RCE+29
Supply Chain+24
AI+23
SSRF+17
Bug Bounty+12
XSS+8
API Security+6
Secrets+3
SQLi+3
Recon+2
OSINT+2
AuthZ+2
GraphQL+1
Mobile+1
JWT+1
Burp Suite+1
SSTI+1
XXE+1
IDOR+1
Authentication+1
RCE +29
| Date | Resource | Summary |
|---|---|---|
| 2026-07-12 | Critical CVE-2026-2699 and CVE-2026-2701 Vulnerabilities Force Immediate Shutdown of Progress ShareFile Storage Zone Controller v5.x | Progress ShareFile Storage Zone Controller v5.x has been forced into an immediate shutdown due to critical vulnerabilities, CVE-2026-2699 and CVE-2026-2701. These security flaws necessitate this urgent action to protect affected systems. Further details are available via the provided link. |
| 2026-07-12 | Global CMS Attack Wave: Attackers Distribute Web Shells via Known WordPress Joomla and Craft Vulnerabilities | Attackers are exploiting known vulnerabilities in WordPress, Joomla, and Craft CMS to distribute web shells globally. This widespread attack wave targets these popular content management systems, indicating a coordinated effort to gain unauthorized access to websites. The specific vulnerabilities being leveraged allow attackers to upload and execute malicious code, potentially leading to data breaches, website defacement, and further compromise of server resources. Users of these CMS platforms are strongly advised to update their software immediately and ensure all plugins and themes are also current to mitigate the risk of infection. |
| 2026-07-10 | Zero Day Initiative CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys | Writeup detailing CVE-2026-47291, a kernel-mode remote code execution vulnerability in Windows HTTP.sys. Exploitation involves an attacker sending crafted HTTP/1.x requests over TLS, triggering a heap buffer overflow during header parsing due to insufficient bounds checking when growing a buffer reference array. This can lead to denial-of-service or code execution with kernel privileges. The vulnerability is mitigated by configuring `MaxRequestBytes` to 65,535 or lower, and detection requires monitoring TLS-encrypted traffic for an unusually high number of HTTP header lines per request. |
| 2026-07-10 | OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution | Researchers have discovered critical vulnerabilities in OpenClaw, a messaging application. These flaws could allow attackers to execute arbitrary code on a user's host system simply by sending a specially crafted WhatsApp message. This means a malicious message could potentially compromise a user's entire device, going beyond just the messaging application itself. Further details are available at the provided link. |
| 2026-07-10 | Developers face RCE via Claude Code 'auto-mode' exploit | A vulnerability in Claude Code's "auto-mode" allows for Remote Code Execution (RCE), posing a significant security risk to developers. This exploit enables malicious actors to potentially run arbitrary code on a developer's system through the AI assistant. Further details are available via the provided link. The summary does not include a payout amount as none was stated in the content. |
| 2026-07-10 | Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws | Writeup detailing a WhatsApp-to-host attack chain leveraging three OpenClaw vulnerabilities: GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm, both involving OS command injection and incomplete input validation in the host execution environment filtering; and GHSA-575v-8hfq-m3mc, a path traversal flaw enabling sandbox bind mount bypass. These flaws allow for credential theft, privilege escalation, and arbitrary code execution without prior host compromise, as demonstrated by accessing sensitive user files or the Docker socket. |
| 2026-07-09 | Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access | Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access https://ift.tt/l8HGU0N |
| 2026-07-09 | Chrome Update Patches 27 Vulnerabilities including Two Code Execution Flaws | Google has released a Chrome update addressing 27 vulnerabilities, including two critical code execution flaws. These security patches are essential for users to protect their systems from potential exploits. The update enhances Chrome's overall security posture, safeguarding against malicious attacks. Users are strongly advised to update their Chrome browsers immediately to benefit from these vital security fixes and prevent any compromise. |
| 2026-07-09 | 20 Remote Code Execution Vulnerabilities Patched in Foxit PDF Reader and Editor | Foxit has released updates to address 20 critical Remote Code Execution (RCE) vulnerabilities discovered in its PDF Reader and Editor software. These flaws could allow attackers to execute arbitrary code on a user's system by tricking them into opening a specially crafted PDF file. Users are strongly advised to update their Foxit software immediately to the latest version to mitigate these security risks. No specific bounty amounts were mentioned in the provided content. |
| 2026-07-09 | Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic | A critical vulnerability in Palo Alto Networks' PAN-OS allows for arbitrary code execution. Attackers can exploit this by sending specially crafted network traffic, potentially compromising affected devices. While the article highlights the severity of this security flaw, no specific bug bounty payout amount is mentioned. Organizations using PAN-OS should prioritize patching their systems to mitigate this risk. |
| 2026-07-09 | Juniper Junos OS Multiple Vulnerabilities | Bulletin on multiple Juniper Junos OS vulnerabilities, including CVE-2020-7450, CVE-2026-33794, and CVE-2026-57019, which can lead to denial of service, remote code execution, information disclosure, and security restriction bypass. These issues affect both Junos OS and Junos OS Evolved. |
| 2026-07-08 | Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) | Writeup on CVE-2026-55255, an insecure direct object reference (IDOR) vulnerability in Langflow versions prior to 1.9.2. This flaw allows an authenticated attacker to execute any user's flow by supplying its ID, leading to credential harvesting, cross-tenant data exposure, and secret theft, as demonstrated by attackers exploiting it alongside CVE-2026-33017 for code execution and implant delivery. CISA has mandated federal agencies patch this vulnerability by July 10, 2026. |
| 2026-07-08 | PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability | Proof-of-concept (PoC) and technical details for a SharePoint remote code execution (RCE) vulnerability have been released. This vulnerability could allow attackers to execute arbitrary code on affected SharePoint servers, posing a significant security risk. The public disclosure enables security researchers and administrators to better understand and address the threat. No bug bounty payout amount was explicitly stated in the provided content. |
| 2026-07-08 | CISA Flags Actively Exploited SharePoint RCE Flaw | Analysis of CVE-2026-45659, an actively exploited SharePoint RCE vulnerability, details its exploitation via insecure deserialization by authenticated users with basic permissions. The flaw, impacting SharePoint Server Subscription Edition, 2019, and 2016, carries a CVSS score of 8.8, a network attack vector, and low complexity. CISA has added it to its Known Exploited Vulnerabilities Catalog, mandating fixes by July 4th. |
| 2026-07-08 | CISA flags active SharePoint RCE exploit as Cisco UCM attacks continue | Library of techniques and tools addressing active exploits against enterprise systems, including a Microsoft SharePoint deserialization flaw (CVE-2026-45659) allowing remote code execution and a Cisco Unified Communications Manager (UCM) vulnerability (CVE-2026-20230) enabling unauthorized file creation. The entry also touches on macOS credential harvesting via an infostealer utilizing AppleScript validation. |
| 2026-07-08 | CISA Adds 4 Actively Exploited Adobe Joomla and Langflow Flaws to KEV | Vulnerabilities in Adobe ColdFusion (CVE-2026-48282), Joomlack Page Builder (CVE-2026-56290), Langflow (CVE-2026-55255), and JoomShaper SP Page Builder (CVE-2026-48908) have been added to CISA's Known Exploited Vulnerabilities catalog. These flaws, ranging from path traversal to authorization bypass and unrestricted file uploads, are being actively exploited for arbitrary code execution, remote code execution, and web shell deployment. Langflow vulnerabilities CVE-2026-55255 and CVE-2026-33017 have been weaponized in campaigns targeting LLM and AWS keys. |
| 2026-07-07 | Active Exploitation Alert: Critical CVE-2024-12356 Authentication Bypass and RCE in BeyondTrust Remote Support and PRA | Writeup of CVE-2024-12356, a critical authentication bypass and RCE in BeyondTrust Remote Support and PRA. This flaw allows unauthenticated attackers to execute arbitrary commands via command injection in the thin-scc-wrapper script, chaining with CVE-2025-1094 for SQL injection. CISA has confirmed active exploitation by APT groups, including breaches of the U.S. Treasury, and a Metasploit module is available. Immediate patching of affected versions up to 24.3.1 is mandatory. |
| 2026-07-07 | Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) | Analysis of CVE-2026-48282, a critical path traversal vulnerability in Adobe ColdFusion, details how attackers exploit this flaw to achieve arbitrary code execution by uploading malicious files via the Remote Development Services (RDS) feature. Exploitation attempts were detected shortly after WatchTowr researchers published analysis, highlighting the immediate threat posed by this vulnerability, especially when RDS is enabled and unauthenticated. Recommended fixes include upgrading to the latest ColdFusion updates and hunting for indicators of compromise. |
| 2026-07-07 | Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities | Library exploiting N-day Roundcube vulnerabilities like CVE-2024-42009 and CVE-2025-49113, enabling credential theft and post-exploitation via VShell or SquareShell. This toolkit, tracked as UNK_MassTraction and potentially shared among China-nexus clusters, has targeted academic institutions for reconnaissance and network pivoting. The IceCube payload, written in JavaScript and Go, exhibits advanced evasion tactics by re-attempting exploitation on user interaction changes. |
| 2026-07-07 | Google Gemini Live API Flaw Allows RCE via Unconstrained Ephemeral Tokens | A critical flaw in the Google Gemini Live API allowed for Remote Code Execution (RCE) by exploiting unconstrained ephemeral tokens. This vulnerability enabled attackers to potentially gain unauthorized access and control over systems utilizing the Gemini Live API. Further details about the exploit and its impact can be found at the provided link. |
| 2026-07-07 | RCE via Gemini Live AI Voice Session Misconfiguration. | Library for exploiting RCE vulnerabilities in applications integrating Google's Gemini Live AI Voice sessions by injecting client-controlled setup frames. The vulnerability arises when ephemeral tokens, used for browser-facing WebSocket connections to endpoints like `BidiGenerateContentConstrained`, are issued without proper `live_connect_constraints`. This misconfiguration allows attackers to control session parameters, including the model, system instruction, and critically, the `tools` field, enabling the injection of code execution capabilities. The writeup details how the official Gemini Live API example repository promotes this insecure pattern by omitting the `bidi_generate_content_setup` from token creation. |
| 2026-07-07 | Microsoft Edge High-Severity Vulnerability Allows Remote Code Execution | Microsoft has addressed a high-severity vulnerability in Microsoft Edge that could allow for remote code execution. This flaw, if exploited, enables attackers to run malicious code on a user's system without their knowledge or consent. While the severity is highlighted, no specific bug bounty payout amount is mentioned in the provided content. Users are advised to update their Edge browsers promptly to patch this security risk. |
| 2026-07-07 | Microsoft Edge Use-After-Free Flaw Lets Attackers Execute Code Remotely | A critical use-after-free vulnerability in Microsoft Edge has been disclosed, allowing attackers to remotely execute code on vulnerable systems. This flaw could potentially lead to complete system compromise. While a specific payout amount for reporting this bug is not mentioned in the provided content, the severity of the vulnerability highlights the ongoing importance of security research and patching for web browsers. Users are advised to ensure their Microsoft Edge browser is updated to the latest version to mitigate this risk. |
| 2026-07-07 | SharePoint Vulnerability CVE-2026-45659 Exploited [2026] | Writeup of CVE-2026-45659, a SharePoint RCE vulnerability, details how a flaw initially assessed as "less likely to be exploited" by Microsoft became a federally mandated fix by CISA within weeks. The deserialization bug requires only "Site Member" privileges and low complexity, making authenticated access a potent attack vector. This "n-day" exploit highlights the danger of unpatched on-premises SharePoint servers, impacting sectors like government and finance, and underscores the urgency of CISA's Known Exploited Vulnerabilities catalog. |
| 2026-07-06 | More than just data: The hidden security risks in Jupyter notebooks | More than just data: The hidden security risks in Jupyter notebooks https://ift.tt/bWszvx6 |
| 2026-07-06 | Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild | Writeup of CVE-2026-48282, a critical path traversal vulnerability in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. This unauthenticated flaw allows remote attackers arbitrary code execution and is actively exploited in the wild, with attacks originating from India. Adobe urges immediate installation of security updates. This follows recent exploitation trends, including CISA's inclusion of CVE-2017-3066 and a coordinated campaign exploiting numerous ColdFusion flaws. |
| 2026-07-06 | Microsoft Edge Vulnerability Allows Remote Attacker to Execute Arbitrary Code | A critical vulnerability in Microsoft Edge has been disclosed, potentially allowing remote attackers to execute arbitrary code. This means a hacker could exploit this flaw to gain control of a user's system without their knowledge. The exploit likely targets a weakness within the browser's rendering engine or JavaScript execution. Further details on the specific vulnerability and its impact are available at the provided link. No bug bounty payout amount is mentioned in the content. |
| 2026-07-06 | Veeam Backup BinaryFormatter Flaw Enables Remote Code Execution | Veeam Backup BinaryFormatter Flaw Enables Remote Code Execution https://ift.tt/XzVLFtl |
| 2026-07-06 | Microsoft Edge Multiple Vulnerabilities | Writeup of multiple Microsoft Edge vulnerabilities, including CVE-2026-13774 through CVE-2026-14156 and CVE-2026-45488 through CVE-2026-58300. These issues could allow remote attackers to achieve remote code execution, denial of service, information disclosure, security restriction bypass, data manipulation, and spoofing. Users should update to Microsoft Edge version 150.0.4078.48 or later to mitigate these risks. |
Supply Chain +24
| Date | Resource | Summary |
|---|---|---|
| 2026-07-12 | Software Supply Chain Attack Highlights Growing Demand for Preemptive Package Security | A recent software supply chain attack has underscored the increasing need for preemptive security in package management. These attacks target the dependencies that software relies on, introducing malicious code into legitimate applications. This incident highlights the vulnerabilities inherent in interconnected development environments and emphasizes the growing demand for robust solutions that can identify and mitigate risks *before* they impact end-users. Organizations are realizing the critical importance of securing their software supply chains to prevent widespread compromise. |
| 2026-07-12 | Ghostcommit: Multimodal Prompt Injection Attack Exposes AI Code Review Tools to Supply Chain Risks | A new multimodal prompt injection attack, dubbed "Ghostcommit," targets AI code review tools, posing significant supply chain risks. This attack leverages the AI's ability to process both text and image inputs. By embedding malicious prompts within images, attackers can trick AI code reviewers into accepting vulnerable code or even executing arbitrary commands. This bypasses traditional security checks and injects compromised code into development pipelines, potentially leading to widespread system compromise. The research highlights a critical vulnerability in how AI models handle mixed-media inputs, demanding urgent attention from developers of AI-powered security solutions. |
| 2026-07-12 | Compromised jscrambler 8.14.0 npm Release Runs Hidden Platform-Specific Binary During Install | The jscrambler npm package version 8.14.0 was found to be compromised. During installation, it secretly executed a platform-specific binary. This binary's purpose and potential impact are currently unclear. Users who have installed this version are advised to uninstall it immediately and review their systems for any suspicious activity. Further investigation is ongoing to determine the full extent of the compromise and its implications. |
| 2026-07-11 | New Trojan Turns Visual Studio Projects Into a Software Supply Chain Attack Vector | A new Trojan has been discovered that exploits Visual Studio projects, turning them into a potent software supply chain attack vector. This malicious code can infiltrate development environments, allowing attackers to compromise legitimate software builds. The ultimate impact is the potential for widespread distribution of malware through trusted software updates. |
| 2026-07-10 | Injective Labs SDK npm package compromised to steal cryptocurrency keys | Library for detecting supply-chain attacks like the compromise of the @injectivelabs/sdk-ts npm package. Hackers injected malicious code into version 1.20.21 of the package, which was downloaded 310 times, to steal cryptocurrency private keys and mnemonic seed phrases. The malware targeted functions for generating or importing wallet keys, exfiltrating captured data via HTTP POST requests. This incident highlights the risk to applications built with cryptocurrency wallets, trading bots, decentralized exchanges, and DeFi applications. |
| 2026-07-10 | Hackers tried to backdoor Injective npm package to steal wallet keys | Malicious actors attempted to compromise the Injective npm package, a crucial component for developers building on the Injective blockchain. The attackers aimed to inject malicious code into the package to steal users' private wallet keys. This incident highlights the ongoing threats to the cryptocurrency ecosystem and the importance of robust security measures for open-source software. Further details on the specifics of the attack and its prevention are likely to be found in the linked article. |
| 2026-07-10 | Injective software package hit by malicious supply chain attack | Library for building Injective applications, compromised via a malicious supply chain attack on the `@injectivelabs/sdk-ts` package (v1.20.21) published to npm. Attackers gained access to a contributor's GitHub account to push malicious commits and, under the guise of telemetry, uploaded a backdoor that stole developers' private keys and mnemonic seed phrases when using `fromMnemonic` or `fromHex` wallet generation functions. The attack spread through transitive dependencies in 17 additional Injective packages. |
| 2026-07-10 | Turning software supply chain security into a daily habit | Guide on operationalizing software supply chain risk, arguing for daily use of SBOMs beyond compliance for vulnerability triage, vendor access reviews, identity monitoring, and incident response. It draws on Group-IB’s High-Tech Crime Trend Report 2026 to illustrate how supply chain attacks link phishing, ransomware, and data breaches through inherited trust. The guide details prioritizing exposed systems, defining compromise windows, containing stolen credentials, and vendor risk scoring, highlighting AI's acceleration of attack timelines. |
| 2026-07-10 | Xsnow "protestware" in Debian | Writeup detailing the "protestware" controversy surrounding the Xsnow application in Debian. The entry discusses how Xsnow's maintainer included a feature that displayed Ukrainian flags when the application's language was set to Russian. This triggered a debate on the Debian development list regarding potential violations of the Debian Free Software Guidelines (DFSG), specifically concerning discrimination. While Xsnow itself was deemed DFSG-compliant, the discussion highlighted concerns about software exhibiting deceptive behavior based on user settings. |
| 2026-07-10 | Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry | Writeup detailing a malicious release of `@injectivelabs/sdk-ts` version 1.20.21, which exfiltrated wallet mnemonics and private keys by masquerading as telemetry. The compromised package subtly injected code into `PrivateKey.fromMnemonic` and `PrivateKey.fromHex` to capture sensitive data and send it to an attacker-controlled endpoint disguised as normal gRPC-web traffic. The attack also involved republishing 17 other `@injectivelabs` packages with a hard dependency on the poisoned SDK, highlighting the risks of transitive dependencies. |
| 2026-07-10 | Securing supply chains from network-based threats | Library for securing supply chains from network-based threats, focusing on visibility, control, and resilience. It details proactive vendor assessment, continuous monitoring, behavior-based endpoint protection, and managed hosting with robust access controls. Specific measures include regular audits of third-party partners against standards like ISO and GDPR, adopting least-privilege access, network segmentation, intrusion detection systems, and mandatory multi-factor authentication. The library also emphasizes the importance of enterprise-grade email security with behavioral detection, DNS filtering, web protection, and modern endpoint solutions leveraging machine learning and analytics for zero-day exploit detection. Continuous security awareness training is highlighted as crucial for strengthening the human element. |
| 2026-07-10 | Hackers tried to backdoor Injective npm package to steal wallet keys | Writeup on a supply chain attack targeting the Injective npm package `@injectivelabs/sdk-ts`. Version 1.20.21 was compromised through a malicious commit on a developer's GitHub account, leading to the exfiltration of private keys and seed phrases via fake telemetry. This attack vector, which bypasses traditional blockchain security, underscores the risks associated with compromised developer tools, impacting users who may not have installed the affected SDK directly. The malicious code has since been removed and affected versions deprecated. |
| 2026-07-10 | Hackers attempt to backdoor Injective npm package to steal wallet keys | Library providing security analysis of Injective Labs' TypeScript SDK, detailing a supply chain attack where malicious code was pushed to npm, specifically version 1.20.21. Attackers aimed to steal crypto wallet keys and mnemonics by hooking wallet creation functions, exfiltrating data to an obfuscated endpoint. The attack compromised 18 packages before being reversed, affecting ~50,000 weekly downloads and 87 dependent packages. Developers are advised to upgrade to version 1.20.23 and treat any processed credentials as compromised. |
| 2026-07-09 | Active Exploitation Alert: Prompt Injection Vulnerability in GitHub Agentic Workflows Threatens Software Supply Chain Security | Analysis of prompt injection attacks targeting GitHub agentic workflows, affecting tools like GitHub Copilot, Google Gemini CLI, and Anthropic Claude Code. These attacks, demonstrated in campaigns like GhostAction and the NX Build System compromise, leverage CWE-1427 (Improper Neutralization of Untrusted Input for LLM Prompting) and MITRE ATT&CK T1677 (Poisoned Pipeline Execution) to steal credentials, execute arbitrary code, and modify repositories, impacting software supply chain security. |
| 2026-07-08 | North Korea Expands the Reach of PolinRider Supply Chain Attack Campaign | Analysis of the PolinRider supply chain attack campaign, attributed to North Korean groups Famous Chollima and APT37. This ongoing campaign, targeting open source ecosystems like npm, Packagist, Go modules, and the Chrome Store, utilizes obfuscated JavaScript loaders hidden within malicious packages and browser extensions. Attackers leverage techniques such as whitespace padding, deceptive .woff2 font files, VS Code task files, and Git history rewriting to compromise developer accounts and repositories. Subsequent payloads, including DEV#POPPER RAT and OmniStealer, are fetched from blockchain and RPC infrastructure, aiming to steal credentials, exfiltrate source code, and achieve lateral movement within organizations. |
| 2026-07-08 | npm v12 Ships This Month Blocking Install Scripts That Enabled Year of Supply Chain Attacks | Library for securing npm package installations, npm v12 introduces a significant security redesign by defaulting to blocking install scripts. This prevents arbitrary code execution from dependencies, a long-standing vulnerability exploited in supply chain attacks like Shai-Hulud and campaigns targeting Axios and Mastra AI. The new allowlist model requires explicit inclusion of packages authorized to run scripts, with changes version-controlled in source code and auditable in pull requests. It also addresses risks from Git dependencies and binding.gyp files, moving from implicit trust to explicit allowlisting as the default security posture. |
| 2026-07-08 | GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail | Library detailing GitLost, a prompt injection vulnerability in GitHub's Agentic Workflows. An unauthenticated attacker can exploit GitLost by posting a crafted GitHub Issue in a public repository, tricking the AI agent into leaking private repository contents. The vulnerability arises from treating user-controlled content as trusted instruction input, bypassing guardrails like the "Additionally" keyword, allowing unauthorized access to files such as README.md from private repositories within the same organization. |
| 2026-07-07 | Sophos Flags Vect-TeamPCP Cybercriminal Ransomware Alliance | Alliance between ransomware-as-a-service group Vect and credential theft specialist TeamPCP represents a significant evolution in cybercrime, combining TeamPCP's expertise in supply chain compromise and harvesting credentials from tools like Trivy and Checkmarx with Vect's RaaS infrastructure. This partnership, confirmed by Sophos, creates an efficient attack pipeline enabling rapid ransomware deployment, lowering the barrier for less skilled attackers and accelerating campaign sophistication. |
| 2026-07-07 | Software transparency becomes cyber-security priority | Survey of software supply chain security trends, highlighting the accelerated adoption of Software Bills of Materials (SBOMs) driven by upcoming EU Cyber Resilience Act (CRA) regulations. This shift moves beyond traditional vulnerability management to prioritize full transparency of software components, including open-source libraries and third-party dependencies, to better identify risks and respond to emerging threats before the CRA's December 2027 effective date. |
| 2026-07-06 | North Korean PolinRider supply chain attack targets 108 unique repos | Analysis of the PolinRider supply chain attack, linked to North Korea's Lazarus group, details how adversaries compromise maintainer accounts across 108 unique open-source repositories. The attack injects obfuscated code into trusted packages, with a hidden loader retrieving payloads from blockchain infrastructure to install remote-access trojans and information stealers. This campaign targets developer secrets, cloud tokens, and cryptocurrency wallets, expanding beyond npm to ecosystems like Go modules and Packagist. |
| 2026-07-06 | North Korean Hackers Target Open Source Developers in Supply Chain Attacks | Analysis of PolinRider, a North Korean supply chain campaign targeting open source developers since December 2025. The operation injects JavaScript loaders into compromised GitHub repositories, distributing the DEV#POPPER RAT and OmniStealer. Attacked ecosystems include NPM, Packagist, Go modules, and Chrome extensions, with over 160 malicious artifacts identified. This campaign, linked to Contagious Interview operations, relies on tampering with maintainer accounts and Git history rewriting to disguise malicious code. Affected environments and credentials should be treated as compromised and remediation performed from a clean system. |
| 2026-07-06 | npm Supply Chain Attack: North Korea Hits Mastra AI [2026] | Analysis of the @mastra npm supply chain attack reveals North Korea's Sapphire Sleet (BlueNoroff, APT38) compromised over 140 packages via a stolen maintainer account. The attackers leveraged a typosquatted dependency, `easy-day-js`, within a `postinstall` script to inject malware. This implant disabled TLS verification, contacted C2 infrastructure, deployed a persistent implant, and targeted cryptocurrency wallets like MetaMask, Phantom, and Coinbase Wallet, along with cloud credentials, demonstrating a significant maturation in nation-state-sponsored open-source malware campaigns. |
| 2026-07-06 | Supply Chain Attacks Have Become Self-Reinforcing | Supply chain attacks are increasingly self-reinforcing, creating a vicious cycle. Attackers exploit vulnerabilities in one component, which then compromises others down the chain. This means a single breach can have cascading effects, impacting numerous downstream systems and organizations. The interconnectedness of modern software and infrastructure amplifies this problem, making it harder to detect and mitigate these sophisticated threats. |
| 2026-07-06 | FBI warns developers over TeamPCP software supply chain attacks | The FBI has issued a warning to developers regarding software supply chain attacks involving the TeamPCP tool. These attacks exploit vulnerabilities within the development process to compromise software. While the provided content does not mention a specific bug bounty payout amount, the alert highlights the significant threat posed by these sophisticated attacks to the integrity of software and the security of end-users. Developers are urged to implement robust security measures to mitigate these risks. |
AI +23
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | HalluSquatting Turns AI Hallucinations Into Botnet Delivery Mechanism | Technique detailing HalluSquatting, an attack that leverages AI hallucinations to deliver botnets at scale. This untargeted promptware method exploits AI applications by pre-registering fake repository or package names that LLMs commonly invent. When users ask AI tools like Cursor, GitHub Copilot, or Gemini CLI to fetch resources, the AI may hallucinate a squatted name, download malicious instructions, and execute them via the built-in terminal, leading to the deployment of malware and the creation of agentic botnets. |
| 2026-07-11 | Researchers hid a prompt injection inside a PNG and AI fell for it | Technique for prompt injection via image files that targets AI coding assistants like Claude. Researchers demonstrated hiding malicious instructions within a PNG image, which AI review tools often overlook. These hidden commands can later trigger AI assistants to access sensitive project files and exfiltrate data, disguised as legitimate code. The vulnerability's manifestation varies depending on the specific coding assistant used, emphasizing the need for multimodal AI review that scrutinizes all asset types. |
| 2026-07-11 | 'Ghostcommit' hides prompt injection in images to fool AI agents steal secrets | Writeup on Ghostcommit, an attack technique that hides prompt injection within PNG images to bypass AI code reviewers and steal repository secrets. Researchers demonstrated how a malicious instruction embedded in an image file referenced by an AGENTS.md document could trick AI agents like Cursor with Claude Sonnet into exfiltrating sensitive data from .env files. This exploit leverages the current blind spot where AI code reviewers often skip image analysis, unlike proposed multimodal defenders. |
| 2026-07-11 | Shadow AI is Your New Attack Surface | Analysis of "Shadow AI" highlights how unmanaged AI systems, adopted by employees for efficiency, create significant security risks. These "Shadow AI" deployments bypass traditional security controls and introduce new attack vectors such as data poisoning, prompt injection, third-party AI supply chain risk, and credential exposure, exemplified by the Samsung incident in March 2024. Addressing this emergent threat requires integrating AI governance and cybersecurity functions, focusing on visibility, accountability, AI-specific controls, and expertise investment. |
| 2026-07-11 | How to Use AI Browsers Without Getting Hacked | Guide to using AI browsers like Perplexity Comet, ChatGPT Atlas, and Dia securely, highlighting risks such as prompt injection, unauthorized account access, and data leakage. It details vulnerabilities including CometJacking and Cross-Site Request Forgery (CSRF) affecting Atlas, and advises disabling data sharing for model training, restricting agent access to logged-in sessions, and utilizing incognito mode for sensitive tasks to mitigate these threats. |
| 2026-07-11 | New hack exploits AI hallucinations to trick agents into running malicious code 'HalluSquatting' attack exploits a fundamental weakness in every available model | Writeup of the HalluSquatting attack, an exploit leveraging AI hallucinations to trick agentic AI models like Claude into executing malicious code from fake GitHub repositories. This technique exploits the non-deterministic nature of LLMs, causing them to generate plausible but nonexistent repository names, which attackers then register. Successful exploitation can lead to reverse shells, data exfiltration, and further system compromise, affecting models such as Claude Opus 4.5 and applications like Cursor and Copilot. |
| 2026-07-11 | Designing for the inevitable: System prompt leakage and mitigations in generative AI applications | Library for defending against system prompt leakage in generative AI applications. This resource addresses LLM07, a top vulnerability where attackers use prompt injection to extract an application's system prompt, potentially revealing proprietary information and tool definitions. It emphasizes that full remediation is not currently possible, advocating for design principles that assume leaks will occur and implementing mitigation controls like Amazon Bedrock Guardrails' prompt attack filters to reduce exposure and increase extraction difficulty. |
| 2026-07-11 | AI agents fall for indirect prompt injection traps | Analysis of indirect prompt injection (IPI) traps reveals vulnerabilities in AI agents, with specific models like Llama3-3-70b-instruct, Llama3-2-90b-instruct, Gemini-3-flash, and Gemini-2.5-pro exhibiting susceptibility. This research highlights how hidden instructions embedded in websites can manipulate AI behavior, leading to scams that human users would typically avoid. The attack surface is expanding as AI agents interact more with the web, necessitating architectural rather than purely behavioral defenses, as traditional enterprise security models struggle to address these novel threats. |
| 2026-07-11 | When AI Agents Attack: Autonomous Cyber Operations and Europes Governance Gap | Analysis of autonomous AI agent operations reveals evolving cybersecurity threats and governance gaps. The emergence of platforms like Moltbook, where millions of AI agents interact, highlights risks from data leaks (API authentication tokens) and the difficulty of tracing accountability. Major AI models like Anthropic's Claude, capable of identifying and exploiting zero-day vulnerabilities across operating systems and browsers, demonstrate the blurring line between AI-assisted operations and autonomous cyber capabilities. The EU faces challenges adapting its governance frameworks to address these rapidly evolving, agentic AI risks, particularly given its dependence on U.S. AI infrastructure. |
| 2026-07-11 | Can AI-generated adversaries break TTP-based attribution? (arXiv 2026) | This research explores whether AI-generated adversaries can evade TTP-based attribution methods. The study, "Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)," investigates the effectiveness of current attribution techniques against sophisticated, AI-driven attackers. It analyzes how advanced AI might mimic or alter Tactics, Techniques, and Procedures (TTPs) to mislead security systems and prevent the identification of the true attacker. The paper aims to understand the potential vulnerabilities in attribution models when faced with AI-powered threats and suggests future directions for developing more robust attribution systems. |
| 2026-07-11 | A way to exclude sensitive files issue still open for OpenAI Codex | Library of proposed features for OpenAI Codex, addressing the exclusion of sensitive files and paths from model analysis. This includes a mechanism for both repository-local and global ignore files, akin to `.codexignore`, to prevent the exposure of sensitive data such as `.env` files, `.pem` certificates, and `.ssh` directories, while still allowing analysis of others like `node_modules/`. The goal is deterministic and shareable configurations for team-wide consistency, building on prior discussions and aiming to rectify a gap in the current `codex-rs` implementation. |
| 2026-07-10 | Hackers can use 9 of the most popular AI tools to assemble massive botnets | Library for mitigating prompt injection vulnerabilities in AI assistants. HalluSquatting, a novel pull-based attack, exploits LLMs' tendency to hallucinate resource identifiers, enabling the assembly of massive botnets and large-scale device infections. This technique targets AI coding assistants like Cursor, Gemini CLI, GitHub Copilot, and others by registering predicted hallucinated identifiers and seeding them with malicious payloads. |
| 2026-07-10 | CrowdStrike identifies five new prompt injection threats to AI | Analysis of five new prompt injection threats identified by CrowdStrike against AI systems. These techniques include Trigger-Activated Rule Addition, Cognitive Token Suppression, Algorithmic Payload Decomposition, Special Token Injection, and Unwitting User Context-Data Injection, which exploit LLMs by tricking them into accepting dubious instructions disguised as benign input. Security teams can counter these attacks through threat modeling, expanded testing, and detection engineering for composite attacks. |
| 2026-07-10 | Claude Code is steganographically marking requests | Analysis of Claude Code reveals prompt steganography used to mark requests. The application locally alters the system prompt by subtly changing date separators or apostrophes, embedding classification data about API base URLs and system timezones. This technique, triggered by the `ANTHROPIC_BASE_URL` environment variable and specific geographical timezones, aims to detect API resellers and unauthorized gateways. While not malicious, the hidden implementation of this classification mechanism undermines trust in a tool with extensive filesystem and shell access. |
| 2026-07-10 | Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) | Library detailing symlink attacks, a decades-old vulnerability vector enabling arbitrary file access and RCE. These attacks leverage symbolic links, small files containing paths that, when opened by a program, redirect to another location. Git's support for committing symlinks allows attackers to ship them in repositories, posing risks to build scripts, editors, and AI agents that process files without proper path resolution. The library highlights historical examples like CVE-2021-32803, Zip Slip, CVE-2024-21626, and CVE-2024-32002, alongside modern instances in Incus, emphasizing the need to resolve paths atomically before operation. |
| 2026-07-09 | GhostApproval: A Trust Boundary Gap in AI Coding Assistants | Library for detecting GhostApproval, a trust boundary gap vulnerability in AI coding assistants affecting Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This vulnerability exploits symlink following (CWE-61) and UI misrepresentation (CWE-451), allowing malicious repositories to trick agents into writing to arbitrary files outside the workspace, potentially leading to remote code execution by concealing the true target from the user during confirmation prompts. |
| 2026-07-09 | Secure AI Workflows: The Identity and Access Management (IAM) Checklist | Checklist for securing AI workflows, focusing on Identity and Access Management (IAM) for both human-assisted AI (e.g., Claude Code, Cursor via MCP) and autonomous agents in CI/CD. It details an 8-point roadmap, including disabling anonymous access, using vetted MCP servers, employing restricted scoped tokens with downscoping, dynamic permission validation, audit log visibility via custom user-agent headers, composite identities for agents, restricting write operations (e.g., pull requests), and enforcing deterministic infrastructure-level IAM policies to prevent prompt injection attacks against production databases. The checklist principles apply broadly, though examples are from the JFrog Platform. |
| 2026-07-09 | Cracking Firmware with Claude: Senior-Level Skill, Junior-Level Autonomy | Library for AI-assisted firmware analysis, demonstrating Claude Code's ability to reverse-engineer proprietary SonicWall SWI encryption. This AI independently traced decryption logic through a decompiled binary, located a key within a HashiCorp Vault instance, reconstructed its master key from Shamir secret shares, and recovered an RSA private key. The process highlights senior-level technical knowledge combined with junior-level autonomy, requiring human guidance for strategic pivots and verification. |
| 2026-07-08 | What is Prompt Injection? How it Works and How to Prevent It | Library for understanding and defending against prompt injection attacks, a top risk for LLM Applications, including techniques like EchoLeak (CVE-2025-32711) impacting Microsoft 365 Copilot and the OWASP LLM Top 10 designation. It details how instruction-overriding, natural-language-based, model-agnostic, and hard-to-eliminate attacks work, differentiating them from jailbreaking, and covers risks such as data theft and remote code execution. The library also explores methods to reduce this threat in connected systems and agentic AI. |
| 2026-07-08 | Beyond Tokens SF: Best Ideas of the Evening | Library for building secure and efficient AI agents, tackling challenges like token waste, context evaporation, and insecure infrastructure. It introduces JFrog Fly for managing release context and decision records, JFrog Boost for reducing token costs by filtering noise and preventing inefficient search, and NanoClaw for agent isolation, credential security, and human-in-the-loop approvals. These tools enable agents to operate autonomously with increased speed, trustworthiness, and reduced expenditure. |
| 2026-07-08 | New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis | Library written in Rust, codenamed Gaslight, targets macOS and functions as an information stealer. It employs prompt injection against AI-assisted analysis tools by embedding fabricated system failure messages designed to deceive LLM triage agents into aborting analysis. Gaslight uses a Telegram bot API for its command-and-control channel, supports commands for remote execution, file exfiltration, and process termination, and employs a LaunchAgent for persistence. An embedded Python script gathers sensitive data from browsers and system processes, while a Bash installer deploys a Python interpreter from the "astral-sh/python-build-standalone" project. Operator configuration, including the Telegram bot token, is provided at runtime, and the malware self-redacts tokens from logs to further evade detection. |
| 2026-07-07 | Beyond Prompt Injection | Library for verifying generative AI agent actions, shifting security from input filtering to deterministic policy enforcement. It emphasizes validating agent proposals against external, auditable rules before execution, rather than attempting to prevent prompt injection at the model level. This approach addresses risks like indirect prompt injection and data exfiltration demonstrated in scenarios such as the ForcedLeak vulnerability in Salesforce's Agentforce platform, moving security decisions to a place where adversaries have limited freedom. |
| 2026-07-07 | 8 Best Agentic AI Security Companies for Prompt Injection & Secret Sprawl Defense | Library for agentic AI security vendors, this resource spotlights eight companies providing guardrails against prompt injection and secret sprawl, including Entro Security for identity governance and secret scanning, Palo Alto Networks for extending SOC visibility, Trend Micro Vision One with DLP capabilities, and Noma Security offering a control plane with a self-driving red team. The selection process involved mapping the market, applying strict inclusion rules, and scoring vendors on criteria such as prompt-injection defense, data-leak prevention, and real-time detection, prioritizing those proven in live environments. |
SSRF +17
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | ZOWEH: XXE LAB SOLVED: Exploiting XXE to perform SSRF attacks Goal: Use XXE to access AWS metadata endpoint Method: External entity pointing to #XXE #SSRF | This content details the successful exploitation of an XML External Entity (XXE) vulnerability to perform a Server-Side Request Forgery (SSRF) attack. The objective was to access the AWS metadata endpoint. The method involved utilizing an external entity to achieve this. The provided link points to further information on this XXE and SSRF exploit. No bug bounty payout amount is mentioned. |
| 2026-07-10 | Sudarshana: Cornered a headless PDF export that fetched user URLs. Pointed it at 169.254.169.254/latest/meta-data/iam/security-credentials/ and it echoed a role's temp keys. IMDSv2 blocks this: no PUT token no answer. Allowlist the hosts you call denylists miss the IP. #SSRF #IMDSv2 | A security researcher, Sudarshana, discovered a Server-Side Request Forgery (SSRF) vulnerability in a headless PDF export. By directing the export to a specific AWS IMDSv2 endpoint (169.254.169.254/latest/meta-data/iam/security-credentials/), they successfully retrieved temporary AWS credentials. The researcher notes that IMDSv2's default configuration, which requires a PUT token, prevents this exploitation. They recommend using host allowlists rather than denylists to mitigate such vulnerabilities, as denylists may miss specific IPs. |
| 2026-07-10 | Daily CyberSecurity: Four Apache Camel vulnerabilities allow header injection server-side request forgery secret disclosure and an authentication bypass. Patch to 4.21.0 now. #ApacheCamel #HeaderInjection #SSRF #CyberSecurity #Vulnerability #InfoSec | Four critical vulnerabilities have been discovered in Apache Camel, affecting versions prior to 4.21.0. These vulnerabilities enable header injection, server-side request forgery (SSRF), secret disclosure, and authentication bypass. Users are strongly advised to update to version 4.21.0 immediately to patch these security flaws and protect their systems. |
| 2026-07-10 | Roundcube Webmail 1.7.2 Fixes Zero-Click XSS SSRF Bypass and DoS Flaws | Roundcube Webmail 1.7.2 addresses critical security vulnerabilities, including a zero-click Cross-Site Scripting (XSS) flaw, a Server-Side Request Forgery (SSRF) bypass, and Denial of Service (DoS) issues. The update provides essential patches to protect users from these threats. |
| 2026-07-09 | Dev: SSRF: Your ticket to internal networks & cloud metadata! Misconfigs in web apps let you fetch backend resources. Check URL params API endpoints. Ffuf & Burp are your friends. Master it! #SSRF #BugBounty | This content explains Server-Side Request Forgery (SSRF) vulnerabilities. SSRF attacks exploit web application misconfigurations to allow attackers to access internal networks and cloud metadata by fetching backend resources. Key areas to investigate for SSRF include URL parameters and API endpoints. Tools like Ffuf and Burp Suite are recommended for identifying these vulnerabilities. The post encourages mastering SSRF for bug bounty hunting. No specific payout amount is mentioned. |
| 2026-07-09 | Daily CyberSecurity: Five Apache Camel vulnerabilities enable server-side request forgery and a Keycloak authentication bypass. Upgrade to 4.21.0 4.18.3 or 4.14.8. #ApacheCamel #SSRF #AuthBypass #Deserialization #Keycloak #InfoSec | Five vulnerabilities in Apache Camel have been disclosed, enabling server-side request forgery (SSRF) and an authentication bypass in Keycloak. Users are strongly advised to upgrade their Apache Camel installations to versions 4.21.0, 4.18.3, or 4.14.8 to mitigate these security risks. The vulnerabilities also involve deserialization flaws. |
| 2026-07-08 | Hugo | DevOps | Cybersecurity : #CVE-2026-57573 - #SSRF in #Crawl4AI #Docker #API. Streaming paths skip destination validation. Unauthenticated remote access to internal networks. #CVSS 8.6. No patch available. Mitigate immediately. #CVE #infosec #k8s #devops #devsecops #sysadmin #kubernetes | CVE-2026-57573 is a critical Server-Side Request Forgery (SSRF) vulnerability in the Crawl4AI Docker API. It allows unauthenticated remote attackers to access internal networks due to streaming paths skipping destination validation. With a CVSS score of 8.6, this vulnerability is severe. No patch is currently available, making immediate mitigation crucial for DevOps, cybersecurity, and system administration professionals. |
| 2026-07-08 | Graven - Herald.codes: Hello tout le monde ! Nouvelle video Nouveau format #ssrf #owasp #python | This content announces a new video from Graven - Herald.codes in a new format, focusing on Server-Side Request Forgery (SSRF), OWASP, and Python. The post includes a link to the video. No bug bounty payout amounts are mentioned. |
| 2026-07-08 | Daily CyberSecurity: New pretix vulnerabilities include a critical session takeover chain (CVE-2026-13602) and an SSRF API key leak. Update to 2026.5.3 now. #pretix #SessionTakeover #SSRF #CyberSecurity #CVE202613602 #CVE202613603 | Pretix has released version 2026.5.3 to address two critical vulnerabilities. CVE-2026-13602 is a session takeover chain, and another vulnerability allows for an SSRF API key leak. Users are urged to update immediately to mitigate these security risks. |
| 2026-07-08 | The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration. | Writeup detailing an HTTP 303 SSRF vulnerability that escalates to AWS credential exfiltration. This exploit chains a user-controlled `token_uri` field in BigQuery service account credentials, an HTTP client with default redirect handling, and the AWS Instance Metadata Service (IMDS). By configuring a server to respond with an HTTP 303 redirect, a POST request to IMDS is implicitly converted to a GET request, allowing the attacker to retrieve temporary IAM credentials for the Kubernetes worker node. |
| 2026-07-07 | InfoSec Community: New Writeup Alert! "The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration." by Alvin Ferdiansyah is now live on IW! Check it out here: #oauth #python #ssrf #bugbountywriteup | Alvin Ferdiansyah's new writeup, "The HTTP 303 SSRF Hack: From Python HTTP Client Defaults to AWS Credential Exfiltration," is now available. The analysis explores how default Python HTTP client behaviors can lead to SSRF vulnerabilities, ultimately enabling AWS credential exfiltration. This bug bounty writeup is a valuable resource for those interested in OAuth, Python security, and SSRF exploit techniques. |
| 2026-07-06 | Daily CyberSecurity: Four Fluentd vulnerabilities are fixed in v1.19.3 including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now. #Fluentd #RCE #SSRF #CVE #Cybersecurity #Infosec | Daily CyberSecurity: Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now. #Fluentd #RCE #SSRF #CVE #Cybersecurity #Infosec http... |
| 2026-07-06 | Daily CyberSecurity: HawkTrace publicly disclosed Microsoft Exchange vulnerability CVE-2026-45504 with PoC exploit code. The SSRF flaw reads arbitrary files. Patch now. #MicrosoftExchange #CVE202645504 #SSRF #Cybersecurity #PoC #Infosec | Daily CyberSecurity: HawkTrace publicly disclosed Microsoft Exchange vulnerability CVE-2026-45504 with PoC exploit code. The SSRF flaw reads arbitrary files. Patch now. #MicrosoftExchange #CVE20264550... |
| 2026-07-06 | Daily CyberSecurity: HawkTrace publicly disclosed Microsoft Exchange vulnerability CVE-2026-45504 with PoC exploit code. The SSRF flaw reads arbitrary files. Patch now. #MicrosoftExchange #CVE202645504 #SSRF #Cybersecurity #PoC #Infosec | Daily CyberSecurity: HawkTrace publicly disclosed Microsoft Exchange vulnerability CVE-2026-45504 with PoC exploit code. The SSRF flaw reads arbitrary files. Patch now. #MicrosoftExchange #CVE20264550... |
| 2026-07-05 | Tasfiul Hedayet: Alhamdulillah I have reported my 1st SSRF findings on @Hacker0x01 today 05.07.26 Thanks @ruh4nX bro Every valid finding boost your level and confidence. If bug exists then doesn't matter if it's out of scope. Report it mistakenly tested scope :3 #SSRF #Hacking | Tasfiul Hedayet has successfully reported their first Server-Side Request Forgery (SSRF) vulnerability on HackerOne. They encourage reporting bugs regardless of scope, as valid findings boost confidence and skill. This achievement was shared with thanks to @ruh4nX. The report was made on July 5, 2026. |
| 2026-07-05 | Hugo | DevOps | Cybersecurity : #CVE-2026-22874 - Critical #SSRF in #Gitea =1.26.2. Incomplete webhook/migration filtering. #CVSS 9.6. Upgrade immediately. #CVEAlert #DevSecOps #DevOps #sysadmin #infosec More free detailed info: | A critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-22874, has been discovered in Gitea version 1.26.2. The issue stems from incomplete filtering of webhooks and migrations, resulting in a high CVSS score of 9.6. Users are strongly advised to upgrade immediately to mitigate this security risk. This alert is part of ongoing cybersecurity and DevOps awareness efforts. |
| 2026-07-05 | CYBER MIND SPACE: Your firewall is useless... If your own server becomes the attacker. That's SSRF. #CyberSecurity #SSRF #AppSec | Server-Side Request Forgery (SSRF) is a critical cybersecurity vulnerability where an attacker exploits an application to make the server send requests to an unintended location. This bypasses firewalls, as the malicious request originates from within the trusted network. Attackers can use SSRF to access internal systems, cloud metadata, or even trigger actions on other servers. The content highlights that even with robust firewalls, an SSRF vulnerability can render them ineffective if the server itself becomes the attacker's tool. |
Bug Bounty +12
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | Anonymous GitHub account mass-dropping undisclosed 0-days | Archive of public proof-of-concept and vulnerability research writeups, including specific findings for c-ares-tcp-uaf-calc-poc, curl-smtp-expn-recipient-crlf-injection, discourse-scoped-api-key-preauth-bypass, and rustdesk-session-permission-pocs. The repository preserves original READMEs and tracked files from former standalone repositories, ensuring byte-for-byte identical content as verified by Git tree data. This collection aims to foster interest in cybersecurity vulnerability research and encourage ethical disclosure. |
| 2026-07-11 | PUMA live hacking event revisited: leHACK’s biggest Bug Bounty yet | leHACK's biggest Bug Bounty event, focused on PUMA, saw participants uncover numerous vulnerabilities. The event, which brought together ethical hackers and security researchers, aimed to identify and fix security flaws within PUMA's digital systems. The detailed analysis of the event highlights the significant findings and contributions made by the hacking community to enhance PUMA's cybersecurity posture. |
| 2026-07-10 | Why offensive security and exposure management can't stay siloed in the AI era | In the AI era, offensive security and exposure management must integrate. Traditional silos hinder proactive threat identification and mitigation. AI-powered tools can enhance both, offering deeper insights into vulnerabilities and potential attack vectors. Integrating these disciplines allows organizations to move beyond reactive security measures and build a more resilient defense against evolving cyber threats. This unified approach is crucial for effective risk management in a rapidly changing landscape. |
| 2026-07-10 | [tl;dr sec] #336 - Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked? | Library for automatically discovering and reproducing vulnerabilities, featuring improvements to Datadog's GuardDog 3.0 malware hunting tool. The entry also discusses the future of bug bounties in the age of AI, mentioning techniques for autonomous vulnerability hunting and the potential impact of frontier models on competition. It highlights security defaults for AWS Lambda Firecracker microVMs and Amazon's approach to AI governance, emphasizing end-to-end accountability. |
| 2026-07-08 | How LLMs are changing Bug Bounty: an interview with Icare | LLMs are revolutionizing bug bounty programs by enhancing vulnerability discovery and streamlining workflows. In an interview with Icare, it's highlighted how these AI tools can automate tasks, identify complex patterns, and even assist in report generation, leading to faster and more efficient bug hunting. This advancement allows researchers to focus on more sophisticated exploits. While specific payout amounts weren't mentioned, the overall sentiment is that LLMs are significantly boosting the effectiveness and potential of bug bounty programs. |
| 2026-07-07 | How I Found a Data Deletion Bypass via Subdomain Synchronization | Writeup detailing a business logic vulnerability bypass on interconnected subdomains. A Moderator role, lacking delete permissions on the primary account management subdomain, could initiate a full organizational group deletion by exploiting synchronization flaws in the secondary task scheduling subdomain. This allowed for a cascade deletion affecting both platforms, a privilege intended only for Admin or Owner roles. The discovery highlights how understanding application workflows and reading developer documentation can uncover critical security gaps. |
| 2026-07-07 | How I Found a Critical OAuth Misconfiguration That Led to Account Takeover | Writeup detailing an account takeover vulnerability found via chaining multiple OAuth misconfigurations. The exploit leveraged open client registration, an authorization endpoint lacking authentication enforcement, and PKCE validation weaknesses that allowed token exchanges without client secrets. Additionally, wildcard CORS expanded attack vectors, while Google SSO auto-provisioning provided context for user authentication. |
| 2026-07-07 | Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover | Writeup detailing Mass Assignment vulnerabilities that enable "identity drift" by allowing attackers to alter sensitive profile fields like legal name, date of birth, and government ID number without invalidating the verified status. This can lead to downstream impacts, such as falsely linking third-party insurance records by manipulating matching attributes like date of birth, effectively granting unauthorized financial access. |
| 2026-07-07 | Mastering curl Commands Bug Bounty Hunter's Guide | Guide to mastering curl commands for bug bounty hunting, focusing on advanced techniques beyond basic POST requests. It covers real-world workflows like fuzzing, WAF bypasses, pipeline automation, and creative exploitation. Specific examples include subdomain discovery using Certificate Transparency logs with `curl` and `jq`, and header fingerprinting to gather intelligence on target applications. |
| 2026-07-06 | TryHackMe — Bounty Hacker: The FTP Server Was Talking. I Just Listened. | Writeup detailing a TryHackMe room, "Bounty Hacker: The FTP Server Was Talking. I Just Listened." This walkthrough focuses on practical exploitation, starting with anonymous FTP access on port 21 to obtain a username (`lin`) and a password list (`locks.txt`). It then proceeds to use Hydra for an SSH brute-force attack against port 22, successfully gaining a user shell. Privilege escalation is achieved by leveraging `tar`'s `checkpoint-action` capability, as documented on GTFOBins, to execute commands as root and retrieve the final flag. |
| 2026-07-06 | Mr Robot CTF Walkthrough -TryHackMe Detailed | Library detailing a CTF walkthrough, starting with web enumeration via robots.txt to find `key-1-of-3.txt` and `fsocity.dic`. It then covers Nmap scans, Gobuster directory brute-forcing to discover WordPress, and exploiting a Base64-encoded string in the `/license` page's source for WordPress credentials. The entry explains obtaining a reverse shell through the WordPress Theme Editor, cracking an MD5 hash for the `robot` user, and performing privilege escalation by abusing the SUID bit on the `/usr/local/bin/nmap` binary to gain root access. |
| 2026-07-06 | TryHackMe CTF Writeup of Hidden Deep Into my Heart | Writeup detailing a TryHackMe CTF challenge involving web enumeration. The process begins with analyzing `robots.txt` and `sitemap.xml`, leading to the discovery of a hidden directory. The tool `gobuster` is then employed for further directory enumeration, uncovering an administrator login page. Exploitation involves identifying a password clue within the `robots.txt` comments and successfully logging in to retrieve the flag. |
XSS +8
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions | Library update addressing stored XSS in Zimbra Classic Web Client. Exploitation of this vulnerability allows attackers to inject and execute malicious JavaScript within user sessions via crafted emails, potentially leading to mailbox access, session data compromise, and account setting manipulation. This flaw, though unassigned a CVE, follows a history of XSS vulnerabilities in Zimbra, including CVE-2025-27915, CVE-2023-37580, and CVE-2024-27443. Users are advised to update to Zimbra Collaboration Suite version 10.1.19. |
| 2026-07-11 | Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails | Zimbra 10.1.19 addresses a stored cross-site scripting (XSS) vulnerability that could be exploited by sending specially crafted emails. This flaw allowed attackers to inject malicious scripts into the Zimbra web client, potentially leading to unauthorized actions or data theft by users who viewed the compromised email. The update rectifies this security weakness, enhancing the platform's safety. |
| 2026-07-10 | Roundcube Webmail Security Update Patches Critical Zero-Click XSS and SSRF Bypass Flaws | Roundcube Webmail has released a security update addressing critical zero-click vulnerabilities. These flaws allowed for Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF) bypasses, potentially enabling attackers to execute malicious code or access internal resources without user interaction. Users are strongly advised to update their Roundcube installations immediately to mitigate these risks. The update is crucial for protecting against potential exploitation of these severe security weaknesses. |
| 2026-07-09 | Roundcube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment | A critical 0-click vulnerability in Roundcube allows stored XSS attacks through specially crafted MIME type attachments. Attackers can exploit this by sending an email with an attachment having a malicious MIME type. When Roundcube processes this attachment, it renders the malicious content, leading to cross-site scripting execution within the victim's browser without any user interaction. This means sensitive data could be compromised or actions taken on behalf of the user. |
| 2026-07-08 | Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account… | Library for chaining DOM XSS, WAF bypass via `window.name` cross-origin smuggling, and SDK abuse to achieve one-click account takeover. The technique exploits a `javascript:` URL sink, bypasses Akamai's WAF by inserting characters between keywords and parentheses, leverages `window.name` persistence across navigations, and abuses a first-party authentication SDK to retrieve signed JWTs and live AWS STS credentials. |
| 2026-07-06 | Multiple IBM WebSphere Vulnerabilities Enable XSS and Path Traversal Attacks | Multiple vulnerabilities have been discovered in IBM WebSphere that could allow attackers to perform cross-site scripting (XSS) and path traversal attacks. These flaws impact various versions of the software, potentially exposing sensitive data and enabling malicious code execution. Organizations using IBM WebSphere should prioritize applying the latest security patches and updates to mitigate these risks. |
| 2026-07-06 | IBM WebSphere Application Server Hit by Critical XSS and Path Traversal Vulnerabilities | IBM WebSphere Application Server is affected by critical vulnerabilities. These include Cross-Site Scripting (XSS) and path traversal flaws. The XSS vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking or data theft. The path traversal vulnerability could enable unauthorized access to sensitive files and directories on the server. Organizations using IBM WebSphere Application Server should update to the latest secure versions to mitigate these risks. |
| 2026-07-06 | Critical IBM WebSphere Flaws Expose Servers to XSS and Path Traversal Attacks | Critical vulnerabilities have been discovered in IBM WebSphere Application Server, enabling attackers to execute Cross-Site Scripting (XSS) and path traversal attacks. These flaws could allow for unauthorized access to sensitive data and the execution of malicious code on vulnerable servers. Organizations utilizing IBM WebSphere are strongly advised to apply available security patches and updates to mitigate these risks and protect their environments. Further details on the specific vulnerabilities and remediation steps can be found at the provided link. |
API Security +6
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | How to keep an HTTP connection alive for 9 hours | Tool for managing CTF user accounts and notifications, built with Spring Boot, Spring Security, and WebFlux. It integrates with the CTFd API to create users, assign unique aliases, and manage email notifications, including handling API rate limits with robust retry mechanisms and supporting long-running bulk email processes using Server-Sent Events (SSE) for status updates. |
| 2026-07-10 | Your next insider threat doesnt have a badge. It has an API token | Library for securing AI agents, this resource addresses the evolving threat landscape where authorized AI agents, acting within their granted permissions, can cause breaches through sequences of seemingly benign actions. It details failure modes like tool-chain abuse, delegation-chain exploitation, and approval evasion, arguing that traditional security models focused on "who is allowed in" and "what data is allowed out" are insufficient for agentic systems. The library advocates for a runtime policy engine to govern agent actions at the moment they occur, ensuring authority shrinks during delegation and that audit logs serve as immutable evidence. |
| 2026-07-07 | Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious Code | A critical vulnerability has been discovered in Google Cloud Platform's Dialogflow that allows attackers to inject malicious code. This flaw could enable unauthorized access and manipulation of sensitive data within applications built on Dialogflow. The exact payout amount for reporting this vulnerability is not specified in the provided content. |
| 2026-07-07 | Gemini Live API Flaw Lets Attackers Inject Code Execution Through Unconstrained Tokens | A critical flaw in the Gemini Live API allowed attackers to achieve code execution by injecting unconstrained tokens. This vulnerability, identified by researchers, could have enabled malicious actors to compromise systems. The specific bounty payout for this discovery is not mentioned in the provided content. |
| 2026-07-07 | Chasing Zero-Day Vulnerabilities via the Anchore Enterprise API | This content, titled "Chasing Zero-Day Vulnerabilities via the Anchore Enterprise API," suggests a focus on identifying previously unknown (zero-day) security flaws within the Anchore Enterprise API. The provided link likely leads to a detailed explanation or demonstration of techniques used for this pursuit. The core theme revolves around proactive vulnerability research and the exploitation of a specific API for discovering critical security issues. No bug bounty payout amount is mentioned. |
| 2026-07-06 | JuiceFS Authentication Bypass via pprof and metrics Endpoints (CVE-2026-59092) | Writeup detailing CVE-2026-59092, an authentication bypass in JuiceFS (versions prior to 1.3.1) that exploits improper handler registration on `http.DefaultServeMux`. Attackers can access sensitive debug and metrics endpoints, including `/debug/pprof/cmdline`, to retrieve database credentials embedded in the process command line, leading to full read/write access to filesystem metadata. Other pprof handlers may reveal internal state or enable denial of service. |
Secrets +3
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | Show HN: Bramble – Local-first password manager | Library for local-first password management, Bramble offers Chromium browser extensions, and iOS/Android apps that sync vaults peer-to-peer. It uses a Rust crypto core for Argon2id key derivation and AES-256-GCM encryption, with secrets wiped from memory post-use. Bramble supports passkeys, smart autofill, TOTP codes, and encrypted backups to local files or future cloud storage providers. It contrasts with cloud-based managers by ensuring vaults remain on user devices, eliminating a central breach target. Unlock options include master password, hardware keys, biometrics, or a recovery code. |
| 2026-07-10 | Inside an AI coal mine security camera network powered by plaintext passwords | Writeup of plaintext password vulnerability in Coal India's AI security camera network, exposing the "RPI Dashboard" developed by DeepSight AI Labs. The analysis details how an unauthenticated API call to `get_users` revealed an entire user list with weak, duplicated passwords, and how local storage manipulation could bypass authentication to access the alert dashboard across seven coal mines, a flaw later confirmed fixed by CERT-IN. |
| 2026-07-08 | Every Laptop Is a Credential Store: Where Secrets Hide | Reference mapping credential locations on developer laptops; highlights shell history, environment files, cloud credential files like `~/.aws/credentials`, SSH keys, package registry tokens, AI agent caches, browser storage, and structured file exports. Discusses how traditional scanners miss these plaintext or configuration-based secrets, which are prime targets for infostealer malware and cloud credential theft. |
SQLi +3
| Date | Resource | Summary |
|---|---|---|
| 2026-07-10 | Django SQL Injection Vulnerability Actively Exploited in the Wild | A critical SQL injection vulnerability in Django is currently being exploited in the wild. This vulnerability affects Django versions 3.2.x prior to 3.2.18, 4.0.x prior to 4.0.7, and 4.1.x prior to 4.1.1. The exploit targets specific database queries that can be manipulated to gain unauthorized access or execute malicious commands. Users are strongly advised to update to the patched versions immediately to mitigate this risk. No specific bounty payout amount was mentioned in the provided content. |
| 2026-07-07 | Ubiquiti Disclosed 25 Security Vulnerabilities Including Injection and DoS Flaws | Ubiquiti has disclosed 25 security vulnerabilities affecting various products, including injection and denial-of-service (DoS) flaws. The specific details and affected products were not elaborated upon in the provided information, beyond the general categories of vulnerabilities. This disclosure highlights potential security risks for users of Ubiquiti devices. No bug bounty payout amounts were mentioned. |
| 2026-07-06 | SourceCodester Timetabling: SQL Injection vulnerability CVE-2026-14770 | A SQL injection vulnerability, identified as CVE-2026-14770, has been discovered in SourceCodester Timetabling. This flaw allows attackers to potentially execute arbitrary SQL commands on the database. Further details regarding the exploit and its impact can be found at the provided link. No bug bounty payout amount was specified in the content. |
Recon +2
| Date | Resource | Summary |
|---|---|---|
| 2026-07-12 | Scanning malicious websites with arbitrary number of VPN tunnels (Part 2) | This document, Part 2 of "Scanning malicious websites with arbitrary number of VPN tunnels," likely details advanced techniques for identifying malicious websites by leveraging multiple VPN tunnels. It probably explores methods to bypass security measures and gather intelligence on threats, potentially by obfuscating the origin of scanning activity. The focus is on a technical approach to enhance the detection and analysis of harmful online content through sophisticated network routing. |
| 2026-07-06 | AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation | Library for CTI-to-detection workflow automation, AdversaryGraph v5.0 enhances attack simulation and SIEM validation. It integrates threat intelligence analysis, MITRE ATT&CK mapping, IOC enrichment, malware analysis, attack-surface mapping, and AI-assisted reporting. New in v5.0, the Attack Simulation module allows analysts to run controlled lab scenarios based on TTPs, inspect target telemetry, forward logs to a SIEM collector, and utilize an AI assistant for multi-phase attack chain drills, directly linking observed behaviors to detection engineering. |
OSINT +2
| Date | Resource | Summary |
|---|---|---|
| 2026-07-11 | Show HN: Osint tool that finds exposed files on domains | This "Show HN" post introduces an OSINT tool designed to discover exposed files on various domains. The tool aids in identifying potentially sensitive information that might be unintentionally accessible via websites. No bug bounty payout amount is mentioned in the provided content. |
| 2026-07-06 | The Internet’s Dirty Little Secret: Anyone Can Investigate Anyone — and Here Are 20 Free Tools to… | Tools for OSINT investigations, offering 20 free online resources that allow individuals to legally gather information on anyone. These platforms enable users to conduct digital investigations comparable to those used by professionals and intelligence agencies, focusing on publicly available data. |
AuthZ +2
| Date | Resource | Summary |
|---|---|---|
| 2026-07-08 | BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025 | Library for exploiting delegated Managed Service Accounts (dMSAs) in Windows Server 2025, detailing the "BadSuccessor" vulnerability. This flaw arises from missing permission checks, allowing low-level users with `CreateChild` rights on an OU to create a dMSA and link it to a privileged account. The system then incorrectly grants the dMSA all of the predecessor's permissions during Kerberos ticket issuance, enabling privilege escalation to high-level administrative roles. |
| 2026-07-06 | I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin — and a… | Writeup detailing an unauthenticated attachment disclosure vulnerability in a WordPress support plugin. The research, conducted in an isolated Docker environment, reveals that a specific REST API endpoint lacks proper authorization checks, allowing anonymous users to access sensitive customer attachments like invoices and personal records. The author validates the vulnerability through proof-of-concept requests and MD5 hash comparisons, highlighting the potential for widespread data exfiltration. |
GraphQL +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-12 | Ghost Accounts Abuse GitHub API in Mass Recon Campaign | Analysis of ghost account abuse of the GitHub API reveals mass reconnaissance campaigns leveraging dormant accounts and leaked credentials. Threat actors exploit unauthenticated API endpoints, including REST and GraphQL, to enumerate organizations, repositories, and users. While primarily focused on reconnaissance, some campaigns escalated to cloning repositories and exfiltrating data, sometimes using inadvertently exposed tokens. Detection strategies involve monitoring for data exfiltration from private repositories, anomalous user agent behavior, and establishing baselines for normal GitHub activity. |
Mobile +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-09 | 1 in 2 devices sold in Africa exfiltrate data to China | Writeup detailing the reverse-engineering of Transsion's "Athena" and "oneID" telemetry frameworks, found on millions of TECNO, Infinix, and itel devices. The analysis reveals how embedded AES keys and a fixed IV within the client binary allow for decryption of sensitive data, including app network activity, foreground app status, precise location, and camera usage, all tied to permanent device identifiers. This research highlights significant mobile security risks stemming from hidden, first-party software collecting extensive user information without clear visibility. |
JWT +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-08 | JWTweak v2.1: A Guided, Offline Toolkit for Modern JWT Attacks | Toolkit for offline JWT attack execution, JWTweak v2.1 guides users through identifying and exploiting vulnerabilities. Users paste JWTs to receive decoded and risk-scored tokens, suggested attack vectors, and step-by-step instructions for executing techniques such as algorithm confusion. This Python 3.8+ powered application requires pyjwt and cryptography libraries and operates entirely offline. |
Burp Suite +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-08 | Top Burp Suite alternatives for web application security testing | Library for identifying and assessing web application security vulnerabilities, this resource highlights alternatives to Burp Suite, focusing on tools that excel in CI/CD integration, AI-driven pentesting, and comprehensive attack surface management. It contrasts Burp's manual testing strengths and DAST capabilities with modern approaches like AI pentesting agents that discover shadow APIs, reason about business logic, and chain findings. The selection prioritizes solutions offering continuous automated testing, broader visibility into code and infrastructure, and automated discovery beyond provided specifications. |
SSTI +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-07 | PicoCTF Web Exploitation Easy Category Web Challenge [SSTL 1] | Writeup detailing Server Side Template Injection (SSTI) techniques used to exploit a PicoCTF web challenge. The article explains how to identify template engines like Jinja2 by testing inputs such as `{{ 8*8 }}` and then leverages object traversal through `{{ config }}`, `{{ request }}`, and `{{ self }}` to access Python internals. It demonstrates how to use `__init__.__globals__.__builtins__.__import__('os').popen('ls').read()` and similar payloads to execute system commands and read files like `flag`, highlighting the importance of understanding template engine processing and object structures for deeper exploitation. |
XXE +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-07 | The File That Answered Back — XXE Hidden in Cell A2 | Writeup detailing an XML External Entity (XXE) vulnerability discovered in an Excel file upload endpoint. The exploit bypasses Imperva WAF rules by hiding the `DOCTYPE` declaration within the XML structure of an `.xlsx` file, which is essentially a ZIP archive containing XML documents. The writeup explains how to manually construct a valid XLSX file with a malicious XML parser instruction to read server-side files, ultimately returning sensitive data within the application's JSON response. |
IDOR +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-07 | Predicting MongoDB ObjectId() continuously in Rocket.Chat | Writeup detailing a vulnerability in Rocket.Chat, #3687142, where unauthenticated users can access any uploaded file by predicting its MongoDB ObjectId(). The article explains how the ObjectId() is composed of a timestamp, machine/process ID, and a counter, allowing attackers to enumerate valid file IDs and bypass authorization checks through the Livechat functionality. |
Authentication +1
| Date | Resource | Summary |
|---|---|---|
| 2026-07-06 | Protocols and Servers 2 TryHackMe Writeup | Library detailing foundational attacks against network protocols, including sniffing with tools like tcpdump and Wireshark, Man-in-the-Middle (MITM) attacks using Bettercap and Responder, and password attacks. The resource emphasizes that cleartext protocols like POP3, FTP, and HTTP are insecure by design, highlighting vulnerabilities where credentials can be exposed over internal networks, legacy systems, and wireless connections. It also covers mitigations such as TLS encryption, network segmentation, and zero-trust principles. |