π§© From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX β’ π₯ Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine β’ π Countering misuse of AI: September 2026 / Anthropic
π€ Special Token Injection (STI) Attack Guide β’ πͺ² MAD Bugs: My Cousin Vinyl (CVE-2026-50052) β’ πͺ² From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
With AI, technical interviews are becoming harder and harder to trust. Candidates now have access to automated tools designed to help ...
π₯οΈ Local AI for Penetration Testing & Research β’ π§ The context an agent needs to find the next vulnerability. β’ π€ The Bug Bounty Singularity: Our Hackbot
I have been travelling to conferences across Europe this year, running workshops and giving talks, mostly on code review and CVE ...
π©Ή Introducing Patch the Planet β’ π€ Building an AI pentesting platform β’ π€ Comparing AI Application Security Testing Platforms
π΄ DietrichGebert / ponytail β’ π€― curl summer of bliss β’ βοΈ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
πͺ² Jupyter Enterprise Gateway β’ π€ Measuring LLMsβ impact on N-day exploits β’ π Bypassing a 3 layer SVG sanitizer: Stored XSS in Mozilla
π Letβs talk about encrypted reasoning β’ π Golang code review notes II β’ π€ The sorry state of skill distribution
A big part of what I do for PentesterLab is reading CVEs. I spend a lot of time going through them: ...
βοΈ evilsocket / audit β’ π€ Autonomous fuzzing process under LLM supervision β’ π° StubZero: $148,337 RCE in Google Cloud Production
π The React2Shell Story and What Happened Next.js β’ ποΈ Mythos finds a curl vulnerability β’ π€ Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
π€ AI threats in the wild: The current state of prompt injections on the web β’ πͺ Persistence Atlas: 19 Techniques Nobody Talks About β’ π³ Securing GitHub: Wiz Research uncovers RCE in GitHub.com