AutoJack: How a single page can RCE the host running your AI agent
https://www.microsoft.com/en-us/security/blog/2026/06/18/autojack-single-page-rce-host-running-ai-agent/
https://www.microsoft.com/en-us/security/blog/2026/06/18/autojack-single-page-rce-host-running-ai-agent/
Microsoft News
AutoJack: How a single page can RCE the host running your AI agent
AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter handling, attackers…
❤6
We have Mythos at Home: GLM 5.2 beats Claude in our Cyber Benchmarks
https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks
https://semgrep.dev/blog/2026/we-have-mythos-at-home-glm-52-beats-claude-in-our-cyber-benchmarks
Semgrep
We have Mythos at Home: GLM 5.2 beats Claude in our Cyber Benchmarks
Among models given nothing but a prompt, the best open-weight option beat Claude Opus 4.8.
❤5
Exploiting vulnerabilities in Johnson & Johnson web apps
https://eaton-works.com/2026/06/24/jnj-webapp-hacks/
https://eaton-works.com/2026/06/24/jnj-webapp-hacks/
Eaton-Works
Exploiting vulnerabilities in Johnson & Johnson web apps
Campus Recruiting vulnerability exposed student information, and Audit Tracking Management System vulnerability exposed confidential internal audit data.
❤9👍1
Claude Code: unsandboxed code execution from prompt injection via
https://github.com/Metnew/write-ups/tree/main/claude-code-worktree-sandbox-escape
.git worktree confusionhttps://github.com/Metnew/write-ups/tree/main/claude-code-worktree-sandbox-escape
GitHub
write-ups/claude-code-worktree-sandbox-escape at main · Metnew/write-ups
Contribute to Metnew/write-ups development by creating an account on GitHub.
❤8
The Biometric AuthToken Heist: Cracking PINs and Bypassing CE via a Long-Ignored Attack Surface
https://www.darknavy.org/blog/the_biometric_authtoken_heist/
https://www.darknavy.org/blog/the_biometric_authtoken_heist/
DARKNAVY Blog
The Biometric AuthToken Heist: Cracking PINs and Bypassing CE via a Long-Ignored Attack Surface
Modern Android devices make biometric authentication feel routine: a touch, a glance, and the device accepts that the user is present. Underneath that convenience is a security boundary that is easy to underestimate. Fingerprint and face authentication are…
❤6
No need to be a Mythos to do offensive security
https://fuzzinglabs.com/wp-content/uploads/2026/06/Le-Hack-2026-Keynote-_-No-Need-to-be-a-Mythos-to-do-Offensive-security-Patrick-Ventuzelo-_-FuzzingLabs.pdf
https://fuzzinglabs.com/wp-content/uploads/2026/06/Le-Hack-2026-Keynote-_-No-Need-to-be-a-Mythos-to-do-Offensive-security-Patrick-Ventuzelo-_-FuzzingLabs.pdf
❤7🔥6
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
watchTowr Labs
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out.
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into…
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into…
Find Comment, Get Shell: Command Injection in dbt’s GitHub Actions
https://www.landh.tech/blog/20260701-find-comment-get-shell/
https://www.landh.tech/blog/20260701-find-comment-get-shell/
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/
https://www.papermtn.co.uk/detecting-agentic-threats-in-claude-writing-rules-on-the-execution-layer/
PaperMtn
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
Detections for Claude on the execution layer: Sigma rules and a correlation runner that catch permission bypasses, rogue MCP servers, and more.
The Bug Bounty Singularity: Our Hackbot
https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html
https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html
❤4🤔2👍1
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
devploit / blog
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
What happens if an app without READ_CONTACTS asks Google Messages for Android to load a Contacts photo for it?
❤7
How I Chained an Open Redirect into Email Leak and Got $1,337 from Google
https://xlsize0bruh.medium.com/how-i-chained-an-open-redirect-into-email-leak-and-got-1-337-from-google-c8a4655677a2
https://xlsize0bruh.medium.com/how-i-chained-an-open-redirect-into-email-leak-and-got-1-337-from-google-c8a4655677a2
Medium
How I Chained an Open Redirect into Email Leak and Got $1,337 from Google
Who Am I?
👍11❤8
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
weirdmachine64.github.io
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64
RFC 8628's device authorization grant lets a TV or CLI
❤4
How to use Claude Code for Bug Bounty: find fast, validate manually
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
YesWeHack
How to use Claude Code for Bug Bounty: find fast, validate manually
We put Claude Code through two blind Bug Bounty labs – DOM XSS and HTTP request smuggling – to see if it can find and prove real vulnerabilities.
👍9❤4👎2👏2
WP2SHELL: PRE AUTHENTICATION RCE IN WORDPRESS CORE
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
Searchlight Cyber
wp2shell: Pre Authentication RCE in WordPress Core › Searchlight Cyber
Critical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiring…
❤7👍2
Language Model Security Database
A comprehensive collection of LLM vulnerabilities, curated from cutting-edge research papers and real-world discoveries.
https://www.promptfoo.dev/lm-security-db
A comprehensive collection of LLM vulnerabilities, curated from cutting-edge research papers and real-world discoveries.
https://www.promptfoo.dev/lm-security-db
www.promptfoo.dev
LM Security Database
A comprehensive database of researched vulnerabilities for Large Language Models
❤6👍4
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
Searchlight Cyber
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 › Searchlight Cyber
Stay current: Get research alerts for newly disclosed vulnerabilities and exposures If you're running WordPress and want to check if your instance is vulnerable, you can use our tool we've hosted here: https://wp2shell.com/. We held off on publishing this…
❤5👍4🔥4