Stored XSS via SVG Upload in chat.line.biz on 05/01/2026
LY Corporation disclosed a bug submitted by imnotr3al: https://hackerone.com/reports/3008878 - Bounty: $100 [...]
LY Corporation disclosed a bug submitted by imnotr3al: https://hackerone.com/reports/3008878 - Bounty: $100 [...]
curl disclosed a bug submitted by 7hackerstar: https://hackerone.com/reports/3485930 [...]
curl disclosed a bug submitted by amik_f: https://hackerone.com/reports/3485826 [...]
Nextcloud disclosed a bug submitted by loremipsumi: https://hackerone.com/reports/3385434 - Bounty: $100 [...]
Nextcloud disclosed a bug submitted by rolandsch: https://hackerone.com/reports/3040887 - Bounty: $150 [...]
Nextcloud disclosed a bug submitted by jayateerthag: https://hackerone.com/reports/2326618 - Bounty: $100 [...]
Nextcloud disclosed a bug submitted by nilsding: https://hackerone.com/reports/3159877 [...]
Nextcloud disclosed a bug submitted by updatelap: https://hackerone.com/reports/3293290 - Bounty: $100 [...]
Probably a college prank. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
curl disclosed a bug submitted by huntsd: https://hackerone.com/reports/3483902 [...]
The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it’s time for a broader awareness of the threat. The short version is that everything you thought you knew about the security of the internal network behind your Internet router probably is now dangerously out [...]
404 Media has the story: Unlike many of Flock’s cameras, which are designed to capture license plates as people drive by, Flock’s Condor cameras are pan-tilt-zoom (PTZ) cameras designed to record and track people, not vehicles. Condor cameras can be set to automatically zoom in on people’s faces as they walk through a parking lot, down a public street, or play on a playground, or [...]
curl disclosed a bug submitted by n12d11n: https://hackerone.com/reports/3484431 [...]
curl disclosed a bug submitted by gaurav0212: https://hackerone.com/reports/3484506 [...]
PortSwigger Web Security disclosed a bug submitted by osama-hamad: https://hackerone.com/reports/2276148 [...]
curl disclosed a bug submitted by ssyyaa: https://hackerone.com/reports/3484319 [...]
curl disclosed a bug submitted by ltl_professor: https://hackerone.com/reports/3483225 [...]
IBM disclosed a bug submitted by dara_7979: https://hackerone.com/reports/3463045 [...]
Interesting article on the variety of LinkedIn job scams around the world: In India, tech jobs are used as bait because the industry employs millions of people and offers high-paying roles. In Kenya, the recruitment industry is largely unorganized, so scamsters leverage fake personal referrals. In Mexico, bad actors capitalize on the informal nature of the job economy by advertising fake formal ro [...]
Go’s arithmetic operations on standard integer types are silent by default, meaning overflows “wrap around” without panicking. This behavior has hidden an entire class of security vulnerabilities from fuzzing campaigns. Today we’re changing that by releasing go-panikint, a modified Go compiler that turns silent integer overflows into explicit panics. We used it to find a live integer overflow in t [...]
Scammers are generating images of broken merchandise in order to apply for refunds. [...]
curl disclosed a bug submitted by cyberguardianrd: https://hackerone.com/reports/3481849 [...]
curl disclosed a bug submitted by yupiy: https://hackerone.com/reports/3480713 [...]
curl disclosed a bug submitted by ltl_professor: https://hackerone.com/reports/3481595 [...]
KrebsOnSecurity.com celebrates its 16th anniversary today! A huge “thank you” to all of our readers — newcomers, long-timers and drive-by critics alike. Your engagement this past year here has been tremendous and truly a salve on a handful of dark days. Happily, comeuppance was a strong theme running through our coverage in 2025, with a primary focus on entities that enabled comp [...]
curl disclosed a bug submitted by stif: https://hackerone.com/reports/3480712 [...]
Artificial Intelligence (AI) overlords are a common trope in science-fiction dystopias, but the reality looks much more prosaic. The technologies of artificial intelligence are already pervading many aspects of democratic government, affecting our lives in ways both large and small. This has occurred largely without our notice or consent. The result is a government incrementally transformed by AI [...]
curl disclosed a bug submitted by onevone: https://hackerone.com/reports/3480641 [...]
curl disclosed a bug submitted by efrsxcv: https://hackerone.com/reports/3480039 [...]
curl disclosed a bug submitted by efrsxcv: https://hackerone.com/reports/3480078 [...]
curl disclosed a bug submitted by efrsxcv: https://hackerone.com/reports/3479984 [...]
curl disclosed a bug submitted by 0x0000nosfu: https://hackerone.com/reports/3479203 [...]
curl disclosed a bug submitted by y_security: https://hackerone.com/reports/3479019 [...]
New research: Abstract: Coleoid cephalopods have the most elaborate camouflage system in the animal kingdom. This enables them to hide from or deceive both predators and prey. Most studies have focused on benthic species of octopus and cuttlefish, while studies on squid focused mainly on the chromatophore system for communication. Camouflage adaptations to the substrate while moving has been recen [...]
Someone hacked an Italian ferry. It looks like the malware was installed by someone on the ferry, and not remotely. [...]
curl disclosed a bug submitted by 0x0000nosfu: https://hackerone.com/reports/3477023 [...]
curl disclosed a bug submitted by vovohelo: https://hackerone.com/reports/3476928 [...]
curl disclosed a bug submitted by pwnie: https://hackerone.com/reports/3475472 [...]
curl disclosed a bug submitted by strokep: https://hackerone.com/reports/3470073 [...]
This is pretty scary: Urban VPN Proxy targets conversations across ten AI platforms: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), Meta AI. For each platform, the extension includes a dedicated “executor” script designed to intercept and capture conversations. The harvesting is enabled by default through hardcoded flags in the extension’s configura [...]
Nextcloud disclosed a bug submitted by waloodi109: https://hackerone.com/reports/3367676 [...]
At Intigriti, we host monthly web-based Capture The Flag (CTF) challenges as a way to engage with the security researcher community. December's challenge by Renwa took inspiration from the Marvel Cinematic Universe, specifically Thanos's quest to collect all six Infinity Stones. This challenge required us to chain multiple client-side vulnerabilities across different subdomains to ultimately achie [...]
curl disclosed a bug submitted by anonymous_237: https://hackerone.com/reports/3475613 [...]
curl disclosed a bug submitted by pwnie: https://hackerone.com/reports/3474865 [...]
News: The Danish Defence Intelligence Service (DDIS) announced on Thursday that Moscow was behind a cyber-attack on a Danish water utility in 2024 and a series of distributed denial-of-service (DDoS) attacks on Danish websites in the lead-up to the municipal and regional council elections in November. The first, it said, was carried out by the pro-Russian group known as Z-Pentest and the second by [...]
Is an AI-to-AI attack scenario a science fiction possibility only for blockbusters like the Terminator series of movies? Well, maybe not! Researchers recently discovered that one AI agent can “inject malicious instructions into a conversation, hiding them among otherwise benign client requests and server responses.” While known AI threats involve tricking an agent with malicious data, this [...]
Nextcloud disclosed a bug submitted by lauritz: https://hackerone.com/reports/2902856 [...]
Basecamp disclosed a bug submitted by brumbelow: https://hackerone.com/reports/3445890 [...]
After twenty-six years, Microsoft is finally upgrading the last remaining instance of the encryption algorithm RC4 in Windows. of the most visible holdouts in supporting RC4 has been Microsoft. Eventually, Microsoft upgraded Active Directory to support the much more secure AES encryption standard. But by default, Windows servers have continued to respond to RC4-based authentication requests and re [...]
curl disclosed a bug submitted by herdiyanitdev: https://hackerone.com/reports/3473384 [...]
curl disclosed a bug submitted by herdiyanitdev: https://hackerone.com/reports/3473182 [...]
curl disclosed a bug submitted by gaurav0212: https://hackerone.com/reports/3471553 [...]
curl disclosed a bug submitted by strokep: https://hackerone.com/reports/3470095 [...]
Node.js disclosed a bug submitted by sideni: https://hackerone.com/reports/3463949 [...]
The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum of technology challenges, from cybersecurity and privacy to countering disinformation, fraud and corruption. These shifts, along with the president’s efforts to restrict free speech and freedom of the press, hav [...]
Lefteris Tzelepis, CISO at Steelmet /Viohalco Companies, was shaped by cybersecurity. From his early exposure to real-world attacks at the Greek Ministry of Defense to building and leading security programs inside complex enterprises, his career mirrors the evolution of the CISO role itself. Now a group CISO overseeing security across multiple organizations, Lefteris brings a practitioner’s mi [...]
I recently attended the AI Engineer Code Summit in New York, an invite-only gathering of AI leaders and engineers. One theme emerged repeatedly in conversations with attendees building with AI: the belief that we’re approaching a future where developers will never need to look at code again. When I pressed these proponents, several made a similar argument: Forty years ago, when high-level program [...]
Trellix disclosed a bug submitted by lemonoftroy: https://hackerone.com/reports/1068477 [...]
curl disclosed a bug submitted by im4x: https://hackerone.com/reports/3470649 [...]
Cosmos disclosed a bug submitted by tychebe: https://hackerone.com/reports/3425308 [...]
IBM disclosed a bug submitted by kanon4: https://hackerone.com/reports/3458235 [...]
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: React2Shell scanner (with WAF bypasses) Identifying server origin IP to bypass popular WAFs CSRF exploitation cheat sheet Finding vulnerabilities in sign-ups And so much more! Let’s dive in! INTIGRITI 1125 results are in November’s Intigriti Challenge was on us. 1125 brought hundreds of hack [...]
curl disclosed a bug submitted by anonymous_237: https://hackerone.com/reports/3468098 [...]
curl disclosed a bug submitted by badrodin22: https://hackerone.com/reports/3468410 [...]
Introducing Pathfinding.cloud, a library of AWS IAM privilege escalation paths [...]
Direct navigation — the act of visiting a website by manually typing a domain name in a web browser — has never been riskier: A new study finds the vast majority of “parked” domains — mostly expired or dormant domain names, or common misspellings of popular websites — are now configured to redirect visitors to sites that foist scams and malware. A lookalike doma [...]
Memory safety bugs like use-after-free and buffer overflows remain among the most exploited vulnerability classes in production software. While AddressSanitizer (ASan) excels at catching these bugs during development, its performance overhead (2 to 4 times) and security concerns make it unsuitable for production. What if you could detect many of the same critical bugs in live systems with virtuall [...]
Cloudflare Public Bug Bounty disclosed a bug submitted by matured_kazama: https://hackerone.com/reports/3316910 [...]
curl disclosed a bug submitted by the-pink-panther: https://hackerone.com/reports/3466896 [...]
curl disclosed a bug submitted by the-pink-panther: https://hackerone.com/reports/3466883 [...]