27 May 2026

Maybe it was all marketing...

It's rare to see this side of security research, especially for vulnerabilities with this level of impact: The React2Shell Story and What Happened Next.js.

After the apocalypse announcement, it is refreshing to get real information from Daniel Stenberg: Mythos finds a curl vulnerability.

Really interesting to see how the Claude Code team decided to handle option parsing for deep links and the impact of this choice: Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection.

📬 Never Miss Quality Security Research

Get these curated picks delivered to your inbox every week:

  • Hand-picked vulnerability research
  • Practical security insights
  • CVE deep-dives worth your time
  • No fluff, just signal
Subscribe for Free →

Want to build these skills hands-on?

PentesterLab has 700+ real-world labs on web hacking, code review, and vulnerability analysis. Start with a free account.

Photo of PentesterLab
PentesterLab
The platform to learn web hacking and security code review