Researching Employment Scams on 03/09/2026
Researchers built a fake company to study fake employee scams. [...]
Researchers built a fake company to study fake employee scams. [...]
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier [...]
Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity. Comcast acknowledges that the system has some limi [...]
As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be. At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire, Founding Member of Intigriti, delivered a talk on how attackers can abuse today's AI agents in ways most defender [...]
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a [...]
To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line: Thank you for the positive impact your emails have had o [...]
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as [...]
Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy party, Team Mirai. Part 2 is about the Swiss Public AI model, Apertus. Part 3 is about the civic technologists of Open K [...]
At Intigriti, we have been exploring a simple but important shift in security: the work that happens before a vulnerability report is often where the real signal begins. As vulnerability discovery accelerates, organizations need practical ways to identify and reduce risk before vulnerabilities are used in attacks. In Reconnaissance for exposure management, I discussed how context turns scanning a [...]
It sure seems like it. The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation. Naval Air Station Lemoore, Calif., also experienced an outage, according to M. Elizabeth, writer of [...]
Someone hid AI instructions into a legal filing. Alternate link. [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973127 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971585 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973158 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973093 [...]
Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations. [...]
Weblate disclosed a bug submitted by visionx7: https://hackerone.com/reports/3869124 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973228 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3973169 [...]
Ugh: A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covere [...]
IBM disclosed a bug submitted by inventor0x01: https://hackerone.com/reports/3909372 [...]
WordPress disclosed a bug submitted by jakubk: https://hackerone.com/reports/3931777 [...]
WordPress disclosed a bug submitted by jakubk: https://hackerone.com/reports/3931771 [...]
Node.js disclosed a bug submitted by byvini: https://hackerone.com/reports/3857258 [...]
Node.js disclosed a bug submitted by yushengchen: https://hackerone.com/reports/3564941 [...]
Node.js disclosed a bug submitted by cantina-security: https://hackerone.com/reports/3795657 [...]
Node.js disclosed a bug submitted by cantina-security: https://hackerone.com/reports/3795900 [...]
Node.js disclosed a bug submitted by hahahkim: https://hackerone.com/reports/3833629 [...]
Node.js disclosed a bug submitted by leduckhuong: https://hackerone.com/reports/3846922 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972316 [...]
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love. We think the [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3971496 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3972196 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3970639 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3970650 [...]
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in one AI-ready toolkit And so much more! Let's dive in! CrowdRecon is coming Most security teams [...]
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cyberc [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3968729 [...]
curl disclosed a bug submitted by giant_anteater: https://hackerone.com/reports/3968431 [...]
Essity disclosed a bug submitted by matty69v: https://hackerone.com/reports/3729501 [...]
Essity disclosed a bug submitted by matty69v: https://hackerone.com/reports/3778282 [...]
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times. First, it used recently disclosed bugs [...]
curl disclosed a bug submitted by k4rasu_s4ma: https://hackerone.com/reports/3955945 [...]
Discourse disclosed a bug submitted by ahpuh: https://hackerone.com/reports/3689633 [...]
GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3527788 [...]
curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3966955 [...]
curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963330 [...]
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tokenized loans, private equity tokens, bridged assets, and asset registries. Our bug affected 82 markers representing live [...]
8x8 disclosed a bug submitted by a3z4km3: https://hackerone.com/reports/3889473 [...]
curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963494 [...]
curl disclosed a bug submitted by subadevan: https://hackerone.com/reports/3963725 [...]
Ruby on Rails disclosed a bug submitted by offsetmd: https://hackerone.com/reports/3727743 [...]
Nextcloud disclosed a bug submitted by mirachael: https://hackerone.com/reports/3696266 [...]
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo [...]
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. Ryan, how did you get started? To put it frankly, I got fired from my first pentesting jo [...]
curl disclosed a bug submitted by accl: https://hackerone.com/reports/3952619 [...]
Monero disclosed a bug submitted by lilpeko: https://hackerone.com/reports/3819475 [...]
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3686283 [...]
Monero disclosed a bug submitted by fg0x0: https://hackerone.com/reports/3679471 [...]
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3619409 [...]
Monero disclosed a bug submitted by qttps: https://hackerone.com/reports/3648638 [...]
Monero disclosed a bug submitted by k-privacy-enjoyer: https://hackerone.com/reports/3515557 [...]
Rocket.Chat disclosed a bug submitted by iamaangx028: https://hackerone.com/reports/3852135 [...]
Rocket.Chat disclosed a bug submitted by hillng: https://hackerone.com/reports/3872858 [...]
Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently crashing the UNIX utilities he was running. Web fuzzing is no different. Despite the rise of automated sc [...]
Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence. [...]
We tested Sonnet 5, Composer 2.5, and GPT 5.5 in plan mode and default mode to see whether plan mode produces measurably more secure code. [...]
Monero disclosed a bug submitted by usagirabbit: https://hackerone.com/reports/3620006 [...]
Monero disclosed a bug submitted by usagirabbit: https://hackerone.com/reports/3601469 [...]
Nextcloud disclosed a bug submitted by kuninogu: https://hackerone.com/reports/3799010 [...]
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938185 [...]
curl disclosed a bug submitted by mr4bugs: https://hackerone.com/reports/3938220 [...]
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds s [...]
curl disclosed a bug submitted by 1rhino2: https://hackerone.com/reports/3920276 [...]
Yelp disclosed a bug submitted by 0xkarim_dix: https://hackerone.com/reports/3829030 [...]
8x8 disclosed a bug submitted by offseq: https://hackerone.com/reports/3837634 - Bounty: $500 [...]
We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f [...]
Myndr disclosed a bug submitted by hackwithshubh: https://hackerone.com/reports/3930957 [...]
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. Image: Shutterstock, Mallika Home Studio. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording break [...]
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false public key, allowing the client to encrypt messages to an attacker rather than the intended recipient. Until now, the only way to detect such malfeasance was to veri [...]
At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and our Senior Product Manager, Radu Voloaga, took to the stage in the Bug Bounty Village to give everyone the first real look at CrowdRecon. How CrowdRecon closes the gap It started with a question we kept running into: what happens to all the reconnaissance work hackers do before a v [...]
CoinMate.io disclosed a bug submitted by ganesh_reddy: https://hackerone.com/reports/3265780 - Bounty: $100 [...]
curl disclosed a bug submitted by thinhlx: https://hackerone.com/reports/3923212 [...]
Nintendo disclosed a bug submitted by jonbarrow: https://hackerone.com/reports/2551512 [...]
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A survei [...]
CVSS open framework, rapid recap Stands for Common Vulnerability Scoring System. Owned by a US-based non-profit organization, the Forum of Incident Response and Security Teams (FIRST). The purpose is to help response teams quickly and easily calculate the severity of cybersecurity vulnerabilities based on metrics. Latest version: (4.0) designed to assess multiple environments and dimensio [...]
Mozilla disclosed a bug submitted by griffinf: https://hackerone.com/reports/3782701 - Bounty: $12000 [...]
curl disclosed a bug submitted by kiyin: https://hackerone.com/reports/3917775 [...]
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed service. But integrating an external service with your trusted enclaves comes with new threats, even if that service comes from the same provider. In this blog post—t [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3699522 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3698862 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3693636 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3700036 [...]
Monero disclosed a bug submitted by bebensap: https://hackerone.com/reports/3723315 [...]
Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3686259 [...]
Monero disclosed a bug submitted by benisprlh: https://hackerone.com/reports/3687543 [...]
curl disclosed a bug submitted by juthawong: https://hackerone.com/reports/3911968 [...]
"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray Huygen is a Security Analyst at Orange Cyberdefense, a managed security service provider with [...]
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of [...]
On August 4, 2026, several popular npm packages, including 'keyv', were compromised to deliver malware. [...]