We published a new research article on the Chromium 146 Renderer Process!
In this article, we start from the CVE-2026-3910 Maglev write barrier elision bug and walk through the full exploit chain: building a V8 heap R/W primitive via a GC-induced UAF, achieving an out-of-sandbox read using WebAssembly internals, abusing JSPI UAF and StackMemory / JumpBuffer, and ultimately reaching renderer process RCE.
Our goal was to provide a structured explanation of how modern V8 exploitation works in practice, from compiler-level bug analysis to sandbox-boundary primitives and final code execution. Huge thanks to our team member @m411k_ for conducting this research!
Check out the PoC!
Full article:
https://t.co/qezGcrklC1
I've been seeing posts all over about the state of CTFs post-LLM. I've seen many attempts to explain why this is just a new evolution of CTFs, but I fundamentally disagree. I believe the original spirit is gone and I've written why in my blog.
https://t.co/tgUZOGkhGV
๐จ BREAKING: Wiz Research discovered Remote Code Execution on https://t.co/SvN2lGsnbO with a single git push
The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations ๐คฏ
We published a new research article on prompt injection in modern agentic systems
This write-up covers:
- direct and indirect prompt injection
- multi-turn attack methodology
- tool-calling and MCP-related abuse cases
- case studies including WhatsApp MCP, GitHub MCP, and OpenClaw
mitigation strategies such as permission segmentation, - sandboxing, PTC, and HITL
Our goal was to provide a structured overview of how these attacks work and how they can be addressed in practice
Full write-up:
https://t.co/0UEOHkQq9f
We have successfully published a new research article!
This research takes an in-depth look at several interesting security incidents that occurred in 2025 and analyzes them in detail
While some of these incidents were already widely known, this research focuses more closely on cases that people may have only glanced over without examining thoroughly
Special thanks to One, TCP/IP, and @filime_sec for conducting this research!
We hope it receives a lot of interest! : )
https://t.co/4L9JeYNATY
[ RewriteLab Web Security Research Team, 2026 First Half Researcher Recruitment ]
Rewrite is a specialized web security research team composed of web hackers from around the world.
Researchers from various regions including Korea, Europe, Asia, and Africa collaborate to conduct in-depth research on the latest web exploitation techniques and technologies, while also working on a range of web security related projects
We are now publicly recruiting new researchers who would like to join RewriteLab and conduct research together with us
For detailed information about the recruitment requirements and the application process, please refer to the recruitment page below!
https://t.co/PHZ7NazvAD
I placed 3rd in the SECCON International division with my team Pochita! ๐ฏ๐ต
Honestly I never imagined we would finish in the top ranks, so Iโm really happy about this unexpected result : )
Huge thanks to my teammates (@wlswotmd, @slyfizz3, SharpEdged, @OpenAI) for playing together
Iโll keep pushing and stay active in future events!!