1-Click Account Takeover via Open Redirect through Regex Bypass in Domain Validation on 20/06/2026
Khan Academy disclosed a bug submitted by farr: https://hackerone.com/reports/3723458 [...]
Khan Academy disclosed a bug submitted by farr: https://hackerone.com/reports/3723458 [...]
Dolphins, sharks, turtles, and human workers are all victims of unregulated squid fishing fleets. Another news article. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
The 2026 Burp Suite Extension Awards Best Recon & Discovery Best Auth & Access Control Best Workflow & Manipulation Best API & Specialist Testing Hidden Gem Most Nominated The talks In [...]
On June 9th, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, the company shut off access for everyone. The government’s actions won’t help. The problem isn’ [...]
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Isra [...]
Node.js disclosed a bug submitted by pimterry: https://hackerone.com/reports/3658225 [...]
Node.js disclosed a bug submitted by suul: https://hackerone.com/reports/3692858 [...]
Shopify disclosed a bug submitted by saltymermaid: https://hackerone.com/reports/2509022 - Bounty: $1600 [...]
At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details: The _index.js payload begins with a large JavaScript block comment containing fake system instructions and policy-triggering content. Because it is inside a comment, it does not affect JavaScript execution. The runtime skips it. The real malware [...]
Continuing our Agent ID series, this post demonstrates how a privileged agent could be compromised through its third-party blueprint. This leads to a cross-tenant incident similar to Midnight Blizzard, since an attacker with control over an agent blueprint can authenticate as any agent associated with that blueprint. [...]
HackerOne disclosed a bug submitted by brumbelow: https://hackerone.com/reports/3694007 - Bounty: $7000 [...]
On 14 April, the Trump administration quietly acknowledged the widespread use of AI to automate government processes. The office of management and budget (OMB) disclosed a staggering 3,611 active or planned use cases for AI across the federal government. The list has ballooned by 70% from the one published in the final year of the Biden administration, and includes many disturbing-seeming plans to [...]
curl disclosed a bug submitted by argareksapatii: https://hackerone.com/reports/3802645 [...]
Cristian Zot, known by most in the industry as CristiVlad25, is an active security researcher, experienced pentester, and an Intigriti Hacker Ambassador. He is a prominent figure in the ethical hacking community and frequently collaborates with Intigriti through platform meetups, podcast appearances, and educational content. Cristian has featured as a guest expert on Intigriti's live Office Hour [...]
Cristian Zot, known by most in the industry as CristiVlad25, is an active security researcher, experienced pentester, and an Intigriti Hacker Ambassador. He is a prominent figure in the ethical hacking community and frequently collaborates with Intigriti through platform meetups, podcast appearances, and educational content. Cristian has featured as a guest expert on Intigriti's live Office Hour [...]
curl disclosed a bug submitted by newstuff321: https://hackerone.com/reports/3804525 [...]
There are over a dozen cases around the country where police officers are using the Flock surveillance camera system to obsessively and illegally stalk people. Alternate link. [...]
Rocket.Chat disclosed a bug submitted by eldudareeno: https://hackerone.com/reports/3611837 [...]
Tor disclosed a bug submitted by aptupdate: https://hackerone.com/reports/3701692 - Bounty: $100 [...]
In this post, we walk through different threats to Salesforce and how to detect them. [...]
Rocket.Chat disclosed a bug submitted by aikido_security: https://hackerone.com/reports/3687142 [...]
IBM disclosed a bug submitted by entrovyx: https://hackerone.com/reports/3664261 [...]
curl disclosed a bug submitted by unknowperson0212: https://hackerone.com/reports/3793495 [...]
curl disclosed a bug submitted by daviey: https://hackerone.com/reports/3803415 [...]
A proposed FCC rule would kill burner phones: phones whose accounts are not attached to a particular person. The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information about essentially all phone customers, including a government issued identification number and their physical address, alarming privacy advocates and civil rights activists who [...]
PortSwigger Web Security disclosed a bug submitted by hacker-kartel: https://hackerone.com/reports/3717354 [...]
This post explores four vectors for threat actors to abuse Azure Storage to maliciously encrypt victim blobs, including step-by-step explanations and event codes for detection. [...]
This is a current list of where and when I am scheduled to speak: I’m giving a keynote at Cybernation 2026 in Berlin, Germany, on June 24, 2026. I’m speaking at the Potsdam Conference on National Cybersecurity at the Hasso Plattner Institut in Potsdam, Germany. The event runs June 24–25, 2026, and my talk will be the evening of June 24. I’m participating in a panel discussion at the Austrian Inst [...]
PortSwigger Web Security disclosed a bug submitted by kawakatz: https://hackerone.com/reports/3712279 - Bounty: $5000 [...]
curl disclosed a bug submitted by violet12331: https://hackerone.com/reports/3795615 [...]
This fluid pump was inspired by the way squids propel themselves through the water. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]
Let no one accuse Bernie Sanders of ducking the big questions. Writing in the New York Times last week, the senator asked: “Will the future of humanity be determined by a handful of billionaires who have promoted and developed AI, with virtually no democratic input, who stand to become even richer and more powerful than they are today?” We agree entirely that this is one of the most po [...]
What happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enough for us to detect these incorrectly generated keys in the wild. Together with Hanno Böck of the badkeys project, we found hundreds of unique keys that not only have this property, but can be quickly factored. We also found the bug that led to [...]
Node.js disclosed a bug submitted by shinchan_69: https://hackerone.com/reports/3781015 [...]
AWS VDP disclosed a bug submitted by inkerton: https://hackerone.com/reports/3558713 [...]
AWS VDP disclosed a bug submitted by terrynini38514: https://hackerone.com/reports/3738654 [...]
curl disclosed a bug submitted by bugthiru: https://hackerone.com/reports/3741744 [...]
curl disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3774279 [...]
DuckDuckGo disclosed a bug submitted by 6r1ff1n: https://hackerone.com/reports/3619288 [...]
DuckDuckGo disclosed a bug submitted by 6r1ff1n: https://hackerone.com/reports/3619287 [...]
Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3383079 [...]
Rocket.Chat disclosed a bug submitted by button142857: https://hackerone.com/reports/3393664 [...]
The surveillance company Leonardo wants more data: A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phones, wearables, and other Bluetooth-enabled devices in those cars, potentially letting law enforcement identify specific dr [...]
The intersection of AI and cybersecurity is reshaping how we find, fix, and think about vulnerabilities. Yet for all the headlines, few conversations cut through the noise to ask what AI means for those on the ground: the hunters, the security engineers, and the organizations trying to secure their data. In this blog, we open up that discussion, with insights from Leo Racanelli for an unflinching [...]
Entra Agent ID is an extension of Entra's application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) to multiple identities and their associated privileges, increasing the potential blast radius of a compromised agent. [...]
curl disclosed a bug submitted by monk17: https://hackerone.com/reports/3791168 [...]
curl disclosed a bug submitted by azraelxuemo: https://hackerone.com/reports/3791191 [...]
curl disclosed a bug submitted by nyymi: https://hackerone.com/reports/1826392 [...]
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group. A graphic create [...]
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available. The s [...]
curl disclosed a bug submitted by byteray_ltd: https://hackerone.com/reports/3788506 [...]
curl disclosed a bug submitted by kalfkinen: https://hackerone.com/reports/3786077 [...]
Ruby on Rails disclosed a bug submitted by ooooooo_q: https://hackerone.com/reports/2389431 [...]
We are delighted to share that Intigriti has won Best Security Company (under 250 employees), at this year’s SC Awards Europe. What it means to be an SC Award winner For over 25 years, the SC Awards Europe have defined what excellence looks like in cybersecurity, recognizing the organizations, technologies, and leaders shaping the future of the industry. On the 3rd of June 2026, Intigriti met wi [...]
curl disclosed a bug submitted by torkd1: https://hackerone.com/reports/3785919 [...]
curl disclosed a bug submitted by maxhearnden: https://hackerone.com/reports/3780733 [...]
curl disclosed a bug submitted by awofjawofjfawf: https://hackerone.com/reports/3781305 [...]
curl disclosed a bug submitted by fanhua: https://hackerone.com/reports/3749428 [...]
curl disclosed a bug submitted by alphalaab: https://hackerone.com/reports/3766392 [...]
Nextcloud disclosed a bug submitted by pirikara: https://hackerone.com/reports/3483708 [...]
Nextcloud disclosed a bug submitted by priyanka010: https://hackerone.com/reports/3489490 - Bounty: $2500 [...]
Nextcloud disclosed a bug submitted by alper_ozturk: https://hackerone.com/reports/3625210 [...]
curl disclosed a bug submitted by argus-systems: https://hackerone.com/reports/3784125 [...]
curl disclosed a bug submitted by bagder: https://hackerone.com/reports/3717552 [...]
curl disclosed a bug submitted by bagder: https://hackerone.com/reports/3718265 [...]
curl disclosed a bug submitted by hamaowo: https://hackerone.com/reports/3776535 [...]
curl disclosed a bug submitted by bowen111: https://hackerone.com/reports/3776433 [...]
curl disclosed a bug submitted by skksndk: https://hackerone.com/reports/3774977 [...]
curl disclosed a bug submitted by azraelxuemo: https://hackerone.com/reports/3766065 [...]