No need to be a Mythos to do offensive security
https://fuzzinglabs.com/wp-content/uploads/2026/06/Le-Hack-2026-Keynote-_-No-Need-to-be-a-Mythos-to-do-Offensive-security-Patrick-Ventuzelo-_-FuzzingLabs.pdf
https://fuzzinglabs.com/wp-content/uploads/2026/06/Le-Hack-2026-Keynote-_-No-Need-to-be-a-Mythos-to-do-Offensive-security-Patrick-Ventuzelo-_-FuzzingLabs.pdf
β€7π₯6
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
watchTowr Labs
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out.
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? βBut watchTowr, what do you mean?β
Well, if youβre here, you likely fit intoβ¦
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? βBut watchTowr, what do you mean?β
Well, if youβre here, you likely fit intoβ¦
Find Comment, Get Shell: Command Injection in dbtβs GitHub Actions
https://www.landh.tech/blog/20260701-find-comment-get-shell/
https://www.landh.tech/blog/20260701-find-comment-get-shell/
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/
https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/
PaperMtn
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
Detections for Claude on the execution layer: Sigma rules and a correlation runner that catch permission bypasses, rogue MCP servers, and more.
The Bug Bounty Singularity: Our Hackbot
https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html
https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html
β€4π€2π1
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
devploit / blog
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
What happens if an app without READ_CONTACTS asks Google Messages for Android to load a Contacts photo for it?
β€7
How I Chained an Open Redirect into Email Leak and Got $1,337 from Google
https://xlsize0bruh.medium.com/how-i-chained-an-open-redirect-into-email-leak-and-got-1-337-from-google-c8a4655677a2
https://xlsize0bruh.medium.com/how-i-chained-an-open-redirect-into-email-leak-and-got-1-337-from-google-c8a4655677a2
Medium
How I Chained an Open Redirect into Email Leak and Got $1,337 from Google
Who Am I?
π11β€8
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
weirdmachine64.github.io
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64
RFC 8628's device authorization grant lets a TV or CLI
β€4
How to use Claude Code for Bug Bounty: find fast, validate manually
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
YesWeHack
How to use Claude Code for Bug Bounty: find fast, validate manually
We put Claude Code through two blind Bug Bounty labs β DOM XSS and HTTP request smuggling β to see if it can find and prove real vulnerabilities.
π9β€4π2π2
WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
Searchlight Cyber
wp2shell: Pre Authentication RCE in WordPress Core βΊ Searchlight Cyber
Critical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiringβ¦
β€7π2
Language Model Security Database
A comprehensive collection of LLM vulnerabilities, curated from cutting-edge research papers and real-world discoveries.
https://www.promptfoo.dev/lm-security-db
A comprehensive collection of LLM vulnerabilities, curated from cutting-edge research papers and real-world discoveries.
https://www.promptfoo.dev/lm-security-db
www.promptfoo.dev
LM Security Database
A comprehensive database of researched vulnerabilities for Large Language Models
β€6π4
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
Searchlight Cyber
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 βΊ Searchlight Cyber
Stay current: Get research alerts for newly disclosed vulnerabilities and exposures If you're running WordPress and want to check if your instance is vulnerable, you can use our tool we've hosted here: https://wp2shell.com/. We held off on publishing thisβ¦
β€5π4π₯4
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
wiz.io
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
π5π4π₯4β€3
A Shell Is Worth A Thousand Images: Bing Images RCEs
https://xbow.com/blog/bing-images-rce-vulnerabilities
https://xbow.com/blog/bing-images-rce-vulnerabilities
β€3π2
From a βHey, {name} πβ Banner to Full Account Takeover | Chaining 4 Bugs Through a Rewards WebView
https://medium.com/@bag0zathev2/from-a-hey-name-banner-to-full-account-takeover-chaining-4-bugs-through-a-rewards-webview-f89a2b0f830f
https://medium.com/@bag0zathev2/from-a-hey-name-banner-to-full-account-takeover-chaining-4-bugs-through-a-rewards-webview-f89a2b0f830f
Medium
From a βHey, {name} πβ Banner to Full Account Takeover | Chaining 4 Bugs Through a Rewards WebView
Hey folks π Hope you are doing great today! β€
β€8
How to use Claude Code for Bug Bounty: find fast, validate manually
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
YesWeHack
How to use Claude Code for Bug Bounty: find fast, validate manually
We put Claude Code through two blind Bug Bounty labs β DOM XSS and HTTP request smuggling β to see if it can find and prove real vulnerabilities.
π9β€2π1