curl Missing Sec-WebSocket-Accept Verification Enables MITM WebSocket Session Hijacking on 05/08/2026
curl disclosed a bug submitted by kiyin: https://hackerone.com/reports/3917775 [...]
curl disclosed a bug submitted by kiyin: https://hackerone.com/reports/3917775 [...]
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service with your trusted enclaves comes with new threats, even if that service comes from the same provider. In this blog post—t [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3699522 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3698862 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3693636 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3700036 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3723315 [...]
This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or [...]
Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3687543 [...]
Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I wo [...]
curl disclosed a bug submitted by juthawong: https://hackerone.com/reports/3911968 [...]
"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray H. is a Security Analyst at a managed security service provider with over 2500 employees world [...]
And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses. What seems to be the issue is a user [...]
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of [...]
On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware. [...]
AWS VDP disclosed a bug submitted by sh3d0w: https://hackerone.com/reports/3478646 [...]
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or [...]
Rocket.Chat disclosed a bug submitted by howtoplay: https://hackerone.com/reports/3514640 [...]
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how goo [...]
curl disclosed a bug submitted by dark_river: https://hackerone.com/reports/3911605 [...]
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings. [...]
Liberapay disclosed a bug submitted by its9me: https://hackerone.com/reports/3878586 - Bounty: $100 [...]
The Squid is a new scientific machine: One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could d [...]
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Cl [...]
Node.js disclosed a bug submitted by nadav0077: https://hackerone.com/reports/3723248 [...]
Tucows (VDP) disclosed a bug submitted by axolot23: https://hackerone.com/reports/3644182 [...]
Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor Swift’s wedding. Evan Greer—one of the people that MSG alerts on—comments: Ironically, Swift herself ha [...]
Hello hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much more! Let's dive in! Intigriti turns 10! 🚀 Ten years ago, the idea that inviting [...]
phpBB disclosed a bug submitted by a7mmr: https://hackerone.com/reports/3606773 [...]
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a [...]
He’s being prosecuted for giving border officials a code that wiped his phone: The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wi [...]
Node.js disclosed a bug submitted by sinan-polat: https://hackerone.com/reports/3815767 [...]
This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is o [...]
Ruby on Rails disclosed a bug submitted by friedchicken112211: https://hackerone.com/reports/3553340 [...]
This essay originally appeared in The Guardian. I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn’t they [...]
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that show what can go wrong in that code. Together, they account for more than $20M in losses. Neither incident stemmed from a [...]
Node.js disclosed a bug submitted by vnyuh: https://hackerone.com/reports/3812439 [...]
Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are mishandled, closed incorrectly, downgraded in severity, or left unresolved for extended periods. When th [...]
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3638909 [...]
Node.js disclosed a bug submitted by sy2n0: https://hackerone.com/reports/3761342 [...]
HackerOne disclosed a bug submitted by 0v3rw4tch: https://hackerone.com/reports/3577216 [...]
Node.js disclosed a bug submitted by yottt: https://hackerone.com/reports/3816840 [...]
Node.js disclosed a bug submitted by 0xoroot: https://hackerone.com/reports/3838601 [...]
Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3473145 [...]
AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3633146 [...]
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at some of the most widely used, heavily audited codebases in the world, like Rust, curl, and zlib. One tool came up again and [...]
Key takeaways RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does. In simple QA systems, that may mean misinformation or unsafe recommendations. In agentic systems with tools and permissions, it can become data leakage, un [...]
In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, "the AI went rogue," is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the [...]
AWS VDP disclosed a bug submitted by nick_frichette_dd: https://hackerone.com/reports/3775702 [...]
Rocket.Chat disclosed a bug submitted by 0jayden: https://hackerone.com/reports/3827674 [...]
Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries [...]
We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act. [...]
Monero disclosed a bug submitted by redlobsterzzz: https://hackerone.com/reports/3621606 [...]
The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant, the more its access, permissions, and actions need guardrails. This blog takes a look at the lethal [...]
AWS VDP disclosed a bug submitted by notnotnotveg: https://hackerone.com/reports/3809407 [...]
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3641229 [...]
8x8 disclosed a bug submitted by kyotozzx: https://hackerone.com/reports/3800870 - Bounty: $1337 [...]
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traff [...]
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3588801 [...]
Monero disclosed a bug submitted by int0ha_: https://hackerone.com/reports/3738727 [...]
What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What we believe security teams will need next: earlier signals that support action before the next repor [...]
Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass [...]
Rocket.Chat disclosed a bug submitted by olidayw: https://hackerone.com/reports/3779690 [...]
GitHub disclosed a bug submitted by vaib25vicky: https://hackerone.com/reports/3713965 [...]
AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3632577 [...]