Here we go! Introducing ShadowClone - github.com/fyoorer/ShadowClo…!
Run your tools with the power of cloud. Dynamically spawn upto 1000 copies of your script to run in parallel. Oh and it costs almost zero! #bugbounty#RECON#cloud
@SLCyberSec Labs Team found a Remote Code Execution in the GoJa Javascript Sandbox that is used by a lot of products including Zendesk and Nuclei 😉
read the whole writeup here: searchlight-web-new.webflow.…
and watch Nuclei getting pwned with a template file here 👇🏻
Just published the writeup for my RCE in Google Cloud Application Integration, found last year - before this whole AI vulnpocalypse.
nopnop.pro/2026/08/26/escapi…
Type text into Wikipedia. Get the shell's output back on the page.
A bug introduced 22 years ago.
Still alive in the wild, until it was found by V12.
Here's how EasyTimeline allowed arbitrary code execution (RCE) directly from wikitext.
@DefCon 32 Matt (@emptynebuli) released 6 CE bugs affecting Diebold Nixdorf.. and now he is back with 9 more via the CryptoPro supply chain! 👀 Come join his #BHUSA briefing on Wednesday August 5th - you won't want to miss it! 🏧 🏦 @BlackHatEventsbuff.ly/G8bvkom
We decided to revisit an old research problem with some new LLM powered tooling. Check out our latest blog post to see how we approached this research, and the new Java deserialization gadget chains it discovered in just two days! buff.ly/CeAQZ2B
Excited to disclose my research allowing RCE in Kubernetes
It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout.
Unfortunately, this will NOT be patched.
We just dove into our shelf of archived bug bounty write-ups from the most notable hackers! 🤠
In this issue, we selected 5 compelling articles (that are still relevant today) to share with you, from which you can learn something new! 😎
🧵 👇
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
Meta tracks your activity across millions of websites and apps, regardless of whether you use its platforms, and profits from that data through targeted ads. Here’s what you need to know if you want to limit the company’s ability to harvest and profit from your personal data. eff.org/deeplinks/2025/01/ma…
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click
project-zero.issues.chromium…
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
samcurry.net/hacking-kia