The Bug Bounty Hunter
СтатистикаHappy hunting! thebugbountyhunter.com hello@thebugbountyhunter.com
- Последний пост
- 15 авг.
- Последнее чтение
- 11:21
- Постов за неделю
- 6
- Всего постов
- 36
- Тип
- открытый
- Язык
- английский
- Категория
- Новости и СМИ (по похожим)
- В каталоге с
- 12 авг.
- 1/24сутки в ленте
- 2 625
- 1/48двое суток
- 3 008
- 1/72трое суток
- 3 244
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
Part 1/6 | Systemic Risks in the Managed PostgreSQL Industry: Extension Risks Are Real! Exploiting PostGis Memory Corruption Bug at NeonDB, SupaBase and Many More https://mehmetince.net/part-1-6-systemic-risks-in-the-managed-postgresql-industry-extension-risks-are-real-exploiting-postgis-memory-corruption-bug-at-neondb-supabase-and-many-more/
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Ruby 4.0 Universal RCE Deserialization Gadget Chain https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain
The Future - On AI Soveriegnity, Vulnerability Research, and Bug Bounty https://ret2p.lt/2026/08/10/ai-vuln-research-future.html
How to start (or come back to) bug bounties in 2026 https://hakluke.com/how-to-start-or-come-back-to-bug-bounties-in-2026
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/
When a Web App Detects Burp Suite via TLS Fingerprinting https://kecman.co/blog/burp-suite-tls-fingerprint-bot-detection-bypass.html
What Happened to HackerOne? https://blog.teknogeek.io/posts/what-happened-to-hackerone/
The WordPress Chain Massacre https://blog.calif.io/p/the-wordpress-chain-massacre
Apple Screen Sharing Pre-Auth RCE https://warez.sl0p.foo/apple-screensharing-rce/
AISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity https://aisle.com/blog/aisle-discovers-1-click-rce-vulnerability-in-cursor-vs-code-and-google-antigravity
[PWN2OWN IRELAND 2025] Bypassing Authentication via Synology DS925+ SAML SSO https://chanzep.github.io/posts/pwn2own-ireland-2025-bypassing-authentication-via-synology-ds925-saml-sso/?preview=true
1-Click GitHub Token Stealing via a VSCode Bug https://blog.ammaraskar.com/github-token-stealing/
How to use Claude Code for Bug Bounty: find fast, validate manually https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
From a “Hey, {name} 👋” Banner to Full Account Takeover | Chaining 4 Bugs Through a Rewards WebView https://medium.com/@bag0zathev2/from-a-hey-name-banner-to-full-account-takeover-chaining-4-bugs-through-a-rewards-webview-f89a2b0f830f
A Shell Is Worth A Thousand Images: Bing Images RCEs https://xbow.com/blog/bing-images-rce-vulnerabilities
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Pwn2Own with Microslop https://dungnm.hashnode.dev/pwn2own-with-microslop
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
Language Model Security Database A comprehensive collection of LLM vulnerabilities, curated from cutting-edge research papers and real-world discoveries. https://www.promptfoo.dev/lm-security-db