, credit car [...]
See full content
Out-of-bounds read in HTTP method handling causes undefined behavior and potential crash This is sharp, Gaurav. Weve got a real memory-safety bug ins
on 20/11/2025
curl disclosed a bug submitted by gaurav_7777: https://hackerone.com/reports/3434510 [...]
See full content
AI Hacking CTF | Win Prizes!!! | AMA
on 20/11/2025
See full content
Lack of minimum value bid wheel verification on customer_bid in Rental Trips
on 20/11/2025
Bykea disclosed a bug submitted by sameer_ali: https://hackerone.com/reports/3328343 [...]
See full content
Customer can cancel a individual booking in a batch, causing locking of partner.
on 20/11/2025
Bykea disclosed a bug submitted by sameer_ali: https://hackerone.com/reports/3295503 [...]
See full content
Why Datadog is a 2025 Cloud Security Leader
on 20/11/2025
A recap of Datadog's awards from the 2025 Latio Cloud Security Market Report [...]
See full content
Existence of completed pods allows for bypass of Kubernetes NetworkPolicy
on 19/11/2025
AWS VDP disclosed a bug submitted by savannabungee: https://hackerone.com/reports/3328291 [...]
See full content
The Cloudflare Outage May Be a Security Roadmap
by BrianKrebs on 19/11/2025
An intermittent outage at Cloudflare on Tuesday briefly knocked many of the Internet’s top destinations offline. Some affected Cloudflare customers were able to pivot away from the platform temporarily so that visitors could still access their websites. But security experts say doing so may have also triggered an impromptu network penetration test for organizations that have come to rely on [...]
See full content
Unrestricted setPerPage allows huge result sets / resource exhaustion / mass log retrieval
on 19/11/2025
Revive Adserver disclosed a bug submitted by vidang04: https://hackerone.com/reports/3413890 [...]
See full content
Username normalization missing allows visually indistinguishable accounts (Whitespace-Based Impersonation)
on 19/11/2025
Revive Adserver disclosed a bug submitted by yoyomiski: https://hackerone.com/reports/3413764 [...]
See full content
Stored-XSS in campaign name displayed in Banners modal
on 19/11/2025
Revive Adserver disclosed a bug submitted by vidang04: https://hackerone.com/reports/3411750 [...]
See full content
Stored-XSS in Banner Name field
on 19/11/2025
Revive Adserver disclosed a bug submitted by yoyomiski: https://hackerone.com/reports/3404968 [...]
See full content
Reflected XSS in /admin/banner-zone.php (v6.0.0+)
on 19/11/2025
Revive Adserver disclosed a bug submitted by vidang04: https://hackerone.com/reports/3403727 [...]
See full content
Information Disclosure via Verbose Error Messages
on 19/11/2025
Revive Adserver disclosed a bug submitted by yoyomiski: https://hackerone.com/reports/3403450 [...]
See full content
IDOR Vulnerability in Banner Deletion
on 19/11/2025
Revive Adserver disclosed a bug submitted by cyberjoker: https://hackerone.com/reports/3401612 [...]
See full content
Information Disclosure via Add user lookup in Account Management (User Access)
on 19/11/2025
Revive Adserver disclosed a bug submitted by yoyomiski: https://hackerone.com/reports/3401464 [...]
See full content
Stored XSS in Conversion Statistics via Tracker Name
on 19/11/2025
Revive Adserver disclosed a bug submitted by cyberjoker: https://hackerone.com/reports/3400506 [...]
See full content
Stored XSS on inventory-retrieve.php
on 19/11/2025
Revive Adserver disclosed a bug submitted by lu3ky-13: https://hackerone.com/reports/3399809 [...]
See full content
Improper sanitisation of input in the settings could cause DoS
on 19/11/2025
Revive Adserver disclosed a bug submitted by lu3ky-13: https://hackerone.com/reports/3399218 [...]
See full content
Reflected XSS in account-preferences-plugin.php
on 19/11/2025
Revive Adserver disclosed a bug submitted by lu3ky-13: https://hackerone.com/reports/3399191 [...]
See full content
Authorization bypass allows changing email address of other users
on 19/11/2025
Revive Adserver disclosed a bug submitted by yoyomiski: https://hackerone.com/reports/3398283 [...]
See full content
Black Friday and Cyber Monday price distortion identification
by Eleanor Barlow on 19/11/2025
Brick-and-click sales leaving no dollar behind
The evolution of the internet and, with it, international levels of e-commerce, meant that Black Friday soon became the unofficial start of winter purchases ahead of holiday festivities across the globe. In the early 2000s, Cyber Monday, held on the Monday after Thanksgiving, materialized to encourage people to shop online following the black-Friday [...]
See full content
Double free in tool_ssls_load()
on 18/11/2025
curl disclosed a bug submitted by xkernel: https://hackerone.com/reports/3431180 [...]
See full content
Hack This Bot & Win Prizes!
on 18/11/2025
See full content
Credentials in URL
on 18/11/2025
See full content
Science drives progress and creativity fuels discovery
on 18/11/2025
See full content
Microsoft Entra ID INSECURE DEFAULTS
on 18/11/2025
See full content
We found cryptography bugs in the elliptic library using Wycheproof
on 18/11/2025
Trail of Bits is publicly disclosing two vulnerabilities in elliptic, a widely used JavaScript library for elliptic curve cryptography that is downloaded over 10 million times weekly and is used by close to 3,000 projects. These vulnerabilities, caused by missing modular reductions and a missing length check, could allow attackers to forge signatures or prevent valid signatures from being verified [...]
See full content
Bypass of Cloudflare's Cache Keys and WAF via header overflow
on 18/11/2025
Cloudflare Public Bug Bounty disclosed a bug submitted by david96: https://hackerone.com/reports/3027461 [...]
See full content
Intigriti wins ‘Security Innovation of the Year’ at the 2025 UK IT Industry Awards
by Eleanor Barlow on 18/11/2025
We are thrilled to announce that Intigriti has won Security Innovation of the Year at the UK IT Industry Awards 2025.
A powerful recognition for innovation
The UK IT Industry Awards are designed to celebrate organizations, teams, projects, technologies, and individuals who continue to help shape the future of IT.
This accolade is a testament to the ingenuity, dedication, and forward-thinking appro [...]
See full content
Raid weekend update 21 reports done
on 17/11/2025
See full content
it's not that complicated
on 17/11/2025
See full content
Hacking with Nuclei: Uncovering .git Secrets
on 17/11/2025
See full content
How to Use Nuclei And Automate Cross-Site Scripting Vulnerabilities
on 17/11/2025
See full content
Authentication Bypass in Subscription Management Endpoint
on 17/11/2025
lemlist disclosed a bug submitted by 0hmz: https://hackerone.com/reports/3417162 [...]
See full content
Double-free vulnerability in libcurl with rustls via NoServerCertVerifier condition leads to application crash
on 16/11/2025
curl disclosed a bug submitted by xkernel: https://hackerone.com/reports/3427670 [...]
See full content
Microsoft Patch Tuesday, November 2025 Edition
by BrianKrebs on 16/11/2025
Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being exploited. Microsoft also fixed a glitch that prevented some Windows 10 users from taking advantage of an extra year of security updates, which is nice because the zero-day flaw and other critical weakness [...]
See full content
Bug Bounty Tips In 2025 With @ZACK0X01
on 16/11/2025
See full content
a new kind of Capture The Flag hacking
on 16/11/2025
See full content
Incorrect sizeof() in Rustls Backend Memory Allocation
on 15/11/2025
curl disclosed a bug submitted by pelioro: https://hackerone.com/reports/3427460 [...]
See full content
Off-by-One Buffer Overflow in SMB Path Handler
on 15/11/2025
curl disclosed a bug submitted by pelioro: https://hackerone.com/reports/3427343 [...]
See full content
Malicious server forces .curlrc creation via curl -OJ leading to local file exfiltration
on 15/11/2025
curl disclosed a bug submitted by djogho: https://hackerone.com/reports/3427194 [...]
See full content