InfoSec Planet
A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
by BrianKrebs on 07/10/2026
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divest [...]
See full content
Just Hacking Training Turns 2!
on 07/10/2026
See full content
Apple’s Verified Photography System
on 07/10/2026
Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone.
Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are conce [...]
See full content
Beyond asset discovery. Real-life CrowdRecon use case explored
by Radu Voloaga on 07/10/2026
Security teams have more ways than ever to map assets, scan infrastructure, and track vulnerabilities. Yet one question often remains difficult to answer: what does a skilled researcher consider worth exploring? That question matters because external exposure is not only a list of internet-facing assets; it is also a set of relationships, assumptions, and possible paths that change as products, do [...]
See full content
Giveaway wheel of fortune
on 06/10/2026
See full content
What Do Security Professionals Look for in Code?
on 06/10/2026
See full content
Possible Vulnerability in Apple’s Automatic Reboot
on 06/10/2026
404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours.
The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, [...]
See full content
Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access
on 06/10/2026
In this post, we share LLM-specific validation patterns that attackers use to test exposed AWS credentials for Amazon Bedrock access. [...]
See full content
PowerShell Payload Unpacked
on 05/10/2026
See full content
I Gave Claude Access to My Hacking Traffic
on 05/10/2026
See full content
The AI Harness Is Where Security Researchers Win
on 05/10/2026
See full content
Another Historic Cipher Falls to AI
on 05/10/2026
This one is from 1809, written by Napoleon’s nephew.
[...]
See full content
Guarding the gates: Assessing dangerous permissions granted to Kubernetes built-in principals
on 05/10/2026
We analyzed RBAC bindings across over 65,000 Kubernetes clusters to find dangerous permissions granted to system:anonymous, system:unauthenticated, and system:authenticated. [...]
See full content
Security Through Complexity #shorts
on 04/10/2026
See full content
Payload Podcast 012 - Yarden Shafir
on 03/10/2026
See full content
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
on 02/10/2026
The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
[...]
See full content
DEF CON CTF Walkthrough: Packet Analysis
on 02/10/2026
See full content
Unidentified Flock Cameras in Florida
on 02/10/2026
St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted.
I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown.
My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case i [...]
See full content
OpenAI Hacked with a 1-Year-Old Bug
on 02/10/2026
See full content
Facebook’s marketplace is just getting weirder especially with AI in the mix. #ai #meta #facebook
on 02/10/2026
See full content
AI Won’t Kill Vulnerability Research. It Will Reward Intuition.
on 02/10/2026
See full content
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
on 02/10/2026
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.
Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet abou [...]
See full content
SequenceHash: multihashing for the rest of us
on 02/10/2026
Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes.
As part of our goal to “fix software, not bugs,” Trail of Bits is introducing SequenceHash and its sister function SequenceMAC, a pair of related hash constructions that bring secure multihashing to de [...]
See full content
OpenAI has shifted threat models #shorts
on 02/10/2026
See full content
Firefox Profile Payload
on 01/10/2026
See full content
Finding a vulnerability in libheif #shorts
on 01/10/2026
See full content
Black Hat AI
on 01/10/2026
See full content
AI Can Chain Vulnerabilities Faster Than Expected
on 01/10/2026
See full content
Connected Cars Are a Surveillance Platform
on 01/10/2026
Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:
The new Northeastern study shows, for the first time, data flowing among the vehicles, the vehicle apps you download when you buy your car, and third-party companies, documenting exactly what kind of data gets siphoned from our vehicles and which companies are receiv [...]
See full content
Real Folks of Cyber | Marshall Livingston | DITL
on 01/10/2026
See full content
AI Governance on AWS: The Runtime Control Loop: AI Governance on AWS: Four Functions, One Loop, and a Deadline That Already Passed
by Annette Reed on 30/09/2026
Answer this without checking: how many AI agents are running in your environment right now?
Most security leaders give an estimate and a shrug. That is a fair response, because agents get spun up by an engineer solving a problem on a Tuesday afternoon, through a path that puts them on nobody's radar. In August 2026, researchers found AI agents connected to Hugging Face running loose inside ent [...]
See full content
Why Old Threat Models Are Dead #shorts
on 30/09/2026
See full content
Google built PageBreak and it found 500 XSS on Google’s own application. That kinda hurts 😭
on 30/09/2026
See full content
Agentic AI Testing Has To Learn The Application First
on 30/09/2026
See full content
I Want Better Reporting on AI Genie Behavior
on 30/09/2026
AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening.
I wish the popular press would report on this better. I don’t like the “going rogue& [...]
See full content
Can Developers Switch to AppSec Roles?
on 29/09/2026
See full content
Using Claude 5 to write an exploit against Discourse #shorts
on 29/09/2026
See full content
Why AI Cybersecurity Benchmarks Miss Real Attackers
on 29/09/2026
See full content
Using Device Linking to Eavesdrop on WhatsApp and Signal
on 29/09/2026
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:
Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.
Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’ [...]
See full content
Why AI Cybersecurity Benchmarks Miss Real Attackers with Nahman Khayet
on 29/09/2026
See full content
10 years of Intigriti
by Eleanor Barlow on 29/09/2026
In the summer of 2026, Intigriti celebrated a major milestone: its 10th anniversary! To mark the occasion, the team came together from around the globe. This article shares what they had to say about a decade of Intigriti!
A note from CEO and Founder, Stijn Jans
What 10 years of evolution looks like
Intigriti’s journey shows how a bold idea evolved into a global cybersecurity company combining in [...]
See full content
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
by BrianKrebs on 28/09/2026
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0 [...]
See full content
Steam IPC Exploit
on 28/09/2026
See full content
Builders & Breakers | Local AI for Offensive Security: Models, Harnesses & Human Judgment ft Thomas
on 28/09/2026
See full content
This WordPress Core Bug Can Lead to Remote Code Execution (CVE-2026-87902)
on 28/09/2026
See full content
Why Cybersecurity Needs Ecosystem Collaboration
on 28/09/2026
See full content
New Attack Against RSA
on 28/09/2026
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.
First, this attack isn’t new. The original research is from 2007. What is new is the implementation.
Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.
Third, the attack only works against pure signatures. Th [...]
See full content
OpenAI paid $6,500 for this bug! #shorts
on 27/09/2026
See full content
Gaining access to OpenAI's monorepo through ChatGPT #short
on 27/09/2026
See full content
Saturday evening candy haul and photography vibes #travel #photography #vlog
on 26/09/2026
See full content
Steam Privilege Escalation
on 26/09/2026
See full content
Hacking OpenAI shortly after the Hugging Face incident.
on 26/09/2026
See full content
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
by BrianKrebs on 25/09/2026
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
One of several selfies from the Facebook page of Cameron Wagenius.
Cameron John Wagenius, 22, was [...]
See full content
Ask and you shall receive. This is how a hacker got access to Meta’s Muse file system.
on 25/09/2026
See full content
OpenAI’s agents went rogue again. 😭
on 25/09/2026
See full content
Tracking TeamPCP Telegram
on 25/09/2026
See full content
OpenAI and Slack got hacked with the same vulnerability! #short
on 25/09/2026
See full content
Why You Need AI in Security Operations Now
on 25/09/2026
See full content
Don't let TEEs break your MPC
on 25/09/2026
Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust across multiple independent parties, while TEEs root trust in the hardware manu [...]
See full content
Intigriti Bug Bytes #240 - September 2026 🚀
by Ayoub on 25/09/2026
Hi hackers,
Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring:
Compromising OpenAI, Slack, Meta, and more via a vulnerable image library
Hacking OpenAI employee accounts in under 72 hours
Breaking into Google's GFile for $100K
Hacking AI CX agents
Turbo Intruder 2 surpassing 100K requests per second over HTTP/3
And so much more! Let's dive in!
Reconnaissan [...]
See full content
My AI Cybersecurity Mod Finally Looks Like a Real Game
on 24/09/2026
See full content
How Wiz And HackerOne Help Teams Remediate Faster
on 24/09/2026
See full content
They Hacked OpenAI! #shorts
on 24/09/2026
See full content
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)
on 24/09/2026
Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a vulnerability in OpenCode's upgrade endpoint that, under certain conditions, allowed malicious webpages to execute code on developers' machines. [...]
See full content
Exploring Trezor Safe 7 with Tomáš Sušánka
on 23/09/2026
See full content
Hacking AI for $100,000 Was Harder Than I Expected
on 23/09/2026
See full content
Vulnerability Prioritization: From Noise to True Risk
on 23/09/2026
See full content
oh my god
on 23/09/2026
See full content
Is AppSec a Realistic First Cybersecurity Job?
on 22/09/2026
See full content
TeamPCP OSINT Investigation
on 22/09/2026
See full content
Exposure Management Means Breaking Security Silos
on 22/09/2026
See full content
Wiz and HackerOne: Turning Exposure Management Into Faster Remediation with Eyal Golombek
on 22/09/2026
See full content
The Skill Gap AI Can't Close in Cybersecurity
on 22/09/2026
See full content
Superbacked 2 is open source
on 21/09/2026
See full content
Anthropic Caught Hackers Doing This So I Rebuilt It in a Few Hours
on 21/09/2026
See full content
SAML: A fractal of bad design
on 21/09/2026
Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoni [...]
See full content
From sceptic to supercharged. How AI changed my day as a QA Engineer
by Martin Klimovski on 21/09/2026
When the push came to start weaving AI into our everyday work, I had doubts at the start. But I have since come around, and here's why.
What I actually do (and why that matters)
I'm on the engineering team at Intigriti, but my role is Quality Assurance (QA), so I'm the one writing the tests, running the tests, and then collaborating with the developers when something doesn't work the way it shoul [...]
See full content
Where Human Expertise Still Beats AI in Hacking
on 20/09/2026
See full content
The Scale Advantage: AI vs. Human Security Research
on 19/09/2026
See full content
Tracking TeamPCP
on 19/09/2026
See full content
Free Web Hacking Challenge!
on 19/09/2026
See full content
Payload Podcast 011 - Reunion
on 19/09/2026
See full content
Hunt.io Attack Capture
on 18/09/2026
See full content
Soft Skills for the Job Market: Personal Websites
on 18/09/2026
See full content
Auditing in the age of (good enough) AI
on 18/09/2026
Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs (we’re one of them). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security reviews. We want to give a different perspective: before code review even starts, agents now allow us to build custom tooling [...]
See full content
Discourse Vulnerability: Urgent Warning for Self-Hosters! #shorts
on 18/09/2026
See full content
How OpenAI got hacked with an image
on 18/09/2026
See full content
Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
on 18/09/2026
In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets. [...]
See full content
Data Broker Radaris Loses Domains in Privacy Fight
by BrianKrebs on 16/09/2026
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement off [...]
See full content
The XSS Rat - OWASP Software Assurance Maturity Model - Just one of the services we offer!
on 16/09/2026
See full content
Mapping out your unknown: A threat hunter’s guide to GitHub
on 16/09/2026
In this post, we walk through different threats to GitHub and how to detect them. [...]
See full content
ZProxy - the minimal proxy browser plugin you didn't know you needed
on 15/09/2026
See full content
Start Hardware Hacking for Just $20!
on 15/09/2026
See full content
1Password's AI patching benchmark is misleading
on 15/09/2026
1Password’s FLAWED report, published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along with experiments in which agents could not compile or test their patches.
The report risks making defenders less effective b [...]
See full content
[Nederlands/Dutch] - Het OSCP learning path op RatCTF.com
on 14/09/2026
See full content
AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of
by Tim Erlin on 14/09/2026
Here's the uncomfortable part first: in August 2026, researchers found AI agents connected to Hugging Face running loose inside enterprise networks. No owner, no audit trail, nobody who could tell you they existed until something broke. If that sentence made your stomach drop a little, good, because it should. It's the same blind spot most security teams are sitting on right now. They just haven' [...]
See full content
Our Booth at DEF CON! #shorts
on 14/09/2026
See full content
Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfi
on 14/09/2026
See full content
Met Cosmodium Cybersecurity at DEF CON! #shorts
on 13/09/2026
See full content
TryHackMe? Nah… HTB? Not even maybe - RatCTF.com - come hack this rat for free right now
on 11/09/2026
See full content