InfoSec Planet
A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.
Attacking the MCP Trust Boundary
by Chandler Johnson on 22/04/2026
Every secure API draws a line between code and data. HTTP separates headers from bodies. SQL has prepared statements. Even email distinguishes the envelope from the message. The Model Context Protocol (MCP), the fast-growing standard for connecting AI agents to external services, inherits that gap from the models it sits on top of. Its central premise is that a language model reads tool descripti [...]
See full content
ICE Uses Graphite Spyware
on 22/04/2026
ICE has admitted that it uses spyware from the Israeli company Graphite.
[...]
See full content
How to approach a bug bounty target
on 22/04/2026
See full content
Cybersecurity certs
on 22/04/2026
See full content
Complete authentication bypass to admin permissions
on 22/04/2026
Rocket.Chat disclosed a bug submitted by npc: https://hackerone.com/reports/3564655 [...]
See full content
Bug Bounty Guide - SSRF 101
on 21/04/2026
See full content
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
by BrianKrebs on 21/04/2026
A 24-year-old British national and senior member of the cybercrime group “Scattered Spider” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of doll [...]
See full content
The Dawn of AI Warfare (with Katrina Manson)
on 21/04/2026
See full content
Why API Discovery Is the First Step to Securing AI
by Tim Erlin on 21/04/2026
TL;DR
AI risk doesn’t live in the model. It lives in the APIs behind it. Every AI interaction triggers a chain of API calls across your environment. Many of those APIs aren’t documented or tracked. That’s your real exposure.
Shadow API discovery gives you visibility into those hidden endpoints, so you can find them before attackers do. If you don’t know which APIs your AI relies on, you can [...]
See full content
Mexican Surveillance Company
on 21/04/2026
Grupo Seguritech is a Mexican surveillance company that is expanding into the US.
[...]
See full content
The Payload Podcast #005 - Casey Smith
on 21/04/2026
See full content
SVG filter primitives bypass remote image blocking, enabling email tracking without consent.
on 20/04/2026
Nextcloud disclosed a bug submitted by nullcathedral: https://hackerone.com/reports/3486747 [...]
See full content
position: fixed !important bypasses CSS sanitizer's fixed-position mitigation, enabling full-viewport phishing overlays.
on 20/04/2026
Nextcloud disclosed a bug submitted by nullcathedral: https://hackerone.com/reports/3590586 [...]
See full content
Unquoted body background attribute enables CSS injection that bypasses remote image blocking
on 20/04/2026
Nextcloud disclosed a bug submitted by nullcathedral: https://hackerone.com/reports/3590583 [...]
See full content
SMIL values and by attributes bypass remote image blocking via unvalidated resource-loading animations, enabling email tracking without consent
on 20/04/2026
Nextcloud disclosed a bug submitted by nullcathedral: https://hackerone.com/reports/3590576 [...]
See full content
Is “Satoshi Nakamoto” Really Adam Back?
on 20/04/2026
The New York Times has a long article where the author lays out an impressive array of circumstantial evidence that the inventor of Bitcoin is the cypherpunk Adam Back.
I don’t know. The article is convincing, but it’s written to be convincing.
I can’t remember if I ever met Adam. I was a member of the Cypherpunks mailing list for a while, but I was never really an active partici [...]
See full content
libcurl omits IPv6 zoneid from host identity and leaks credentials/cookies across scoped link-local realms
on 19/04/2026
curl disclosed a bug submitted by valvelvel: https://hackerone.com/reports/3680680 [...]
See full content
Digest Auth State Leak on Cross-Origin Redirect via Netrc - Username and Password Hash Sent to Wrong Host
on 19/04/2026
curl disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3680038 [...]
See full content
Stored XSS in attachment-display exploitable through SameSite
on 19/04/2026
Nextcloud disclosed a bug submitted by aikido_security: https://hackerone.com/reports/3594137 [...]
See full content
libcurl reuses a learned RTSP Session header across different hosts on the same easy handle, enabling cross-host session leak and replay
on 18/04/2026
curl disclosed a bug submitted by skksndk: https://hackerone.com/reports/3680234 [...]
See full content
Rails::HTML::Sanitizer.allowed_uri? returns true for entity-encoded control-character-split javascript: URLs
on 18/04/2026
Ruby on Rails disclosed a bug submitted by smlee: https://hackerone.com/reports/3601655 [...]
See full content
Sould I focus on BAC or multiple exploits
on 18/04/2026
See full content
Friday Squid Blogging: New Giant Squid Video
on 17/04/2026
Pretty fantastic video from Japan of a giant squid eating another squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
[...]
See full content
libcurl stale CURLOPT_AUTOREFERER leaks a previous request URL to a different origin on a reused easy handle
on 17/04/2026
curl disclosed a bug submitted by asdwe: https://hackerone.com/reports/3673277 [...]
See full content
JHT Livestream: mitmproxy & OpenWRT to read HTTPS traffic!
on 17/04/2026
See full content
Mythos and Cybersecurity
on 17/04/2026
Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors of critical infrastructure—under an in [...]
See full content
We beat Google’s zero-knowledge proof of quantum cryptanalysis
on 17/04/2026
Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum computers will break elliptic curve cryptography keys in as little as 9 minutes. Today, Trail of Bits is publishing our own zero-knowledge proof that significantly improves Google’s on all metrics. Our result is not due to some quantum breakthrou [...]
See full content
Common misconceptions debugged!
by Greg Jenkins on 17/04/2026
What you will learn
How AI is boosting researcher productivity
How new researchers are approaching bug bounties
Why the quality of submissions is not declining
How effective triage and coordination are crucial
AI and the growing ecosystem of tools built around it have now moved beyond early experimentation and into everyday use across the bug bounty community. What initially showed up as AI- [...]
See full content
Introducing the official Burp Ambassador Program
on 16/04/2026
Why we’re launching the program What it means to be a Burp Ambassador What we’re aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3rius Looking ahead Get Involved - B [...]
See full content
Residual Malicious Payloads on HackerOne after Vulnerability Fixes
on 16/04/2026
HackerOne disclosed a bug submitted by joejoe5: https://hackerone.com/reports/3168691 [...]
See full content
DOS via Mutation Aliasing in GraphQL Account Recovery Phone Number Verification API
on 16/04/2026
HackerOne disclosed a bug submitted by hellokbit: https://hackerone.com/reports/3287208 - Bounty: $12500 [...]
See full content
Human Trust of AI Agents
on 16/04/2026
Interesting research: “Humans expect rationality and cooperation from LLM opponents in strategic games.”
Abstract: As Large Language Models (LLMs) integrate into our social and economic interactions, we need to deepen our understanding of how humans respond to LLMs opponents in strategic settings. We present the results of the first controlled monetarily-incentivised laboratory experim [...]
See full content
lib/http2.c: SSL connections accept non-HTTP push schemes (incomplete fix for 2e8c922a)
on 16/04/2026
curl disclosed a bug submitted by hybirdss: https://hackerone.com/reports/3674275 [...]
See full content
The case for dependency cooldowns in a post-axios world
on 16/04/2026
Understanding npm and the importance of dependency cooldowns. [...]
See full content
Authorization header leak in ssrf_filter via cross-host redirect leads to credential theft and unauthorized access
on 15/04/2026
arkadiyt-projects disclosed a bug submitted by argareksapatii: https://hackerone.com/reports/3642600 [...]
See full content
SQL Injection Detection Bypass in AWS WAF Managed Rules (AWSManagedRulesSQLiRuleSet)
on 15/04/2026
AWS VDP disclosed a bug submitted by killnet-edc: https://hackerone.com/reports/3591725 [...]
See full content
Defense in Depth, Medieval Style
on 15/04/2026
This article on the walls of Constantinople is fascinating.
The system comprised four defensive lines arranged in formidable layers:
The brick-lined ditch, divided by bulkheads and often flooded, 15-20 meters wide and up to 7 meters deep.
A low breastwork, about 2 meters high, enabling defenders to fire freely from behind.
The outer wall, 8 meters tall and 2.8 meters thick, with 82 projecting to [...]
See full content
Patch Tuesday, April 2026 Edition
by BrianKrebs on 14/04/2026
Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed “BlueHammer.” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited [...]
See full content
DOM XSS in `fizzy.do` import filename preview enables one-click victim account takeover
on 14/04/2026
Basecamp disclosed a bug submitted by xavlimsg: https://hackerone.com/reports/3608199 - Bounty: $500 [...]
See full content
Improper Access Control in `fizzy.do` import flow allows cross-tenant ActionText reference resolution and data disclosure
on 14/04/2026
Basecamp disclosed a bug submitted by xavlimsg: https://hackerone.com/reports/3543475 - Bounty: $218 [...]
See full content
BOLA/IDOR in Out-of-Office API allows any authenticated user to read other users' absence data
on 14/04/2026
Nextcloud disclosed a bug submitted by cyberjoker: https://hackerone.com/reports/3382343 [...]
See full content
Upcoming Speaking Engagements
on 14/04/2026
This is a current list of where and when I am scheduled to speak:
I’m speaking at DemocracyXChange 2026 in Toronto, Ontario, Canada, on April 18, 2026.
I’m speaking at the SANS AI Cybersecurity Summit 2026 in Arlington, Virginia, USA, at 9:40 AM ET on April 20, 2026.
I’m speaking at the Greater Good Gathering in New York City, USA, on Tuesday, April 21, 2026.
I’m speaking at the Nemertes [N [...]
See full content
How Hackers Are Thinking About AI
on 14/04/2026
Interesting paper: “What hackers talk about when they talk about AI: Early-stage diffusion of a cybercrime innovation.”
Abstract: The rapid expansion of artificial intelligence (AI) is raising concerns about its potential to transform cybercrime. Beyond empowering novice offenders, AI stands to intensify the scale and sophistication of attacks by seasoned cybercriminals. This paper exa [...]
See full content
[Variation of #3321406] YetAnother 1-Click Chaining of Self-XSS, Cookie Tossing and AntiCSRF Token Prediction leads to auto approval in AccessTempAuth
on 14/04/2026
Cloudflare Public Bug Bounty disclosed a bug submitted by matured_kazama: https://hackerone.com/reports/3423950 [...]
See full content
[Variation of #1554049] 1-Click Chaining of Self-XSS, Cookie Tossing and AntiCSRF Token Prediction leads to auto approval in Access Temp Auth
on 14/04/2026
Cloudflare Public Bug Bounty disclosed a bug submitted by matured_kazama: https://hackerone.com/reports/3321406 [...]
See full content
Brave Shields Domain Reordering Leads to Origin Confusion
on 13/04/2026
Brave Software disclosed a bug submitted by mousepadkalilinux12: https://hackerone.com/reports/3665151 - Bounty: $100 [...]
See full content
On Anthropic’s Mythos Preview and Project Glasswing
on 13/04/2026
The cybersecurity industry is obsessing over Anthropic’s new model, Claude Mythos Preview, and its effects on cybersecurity. Anthropic said that it is not releasing it to the general public because of its cyberattack capabilities, and has launched Project Glasswing to run the model against a whole slew of public domain and proprietary software, with the aim of finding and patching all the vu [...]
See full content
Credential Disclosure via Unvalidated directDownloadUrl (Missing DontAddCredentialsAttribute)
on 13/04/2026
Nextcloud disclosed a bug submitted by py0zz1: https://hackerone.com/reports/3400143 - Bounty: $250 [...]
See full content
This XSS Tool Is AMAZING!
on 13/04/2026
See full content
Argument Injection via curl Short-Flag Grouping
on 13/04/2026
curl disclosed a bug submitted by midoussa7: https://hackerone.com/reports/3669305 [...]
See full content
How Intigriti uses AI in their submissions
on 11/04/2026
See full content
Integer Overflow/Signedness Mismatch in Printf Precision for HTTP/2 Trailer Headers
on 11/04/2026
curl disclosed a bug submitted by pwnpwn: https://hackerone.com/reports/3665363 [...]
See full content
Encryption context keys and values logged at INFO level
on 10/04/2026
AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620760 [...]
See full content
Bringing Rust to the Pixel Baseband
on 10/04/2026
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team
Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its p [...]
See full content
Is ClaudeAI useful for bug bounty?
on 10/04/2026
See full content
Open Redirect in Rocket.Chat
on 10/04/2026
Rocket.Chat disclosed a bug submitted by soohyun: https://hackerone.com/reports/3418031 [...]
See full content
[Vertical Privilege Escalation] User can Unapproved any Approved Translation at [/translations/unapprove/]
on 10/04/2026
Mozilla disclosed a bug submitted by adilnbabras: https://hackerone.com/reports/3020021 [...]
See full content
User Can Delete Other Users' Personal Access Tokens at /delete-token/{token_id}/ on Mozilla Pontoon
on 10/04/2026
Mozilla disclosed a bug submitted by adilnbabras: https://hackerone.com/reports/3325582 [...]
See full content
A(I) future of Bug Bounty
by Chris Holt on 10/04/2026
What you will learn
How AI is changing bug bounty
Where AI helps security teams
Why human hackers matter
What the future of bug bounty looks like
AI and all the tools built around related technologies have been working their way into the Bug Bounty community for a little over a year now and by around March 2025 we started seeing notably AI-written reports. It is time to take stock of what imp [...]
See full content
Protecting Cookies with Device Bound Session Credentials
on 09/04/2026
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team
Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to co [...]
See full content
HUGE AI-powered Microsoft Account phishing campaign
on 09/04/2026
See full content
Memory leak in gem decode logic can allow attacker to take down Rubygems.org application
on 09/04/2026
RubyGems disclosed a bug submitted by mclaren650sspider: https://hackerone.com/reports/3079931 [...]
See full content
Master C and C++ with our new Testing Handbook chapter
on 09/04/2026
We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code. We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases and organized them into sections covering Linux, Windows, and seccomp. Whereas other handbook chapters focus on static and dynamic analysis, this chapter offers a strong basis for manu [...]
See full content
Is Cybersecurity Dead? Should You Start Bug Bounty?
on 09/04/2026
See full content
libcurl: Integer truncation in curl_easy_ssls_import() causes TLS sessions to never expire
on 09/04/2026
curl disclosed a bug submitted by adityasunny_06: https://hackerone.com/reports/3658049 [...]
See full content
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562
on 09/04/2026
A look at how Kubernetes CVE-2020-8562 allows attackers to bypass API server proxy protections using DNS rebinding [...]
See full content
wasResumeUsed on /api-internal/api.htm endpoint leaking other user's resume usage status
on 08/04/2026
Glassdoor disclosed a bug submitted by auxilus: https://hackerone.com/reports/909084 [...]
See full content
Account Takeover
on 08/04/2026
Glassdoor disclosed a bug submitted by amakki: https://hackerone.com/reports/970763 [...]
See full content
Open Redirect
on 08/04/2026
Glassdoor disclosed a bug submitted by z3ron3: https://hackerone.com/reports/818094 [...]
See full content
robots take over the world or something i guess idk
on 08/04/2026
See full content
How Teenage Hackers Hijack the Internet (with Joe Tidy!)
on 08/04/2026
See full content
Russia Hacked Routers to Steal Microsoft Office Tokens
by BrianKrebs on 07/04/2026
Hackers linked to Russia’s military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks without deploying any malicious software or code.
Micros [...]
See full content
Health check errors silently dropped when channel buffer full
on 07/04/2026
AWS VDP disclosed a bug submitted by misop00p: https://hackerone.com/reports/3620761 [...]
See full content
Hackers make FAKE notifications
on 07/04/2026
See full content
IDOR on via direct photo URL leads to unauthorized access to deleted and other users' photos
on 07/04/2026
Nextcloud disclosed a bug submitted by shiva2550: https://hackerone.com/reports/3518758 [...]
See full content
PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses
on 07/04/2026
More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We’re excited to announce a new partnership with Meta [...]
See full content
What we learned about TEE security from auditing WhatsApp's Private Inference
on 07/04/2026
WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such as message summarization. To make this possible, Meta built a system that processes encrypted user messages inside trusted execution environments (TEEs), secure hardware enclaves designed so that not even Meta can access the plaintext. Our now [...]
See full content
no_proxy IDN mismatch: Unicode hostnames bypass proxy exclusion list
on 07/04/2026
curl disclosed a bug submitted by mzfr: https://hackerone.com/reports/3650443 [...]
See full content
FTP entrypath accepts 0xFF (Telnet IAC) through incomplete ISCNTRL filter, sent on wire via CWD on connection reuse
on 07/04/2026
curl disclosed a bug submitted by mzfr: https://hackerone.com/reports/3650473 [...]
See full content
Improper enforcement of CURLOPT_SOCKS5_AUTH due to missing reuse key validation in libcurl
on 07/04/2026
curl disclosed a bug submitted by cutiapretaa: https://hackerone.com/reports/3650435 [...]
See full content
Five key takeaways from the UK’s new Cyber Security & Resilience Bill
by Ed Parsons on 07/04/2026
What You Will Learn
What the UK Cyber Security & Resilience Bill covers
Which organizations and sectors will be affected
New incident reporting and regulatory requirements
How to prepare your organization for compliance
The content of the Cyber Security & Resilience Bill (CSRB) recently introduced to Parliament contained few surprises. Having spent a significant amount of time working with E [...]
See full content
Cross-Site Leakage of Review Ownership via Navigation Detection
on 06/04/2026
Glassdoor disclosed a bug submitted by downgrade: https://hackerone.com/reports/2516237 [...]
See full content
eflected Vulnerability in Glassdoor Blog earch
on 06/04/2026
Glassdoor disclosed a bug submitted by zorixu: https://hackerone.com/reports/2682538 [...]
See full content
Full account takeover without user Interaction
on 06/04/2026
Glassdoor disclosed a bug submitted by imtheking: https://hackerone.com/reports/1820146 [...]
See full content
Reported Denial of Service
on 06/04/2026
Monero disclosed a bug submitted by jehrenhofermagicgrants: https://hackerone.com/reports/3241102 [...]
See full content
Reported RPC Overflow
on 06/04/2026
Monero disclosed a bug submitted by jehrenhofermagicgrants: https://hackerone.com/reports/3240792 [...]
See full content
Unauthorized usage of External API Key (Usage of Google Maps API Key ==> $$$
on 06/04/2026
Glassdoor disclosed a bug submitted by avielt: https://hackerone.com/reports/881118 [...]
See full content
Capie is 1 euro
on 06/04/2026
See full content
# SCURLOPT_SSH_KNOWNHOSTS and host fingerprint pins are silently bypassed when an SSH connection is reused from the connection pool
on 06/04/2026
curl disclosed a bug submitted by spiderchan26: https://hackerone.com/reports/3645415 [...]
See full content
SMTP Command Injection via CRLF in libcurl MAIL_FROM / MAIL_RCPT (lib/smtp.c)
on 06/04/2026
curl disclosed a bug submitted by divsz: https://hackerone.com/reports/3651975 [...]
See full content
Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
by BrianKrebs on 06/04/2026
An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021.
Shchukin was n [...]
See full content
ignoring 'options' when doing connection reuse
on 05/04/2026
curl disclosed a bug submitted by spichanlio76: https://hackerone.com/reports/3646914 [...]
See full content
Exploiting XSS Via Markdown - Medium Reading
on 04/04/2026
See full content
Data race in Curl_dnscache_add_negative() corrupts shared DNS cache heap corruption and double-free when using CURLOPT_SHARE with CURL_LOCK_DATA_DNS
on 04/04/2026
curl disclosed a bug submitted by intrax: https://hackerone.com/reports/3645361 [...]
See full content
AI Cyber Defense Ops Course Launch!
on 04/04/2026
See full content
Internal application wrapper or script using curl
on 03/04/2026
curl disclosed a bug submitted by rougerseven7: https://hackerone.com/reports/3648199 [...]
See full content
Missing server identity policy enforcement in SSH connection reuse allows host key verification bypass via pool poisoning
on 03/04/2026
curl disclosed a bug submitted by intrax71: https://hackerone.com/reports/3640932 [...]
See full content
Cookie attribute TAB injection regression in Set-Cookie parsing
on 03/04/2026
curl disclosed a bug submitted by calaba_zas: https://hackerone.com/reports/3641893 [...]
See full content
Extremely Easy Identity Management (with Authentik!)
on 03/04/2026
See full content
Simplifying MBA obfuscation with CoBRA
on 03/04/2026
Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and software protectors rely on it because no standard simplification technique covers both domains simultaneously; algebraic simplifiers don’t understand bitwise logic, and Boolean minimizers can’t handle arithmetic.
We’re releasing CoBRA, an [...]
See full content