InfoSec Planet
A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.
50: CMake `HTTP_ONLY` does not disable SSH backends SCP and SFTP remain usable on 29/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973228 [...]
42: `VMS_STS` macro typo (`< 3` vs `<< 3`) turns curl failures into successful OpenVMS conditions on 29/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973169 [...]
Offsec pricing is mental on 29/08/2026
How To Use AI To Become a KiLLER Hacker on 29/08/2026
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island on 28/08/2026
Ugh: A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covere [...]
Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint on 28/08/2026
IBM disclosed a bug submitted by inventor0x01: https://hackerone.com/reports/3909372 [...]
Author arbitrary file deletion anywhere on disk (site takeover) via `POST /wp/v2/media/<id>/finalize` poisoning `_wp_attachment_metadata` on 28/08/2026
WordPress disclosed a bug submitted by jakubk: https://hackerone.com/reports/3931777 [...]
Author stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()` on 28/08/2026
WordPress disclosed a bug submitted by jakubk: https://hackerone.com/reports/3931771 [...]
Reachable assertion in node:zlib sync API crashes the entire process via spoofed TypedArray byteLength (all 11 *Sync functions affected) on 28/08/2026
Node.js disclosed a bug submitted by byvini: https://hackerone.com/reports/3857258 [...]
HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser on 28/08/2026
Node.js disclosed a bug submitted by yushengchen: https://hackerone.com/reports/3564941 [...]
dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records on 28/08/2026
Node.js disclosed a bug submitted by cantina-security: https://hackerone.com/reports/3795657 [...]
node:sqlite SQLTagStore Iterator Replay Lets Attacker Re-Execute Victim-Bound Writes Indefinitely on 28/08/2026
Node.js disclosed a bug submitted by cantina-security: https://hackerone.com/reports/3795900 [...]
Re-entrant `nghttp2_session_mem_send()` during `nghttp2_session_mem_recv()` causes heap-use-after-free in Node.js HTTP/2 on 28/08/2026
Node.js disclosed a bug submitted by hahahkim: https://hackerone.com/reports/3833629 [...]
HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion on 28/08/2026
Node.js disclosed a bug submitted by leduckhuong: https://hackerone.com/reports/3846922 [...]
46: `--libcurl` output carries `--insecure` across `--next` boundaries on 28/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972316 [...]
AI Doesn’t Mean the End of Mathematics—at Least Not Yet on 28/08/2026
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love. We think the [...]
Why AI Can't Fix Vulnerabilities Alone. on 28/08/2026
28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket on 28/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971496 [...]
34: `curl_mprintf` reads `double` for documented `long double` conversions uninitialized value disclosure on 28/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972196 [...]
--etag-save - truncates append-redirected stdout on 28/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3970639 [...]
Stacked --proto modifiers leave denied protocol enabled on 28/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3970650 [...]
Intigriti Bug Bytes #239 - August 2026 🚀 by Ayoub on 28/08/2026
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready toolkit And so much more! Let's dive in! CrowdRecon is coming Most security teams [...]
GitHub Hacker EXPOSED BY HIS CAT on 27/08/2026
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia by BrianKrebs on 27/08/2026
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cyberc [...]
False Positives Burn Developer Trust. on 27/08/2026
LLM-Based Social Engineering Scams on 27/08/2026
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in [...]
Unbound cross-peer HTTP Digest challenge state on 27/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3968729 [...]
ARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds on 27/08/2026
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3968431 [...]
Pre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit) on 27/08/2026
Essity disclosed a bug submitted by matty69v: https://hackerone.com/reports/3729501 [...]
Critical SQL Injection WDM API () on 27/08/2026
Essity disclosed a bug submitted by matty69v: https://hackerone.com/reports/3778282 [...]
Real Folks of Cyber | Joel Valenzuela | DITL on 27/08/2026
Device Code Phishing on 26/08/2026
Spyware for Babies on 26/08/2026
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech an [...]
VMs won't contain cyber-capable agents on 26/08/2026
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times. First, it used recently disclosed bugs [...]
Why Vulnerability Remediation Gets Blocked. on 26/08/2026
curl_share TOCTOU > RCE via Curl_llist _dtor Function Pointer Hijack on 26/08/2026
curl disclosed a bug submitted by k4rasu_s4ma: https://hackerone.com/reports/3955945 [...]
Hidden/restricted tags can be mutated through synonym ID paths without per-tag authorization on 26/08/2026
Discourse disclosed a bug submitted by ahpuh: https://hackerone.com/reports/3689633 [...]
Add labels to arbitrary issues/prs via Memex Bulk Update to compromise github actions label gating on 25/08/2026
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3527788 [...]
TLS session cache case-folds CA paths and bypasses the active trust profile on 25/08/2026
curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3966955 [...]
How to Build a Home Lab for Cheap! on 25/08/2026
libcurl Digest/NTLM authentication ignores an explicit Authorization header on 25/08/2026
curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963330 [...]
State divergence enables unauthorized access on 25/08/2026
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tokenized loans, private equity tokens, bridged assets, and asset registries. Our bug affected 82 markers representing live [...]
Black Hat State of Security Vendors on 25/08/2026
Andy Ellis has a roundup of the security vendors at Black Hat this year. Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse. At the same tim [...]
Your Vulnerability Backlog Is The Risk. on 25/08/2026
Why Vulnerability Backlogs Keep Growing (And How AI Remediation Fixes It) on 25/08/2026
@jitsi/docker-jitsi-meet: `/colibri-relay-ws/` unsafe nginx regex (OCTO relay configuration) on 25/08/2026
8x8 disclosed a bug submitted by a3z4km3: https://hackerone.com/reports/3889473 [...]
RTSP CRLF injection in libcurl allows CURLOPT_RTSP_* values to inject commands into independent sessions on 24/08/2026
curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963494 [...]
wolfSSL backend disables hostname verification when CURLOPT_SSL_VERIFYPEER is 0 on 24/08/2026
curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963725 [...]
URI scheme validation bypass in ActionText `to_markdown` via user-supplied `<action-text-markdown>` marker tag on 24/08/2026
Ruby on Rails disclosed a bug submitted by offsetmd: https://hackerone.com/reports/3727743 [...]
Inventory The Entire Host on 24/08/2026
This Word Document Steals Your Password From Microsoft Copilot (+ LIVE DEMO) on 24/08/2026
Criminal Deception in Silicon Valley on 24/08/2026
Interesting paper: Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: En [...]
Attackers Win When Research Stays Private. on 24/08/2026
Path Traversal in Nextcloud Talk Android Exposes User Credentials and Private Data via FileProvider on 24/08/2026
Nextcloud disclosed a bug submitted by mirachael: https://hackerone.com/reports/3696266 [...]
When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS) by Eleanor Barlow on 24/08/2026
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo [...]
When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS) by Eleanor Barlow on 24/08/2026
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo [...]
My Life, AI and the Future of LiveOverflow on 23/08/2026
Friday Squid Blogging: Neon Flying Squid on 21/08/2026
The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii), [...]
AI Is Learning to Write Genetic Code on 21/08/2026
This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E [...]
Vanta vs. Drata: The 10 Questions Our CISO Asks GRC Vendors on 21/08/2026
Canary Tokens, Meet AI on 21/08/2026
How To Shut Down CSS Attacks. on 21/08/2026
More Incidents of AIs Going Rogue in Cybersecurity Challenges on 21/08/2026
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our inves [...]
Domainless COOKIEFILE cookie leaks to unrelated IP-literal hosts on 21/08/2026
curl disclosed a bug submitted by accl: https://hackerone.com/reports/3952619 [...]
Monero GUI OpenAlias DNSSEC-invalid resolution still writes spoofable address into recipient field on 20/08/2026
Monero disclosed a bug submitted by lilpeko: https://hackerone.com/reports/3819475 [...]
View-only offline transaction creation bypasses the long-payment-ID privacy block on 20/08/2026
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3686283 [...]
HTML Injection in Transaction Confirmation Dialog via Address Book Description Enables UI Spoofing Before Fund Transfer on 20/08/2026
Monero disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3679471 [...]
Windows installer grants low-privileged users write access to executable P2Pool directory, enabling local code execution on 20/08/2026
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3619409 [...]
monero:// deeplink parsing accepts tx_amount=(all) and can trigger send-all transaction mode on 20/08/2026
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3648638 [...]
Loss of multisig funds through single malicious participant's deliberate deception on 20/08/2026
Monero disclosed a bug submitted by k-privacy-enjoyer: https://hackerone.com/reports/3515557 [...]
DDP methods getThreadsList / getThreadMessages leaks private thread content to any authenticated low privilege user (unpatched sibling of #1446767) on 20/08/2026
Rocket.Chat disclosed a bug submitted by iamaangx028: https://hackerone.com/reports/3852135 [...]
Stored HTML Injection (CWE-79) via Livechat Visitor Name on 20/08/2026
Rocket.Chat disclosed a bug submitted by hillng: https://hackerone.com/reports/3872858 [...]
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face on 20/08/2026
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work. [...]
I Built a Minecraft Mod That Sees Real Internet Data on 20/08/2026
It's Not Just JavaScript Anymore. on 20/08/2026
Web fuzzing for hackers by Ayoub and Orwa Atyat on 20/08/2026
Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently crashing the UNIX utilities he was running. Web fuzzing is no different. Despite the rise of automated sc [...]
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it on 20/08/2026
Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence. [...]
You Can't Turn CSS Off. on 19/08/2026
Putting models to the secure coding test: Plan vs default mode on 19/08/2026
We tested Sonnet 5, Composer 2.5, and GPT 5.5 in plan mode and default mode to see whether plan mode produces measurably more secure code. [...]
Do I Need to Know Programming in 2026? on 18/08/2026
Beyond JavaScript: The Rise of CSS-Based Attacks on 18/08/2026
Stealing Passwords With Just CSS. on 18/08/2026
Blueprint to Making $100K with Caido (Free Bug Bounty Course) on 17/08/2026
The Security Blind Spot Nobody's Talking About with Nidhi Aggarwal on 17/08/2026
AI Malware Gets Weird on 17/08/2026
Ignore Your AI Strategy on 17/08/2026
Your Exposure Backlog Is Growing Right Now on 17/08/2026
The Missing Piece in Your Threat Exposure Strategy on 17/08/2026
Wallet RPC Restricted-Mode Policy Bypass on 17/08/2026
Monero disclosed a bug submitted by usagirabbit: https://hackerone.com/reports/3620006 [...]
Restricted RPC Policy Bypass on ZMQ JSON-RPC Allows Unauthenticated Remote Admin Actions on 17/08/2026
Monero disclosed a bug submitted by usagirabbit: https://hackerone.com/reports/3601469 [...]
The OpenAI Story Actually Scares Me on 16/08/2026
Soft Skills for the Job Market: Standing Out! on 14/08/2026
TaskProcessing callback authorization bypass allows ex-members to post as Assistant Talk Bot on 14/08/2026
Nextcloud disclosed a bug submitted by kuninogu: https://hackerone.com/reports/3799010 [...]
Windows SSPI connection-pool probe can reuse a connection under the wrong user on 14/08/2026
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938185 [...]
libcurl cache updates follow symlinks and truncate their targets on 14/08/2026
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938220 [...]
Who’s Tracking You? Use This New Service to Find Out by BrianKrebs on 14/08/2026
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds s [...]
Cookie jar load skips public suffix check on PSL builds on 14/08/2026
curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3920276 [...]