URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag on 24/08/2026
Ruby on Rails disclosed a bug submitted by offsetmd: https://hackerone.com/reports/3727743 [...]
Ruby on Rails disclosed a bug submitted by offsetmd: https://hackerone.com/reports/3727743 [...]
Interesting paper: Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: En [...]
Nextcloud disclosed a bug submitted by mirachael: https://hackerone.com/reports/3696266 [...]
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo [...]
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo [...]
The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii), [...]
This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E [...]
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our inves [...]
curl disclosed a bug submitted by accl: https://hackerone.com/reports/3952619 [...]
Monero disclosed a bug submitted by lilpeko: https://hackerone.com/reports/3819475 [...]
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3686283 [...]
Monero disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3679471 [...]
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3619409 [...]
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3648638 [...]
Monero disclosed a bug submitted by k-privacy-enjoyer: https://hackerone.com/reports/3515557 [...]
Rocket.Chat disclosed a bug submitted by iamaangx028: https://hackerone.com/reports/3852135 [...]
Rocket.Chat disclosed a bug submitted by hillng: https://hackerone.com/reports/3872858 [...]
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work. [...]
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE, [...]
Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently crashing the UNIX utilities he was running. Web fuzzing is no different. Despite the rise of automated sc [...]
Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence. [...]
ICE collected nearly a million DNA samples last year. [...]
We tested Sonnet 5, Composer 2.5, and GPT 5.5 in plan mode and default mode to see whether plan mode produces measurably more secure code. [...]
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this me [...]
Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials. [...]
Monero disclosed a bug submitted by usagirabbit: https://hackerone.com/reports/3620006 [...]
Monero disclosed a bug submitted by usagirabbit: https://hackerone.com/reports/3601469 [...]
Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching. As usual, you can [...]
Nextcloud disclosed a bug submitted by kuninogu: https://hackerone.com/reports/3799010 [...]
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938185 [...]
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938220 [...]
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds s [...]
curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3920276 [...]
Yelp disclosed a bug submitted by 0xkarim_dix: https://hackerone.com/reports/3829030 [...]
8x8 disclosed a bug submitted by offseq: https://hackerone.com/reports/3837634 - Bounty: $500 [...]
We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f [...]
Myndr disclosed a bug submitted by hackwithshubh: https://hackerone.com/reports/3930957 [...]
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording break [...]
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt messages to an attacker rather than the intended recipient. Until now, the only way to detect such malfeasance was to veri [...]
At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and our Senior Product Manager, Radu Voloaga, took to the stage in the Bug Bounty Village to give everyone the first real look at CrowdRecon. How CrowdRecon closes the gap It started with a question we kept running into: what happens to all the reconnaissance work hackers do before a v [...]
CoinMate.io disclosed a bug submitted by ganesh_reddy: https://hackerone.com/reports/3265780 - Bounty: $100 [...]
curl disclosed a bug submitted by thinhlx: https://hackerone.com/reports/3923212 [...]
Nintendo disclosed a bug submitted by jonbarrow: https://hackerone.com/reports/2551512 [...]
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A survei [...]
CVSS open framework, rapid recap Stands for Common Vulnerability Scoring System. Owned by a US-based non-profit organization, the Forum of Incident Response and Security Teams (FIRST). The purpose is to help response teams quickly and easily calculate the severity of cybersecurity vulnerabilities based on metrics. Latest version: (4.0) designed to assess multiple environments and dimensio [...]
Mozilla disclosed a bug submitted by griffinf: https://hackerone.com/reports/3782701 - Bounty: $12000 [...]
curl disclosed a bug submitted by kiyin: https://hackerone.com/reports/3917775 [...]
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service with your trusted enclaves comes with new threats, even if that service comes from the same provider. In this blog post—t [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3699522 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3698862 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3693636 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3700036 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3723315 [...]
Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3686259 [...]
Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3687543 [...]
curl disclosed a bug submitted by juthawong: https://hackerone.com/reports/3911968 [...]
"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray Huygen is a Security Analyst at Orange Cyberdefense, a managed security service provider with [...]
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of [...]
On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware. [...]
AWS VDP disclosed a bug submitted by sh3d0w: https://hackerone.com/reports/3478646 [...]
Rocket.Chat disclosed a bug submitted by howtoplay: https://hackerone.com/reports/3514640 [...]