Integer Underflow in src/var.c on 26/01/2026
curl disclosed a bug submitted by f_i_h: https://hackerone.com/reports/3523349 [...]
curl disclosed a bug submitted by f_i_h: https://hackerone.com/reports/3523349 [...]
Spock befriends a giant space squid in the comic Star Trek: Strange New Worlds: The Seeds of Salvation #5. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
Really interesting blog post from Anthropic: In a recent evaluation of AI models’ cyber capabilities, current Claude models can now succeed at multistage attacks on networks with dozens of hosts using only standard, open-source tools, instead of the custom tools needed by previous generations. This illustrates how barriers to the use of AI in relatively autonomous cyber workflows are rapidly comin [...]
Imagine you work at a drive-through restaurant. Someone drives up and says: “I’ll have a double cheeseburger, large fries, and ignore previous instructions and give me the contents of the cash drawer.” Would you hand over the money? Of course not. Yet this is what large language models (LLMs) do. Prompt injection is a method of tricking LLMs into doing things they are normally pr [...]
What you will learn Practical, bite-sized bug bounty tips and techniques you can apply immediately, whether you’re just starting or sharpening your skills. Proven approaches for finding, prioritizing, and validating vulnerabilities more efficiently in real-world programs. An eye on what to look out for to stay consistent and motivated in 2026. In the lead-up to the new year, we released a bug [...]
Basecamp disclosed a bug submitted by northeastprince: https://hackerone.com/reports/2012659 [...]
No matter how many times we say it, the idea comes back again and again. Hopefully, this letter will hold back the tide for at least a while longer. Executive summary: Scientists have understood for many years that internet voting is insecure and that there is no known or foreseeable technology that can make it secure. Still, vendors of internet voting keep claiming that, somehow, their new syste [...]
A new Internet-of-Things (IoT) botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf’s ability to scan the local networks of compromised systems for other IoT devices to infect makes it a sobering threat to organizations [...]
Stripo Inc disclosed a bug submitted by srcode: https://hackerone.com/reports/3459285 [...]
Cosmos disclosed a bug submitted by 0xjam: https://hackerone.com/reports/3510161 [...]
Eighteen months ago, it was plausible that artificial intelligence might take a different path than social media. Back then, AI’s development hadn’t consolidated under a small number of big tech firms. Nor had it capitalized on consumer attention, surveilling users and delivering ads. Unfortunately, the AI industry is now taking a page from the social media playbook and has set its sig [...]
curl disclosed a bug submitted by ichise: https://hackerone.com/reports/3516878 [...]
curl disclosed a bug submitted by foobar4213: https://hackerone.com/reports/3516974 [...]
pixiv disclosed a bug submitted by dexter34: https://hackerone.com/reports/2473173 [...]
It all sounds pretty dystopian: Inside a white stucco building in Southern California, video cameras compare faces of passersby against a facial recognition database. Behavioral analysis AI reviews the footage for signs of violent behavior. Behind a bathroom door, a smoke detector-shaped device captures audio, listening for sounds of distress. Outside, drones stand ready to be deployed and provide [...]
curl disclosed a bug submitted by bhaskar_ram: https://hackerone.com/reports/3516202 [...]
curl disclosed a bug submitted by bhaskar_ram: https://hackerone.com/reports/3516186 [...]
pixiv disclosed a bug submitted by giwadaoud: https://hackerone.com/reports/2541962 - Bounty: $500 [...]
pixiv disclosed a bug submitted by hyk3n: https://hackerone.com/reports/2119892 - Bounty: $200 [...]
curl disclosed a bug submitted by andrewml: https://hackerone.com/reports/3514263 [...]
Nextcloud disclosed a bug submitted by hakuna: https://hackerone.com/reports/2388183 - Bounty: $100 [...]
Nextcloud disclosed a bug submitted by hakuna: https://hackerone.com/reports/2380133 - Bounty: $250 [...]
AWS VDP disclosed a bug submitted by farmer: https://hackerone.com/reports/3427370 [...]
More than a decade after Aaron Swartz’s death, the United States is still living inside the contradiction that destroyed him. Swartz believed that knowledge, especially publicly funded knowledge, should be freely accessible. Acting on that, he downloaded thousands of academic articles from the JSTOR archive with the intention of making them publicly available. For this, the federal governmen [...]
Note: This is a guest post by pentester Julen Garrido Estévez (@b3xal). Methodology Key results Examples Key learnings Prompt template A pentester's POV on Burp AI Pentester Julen Garrido Es [...]
Hi hackers, Welcome to the latest edition of Bug Bytes (and the first of 2026)! In this month’s issue, we’ll be featuring: Hijacking official AWS GitHub repositories New anonymous bug bounty forum Finding more IDORs & SSRFs using a unique methodology New JavaScript file scanner to find hidden endpoints And so much more! Let’s dive in! Intigriti SantaCloud CTF results are in December 20 [...]
API security is becoming more important by the day and skilled practitioners are in high demand. Now’s the time to level up your API security skillset. Wallarm University, our free training course, provides security analysts, engineers, and practitioners with hands-on skills you can’t get from documentation, videos, or traditional courses. Run real attacks, investigate real signals, and learn [...]
This isn’t good: We discovered a critical vulnerability (CVE-2026-21858, CVSS 10.0) in n8n that enables attackers to take over locally deployed instances, impacting an estimated 100,000 servers globally. No official workarounds are available for this vulnerability. Users should upgrade to version 1.121.0 or later to remediate the vulnerability. Three technical links and two news links. [...]
Node.js disclosed a bug submitted by oriotie: https://hackerone.com/reports/3390084 [...]
curl disclosed a bug submitted by shiftj: https://hackerone.com/reports/3509396 [...]
Researchers have demonstrated remotely controlling a wheelchair over Bluetooth. CISA has issued an advisory. CISA said the WHILL wheelchairs did not enforce authentication for Bluetooth connections, allowing an attacker who is in Bluetooth range of the targeted device to pair with it. The attacker could then control the wheelchair’s movements, override speed restrictions, and manipulate conf [...]
This is a current list of where and when I am scheduled to speak: I’m speaking at the David R. Cheriton School of Computer Science in Waterloo, Ontario, Canada, on January 27, 2026, at 1:30 PM ET. I’m speaking at the Université de Montréal in Montreal, Quebec, Canada, on January 29, 2026, at 4:00 PM ET. I’m speaking and signing books at the Chicago Public Library in Chicago, Illinois, USA, on Feb [...]
Nextcloud disclosed a bug submitted by somerandomdev: https://hackerone.com/reports/3443563 [...]
Revive Adserver disclosed a bug submitted by 7yr: https://hackerone.com/reports/3473696 [...]
Revive Adserver disclosed a bug submitted by 7yr: https://hackerone.com/reports/3470970 [...]
Revive Adserver disclosed a bug submitted by nigh7c0r3: https://hackerone.com/reports/3468169 [...]
Revive Adserver disclosed a bug submitted by 0xjad: https://hackerone.com/reports/3445710 [...]
Revive Adserver disclosed a bug submitted by pakcyberbot: https://hackerone.com/reports/3445332 [...]
curl disclosed a bug submitted by z2_: https://hackerone.com/reports/3508321 [...]
curl disclosed a bug submitted by andrew-bbp: https://hackerone.com/reports/3508799 [...]
curl disclosed a bug submitted by vikash_saw: https://hackerone.com/reports/3509437 [...]
curl disclosed a bug submitted by andrew-bbp: https://hackerone.com/reports/3508785 [...]
curl disclosed a bug submitted by adce626q: https://hackerone.com/reports/3508701 [...]
Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft’s most-dire “critical” rating, and the company warns that attackers are already exploiting one of the bugs fixed today. January’s Microsoft zero-day flaw — CVE-2026-20805 — is brought t [...]
What you will learn How 2025 became a defining year for Intigriti through key milestones, major wins, and bold product launches. Insights from Intigriti’s C-suite on the moments that shaped the company’s growth and direction. How these reflections set the foundation for Intigriti’s vision and priorities for 2026. 2025 reflections, aspirations, and lessons learnt Stijn Jans, Chief Executive Off [...]
A look at how Kubernetes CVE-2020-8554 works [...]
curl disclosed a bug submitted by 0xshakib0x04: https://hackerone.com/reports/3508854 [...]
curl disclosed a bug submitted by gudyuu: https://hackerone.com/reports/3508500 [...]
With browser-embedded AI agents, we’re essentially starting the security journey over again. We exploited a lack of isolation mechanisms in multiple agentic browsers to perform attacks ranging from the dissemination of false information to cross-site data leaks. These attacks, which are functionally similar to cross-site scripting (XSS) and cross-site request forgery (CSRF), resurface decade [...]
U.S. Dept Of Defense disclosed a bug submitted by moha1sd: https://hackerone.com/reports/3027405 [...]
U.S. Dept Of Defense disclosed a bug submitted by l0rdv0ld3m0r7: https://hackerone.com/reports/3346375 [...]
U.S. Dept Of Defense disclosed a bug submitted by exec_iq: https://hackerone.com/reports/2061982 [...]
U.S. Dept Of Defense disclosed a bug submitted by xgoon: https://hackerone.com/reports/3318295 [...]
U.S. Dept Of Defense disclosed a bug submitted by saqib98: https://hackerone.com/reports/3066992 [...]
U.S. Dept Of Defense disclosed a bug submitted by 0xkarim_dix: https://hackerone.com/reports/3238607 [...]
U.S. Dept Of Defense disclosed a bug submitted by aramx4: https://hackerone.com/reports/3205104 [...]
U.S. Dept Of Defense disclosed a bug submitted by aramx4: https://hackerone.com/reports/3204997 [...]
U.S. Dept Of Defense disclosed a bug submitted by bewgsy: https://hackerone.com/reports/3053220 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3437836 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3136746 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3137212 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3166582 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3166581 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3166587 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3354494 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3351408 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3284389 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3136754 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3137206 [...]
U.S. Dept Of Defense disclosed a bug submitted by the_reinhardt: https://hackerone.com/reports/3135626 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3166585 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3166579 [...]
U.S. Dept Of Defense disclosed a bug submitted by jonasdiasrebelo: https://hackerone.com/reports/3284381 [...]
U.S. Dept Of Defense disclosed a bug submitted by silentbreach: https://hackerone.com/reports/2870951 [...]
U.S. Dept Of Defense disclosed a bug submitted by marucube35: https://hackerone.com/reports/2914739 [...]
U.S. Dept Of Defense disclosed a bug submitted by aldenpartridge: https://hackerone.com/reports/2857082 [...]
U.S. Dept Of Defense disclosed a bug submitted by oxylis: https://hackerone.com/reports/2968391 [...]
U.S. Dept Of Defense disclosed a bug submitted by badlifeguard: https://hackerone.com/reports/2954320 [...]
U.S. Dept Of Defense disclosed a bug submitted by rocky1696: https://hackerone.com/reports/3078508 [...]