BleepingComputer
51m ago
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
The Record
Today, 06:43 PM
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.
Schneier on Security
Today, 06:28 PM
I received the two emails below earlier in the month. Theyre vaguely coherent. I suppose I shouldnt be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in...
ai-securityexploitresearch
Read →
The Hacker News
Today, 06:27 PM
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments,...
The Record
Today, 05:15 PM
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
The Hacker News
Today, 04:41 PM
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily...
BleepingComputer
Today, 03:47 PM
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
The Record
Today, 03:07 PM
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
The Hacker News
Today, 02:06 PM
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the...
BleepingComputer
Today, 02:02 PM
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
The Hacker News
Today, 01:44 PM
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and...
The Hacker News
Today, 01:12 PM
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor...
The Record
Today, 01:00 PM
Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information.
BleepingComputer
Today, 12:30 PM
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]
The Hacker News
Today, 12:22 PM
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's...
The Record
Today, 12:15 PM
U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators.
The Hacker News
Today, 11:30 AM
The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the...
The Hacker News
Today, 10:53 AM
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below -...
BleepingComputer
Today, 10:29 AM
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]
Schneier on Security
Today, 10:22 AM
Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see...
Unit 42
Today, 10:00 AM
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
The Hacker News
Today, 09:18 AM
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the...
The Hacker News
Today, 09:10 AM
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was...
BleepingComputer
Today, 09:06 AM
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
BleepingComputer
Today, 08:00 AM
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
The Hacker News
Today, 07:47 AM
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a...
The Hacker News
Today, 07:08 AM
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma...
The Hacker News
Today, 06:56 AM
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in...
BleepingComputer
Today, 06:39 AM
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
Microsoft Security Blog
Today, 10:48 PM
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help...
ai-securityaptbug-bountycloudexploitiotmalwareransomwareresearch
Read →
KrebsOnSecurity
Today, 10:40 PM
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning...
exploitphishingransomwareresearch
Read →
SANS ISC
Today, 09:30 PM
Introduction
BleepingComputer
Today, 08:53 PM
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
BleepingComputer
Yesterday, 07:28 PM
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
Microsoft Security Blog
Yesterday, 06:55 PM
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.
cloudexploitiotmobileresearch
Read →
BleepingComputer
Yesterday, 05:54 PM
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
The Hacker News
Yesterday, 05:53 PM
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in...
Schneier on Security
Yesterday, 05:36 PM
To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving a lot of individual...
The Hacker News
Yesterday, 05:19 PM
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating...
Schneier on Security
Yesterday, 04:29 PM
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. [] The reporting also linked...
aptexploitmalwareresearch
Read →
HackerOne Blog
Yesterday, 02:53 PM
HackerOne ran Anthropic's Mythos 5 model against its own production code. Here's what a critical RCE finding revealed about AI-accelerated security.
hackerone-newshai-triageexposure-managementh1-responsepublic-policyctemh1-platformaibug-bountyexploit
Read →
BleepingComputer
Yesterday, 02:45 PM
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
BleepingComputer
Yesterday, 02:28 PM
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
The Hacker News
Yesterday, 02:07 PM
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The...
malwaremobileresearchzero-day
Read →
BleepingComputer
Yesterday, 02:01 PM
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement...
The Hacker News
Yesterday, 01:08 PM
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs)...
BleepingComputer
Yesterday, 12:38 PM
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
exploitresearchzero-day
Read →
The Hacker News
Yesterday, 11:30 AM
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix,...
Schneier on Security
Yesterday, 09:59 AM
Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I havent been posting the full text on the blog because theyre a bit long, but here are links. Part 1 is about the Japanese digital democracy party, Team Mirai. Part 2 is...
The Hacker News
Yesterday, 09:05 AM
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external...
The Hacker News
Yesterday, 08:26 AM
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts...
ai-securitymalwareresearch
Read →
The Hacker News
Yesterday, 07:22 AM
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be...
Intigriti Blog
Yesterday, 12:00 AM
At Intigriti, we have been exploring a simple but important shift in security: the work that happens before a vulnerability report is often where the real signal begins. As vulnerability discovery accelerates, organizations need practical ways to identify and reduce risk before vulnerabilities are...
bug-bountyexploitnewsresearch
Read →
SANS ISC
31 Aug, 2026
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &x26xe2&x26x80&x26x94 history, filesystem output, working paths,...
Schneier on Security
31 Aug, 2026
It sure seems like it. The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation....
The Hacker News
31 Aug, 2026
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical...
The Hacker News
31 Aug, 2026
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional....
The Hacker News
31 Aug, 2026
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky...
The Hacker News
31 Aug, 2026
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed...
cloudmalwareransomwareresearch
Read →
The Hacker News
31 Aug, 2026
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone...
Schneier on Security
31 Aug, 2026
Someone hid AI instructions into a legal filing. Alternate link.
Unit 42
31 Aug, 2026
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.
The Hacker News
31 Aug, 2026
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value...
The Hacker News
31 Aug, 2026
The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and...
The Hacker News
30 Aug, 2026
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique...
SANS ISC
30 Aug, 2026
YARA-X&x2639s 1.20.0 release brings 14 improvements and 13 bugfixes.
The Hacker News
29 Aug, 2026
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and...
Microsoft Security Blog
29 Aug, 2026
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft...
ai-securitycloudexploitiotmalwarephishingransomwareresearch
Read →
Unit 42
28 Aug, 2026
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
The Hacker News
28 Aug, 2026
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in...
Schneier on Security
28 Aug, 2026
Ugh: A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the Squidpocalypse of 26. That would be twenty tons of squid. As usual, you can also use this squid...
The Hacker News
28 Aug, 2026
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE...
The Hacker News
28 Aug, 2026
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's...
The Hacker News
28 Aug, 2026
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks...
The Hacker News
28 Aug, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body...
The Hacker News
28 Aug, 2026
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share...
The Hacker News
28 Aug, 2026
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the...
The Hacker News
28 Aug, 2026
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on...
The Hacker News
28 Aug, 2026
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and...
Schneier on Security
28 Aug, 2026
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAIs offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was...
The Hacker News
28 Aug, 2026
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and...
The Hacker News
28 Aug, 2026
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel &...
The Hacker News
28 Aug, 2026
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of...
The Hacker News
28 Aug, 2026
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously...
SANS ISC
28 Aug, 2026
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware1. Can we go a bit further I (vibe-)coded a Python script based on the...
Intigriti Blog
28 Aug, 2026
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in...
bug-bountybug-bytesresearch
Read →
The Hacker News
27 Aug, 2026
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations...
Talos Intelligence
27 Aug, 2026
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
ai-securitybug-bountycloudexploitiotmalwaremobilephishingransomwareresearch
Read →
Microsoft Security Blog
27 Aug, 2026
This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post What’s new in Microsoft Security: August 2026 appeared first on...
ai-securitycloudexploitransomwareresearch
Read →
The Hacker News
27 Aug, 2026
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting...
The Hacker News
27 Aug, 2026
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing...
exploitiotmalwarephishing
Read →
The Hacker News
27 Aug, 2026
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE...
ai-securityexploitresearch
Read →
The Hacker News
27 Aug, 2026
Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security...
The Hacker News
27 Aug, 2026
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis...
ai-securityexploitiotsupply-chain
Read →
The Hacker News
27 Aug, 2026
AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to...
KrebsOnSecurity
27 Aug, 2026
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two...
ai-securityaptbug-bountycloudexploitiotmalwaremobilephishingransomwareresearchsupply-chain
Read →
Talos Intelligence
27 Aug, 2026
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
cloudexploitiotmalwarephishingresearchsupply-chain
Read →
SANS ISC
27 Aug, 2026
As Ive mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
Schneier on Security
27 Aug, 2026
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing...
Bugcrowd Blog
27 Aug, 2026
By Braden Russell, Aug 27, 2026
Microsoft Security Blog
26 Aug, 2026
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft...
Talos Intelligence
26 Aug, 2026
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
ai-securityexploitiotmobileresearch
Read →
Microsoft Security Blog
25 Aug, 2026
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
cloudexploitiotransomwareresearchzero-day
Read →
PortSwigger Research
25 Aug, 2026
I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t
Unit 42
25 Aug, 2026
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.
Talos Intelligence
25 Aug, 2026
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.
ai-securitycloudexploitiotmalwaremobileresearch
Read →
Google Bug Hunters
24 Aug, 2026
This blog post describes how we used AI to help us rewrite a C library (giflib) to Rust to mitigate memory safety vulnerabilities.
Intigriti Blog
24 Aug, 2026
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting...
bug-bountybusiness-insightsresearch
Read →
Intigriti Blog
24 Aug, 2026
Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting...
bug-bountyhacker-spotlightresearch
Read →
Unit 42
21 Aug, 2026
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.
Talos Intelligence
20 Aug, 2026
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.
ai-securitycloudexploitmalwarephishing
Read →
Talos Intelligence
20 Aug, 2026
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.
Talos Intelligence
20 Aug, 2026
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
Unit 42
20 Aug, 2026
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
Bugcrowd Blog
20 Aug, 2026
By David Brumley I Chief AI and Science Officer, Aug 20, 2026
Intigriti Blog
20 Aug, 2026
Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently...
Microsoft Security Blog
19 Aug, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on...
ai-securitycloudexploitmalwareresearch
Read →
Talos Intelligence
19 Aug, 2026
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
ai-securityexploitiotresearch
Read →
Unit 42
18 Aug, 2026
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first...
Microsoft Security Blog
18 Aug, 2026
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.
ai-securitycloudexploitiotmalwarephishingransomwareresearch
Read →
KrebsOnSecurity
14 Aug, 2026
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of...
ai-securitycloudexploitiotmalwaremobilephishingransomwareresearchsupply-chain
Read →
Talos Intelligence
13 Aug, 2026
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
cloudexploitiotmalwarephishingransomwareresearch
Read →
Talos Intelligence
13 Aug, 2026
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
exploitiotphishingransomwareresearch
Read →
Bugcrowd Blog
13 Aug, 2026
By David Brumley I Chief AI and Science Officer, Aug 13, 2026
PortSwigger Blog
12 Aug, 2026
We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f
Talos Intelligence
11 Aug, 2026
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
KrebsOnSecurity
11 Aug, 2026
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Unit 42
11 Aug, 2026
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.
Unit 42
10 Aug, 2026
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.
Microsoft Security Blog
10 Aug, 2026
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft...
cloudexploitiotmalwarephishingransomwareresearch
Read →
Microsoft Security Blog
10 Aug, 2026
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. The...
ai-securitycloudexploitiotmalwaremobilephishingransomwareresearch
Read →
Google Bug Hunters
10 Aug, 2026
This post analyzes results published by Anthropic and argues that these recent advances do not signal the downfall of cryptography.
Intigriti Blog
10 Aug, 2026
At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and our Senior Product Manager, Radu Voloaga, took to the stage in the Bug Bounty Village to give everyone the first real look at CrowdRecon. How CrowdRecon closes the gap It started...
Unit 42
7 Aug, 2026
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.
Unit 42
6 Aug, 2026
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
PortSwigger Research
6 Aug, 2026
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
Talos Intelligence
6 Aug, 2026
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
ai-securitybug-bountyexploitiotmalwaremobilephishingransomwareresearchsupply-chainzero-day
Read →
KrebsOnSecurity
6 Aug, 2026
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener,...
cloudexploitiotmobilephishingransomwareresearch
Read →
Unit 42
6 Aug, 2026
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.
Bugcrowd Blog
6 Aug, 2026
By David Brumley I Chief AI and Science Officer, Aug 06, 2026
Intigriti Blog
6 Aug, 2026
CVSS open framework, rapid recap Stands for Common Vulnerability Scoring System. Owned by a US-based non-profit organization, the Forum of Incident Response and Security Teams (FIRST). The purpose is to help response teams quickly and easily calculate the severity of cybersecurity vulnerabilities...
ai-securitybusiness-insightsexploitiot
Read →
PortSwigger Research
5 Aug, 2026
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
PortSwigger Research
5 Aug, 2026
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
Bugcrowd Blog
5 Aug, 2026
By Erica Azad, Aug 05, 2026
PortSwigger Blog
4 Aug, 2026
"It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray Huygen is a Security Analyst at Orange Cyberdefense, a managed security service provider with
Unit 42
4 Aug, 2026
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit...
exploitresearchsupply-chainzero-day
Read →
Unit 42
4 Aug, 2026
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.
Talos Intelligence
4 Aug, 2026
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.
ai-securityaptbug-bountycloudexploitiotmalwaremobilephishingransomwareresearchweb-securityzero-day
Read →
Intigriti Blog
4 Aug, 2026
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how...
Talos Intelligence
3 Aug, 2026
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
malwarephishingransomware
Read →
Unit 42
3 Aug, 2026
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.
Bugcrowd Blog
3 Aug, 2026
By Erica Azad, Aug 03, 2026
Intigriti Blog
31 Jul, 2026
Hello hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub...
bug-bountybug-bytesexploitransomware
Read →
Talos Intelligence
30 Jul, 2026
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
cloudexploitiotmalwarephishingransomwareresearch
Read →
KrebsOnSecurity
30 Jul, 2026
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also...
cloudexploitiotmalwaremobileransomwareresearch
Read →
PortSwigger Blog
30 Jul, 2026
This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is o
Bugcrowd Blog
30 Jul, 2026
By Julian Brownlow Davies, Jul 30, 2026
Intigriti Blog
30 Jul, 2026
Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are...
bug-bountyhacking-toolsresearch
Read →
Bugcrowd Blog
29 Jul, 2026
By Erica Azad, Jul 29, 2026
Bugcrowd Blog
28 Jul, 2026
By Joe Castellanos | Head of Product and Design, Jul 28, 2026
Intigriti Blog
28 Jul, 2026
Key takeaways RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does. In simple QA systems, that may mean misinformation or unsafe...
PortSwigger Blog
27 Jul, 2026
Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries
Intigriti Blog
23 Jul, 2026
The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant,...
KrebsOnSecurity
22 Jul, 2026
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available...
exploitiotransomwareresearch
Read →
Intigriti Blog
20 Jul, 2026
What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What...
business-insightsexploitresearch
Read →
PortSwigger Blog
17 Jul, 2026
Growing our Burp Ambassador community Meet our newest Burp Ambassadors Katie Paxton-Fear Malek Mohammad Yogesh Tantak James Lester Looking ahead Interested in getting involved? Growing our Burp Ambass
KrebsOnSecurity
14 Jul, 2026
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning...
KrebsOnSecurity
13 Jul, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity....
cloudexploitransomwareresearch
Read →
PortSwigger Blog
9 Jul, 2026
First hand of the week: Find us at BSides Workshop: Burp But Yours, with Hannah and Tib3rius Center stage: Visit us at Black Hat USA - Booth 5342 Lightning talks at the booth Catch our researchers' br
KrebsOnSecurity
8 Jul, 2026
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform...
cloudexploitiotresearchzero-day
Read →
Bug Bounty Daily
7 Jul, 2026
Intigriti Blog
29 Jun, 2026
Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!), and the human layer triage (The AI Impact), judgment, and prioritization has become more important, not less (CEO Insights). But...
business-insightsresearch
Read →
Intigriti Blog
27 Jun, 2026
Cookies are one of the most fundamental building blocks of the modern web, and yet they are often overlooked from a security perspective. When misconfigured, they can potentially lead to exposure of sensitive session data, enable several client-side attacks, and in severe cases, even allow...
Intigriti Blog
26 Jun, 2026
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo...
bug-bountybug-bytescloudexploitresearch
Read →
Intigriti Blog
24 Jun, 2026
Web (or HTTP) caching is a highly adopted practice to effectively optimize web page loading times for clients. However, as with most technologies, when incorrectly implemented, it may open up a new exploitable attack surface for us to look into. In this article, we'll cover what web cache poisoning...
PortSwigger Blog
19 Jun, 2026
The 2026 Burp Suite Extension Awards Best Recon & Discovery Best Auth & Access Control Best Workflow & Manipulation Best API & Specialist Testing Hidden Gem Most Nominated The talks In
Intigriti Blog
17 Jun, 2026
Cristian Zot, known by most in the industry as CristiVlad25, is an active security researcher, experienced pentester, and an Intigriti Hacker Ambassador. He is a prominent figure in the ethical hacking community and frequently collaborates with Intigriti through platform meetups, podcast...
bug-bountybusiness-insightsresearch
Read →
Intigriti Blog
17 Jun, 2026
Cristian Zot, known by most in the industry as CristiVlad25, is an active security researcher, experienced pentester, and an Intigriti Hacker Ambassador. He is a prominent figure in the ethical hacking community and frequently collaborates with Intigriti through platform meetups, podcast...
bug-bountyhacker-spotlightresearch
Read →
Bug Bounty Daily
16 Jun, 2026
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling FIFA, MediaKind, HBS, CISA, and the FBI...
Bug Bounty Daily
12 Jun, 2026
My blog, mostly about programming
Bug Bounty Daily
11 Jun, 2026
What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found.
Intigriti Blog
11 Jun, 2026
The intersection of AI and cybersecurity is reshaping how we find, fix, and think about vulnerabilities. Yet for all the headlines, few conversations cut through the noise to ask what AI means for those on the ground: the hunters, the security engineers, and the organizations trying to secure their...
Bug Bounty Daily
5 Jun, 2026
Because we can!
Google Bug Hunters
5 Jun, 2026
Gemini Spark brings a persistent agent to the Gemini App. Learn how to approach security testing for this new paradigm and focus on high-impact bugs.
Bug Bounty Daily
4 Jun, 2026
Google Bug Hunters
4 Jun, 2026
This blog post takes us back to 2010, retracing and incident where a statistical anomaly led to the discovery of a subtle flaw in the way we were using a security-critical library.
Bug Bounty Daily
2 Jun, 2026
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malicious content.
Bug Bounty Daily
2 Jun, 2026
How a flagged Meta IP running an open Grafana turned into a five-hop chain ending at 507 private repositories. The full story, no code accessed.
Bug Bounty Daily
1 Jun, 2026
How HTTP/2’s multi-frame architecture allows attackers to bypass WAFs by exploiting timing delays, protocol translation flaws, and incomplete body inspection across various reverse proxies
Bug Bounty Daily
1 Jun, 2026
Introduction Hello, I’m RyotaK ( @ryotkak ), a security researcher at GMO Flatt Security Inc. After publishing my previous article ( Pwning Claude Code in 8 Different Ways ), I continued investigating Claude-related products and found several more vulnerabilities. In this article, I will explain a...
exploitransomwareresearchsupply-chain
Read →
Google Bug Hunters
1 Jun, 2026
This blog post explores how Google thinks about the development and deployment of quantum-safe digital signatures.
Google Bug Hunters
27 May, 2026
Passkeys can be combined with hardware security keys to implement advanced security features when a particularly robust security strategy is required.
Bug Bounty Daily
25 May, 2026
In March, our system detected a severe vulnerability in V8, the JavaScript engine used by Chrome. This vulnerability enabled remote code execution against billions of Chrome users worldwide.
Bug Bounty Daily
25 May, 2026
Some weeks ago, I was testing a mature and heavily audited application from a bug bounty program. Since I had previously found several interesting client-side vulnerabilities in that target, I decided to focus on the frontend again. What first looked like a safely sanitized name field eventually...
Bug Bounty Daily
22 May, 2026
Two minimal Node.js scripts demonstrating a SOCKS5 hostname null-byte injection that defeats Claude Code's wildcard network allowlist on vulnerable releases.
Bug Bounty Daily
22 May, 2026
A chance Discord message, two missing pieces, and one hour before the window closed: From info leak to RCE on Google Cloud. Three months later, it happened again.
Bug Bounty Daily
22 May, 2026
Some organisations’ most sensitive information is only ever discussed in person. Ironically, the equipment in meeting rooms, conference halls, and other physical locations is often among the least-monitored and most insecurely-configured attack surfaces in an organisation.
Bug Bounty Daily
22 May, 2026
The Sanitizer API arrived with much fanfare in both Chrome 146 and Firefox 148 just a few months ago. The API provides two new ways to set HTML safely from within javascript; the default mode: node.setHTML(`Hello, world!`) And the more customizable mode: const config = { "elements": ["p", "span",...
Bug Bounty Daily
21 May, 2026
Inside SA-Core2026-004 On the 20th of May, the Drupal Security Team released SA-CORE-2026-004 (CVE-2026-9082), a Highly critical (20/25) SQL injection in Drupal core. The issue is reachable by fully anonymous users on any deployment that backs Drupal with PostgreSQL. It was reported upstream by...
Immunefi Blog
21 May, 2026
An Immunefi field guide to running an effective war room during an active onchain exploit, from preparation and role assignment to postmortem discipline.
bug-bountyexploitiotresearch
Read →
Bug Bounty Daily
21 May, 2026
Data exfiltration in Gemini via Android's volume settings, using a classification system.
Bug Bounty Daily
21 May, 2026
Achieving consistent exploitation of prompt injections using client-side gadgets.
Bug Bounty Daily
19 May, 2026
Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned (this page) Note: The vulnerab…
Bug Bounty Daily
19 May, 2026
Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell image (this page)Bug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…
Bug Bounty Daily
19 May, 2026
Quick navigation IntroductionBug #1 – The Python language server (this page)Bug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…
Bug Bounty Daily
19 May, 2026
Quick navigation Introduction Bug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git clone (this page)Bug #4 – Go and get pwned Note: The vulnera…
Bug Bounty Daily
19 May, 2026
Discover how attackers exploit HTTP redirect discrepancies to extract sensitive data embedded in URLs, and what you can do to prevent secret leakage in your web infrastructure.
Bug Bounty Daily
19 May, 2026
Stealth Request That Bypasses CSP, Hides from DevTools, and Leaks the Real User-Agent
PortSwigger Blog
12 May, 2026
Now that the dust has settled on Mythos dropping, there is space for more considered reflection on the direction of travel. Mythos wasn't a surprise; it's another data point on a trajectory that's bee
Bug Bounty Daily
12 May, 2026
Of course I took a peek at the Claude Code source 🙈. What I found was a very entertaining vulnerability which is now fixed since Claude Code version 2.1.118. Just wading through the massive codebase manually wasn’t really a feasible approach. So took an army of AI Agents to…. no wait actually I...
Google Bug Hunters
11 May, 2026
In this blog post, we'll take a look at what makes bugSWAT events valuable in general, and focus on the latest edition in Seoul, which took place in April 2026.
Bug Bounty Daily
6 May, 2026
How opening Chrome DevTools on a cross-site POST response can bypass SameSite=Strict cookie protections when a service worker is present.
Bug Bounty Daily
6 May, 2026
I’m here to share my Self-XSS escalation write-up, one that took me multiple failed attempts before I finally cracked it with some much needed help.
Bug Bounty Daily
6 May, 2026
Have you noticed that almost every marketing email you receive looks somewhat similar, or has functionality that seems centralised? This is because most corporations have moved to some form of marketing cloud to facilitate sending mass email campaigns. This shift appears to have happened in the...
Bug Bounty Daily
6 May, 2026
A high-severity CVE-2026-0628 in Chrome's Gemini allowed local file access and privacy invasion. Google quickly patched the flaw.
PortSwigger Blog
1 May, 2026
Senior pentesters have a deeply refined intuition about what is vulnerable in an environment. The problem? That expertise is often siloed with an individual and trapped in their notes or Python scripts.
Google Bug Hunters
30 Apr, 2026
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of reports and bug categories that provide the most value to security today.
Bug Bounty Daily
28 Apr, 2026
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
PortSwigger Blog
28 Apr, 2026
We’re proud to announce that PortSwigger recently won the Overall Judges’ Award at the Northern Tech Awards 2026. The Northern Tech Awards are run by GP Bullhound, the tech advisory and investment fir
Immunefi Blog
27 Apr, 2026
Immunefi maps six years of DeFi protocol losses across major ecosystems. Total losses fell 80% from 2022, but new multi-chain and custodial risks are emerging.
ai-securityaptbug-bountycloudexploitmalwaremobilephishingransomwareresearch
Read →
Immunefi Blog
23 Apr, 2026
Immunefi, the leading onchain security platform, and Base, one of the largest Ethereum Layer 2 networks, launched an audit competition on April 21 for the Base Azul network upgrade with a reward pool of up to $250,000. The competition is live now and runs through May 4, 2026.Base
Immunefi Blog
20 Apr, 2026
Five years of Immunefi data shows that 93.9% of bug bounty programs running 5+ years have surfaced a confirmed critical vulnerability. Bugs are inevitable.
ai-securitybug-bountycloudexploitiotransomwareresearch
Read →
PortSwigger Blog
16 Apr, 2026
Why we’re launching the program What it means to be a Burp Ambassador What we’re aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3rius Looking ahead Get Involved - B
Google Bug Hunters
8 Apr, 2026
We are evolving our reward model to reflect the changing security landscape by introducing two new dimensions to our model: Information Tiers and Action Criticality.
PortSwigger Blog
7 Apr, 2026
More power for bug hunters An education-first approach to bug bounty Rewards on Meta's Bug Bounty Platform Our shared vision Ready to get started? We’re excited to announce a new partnership with Meta
Bug Bounty Daily
31 Mar, 2026
How I found my first vulnerability in Google - a way to leak private customer data for all cases in Google's internal support systems
Google Bug Hunters
30 Mar, 2026
Find out more about how passkeys, which are designed to replace passwords, work and which advantages they bring.
Immunefi Blog
25 Mar, 2026
An Immunefi research report on what a crypto exploit actually does to a protocol, beyond the stolen funds, based on five years of onchain incident data.SummaryBack in 2024, Immunefi published the industry's first comprehensive look at what onchain hacks actually cost a project, covering the...
bug-bountyexploitransomwareresearch
Read →
Bug Bounty Daily
23 Mar, 2026
The post describes how the author discovered a one-click account takeover vulnerability in a large automotive company’s OAuth implementation, despite apparently robust redirect_uri validation. By exploiting a subtle double-decoding inconsistency in URL parsing, they were able to redirect the...
Bug Bounty Daily
23 Mar, 2026
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During this event, I discovered a remote command execution vulnerability in one of Google Cloud’s...
Google Bug Hunters
19 Mar, 2026
Read about our updates to the OSS VRP rules which are designed to help us filter out low-quality reports and focus on real-world impact.
Bug Bounty Daily
18 Mar, 2026
Ignoring the obvious name, this blogpost is not tips that will help you “exploit” a bug or give you tips on how to find awesome bugs, it is obvious that you need technical knowledge.
Bug Bounty Daily
13 Mar, 2026
How WHATWG URL compliance in Bun creates a normalization desync with POSIX utilities, enabling double-slash and partial-path middleware bypasses.
PortSwigger Blog
13 Mar, 2026
Note: This is a guest post by pentester Julen Garrido Estévez (@b3xal). 1. Acknowledgements 2. Intro 3. Required tools 4. Strategy to solve/exploit the lab 5. Detecting 0.CL 5.1. Practical confirmatio
Bug Bounty Daily
12 Mar, 2026
While auditing a multi-tenant application, I came across an interesting chain leading to a full tenant takeover. It started innocuously - with a self-XSS in a rich-text editor. Exploitation would require the user to insert a dangerous element into the editor via its API themselves, which meant a...
Bug Bounty Daily
12 Mar, 2026
A popular enterprise chatbot left an old, unauthenticated WebSocket endpoint active that still accepted full bidirectional messages using only a conversation UUID as “protection.” Anyone who obtained a conversation ID could connect, impersonate the user, read their chats, and exfiltrate sensitive...
PortSwigger Blog
12 Mar, 2026
Watch the webinar recording: Burp Suite DAST x Burp Suite Professional: Better Together I'm a firm believer that if you want to understand how secure an application really is, you have to test how it
Immunefi Blog
11 Mar, 2026
We're excited to announce a new strategic partnership with Anchorage Digital, home to America's first federally chartered crypto bank, to deliver enhanced security and risk management solutions to institutional DeFi participants.Alongside this partnership, Anchorage Digital Ventures has...
bug-bountyexploitresearch
Read →
PortSwigger Blog
11 Mar, 2026
At PortSwigger, we’re always looking for ways to enable the world to secure the web, and today we’re excited to take that mission a step further. We’re pleased to announce a new collaboration bringing
Google Bug Hunters
11 Mar, 2026
This blog post takes you through the 2025 highlights across the assorted VRPs at Google.
Bug Bounty Daily
10 Mar, 2026
A deep dive into chaining DOM XSS, drag-and-drop abuse, postMessage hijacking, and cookie bombs to steal OAuth tokens — all from one drag and one click.
Google Bug Hunters
9 Mar, 2026
This post takes a look at how Gemini and other agents created by Google mitigate URL-based data exfiltration attacks.
Bug Bounty Daily
4 Mar, 2026
Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning - Security research by adnanthekhan
Bug Bounty Daily
4 Mar, 2026
How three overlooked flaws in a postMessage + MessageChannel login architecture combine into a zero-click, cross-origin account takeover affecting hundreds of millions of users — and why PKCE couldn't save it.
Google Bug Hunters
4 Mar, 2026
Find out how the FIDO alliances's Hybrid transport architecture was expanded to support authentication in the offline world, increasing reliability and unlocking many new use cases.
Bug Bounty Daily
2 Mar, 2026
Cloudflare built a Next.js replacement in a week with AI for $1100. We pointed Hacktron at it to find what the tests missed.
Bug Bounty Daily
2 Mar, 2026
Achieving path traversal and even RCE via developer oversights in using os.path.join, urljoin, Python object handling and more functions besides.
Bug Bounty Daily
2 Mar, 2026
A technical teardown of a 1-click RCE against OpenClaw (formerly Moltbot/ClawdBot), a viral open-source AI assistant trusted by 100,000+ developers with high-privilege access. See how a settings logic flaw and a WebSocket pivot turn a single webpage visit into token exfiltration, safety-control...
Bug Bounty Daily
2 Mar, 2026
By Aviv Donenfeld and Oded Vanunu Executive Summary Check Point Research has discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution and steal API credentials through malicious project configurations. The vulnerabilities exploit various...
Bug Bounty Daily
2 Mar, 2026
SvelteSpill is a cache deception vulnerability affecting default SvelteKit apps deployed on Vercel. Authenticated responses can be cached and exposed across users. Learn how to check if you’re vulnerable and how to mitigate risk.
Bug Bounty Daily
2 Mar, 2026
This post walks through a real-world OAuth popup hijacking attack. The target had solid defenses origin validation, source checking, CSP but a single predictable window.open() target name created an exploitable gap. It also serves as a real-world case use of iframe hijacking, showing how I managed...
Bug Bounty Daily
2 Mar, 2026
RCEs, RCEs…they are all around and Total.js framework will be in our scope this time
Bug Bounty Daily
2 Mar, 2026
Pivoting from a compromised Windows VM to the cloud by intercepting Azure DevOps Agent traffic
Google Bug Hunters
23 Feb, 2026
This post highlights how Hybrid transport is being extended to support generic JSON messages – paving the way for a host of new, secure authentication and credential use cases.
Immunefi Blog
20 Feb, 2026
An Immunefi research report on where post-launch critical vulnerabilities in the onchain economy actually get disclosed, and what the data says about industry-wide security.Key findingsRoughly 92.33% of post-launch critical vulnerabilities in crypto are disclosed through Immunefi, a concentration...
bug-bountycloudexploitransomwareresearch
Read →
Bug Bounty Daily
14 Feb, 2026
Novel data exfiltration in Google Gemini via the Phone tool call.
Google Bug Hunters
10 Feb, 2026
This blog post details the results of the joint security review of the Intel Trust Domain Extensions (TDX) 1.5 Google performed together with Intel.
PortSwigger Research
5 Feb, 2026
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
Google Bug Hunters
3 Feb, 2026
Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.
Google Bug Hunters
27 Jan, 2026
Based on the FIDO specification, online authentication has undergone a significant transformation in the past years, moving beyond simple passwords to more secure, phishing-resistant methods.
PortSwigger Blog
22 Jan, 2026
Note: This is a guest post by IT security consultant Adarsh Kumar. I’ve been using Burp Suite day to day for years, so when Burp AI was introduced, I was curious how it would actually hold up dur
PortSwigger Blog
16 Jan, 2026
Note: This is a guest post by pentester Julen Garrido Estévez (@b3xal). Methodology Key results Examples Key learnings Prompt template A pentester's POV on Burp AI Pentester Julen Garrido Es
PortSwigger Research
6 Jan, 2026
Update: nominations are now closed, and voting is live! Cast your vote here Over the last year, security researchers have shared a huge amount of work with the community through blog posts, presentati
PortSwigger Blog
12 Dec, 2025
In 2025, we set out with a simple mission: take Burp Suite on the road and meet the global AppSec community where you are. Burp On Tour was born from our desire to learn from you; the brilliant people
PortSwigger Blog
11 Dec, 2025
AppSec teams are under constant pressure to secure fast-moving applications without slowing anything down. But scanning windows, fragile authentication, and sprawling API estates often get in the way
Google Bug Hunters
11 Dec, 2025
Check this post to find out what a Task Injection attack is, how this type of attack differs from Prompt Injection, and how it is particularly relevant to AI agents designed for a wide range of actions and tasks.
PortSwigger Research
10 Dec, 2025
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
PortSwigger Blog
5 Dec, 2025
Detecting React2Shell with Burp Suite Two new critical vulnerabilities, collectively known as React2Shell (CVE-2025-55182 and CVE-2025-66478), are rapidly gaining traction in the security community. D
PortSwigger Blog
1 Dec, 2025
Every December, TryHackMe’s Advent of Cyber brings the security community together around a simple idea: learn something new by getting hands-on. Each day during the festive season reveals a beginner-
Google Bug Hunters
1 Dec, 2025
In this post, we're sharing our assessment of the Quantum Key Distribution (QKD) technology and explaining why we believe PQC is the more mature and scalable solution for Google's needs.
Immunefi Blog
19 Nov, 2025
Code Review Agent introduces AI-powered automation to PR Reviews in Immunefi Magnus, allowing you to find and fix vulnerabilities as you code.
exploitransomwaresupply-chain
Read →
Immunefi Blog
18 Nov, 2025
Through this partnership, Shield3’s expertise in incident response readiness will be offered through the Immunefi Magnus platform.
Immunefi Blog
17 Nov, 2025
This partnership will advance a shared mission: building the unified security stack for the onchain economy.
PortSwigger Blog
14 Nov, 2025
AI isn’t just reshaping cybersecurity - it’s challenging testers to rethink their entire playbook. In his latest article, “Hacking with Burp AI in the Chesspocalypse”, API expert Corey Ball draws less
Google Bug Hunters
14 Nov, 2025
This blog post presents two initiatives that demonstrate two ways Google shares security work with the industry: Contributing to the Secure Web Application Guidelines Community Group in W3C, and introducing auto-CSP in Angular.
PortSwigger Research
11 Nov, 2025
HTTP Anomaly Rank If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length,
Immunefi Blog
7 Nov, 2025
In November 2025, Balancer was exploited for over $100 million through a precision-loss bug in composable stable pools.This isn't a coding blunder on Balancer's end, but a coordinated failure stemming from security controls that don't work together, a major problem for
bug-bountyexploitransomwareresearch
Read →
Google Bug Hunters
7 Nov, 2025
ESCAL8 is focused on collaboration, knowledge-sharing, and a commitment to a safer digital world. See our blog post for an overview of the four main segments of the 2025 edition of ESCAL8.
Immunefi Blog
27 Oct, 2025
Immunefi has successfully completed its SOC 2 Type II attestation, verifying our internal controls meet the highest standards for security, availability, and confidentiality.Conducted by Sensiba, this attestation evaluated both the design and the consistent operation of our systems over time. This...
PortSwigger Blog
22 Oct, 2025
In her latest video, CyberMaddy dives into the world of AI-driven ethical hacking, exploring how Burp AI performs in Repeater when tasked with finding web vulnerabilities like SQL injection, cross-sit
PortSwigger Blog
22 Oct, 2025
What happens when you set Burp AI loose on a deliberately vulnerable web app? In his latest video, Tib3rius takes Burp’s new agentic Burp AI capabilities for a spin - and the results are seriously coo
Immunefi Blog
13 Oct, 2025
Ripple and Immunefi are collaborating to launch a $200,000 Attackathon to secure the proposed XRPL Lending Protocol as part of the institutional DeFi roadmap. This program is a time-boxed, adversarial competition, where security researchers dive into the code to ensure the protocol has the...
ai-securityexploitresearch
Read →
PortSwigger Blog
9 Oct, 2025
At Black Hat USA 2025 and DEF CON 33, PortSwigger's Director of Research, James Kettle, unveiled new HTTP desync techniques that prove one thing beyond doubt: HTTP/1.1 is broken, and every organizatio
Immunefi Blog
9 Oct, 2025
Sigma Prime, a team recognized for its precision and extensive history in web3 security, has joined Immunefi's Magnus platform.
PortSwigger Blog
7 Oct, 2025
The latest Hacker-Powered Security Report from HackerOne makes one thing clear: AI-assisted pentesting isn't a future trend; it's today's reality. In HackerOne's 2025 report, 70% of surveyed researche
Google Bug Hunters
6 Oct, 2025
Looking back at two years of AI bug bounties at Google, and announcing our new AI Vulnerability Reward Program!
Immunefi Blog
1 Oct, 2025
VeChain has partnered with Immunefi to launch an Attackathon focused on one of the most significant blockchain upgrades of the year: the Hayabusa Upgrade.This Attackathon invites security researchers to explore, test, and strengthen VeChainThors live infrastructure during its transition to a more...
PortSwigger Blog
1 Oct, 2025
Bug bounty legend, NahamSec, has taken Burp AI for a spin. If you're curious how Burp AI fits into a real workflow, his new video is the perfect place to start. Watch on YouTube Burp AI was built to a
Google Bug Hunters
25 Sep, 2025
See how we're updating the Cloud VRP rewards structure to increase transparency, improve consistency, and reduce ambiguity.
PortSwigger Blog
24 Sep, 2025
Whether you’re navigating a client pentest or chasing a bounty target, even the most experienced testers hit roadblocks, burn time on repetitive tasks, or just want a second opinion. Burp AI is design
Google Bug Hunters
22 Sep, 2025
We're announcing an update to how we evaluate report quality across the Google, Cloud, AI, and Abuse Vulnerability Reward Programs (VRPs) to ensure more consistent reward outcomes, and make it straightforward to qualify for the exceptional reward bonus.
Google Bug Hunters
19 Sep, 2025
This blog shares a detailed overview of the L1TF vulnerability, a CPU vulnerability on some Intel CPUs (Skylake and older), and explains how it could be exploited and what mitigation strategies are possible.
PortSwigger Blog
18 Sep, 2025
Note: This is a guest post by pentester and researcher, Tom Stacey (@t0xodile). You'd think that after almost 21 years since its initial public discovery, HTTP Request Smuggling would be barely exploi
Google Bug Hunters
18 Sep, 2025
Rendering untrusted web content is fraught with security risks. Learn how SafeContentFrame, a new TypeScript library, offers a robust solution for isolating web content and protecting against threats like XSS and side-channel attacks.
PortSwigger Research
17 Sep, 2025
Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis. This is a huge blind spot, leaving many bugs like Broken Access Controls, Race condi
Google Bug Hunters
17 Sep, 2025
Find out more about last year’s ESCAL8 conference, and also see what we have planned for ESCAL8 2025.
PortSwigger Blog
12 Sep, 2025
Arman S. (Tess), a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite Professional and HackerOne in tandem to find and report high-value security
Google Bug Hunters
10 Sep, 2025
Check out this blog post for more on the inaugural Cloud-focused bugSWAT, hosted by the Cloud VRP, and how events like this help boost Google's security posture in close collaboration with external researchers.
PortSwigger Blog
4 Sep, 2025
Application security teams are under pressure. With expanding application estates, growing API usage, and faster release cycles, many teams struggle to keep up. Backlogs grow, releases are delayed, an
PortSwigger Research
3 Sep, 2025
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
PortSwigger Blog
28 Aug, 2025
Enterprise security teams are under more pressure than ever to secure sprawling application estates, without slowing down delivery. That's why, over the first half of 2025, we've delivered some of our
PortSwigger Blog
27 Aug, 2025
In a brand-new collaboration between ethical hacking and AppSec expert John Hammond and world-renowned security researcher James Kettle, the pair explore how tens of millions of websites are compromis
PortSwigger Research
26 Aug, 2025
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: Someone asked if you c
PortSwigger Research
19 Aug, 2025
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real
Google Bug Hunters
18 Aug, 2025
This blog post describes the journey of discovering a VM escape bug with the goal of demystifying the security research process and demonstrating how persistence and pivoting can lead to achieving successful exploitation.
Google Bug Hunters
7 Aug, 2025
Curious to hear about our experience exploiting Retbleed (a security vulnerability affecting modern CPUs)? Then check out this post to see how we pushed the boundaries of Retbleed exploitation and understand more about the security implications of this exploit for modern computing systems.
Google Bug Hunters
7 Aug, 2025
Check out our new Patch Rewards Program for OSV-SCALIBR, offering financial incentives for providing novel OSV-SCALIBR plugins for inventory, vulnerability, or secret detection.
PortSwigger Blog
6 Aug, 2025
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
PortSwigger Blog
6 Aug, 2025
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
PortSwigger Blog
6 Aug, 2025
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
PortSwigger Blog
6 Aug, 2025
At Black Hat USA and DEFCON 2025, PortSwigger's Director of Research, James Kettle, issued a stark warning: request smuggling isn't dying out, it's evolving and thriving. Despite years of defensive ef
PortSwigger Blog
6 Aug, 2025
The Hidden Threat That's Slipping Past Your Security HTTP request smuggling remains one of the most dangerous yet frequently overlooked web vulnerabilities today. Despite being a widely known issue si
PortSwigger Research
6 Aug, 2025
Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover. Six years of attempted mitigations have hidden the issue, but failed to fix it. This p
PortSwigger Blog
5 Aug, 2025
Ever wondered how attackers can compromise modern websites by exploiting invisible cracks in HTTP infrastructure to win big bounties? In his latest video, NahamSec walks through the basics of request
bug-bountyexploitiotresearch
Read →
PortSwigger Research
15 Jul, 2025
Manual testing doesn't have to be repetitive. In this post, we're introducing Repeater Strike - a new AI-powered Burp Suite extension designed to automate the hunt for IDOR and similar vulnerabilities
PortSwigger Blog
14 Jul, 2025
Shifting security left promises faster, safer software delivery - but for many teams, that promise is undercut by painful scan performance, false positives, and pipeline friction. In our recent webina
Google Bug Hunters
12 Jun, 2025
The HTML specification has been updated to escape '<' and '>' in attributes to prevent mutation XSS (mXSS) vulnerabilities. This post details the reasoning behind this change and explains why this update improves security.
Google Bug Hunters
3 Jun, 2025
This blog post presents one of the events we regularly host to complement our VRP program – bugSWAT, with a particular focus on our latest, AI-related event in Tokyo!
PortSwigger Research
30 Apr, 2025
Control characters like SOH, STX, EOT and ETX were never meant to run your code - but in the world of modern terminal emulators, they sometimes do. In this post, I'll dive into the forgotten mechanics
PortSwigger Research
23 Apr, 2025
Tired of repeating yourself? Automate your web security audit trail. In this post I'll introduce a new Burp AI extension that takes the boring bits out of your pen test. Web security testing can be a
Google Bug Hunters
26 Mar, 2025
The Android & Google Device VRP now offers a $1,000 reward to researchers who include an AutoRepro test with their vulnerability report! Check out our blog post for more details.
PortSwigger Research
18 Mar, 2025
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
Google Bug Hunters
17 Mar, 2025
This blog post takes you through the 2024 highlights across the assorted VRPs at Google.
Google Bug Hunters
5 Mar, 2025
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
Google Bug Hunters
27 Feb, 2025
Join us as we take a closer look at the technical details of how we identified the root causes for TT violations in two flagship rollouts: Gmail and AppSheet.
PortSwigger Research
20 Feb, 2025
Have you ever wondered how many vulnerabilities you've missed by a hair's breadth, due to a single flawed choice? We've just released Shadow Repeater, which enhances your manual testing with AI-powere
PortSwigger Research
4 Feb, 2025
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
Google Bug Hunters
4 Feb, 2025
Learn more about how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities.
PortSwigger Research
28 Jan, 2025
Unicode codepoint truncation - also called a Unicode overflow attack - happens when a server tries to store a Unicode character in a single byte. Because the maximum value of a byte is 255, an overflo
PortSwigger Research
22 Jan, 2025
In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie
Google Bug Hunters
21 Jan, 2025
This blog post takes you through everything you need to know about the Patch Rewards Program, including our newly introduced focus on memory safety (including reward multipliers!), recently increased reward amounts, and lots more!
PortSwigger Research
8 Jan, 2025
Nominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an
Google Bug Hunters
8 Jan, 2025
The InternetCTF offers a total reward of up to $10,000 to bug hunters who not only discover novel code execution vulnerabilities in Open Source Software, but also provide Tsunami plugin patches for them!
Google Bug Hunters
17 Dec, 2024
This blog discusses what one year of AI bug bounties has taught us and where we're planning to go from here.
PortSwigger Research
4 Dec, 2024
HTTP cookies often control critical website features, but their long and convoluted history exposes them to parser discrepancy vulnerabilities. In this post, I'll explore some dangerous, lesser-known
Google Bug Hunters
4 Dec, 2024
The Leaving Tradition in Google's security team, which could be described as a type of small-scale offensive security exercise, is a great (and fun) example of team culture. Curious? See this blog post for details.
Google Bug Hunters
21 Nov, 2024
Want to learn about using a static analysis tool called CodeQL to search for vulnerabilities in Google Chrome? Then this blog post is for you!
Google Bug Hunters
12 Nov, 2024
Read this blog post to understand VPC-SC product details, how to set up an environment, and what vulnerability criteria to consider when bug hunting on this product.
PortSwigger Research
29 Oct, 2024
The strength of our URL Validation Bypass Cheat Sheet lies in the contributions from the web security community, and today’s update is no exception. We are excited to introduce a new and improved IP a
Google Bug Hunters
28 Oct, 2024
This blog post looks at a few examples of how the `SslErrorHandler` class has been (mis)used, and then highlights how the class is actually meant to be implemented.
PortSwigger Research
23 Oct, 2024
Last year Johan Carlsson discovered you could conceal payloads inside the credentials part of the URL . This was fascinating to me especially because the payload is not actually visible in the URL in
Google Bug Hunters
4 Oct, 2024
This blog post describes Google's approach to vulnerability research on our Cloud AI Platform, Vertex AI. We're sharing this so that external researchers can learn from our work and to help them discover new vulnerabilities.
Google Bug Hunters
16 Sep, 2024
False positive are a recurring issue when working with external scanning tools. This blog post discusses the most common types of false positives the AutoVM team at Google has observed in this context and provides instructions on how to identify them.
Google Bug Hunters
10 Sep, 2024
In this document, Google's Cloud Vulnerability Research team (CVR) presents vulnerabilities in a third-party JPEG 2000 image library called Kakadu. Exploiting memory corruption vulnerabilities typically requires knowledge about the target environment; however, CVR outlines how to overcome these...
PortSwigger Research
3 Sep, 2024
URL validation bypasses are the root cause of numerous vulnerabilities including many instances of SSRF, CORS misconfiguration, and open redirection. These work by using ambiguous URLs to trigger URL
Google Bug Hunters
28 Aug, 2024
The Chrome VRP is increasing reward amounts and their structure to incentivize high-quality reporting and deeper research of Chrome vulnerabilities, see this post for details!
Google Bug Hunters
19 Aug, 2024
In our latest post on PQC, we discuss how we are partnering with Cryspen to produce formally verified implementations of the NIST-selected post-quantum algorithms.
PortSwigger Research
8 Aug, 2024
Through the years, we have seen many attacks exploiting web caches to hijack sensitive information or store malicious payloads. However, as CDNs became more popular, new discrepancies between propriet
Google Bug Hunters
8 Aug, 2024
This blog post takes a look at the years where eBPF was one of the kernel subsystems that grabbed the attention of a lot of security researchers. We will tell the story of how we discovered CVE-2023-2163, what our root-cause analysis process looked like, and what we did to ultimately fix the issue.
PortSwigger Research
7 Aug, 2024
Some websites parse email addresses to extract the domain and infer which organisation the owner belongs to. This pattern makes email-address parser discrepancies critical. Predicting which domain an
PortSwigger Research
7 Aug, 2024
Websites are riddled with timing oracles eager to divulge their innermost secrets. It's time we started listening to them. In this paper, I'll unleash novel attack concepts to coax out server secrets
Google Bug Hunters
11 Jul, 2024
The reward amounts on offer by the Google VRP have undergone a major overhaul: We're increasing reward amounts by up to 5x (with maximum rewards of up to $151,515)!
PortSwigger Research
9 Jul, 2024
Imagine the CEO of a random company receives an email containing a PDF invoice file. In Safari and MacOS Preview, the total price displayed is £399. After approval, the invoice is sent to the accounti
Google Bug Hunters
8 Jul, 2024
We released two new open-source projects aimed at enhancing security and flexibility in containerized and Kubernetes environments. Check out this post to learn more!
PortSwigger Research
2 Jul, 2024
We're delighted to announce three major research releases from PortSwigger Research will be published at both Black Hat USA and DEF CON 32. In this post, we'll offer a quick teaser of each talk, info
Google Bug Hunters
1 Jul, 2024
Want to know more about adopting Trusted Types to improve the security posture of an application? Take a look at our case study describing how we rolled out Trusted Types in AppSheet, a Google product.
Google Bug Hunters
24 Jun, 2024
In the 3rd post in our series on PQC, we discuss how to actually migrate to PQC and explore the role cryptographic agility and key rotation play in this process.
Google Bug Hunters
18 Jun, 2024
We're thrilled to announce a major upgrade: Bugcrowd is now live as a new payment option for bug hunters!
Google Bug Hunters
12 Jun, 2024
It’s Google CTF time! The competition kicks off on June 21 2024 6:00 PM UTC and runs through June 23 2024 6:00 PM UTC.
PortSwigger Research
11 Jun, 2024
The power of our XSS cheat sheet is we get fantastic contributions from the web security community and this update is no exception. We had valuable contributions from Mozilla to remove events that no
Google Bug Hunters
3 Jun, 2024
Find out more about last year’s ESCAL8 conference, and also see what we have planned for ESCAL8 2024.
PortSwigger Research
29 May, 2024
When you open a HTTP request or response, what do you instinctively look for? Suspicious parameter names? CORS headers? Some clue as to the request's origin or underlying purpose? A single HTTP messag
PortSwigger Research
22 May, 2024
Signed web tokens are widely used for stateless authentication and authorization throughout the web. The most popular format is JSON Web Tokens (JWT) which we've already covered in depth, but beyond t
Google Bug Hunters
21 May, 2024
This blog post explores the advantages of hybrid deployments in a world of post-quantum cryptography, looks at the reasons behind our recommendation, and offers implementation guidance.
Google Bug Hunters
30 Apr, 2024
We're celebrating one year of the Google Mobile VRP. See our blog to see what happened in that time and how we are adjusting our rewards structure to be even more attractive for security researchers!
Google Bug Hunters
26 Mar, 2024
Infinite loops between servers can lead to performance degradation or network overload. In this blog, we'll take a look at how we prevented cross-service UDP loops in QUIC and share some general conclusions.
PortSwigger Research
19 Mar, 2024
Have you ever found an HTTP desync vulnerability that seemed impossible to exploit due to its complicated constraints? In this blogpost we will explore a new exploitation technique that can be used to
Google Bug Hunters
19 Mar, 2024
Interested in creating an AI-related plugin for the Tsunami network scanner and getting rewarded for your efforts? See this post for details!
Google Bug Hunters
11 Mar, 2024
Read on to understand how Google currently evaluates the threat landscape related to post-quantum cryptography, and what implications this has for migrating from classical cryptographic algorithms to PQC.
PortSwigger Research
5 Mar, 2024
In this post we'll show you how to bypass CSP by using an often overlooked technique that can enable password theft in a seemingly secure configuration. What is form hijacking? Form hijacking isn't re
Google Bug Hunters
26 Feb, 2024
Introducing three new open-source libraries in Go that provide secure and efficient solutions: SafeText, SafeOpen, and SafeArchive.
Google Bug Hunters
20 Feb, 2024
Curious to understand what our team looks for when reviewing product security? Read on to find out more about how we conducted our review of Nomulus, and the issues we discovered.
PortSwigger Research
19 Feb, 2024
Welcome to the Top 10 Web Hacking Techniques of 2023, the 17th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
Google Bug Hunters
12 Feb, 2024
In this blog post, we're sharing how we evaluated LLVM's proposed approach at Google, outlining our initial conclusions from this process, sharing useful adoption tips, and pointing to the next steps we plan to take on this journey.
Google Bug Hunters
5 Feb, 2024
We are excited to announce an update to the TensorFlow threat model, providing updates to security recommendations, clear examples, and a baseline for defining scope in the Google Vulnerability Reward Program.
Google Bug Hunters
30 Jan, 2024
Do you want to know more about the concept of domain tiers, understand how they are applied at Google, and view a list of Google's highest sensitivity domains? Take a look at this blog post to find out more.
PortSwigger Research
23 Jan, 2024
In this post we'll show you how Java handles unicode escapes in source code strings in a way you might find surprising - and how you can abuse them to conceal payloads. We recently released a powerful
Google Bug Hunters
22 Jan, 2024
There are vastly more engineers at Google dedicated to creating and maintaining new products than there are security engineers working to secure products. For this reason, Google security has to focus on operating at scale and find ways to make meaningful security improvements across Google’s vast...
Google Bug Hunters
15 Jan, 2024
Logs are essential tools that help developers debug errors, but they can be problematic when developers don't know the data structure that they're logging. This can lead to unintentional logging of data such as cryptographic keys. Check out this blog to understand how Google prevents such logging...
PortSwigger Research
9 Jan, 2024
Update: The results are in! Check out the final top ten here or scroll down to view all nominations Over the last year, numerous security researchers have shared their discoveries with the community t
PortSwigger Research
12 Dec, 2023
Security research involves a lot of failure. It's a perpetual balancing act between taking small steps with a predictable but boring outcome, and trying out wild concepts that are so crazy they might
Google Bug Hunters
12 Dec, 2023
Just as Vulnerability Research is an important area of focus at Google, so is Vulnerability Response to critical and complex vulnerabilities. Vulnerability Response at Google not only helps secure Google’s products and users, but in certain cases, it affects millions of devices across the Internet....
Google Bug Hunters
8 Dec, 2023
We’re pleased to share that we’ve worked with the Rust community to add LLVM CFI and cross-language LLVM CFI (and LLVM KCFI and cross-language LLVM KCFI) to the Rust compiler as part of our work in the Rust Exploit Mitigations Project Group. Check out details in this post!
Google Bug Hunters
6 Dec, 2023
Are you interested in understanding what can go wrong inside modern CPUs? As part of our ongoing work to verify the safety of CPUs, we found a way to cause some processors to enter a glitch state where the normal rules do not apply. Check out this post to find out more!
Google Bug Hunters
3 Nov, 2023
Note: This blog post was originally published on the Google Security blog in April 2023. Many web applications need to display user-controlled content. This can be as simple as serving user-uploaded images (e.g. profile photos), or as complex as...
Google Bug Hunters
21 Aug, 2023
CPU vulnerabilities are a widespread problem, yet they are not well understood and are generally hard to mitigate. Some of these vulnerabilities affect nearly all modern processors, regardless of running software, so we decided to explore their...