27 Apr 2026

Better late than never...

CTF in the age of AI. A great read for people running CTF competitions: Lessons Learned From RITSEC CTF.

A cool entry point for deserialization in Apache Tomcat's cluster. Fail Open, Game Over: Turning a One-Line Tomcat Fix into Unauthenticated RCE.

A week, $2,283 in API costs and 20 hours of human work... I Let Claude Opus Write a Chrome Exploit.

AISI reviewing the capabilities of Mythos... Our evaluation of Claude Mythos Preview’s cyber capabilities.

Small models can find 0-days too! Great write-up with an open-source tool to prove it: System Over Model: Zero-Day Discovery at the Jagged Frontier.

📬 Never Miss Quality Security Research

Get these curated picks delivered to your inbox every week:

  • Hand-picked vulnerability research
  • Practical security insights
  • CVE deep-dives worth your time
  • No fluff, just signal
Subscribe for Free →

Want to build these skills hands-on?

PentesterLab has 700+ real-world labs on web hacking, code review, and vulnerability analysis. Start with a free account.

Photo of PentesterLab
PentesterLab
The platform to learn web hacking and security code review