InfoSec Planet
A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.
Cognyte Sells a Mobile Cell Surveillance Van
on 27/07/2026
Yet another Israeli mass surveillance company:
Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed [...]
See full content
Any App Notification
on 26/07/2026
See full content
How do you keep up to date with the latest cybernews and development?
on 26/07/2026
See full content
RATS Q4 - What hardware and OS do I need to start hacking
on 25/07/2026
See full content
RATS Q3 - How Much Python Should I Know before Hacking
on 25/07/2026
See full content
Building Fake Notifications
on 25/07/2026
See full content
Why Being a Great Hacker Doesn't Pay Anymore
on 25/07/2026
See full content
Friday Squid Blogging: Illex Squid Catch in the Falklands
on 24/07/2026
Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
[...]
See full content
ZMQ RPC Log Injection and Untrusted Payload Persistence
on 24/07/2026
Monero disclosed a bug submitted by redlobsterzzz: https://hackerone.com/reports/3621606 [...]
See full content
Why AI Needs a “Genie Coefficient”
on 24/07/2026
This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum.
Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new metric: the Genie coefficient.
There’s often a gap between one person’s request and anot [...]
See full content
Fake Edge Update
on 23/07/2026
See full content
End-to-End Encryption and “Going Dark”
on 23/07/2026
New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“:
Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments ar [...]
See full content
They hacked Google's AI in Seoul
on 23/07/2026
See full content
TCM Course Release | New Creator | Cybersecurity | AMA
on 23/07/2026
See full content
AI’s convenience cost. The impact of the lethal trifecta on organizations today
by Eleanor Barlow on 23/07/2026
The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant, the more its access, permissions, and actions need guardrails.
This blog takes a look at the lethal [...]
See full content
AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF
on 22/07/2026
AWS VDP disclosed a bug submitted by notnotnotveg: https://hackerone.com/reports/3809407 [...]
See full content
GitHub user to server tokens can create issues in any public repository
on 22/07/2026
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3641229 [...]
See full content
First-Person Identity Theft Story
on 22/07/2026
Harrowing story of an identity theft victim.
Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts hangs on the security of our email accounts.
[...]
See full content
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability
on 22/07/2026
8x8 disclosed a bug submitted by kyotozzx: https://hackerone.com/reports/3800870 - Bounty: $1337 [...]
See full content
LG to Ban Residential Proxies from Smart TV Apps
by BrianKrebs on 22/07/2026
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traff [...]
See full content
OAuth redirect uri validation bypass for :proxima_first_party_sync apps
on 21/07/2026
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3588801 [...]
See full content
An AI Botnet
on 21/07/2026
See full content
MIT to Become Hotbed of AI Video Surveillance
on 21/07/2026
It’s a lot:
According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.
Technical specifi [...]
See full content
Hunt Like A Real Rat - CyberStarterNexusCTF - Bug Bounty Tips From A Industry Icon
on 20/07/2026
See full content
Redirect Chain Abuse
on 20/07/2026
See full content
Microsoft Exchange Hacked, Five Years Later
on 20/07/2026
See full content
On Flock License Plate Tracking Cameras
on 20/07/2026
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral.
The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the m [...]
See full content
Stop Playing Whack-a-Mole With Bugs.
on 20/07/2026
See full content
Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes
on 20/07/2026
Monero disclosed a bug submitted by int0ha_: https://hackerone.com/reports/3738727 [...]
See full content
The between-reports problem: why security teams miss what attackers see
by Greg Jenkins on 20/07/2026
What you will learn
Why faster discovery and higher volume can still leave teams blind between vulnerability reports.
Why scanners and inventories are necessary, but not enough to explain attacker focus and intent.
What “between-reports visibility” actually means (without the product pitch).
What we believe security teams will need next: earlier signals that support action before the next repor [...]
See full content
Q and A: RATS Q2 What Is A Good Web App Hacking Workflow
on 19/07/2026
See full content
CyberLab Con 26 Track 1 (I'm live at 2PM UTC!)
on 19/07/2026
See full content
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
on 17/07/2026
Lots of articles about this.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
[...]
See full content
Happy hacking
on 17/07/2026
See full content
Burp's new Ambassadors: learn from the people who use Burp Suite everyday
on 17/07/2026
Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass [...]
See full content
Details of Alan Turing’s Voice Encryption System
on 17/07/2026
Really interesting piece of cryptographic history:
In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delil [...]
See full content
Your Scanners Were Not Thinking About This.
on 17/07/2026
See full content
Evil Token Marketplace
on 16/07/2026
See full content
Protecting Privacy in an AI Era
on 16/07/2026
Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technologic [...]
See full content
Bug Bounty Is Your Safety Parachute.
on 16/07/2026
See full content
Payload Podcast 009 - Steven Flores
on 16/07/2026
See full content
Stored XSS in Rocket.Chat HTML File Export Unauthenticated Entry via LiveChat
on 16/07/2026
Rocket.Chat disclosed a bug submitted by olidayw: https://hackerone.com/reports/3779690 [...]
See full content
Able to bypass authorization logic and gain more access then intended
on 15/07/2026
GitHub disclosed a bug submitted by vaib25vicky: https://hackerone.com/reports/3713965 [...]
See full content
Q and A: RATS Q1 - How Do You Develop A Tinkering Mindset
on 15/07/2026
See full content
Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections
on 15/07/2026
AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3632577 [...]
See full content
Your Weekly Test Is Already Too Late.
on 15/07/2026
See full content
Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass
on 14/07/2026
Basecamp disclosed a bug submitted by newbiefromcoma: https://hackerone.com/reports/3581911 - Bounty: $337 [...]
See full content
Microsoft Patches a Record 570 Security Flaws
by BrianKrebs on 14/07/2026
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Nearly 60 of the bugs qu [...]
See full content
bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys
on 14/07/2026
AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3702072 [...]
See full content
Backdoored TortoiseSVN Installer
on 14/07/2026
See full content
More Scans Are Not Continuous Security.
on 14/07/2026
See full content
Is Your Continuous Threat Exposure Management Actually Continuous with Michiel Prins
on 14/07/2026
See full content
Compromised AsyncAPI npm packages: inside a CI supply-chain attack
on 14/07/2026
On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected. [...]
See full content
AI Control Platform vs. AI Firewall vs. AI Gateway: Clearing Up The Terminology
by Tim Erlin on 13/07/2026
Editor's note: This article was originally published by Tim Erlin on LinkedIn. It has been republished here with the author's permission. https://www.linkedin.com/pulse/ai-control-platform-vs-firewall-gateway-clearing-up-tim-erlin-ypodc
It seems like every security vendor now sells "AI security." The WAF companies, the API gateway companies, the cloud platforms, the proxy startups: all of them [...]
See full content
SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server
on 13/07/2026
SingleStore disclosed a bug submitted by bisht-ji: https://hackerone.com/reports/3780695 [...]
See full content
Lessons Learned from CISA’s Recent GitHub Leak
by BrianKrebs on 13/07/2026
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important [...]
See full content
This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)
on 13/07/2026
See full content
Rust-proof your code with our new Testing Handbook chapter
on 13/07/2026
We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems.
fn
main()
{(|f:&dyn
Fn(u128)->Box<
dyn Iterator<Item=
char>+'static>|f(*[&(
0x7B736D70683F73u128<<64|
0x7A6A6D7C3F7A667D),&(0x7B73 [...]
See full content
NEW AI Hacking Challenges with Andrew Bellini!
on 11/07/2026
See full content
Soft Skills for the Job Market: Applying for Jobs
on 10/07/2026
See full content
The most severe exposure lives in the quiet overlap between tech, people, and process. ♾️
on 10/07/2026
See full content
Fake Microsoft Installer
on 10/07/2026
See full content
See you at Black Hat USA 2026!
on 09/07/2026
See full content
Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)
on 09/07/2026
AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3630605 [...]
See full content
Heading to Vegas? Meet PortSwigger at Black Hat, BSides, and DEF CON 34.
on 09/07/2026
First hand of the week: Find us at BSides Workshop: Burp But Yours, with Hannah and Tib3rius Center stage: Visit us at Black Hat USA - Booth 5342 Lightning talks at the booth Catch our researchers' br [...]
See full content
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
on 09/07/2026
A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys. [...]
See full content
LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway
on 08/07/2026
See full content
TeamPCP Attention
on 08/07/2026
See full content
Welcome to the best security page ever.
on 08/07/2026
See full content
Felons, Fraudsters Flog Offensive Cybersecurity Startup
by BrianKrebs on 08/07/2026
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 [...]
See full content
Mutation testing comes to DAML
on 08/07/2026
In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DAML’s authorization primitives), and runs them through your existing test suite to count how many [...]
See full content
Coordinated GitHub API enumeration and access token abuse
on 08/07/2026
Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning private repositories. [...]
See full content
OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)
on 06/07/2026
AWS VDP disclosed a bug submitted by kaporia: https://hackerone.com/reports/3637898 [...]
See full content
Stop what you're doing
on 06/07/2026
See full content
Open Source Malware
on 06/07/2026
See full content
I Made an AI Agent That Reverses CVEs While I Sleep
on 06/07/2026
See full content
THE MOD WORKS! lets improve it
on 06/07/2026
See full content
Entra Agent ID: Protect, detect, respond
on 06/07/2026
This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant. [...]
See full content
Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity
on 04/07/2026
Basecamp disclosed a bug submitted by zerodaysec_xyz: https://hackerone.com/reports/3764217 - Bounty: $287 [...]
See full content
admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed
on 03/07/2026
Shopify disclosed a bug submitted by abahack: https://hackerone.com/reports/3628961 [...]
See full content
Are your employees using AI?
on 03/07/2026
See full content
FBI Seizes NetNut Proxy Platform, Popa Botnet
by BrianKrebs on 02/07/2026
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botn [...]
See full content
Non-Production API Endpoints for the Amazon S3 Tables Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration
on 02/07/2026
AWS VDP disclosed a bug submitted by nick_frichette_dd: https://hackerone.com/reports/3780277 [...]
See full content
We get this question a lot
on 02/07/2026
See full content
jitsi-meet: Prosody/Jigasi missing header whitelist in mod_filter_iq_rayo allows arbitrary SIP header injection and Caller ID spoofing
on 02/07/2026
8x8 disclosed a bug submitted by pmgjoe: https://hackerone.com/reports/3789570 - Bounty: $100 [...]
See full content
jitsi-call-analytics: Unauthenticated arbitrary file write via path traversal in `/api/v1/uploads/analyze`
on 02/07/2026
8x8 disclosed a bug submitted by r1skr1der: https://hackerone.com/reports/3485343 - Bounty: $100 [...]
See full content
Yelp for Business: locked Email field silently editable via API
on 02/07/2026
Yelp disclosed a bug submitted by 0xmanticore: https://hackerone.com/reports/3766455 [...]
See full content
Celebrating 1 Million Subscribers on July 8th!
on 02/07/2026
See full content
GPT-5.5-Cyber built a zlib fuzzing lab in a day
on 02/07/2026
We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon create a firehose of bug reports, and OSS maintainers are already spread thin. Our plan is to point OpenAI’s latest model [...]
See full content
Splatoon 3 In-Match Integrity Bypass via Consensus Reflection Attack on Unordered Peer Submission
on 02/07/2026
Nintendo disclosed a bug submitted by hana2736: https://hackerone.com/reports/3559522 [...]
See full content
[Splatoon 3] Kick other players with NplnLogin message
on 02/07/2026
Nintendo disclosed a bug submitted by alzxk11: https://hackerone.com/reports/3813932 [...]
See full content
Exceeding the maximum number of spaces allowed by exploiting a Race Condition in the Workspace creation process
on 01/07/2026
SingleStore disclosed a bug submitted by bl4ck-: https://hackerone.com/reports/3295500 [...]
See full content
Insecure Direct Object Reference (IDOR) allows creating folders.
on 01/07/2026
SingleStore disclosed a bug submitted by bl4ck-: https://hackerone.com/reports/3353057 [...]
See full content
Delete any folder for any user within the organization
on 01/07/2026
SingleStore disclosed a bug submitted by bl4ck-: https://hackerone.com/reports/3353035 [...]
See full content
Privilege Escalation Access to the Alert Subscribers page for users with low privileges
on 01/07/2026
SingleStore disclosed a bug submitted by bl4ck-: https://hackerone.com/reports/3353000 [...]
See full content
Improper Input Validation HTTP Response Parser Unconditionally Accepts Bare CR in Status Line
on 01/07/2026
Node.js disclosed a bug submitted by saif-01: https://hackerone.com/reports/3648681 [...]
See full content
Backdoors & Breaches: New scenarios and adaptations
on 01/07/2026
Sharing new scenarios and adaptations to play the Datadog expansion pack of Backdoors & Breaches. [...]
See full content
heap-use-after-free in curl_easy_cleanup() called from callback
on 30/06/2026
curl disclosed a bug submitted by carehi1324: https://hackerone.com/reports/3833577 [...]
See full content
setopt(VERIFYPEER) from callback bypasses TLS verify on connection reuse
on 30/06/2026
curl disclosed a bug submitted by a6b30108: https://hackerone.com/reports/3831432 [...]
See full content
Shipping post-quantum cryptography to Python
on 30/06/2026
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography.
On June 22, 2026, the White House ordered the U.S. government to accelerate its transition to post-quantu [...]
See full content