g3n3r4l22
-
Attacker File Extensions Database for Threat Intel (filesec.io)
provides a database of file extensions used by attackers, helping you stay up-to-date with threat intelligence. You can contribute to expand this valuable resource. Filesec.io
-
Red-Teaming AI Models for Vulnerabilities (kaggle.com)
A Kaggle competition challenges participants to find previously undiscovered flaws and vulnerabilities in the gpt-oss-20b model. This aims to improve AI security through community red-teaming efforts. Kaggle
-
Vulnerability Vibes: Network, Learn, Connect (vulnerabilityvibes.com)
Vulnerability Vibes offers an opportunity to network and make new connections within the security industry. Attendees can learn from the hackers themselves, understanding both industry trends and attacker tactics. Vulnerabilityvibes.com
-
HTTP/1.1 Desynchronization Endgame (http1mustdie.com)
Protocol deemed inherently insecure.
-
AWS SAR IAM Action Nuances (fogsecurity.io)
AWS Service Authorization References (SAR) and IAM action risks.
-
AWS Account Termination Without Warning (seuros.com)
10-year-old AWS account deleted without recovery.
-
ORM Injection Crypto Theft Exploit (blog.p1.gs)
Cryptocurrency theft via ORM injection in online game.
-
CVE-2025-29891 Apache Camel RCE (offsec.com)
Header injection RCE via misconfiguration.
-
Squid Proxy Critical RCE Vulnerability (cyberpress.org)
SQUID-2025:1 flaw enables remote code execution.
-
Adobe Experience Manager Pre-Auth Flaws (slcyber.io)
Critical vulnerabilities in AEM Forms via Struts DevMode.
-
Jenkins RCE via Git Parameter Plugin (hackread.com)
CVE-2025-53652 allows unauthenticated RCE.
-
Fastly HTTP/1.1 Attack Resilience (fastly.com)
Parser robustness protects against desync.
-
Buttercup Open-Source Release (blog.trailofbits.com)
AI Cyber Challenge runner-up CRS open-sourced.
-
Blind SSRF to File Reading Oracle (xbow.com)
Turning SSRF into a file oracle.
-
Copilot Studio AIjacking Data Theft (labs.zenity.io)
Prompt injection leads to full data exfiltration.
-
Security Products and Human Psychology (philvenables.com)
Security tools linked to 7 deadly sins.
-
HashiCorp Vault Auth Flaws Exposed (cyata.ai)
Zero-day in authentication & authorization.
-
Zscaler SAML Auth Bypass Advisory (blog.amberwolf.com)
CVE-2025-54982 missing signature verification.
-
Confluence Auth Bypass via XSS (bugcrowd.com)
iOS-specific XSS leads to auth bypass.
-
FileJacking Initial Access with File System API (print3m.github.io)
Experimental API allows direct file editing.
-
Introducing AI-powered Exploit Verification and Triage (nahsra.hashnode.dev)
AI to triage vulnerabilities.
-
Cursor IDE's MCP Vulnerability Discovery (research.checkpoint.com)
MCP flaw in AI IDE allows local command execution.
X1
-
Brave HTML Serialization Vulnerability (@kinugawamasato)
Demo shows broken serialization. Watch Here
g1thub10
-
1Panel Agent Certificate Bypass (github.com)
GHSA-8j63-96wh-wh3j allows arbitrary code execution.
-
Safari PermissionJacking Privacy Risk (github.com)
Permission hijacking in Safari.
-
Quack PHP Deserialization Protector (github.com)
Runtime validation against PHP deserialization attacks. Explore on GitHub
-
Finch TLS Fingerprint-Aware Proxy (github.com)
Reverse proxy blocks/reroutes traffic using JA3/JA4 fingerprints. Explore on GitHub
-
Kwcmd Hidden Linux Backdoor (github.com)
Persistent access via disguised commands. Explore on GitHub
-
Beelzebub AI Honeypot Framework (github.com)
AI for virtualization deception environments. Explore on GitHub
-
Signal Key Transparency Auditor (github.com)
Audits Signal's Merkle^2-style logs. Explore on GitHub
-
Claude-Powered Security Code Review (github.com)
Uses Claude AI to analyze commits for vulnerabilities. Explore on GitHub
-
ECSpace AWS ECS Credential Theft (github.com)
IAM credential theft in EC2 launch mode. Explore on GitHub
-
Viper AI Red Teaming Platform (github.com)
AI-powered adversary simulation. Explore on GitHub