$10,000 Google Bug Bounty: AppSheet RCE
BugTraceAI found deserialization RCE in AppSheet automation. Malicious .NET payload → PowerShell execution on Google's backend.
🔗 https://t.co/XiBqxr8dLi
---
More writeups like this? 👇
🔗 Want to perfect?👉https://t.co/pJWHoCMDix
10-Year-Old RCE Found in Linux PDF Viewers 🤯🔥
CVE-2026-46529 affects XReader, Evince, and Atril, allowing code execution through a malicious PDF.
Huge find by N1et 👏
🔗 https://t.co/gf99UTM5fX
#CyberSecurity#Linux#RCE#CVE
Join team 👉https://t.co/FeMz53HSN0
In April 2026, we held the latest edition of bugSWAT (our live event for security researchers) in Seoul, South Korea.
For more information on this edition's focus, its impact & winners, as well as bugSWAT in general, see 👇
https://t.co/uJaaTARPM7
📢📢📢 Attention bug hunters!
The Google VRP is updating its reward model, with a focus on the impact of vulnerabilities and the sensitivity of the data involved. To this end, we're introducing two dimensions: Information Tiers and Action Criticality. 👀👇
https://t.co/QVXiZVBazJ
I developed a Burp vulnerability scanning plug-in based on #DeepSeek model, which can detect injection vulnerabilities and XSS vulnerabilities at present
#bugbounty#bugbountytips
I welcome your questions in the Github Issues section
https://t.co/XDyFi5hwxv
Digital Forensics is a science and art! In the Yellow Volume of our Infosec Survival Guide, Blake Regan @Zer0C00L, breaks down the art of digital forensics, career paths you can take to becoming a digital forensics investigator, and resources to help you in your career!
Resources:
Blue Team Tactics by Blake regan - https://t.co/CWoIduAV00
Attack Tactics 6: Return of the Blue Team - https://t.co/2DVA7CsZKV
Blue Team Summit - https://t.co/N8GjNHWELI
A Blue Team's Perspective on Red Team Hack Tools - https://t.co/oGGvzfJoEf
https://t.co/KKfzu2rNpx
Open-Source Tools:
Forensic Tool Kit (FTK) Imager - https://t.co/f7sPJAkGEH
Autopsy Forensics Suite - https://t.co/HJaudWlD24
Volatility (memory analysis) - https://t.co/2fnkhVN0O3
Zimmerman Tools - https://t.co/ccM1AYbKvo
Wireshark - https://t.co/rUP8yYqz0z
iLEAPP and aLEAPP - https://t.co/tRzbqG0yJc
https://t.co/QxMcWusnQ7
Klogg - https://t.co/RCGvOOr04O
If you'd like more helpful educational content, check out the Infosec Survival Guide: GREEN BOOK - https://t.co/ni3WRBhmBJ
Quick PSA: Someone is attacking Tor right now and has been for a few weeks.
The attacker is spoofing the IPs of Tor Exit and Directory nodes, and blasting TCP SYN packets indiscriminately on 22/TCP- spurring a large amount of abuse complaints to hosting providers, which are then temp blocking/banning Tor infrastructure which isn't actually doing anything wrong.
For the time being, I recommend all hosting providers *ignore* abuse complaints that indicate "SSH scanning" or "port scanning on 22/TCP" and originate from any of the following IPs: https://t.co/RQFUGuI8XU
This is a clever attack. I'm working with partners to triangulate the true origin of this traffic then try to get it disconnected.
Weird attacker website here: https://t.co/xyd9CwE1hF
Related links:
https://t.co/RZdC51gQoR
https://t.co/9NF9oGgapj
How to fix the Crowdstrike thing:
1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
🚨 Alerte CERT-FR 🚨
Une porte dérobée (backdoor) a été découverte dans la bibliothèque Linux xz dans les versions 5.6.0 et 5.6.1. Son utilisation semble permettre de contourner l'authentification ssh.
Veuillez consulter les avis de sécurité des éditeurs.
You can find easy critical vulnerabilities.
It just takes finding unique attack surfaces.
Here's an example of how you can, using a story of how I hacked a car company:
Found a Critical today: Nacos auth bypass - using default JWT Secret. The Nuclei template I used can be found here: https://t.co/6MblqtLTRu. #BugBounty
❗ ALERT ❗ Remote code execution vulnerability found in Microsoft Office Outlook (CVE-2024-21413), which enables malicious code execution.
All Microsoft Office Outlook users are strongly advised to follow Microsoft's mitigation advice.
Read more 👉 https://t.co/HU99VgYWnZ
A Beginners Guide to Tracking Malware Infrastructure
New post with 11 Examples (Including Cobalt Strike and Qakbot) that you can use to query and track C2’s, Open Directories and More🔥
(Special thanks to @censysio 🥳)
https://t.co/9h1Q07mbuj
#threatintel#malware