As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...
🔒 IronCurtain: A Personal AI Assistant Built Secure from the Ground Up • 🚥 mitmproxy for fun and profit: Interception and Analysis of Application Traffic • ⛓️💥 Authentication Bypass in pac4j
💻 Browser-Based Port Scanning in the Age of LNA • 🪟 100+ Kernel Bugs in 30 Days • ⛈️ vinext: Vibe-Hacking Cloudflare's Vibe-Coded Next.js Replacement
🦫 CTFtime.org / justCTF [*] 2020 / Go-fs / Writeup • ☕️ Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services • 😱 Vulnerability Disclosure: JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat
⨐ Breaking Down CVE-2026-25049: How TypeScript Types Failed n8n's Security • ⚒️ Introducing Augustus: Open Source LLM Prompt Injection Tool • 🤺 When Two Parsers Disagree: Exploiting Query String Differentials for XSS
🤖 Semgrep's Agent Skills • 🤿 Shaking the MCP Tree: A Security Deep Dive • 🤖 Evaluating and mitigating the growing risk of LLM-discovered 0-days
🪟 Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals • ␛ On the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025 • 🪲 Insecure Defaults Detection
🤯 On the Coming Industrialisation of Exploit Generation with LLMs • 🚨 Cloudflare Zero-day: Accessing Any Host Globally • 🤖 Claude Magic String Denial of Service
🤖 AI models are showing a greater ability to find and exploit vulnerabilities on realistic cyber ranges • 🏴☠️ Pwning Claude Code in 8 Different Ways • 🔐 The State of OpenSSL for pyca/cryptography
💧 Cross-Site ETag Length Leak • 🛠️ Detect Go's silent arithmetic bugs with go-panikint • 💎 Ruby Array Pack Bleed