InfoSec Planet

A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.

FBI Arrests Executive at Ransomware Negotiation Firm

by BrianKrebs on 10/10/2026

Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested an executive at a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity. The New York Times reported today that the FBI has arrested a Canadian man in Pennsylvania on s [...]

See full content

Friday Squid Blogging: I Caught a Squid

on 09/10/2026

On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA. We caught many cod (none of which we could keep), and a bunch of hake and mackerel (all of which we could keep). And…I caught a squid! Near as I can tell, it’s a longfin squid, sometimes called a Boston squid (Doryteuthis (Amerigo) pealeii). That night I cooked it over a barbecue grill—hot and fast. Delici [...]

See full content

You Can’t Secure the AWS Accounts You Don’t Know About.

by Tim Erlin on 08/10/2026

Wallarm Infrastructure Discovery Named Enterprise Cloud Security Solution of the Year. Ask an AWS security team how many accounts they run, and the honest answer is usually a range. Enterprises on AWS operate anywhere from 100 to 5,000 accounts. Most security teams can see only a fraction of them. That gap is why we built Wallarm Infrastructure Discovery. This week, it was named Enterprise [...]

See full content

How Technology Empowers—and Imperils—Dictators

on 08/10/2026

This essay was written with Seva Gunitsky, and originally appeared in Foreign Affairs. Two weeks after Moscow’s full-scale invasion of Ukraine in March 2022, the Russian TV Channel One editor Marina Ovsyannikova burst onto the set of the evening newscast. She held up a hand-drawn sign behind the anchor’s head that read: “Stop the war. Don’t believe propaganda. They’re [...]

See full content

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

by BrianKrebs on 07/10/2026

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divest [...]

See full content

Apple’s Verified Photography System

on 07/10/2026

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone. Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are conce [...]

See full content

Beyond asset discovery. Real-life CrowdRecon use case explored

by Radu Voloaga on 07/10/2026

Security teams have more ways than ever to map assets, scan infrastructure, and track vulnerabilities. Yet one question often remains difficult to answer: what does a skilled researcher consider worth exploring? That question matters because external exposure is not only a list of internet-facing assets; it is also a set of relationships, assumptions, and possible paths that change as products, do [...]

See full content

Possible Vulnerability in Apple’s Automatic Reboot

on 06/10/2026

404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours. The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, [...]

See full content

Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access

on 06/10/2026

In this post, we share LLM-specific validation patterns that attackers use to test exposed AWS credentials for Amazon Bedrock access. [...]

See full content

Another Historic Cipher Falls to AI

on 05/10/2026

This one is from 1809, written by Napoleon’s nephew. [...]

See full content

Guarding the gates: Assessing dangerous permissions granted to Kubernetes built-in principals

on 05/10/2026

We analyzed RBAC bindings across over 65,000 Kubernetes clusters to find dangerous permissions granted to system:anonymous, system:unauthenticated, and system:authenticated. [...]

See full content

Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

on 02/10/2026

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]

See full content

Unidentified Flock Cameras in Florida

on 02/10/2026

St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted. I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown. My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case i [...]

See full content

How American Political Campaigns Are Using AI—and What They’re Spending on the Tools

on 02/10/2026

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them. Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet abou [...]

See full content

SequenceHash: multihashing for the rest of us

on 02/10/2026

Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes. As part of our goal to “fix software, not bugs,” Trail of Bits is introducing SequenceHash and its sister function SequenceMAC, a pair of related hash constructions that bring secure multihashing to de [...]

See full content

Connected Cars Are a Surveillance Platform

on 01/10/2026

Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers: The new Northeastern study shows, for the first time, data flowing among the vehicles, the vehicle apps you download when you buy your car, and third-party companies, documenting exactly what kind of data gets siphoned from our vehicles and which companies are receiv [...]

See full content

AI Governance on AWS: The Runtime Control Loop: AI Governance on AWS: Four Functions, One Loop, and a Deadline That Already Passed

by Annette Reed on 30/09/2026

Answer this without checking: how many AI agents are running in your environment right now? Most security leaders give an estimate and a shrug. That is a fair response, because agents get spun up by an engineer solving a problem on a Tuesday afternoon, through a path that puts them on nobody's radar. In August 2026, researchers found AI agents connected to Hugging Face running loose inside ent [...]

See full content

I Want Better Reporting on AI Genie Behavior

on 30/09/2026

AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening. I wish the popular press would report on this better. I don’t like the “going rogue& [...]

See full content

10 years of Intigriti

by Eleanor Barlow on 29/09/2026

In the summer of 2026, Intigriti celebrated a major milestone: its 10th anniversary! To mark the occasion, the team came together from around the globe. This article shares what they had to say about a decade of Intigriti! A note from CEO and Founder, Stijn Jans What 10 years of evolution looks like  Intigriti’s journey shows how a bold idea evolved into a global cybersecurity company combining in [...]

See full content

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

by BrianKrebs on 28/09/2026

Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0 [...]

See full content

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

by BrianKrebs on 25/09/2026

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One of several selfies from the Facebook page of Cameron Wagenius. Cameron John Wagenius, 22, was [...]

See full content

Don't let TEEs break your MPC

on 25/09/2026

Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust across multiple independent parties, while TEEs root trust in the hardware manu [...]

See full content

Intigriti Bug Bytes #240 - September 2026 🚀

by Ayoub on 25/09/2026

Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising OpenAI, Slack, Meta, and more via a vulnerable image library Hacking OpenAI employee accounts in under 72 hours Breaking into Google's GFile for $100K Hacking AI CX agents Turbo Intruder 2 surpassing 100K requests per second over HTTP/3 And so much more! Let's dive in! Reconnaissan [...]

See full content

Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)

on 24/09/2026

Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a vulnerability in OpenCode's upgrade endpoint that, under certain conditions, allowed malicious webpages to execute code on developers' machines. [...]

See full content

SAML: A fractal of bad design

on 21/09/2026

Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoni [...]

See full content

From sceptic to supercharged. How AI changed my day as a QA Engineer

by Martin Klimovski on 21/09/2026

When the push came to start weaving AI into our everyday work, I had doubts at the start. But I have since come around, and here's why. What I actually do (and why that matters)  I'm on the engineering team at Intigriti, but my role is Quality Assurance (QA), so I'm the one writing the tests, running the tests, and then collaborating with the developers when something doesn't work the way it shoul [...]

See full content

Auditing in the age of (good enough) AI

on 18/09/2026

Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs (we’re one of them). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security reviews. We want to give a different perspective: before code review even starts, agents now allow us to build custom tooling [...]

See full content

Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms

on 18/09/2026

In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets. [...]

See full content

Data Broker Radaris Loses Domains in Privacy Fight

by BrianKrebs on 16/09/2026

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement off [...]

See full content

Mapping out your unknown: A threat hunter’s guide to GitHub

on 16/09/2026

In this post, we walk through different threats to GitHub and how to detect them. [...]

See full content

1Password's AI patching benchmark is misleading

on 15/09/2026

1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along with experiments in which agents could not compile or test their patches. The report risks making defenders less effective b [...]

See full content

AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of

by Tim Erlin on 14/09/2026

Here's the uncomfortable part first: in August 2026, researchers found AI agents connected to Hugging Face running loose inside enterprise networks. No owner, no audit trail, nobody who could tell you they existed until something broke. If that sentence made your stomach drop a little, good, because it should. It's the same blind spot most security teams are sitting on right now. They just haven' [...]

See full content

A “proof” of Fermat’s Last Theorem that fits the margin

on 09/09/2026

Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 million lines of Lean code (clearly not what Fermat intended). Luckily, we found a wonderfully cursed Lean bug, shown belo [...]

See full content

Microsoft Plugs Nearly 1,000 Security Holes

by BrianKrebs on 08/09/2026

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and d [...]

See full content

22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal

on 08/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973143 [...]

See full content

Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client

on 08/09/2026

MariaDB disclosed a bug submitted by byteoverride: https://hackerone.com/reports/3788482 [...]

See full content

Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking

on 08/09/2026

MariaDB disclosed a bug submitted by pinebudweiser: https://hackerone.com/reports/3897914 [...]

See full content

49: Cookie-jar save transfers group access to a different GID

on 08/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973194 [...]

See full content

29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides

on 08/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971518 [...]

See full content

08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path

on 08/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973111 [...]

See full content

Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass

on 08/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3993850 [...]

See full content

HTTP Digest nonce reused across an httpshttp scheme change on the same handle

on 08/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3993973 [...]

See full content

How AI has changed the way I think, build, and work. A day in the life of an Intigriti Engineer

by Koen Van Hauwe on 08/09/2026

When I wake up in the morning, as a Senior Software Engineer at Intigriti, the first thing I do is make coffee. The second thing I do is pick up exactly where I left off the day before, usually mid-conversation with an AI.  That probably sounds a bit strange. And, depending on who you're asking, maybe a little unsettling too. But that's genuinely what my working day looks like now, and I think it' [...]

See full content

54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)

on 07/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973213 [...]

See full content

57: Heap out-of-bounds read in `curl_easy_escape_ccsid()` / `curl_easy_unescape_ccsid()`

on 07/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973219 [...]

See full content

43: HTTP proxy CONNECT header chooses the `-OJ` filename after a redirect

on 07/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972293 [...]

See full content

36: HTTP upload resume offset consumed twice after early 307/308 redirect

on 07/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971706 [...]

See full content

11: `CURLOPT_FORBID_REUSE` silently lost on multiplexed HTTP/2 connection when the forbidding transfer finishes first

on 07/09/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973121 [...]

See full content

MariaDB GRANT PROXY permits unauthorized authentication changes and administrator account takeover

on 07/09/2026

MariaDB disclosed a bug submitted by kevin_mizu: https://hackerone.com/reports/3876430 [...]

See full content

MariaDB: heap buffer overflow in ha_tina::chain_append() lets a low-privileged user crash the server via CSV row deletion

on 07/09/2026

MariaDB disclosed a bug submitted by v3rtical: https://hackerone.com/reports/3909248 [...]

See full content

KILL authorization trusts the presented login name instead of the authenticated anonymous account

on 07/09/2026

MariaDB disclosed a bug submitted by dogeshark: https://hackerone.com/reports/3897588 [...]

See full content

ACL cache collision lets a role inherit privileges from a same-named socket user

on 07/09/2026

MariaDB disclosed a bug submitted by dogeshark: https://hackerone.com/reports/3889667 [...]

See full content

Unauthenticated testing endpoint of notify_push expose internal IP

on 05/09/2026

Nextcloud disclosed a bug submitted by chinnuy935336: https://hackerone.com/reports/3513471 - Bounty: $150 [...]

See full content

Email Enumeration via Password-Protected Share Identity Verification

on 05/09/2026

Nextcloud disclosed a bug submitted by cybershinu90: https://hackerone.com/reports/3507273 - Bounty: $100 [...]

See full content

Improper Input Validation and Integer Overflow in timeamount parameter of files_retention app

on 05/09/2026

Nextcloud disclosed a bug submitted by nishantbaswal1996: https://hackerone.com/reports/3521639 [...]

See full content

Missing Duplicate Check allowing Multiple Retention Rules per System Tag

on 05/09/2026

Nextcloud disclosed a bug submitted by charankumar39: https://hackerone.com/reports/3521646 [...]

See full content

Activity app does not verify federated file activity received from remote servers

on 05/09/2026

Nextcloud disclosed a bug submitted by cyebrsunita: https://hackerone.com/reports/3534050 - Bounty: $150 [...]

See full content

Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope

on 04/09/2026

Nextcloud disclosed a bug submitted by njh215: https://hackerone.com/reports/3617729 [...]

See full content

Dissecting Attacks Is Only Valuable If It Informs Controls: What the Unit 42 agentic AI investigation should change in your control set, stage by stage.

by Tim Erlin on 04/09/2026

The volume of published incident research involving agentic AI is increasing, and the analysis that follows each report tends to concentrate on the same attribute: speed. The recent investigation from Unit 42, the threat intelligence and incident response group at Palo Alto Networks, is a representative case. A human operator delegated tactical execution to frontier AI agents, compressing what wo [...]

See full content

API token sent to URL dictated by an untrusted project .weblate file

on 04/09/2026

Weblate disclosed a bug submitted by type5afe: https://hackerone.com/reports/3825141 [...]

See full content

Unauthenticated ?q= search query causes exponential pyparsing backtracking under a process-global lock in Weblate

on 04/09/2026

Weblate disclosed a bug submitted by type5afe: https://hackerone.com/reports/3898281 [...]

See full content

Hacking AI customer service agents

by Ayoub and Inti De Ceukelaire on 02/09/2026

As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be. At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire, Founding Member of Intigriti, delivered a talk on how attackers can abuse today's AI agents in ways most defender [...]

See full content

FBI Probes Service Selling 153M+ Drivers Licenses

by BrianKrebs on 01/09/2026

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a [...]

See full content

Reconnaissance unleashed: Meet CrowdRecon

by Radu Voloaga on 01/09/2026

At Intigriti, we have been exploring a simple but important shift in security: the work that happens before a vulnerability report is often where the real signal begins. As vulnerability discovery accelerates, organizations need practical ways to identify and reduce risk before vulnerabilities are used in attacks.  In Reconnaissance for exposure management, I discussed how context turns scanning a [...]

See full content

18: Explicit IPv6 proxy zone ID silently ignored proxy credentials sent to wrong interface

on 31/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973127 [...]

See full content

33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231)

on 31/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971585 [...]

See full content

41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body

on 31/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973158 [...]

See full content

06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses

on 31/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973093 [...]

See full content

Password spraying campaign targets AWS root user accounts across 150+ organizations

on 31/08/2026

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations. [...]

See full content

**Unauthenticated IDOR allows modification of payment customer billing information**

on 30/08/2026

Weblate disclosed a bug submitted by visionx7: https://hackerone.com/reports/3869124 [...]

See full content

50: CMake `HTTP_ONLY` does not disable SSH backends SCP and SFTP remain usable

on 29/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973228 [...]

See full content

42: `VMS_STS` macro typo (`< 3` vs `<< 3`) turns curl failures into successful OpenVMS conditions

on 29/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973169 [...]

See full content

Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint

on 28/08/2026

IBM disclosed a bug submitted by inventor0x01: https://hackerone.com/reports/3909372 [...]

See full content

Author arbitrary file deletion anywhere on disk (site takeover) via `POST /wp/v2/media/<id>/finalize` poisoning `_wp_attachment_metadata`

on 28/08/2026

WordPress disclosed a bug submitted by jakubk: https://hackerone.com/reports/3931777 [...]

See full content

Author stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()`

on 28/08/2026

WordPress disclosed a bug submitted by jakubk: https://hackerone.com/reports/3931771 [...]

See full content

HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser

on 28/08/2026

Node.js disclosed a bug submitted by yushengchen: https://hackerone.com/reports/3564941 [...]

See full content

Reachable assertion in node:zlib sync API crashes the entire process via spoofed TypedArray byteLength (all 11 *Sync functions affected)

on 28/08/2026

Node.js disclosed a bug submitted by byvini: https://hackerone.com/reports/3857258 [...]

See full content

dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records

on 28/08/2026

Node.js disclosed a bug submitted by cantina-security: https://hackerone.com/reports/3795657 [...]

See full content

node:sqlite SQLTagStore Iterator Replay Lets Attacker Re-Execute Victim-Bound Writes Indefinitely

on 28/08/2026

Node.js disclosed a bug submitted by cantina-security: https://hackerone.com/reports/3795900 [...]

See full content

Re-entrant `nghttp2_session_mem_send()` during `nghttp2_session_mem_recv()` causes heap-use-after-free in Node.js HTTP/2

on 28/08/2026

Node.js disclosed a bug submitted by hahahkim: https://hackerone.com/reports/3833629 [...]

See full content

HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion

on 28/08/2026

Node.js disclosed a bug submitted by leduckhuong: https://hackerone.com/reports/3846922 [...]

See full content

46: `--libcurl` output carries `--insecure` across `--next` boundaries

on 28/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972316 [...]

See full content

28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket

on 28/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971496 [...]

See full content

34: `curl_mprintf` reads `double` for documented `long double` conversions uninitialized value disclosure

on 28/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972196 [...]

See full content

--etag-save - truncates append-redirected stdout

on 28/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3970639 [...]

See full content

Stacked --proto modifiers leave denied protocol enabled

on 28/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3970650 [...]

See full content

Intigriti Bug Bytes #239 - August 2026 🚀

by Ayoub on 28/08/2026

Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready toolkit And so much more! Let's dive in! CrowdRecon is coming Most security teams [...]

See full content

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

by BrianKrebs on 27/08/2026

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cyberc [...]

See full content

Unbound cross-peer HTTP Digest challenge state

on 27/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3968729 [...]

See full content

ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds

on 27/08/2026

curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3968431 [...]

See full content

Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit)

on 27/08/2026

Essity disclosed a bug submitted by matty69v: https://hackerone.com/reports/3729501 [...]

See full content

Critical SQL Injection WDM API ()

on 27/08/2026

Essity disclosed a bug submitted by matty69v: https://hackerone.com/reports/3778282 [...]

See full content

VMs won't contain cyber-capable agents

on 26/08/2026

As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times. First, it used recently disclosed bugs [...]

See full content

curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack

on 26/08/2026

curl disclosed a bug submitted by k4rasu_s4ma: https://hackerone.com/reports/3955945 [...]

See full content

Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization

on 26/08/2026

Discourse disclosed a bug submitted by ahpuh: https://hackerone.com/reports/3689633 [...]

See full content

Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating

on 25/08/2026

GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3527788 [...]

See full content

TLS session cache case-folds CA paths and bypasses the active trust profile

on 25/08/2026

curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3966955 [...]

See full content

libcurl Digest/NTLM authentication ignores an explicit Authorization header

on 25/08/2026

curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963330 [...]

See full content

State divergence enables unauthorized access

on 25/08/2026

We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tokenized loans, private equity tokens, bridged assets, and asset registries. Our bug affected 82 markers representing live [...]

See full content

@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration)

on 25/08/2026

8x8 disclosed a bug submitted by a3z4km3: https://hackerone.com/reports/3889473 [...]

See full content

Sources

The content of this page is fetched from the following sources:

  1. Datadog Security Labs
  2. The Trail of Bits Blog
  3. Schneier on Security
  4. Krebs on Security
  5. Google Online Security Blog
  6. $BLOG_TITLE
  7. Agarri : Sécurité informatique offensive
  8. Alex Chapman's Blog
  9. www.alphabot.com
  10. ziot
  11. cat ~/footstep.ninja/blog.txt
  12. Ezequiel Pereira
  13. Intigriti
  14. PortSwigger Blog
  15. Richard’s Infosec blog
  16. Ron Chan
  17. ropnop blog
  18. The unofficial HackerOne disclosure timeline
  19. Wallarm