S

SecFeed

8:20:43 PM · 386 articles · 17/17 sources
Categories
Schneier on Security Today, 06:28 PM

AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. Theyre vaguely coherent. I suppose I shouldnt be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in...

ai-securityexploitresearch
Read →
The Hacker News Today, 04:41 PM

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily...

malware
Read →
BleepingComputer Today, 02:02 PM

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

malwareransomware
Read →
The Hacker News Today, 11:30 AM

How to Secure Enterprise AI: From Adoption to Incident Readiness

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the...

Schneier on Security Today, 10:22 AM

Wireless Routers as Motion Detectors

Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see...

exploitiot
Read →
Unit 42 Today, 10:00 AM

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.

Microsoft Security Blog Today, 10:48 PM

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help...

ai-securityaptbug-bountycloudexploitiotmalwareransomwareresearch
Read →
KrebsOnSecurity Today, 10:40 PM

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning...

exploitphishingransomwareresearch
Read →
Microsoft Security Blog Yesterday, 06:55 PM

Cybersecurity IR Workshop: The workshop you shouldn’t miss

Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.

cloudexploitiotmobileresearch
Read →
Schneier on Security Yesterday, 05:36 PM

What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving a lot of individual...

Schneier on Security Yesterday, 04:29 PM

Leaked Russian Cyber-Operations Training Materials

This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. [] The reporting also linked...

aptexploitmalwareresearch
Read →
BleepingComputer Yesterday, 02:01 PM

Why Even the Best Edge Security Still Misses High-Risk Sessions

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement...

exploit
Read →
The Hacker News Yesterday, 11:30 AM

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix,...

research
Read →
Schneier on Security Yesterday, 09:59 AM

Rewiring Democracy Series on The Renovator

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I havent been posting the full text on the blog because theyre a bit long, but here are links. Part 1 is about the Japanese digital democracy party, Team Mirai. Part 2 is...

The Hacker News Yesterday, 09:05 AM

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external...

research
Read →
Intigriti Blog Yesterday, 12:00 AM

Reconnaissance unleashed: Meet CrowdRecon

At Intigriti, we have been exploring a simple but important shift in security: the work that happens before a vulnerability report is often where the real signal begins. As vulnerability discovery accelerates, organizations need practical ways to identify and reduce risk before vulnerabilities are...

bug-bountyexploitnewsresearch
Read →
SANS ISC 31 Aug, 2026

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &x26xe2&x26x80&x26x94 history, filesystem output, working paths,...

ai-security
Read →
Schneier on Security 31 Aug, 2026

Is Someone Hacking DoD Refrigerators?

It sure seems like it. The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation....

exploit
Read →
The Hacker News 31 Aug, 2026

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical...

The Hacker News 31 Aug, 2026

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed...

cloudmalwareransomwareresearch
Read →
The Hacker News 30 Aug, 2026

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique...

cloudmalwareresearch
Read →
Microsoft Security Blog 29 Aug, 2026

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft...

ai-securitycloudexploitiotmalwarephishingransomwareresearch
Read →
The Hacker News 28 Aug, 2026

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in...

Schneier on Security 28 Aug, 2026

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

Ugh: A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the Squidpocalypse of 26. That would be twenty tons of squid. As usual, you can also use this squid...

The Hacker News 28 Aug, 2026

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's...

cloudexploit
Read →
The Hacker News 28 Aug, 2026

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks...

mobile
Read →
The Hacker News 28 Aug, 2026

Key Reasons Why Identity Fabric Matters in 2026

An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on...

cloud
Read →
Schneier on Security 28 Aug, 2026

AI Doesn’t Mean the End of Mathematics—at Least Not Yet

This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAIs offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was...

ai-securityiotresearch
Read →
The Hacker News 28 Aug, 2026

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of...

exploitzero-day
Read →
SANS ISC 28 Aug, 2026

Some Malicious PE Stats

During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware1. Can we go a bit further I (vibe-)coded a Python script based on the...

iotmalware
Read →
Intigriti Blog 28 Aug, 2026

Intigriti Bug Bytes #239 - August 2026 🚀

Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: Intigriti as the new provider for Adobe's Bug Bounty Program CSS injection as an attack vector inside your email inbox AI doing novel security research: the HTTP Terminator 169 offensive recon skills in...

bug-bountybug-bytesresearch
Read →
Microsoft Security Blog 27 Aug, 2026

​​​​​​What’s new in Microsoft Security: August 2026

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post ​​​​​​What’s new in Microsoft Security: August 2026 appeared first on...

ai-securitycloudexploitransomwareresearch
Read →
The Hacker News 27 Aug, 2026

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE...

ai-securityexploitresearch
Read →
The Hacker News 27 Aug, 2026

Learn How to Build Security Operations Ready for AI-Powered Attacks

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security...

exploit
Read →
The Hacker News 27 Aug, 2026

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis...

ai-securityexploitiotsupply-chain
Read →
The Hacker News 27 Aug, 2026

What the Data Says About AI in Security Operations in 2026

AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to...

KrebsOnSecurity 27 Aug, 2026

Two Alleged TeamPCP Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two...

ai-securityaptbug-bountycloudexploitiotmalwaremobilephishingransomwareresearchsupply-chain
Read →
Schneier on Security 27 Aug, 2026

LLM-Based Social Engineering Scams

OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing...

ai-securityexploit
Read →
Microsoft Security Blog 26 Aug, 2026

When AI infrastructure becomes the target: Securing gateways and control points

Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft...

ai-securitycloudcveexploitiotmalwarephishingransomwareresearchweb-security CVE-2025-68700 CVE-2025-69286 CVE-2026-24770 CVE-2026-28797 CVE-2026-42271 CVE-2026-45312 CVE-2026-48710 CVE-2026-49869
Read →
PortSwigger Research 25 Aug, 2026

What's in a tag name? JavaScript, apparently

I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t

Talos Intelligence 25 Aug, 2026

The safety penalty: Reclaiming operational sovereignty in the age of AI

As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.

ai-securitycloudexploitiotmalwaremobileresearch
Read →
Intigriti Blog 24 Aug, 2026

When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS)

Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting...

bug-bountybusiness-insightsresearch
Read →
Intigriti Blog 24 Aug, 2026

When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS)

Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting...

bug-bountyhacker-spotlightresearch
Read →
Talos Intelligence 20 Aug, 2026

Is Cyber missing the Marque?

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.

ai-securitycloudexploitmalwarephishing
Read →
Talos Intelligence 20 Aug, 2026

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.

Unit 42 20 Aug, 2026

Identity Abuse Through Trusted Communication Channels

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

exploitphishing
Read →
Intigriti Blog 20 Aug, 2026

Web fuzzing for hackers

Fuzzing has been around for as long as web applications have. In fact, the term itself was coined back in 1988, when Barton Miller, a professor at the University of Wisconsin, was working over a dial-up connection during a thunderstorm and noticed that the resulting line noise was consistently...

hacking-toolsresearch
Read →
Talos Intelligence 19 Aug, 2026

Describing attacks with crime script analysis

Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.

ai-securityexploitiotresearch
Read →
Microsoft Security Blog 18 Aug, 2026

Hunting MacSync Stealer infrastructure through behavioral pivots

MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.

ai-securitycloudexploitiotmalwarephishingransomwareresearch
Read →
KrebsOnSecurity 14 Aug, 2026

Whos Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of...

ai-securitycloudexploitiotmalwaremobilephishingransomwareresearchsupply-chain
Read →
Talos Intelligence 13 Aug, 2026

Curiouser and Curiouser

In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.

cloudexploitiotmalwarephishingransomwareresearch
Read →
Talos Intelligence 13 Aug, 2026

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.

exploitiotphishingransomwareresearch
Read →
Talos Intelligence 11 Aug, 2026

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."

Unit 42 11 Aug, 2026

Kimwolf v7: An Evolution of the Kimwolf Botnet

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

iotmalwaremobile
Read →
Microsoft Security Blog 10 Aug, 2026

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft...

cloudexploitiotmalwarephishingransomwareresearch
Read →
Microsoft Security Blog 10 Aug, 2026

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. The...

ai-securitycloudexploitiotmalwaremobilephishingransomwareresearch
Read →
Intigriti Blog 10 Aug, 2026

CrowdRecon is coming: turning hacker reconnaissance into security intelligence

At DEF CON 34, our team introduced something exciting. Something the Intigriti team has been building for months, and our Senior Product Manager, Radu Voloaga, took to the stage in the Bug Bounty Village to give everyone the first real look at CrowdRecon. How CrowdRecon closes the gap It started...

bug-bountyexploitnews
Read →
Unit 42 7 Aug, 2026

Inside the Modern SOC: The Identity Front Door

Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.

exploit
Read →
Unit 42 6 Aug, 2026

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

malwaresupply-chain
Read →
PortSwigger Research 6 Aug, 2026

CSS:the bomb inside your inbox

Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this

Talos Intelligence 6 Aug, 2026

Why metaphor may dictate your security strategy

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.

ai-securitybug-bountyexploitiotmalwaremobilephishingransomwareresearchsupply-chainzero-day
Read →
KrebsOnSecurity 6 Aug, 2026

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener,...

cloudexploitiotmobilephishingransomwareresearch
Read →
Intigriti Blog 6 Aug, 2026

Beyond CVSS: rethinking scoring systems amidst AI Safety and Security

CVSS open framework, rapid recap Stands for Common Vulnerability Scoring System. Owned by a US-based non-profit organization, the Forum of Incident Response and Security Teams (FIRST). The purpose is to help response teams quickly and easily calculate the severity of cybersecurity vulnerabilities...

ai-securitybusiness-insightsexploitiot
Read →
PortSwigger Research 5 Aug, 2026

CRLF-Powered Desync Attacks: Beheading HTTP Streams

Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power

web-security
Read →
Unit 42 4 Aug, 2026

Almost Half of Malware Samples Communicate Direct to IP

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

exploitmalwareresearch
Read →
Intigriti Blog 4 Aug, 2026

Intigriti named new provider for Adobe's Bug Bounty Program

Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how...

bug-bountynewsresearch
Read →
Intigriti Blog 31 Jul, 2026

Intigriti Bug Bytes #238 - July 2026 🚀

Hello hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Intigriti turns 10! RCE in GitHub.com and GitHub Enterprise Server Burp Suite going agentic with Burp AT Hacking Gemini Enterprise for $15,000 3,708 live credentials found by scanning GitHub...

bug-bountybug-bytesexploitransomware
Read →
KrebsOnSecurity 30 Jul, 2026

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also...

cloudexploitiotmalwaremobileransomwareresearch
Read →
PortSwigger Blog 30 Jul, 2026

From capable AI models to trusted security testing

This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is o

research
Read →
Intigriti Blog 30 Jul, 2026

How to appeal a bug bounty submission

Bug bounty is a collaborative process that involves multiple parties, including the security researcher, triage team, and the affected organization managing the bug bounty program. While the vast majority of submissions are handled correctly, there are exceptional instances in which reports are...

bug-bountyhacking-toolsresearch
Read →
Intigriti Blog 28 Jul, 2026

RAG and ruin: why your existing controls may miss AI poisoning attacks

Key takeaways RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does. In simple QA systems, that may mean misinformation or unsafe...

business-insights
Read →
KrebsOnSecurity 22 Jul, 2026

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available...

exploitiotransomwareresearch
Read →
Intigriti Blog 20 Jul, 2026

The between-reports problem: why security teams miss what attackers see

What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What...

business-insightsexploitresearch
Read →
KrebsOnSecurity 14 Jul, 2026

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning...

cloudcveexploitmalwaremobileransomwareresearchzero-day CVE-2026-48561 CVE-2026-50661 CVE-2026-56155 CVE-2026-56164
Read →
KrebsOnSecurity 13 Jul, 2026

Lessons Learned from CISAs Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity....

cloudexploitransomwareresearch
Read →
KrebsOnSecurity 8 Jul, 2026

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform...

cloudexploitiotresearchzero-day
Read →
Intigriti Blog 29 Jun, 2026

Reconnaissance for exposure management: why context matters in the AI era

Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!), and the human layer triage (The AI Impact), judgment, and prioritization has become more important, not less (CEO Insights). But...

business-insightsresearch
Read →
Intigriti Blog 27 Jun, 2026

Exploiting insecure cookie policies

Cookies are one of the most fundamental building blocks of the modern web, and yet they are often overlooked from a security perspective. When misconfigured, they can potentially lead to exposure of sensitive session data, enable several client-side attacks, and in severe cases, even allow...

exploithacking-tools
Read →
Intigriti Blog 26 Jun, 2026

Intigriti Bug Bytes #237 - June 2026 🚀

Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we are featuring: A 10-year-old pre-auth RCE in phpBB Earning $500K hacking Google with AI Reading any Salesforce Marketing Cloud account's emails New DOMPurify sanitizer bypass Mapping abandoned S3 buckets to redo...

bug-bountybug-bytescloudexploitresearch
Read →
Intigriti Blog 24 Jun, 2026

Exploiting web cache poisoning vulnerabilities

Web (or HTTP) caching is a highly adopted practice to effectively optimize web page loading times for clients. However, as with most technologies, when incorrectly implemented, it may open up a new exploitable attack surface for us to look into. In this article, we'll cover what web cache poisoning...

exploithacking-tools
Read →
Intigriti Blog 17 Jun, 2026

Using AI the smart way. Interview with Cristian Zot (CristiVlad25)

Cristian Zot, known by most in the industry as CristiVlad25, is an active security researcher, experienced pentester, and an Intigriti Hacker Ambassador. He is a prominent figure in the ethical hacking community and frequently collaborates with Intigriti through platform meetups, podcast...

bug-bountybusiness-insightsresearch
Read →
Intigriti Blog 17 Jun, 2026

Using AI the smart way. Interview with Cristian Zot (CristiVlad25)

Cristian Zot, known by most in the industry as CristiVlad25, is an active security researcher, experienced pentester, and an Intigriti Hacker Ambassador. He is a prominent figure in the ethical hacking community and frequently collaborates with Intigriti through platform meetups, podcast...

bug-bountyhacker-spotlightresearch
Read →
Bug Bounty Daily 16 Jun, 2026

I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.

How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling FIFA, MediaKind, HBS, CISA, and the FBI...

iot
Read →
Bug Bounty Daily 11 Jun, 2026

Hacking Google with A.I. for $500,000

What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found.

Google Bug Hunters 5 Jun, 2026

Bug Hunting on Gemini Spark

Gemini Spark brings a persistent agent to the Gemini App. Learn how to approach security testing for this new paradigm and focus on high-impact bugs.

Bug Bounty Daily 2 Jun, 2026

Finding XSS on Shazzer (literally) | Jorian Woltjer

How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malicious content.

researchweb-security
Read →
Bug Bounty Daily 1 Jun, 2026

WAF Bypasses via h2 framing

How HTTP/2’s multi-frame architecture allows attackers to bypass WAFs by exploiting timing delays, protocol translation flaws, and incomplete body inspection across various reverse proxies

cloudexploitresearch
Read →
Bug Bounty Daily 1 Jun, 2026

Poisoning Claude Code: One GitHub Issue to Break the Supply Chain

Introduction Hello, I’m RyotaK ( @ryotkak ), a security researcher at GMO Flatt Security Inc. After publishing my previous article ( Pwning Claude Code in 8 Different Ways ), I continued investigating Claude-related products and found several more vulnerabilities. In this article, I will explain a...

exploitransomwareresearchsupply-chain
Read →
Bug Bounty Daily 25 May, 2026

From a Sanitized Name Field to One-Click Account Takeover

Some weeks ago, I was testing a mature and heavily audited application from a bug bounty program. Since I had previously found several interesting client-side vulnerabilities in that target, I decided to focus on the frontend again. What first looked like a safely sanitized name field eventually...

bug-bountyresearch
Read →
Bug Bounty Daily 22 May, 2026

Discovering Vulnerabilities in Enterprise Audiovisual Hardware

Some organisations’ most sensitive information is only ever discussed in person. Ironically, the equipment in meeting rooms, conference halls, and other physical locations is often among the least-monitored and most insecurely-configured attack surfaces in an organisation.

Bug Bounty Daily 22 May, 2026

Two Bypasses for Chrome’s Sanitizer API › Searchlight Cyber

The Sanitizer API arrived with much fanfare in both Chrome 146 and Firefox 148 just a few months ago. The API provides two new ways to set HTML safely from within javascript; the default mode: node.setHTML(`Hello, world!`) And the more customizable mode: const config = { "elements": ["p", "span",...

research
Read →
Bug Bounty Daily 19 May, 2026

4 Google Cloud Shell bugs explained – bug #4

Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned (this page) Note: The vulnerab…

cloud
Read →
Bug Bounty Daily 19 May, 2026

4 Google Cloud Shell bugs explained – bug #2

Quick navigation IntroductionBug #1 – The Python language serverBug #2 – A custom Cloud Shell image (this page)Bug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…

cloud
Read →
Bug Bounty Daily 19 May, 2026

4 Google Cloud Shell bugs explained – bug #1

Quick navigation IntroductionBug #1 – The Python language server (this page)Bug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…

cloud
Read →
Bug Bounty Daily 19 May, 2026

4 Google Cloud Shell bugs explained – bug #3

Quick navigation Introduction Bug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git clone (this page)Bug #4 – Go and get pwned Note: The vulnera…

cloud
Read →
Bug Bounty Daily 12 May, 2026

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Of course I took a peek at the Claude Code source 🙈. What I found was a very entertaining vulnerability which is now fixed since Claude Code version 2.1.118. Just wading through the massive codebase manually wasn’t really a feasible approach. So took an army of AI Agents to…. no wait actually I...

exploit
Read →
Google Bug Hunters 11 May, 2026

bugSWAT in Seoul – April 2026

In this blog post, we'll take a look at what makes bugSWAT events valuable in general, and focus on the latest edition in Seoul, which took place in April 2026.

Bug Bounty Daily 6 May, 2026

Breaking SameSite=Strict in Chrome

How opening Chrome DevTools on a cross-site POST response can bypass SameSite=Strict cookie protections when a service worker is present.

researchweb-security
Read →
Bug Bounty Daily 6 May, 2026

Escalating Self-XSS with Disk Cache

I’m here to share my Self-XSS escalation write-up, one that took me multiple failed attempts before I finally cracked it with some much needed help.

web-security
Read →
Google Bug Hunters 30 Apr, 2026

Evolving the Android & Chrome VRPs for the AI Era

We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of reports and bug categories that provide the most value to security today.

exploitmobile
Read →
Immunefi Blog 23 Apr, 2026

Base Immunefi Audit Competition

Immunefi, the leading onchain security platform, and Base, one of the largest Ethereum Layer 2 networks, launched an audit competition on April 21 for the Base Azul network upgrade with a reward pool of up to $250,000. The competition is live now and runs through May 4, 2026.Base

research
Read →
PortSwigger Blog 16 Apr, 2026

Introducing the official Burp Ambassador Program

Why we’re launching the program What it means to be a Burp Ambassador What we’re aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3rius Looking ahead Get Involved - B

Immunefi Blog 25 Mar, 2026

What an Onchain Hack Actually Costs: 2024-2025 Update

An Immunefi research report on what a crypto exploit actually does to a protocol, beyond the stolen funds, based on five years of onchain incident data.SummaryBack in 2024, Immunefi published the industry's first comprehensive look at what onchain hacks actually cost a project, covering the...

bug-bountyexploitransomwareresearch
Read →
Bug Bounty Daily 23 Mar, 2026

Story of Abusing a Fully Secured redirect_uri in an OAuth Flow

The post describes how the author discovered a one-click account takeover vulnerability in a large automotive company’s OAuth implementation, despite apparently robust redirect_uri validation. By exploiting a subtle double-decoding inconsistency in URL parsing, they were able to redirect the...

exploit
Read →
Bug Bounty Daily 23 Mar, 2026

Remote Command Execution in Google Cloud with Single Directory Deletion

Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During this event, I discovered a remote command execution vulnerability in one of Google Cloud’s...

cloudexploit
Read →
Bug Bounty Daily 18 Mar, 2026

how to do good research

Ignoring the obvious name, this blogpost is not tips that will help you “exploit” a bug or give you tips on how to find awesome bugs, it is obvious that you need technical knowledge.

exploitresearch
Read →
PortSwigger Blog 13 Mar, 2026

HTTP/1.1 Must Die: Conquering the 0.CL Challenge

Note: This is a guest post by pentester Julen Garrido Estévez (@b3xal). 1. Acknowledgements 2. Intro 3. Required tools 4. Strategy to solve/exploit the lab 5. Detecting 0.CL 5.1. Practical confirmatio

exploit
Read →
Bug Bounty Daily 12 Mar, 2026

From self-XSS, through AI, to tenant takeover

While auditing a multi-tenant application, I came across an interesting chain leading to a full tenant takeover. It started innocuously - with a self-XSS in a rich-text editor. Exploitation would require the user to insert a dangerous element into the editor via its API themselves, which meant a...

exploitweb-security
Read →
Bug Bounty Daily 12 Mar, 2026

Unauthenticated Chat Takeover in AI Chatbot – un1tycyb3r

A popular enterprise chatbot left an old, unauthenticated WebSocket endpoint active that still accepted full bidirectional messages using only a conversation UUID as “protection.” Anyone who obtained a conversation ID could connect, impersonate the user, read their chats, and exfiltrate sensitive...

Immunefi Blog 11 Mar, 2026

Anchorage Makes Strategic Purchase of $IMU, Partners with Immunefi

We're excited to announce a new strategic partnership with Anchorage Digital, home to America's first federally chartered crypto bank, to deliver enhanced security and risk management solutions to institutional DeFi participants.Alongside this partnership, Anchorage Digital Ventures has...

bug-bountyexploitresearch
Read →
Google Bug Hunters 4 Mar, 2026

Hybrid Transport Goes Offline!

Find out how the FIDO alliances's Hybrid transport architecture was expanded to support authentication in the offline world, increasing reliability and unlocking many new use cases.

Bug Bounty Daily 2 Mar, 2026

Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852 - Check Point Research

By Aviv Donenfeld and Oded Vanunu Executive Summary Check Point Research has discovered critical vulnerabilities in Anthropic’s Claude Code that allow attackers to achieve remote code execution and steal API credentials through malicious project configurations. The vulnerabilities exploit various...

Bug Bounty Daily 2 Mar, 2026

Can a Predicted window.open Target Really Be That Impactful?

This post walks through a real-world OAuth popup hijacking attack. The target had solid defenses origin validation, source checking, CSP but a single predictable window.open() target name created an exploitable gap. It also serves as a real-world case use of iframe hijacking, showing how I managed...

exploit
Read →
Google Bug Hunters 23 Feb, 2026

Hybrid Protocol: The JSON Upgrade

This post highlights how Hybrid transport is being extended to support generic JSON messages – paving the way for a host of new, secure authentication and credential use cases.

Immunefi Blog 20 Feb, 2026

93% of Critical Crypto Vulns Are Disclosed on Immunefi.

An Immunefi research report on where post-launch critical vulnerabilities in the onchain economy actually get disclosed, and what the data says about industry-wide security.Key findingsRoughly 92.33% of post-launch critical vulnerabilities in crypto are disclosed through Immunefi, a concentration...

bug-bountycloudexploitransomwareresearch
Read →
PortSwigger Research 5 Feb, 2026

Top 10 web hacking techniques of 2025

Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

research
Read →
Google Bug Hunters 27 Jan, 2026

The Evolution of FIDO Experiences on Android

Based on the FIDO specification, online authentication has undergone a significant transformation in the past years, moving beyond simple passwords to more secure, phishing-resistant methods.

mobilephishing
Read →
Google Bug Hunters 14 Nov, 2025

Effortless Web Security: Secure by Design in the Wild

This blog post presents two initiatives that demonstrate two ways Google shares security work with the industry: Contributing to the Secure Web Application Guidelines Community Group in W3C, and introducing auto-CSP in Angular.

PortSwigger Research 11 Nov, 2025

Introducing HTTP Anomaly Rank

HTTP Anomaly Rank If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length,

Immunefi Blog 7 Nov, 2025

How fragmented security enabled the $100m Balancer exploit

In November 2025, Balancer was exploited for over $100 million through a precision-loss bug in composable stable pools.This isn't a coding blunder on Balancer's end, but a coordinated failure stemming from security controls that don't work together, a major problem for

bug-bountyexploitransomwareresearch
Read →
Immunefi Blog 27 Oct, 2025

Immunefi achieves SOC 2 Type II Certification

Immunefi has successfully completed its SOC 2 Type II attestation, verifying our internal controls meet the highest standards for security, availability, and confidentiality.Conducted by Sensiba, this attestation evaluated both the design and the consistent operation of our systems over time. This...

ransomware
Read →
Immunefi Blog 1 Oct, 2025

VeChain launches a $200K Attackathon on Immunefi to secure the Hayabusa Upgrade

VeChain has partnered with Immunefi to launch an Attackathon focused on one of the most significant blockchain upgrades of the year: the Hayabusa Upgrade.This Attackathon invites security researchers to explore, test, and strengthen VeChainThors live infrastructure during its transition to a more...

exploitiotresearch
Read →
Google Bug Hunters 19 Sep, 2025

Project Rain:L1TF

This blog shares a detailed overview of the L1TF vulnerability, a CPU vulnerability on some Intel CPUs (Skylake and older), and explains how it could be exploited and what mitigation strategies are possible.

exploit
Read →
Google Bug Hunters 7 Aug, 2025

Exploiting Retbleed in the real world

Curious to hear about our experience exploiting Retbleed (a security vulnerability affecting modern CPUs)? Then check out this post to see how we pushed the boundaries of Retbleed exploitation and understand more about the security implications of this exploit for modern computing systems.

exploit
Read →
Google Bug Hunters 7 Aug, 2025

New Patch Rewards Program for OSV-SCALIBR

Check out our new Patch Rewards Program for OSV-SCALIBR, offering financial incentives for providing novel OSV-SCALIBR plugins for inventory, vulnerability, or secret detection.

exploit
Read →
PortSwigger Research 6 Aug, 2025

HTTP/1.1 must die: the desync endgame

Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover. Six years of attempted mitigations have hidden the issue, but failed to fix it. This p

PortSwigger Research 15 Jul, 2025

Repeater Strike: manual testing, amplified

Manual testing doesn't have to be repetitive. In this post, we're introducing Repeater Strike - a new AI-powered Burp Suite extension designed to automate the hunt for IDOR and similar vulnerabilities

Google Bug Hunters 3 Jun, 2025

AI bugSWAT in Tokyo & 2025 Hacker Roadshow

This blog post presents one of the events we regularly host to complement our VRP program – bugSWAT, with a particular focus on our latest, AI-related event in Tokyo!

PortSwigger Research 23 Apr, 2025

Document My Pentest: you hack, the AI writes it up!

Tired of repeating yourself? Automate your web security audit trail. In this post I'll introduce a new Burp AI extension that takes the boring bits out of your pen test. Web security testing can be a

PortSwigger Research 18 Mar, 2025

SAML roulette: the hacker always wins

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

exploit
Read →
Google Bug Hunters 5 Mar, 2025

Zen and the Art of Microcode Hacking

This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.

exploit
Read →
PortSwigger Research 20 Feb, 2025

Shadow Repeater:AI-enhanced manual testing

Have you ever wondered how many vulnerabilities you've missed by a hair's breadth, due to a single flawed choice? We've just released Shadow Repeater, which enhances your manual testing with AI-powere

PortSwigger Research 4 Feb, 2025

Top 10 web hacking techniques of 2024

Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

research
Read →
PortSwigger Research 28 Jan, 2025

Bypassing character blocklists with unicode overflows

Unicode codepoint truncation - also called a Unicode overflow attack - happens when a server tries to store a Unicode character in a single byte. Because the maximum value of a byte is 255, an overflo

research
Read →
PortSwigger Research 4 Dec, 2024

Bypassing WAFs with the phantom $Version cookie

HTTP cookies often control critical website features, but their long and convoluted history exposes them to parser discrepancy vulnerabilities. In this post, I'll explore some dangerous, lesser-known

research
Read →
Google Bug Hunters 21 Nov, 2024

Finding Bugs in Chrome with CodeQL

Want to learn about using a static analysis tool called CodeQL to search for vulnerabilities in Google Chrome? Then this blog post is for you!

PortSwigger Research 23 Oct, 2024

Concealing payloads in URL credentials

Last year Johan Carlsson discovered you could conceal payloads inside the credentials part of the URL . This was fascinating to me especially because the payload is not actually visible in the URL in

Google Bug Hunters 4 Oct, 2024

Protecting Large Language Models

This blog post describes Google's approach to vulnerability research on our Cloud AI Platform, Vertex AI. We're sharing this so that external researchers can learn from our work and to help them discover new vulnerabilities.

cloudexploitresearch
Read →
Google Bug Hunters 10 Sep, 2024

CVR: The Mines of Kakadûm

In this document, Google's Cloud Vulnerability Research team (CVR) presents vulnerabilities in a third-party JPEG 2000 image library called Kakadu. Exploiting memory corruption vulnerabilities typically requires knowledge about the target environment; however, CVR outlines how to overcome these...

cloudexploitresearch
Read →
PortSwigger Research 3 Sep, 2024

Introducing the URL validation bypass cheat sheet

URL validation bypasses are the root cause of numerous vulnerabilities including many instances of SSRF, CORS misconfiguration, and open redirection. These work by using ambiguous URLs to trigger URL

researchweb-security
Read →
Google Bug Hunters 19 Aug, 2024

Formally Verified Post-Quantum Algorithms

In our latest post on PQC, we discuss how we are partnering with Cryspen to produce formally verified implementations of the NIST-selected post-quantum algorithms.

Google Bug Hunters 24 Jun, 2024

Cryptographic Agility and Key Rotation

In the 3rd post in our series on PQC, we discuss how to actually migrate to PQC and explore the role cryptographic agility and key rotation play in this process.

PortSwigger Research 29 May, 2024

Refining your HTTP perspective, with bambdas

When you open a HTTP request or response, what do you instinctively look for? Suspicious parameter names? CORS headers? Some clue as to the request's origin or underlying purpose? A single HTTP messag

web-security
Read →
Google Bug Hunters 26 Mar, 2024

Preventing Cross-Service UDP Loops in QUIC

Infinite loops between servers can lead to performance degradation or network overload. In this blog, we'll take a look at how we prevented cross-service UDP loops in QUIC and share some general conclusions.

PortSwigger Research 19 Mar, 2024

Making desync attacks easy with TRACE

Have you ever found an HTTP desync vulnerability that seemed impossible to exploit due to its complicated constraints? In this blogpost we will explore a new exploitation technique that can be used to

exploitresearch
Read →
Google Bug Hunters 19 Mar, 2024

Tsunami Network Scanner & AI Security

Interested in creating an AI-related plugin for the Tsunami network scanner and getting rewarded for your efforts? See this post for details!

ai-security
Read →
Google Bug Hunters 11 Mar, 2024

Google's Threat model for Post-Quantum Cryptography

Read on to understand how Google currently evaluates the threat landscape related to post-quantum cryptography, and what implications this has for migrating from classical cryptographic algorithms to PQC.

PortSwigger Research 5 Mar, 2024

Using form hijacking to bypass CSP

In this post we'll show you how to bypass CSP by using an often overlooked technique that can enable password theft in a seemingly secure configuration. What is form hijacking? Form hijacking isn't re

research
Read →
PortSwigger Research 19 Feb, 2024

Top 10 web hacking techniques of 2023

Welcome to the Top 10 Web Hacking Techniques of 2023, the 17th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

research
Read →
Google Bug Hunters 12 Feb, 2024

LLVM's 'RFC: C++ Buffer Hardening' at Google

In this blog post, we're sharing how we evaluated LLVM's proposed approach at Google, outlining our initial conclusions from this process, sharing useful adoption tips, and pointing to the next steps we plan to take on this journey.

Google Bug Hunters 5 Feb, 2024

TensorFlow Threat Model and Security Guidelines Update

We are excited to announce an update to the TensorFlow threat model, providing updates to security recommendations, clear examples, and a baseline for defining scope in the Google Vulnerability Reward Program.

exploit
Read →
Google Bug Hunters 30 Jan, 2024

Externalizing the Google Domain Tiers Concept

Do you want to know more about the concept of domain tiers, understand how they are applied at Google, and view a list of Google's highest sensitivity domains? Take a look at this blog post to find out more.

PortSwigger Research 23 Jan, 2024

Hiding payloads in Java source code strings

In this post we'll show you how Java handles unicode escapes in source code strings in a way you might find surprising - and how you can abuse them to conceal payloads. We recently released a powerful

exploit
Read →
Google Bug Hunters 22 Jan, 2024

A Recipe for Scaling Security

There are vastly more engineers at Google dedicated to creating and maintaining new products than there are security engineers working to secure products. For this reason, Google security has to focus on operating at scale and find ways to make meaningful security improvements across Google’s vast...

Google Bug Hunters 15 Jan, 2024

Fixing Debug Log Leakage with Safe Coding

Logs are essential tools that help developers debug errors, but they can be problematic when developers don't know the data structure that they're logging. This can lead to unintentional logging of data such as cryptographic keys. Check out this blog to understand how Google prevents such logging...

PortSwigger Research 12 Dec, 2023

Finding that one weird endpoint, with Bambdas

Security research involves a lot of failure. It's a perpetual balancing act between taking small steps with a predictable but boring outcome, and trying out wild concepts that are so crazy they might

research
Read →
Google Bug Hunters 12 Dec, 2023

The Tale of Google’s Response to Reptar CPU Vulnerability

Just as Vulnerability Research is an important area of focus at Google, so is Vulnerability Response to critical and complex vulnerabilities. Vulnerability Response at Google not only helps secure Google’s products and users, but in certain cases, it affects millions of devices across the Internet....

exploitresearch
Read →
Google Bug Hunters 8 Dec, 2023

LLVM CFI and Cross-Language LLVM CFI Support for Rust

We’re pleased to share that we’ve worked with the Rust community to add LLVM CFI and cross-language LLVM CFI (and LLVM KCFI and cross-language LLVM KCFI) to the Rust compiler as part of our work in the Rust Exploit Mitigations Project Group. Check out details in this post!

exploit
Read →
Google Bug Hunters 6 Dec, 2023

The Reptar CPU Vulnerability

Are you interested in understanding what can go wrong inside modern CPUs? As part of our ongoing work to verify the safety of CPUs, we found a way to cause some processors to enter a glitch state where the normal rules do not apply. Check out this post to find out more!

exploit
Read →
Google Bug Hunters 3 Nov, 2023

Securely Hosting User Data in Modern Web Applications

Note: This blog post was originally published on the Google Security blog in April 2023. Many web applications need to display user-controlled content. This can be as simple as serving user-uploaded images (e.g. profile photos), or as complex as...

Google Bug Hunters 21 Aug, 2023

No More Speculation: Exploiting CPU Side-Channels for Real

CPU vulnerabilities are a widespread problem, yet they are not well understood and are generally hard to mitigate. Some of these vulnerabilities affect nearly all modern processors, regardless of running software, so we decided to explore their...

exploit
Read →
0
articles selected