MAD Bugs: "cat readme.txt" is not safe in iTerm2 by Calif Team π€―π₯
π¨βπ» Calif Team
π https://t.co/fn176VSQqF
π https://t.co/x3WwC2iMQh
First public macOS kernel memory corruption exploit on Apple M5 π€―π₯
π¨βπ» Calif Team
π https://t.co/nqEwFCZnga
π https://t.co/BZ4wxyQ4u2
CVE-2026-7270: How I Get Root on FreeBSD with a Shell Script by Calif Team π€―π₯
π¨βπ»
π https://t.co/GusEenVrWB
π https://t.co/tWkzzCKdWc
π https://t.co/vvlHP3r89o
Critical Remote Code Execution (RCE) in Roundcube: Your Email is Not Safe! π€―π₯β
π¨βπ» AirCorridor / Hackers-Arise
π https://t.co/igVoNpEMrE
"How I Discovered Account Takeover (ATO) via XSS and Open redirect" by Jeetpal π€―π₯β
π¨βπ» Jeetpal (x/Mr_mars_hacker)
π https://t.co/BsJkIcsDyu
π https://t.co/48kAyS0Vab
π https://t.co/5K7svXbXzb
$2,500 Bug Bounty π€
"How I Took Over Any Account on a Major Platform With One Click β A Client-Side Path Traversal Story" by patrickbatman π€―π₯β
π¨βπ» patrickbatman (x/hamidonsolo)
π https://t.co/g6CLW5h8ZT
π https://t.co/48kAyS0Vab
π https://t.co/5K7svXbXzb
According to a signed statement, the account was also used for prior vulnerability disclosures that allegedly received no bounty payouts. The message concluded with a threatening line directed at Microsoft, referencing July 14th. https://t.co/oNguERWuI0 https://t.co/4K0T70Qp9P
π¨π₯ A security researcher known as βNightmare-Eclipseβ claims their GitHub account was suspended and removed after publishing zero-day PoCs affecting Microsoft products.
Two cPanel Zero Day Vulnerabilities πΎπ₯
Two pre-auth XSS zero-days in cPanel's bundled Mailman fork: a reflected script-context breakout via json.dumps(), and a stored XSS in the moderator queue by Voorivex Team
π¨βπ» Shahinzadeh & Amirmohammad
π https://t.co/UfIpCNk9Es