RCE +10
| Date | Resource | Summary |
|---|---|---|
| 2026-10-08 | CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE | This content is a deep dive into CVE-2026-102489, a vulnerability in Zammad. The vulnerability allows for a session leak that can lead to Remote Code Execution (RCE). The title itself indicates the core issue and its severe consequence. No specific payout amount is mentioned in the provided content. |
| 2026-10-07 | You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) | Writeup on CVE-2026-21589, an arbitrary file read vulnerability affecting Atlassian Jira, Confluence, and Bitbucket. The vulnerability stems from the `atlassian-plugins-webresource*.jar` library, which mishandles path traversal attempts using double colons (`::`) as a substitute for slashes. This allows unauthenticated attackers to read arbitrary files on affected systems by exploiting the `Router.unescapeSlashes` and `ResourceFactory.createResourceWithRelativePath` functions. |
| 2026-10-06 | Wordpress libheif RCE | This content describes a Remote Code Execution (RCE) vulnerability in WordPress related to the libheif library. The specific details and impact of the vulnerability are not provided, nor is any information regarding a bug bounty payout. |
| 2026-10-06 | Open Build Service, one year later: command execution through Mercurial argument injection | Tool identifying CVE-2026-56004, a command execution vulnerability in Open Build Service's `obs_scm` service. The flaw arises from Mercurial argument injection when the `revision` parameter is improperly handled, allowing attackers to exploit Mercurial's `--config` option to execute arbitrary shell commands on the build server, posing a significant risk to software supply chains. |
| 2026-10-04 | RCE and bad crypto in Internxt's 'post-quantum' cloud storage | Writeup detailing critical vulnerabilities in Internxt's cloud storage, including remote code execution via protocol handlers and session/key leakage through unauthenticated public key sharing and insecure redirection. The analysis highlights architectural flaws in their cryptographic implementation, such as a flat key hierarchy and weak password hashing (MD5 with 3 iterations), rendering their "post-quantum" security claims unreliable and enabling potential data interception by Internxt or malicious third parties. |
| 2026-10-03 | 8 out of 10 Banks HATE This One Weird 3SKey RCE | Library for authentication with hardware signing tokens like 3SKeys, SConnect (v2.16.0.0), had a critical remote code execution vulnerability (CVE-2026-18397) due to a hand-rolled RSA-2048 token validation implementation. This flaw allowed any site or iframe to silently download and execute a DLL by exploiting an uninitialized memory validation bypass, enabling the loading of "plugins" and impacting systems used by banks and national authentication services. |
| 2026-10-03 | Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972) | Advisory for CVE-2026-71972 details an unbounded RLE8 splash image vulnerability in U-Boot. A crafted RLE8 BMP image, loaded from attacker-writable storage before boot stage authentication, can write past the framebuffer's bounds, corrupting adjacent memory and enabling secure boot bypass. Affected versions include U-Boot through 2026.10-rc5, with a fix available in commit 5201e83342d64c2f438ea35158575f28225e752e. |
| 2026-10-02 | How to Spot a Compromised MikroTik Router | Reference detailing techniques for detecting compromised MikroTik routers, focusing on identifying attacker configurations. It covers SSH port forwarding (`forwarding-enabled`), built-in SOCKS proxies (`/ip socks`), and the web proxy (`/ip proxy`), highlighting specific artifacts like `forwarding-enabled: local` and `redirect-to` rules. The document explains how these features, when improperly configured or exposed to the WAN, can facilitate pivoting and traffic manipulation, referencing historical abuse via CVE-2018-14847. |
| 2026-10-02 | Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files | Writeup on WordPress plugin vulnerabilities arising from overreliance on `.htaccess` files. When plugins installed on non-Apache servers, such as Nginx, ignore `.htaccess` directives, sensitive files like backup `.procstat` files in Everest Backup or database backup manifests in BackWPUp can be exposed to unauthenticated attackers. This research highlights security risks when plugin security relies solely on server-specific configurations. |
| 2026-10-02 | One Port to Root: Weaponizing Check Point Management CVE-2026-93616 | Tool for weaponizing Check Point Management CVE-2026-93616, an unauthenticated remote code execution vulnerability. The flaw allows an attacker to write arbitrary files as root via directory traversal and file upload on TCP 19009, leading to root code execution by planting a cron job. Bishop Fox validated the exploit chain against R81.10 and R82.10 servers and developed a detection tool to check patch state externally. |
AI +4
| Date | Resource | Summary |
|---|---|---|
| 2026-10-07 | Why the AI Attack Surface Extends Your Stack | Library for evaluating enterprise AI risk, extending beyond the model to include invoked tools, data sources, surrounding applications and APIs, identities, and cloud infrastructure. It details how prompt injection can lead to code execution and data exposure when service accounts have broad permissions and tenant isolation fails, highlighting that model safety scans and conventional AppSec scans miss critical parts of this expanded attack surface. The library emphasizes mapping AI system access and actions, then testing realistic attack chains across the full application stack. |
| 2026-10-05 | From the creator of Redis; run LLM locally with ds4 | Library for local Large Language Model inference, DwarfStar 4 (ds4) offers asymmetric 2-bit quantization to compress routed experts while preserving critical shared paths, enabling models like DeepSeek V4, GLM 5.x, and Qwen3.8 to run on high-memory Mac, CUDA, and ROCm machines. It supports text and vision models, local APIs, a CLI, and a native agent, with features like SSD-based prefix saving for faster restarts. |
| 2026-10-02 | Why AI Coding Agents Keep Writing Broken Access Control | Library for reasoning over application-context graphs to detect broken access control, specifically focusing on object-level authorization flaws like BOLA and IDOR. This approach moves beyond signature-based scanning, which struggles with authorization defects introduced by AI coding agents, by assembling a model of architecture, data flows, trust boundaries, and production reality to identify missing ownership checks and enforce application-specific rules. |
| 2026-10-02 | [tl;dr sec] #348 - Google's PageBreak Scanner, Perplexity's Agent Security Tool, Defending Agentically | Library implementing Google's PageBreak Scanner, an AI-powered web application security tool that leverages deterministic validation to find vulnerabilities like XSS and path traversal in first-party web applications. It also includes details on defending against AI agents, analyzing Scaleway's IAM model, auditing Cilium network policies with CiliumHound, and adapting detection strategies for AI-driven "living off the land" attacks. |
Supply Chain +3
| Date | Resource | Summary |
|---|---|---|
| 2026-10-08 | Evolution of Web3 in Cloud Supply Chain Attacks | Threat actors are increasingly exploiting Web3 infrastructure and open-source supply chain vulnerabilities to compromise enterprise cloud environments. This evolution in attack methods signifies a growing sophistication in how malicious actors target cloud-based systems. The Unit 42 report highlights this trend, emphasizing the intersection of decentralized technologies and traditional cybersecurity threats. |
| 2026-10-02 | Your SBOM Is Fan Fiction | Tool for runtime Software Bill of Materials generation; queries `/proc` for process dependencies and maps, then correlates with package data and CVE advisories using `yeet.graph.query` and `yeetkit` for enriched security insights on live systems. |
| 2026-10-02 | Public Secrets Monitoring: Find a Credential Leak Beyond Your Borders | Analysis of GitGuardian's Public Monitoring Agents enhances credential leak detection by identifying hardcoded secrets in public GitHub commits, a problem amplified by developer personal repositories and incidents like the CISA leak. This updated tool categorizes public incidents with new verdicts ("Related," "Uncertain," "Unrelated") to prioritize company-relevant exposures, streamlining investigations by organizing the incident queue around relevance and providing reasoning for each verdict. |
Bug Bounty +3
| Date | Resource | Summary |
|---|---|---|
| 2026-10-07 | Bitvulnex: a vulnerable crypto exchange | Library for practicing application security, Bitvulnex is a deliberately vulnerable Bitcoin exchange. It features 40 planted vulnerabilities spanning web security, exchange business logic, Bitcoin workflows, and infrastructure, allowing users to explore and learn from common issues like access control failures, injection, race conditions in withdrawals, price oracle manipulation, and SSRF in KYC processes. The application, built with Next.js, PostgreSQL, and Redis, includes simulated trading, deposits, and background jobs to provide a realistic environment for discovering and understanding security flaws. |
| 2026-10-06 | The evolution of Bug Bounty: history, best practices and the impact of AI | Bug bounty programs have transformed from informal hacker challenges to sophisticated security initiatives. Their evolution is marked by increasing organization, structured rewards, and broader adoption by companies seeking to proactively identify vulnerabilities. Key best practices include clear scope definition, fair compensation, and prompt communication. The emergence of AI is set to significantly impact bug bounties by automating vulnerability discovery and analysis, potentially leading to more efficient programs and a surge in reported bugs. |
| 2026-10-02 | Separating Signal from Slop: Triaging CVEs in the Age of AI Security Research | Library for triaging CVEs, emphasizing the impact of AI-assisted research on vulnerability disclosure volume. It highlights that many AI-discovered bugs, like those in Nginx (e.g., nginx-rift, nginx-poolslip, nginx-quicburst, CVE-2026-42533), require uncommon or non-default configurations, significantly reducing their real-world exploitation potential compared to their critical CVSS scores. The library provides a framework for identifying vulnerabilities likely to be mass-exploited by assessing their commonality in enterprise environments, impact, in-the-wild exploitation, public proof-of-concept availability, and reliance on default configurations. |
Recon +2
| Date | Resource | Summary |
|---|---|---|
| 2026-10-08 | Beyond asset discovery. Real-life CrowdRecon use case explored | The article discusses how security teams struggle to understand an organization's external attack surface beyond just listing assets. It highlights the need to identify what a skilled researcher would deem valuable to explore, considering the dynamic relationships and potential attack paths within evolving digital environments. Automated tools offer scale, but a deeper understanding of an attacker's perspective is crucial for comprehensive security. No bug bounty payout amount was mentioned. |
| 2026-10-03 | security.txt on the Czech web: Scanning 1k popular .cz domains | Writeup analyzing the adoption and validation of security.txt files across the top 1,000 .cz domains. The research reveals that only 16% of these popular Czech websites published a detectable security.txt, with just 12% passing strict RFC 9116 validation. Common failures included incorrect charset headers, missing `Expires` fields, and even WAF blocking of the discovery attempts. The analysis also highlights instances of expired or excessively long-dated `Expires` entries. |
Secrets +2
| Date | Resource | Summary |
|---|---|---|
| 2026-10-07 | Secrets Management Best Practices: 6 Reasons Your Vault Needs Detection | Library for secrets detection and management, this resource highlights the critical need for both secrets vaults and detection tools. Secrets vaults centralize and protect credentials, enforcing access policies and recording usage, while secrets detection continuously scans code, configurations, and platforms for exposed secrets outside the vault. Combining these capabilities provides a comprehensive inventory of all credentials, enabling faster remediation of security incidents, satisfying auditor requirements by demonstrating control effectiveness, and offering robust evidence for frameworks like SOC 2 and ISO 27001. |
| 2026-10-06 | SOPS Guide: How to Encrypt and Manage Secrets in Git, Kubernetes, and CI/CD | Library for encrypting secrets within YAML, JSON, ENV, and INI files using a choice of key stores like PGP, age, AWS KMS, Azure Key Vault, Google Cloud KMS, and HashiCorp Vault. SOPS supports envelope encryption and can be integrated with GitHub Actions and Flux CD for automated decryption at build or reconcile time, ensuring plain text secrets are never committed to Git. It also provides message authentication codes to detect file tampering and can be paired with secrets managers for runtime access. |
Authentication +2
| Date | Resource | Summary |
|---|---|---|
| 2026-10-06 | Smashing the token limit with overlapping fragments | Library for exfiltrating large tokens using overlapping CSS fragments. This technique reconstructs tokens by stitching together smaller identified CSS chunks from a given URL. It optimizes token extraction efficiency by strategically employing two-character, three-character, four-character, and five-character checks to minimize CSS payload size, achieving token lengths of 210 hex characters with a single candidate and up to 640 characters with multiple candidates. |
| 2026-10-02 | From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities | Writeup detailing header smuggling vulnerabilities discovered in Apple iCloud's email infrastructure. This technique, building on lessons from SMTP smuggling, allows for spoofing emails from arbitrary `@icloud.com` addresses by exploiting parsing discrepancies within Apple's SMTP implementation. The research highlights the continued risks of email trust due to these SMTP parsing vulnerabilities, even after widespread fixes for traditional SMTP smuggling. |
Mobile +1
| Date | Resource | Summary |
|---|---|---|
| 2026-10-08 | Presenting DiagNG: After QCSuper, a new open-source initiative for freeing up mobile baseband Diag protocols | DiagNG is a new open-source initiative designed to unblock mobile baseband Diag (diagnostic) protocols. Building on the legacy of QCSuper, DiagNG aims to provide greater accessibility and functionality for developers working with mobile device communication. This project focuses on making these powerful diagnostic tools more readily available for research and development. |
OSINT +1
| Date | Resource | Summary |
|---|---|---|
| 2026-10-07 | Show HN: MailAccess – the true Email OSINT framework | Library for email OSINT and scraping that identifies accounts behind a single email or all emails at a company. It utilizes over 75 modules across 5,300+ platforms to discover business contacts, visualizing findings in a graph format with clear sourcing, confidence scoring, and reasoning. The open-source, MIT-licensed engine is free and can be run locally without data leaving the user's network. |
AuthZ +1
| Date | Resource | Summary |
|---|---|---|
| 2026-10-03 | Azure's Weakest Link - Five Full Cross-Tenant Compromises | Writeup detailing the exploitation of Azure API Connections, which resulted in five cross-tenant compromises. The vulnerabilities allowed attackers to leverage Azure Resource Manager's (ARM) access to any connection within a tenant, enabling unauthorized access to backend services including Azure Key Vaults and Azure SQL databases. Exploitation involved manipulating unpatched `DynamicInvoke` and other undocumented `DynamicList` endpoints through path traversal to execute arbitrary commands and queries on victim systems. |