Windows SSPI connection-pool probe can reuse a connection under the wrong user on 14/08/2026
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938185 [...]
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938185 [...]
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938220 [...]
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds s [...]
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. OpenAI, and then Anthropic, were each formed by AI developers who feared unrestrained corporate AI development—specifically, that companies like Google and Meta would steer the technology towards deleterious, maybe even catastrophically unsafe, outcomes for society. Their founders proclaimed that their ne [...]
curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3920276 [...]
Yelp disclosed a bug submitted by 0xkarim_dix: https://hackerone.com/reports/3829030 [...]
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press. AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technologies like the steam engine provided a quantum leap in our ability to do mechanical work outside of our bodies at scale. I [...]
8x8 disclosed a bug submitted by offseq: https://hackerone.com/reports/3837634 - Bounty: $500 [...]
This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to pre [...]
We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f [...]
Myndr disclosed a bug submitted by hackwithshubh: https://hackerone.com/reports/3930957 [...]
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording break [...]
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt messages to an attacker rather than the intended recipient. Until now, the only way to detect such malfeasance was to veri [...]
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened. The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible. Andrew, who was sitting fourth [...]
Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting. After reconstructing the interface [...]
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography. Remember, the reason to do this now is because there’s no emergency. And because you [...]
At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and our Senior Product Manager, Radu Voloaga, took to the stage in the Bug Bounty Village to give everyone the first real look at CrowdRecon. How CrowdRecon closes the gap It started with a question we kept running into: what happens to all the reconnaissance work hackers do before a v [...]
CoinMate.io disclosed a bug submitted by ganesh_reddy: https://hackerone.com/reports/3265780 - Bounty: $100 [...]
Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
curl disclosed a bug submitted by thinhlx: https://hackerone.com/reports/3923212 [...]
Through data brokers, ICE is buying the information you provided to open a credit card. [...]
Nintendo disclosed a bug submitted by jonbarrow: https://hackerone.com/reports/2551512 [...]
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A survei [...]
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly security theater: “Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said. Bell, however, said “none of these products are tried and tested, and a lot of these survei [...]
CVSS open framework, rapid recap Stands for Common Vulnerability Scoring System. Owned by a US-based non-profit organization, the Forum of Incident Response and Security Teams (FIRST). The purpose is to help response teams quickly and easily calculate the severity of cybersecurity vulnerabilities based on metrics. Latest version: (4.0) designed to assess multiple environments and dimensio [...]
Mozilla disclosed a bug submitted by griffinf: https://hackerone.com/reports/3782701 - Bounty: $12000 [...]
curl disclosed a bug submitted by kiyin: https://hackerone.com/reports/3917775 [...]
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service with your trusted enclaves comes with new threats, even if that service comes from the same provider. In this blog post—t [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3699522 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3698862 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3693636 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3700036 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3723315 [...]
This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or [...]
Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3687543 [...]
curl disclosed a bug submitted by juthawong: https://hackerone.com/reports/3911968 [...]
"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray H. is a Security Analyst at a managed security service provider with over 2500 employees world [...]
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of [...]
On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware. [...]
AWS VDP disclosed a bug submitted by sh3d0w: https://hackerone.com/reports/3478646 [...]
Rocket.Chat disclosed a bug submitted by howtoplay: https://hackerone.com/reports/3514640 [...]
curl disclosed a bug submitted by dark_river: https://hackerone.com/reports/3911605 [...]
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings. [...]
Liberapay disclosed a bug submitted by its9me: https://hackerone.com/reports/3878586 - Bounty: $100 [...]
Node.js disclosed a bug submitted by nadav0077: https://hackerone.com/reports/3723248 [...]
Tucows (VDP) disclosed a bug submitted by axolot23: https://hackerone.com/reports/3644182 [...]
Hello hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much more! Let's dive in! Intigriti turns 10! 🚀 Ten years ago, the idea that inviting [...]
phpBB disclosed a bug submitted by a7mmr: https://hackerone.com/reports/3606773 [...]
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a [...]
Node.js disclosed a bug submitted by sinan-polat: https://hackerone.com/reports/3815767 [...]
This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is o [...]
Ruby on Rails disclosed a bug submitted by friedchicken112211: https://hackerone.com/reports/3553340 [...]
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that show what can go wrong in that code. Together, they account for more than $20M in losses. Neither incident stemmed from a [...]
Node.js disclosed a bug submitted by vnyuh: https://hackerone.com/reports/3812439 [...]
Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are mishandled, closed incorrectly, downgraded in severity, or left unresolved for extended periods. When th [...]
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3638909 [...]
Node.js disclosed a bug submitted by sy2n0: https://hackerone.com/reports/3761342 [...]
HackerOne disclosed a bug submitted by 0v3rw4tch: https://hackerone.com/reports/3577216 [...]
Node.js disclosed a bug submitted by yottt: https://hackerone.com/reports/3816840 [...]
Node.js disclosed a bug submitted by 0xoroot: https://hackerone.com/reports/3838601 [...]
Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3473145 [...]
AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3633146 [...]
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at some of the most widely used, heavily audited codebases in the world, like Rust, curl, and zlib. One tool came up again and [...]
Key takeaways RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does. In simple QA systems, that may mean misinformation or unsafe recommendations. In agentic systems with tools and permissions, it can become data leakage, un [...]
In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, "the AI went rogue," is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the [...]
AWS VDP disclosed a bug submitted by nick_frichette_dd: https://hackerone.com/reports/3775702 [...]
Rocket.Chat disclosed a bug submitted by 0jayden: https://hackerone.com/reports/3827674 [...]
Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries [...]
We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act. [...]