When Your VPN Opens Your Private Network to the Public!
An auth bypass in Palo Alto PAN-OS CAS Auth (CVE-2026-0265) that lets an attacker connect to the company's GlobalProtect VPN.
Blog - https://t.co/xMBbKC60NZ
The 2025 Ingenuity Awards are officially in the books, and what a lineup. 🎉
This year’s winners embody the curiosity, skill, and collaboration that make the Bugcrowd community so powerful. From groundbreaking research to inspiring leadership, they’re shaping the future of security every day.
Your 2025 winners:
🎖️ Global Security Impact Award: @TMobile
🎖️ Breakthrough Hacker: @hbenja_m
🎖️ Top P1 Hacker: @priyanshu_xo
🎖️ Top Pentester: @nerdwell
🎖️ Community Leader: @sw33tLie
Congrats to each winner, and thank you to every customer, hacker, and community member who makes the Bugcrowd ecosystem thrive. You’re the reason these awards exist: https://t.co/kHP4kEimSF
Let’s hear it for Bugcrowd’s Top P1 Hacker of 2025… priyanshuxo! 👑👏
This title is so much more than a badge. It celebrates the quiet grind behind every critical find. Long nights, dead ends, and countless hours dissecting complex systems… all fueled by curiosity and the drive to make the internet safer. ⚔️
P1s can run, but they can’t hide from priyanshuxo. He turns hidden bugs into major wins. Thank you, priyanshuxo. Your persistence and brilliance push the entire community forward. 💫
Learn how he got started and what makes him unstoppable: https://t.co/f4syQyj2RG
#Bugcrowd #IngenuityUnleashed #IngenuityAwards
When HTTP/1.1 Must Die lands at DEFCON we’ll publish a @WebSecAcademy lab with a new class of desync attack. One week later, I’ll livestream the solution on air with @offby1security! You’re invited :)
https://t.co/BPt0h0YiN2
Um... I just had like a 20 minute conversation with ChatGPT about the history of modern physics. If I had this shit as a tutor during high school and college.... OMG.
I think we can basically re-invent the concept of education at scale. College as we know it will cease to exist.
@xnwup@Hacker0x01@martenmickos Punish youself not his guy. Go Donate all the money that you ever collected from Russian linked companies/investors/bounties to UNICEF.
I usually make short-form satirical videos for fun, but never share them with the world. This time tho, I thought I'd make one for the infosec community. Some might even find it educational 😅
If you're in #infosec and you feel a little down this week, this video is for you💙
A while ago I had the pleasure to sit down with @jackhcable to learn about his background, hacking the @DeptofDefense, working with CISA and more!
Full interview 👇https://t.co/tqGoUPEQ4P
🔥 Ghostbuster: new tool to eliminate subdomain takeovers
Enumerates all elastic/public IPs for AWS accounts you own, & checks if there are DNS records pointing to elastic IPs you don’t own.
Code: https://t.co/FlvdCBSoFj
By @infosec_au & @assetnote
https://t.co/QYz76vQk16
@stokfredrik If you don't have perseverance, forget Bug Bounties. Sometimes days spent on a target - no results, u find a great bug, turns out its a dupe, u find a great bug but takes months to be paid on. All these & more will drag u down. With perseverance you will get over it and succeed.