I got CVE - 2026 - 20841 in the latest Microsoft patch. I'm glad Microsoft fixed his new challenge and continued to attack the latest targets. Enjoy the hunting process. Happy hackers 😁📷
https://t.co/L2MWERibsj
@msftsecresponse
Original write-up on the fastjson 1.2.83 gadget-free RCE.
Have fun reading, I hope you missed writeups without AI slop.
Comment here your opinion.
https://t.co/cbAKOAeY62
#Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at https://t.co/XAIi6UXTRB #P2OIreland
Chrome just fixed a very cute URL spoofing vulnearbility on its latest release found by Pwn: CVE-2026-14077
A tall <select> partly above the viewport made Chrome paint over its omnibox. Details below
🎯 Advanced Bug Bounty Tip: Hunt for BFLA in GraphQL Mutations, Not Just REST
Most hunters focus on REST endpoints for Broken Function-Level Authorization (BFLA) and stop there.
Meanwhile, GraphQL mutations often expose privileged functionality that never appears in the UI.
Playbook:
→ Enumerate the schema (introspection or alternative schema discovery when introspection is unavailable)
→ Compare the mutations available to a low-privileged user with what the frontend actually exposes
→ Test mutations that exist in the schema but aren't reachable through the UI
→ Verify authorization on each mutation
→ Combine with object-level authorization testing by using resource IDs from other tenants or accounts where appropriate
The interesting cases aren't where the UI blocks an action—they're where the backend forgets to enforce the same permission check.
GraphQL can hide batch operations, internal tooling, and administrative actions behind a single endpoint. If those mutations trust the client instead of enforcing authorization server-side, you've got a high-value target.
Before you mark a GraphQL target as "fully tested," spend time reviewing its mutation surface. It often pays off.
#BugBounty #GraphQL #API #AppSec #CyberSecurity #BFLA #IDOR #HackerOne #Bugcrowd
I see many people demotivated due to AI and feels like its been a while since I ranted. Probably a mild take but here is how I stay motivated. Nothing really new just how I use what people have said to keep my motivation up. The normal 2026 disclaimer, what is in this post isn't actually 100% in line with my opinion; yes I know there are holes in my logic but some rabbit holes are best "on read".
The biggest change for me is Linus Torvalds saying something along the lines of idk why people say AI makes things, people make thing. If communication was so global in the 70's I am sure people would have said similar things during the conversion from assembly to C. Humans are creating instructions for the compiler to make a program. So why didn't we think the compiler made it? Without internet I think it would take me around 2 minutes to write hello world in C (i know embarrassingly slow but man have i gotten lazy over the years). Do it in assembly? That's probably an hour. Which is a 30x difference of time. Okay now lets say we are in the year 2010 and have Python. I timed myself and it was 3 seconds. That's a 40x time difference from my C. Why did I think I made the program and not python made it?
Unfortunately, the only thing I can come up with is how much we communicate and how quick ideas/sentiments can form. I'm sure C/Python got hate when they first came out. Hate can be a really goo fuel -- Most engineers I know have their best work come out of "hate coding" something to prove someone wrong. Only to later realize they social engineered themself into doing an amazing thing. Could be wrong here, but I think Pythons Flask is a good example of this as it started as an April fools joke. Quite literally "the most engineer thing ever" to have a funny joke spiral out of control and grow beyond their wildest dreams... Kind of like that guy that was vibe coding games last year when AI was "bad", or heck even the W̷a̷r̷e̷l̷a̷y̷ C̷L̷A̷W̷D̷I̷S̷ ̷C̷l̷a̷w̷d̷B̷o̷t̷ ̷M̷o̷l̷t̷B̷o̷t̷ ̷ err OpenClaw person. Really with all those name changes I'm shocked they landed at OpenAI instead of MSFT.
Anyway, our hate on vibe coding created the sentiment that we aren't creating things anymore (AI makes things). I don't really view it that way, AI just makes me 20-30x faster; which is similar to the jumps between Assembly -> Compiler -> Scripting. Actually now that I think about it, I remember trying to learn C many times because scripting wasn't a "real language" and it would never run a web server or it wasn't capable of editing memory (silly times indeed). AI is enabling us to develop faster and expanding the number of people that can do things, which is not new; quite literally every time we come up with a new way to interact with machines -- it does the same thing.
So yes - Anyone can make a cool demo that looks real now but they are still going to spend hours getting AI to work out all the bugs and do it better. To me they are still making something, it is other people telling them they aren't -- Funnily enough, those people trying to convince others they aren't making things, is what in return demotivates themself because it poisons their thought process when it comes to this topic.
So uh. If you look for my permission to learn something? Vibe on and let the good times roll. Just make sure you do things safely, obey terms of service, and try not to end humanity.
Oh wait. That disclaimer. Using AI in a way that causes humans to spend a lot more time than they are used to is bad mmkay? Seeing all the low effort CTF Work, blog posts, bug bounty, etc does get annoying... oh wait I have a diclaimer to the disclaimer. If you use AI to eat up time of scammers, like tricking call center scammers into chatting with robots for hours, I thank you for your token donation to helping fight that plague.
We’ve received notice that the Department of Commerce has lifted export controls on Claude Fable 5 and Mythos 5.
We'll begin restoring access tomorrow, and will share an update soon.
We’re grateful to our users for their patience, and to everyone who worked with us on redeploying the models.
Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs
Today we bring the Spear of Longinus
1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape
Our CVE-2026-6307 writeup https://t.co/zPnCJ4y0R3
New Research: CVE-2026-45502 — Microsoft Exchange Server SSRF
Any mailbox user can force Exchange to make HTTP requests to internal networks. The SSRF protection only runs on cloud deployments — on-premises servers skip the check entirely.
Root cause: the intranet address validation is gated on `isBposUser`, which is always `false` for on-prem Exchange. One SOAP request to EWS InstallApp with a crafted ManifestUrl = blind SSRF from the Exchange server's network position.
Affects Exchange 2016 CU23, 2019 CU14/CU15, and Exchange SE. Patched in the June 2026 SU.
Full analysis + PoC: https://t.co/jiEtZmEQsZ
If social engineering & phishing is your jam, and it should be, given how prevalent it is, we have a heap of great intelligence articles bundled up for you ready to go
https://t.co/Bi8Idwiq3k