InfoSec Planet

A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.

Rails::HTML::Sanitizer.allowed_uri? returns true for entity-encoded control-character-split javascript: URLs

on 18/04/2026

Ruby on Rails disclosed a bug submitted by smlee: https://hackerone.com/reports/3601655 [...]

See full content

Sould I focus on BAC or multiple exploits

on 18/04/2026

See full content

Friday Squid Blogging: New Giant Squid Video

on 17/04/2026

Pretty fantastic video from Japan of a giant squid eating another squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]

See full content

libcurl stale CURLOPT_AUTOREFERER leaks a previous request URL to a different origin on a reused easy handle

on 17/04/2026

curl disclosed a bug submitted by asdwe: https://hackerone.com/reports/3673277 [...]

See full content

JHT Livestream: mitmproxy & OpenWRT to read HTTPS traffic!

on 17/04/2026

See full content

Getting Started with Windows Prefetch

on 17/04/2026

See full content

Mythos and Cybersecurity

on 17/04/2026

Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors of critical infrastructure—under an in [...]

See full content

We beat Google’s zero-knowledge proof of quantum cryptanalysis

on 17/04/2026

Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum computers will break elliptic curve cryptography keys in as little as 9 minutes. Today, Trail of Bits is publishing our own zero-knowledge proof that significantly improves Google’s on all metrics. Our result is not due to some quantum breakthrou [...]

See full content

Common misconceptions debugged!

by Greg Jenkins on 17/04/2026

AI and the growing ecosystem of tools built around it have now moved beyond early experimentation and into everyday use across the bug bounty community. What initially showed up as AI-written reports has evolved into something broader: changes in how researchers work, how submissions scale, and how programs experience that volume. In the first part of this series, we explored how AI is shifting th [...]

See full content

Introducing the official Burp Ambassador Program

on 16/04/2026

Why we’re launching the program What it means to be a Burp Ambassador What we’re aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3rius Looking ahead Get Involved - B [...]

See full content

Here’s everything I have learned from making $2M in bounties. #bugbounty

on 16/04/2026

See full content

Residual Malicious Payloads on HackerOne after Vulnerability Fixes

on 16/04/2026

HackerOne disclosed a bug submitted by joejoe5: https://hackerone.com/reports/3168691 [...]

See full content

DOS via Mutation Aliasing in GraphQL Account Recovery Phone Number Verification API

on 16/04/2026

HackerOne disclosed a bug submitted by hellokbit: https://hackerone.com/reports/3287208 - Bounty: $12500 [...]

See full content

Human Trust of AI Agents

on 16/04/2026

Interesting research: “Humans expect rationality and cooperation from LLM opponents in strategic games.” Abstract: As Large Language Models (LLMs) integrate into our social and economic interactions, we need to deepen our understanding of how humans respond to LLMs opponents in strategic settings. We present the results of the first controlled monetarily-incentivised laboratory experim [...]

See full content

lib/http2.c: SSL connections accept non-HTTP push schemes (incomplete fix for 2e8c922a)

on 16/04/2026

curl disclosed a bug submitted by hybirdss: https://hackerone.com/reports/3674275 [...]

See full content

The case for dependency cooldowns in a post-axios world

on 16/04/2026

Understanding npm and the importance of dependency cooldowns. [...]

See full content

Authorization header leak in ssrf_filter via cross-host redirect leads to credential theft and unauthorized access

on 15/04/2026

arkadiyt-projects disclosed a bug submitted by argareksapatii: https://hackerone.com/reports/3642600 [...]

See full content

What can we say?

on 15/04/2026

See full content

SQL Injection Detection Bypass in AWS WAF Managed Rules (AWSManagedRulesSQLiRuleSet)

on 15/04/2026

AWS VDP disclosed a bug submitted by killnet-edc: https://hackerone.com/reports/3591725 [...]

See full content

Defense in Depth, Medieval Style

on 15/04/2026

This article on the walls of Constantinople is fascinating. The system comprised four defensive lines arranged in formidable layers: The brick-lined ditch, divided by bulkheads and often flooded, 15­-20 meters wide and up to 7 meters deep. A low breastwork, about 2 meters high, enabling defenders to fire freely from behind. The outer wall, 8 meters tall and 2.8 meters thick, with 82 projecting to [...]

See full content

Patch Tuesday, April 2026 Edition

by BrianKrebs on 14/04/2026

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed “BlueHammer.” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited [...]

See full content

DOM XSS in `fizzy.do` import filename preview enables one-click victim account takeover

on 14/04/2026

Basecamp disclosed a bug submitted by xavlimsg: https://hackerone.com/reports/3608199 - Bounty: $500 [...]

See full content

Improper Access Control in `fizzy.do` import flow allows cross-tenant ActionText reference resolution and data disclosure

on 14/04/2026

Basecamp disclosed a bug submitted by xavlimsg: https://hackerone.com/reports/3543475 - Bounty: $218 [...]

See full content

BOLA/IDOR in Out-of-Office API allows any authenticated user to read other users' absence data

on 14/04/2026

Nextcloud disclosed a bug submitted by cyberjoker: https://hackerone.com/reports/3382343 [...]

See full content

Cybersecurity Books to Read: DFIR Investigative Mindset

on 14/04/2026

See full content

Join this Q&A session!

on 14/04/2026

See full content

Upcoming Speaking Engagements

on 14/04/2026

This is a current list of where and when I am scheduled to speak: I’m speaking at DemocracyXChange 2026 in Toronto, Ontario, Canada, on April 18, 2026. I’m speaking at the SANS AI Cybersecurity Summit 2026 in Arlington, Virginia, USA, at 9:40 AM ET on April 20, 2026. I’m speaking at the Greater Good Gathering in New York City, USA, on Tuesday, April 21, 2026. I’m speaking at the Nemertes [N [...]

See full content

How Hackers Are Thinking About AI

on 14/04/2026

Interesting paper: “What hackers talk about when they talk about AI: Early-stage diffusion of a cybercrime innovation.” Abstract: The rapid expansion of artificial intelligence (AI) is raising concerns about its potential to transform cybercrime. Beyond empowering novice offenders, AI stands to intensify the scale and sophistication of attacks by seasoned cybercriminals. This paper exa [...]

See full content

[Variation of #3321406] YetAnother 1-Click Chaining of Self-XSS, Cookie Tossing and AntiCSRF Token Prediction leads to auto approval in AccessTempAuth

on 14/04/2026

Cloudflare Public Bug Bounty disclosed a bug submitted by matured_kazama: https://hackerone.com/reports/3423950 [...]

See full content

[Variation of #1554049] 1-Click Chaining of Self-XSS, Cookie Tossing and AntiCSRF Token Prediction leads to auto approval in Access Temp Auth

on 14/04/2026

Cloudflare Public Bug Bounty disclosed a bug submitted by matured_kazama: https://hackerone.com/reports/3321406 [...]

See full content

Brave Shields Domain Reordering Leads to Origin Confusion

on 13/04/2026

Brave Software disclosed a bug submitted by mousepadkalilinux12: https://hackerone.com/reports/3665151 - Bounty: $100 [...]

See full content

Turn your Nmap scan into a clean report in seconds ⚡ #nmap #hacking #cybersecurity

on 13/04/2026

See full content

On Anthropic’s Mythos Preview and Project Glasswing

on 13/04/2026

The cybersecurity industry is obsessing over Anthropic’s new model, Claude Mythos Preview, and its effects on cybersecurity. Anthropic said that it is not releasing it to the general public because of its cyberattack capabilities, and has launched Project Glasswing to run the model against a whole slew of public domain and proprietary software, with the aim of finding and patching all the vu [...]

See full content

Credential Disclosure via Unvalidated directDownloadUrl (Missing DontAddCredentialsAttribute)

on 13/04/2026

Nextcloud disclosed a bug submitted by py0zz1: https://hackerone.com/reports/3400143 - Bounty: $250 [...]

See full content

Is AI Killing Bug Bounty?

on 13/04/2026

See full content

AI Chatbots and Trust

on 13/04/2026

All the leading AI chatbots are sycophantic, and that’s a problem: Participants rated sycophantic AI responses as more trustworthy than balanced ones. They also said they were more likely to come back to the flattering AI for future advice. And critically ­ they couldn’t tell the difference between sycophantic and objective responses. Both felt equally “neutral” to them. On [...]

See full content

This XSS Tool Is AMAZING!

on 13/04/2026

See full content

Argument Injection via curl Short-Flag Grouping

on 13/04/2026

curl disclosed a bug submitted by midoussa7: https://hackerone.com/reports/3669305 [...]

See full content

How Intigriti uses AI in their submissions

on 11/04/2026

See full content

Integer Overflow/Signedness Mismatch in Printf Precision for HTTP/2 Trailer Headers

on 11/04/2026

curl disclosed a bug submitted by pwnpwn: https://hackerone.com/reports/3665363 [...]

See full content

Friday Squid Blogging: Squid Overfishing in the South Pacific

on 10/04/2026

Regulation is hard: The South Pacific Regional Fisheries Management Organization (SPRFMO) oversees fishing across roughly 59 million square kilometers (22 million square miles) of the South Pacific high seas, trying to impose order on a region double the size of Africa, where distant-water fleets pursue species ranging from jack mackerel to jumbo flying squid. The latter dominated this year’ [...]

See full content

Encryption context keys and values logged at INFO level

on 10/04/2026

AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620760 [...]

See full content

Bringing Rust to the Pixel Baseband

on 10/04/2026

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its p [...]

See full content

Sen. Sanders Talks to Claude About AI and Privacy

on 10/04/2026

Claude is actually pretty good on the issues. [...]

See full content

Is ClaudeAI useful for bug bounty?

on 10/04/2026

See full content

Open Redirect in Rocket.Chat

on 10/04/2026

Rocket.Chat disclosed a bug submitted by soohyun: https://hackerone.com/reports/3418031 [...]

See full content

[Vertical Privilege Escalation] User can Unapproved any Approved Translation at [/translations/unapprove/]

on 10/04/2026

Mozilla disclosed a bug submitted by adilnbabras: https://hackerone.com/reports/3020021 [...]

See full content

User Can Delete Other Users' Personal Access Tokens at /delete-token/{token_id}/ on Mozilla Pontoon

on 10/04/2026

Mozilla disclosed a bug submitted by adilnbabras: https://hackerone.com/reports/3325582 [...]

See full content

A(I) future of Bug Bounty

by Chris Holt on 10/04/2026

AI and all the tools built around related technologies have been working their way into the Bug Bounty community for a little over a year now and by around March 2025 we started seeing notably AI-written reports. It is time to take stock of what impact they have wrought already so we can look to the future and begin to address the reality and some of the fears surrounding this new technology. This [...]

See full content

Protecting Cookies with Device Bound Session Credentials

on 09/04/2026

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to co [...]

See full content

HUGE AI-powered Microsoft Account phishing campaign

on 09/04/2026

See full content

How New AI Models Are Reshaping Cyber Risk at Scale

on 09/04/2026

See full content

Memory leak in gem decode logic can allow attacker to take down Rubygems.org application

on 09/04/2026

RubyGems disclosed a bug submitted by mclaren650sspider: https://hackerone.com/reports/3079931 [...]

See full content

What are WebSockets?

on 09/04/2026

See full content

Master C and C++ with our new Testing Handbook chapter

on 09/04/2026

We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code. We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases and organized them into sections covering Linux, Windows, and seccomp. Whereas other handbook chapters focus on static and dynamic analysis, this chapter offers a strong basis for manu [...]

See full content

Is Cybersecurity Dead? Should You Start Bug Bounty?

on 09/04/2026

See full content

libcurl: Integer truncation in curl_easy_ssls_import() causes TLS sessions to never expire

on 09/04/2026

curl disclosed a bug submitted by adityasunny_06: https://hackerone.com/reports/3658049 [...]

See full content

Bye Bye Bellini! | Andrew Bellini's Farewell Stream | Cybersecurity | AMA

on 09/04/2026

See full content

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562

on 09/04/2026

A look at how Kubernetes CVE-2020-8562 allows attackers to bypass API server proxy protections using DNS rebinding [...]

See full content

wasResumeUsed on /api-internal/api.htm endpoint leaking other user's resume usage status

on 08/04/2026

Glassdoor disclosed a bug submitted by auxilus: https://hackerone.com/reports/909084 [...]

See full content

Account Takeover

on 08/04/2026

Glassdoor disclosed a bug submitted by amakki: https://hackerone.com/reports/970763 [...]

See full content

Open Redirect

on 08/04/2026

Glassdoor disclosed a bug submitted by z3ron3: https://hackerone.com/reports/818094 [...]

See full content

robots take over the world or something i guess idk

on 08/04/2026

See full content

How Teenage Hackers Hijack the Internet (with Joe Tidy!)

on 08/04/2026

See full content

Russia Hacked Routers to Steal Microsoft Office Tokens

by BrianKrebs on 07/04/2026

Hackers linked to Russia’s military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks without deploying any malicious software or code. Micros [...]

See full content

Health check errors silently dropped when channel buffer full

on 07/04/2026

AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620761 [...]

See full content

Hackers make FAKE notifications

on 07/04/2026

See full content

IDOR on via direct photo URL leads to unauthorized access to deleted and other users' photos

on 07/04/2026

Nextcloud disclosed a bug submitted by shiva2550: https://hackerone.com/reports/3518758 [...]

See full content

PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses

on 07/04/2026

More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We’re excited to announce a new partnership with Meta [...]

See full content

What we learned about TEE security from auditing WhatsApp's Private Inference

on 07/04/2026

WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such as message summarization. To make this possible, Meta built a system that processes encrypted user messages inside trusted execution environments (TEEs), secure hardware enclaves designed so that not even Meta can access the plaintext. Our now [...]

See full content

no_proxy IDN mismatch: Unicode hostnames bypass proxy exclusion list

on 07/04/2026

curl disclosed a bug submitted by mzfr: https://hackerone.com/reports/3650443 [...]

See full content

FTP entrypath accepts 0xFF (Telnet IAC) through incomplete ISCNTRL filter, sent on wire via CWD on connection reuse

on 07/04/2026

curl disclosed a bug submitted by mzfr: https://hackerone.com/reports/3650473 [...]

See full content

Improper enforcement of CURLOPT_SOCKS5_AUTH due to missing reuse key validation in libcurl

on 07/04/2026

curl disclosed a bug submitted by cutiapretaa: https://hackerone.com/reports/3650435 [...]

See full content

Five key takeaways from the UK’s new Cyber Security & Resilience Bill

by Ed Parsons on 07/04/2026

The content of the Cyber Security & Resilience Bill (CSRB) recently introduced to Parliament contained few surprises. Having spent a significant amount of time working with European cyber-security frameworks, particularly NIS2, I see the Bill as both a continuation of the trend towards common approaches, and a signal of how seriously governments now take cyber risk. From my perspective, there are [...]

See full content

Cross-Site Leakage of Review Ownership via Navigation Detection

on 06/04/2026

Glassdoor disclosed a bug submitted by downgrade: https://hackerone.com/reports/2516237 [...]

See full content

eflected Vulnerability in Glassdoor Blog earch

on 06/04/2026

Glassdoor disclosed a bug submitted by zorixu: https://hackerone.com/reports/2682538 [...]

See full content

Full account takeover without user Interaction

on 06/04/2026

Glassdoor disclosed a bug submitted by imtheking: https://hackerone.com/reports/1820146 [...]

See full content

Reported Denial of Service

on 06/04/2026

Monero disclosed a bug submitted by jehrenhofermagicgrants: https://hackerone.com/reports/3241102 [...]

See full content

Reported RPC Overflow

on 06/04/2026

Monero disclosed a bug submitted by jehrenhofermagicgrants: https://hackerone.com/reports/3240792 [...]

See full content

Unauthorized usage of External API Key (Usage of Google Maps API Key ==> $$$

on 06/04/2026

Glassdoor disclosed a bug submitted by avielt: https://hackerone.com/reports/881118 [...]

See full content

100 criticals in one week? Great news. Also… a lot 😅

on 06/04/2026

See full content

AI Chatbots Can Hijack Accounts: The New XSS Threat

on 06/04/2026

See full content

Markdown Image Vulnerability Quick Security Test

on 06/04/2026

See full content

An AI Hacker Showed Me How to Exfil Data in Zero Clicks

on 06/04/2026

See full content

Capie is 1 euro

on 06/04/2026

See full content

# SCURLOPT_SSH_KNOWNHOSTS and host fingerprint pins are silently bypassed when an SSH connection is reused from the connection pool

on 06/04/2026

curl disclosed a bug submitted by spiderchan26: https://hackerone.com/reports/3645415 [...]

See full content

SMTP Command Injection via CRLF in libcurl MAIL_FROM / MAIL_RCPT (lib/smtp.c)

on 06/04/2026

curl disclosed a bug submitted by divsz: https://hackerone.com/reports/3651975 [...]

See full content

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

by BrianKrebs on 06/04/2026

An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021. Shchukin was n [...]

See full content

ignoring 'options' when doing connection reuse

on 05/04/2026

curl disclosed a bug submitted by spichanlio76: https://hackerone.com/reports/3646914 [...]

See full content

Exploiting XSS Via Markdown - Medium Reading

on 04/04/2026

See full content

Data race in Curl_dnscache_add_negative() corrupts shared DNS cache heap corruption and double-free when using CURLOPT_SHARE with CURL_LOCK_DATA_DNS

on 04/04/2026

curl disclosed a bug submitted by intrax: https://hackerone.com/reports/3645361 [...]

See full content

AI Cyber Defense Ops Course Launch!

on 04/04/2026

See full content

Internal application wrapper or script using curl

on 03/04/2026

curl disclosed a bug submitted by rougerseven7: https://hackerone.com/reports/3648199 [...]

See full content

Getting Started With The Windows Registry

on 03/04/2026

See full content

Missing server identity policy enforcement in SSH connection reuse allows host key verification bypass via pool poisoning

on 03/04/2026

curl disclosed a bug submitted by intrax71: https://hackerone.com/reports/3640932 [...]

See full content

Cookie attribute TAB injection regression in Set-Cookie parsing

on 03/04/2026

curl disclosed a bug submitted by calaba_zas: https://hackerone.com/reports/3641893 [...]

See full content

Extremely Easy Identity Management (with Authentik!)

on 03/04/2026

See full content

Simplifying MBA obfuscation with CoBRA

on 03/04/2026

Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and software protectors rely on it because no standard simplification technique covers both domains simultaneously; algebraic simplifiers don’t understand bitwise logic, and Boolean minimizers can’t handle arithmetic. We’re releasing CoBRA, an [...]

See full content

The Payload Podcast #005 - AI with Shane Caldwell

on 03/04/2026

See full content

Google Workspace’s continuous approach to mitigating indirect prompt injections

on 02/04/2026

Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This ma [...]

See full content

Sources

The content of this page is fetched from the following sources:

  1. Datadog Security Labs
  2. The Trail of Bits Blog
  3. Schneier on Security
  4. Krebs on Security
  5. Google Online Security Blog
  6. $BLOG_TITLE
  7. Agarri : Sécurité informatique offensive
  8. Alex Chapman's Blog
  9. www.alphabot.com
  10. ziot
  11. Bug Bounty Reports Explained
  12. Bugcrowd
  13. cat ~/footstep.ninja/blog.txt
  14. Ezequiel Pereira
  15. HackerOne
  16. surajdisoja.me
  17. InsiderPhD
  18. Intigriti
  19. John Hammond
  20. LiveOverflow
  21. NahamSec
  22. PortSwigger Blog
  23. Rana Khalil
  24. Richard’s Infosec blog
  25. Ron Chan
  26. ropnop blog
  27. STÖK
  28. Sun Knudsen
  29. The Cyber Mentor
  30. The unofficial HackerOne disclosure timeline
  31. The XSS Rat
  32. TomNomNom
  33. Wallarm