InfoSec Planet

A collection of diverse security content from a curated list of sources. This website also serves as a demo for "worker-planet", the software that powers it.

RATS Q4 - What hardware and OS do I need to start hacking

on 28/07/2026

See full content

Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh

on 28/07/2026

AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3633146 [...]

See full content

Axon Is Another License Plate Surveillance Company

on 28/07/2026

Governments are switching, but I’m not sure it makes a difference: …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings. […] Despite w [...]

See full content

How we use /goal to find bugs in Patch the Planet

on 28/07/2026

Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at some of the most widely used, heavily audited codebases in the world, like Rust, curl, and zlib. One tool came up again and [...]

See full content

JHT Course Launch! Home Labs with Proxmox

on 28/07/2026

See full content

RAG and ruin: why your existing controls may miss AI poisoning attacks

by Eleanor Barlow on 28/07/2026

Key takeaways   RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does.   In simple QA systems, that may mean misinformation or unsafe recommendations.   In agentic systems with tools and permissions, it can become data leakage, un [...]

See full content

Did an AI Really Hack Hugging Face?

on 27/07/2026

See full content

Payload Podcast 010 - Olaf Hartong

on 27/07/2026

See full content

Lessons from the OpenAI and Hugging Face Incident: When Safety Filters Disarm the Defender

by Aleksandr Orekhov on 27/07/2026

In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, "the AI went rogue," is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the [...]

See full content

Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration

on 27/07/2026

AWS VDP disclosed a bug submitted by nick_frichette_dd: https://hackerone.com/reports/3775702 [...]

See full content

Authentication Bypass via XML Signature Wrapping in SAML SSO

on 27/07/2026

Rocket.Chat disclosed a bug submitted by 0jayden: https://hackerone.com/reports/3827674 [...]

See full content

How One File Upload Got Me the Entire Customer Database

on 27/07/2026

See full content

Introducing Burp AT: agentic AI, built on two decades of Burp Suite

on 27/07/2026

Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries [...]

See full content

Cognyte Sells a Mobile Cell Surveillance Van

on 27/07/2026

Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed [...]

See full content

Detection primitives for eBPF rootkits

on 27/07/2026

We analyze how VoidLink, LinkPro, and Atomic Arch abuse eBPF helpers to hide from defenders, and show how to detect them at load time, before they can act. [...]

See full content

Any App Notification

on 26/07/2026

See full content

How do you keep up to date with the latest cybernews and development?

on 26/07/2026

See full content

RATS Q3 - How Much Python Should I Know before Hacking

on 25/07/2026

See full content

Building Fake Notifications

on 25/07/2026

See full content

Why Being a Great Hacker Doesn't Pay Anymore

on 25/07/2026

See full content

Friday Squid Blogging: Illex Squid Catch in the Falklands

on 24/07/2026

Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]

See full content

ZMQ RPC Log Injection and Untrusted Payload Persistence

on 24/07/2026

Monero disclosed a bug submitted by redlobsterzzz: https://hackerone.com/reports/3621606 [...]

See full content

Why AI Needs a “Genie Coefficient”

on 24/07/2026

This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new metric: the Genie coefficient. There’s often a gap between one person’s request and anot [...]

See full content

Fake Edge Update

on 23/07/2026

See full content

End-to-End Encryption and “Going Dark”

on 23/07/2026

New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments ar [...]

See full content

They hacked Google's AI in Seoul

on 23/07/2026

See full content

TCM Course Release | New Creator | Cybersecurity | AMA

on 23/07/2026

See full content

AI’s convenience cost. The impact of the lethal trifecta on organizations today

by Eleanor Barlow on 23/07/2026

The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant, the more its access, permissions, and actions need guardrails.   This blog takes a look at the lethal  [...]

See full content

AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF

on 22/07/2026

AWS VDP disclosed a bug submitted by notnotnotveg: https://hackerone.com/reports/3809407 [...]

See full content

GitHub user to server tokens can create issues in any public repository

on 22/07/2026

GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3641229 [...]

See full content

First-Person Identity Theft Story

on 22/07/2026

Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts hangs on the security of our email accounts. [...]

See full content

connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability

on 22/07/2026

8x8 disclosed a bug submitted by kyotozzx: https://hackerone.com/reports/3800870 - Bounty: $1337 [...]

See full content

LG to Ban Residential Proxies from Smart TV Apps

by BrianKrebs on 22/07/2026

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traff [...]

See full content

OAuth redirect uri validation bypass for :proxima_first_party_sync apps

on 21/07/2026

GitHub disclosed a bug submitted by ahacker1: https://hackerone.com/reports/3588801 [...]

See full content

An AI Botnet

on 21/07/2026

See full content

MIT to Become Hotbed of AI Video Surveillance

on 21/07/2026

It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026. Technical specifi [...]

See full content

Hunt Like A Real Rat - CyberStarterNexusCTF - Bug Bounty Tips From A Industry Icon

on 20/07/2026

See full content

Redirect Chain Abuse

on 20/07/2026

See full content

Microsoft Exchange Hacked, Five Years Later

on 20/07/2026

See full content

On Flock License Plate Tracking Cameras

on 20/07/2026

A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the m [...]

See full content

Stop Playing Whack-a-Mole With Bugs.

on 20/07/2026

See full content

Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes

on 20/07/2026

Monero disclosed a bug submitted by int0ha_: https://hackerone.com/reports/3738727 [...]

See full content

The between-reports problem: why security teams miss what attackers see

by Greg Jenkins on 20/07/2026

What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What we believe security teams will need next: earlier signals that support action before the next repor [...]

See full content

Q and A: RATS Q2 What Is A Good Web App Hacking Workflow

on 19/07/2026

See full content

CyberLab Con 26 Track 1 (I'm live at 2PM UTC!)

on 19/07/2026

See full content

Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

on 17/07/2026

Lots of articles about this. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. [...]

See full content

Happy hacking

on 17/07/2026

See full content

Burp's new Ambassadors: learn from the people who use Burp Suite everyday

on 17/07/2026

Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass [...]

See full content

Details of Alan Turing’s Voice Encryption System

on 17/07/2026

Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delil [...]

See full content

Your Scanners Were Not Thinking About This.

on 17/07/2026

See full content

Evil Token Marketplace

on 16/07/2026

See full content

Bug Bounty Is Your Safety Parachute.

on 16/07/2026

See full content

Payload Podcast 009 - Steven Flores

on 16/07/2026

See full content

Stored XSS in Rocket.Chat HTML File Export Unauthenticated Entry via LiveChat

on 16/07/2026

Rocket.Chat disclosed a bug submitted by olidayw: https://hackerone.com/reports/3779690 [...]

See full content

Able to bypass authorization logic and gain more access then intended

on 15/07/2026

GitHub disclosed a bug submitted by vaib25vicky: https://hackerone.com/reports/3713965 [...]

See full content

Q and A: RATS Q1 - How Do You Develop A Tinkering Mindset

on 15/07/2026

See full content

Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections

on 15/07/2026

AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3632577 [...]

See full content

Your Weekly Test Is Already Too Late.

on 15/07/2026

See full content

Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass

on 14/07/2026

Basecamp disclosed a bug submitted by newbiefromcoma: https://hackerone.com/reports/3581911 - Bounty: $337 [...]

See full content

Microsoft Patches a Record 570 Security Flaws

by BrianKrebs on 14/07/2026

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs qu [...]

See full content

bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys

on 14/07/2026

AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3702072 [...]

See full content

Backdoored TortoiseSVN Installer

on 14/07/2026

See full content

More Scans Are Not Continuous Security.

on 14/07/2026

See full content

Is Your Continuous Threat Exposure Management Actually Continuous with Michiel Prins

on 14/07/2026

See full content

Compromised AsyncAPI npm packages: inside a CI supply-chain attack

on 14/07/2026

On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected. [...]

See full content

AI Control Platform vs. AI Firewall vs. AI Gateway: Clearing Up The Terminology

by Tim Erlin on 13/07/2026

Editor's note: This article was originally published by Tim Erlin on LinkedIn. It has been republished here with the author's permission. https://www.linkedin.com/pulse/ai-control-platform-vs-firewall-gateway-clearing-up-tim-erlin-ypodc It seems like every security vendor now sells "AI security." The WAF companies, the API gateway companies, the cloud platforms, the proxy startups: all of them [...]

See full content

SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server

on 13/07/2026

SingleStore disclosed a bug submitted by bisht-ji: https://hackerone.com/reports/3780695 [...]

See full content

Lessons Learned from CISA’s Recent GitHub Leak

by BrianKrebs on 13/07/2026

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important [...]

See full content

This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)

on 13/07/2026

See full content

Rust-proof your code with our new Testing Handbook chapter

on 13/07/2026

We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems. fn main() {(|f:&dyn Fn(u128)->Box< dyn Iterator<Item= char>+'static>|f(*[&( 0x7B736D70683F73u128<<64| 0x7A6A6D7C3F7A667D),&(0x7B73 [...]

See full content

NEW AI Hacking Challenges with Andrew Bellini!

on 11/07/2026

See full content

Soft Skills for the Job Market: Applying for Jobs

on 10/07/2026

See full content

The most severe exposure lives in the quiet overlap between tech, people, and process. ♾️

on 10/07/2026

See full content

Fake Microsoft Installer

on 10/07/2026

See full content

See you at Black Hat USA 2026!

on 09/07/2026

See full content

Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)

on 09/07/2026

AWS VDP disclosed a bug submitted by mistercloudsec: https://hackerone.com/reports/3630605 [...]

See full content

Heading to Vegas? Meet PortSwigger at Black Hat, BSides, and DEF CON 34.

on 09/07/2026

First hand of the week: Find us at BSides Workshop: Burp But Yours, with Hannah and Tib3rius Center stage: Visit us at Black Hat USA - Booth 5342 Lightning talks at the booth Catch our researchers' br [...]

See full content

Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor

on 09/07/2026

A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys. [...]

See full content

LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway

on 08/07/2026

See full content

TeamPCP Attention

on 08/07/2026

See full content

Welcome to the best security page ever.

on 08/07/2026

See full content

Felons, Fraudsters Flog Offensive Cybersecurity Startup

by BrianKrebs on 08/07/2026

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 [...]

See full content

Mutation testing comes to DAML

on 08/07/2026

In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DAML’s authorization primitives), and runs them through your existing test suite to count how many [...]

See full content

Coordinated GitHub API enumeration and access token abuse

on 08/07/2026

Datadog Security Research has tracked multiple coordinated campaigns enumerating GitHub organizations, repositories, and users through the public GitHub API, abusing leaked access tokens, and cloning private repositories. [...]

See full content

OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)

on 06/07/2026

AWS VDP disclosed a bug submitted by kaporia: https://hackerone.com/reports/3637898 [...]

See full content

Stop what you're doing

on 06/07/2026

See full content

I Made an AI Agent That Reverses CVEs While I Sleep

on 06/07/2026

See full content

Entra Agent ID: Protect, detect, respond

on 06/07/2026

This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant. [...]

See full content

Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity

on 04/07/2026

Basecamp disclosed a bug submitted by zerodaysec_xyz: https://hackerone.com/reports/3764217 - Bounty: $287 [...]

See full content

admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed

on 03/07/2026

Shopify disclosed a bug submitted by abahack: https://hackerone.com/reports/3628961 [...]

See full content

Are your employees using AI?

on 03/07/2026

See full content

FBI Seizes NetNut Proxy Platform, Popa Botnet

by BrianKrebs on 02/07/2026

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botn [...]

See full content

Non-Production API Endpoints for the Amazon S3 Tables Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration

on 02/07/2026

AWS VDP disclosed a bug submitted by nick_frichette_dd: https://hackerone.com/reports/3780277 [...]

See full content

We get this question a lot

on 02/07/2026

See full content

jitsi-meet: Prosody/Jigasi missing header whitelist in mod_filter_iq_rayo allows arbitrary SIP header injection and Caller ID spoofing

on 02/07/2026

8x8 disclosed a bug submitted by pmgjoe: https://hackerone.com/reports/3789570 - Bounty: $100 [...]

See full content

jitsi-call-analytics: Unauthenticated arbitrary file write via path traversal in `/api/v1/uploads/analyze`

on 02/07/2026

8x8 disclosed a bug submitted by r1skr1der: https://hackerone.com/reports/3485343 - Bounty: $100 [...]

See full content

Yelp for Business: locked Email field silently editable via API

on 02/07/2026

Yelp disclosed a bug submitted by 0xmanticore: https://hackerone.com/reports/3766455 [...]

See full content

Celebrating 1 Million Subscribers on July 8th!

on 02/07/2026

See full content

GPT-5.5-Cyber built a zlib fuzzing lab in a day

on 02/07/2026

We’re running Patch the Planet, an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon create a firehose of bug reports, and OSS maintainers are already spread thin. Our plan is to point OpenAI’s latest model [...]

See full content

Splatoon 3 In-Match Integrity Bypass via Consensus Reflection Attack on Unordered Peer Submission

on 02/07/2026

Nintendo disclosed a bug submitted by hana2736: https://hackerone.com/reports/3559522 [...]

See full content

Sources

The content of this page is fetched from the following sources:

  1. Datadog Security Labs
  2. The Trail of Bits Blog
  3. Schneier on Security
  4. Krebs on Security
  5. Google Online Security Blog
  6. $BLOG_TITLE
  7. Agarri : Sécurité informatique offensive
  8. Alex Chapman's Blog
  9. www.alphabot.com
  10. ziot
  11. Bug Bounty Reports Explained
  12. Bugcrowd
  13. cat ~/footstep.ninja/blog.txt
  14. Ezequiel Pereira
  15. HackerOne
  16. surajdisoja.me
  17. InsiderPhD
  18. Intigriti
  19. John Hammond
  20. LiveOverflow
  21. NahamSec
  22. PortSwigger Blog
  23. Rana Khalil
  24. Richard’s Infosec blog
  25. Ron Chan
  26. ropnop blog
  27. STÖK
  28. Sun Knudsen
  29. The Cyber Mentors
  30. The unofficial HackerOne disclosure timeline
  31. The XSS Rat
  32. TomNomNom
  33. Wallarm