🧩 From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX • 🔥 Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine • 🏭 Countering misuse of AI: September 2026 / Anthropic
❄️ When it Snows it Pours - Anatomy of a ServiceNow Red Team - MDSec • 🪤 Breaking Claude Code Opus 5 Auto Mode • ⛓️💥 Compromising Cleo Harmony: A SAML Bypass Chain to Arbitrary Code Execution
💎 Ruby Marshal Kick-off Gadgets - elttam • ␛ VMs won't contain cyber-capable agents - The Trail of Bits Blog • ☕️ Escaping Google Cloud Application Integration Sandbox: Straight into Borg
🤖 Patterns and problems in multiagent systems \ Anthropic • ⚒️ Staying Ahead of Adversarial AI Through Agentic Source Code Review | Google Cloud Blog • 💸 We burned 11.7bn tokens to find the best cyber AI model | GLM5.3 and DeepSeek are now frontier
🏭 visa/visa-vulnerability-agentic-harness: Visa Vulnerability Agentic Harness • 🔀 LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection • 💎 Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam
✅ AI Guardrails That Prove, Not Guess • 🧠 GitHub - Kritt-ai/open-kritt: Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code. · GitHub • 🐚 Cruising for Shells in Flowise - elttam
🪲 CVE-2026–44722: A Zip encryption downgrade caused by an incorrect operator • 🪲 Finding six NGINX vulnerabilities with open models • 🤗 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
⚒️ ethiack / ethibench • ⚒️ capitalone / VulnHunter • 🪲 FastJson 1.2.83 Remote Code Execution
🤖 Special Token Injection (STI) Attack Guide • 🪲 MAD Bugs: My Cousin Vinyl (CVE-2026-50052) • 🪲 From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
🖥️ Local AI for Penetration Testing & Research • 🧠 The context an agent needs to find the next vulnerability. • 🤖 The Bug Bounty Singularity: Our Hackbot
🩹 Introducing Patch the Planet • 🤖 Building an AI pentesting platform • 🤖 Comparing AI Application Security Testing Platforms
🐴 DietrichGebert / ponytail • 🤯 curl summer of bliss • ⛓️ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
🪲 Jupyter Enterprise Gateway • 🤖 Measuring LLMs’ impact on N-day exploits • 🎆 Bypassing a 3 layer SVG sanitizer: Stored XSS in Mozilla