Latest posts

The Bug Bounty Hunter
22 Sept, 21:19
SharePoint CVE-2026-65660: From Anonymous Access to Pre-Auth RCE via EditingPageParser Type-Check Bypasshttps://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/
The Bug Bounty Hunter
20 Sept, 08:13
BragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single Extensionhttps://forever.security/blog/bragjack-attack-hijacks-every-browser-agent/ForeverBragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single Extension · Forever SecurityBragJack attack (discovered by Forever Security) allowed ordinary extensions to hijack the internal browser agent of Comet, Chrome, Edge, Opera, and Claude in Chrome
The Bug Bounty Hunter
19 Sept, 17:16
ROOT Tesla OS on QEMU Part 2 :Debugging + fixinghttps://cn0xroot.wordpress.com/2026/09/20/root_tesla_os_on_qemu_part_2_debugging_fixing/| 混沌通信| RadioHub | IoT RF Hardware Hacking | 博观而约取 厚积而薄发ROOT Tesla OS on QEMU Part 2 :Debugging + fixingPwn for fun
The Bug Bounty Hunter
19 Sept, 16:31
ROOT Tesla OS on QEMU Part 1 :unpackinghttps://cn0xroot.wordpress.com/2026/09/19/root-tesla-os-on-qemu-part-1-unpacking/| 混沌通信| RadioHub | IoT RF Hardware Hacking | 博观而约取 厚积而薄发ROOT Tesla OS on QEMU Part 1 :unpacking直接使用真机设备获取ROOT Shell 是一件很艰难的事情,退而求其次使用固件镜像+QEMU 模拟仿真实现获得ROOTShell
The Bug Bounty Hunter
19 Sept, 16:07
geminiHunterFind and assess exposed Google Gemini API keys in web assets and Android apps.https://github.com/devploit/geminiHunterGitHubGitHub - devploit/geminiHunter: Find and assess exposed Google Gemini API keys across web assets and Android apps.Find and assess exposed Google Gemini API keys across web assets and Android apps. - devploit/geminiHunter
The Bug Bounty Hunter
18 Sept, 17:15
Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chainhttps://pwn.ai/blog/click2shellPWN.AIClick2Shell: Preauth WordPress Core Theme Preview Injection to RCE ChainA pre-authentication Theme Injection to RCE chain in WordPress Core that allows unauthenticated attackers to achieve remote code execution on any default WordPress installation through a single click.
The Bug Bounty Hunter
18 Sept, 06:32
Hacking OpenAI A heap overflow and SSO misconfiguration to compromise OpenAI internal repositorieshttps://www.hacktron.ai/blog/hacking-openaiHacktron AIHacking OpenAIA heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
The Bug Bounty Hunter
17 Sept, 22:12
The Hacker's Guide to Attacking AI Agentshttps://darkmarc.substack.com/p/the-hackers-guide-to-attacking-aiSubstackThe Hacker's Guide to Attacking AI AgentsThis is a practical guide to assessing the security of an agentic AI system.
The Bug Bounty Hunter
17 Sept, 20:07
Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)https://www.cyera.com/research/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858CyeraNi8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)Cyera Research Labs has discovered a "worst-case scenario" flaw in n8n, the industry-leading platform for AI and workflow automation. Dubbed "Ni8mare," this vulnerability (CVE-2026-21858) allows an unauthenticated remote attacker to gain full administrative…
The Bug Bounty Hunter
17 Sept, 19:49
Breaking into Google's GFile for $100khttps://bughunters.google.com/blog/breaking-into-googles-gfile-for-100kGoogleBlog: Breaking into Google's GFile for $100kThis post details an attack on Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage.3,420Open in Telegram
The Bug Bounty Hunter
15 Sept, 13:15
GitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitzRuntimeWireGitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_Researcher @sagitz_ disclosed a remote code execution vulnerability in GitHub, earning a $100,000 bounty—the largest payout in the platform's bug bounty program.
The Bug Bounty Hunter
13 Sept, 14:42
$15k - CSPT to full account takeover, then 2FA bypass via the prototype chainhttps://whoareme.com/blog/cspt-account-takeover-2fa-bypass/Whoareme$15k - CSPT to full account takeover, then 2FA bypass via the prototype chainA client-side path traversal in the front-end's URL builder turned into arbitrary PUT/DELETE on the API, then chained with an inherited-property lookup bug to bypass 2FA
The Bug Bounty Hunter
11 Sept, 07:00
Everyone Chains SSTI to RCE. I Chained It to Account Takeover.https://medium.com/@HariHax/everyone-chains-ssti-to-rce-i-chained-it-to-account-takeover-c279188ff9ceMediumEveryone Chains SSTI to RCE. I Chained It to Account Takeover.Three attempts at code execution paid nothing. One template expression that just read a variable paid $1,000.
The Bug Bounty Hunter
9 Sept, 08:33
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html6,910Open in Telegram
The Bug Bounty Hunter
7 Sept, 06:17
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAXhttps://tantosec.com/blog/2026/09/telerik-padding-oracle-to-shell/Tanto SecurityFrom Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAXTantoSec turned an unauthenticated AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into remote code execution, chaining a decrypt-versus-parse oracle, a predictable HMAC key, and a type-name deserialisation gadget.
The Bug Bounty Hunter
6 Sept, 00:31
ZeroQuarry is finding security vulnerability chains in AI-reviewed codehttps://zeroquarry.com/research/security-vulnerabilities-in-ai-reviewed-code/ZeroquarryZeroQuarry is finding security vulnerability chains in AI-reviewed codeA pre-deployment scan of an open source URL shortener surfaced cross-tenant link takeover, SSRF, and custom-domain takeover chains that AI code review did not flag.7,760Open in Telegram
The Bug Bounty Hunter
6 Sept, 00:11
From Zero Credentials to Super Admin: An SSO Authentication Bypass on AT&Thttps://medium.com/@Tyrion404/from-zero-credentials-to-super-admin-an-sso-authentication-bypass-on-at-t-996fe9d0ec1eMediumFrom Zero Credentials to Super Admin: An SSO Authentication Bypass on AT&TThe Door Was Already Open
The Bug Bounty Hunter
6 Sept, 00:01
From IDOR to Admin: How a Simple ID Parameter Led to Full Platform Takeoverhttps://medium.com/@pankaj_73968/from-idor-to-admin-how-a-simple-id-parameter-led-to-full-platform-takeover-cdc21b989a21MediumFrom IDOR to Admin: How a Simple ID Parameter Led to Full Platform TakeoverA Real Estate Web App Bug Bounty Story5,690Open in Telegram
The Bug Bounty Hunter
5 Sept, 20:16
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attackhttps://sansec.io/research/stylesmugglerSansecStyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attackSansec discovered StyleSmuggler, a Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. Attacks started September ...4,920Open in Telegram
The Bug Bounty Hunter
4 Sept, 14:18
GeoNetwork - PreAuth Remote Code Executionhttps://ethiack.com/info-hub/research/geonetwork-preauth-RCEEthiackGeoNetwork - PreAuth Remote Code Execution | EthiackHow a missing @PreAuthorize line in GeoNetwork led to unauthenticated Remote Code Execution across government geospatial infrastructure in 39 countries.
Related Channels
Other channels in the same section of the catalogue.
