⚠️⚠️ CVE-2026-68771 (CVSS 9.8): Unauthenticated RCE via unsafe pickle deserialization in ComfyUI v0.23.0.
🔗FOFA Link: https://t.co/A22dDvk4qZ
🎯419.2K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="ComfyUI"
🔖Refer: https://t.co/lQmeUNtawD #OSINT #FOFA #CyberSecurity #Vulnerability
10 Years of XSS Bypass
I spent a decade popping alert boxes in places filters said were impossible. Every WAF, every custom filter, every regex written by someone who underestimated what an attacker would try.
This is not a payload list. It is the methodology behind every bypass I found. The thinking process that filters cannot patch because it lives in the researcher, not the payload.
30+ techniques. 10 documented Easy Wins against real filters. The same systematic approach I used against CloudFlare, Akamai, Imperva, and Fortinet.
WAFs get updated. Public bypasses get patched. The methodology does not.
The Brute Art of Bypass.
$10,000 Google Bug Bounty: AppSheet RCE
BugTraceAI found deserialization RCE in AppSheet automation. Malicious .NET payload → PowerShell execution on Google's backend.
🔗 https://t.co/XiBqxr8dLi
---
More writeups like this? 👇
🔗 Want to perfect?👉https://t.co/pJWHoCMDix
JWT SQL Injection
jti (JWT ID) is stored in a DB to prevent token replay.
That lookup is injectable.
"jti": "' OR '1'='1"
Try it: https://t.co/A01VkoVnjK
Full technique: https://t.co/r4ePoKUoFo
#hack2earn#bugbounty#jwt
💀File upload extension bypass new method✅
in media upload section you can upload files like: .png .jpg .txt .mov
but if you upload any php file it block: .php .jpg.php .php7 .shtml
Bypass: ".php " (just add a simple space after .php)
Join my channel https://t.co/J6uPf8H57o
You can also use these awesome Urlscan dorks to find publicly exposed invoices, PDFs, ZIP files, and other sensitive files belonging to your target domain.
page.mimeType:"application/pdf" AND page.url:invoice
https://t.co/78anAoXd2R AND page.mimeType:"application/pdf" AND page.url:invoice
apple.* AND page.mimeType:"application/zip"
If you want to learn more powerful urlscan dorks and master urlscan search, watch this video:
https://t.co/LjSf6OFiyd
👻Certighost (CVE-2026-54121) Detection
A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain.
https://t.co/y8yZbZgsSZ
👇 A Sentinel KQL to help detect AD CS abuse.
https://t.co/bGrHkbHEK4
#Cybersecurity #Certighost #ThreatHunting
Hey Hunters,
just released: Burp Unrestricted MCP
Free and open source, for hunters running AI agents against Burp on
long engagements.
A fork of @PortSwigger's Burp MCP Server that adds the 8 tools an agent
actually needs to work a target end to end.
https://t.co/4CbKF3rIJB
#Bugbounty
#ssrf
extention bypass if it requires the file to end with .yaml
do it: url=http://2852039166/latest/meta-data/iam/security-credentials/target-web-role?a=example.yaml
paramter with bypass #bugbounty#bugbountytrics #
🐀 Just dropped: the 2026 Practical Bug Bounty Guide — a full field manual built on real-world hunting experience. Recon → manual mapping → Burp deep dive → every vuln class (XSS, SSTI, SQLi, IDOR, SSRF, XXE, business logic, GraphQL, OAuth) → chaining → reporting. Opinionated, practical, updated for 2026.
Read it free: https://t.co/FokfrqlYvK
Liked this? The 906 bundle is the natural next step to go deeper — a discount applies via the link: https://t.co/0DRvm9TFbD
#infosec #bugbounty
Our newest labs are all about hacking LLMs. You'll learn:
🟧 What's an LLM?
🟧 Prompt injection
🟧 Exploiting LLM APIs, functions, and plugins
🟧 AI-powered scanner vulnerabilities
🟧 Defending against LLM attacks
Sound good?
Get started here. 👇
https://t.co/Xkn6EZr74s