Account Takeover Vulnerability Affecting Over 400K Installations Patched in Post SMTP Plugin
https://patchstack.com/articles/account-takeover-vulnerability-affecting-over-400k-installations-patched-in-post-smtp-plugin/
https://patchstack.com/articles/account-takeover-vulnerability-affecting-over-400k-installations-patched-in-post-smtp-plugin/
Patchstack
Account Takeover Vulnerability Affecting Over 400K Installations Patched in Post SMTP Plugin - Patchstack
🚨 A critical flaw in Post SMTP (≤3.2.0) let Subscriber users access email logs, intercept reset links, and take over admin accounts. ✅ Update to 3.3.0 now to stay protected!
❤3
Stack Overflows, Heap Overflows, and Existential Dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
https://labs.watchtowr.com/stack-overflows-heap-overflows-and-existential-dread-sonicwall-sma100-cve-2025-40596-cve-2025-40597-and-cve-2025-40598/
https://labs.watchtowr.com/stack-overflows-heap-overflows-and-existential-dread-sonicwall-sma100-cve-2025-40596-cve-2025-40597-and-cve-2025-40598/
watchTowr Labs
Stack Overflows, Heap Overflows, and Existential Dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
It’s 2025, and at this point, we’re convinced there’s a secret industry-wide pledge: every network appliance must include at least one trivially avoidable HTTP header parsing bug - preferably pre-auth. Bonus points if it involves sscanf.
If that’s the case…
If that’s the case…
❤4👍1
Unauthenticated Arbitrary File Deletion Vulnerability in Litho Theme
https://patchstack.com/articles/unauthenticated-arbitrary-file-delete-vulnerability-in-litho-the/
https://patchstack.com/articles/unauthenticated-arbitrary-file-delete-vulnerability-in-litho-the/
❤5
Security as Added Value: WP Umbrella Unlocks Additional Revenue in 3 Weeks
https://patchstack.com/articles/wp-umbrella-unlocks-additional-revenue-in-3-weeks/
https://patchstack.com/articles/wp-umbrella-unlocks-additional-revenue-in-3-weeks/
RapidMitigate: Next-gen vulnerability mitigation for websites
https://patchstack.com/articles/rapidmitigate-next-gen-vulnerability-mitigation-for-websites/
https://patchstack.com/articles/rapidmitigate-next-gen-vulnerability-mitigation-for-websites/
👎2
Red‑Teaming Challenge - OpenAI gpt-oss-20b
Find any flaws and vulnerabilities in gpt-oss-20b that have not been previously discovered or reported.
https://www.kaggle.com/competitions/openai-gpt-oss-20b-red-teaming/
Find any flaws and vulnerabilities in gpt-oss-20b that have not been previously discovered or reported.
https://www.kaggle.com/competitions/openai-gpt-oss-20b-red-teaming/
Kaggle
Red‑Teaming Challenge - OpenAI gpt-oss-20b
Find any flaws and vulnerabilities in gpt-oss-20b that have not been previously discovered or reported.
Critical Vulnerability Impacting Over 100K Sites Patched in Everest Forms Plugin
https://patchstack.com/articles/critical-vulnerability-impacting-over-100k-sites-patched-in-everest-forms-plugin/
https://patchstack.com/articles/critical-vulnerability-impacting-over-100k-sites-patched-in-everest-forms-plugin/
How Agencies Can Operate Like Startups Inside Enterprises with Karim Marucchi of Crowd Favorite
https://patchstack.com/articles/how-agencies-can-operate-like-startups/
https://patchstack.com/articles/how-agencies-can-operate-like-startups/
Is Drupal CMS a good alternative to WordPress? With Steve Persch of Pantheon
https://patchstack.com/articles/is-drupal-cms-a-good-alternative-to-wordpress/
https://patchstack.com/articles/is-drupal-cms-a-good-alternative-to-wordpress/
Patchstack
Is Drupal CMS a good alternative to WordPress? With Steve Persch of Pantheon - Patchstack
Discover how Pantheon manages sites on Drupal, as well as the key changes coming with Drupal's AI agent recipes.
❤8👍1
XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)
https://m.youtube.com/watch?v=rvA8IbyogJ0
https://m.youtube.com/watch?v=rvA8IbyogJ0
YouTube
XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)
Episode 134: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Diego Jurado to give us the scoop on XBOW. We cover a little about its architecture and approach to hunting, the challenges with hallucinations, and the future of AI in…
❤14👎8
From Signal to the Android SDK: Chaining Path Traversal, Mimetype Confusion, Security Check Bypass and File Descriptor Bruteforce for Arbitrary File Access
https://blog.ostorlab.co/signal-arbitrary-file-read.html
https://blog.ostorlab.co/signal-arbitrary-file-read.html
blog.ostorlab.co
Ostorlab: Mobile App Security Testing for Android and iOS
This technical analysis reveals how sophisticated attack chains—combining path traversal, symbolic link manipulation, and Android SDK quirks—can breach Signal Android's defenses to extract sensitive internal files, despite its legendary encryption remaining…
👏6
Multiple Critical Vulnerabilities Patched in WP Job Portal Plugin
https://patchstack.com/articles/multiple-critical-vulnerabilities-patched-in-wp-job-portal-plugin/
https://patchstack.com/articles/multiple-critical-vulnerabilities-patched-in-wp-job-portal-plugin/
Patchstack
Multiple Critical Vulnerabilities Patched in WP Job Portal Plugin - Patchstack
🔐 Severe WP Job Portal vulnerabilities: 💾 SQL Injection & 📥 Arbitrary File Download could let attackers compromise your site. Update to v2.3.3 now to stay protected. 🔒
❤4
GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)
https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/
https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/
Embrace The Red
GitHub Copilot: Remote Code Execution via Prompt Injection
An attacker can put GitHub Copilot into YOLO mode by modifying the project's settings.json file on the fly, and then executing commands, all without user approval
👍8❤5
Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store
http://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html
http://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html
Google
Sustaining Digital Certificate Security - Upcoming Changes to the Chrome Root Store
Note: Google Chrome communicated its removal of default trust of Chunghwa Telecom and Netlock in the public forum on May 30, 2025.The Chrome Root Program Policy states t…
👍4❤1
Discovering hidden parameters: An advanced guide
https://www.intigriti.com/researchers/blog/hacking-tools/finding-hidden-input-parameters
https://www.intigriti.com/researchers/blog/hacking-tools/finding-hidden-input-parameters
Intigriti
Finding Hidden Parameters: Advanced Enumeration Guide
Learn how to find and detect hidden input (query & body) parameters using various advanced testing methods. Read the article now!
❤2👍2
Rare Case of Privilege Escalation in ASE Plugin Affecting 100k+ Sites
https://patchstack.com/articles/rare-case-of-privilege-escalation-in-ase-plugin-affecting-100k-sites/
https://patchstack.com/articles/rare-case-of-privilege-escalation-in-ase-plugin-affecting-100k-sites/
Patchstack
Rare Case of Privilege Escalation in ASE Plugin Affecting 100k+ Sites - Patchstack
Critical privilege escalation vulnerability in Admin and Site Enhancements (ASE) plugin (≤7.6.2.1). Update to 7.6.3 or stay protected with Patchstack.
👍1
Meet Burp Suite DAST: Your questions answered
https://portswigger.net/blog/meet-burp-suite-dast-your-questions-answered
https://portswigger.net/blog/meet-burp-suite-dast-your-questions-answered
PortSwigger Blog
Meet Burp Suite DAST: Your questions answered
We recently hosted a webinar to introduce Burp Suite DAST, the new name for Burp Suite Enterprise Edition, the best-in-class, automated web application and API security scanning solution for modern Ap
CVE-2025-5777: CitrixBleed 2 Exploit Deep Dive by Horizon3.ai
https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/
https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/
Horizon3.ai
CVE-2025-5777: CitrixBleed 2 Write-Up… Maybe?
Explore the CVE-2025-5777 vulnerability in Citrix, dubbed CitrixBleed 2. Learn how it works, attack details, and defensive steps from Horizon3.ai experts.
#NahamCon2025 Day 1 Keynote: Hacking, Prompt Engineering, and the Future of Pentesting with AI
https://www.youtube.com/watch?v=jT4RVAASPIs
https://www.youtube.com/watch?v=jT4RVAASPIs
YouTube
#NahamCon2025 Day 1 Keynote: Hacking, Prompt Engineering, and the Future of Pentesting with AI
LIKE and SUBSCRIBE with NOTIFICATIONS ON if you enjoyed the video! 👍
📚 If you want to learn bug bounty hunting from me: https://bugbounty.nahamsec.training
💻 If you want to practice some of my free labs and challenges: https://app.hackinghub.io
💵 FREE…
📚 If you want to learn bug bounty hunting from me: https://bugbounty.nahamsec.training
💻 If you want to practice some of my free labs and challenges: https://app.hackinghub.io
💵 FREE…
❤1