InfoSec Planet
A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
by BrianKrebs on 28/09/2026
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0 [...]
See full content
Steam IPC Exploit
on 28/09/2026
See full content
Builders & Breakers | Local AI for Offensive Security: Models, Harnesses & Human Judgment ft Thomas
on 28/09/2026
See full content
This WordPress Core Bug Can Lead to Remote Code Execution (CVE-2026-87902)
on 28/09/2026
See full content
Why Cybersecurity Needs Ecosystem Collaboration
on 28/09/2026
See full content
New Attack Against RSA
on 28/09/2026
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.
First, this attack isn’t new. The original research is from 2007. What is new is the implementation.
Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.
Third, the attack only works against pure signatures. Th [...]
See full content
OpenAI paid $6,500 for this bug! #shorts
on 27/09/2026
See full content
Gaining access to OpenAI's monorepo through ChatGPT #short
on 27/09/2026
See full content
Saturday evening candy haul and photography vibes #travel #photography #vlog
on 26/09/2026
See full content
Payload Podcast 012 - Yarden Shafir
on 26/09/2026
See full content
Steam Privilege Escalation
on 26/09/2026
See full content
Hacking OpenAI shortly after the Hugging Face incident.
on 26/09/2026
See full content
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
by BrianKrebs on 25/09/2026
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
One of several selfies from the Facebook page of Cameron Wagenius.
Cameron John Wagenius, 22, was [...]
See full content
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
on 25/09/2026
I feel like someone who reads this blog will want to go to this:
Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life. [...]
See full content
Ask and you shall receive. This is how a hacker got access to Meta’s Muse file system.
on 25/09/2026
See full content
OpenAI’s agents went rogue again. 😭
on 25/09/2026
See full content
Tracking TeamPCP Telegram
on 25/09/2026
See full content
OpenAI and Slack got hacked with the same vulnerability! #short
on 25/09/2026
See full content
Why You Need AI in Security Operations Now
on 25/09/2026
See full content
On Anthropic’s AI Misuse Report
on 25/09/2026
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.
A few of the highlights:
AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs [...]
See full content
Don't let TEEs break your MPC
on 25/09/2026
Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust across multiple independent parties, while TEEs root trust in the hardware manu [...]
See full content
Intigriti Bug Bytes #240 - September 2026 🚀
by Ayoub on 25/09/2026
Hi hackers,
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring:
Compromising OpenAI, Slack, Meta, and more via a vulnerable image library
Hacking OpenAI employee accounts in under 72 hours
Breaking into Google's GFile for $100K
Hacking AI CX agents
Turbo Intruder 2 surpassing 100K requests per second over HTTP/3
And so much more! Let's dive in!
Reconnaissan [...]
See full content
My AI Cybersecurity Mod Finally Looks Like a Real Game
on 24/09/2026
See full content
How Wiz And HackerOne Help Teams Remediate Faster
on 24/09/2026
See full content
Malicious npm Packages That Evade Defenses
on 24/09/2026
This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
[...]
See full content
They Hacked OpenAI! #shorts
on 24/09/2026
See full content
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)
on 24/09/2026
Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a vulnerability in OpenCode's upgrade endpoint that, under certain conditions, allowed malicious webpages to execute code on developers' machines. [...]
See full content
Exploring Trezor Safe 7 with Tomáš Sušánka
on 23/09/2026
See full content
Hacking AI for $100,000 Was Harder Than I Expected
on 23/09/2026
See full content
Vulnerability Prioritization: From Noise to True Risk
on 23/09/2026
See full content
Research on Models Engaging in Genie-Like Behavior
on 23/09/2026
New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”
Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies [...]
See full content
oh my god
on 23/09/2026
See full content
Is AppSec a Realistic First Cybersecurity Job?
on 22/09/2026
See full content
TeamPCP OSINT Investigation
on 22/09/2026
See full content
Exposure Management Means Breaking Security Silos
on 22/09/2026
See full content
GPT-6 Astra Breaks an Old Enigma Message
on 22/09/2026
This is pretty amazing:
However, the most astonishing thing about this break is that the GPT6 Astra did it entirely on its own. Carter Leffer only directed GPT6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and [...]
See full content
Wiz and HackerOne: Turning Exposure Management Into Faster Remediation with Eyal Golombek
on 22/09/2026
See full content
The Skill Gap AI Can't Close in Cybersecurity
on 22/09/2026
See full content
Superbacked 2 is open source
on 21/09/2026
See full content
Reverse-Engineering Flock Cameras
on 21/09/2026
Hackers captured a Flock camera and got a look (alternate link) at the software:
While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of im [...]
See full content
Anthropic Caught Hackers Doing This So I Rebuilt It in a Few Hours
on 21/09/2026
See full content
SAML: A fractal of bad design
on 21/09/2026
Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoni [...]
See full content
From sceptic to supercharged. How AI changed my day as a QA Engineer
by Martin Klimovski on 21/09/2026
When the push came to start weaving AI into our everyday work, I had doubts at the start. But I have since come around, and here's why.
What I actually do (and why that matters)
I'm on the engineering team at Intigriti, but my role is Quality Assurance (QA), so I'm the one writing the tests, running the tests, and then collaborating with the developers when something doesn't work the way it shoul [...]
See full content
Where Human Expertise Still Beats AI in Hacking
on 20/09/2026
See full content
The Scale Advantage: AI vs. Human Security Research
on 19/09/2026
See full content
Tracking TeamPCP
on 19/09/2026
See full content
Free Web Hacking Challenge!
on 19/09/2026
See full content
Payload Podcast 011 - Reunion
on 19/09/2026
See full content
Why Humans Still Matter in the Age of AI Hacking
on 18/09/2026
See full content
Friday Squid Blogging: On Squid Egg Sacs
on 18/09/2026
Short essay about squid egg sacs.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
[...]
See full content
Hunt.io Attack Capture
on 18/09/2026
See full content
Soft Skills for the Job Market: Personal Websites
on 18/09/2026
See full content
I Built a Portal to the Internet in Minecraft
on 18/09/2026
See full content
Are AIs Still Struggling with CAPTCHAs?
on 18/09/2026
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.
In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others [...]
See full content
Auditing in the age of (good enough) AI
on 18/09/2026
Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs (we’re one of them). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security reviews. We want to give a different perspective: before code review even starts, agents now allow us to build custom tooling [...]
See full content
Discourse Vulnerability: Urgent Warning for Self-Hosters! #shorts
on 18/09/2026
See full content
How OpenAI got hacked with an image
on 18/09/2026
See full content
Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
on 18/09/2026
In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets. [...]
See full content
Can AI Actually Find New Security Vulnerabilities?
on 17/09/2026
See full content
AI Security Research Is Moving Faster Than Defenders Can Keep Up with James Kettle
on 17/09/2026
See full content
Hunt.io Meets Minecraft
on 17/09/2026
See full content
My Browser Cache Got Infected
on 17/09/2026
See full content
How Candidates Could Use AI for Good
on 17/09/2026
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda.
Meanwhile, candidates are missing a real opportunity to use A [...]
See full content
Data Broker Radaris Loses Domains in Privacy Fight
by BrianKrebs on 16/09/2026
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement off [...]
See full content
The XSS Rat - OWASP Software Assurance Maturity Model - Just one of the services we offer!
on 16/09/2026
See full content
Mapping out your unknown: A threat hunter’s guide to GitHub
on 16/09/2026
In this post, we walk through different threats to GitHub and how to detect them. [...]
See full content
Minecraft Security Research
on 15/09/2026
See full content
ZProxy - the minimal proxy browser plugin you didn't know you needed
on 15/09/2026
See full content
Start Hardware Hacking for Just $20!
on 15/09/2026
See full content
1Password's AI patching benchmark is misleading
on 15/09/2026
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along with experiments in which agents could not compile or test their patches.
The report risks making defenders less effective b [...]
See full content
[Nederlands/Dutch] - Het OSCP learning path op RatCTF.com
on 14/09/2026
See full content
AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of
by Tim Erlin on 14/09/2026
Here's the uncomfortable part first: in August 2026, researchers found AI agents connected to Hugging Face running loose inside enterprise networks. No owner, no audit trail, nobody who could tell you they existed until something broke. If that sentence made your stomach drop a little, good, because it should. It's the same blind spot most security teams are sitting on right now. They just haven' [...]
See full content
Our Booth at DEF CON! #shorts
on 14/09/2026
See full content
How PayPal Is Rethinking Security in the Age of AI
on 14/09/2026
See full content
Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfi
on 14/09/2026
See full content
Met Cosmodium Cybersecurity at DEF CON! #shorts
on 13/09/2026
See full content
Meeting Laurie Wired at Black Hat #shorts
on 12/09/2026
See full content
TryHackMe? Nah… HTB? Not even maybe - RatCTF.com - come hack this rat for free right now
on 11/09/2026
See full content
Google Bug Hunter Event at Caesars Palace! 🕵️♂️ #shorts
on 11/09/2026
See full content
I am BACK rat pack!
on 10/09/2026
See full content
Exhausted But Thrilled: Teaching Fault Injection at DEF CON! #shorts
on 10/09/2026
See full content
Noob Village CTF Walkthrough | DEF CON | Cybersecurity AMA
on 10/09/2026
See full content
What AI Means For Bug Bounty Report Quality
on 09/09/2026
See full content
How MercadoLibre Secures A Constantly Moving Platform
on 09/09/2026
See full content
Black Hat VIP Party! #shorts
on 09/09/2026
See full content
A “proof” of Fermat’s Last Theorem that fits the margin
on 09/09/2026
Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem, but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 million lines of Lean code (clearly not what Fermat intended). Luckily, we found a wonderfully cursed Lean bug, shown belo [...]
See full content
Microsoft Plugs Nearly 1,000 Security Holes
by BrianKrebs on 08/09/2026
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and d [...]
See full content
We back.
on 08/09/2026
See full content
Is the OWASP Top 10 Still Relevant?
on 08/09/2026
See full content
Defcon Day 1! #shorts
on 08/09/2026
See full content
22: FTP wildcard matching decodes server-provided filenames, enabling directory traversal
on 08/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973143 [...]
See full content
Stack Buffer Overflow in mariadb-dump quote_name() Allows Malicious Server to Execute Arbitrary Code on Client
on 08/09/2026
MariaDB disclosed a bug submitted by byteoverride: https://hackerone.com/reports/3788482 [...]
See full content
Out-of-bounds read in MariaDB .frm parsing enables RCE via vtable hijacking
on 08/09/2026
MariaDB disclosed a bug submitted by pinebudweiser: https://hackerone.com/reports/3897914 [...]
See full content
49: Cookie-jar save transfers group access to a different GID
on 08/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973194 [...]
See full content
29: CURLOPT_ISSUERCERT accepts a different-key certificate when issuer metadata collides
on 08/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971518 [...]
See full content
08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path
on 08/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973111 [...]
See full content
Apple SecTrust fallback ignores CURLOPT_CRLFILE, letting a revoked cert pass
on 08/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3993850 [...]
See full content
HTTP Digest nonce reused across an httpshttp scheme change on the same handle
on 08/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3993973 [...]
See full content
How AI has changed the way I think, build, and work. A day in the life of an Intigriti Engineer
by Koen Van Hauwe on 08/09/2026
When I wake up in the morning, as a Senior Software Engineer at Intigriti, the first thing I do is make coffee. The second thing I do is pick up exactly where I left off the day before, usually mid-conversation with an AI.
That probably sounds a bit strange. And, depending on who you're asking, maybe a little unsettling too. But that's genuinely what my working day looks like now, and I think it' [...]
See full content
54: Rejected HTTP/2 push destroys MIME callback state still used by parent (use-after-free)
on 07/09/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973213 [...]
See full content