InfoSec Planet

A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.

curl Missing Sec-WebSocket-Accept Verification Enables MITM WebSocket Session Hijacking

on 05/08/2026

curl disclosed a bug submitted by kiyin: https://hackerone.com/reports/3917775 [...]

See full content

A few notes on AWS Nitro Enclaves: KMS integration

on 05/08/2026

Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service with your trusted enclaves comes with new threats, even if that service comes from the same provider. In this blog post—t [...]

See full content

`check_reserve_proof` counts duplicate entries: one output can inflate `total`

on 05/08/2026

Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3699522 [...]

See full content

`check_reserve_proof` sums RingCT ECDH amounts without checking the output commitment

on 05/08/2026

Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3698862 [...]

See full content

wallet-rpc crash via malformed /gettransactions response (empty txs vector::front() in check_tx_key / check_tx_proof)

on 05/08/2026

Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3693636 [...]

See full content

SpendProofV1 txid-substitution: get_spend_proof/check_spend_proof do not verify returned transaction hash

on 05/08/2026

Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3700036 [...]

See full content

wallet-rpc describe_transfer uses real_output_in_tx_index instead of real_output: cold-wallet pre-sign review shows wrong ring member

on 05/08/2026

Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3723315 [...]

See full content

Vulnerabilities in Car Anti-Theft Device

on 05/08/2026

This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or [...]

See full content

`relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx`

on 05/08/2026

Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3687543 [...]

See full content

Iran Cyberattacks Against Minnesota Water Systems

on 04/08/2026

Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I wo [...]

See full content

Heap use-after-free (write) in mev_forget_socket() via reentrant curl_easy_pause() incomplete fix for CVE-2026-9080

on 04/08/2026

curl disclosed a bug submitted by juthawong: https://hackerone.com/reports/3911968 [...]

See full content

Case study: How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years

on 04/08/2026

"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray H. is a Security Analyst at a managed security service provider with over 2500 employees world [...]

See full content

Some Claude Chats Are Searchable on Google

on 04/08/2026

And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses. What seems to be the issue is a user [...]

See full content

Intigriti named new provider for Adobe's Bug Bounty Program

by Eleanor Barlow on 04/08/2026

Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of [...]

See full content

Worm compromises hundreds of popular npm packages

on 04/08/2026

On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware. [...]

See full content

GitHub Retired UsernameTakeover From [aws/]

on 03/08/2026

AWS VDP disclosed a bug submitted by sh3d0w: https://hackerone.com/reports/3478646 [...]

See full content

More on the OpenAI Agent’s Attack on Hugging Face

on 03/08/2026

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or [...]

See full content

Cyber Deception Everywhere

on 03/08/2026

See full content

Unauthenticated Path Traversal (LFI) via /custom-sounds/ when CustomSounds uses FileSystem storage

on 03/08/2026

Rocket.Chat disclosed a bug submitted by howtoplay: https://hackerone.com/reports/3514640 [...]

See full content

Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS)

on 03/08/2026

See full content

The OpenAI Hack Shows the Genie Is Out of the Bottle

on 03/08/2026

This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how goo [...]

See full content

SMTP CRLF injection in custom SMTP recipient operand allows additional SMTP commands after authentication

on 03/08/2026

curl disclosed a bug submitted by dark_river: https://hackerone.com/reports/3911605 [...]

See full content

Are you ready for this year's @BugBountyVillage at @DEFCONConference

on 03/08/2026

See full content

Before the first prompt: Code execution paths in trusted coding-agent projects

on 03/08/2026

Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings. [...]

See full content

Unauthenticated team "income/payments" export ignores donor privacy settings (hide_giving, hide_from_lists) and uses frozen visibility, exposing donat

on 01/08/2026

Liberapay disclosed a bug submitted by its9me: https://hackerone.com/reports/3878586 - Bounty: $100 [...]

See full content

JHT Course Launch! Home Labs with Proxmox

on 01/08/2026

See full content

Friday Squid Blogging: Squid Helps Discover New Marine Species

on 31/07/2026

The Squid is a new scientific machine: One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could d [...]

See full content

Anthropic’s Opus 5 Is Better at Resisting Prompt Injection

on 31/07/2026

The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Cl [...]

See full content

HTTP Request Smuggling via Connection: close<TAB> in Node.js llhttp parser

on 31/07/2026

Node.js disclosed a bug submitted by nadav0077: https://hackerone.com/reports/3723248 [...]

See full content

Stored XSS in nameserver field on account settings page

on 31/07/2026

Tucows (VDP) disclosed a bug submitted by axolot23: https://hackerone.com/reports/3644182 [...]

See full content

Do you guys agree? #hacking #bugbounty

on 31/07/2026

See full content

Facial Recognition at Madison Square Garden

on 31/07/2026

Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor Swift’s wedding. Evan Greer—one of the people that MSG alerts on—comments: Ironically, Swift herself ha [...]

See full content

AI in bug bounty - let's talk about how to effectively use AI in bug bounty

on 31/07/2026

See full content

GTA Malware Trap

on 31/07/2026

See full content

Intigriti Bug Bytes #238 - July 2026 🚀

by Ayoub on 31/07/2026

Hello hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub Archive And so much more! Let's dive in! Intigriti turns 10! 🚀 Ten years ago, the idea that inviting [...]

See full content

Stored XSS via SVG Upload check_content() Blocklist Bypass & 256-Byte Scan Limit (Self-Propagating Worm)

on 30/07/2026

phpBB disclosed a bug submitted by a7mmr: https://hackerone.com/reports/3606773 [...]

See full content

Read This Before You Buy That TV Streaming Stick

by BrianKrebs on 30/07/2026

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a [...]

See full content

American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

on 30/07/2026

He’s being prosecuted for giving border officials a code that wiped his phone: The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wi [...]

See full content

Permission Model bypass: process.report writes (and overwrites) files outside --allow-fs-write paths

on 30/07/2026

Node.js disclosed a bug submitted by sinan-polat: https://hackerone.com/reports/3815767 [...]

See full content

From capable AI models to trusted security testing

on 30/07/2026

This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is o [...]

See full content

Meet TCM Security at DEF CON 34!

on 30/07/2026

See full content

Active Storage Vips Transformer Missing validate_transformation CVE-2025-24293 Incomplete Fix

on 30/07/2026

Ruby on Rails disclosed a bug submitted by friedchicken112211: https://hackerone.com/reports/3553340 [...]

See full content

Should You Use AI for a Task? Here’s a Simple Way to Decide

on 30/07/2026

This essay originally appeared in The Guardian. I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn’t they [...]

See full content

Building secure Uniswap v4 hooks

on 30/07/2026

Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that show what can go wrong in that code. Together, they account for more than $20M in losses. Neither incident stemmed from a [...]

See full content

Real Folks of Cyber | Andrew Crotty | DITL

on 30/07/2026

See full content

HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934)

on 30/07/2026

Node.js disclosed a bug submitted by vnyuh: https://hackerone.com/reports/3812439 [...]

See full content

How to appeal a bug bounty submission

by Ayoub on 30/07/2026

Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are mishandled, closed incorrectly, downgraded in severity, or left unresolved for extended periods. When th [...]

See full content

GitHub scoped user to server tokens can escape their installation

on 29/07/2026

GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3638909 [...]

See full content

Permission Model: --allow-fs-read/--allow-fs-write radix-tree prefix-boundary over-grant

on 29/07/2026

Node.js disclosed a bug submitted by sy2n0: https://hackerone.com/reports/3761342 [...]

See full content

Minecraft Security Mods

on 29/07/2026

See full content

`exportReportPdf` mutation shows internal Activity

on 29/07/2026

HackerOne disclosed a bug submitted by 0v3rw4tch: https://hackerone.com/reports/3577216 [...]

See full content

HTTPS Agent PFX object-array key collision allows mTLS client identity reuse across different per-request certificates

on 29/07/2026

Node.js disclosed a bug submitted by yottt: https://hackerone.com/reports/3816840 [...]

See full content

Permission Model Bypass: `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`

on 29/07/2026

Node.js disclosed a bug submitted by 0xoroot: https://hackerone.com/reports/3838601 [...]

See full content

Payload Podcast 010 - Olaf Hartong

on 29/07/2026

See full content

Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)

on 29/07/2026

Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3473145 [...]

See full content

RATS Q4 - What hardware and OS do I need to start hacking

on 28/07/2026

See full content

Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh

on 28/07/2026

AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3633146 [...]

See full content

How we use /goal to find bugs in Patch the Planet

on 28/07/2026

Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at some of the most widely used, heavily audited codebases in the world, like Rust, curl, and zlib. One tool came up again and [...]

See full content

RAG and ruin: why your existing controls may miss AI poisoning attacks

by Eleanor Barlow on 28/07/2026

Key takeaways   RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does.   In simple QA systems, that may mean misinformation or unsafe recommendations.   In agentic systems with tools and permissions, it can become data leakage, un [...]

See full content

Did an AI Really Hack Hugging Face?

on 27/07/2026

See full content

Lessons from the OpenAI and Hugging Face Incident: When Safety Filters Disarm the Defender

by Aleksandr Orekhov on 27/07/2026

In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, "the AI went rogue," is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the [...]

See full content

Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration

on 27/07/2026

AWS VDP disclosed a bug submitted by nick_frichette_dd: https://hackerone.com/reports/3775702 [...]

See full content

Authentication Bypass via XML Signature Wrapping in SAML SSO

on 27/07/2026

Rocket.Chat disclosed a bug submitted by 0jayden: https://hackerone.com/reports/3827674 [...]

See full content

How One File Upload Got Me the Entire Customer Database

on 27/07/2026

See full content

Introducing Burp AT: agentic AI, built on two decades of Burp Suite

on 27/07/2026

Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries [...]

See full content

Detection primitives for eBPF rootkits

on 27/07/2026

We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act. [...]

See full content

Any App Notification

on 26/07/2026

See full content

How do you keep up to date with the latest cybernews and development?

on 26/07/2026

See full content

RATS Q3 - How Much Python Should I Know before Hacking

on 25/07/2026

See full content

Building Fake Notifications

on 25/07/2026

See full content

Why Being a Great Hacker Doesn't Pay Anymore

on 25/07/2026

See full content

ZMQ RPC Log Injection and Untrusted Payload Persistence

on 24/07/2026

Monero disclosed a bug submitted by redlobsterzzz: https://hackerone.com/reports/3621606 [...]

See full content

Fake Edge Update

on 23/07/2026

See full content

They hacked Google's AI in Seoul

on 23/07/2026

See full content

TCM Course Release | New Creator | Cybersecurity | AMA

on 23/07/2026

See full content

AI’s convenience cost. The impact of the lethal trifecta on organizations today

by Eleanor Barlow on 23/07/2026

The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant, the more its access, permissions, and actions need guardrails.   This blog takes a look at the lethal  [...]

See full content

AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF

on 22/07/2026

AWS VDP disclosed a bug submitted by notnotnotveg: https://hackerone.com/reports/3809407 [...]

See full content

GitHub user to server tokens can create issues in any public repository

on 22/07/2026

GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3641229 [...]

See full content

connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability

on 22/07/2026

8x8 disclosed a bug submitted by kyotozzx: https://hackerone.com/reports/3800870 - Bounty: $1337 [...]

See full content

LG to Ban Residential Proxies from Smart TV Apps

by BrianKrebs on 22/07/2026

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traff [...]

See full content

OAuth redirect uri validation bypass for :proxima_first_party_sync apps

on 21/07/2026

GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3588801 [...]

See full content

An AI Botnet

on 21/07/2026

See full content

Hunt Like A Real Rat - CyberStarterNexusCTF - Bug Bounty Tips From A Industry Icon

on 20/07/2026

See full content

Redirect Chain Abuse

on 20/07/2026

See full content

Microsoft Exchange Hacked, Five Years Later

on 20/07/2026

See full content

Stop Playing Whack-a-Mole With Bugs.

on 20/07/2026

See full content

Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes

on 20/07/2026

Monero disclosed a bug submitted by int0ha_: https://hackerone.com/reports/3738727 [...]

See full content

The between-reports problem: why security teams miss what attackers see

by Greg Jenkins on 20/07/2026

What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What we believe security teams will need next: earlier signals that support action before the next repor [...]

See full content

Q and A: RATS Q2 What Is A Good Web App Hacking Workflow

on 19/07/2026

See full content

CyberLab Con 26 Track 1 (I'm live at 2PM UTC!)

on 19/07/2026

See full content

Happy hacking

on 17/07/2026

See full content

Burp's new Ambassadors: learn from the people who use Burp Suite everyday

on 17/07/2026

Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass [...]

See full content

Your Scanners Were Not Thinking About This.

on 17/07/2026

See full content

Evil Token Marketplace

on 16/07/2026

See full content

Bug Bounty Is Your Safety Parachute.

on 16/07/2026

See full content

Payload Podcast 009 - Steven Flores

on 16/07/2026

See full content

Stored XSS in Rocket.Chat HTML File Export Unauthenticated Entry via LiveChat

on 16/07/2026

Rocket.Chat disclosed a bug submitted by olidayw: https://hackerone.com/reports/3779690 [...]

See full content

Able to bypass authorization logic and gain more access then intended

on 15/07/2026

GitHub disclosed a bug submitted by vaib25vicky: https://hackerone.com/reports/3713965 [...]

See full content

Q and A: RATS Q1 - How Do You Develop A Tinkering Mindset

on 15/07/2026

See full content

Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections

on 15/07/2026

AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3632577 [...]

See full content

Sources

The content of this page is fetched from the following sources:

  1. Datadog Security Labs
  2. The Trail of Bits Blog
  3. Schneier on Security
  4. Krebs on Security
  5. Google Online Security Blog
  6. $BLOG_TITLE
  7. Agarri : Sécurité informatique offensive
  8. Alex Chapman's Blog
  9. www.alphabot.com
  10. ziot
  11. Bug Bounty Reports Explained
  12. Bugcrowd
  13. cat ~/footstep.ninja/blog.txt
  14. Ezequiel Pereira
  15. HackerOne
  16. surajdisoja.me
  17. InsiderPhD
  18. Intigriti
  19. John Hammond
  20. LiveOverflow
  21. NahamSec
  22. PortSwigger Blog
  23. Rana Khalil
  24. Richard’s Infosec blog
  25. Ron Chan
  26. ropnop blog
  27. STÖK
  28. Sun Knudsen
  29. The Cyber Mentors
  30. The unofficial HackerOne disclosure timeline
  31. The XSS Rat
  32. TomNomNom
  33. Wallarm