Watch us open the camera and uncover the anonymous identity behind Tor browser:
We published the writeup for the browser RCE in IonStack. Mythos reported 271 bugs in Firefox 150 but still missed this one. And the Tor Browser is also affected by CVE-2026-10702.
Update your Tor!
Most security teams have plenty of findings. What they need is confidence in what to fix first.
That’s where a mature bug bounty program starts to look different. Not as another stream of tickets, but as a way to bring trusted hacker insight into the places your team needs more visibility 🤏🥽
Join our live AMA to hear how Trustpilot thinks about program maturity, better hacker engagement, and turning vulnerability discovery into business-ready action.
We’ll talk through how the right program helps teams move from more findings to better decisions.
🗓️ July 1
🕙 10:00am BST
Add it to your calendar: https://t.co/GUsTEFrve1
I've made $30,000+ from ONE bug class on a single program: broken access control.
Not by spamming lows by chaining them.
New vid: 5 BAC bugs → 1 full account takeover, live. And I built a free lab on @HackingHub so you can follow along.
https://t.co/XZGKbjU4GF
☁️ Cloud-native culture is about speed, learning, and adaptability.
But the faster teams ship, the more important it becomes to continuously test what could break.
Writing for CloudTech, Marc Zottner explores how organizations can build high-performing teams by moving past rigid processes, reducing bottlenecks, and learning faster.
Read more: https://t.co/DP72PgJlaQ
Here's my conversation with Don Lincoln about some of the biggest open questions in physics, including dark energy, dark matter, the matter-antimatter imbalance, quantum vacuum, quantum foam, and the quest to unify the laws of physics.
Don is a particle physicist at Fermilab who has spent decades working at the frontiers of high energy physics. He is also a great teacher & writer. I highly recommend his courses & books. One of my favorite lecture series he has given is The Evidence for Modern Physics where he breaks down the experiments that validate some of the weird laws of physics we have, and what it would take to validate even the weirder ones.
It's not enough to come up with a beautiful theory. You also have to show through experiment that the theory is likely to be correct. This process often doesn't get the love it deserves, even though it's often the most important and difficult part of the scientific process.
I ❤️ physics.
The conversation is here on X in full and is up everywhere else (see comment).
Timestamps:
0:00 - Introduction
0:49 - Unifying the laws of nature
15:20 - General relativity
32:27 - Electroweak force
44:09 - How particle colliders work
1:02:12 - Higgs boson discovery
1:12:32 - Theory of everything
1:42:17 - Physics of empty space
1:49:41 - Antimatter
2:10:31 - Dark energy
2:14:20 - Dark matter
2:42:56 - Future of physics
I originally prepared this bug for Pwn2Own Berlin. A few days before the contest, a CVE got assigned. So, here is my technical analysis and exploitation strategy for CVE-2026-40369: a 12-byte kernel increment, exploitable both as an LPE and SBX.
https://t.co/agxyuR2AjE
⚠️Claude Code's Network Sandbox Vulnerability Exposes User Credentials and Source Code
Source: https://t.co/bqHLfsSJCw
Anthropic’s Claude Code AI coding assistant harbored a critical network sandbox bypass for over five months, allowing attackers to exfiltrate credentials, source code, and environment variables from developer systems, and the company issued no public advisory for either incident.
A second complete bypass of Claude Code’s network sandbox, marking what he describes as a consistent implementation failure rather than an isolated bug.
The vulnerability, a SOCKS5 hostname null-byte injection, affected every Claude Code release from v2.0.24 (sandbox GA on October 20, 2025) through v2.1.89, spanning approximately 130 published versions over roughly 5.5 months.
#cybersecuritynews
Our security bug bounty program is now public on HackerOne.
We've run the program privately within the security research community, and their findings have strengthened our products. Now anyone can report vulnerabilities and get rewarded.
Read more: https://t.co/li1QvSTCMs
Ranking Most common /api vulnerable endpoints:
/api/v1/users
/api/v1/users/{userId}
/api/v1/oauth/token
/api/v1/forgot-password
/api/v1/debug or /api/v1/status
(not only /api/v1 also test for /api/v2)
Join my BugBounty Telegram chennal: https://t.co/J6uPf8H57o
#bugountytips
Day 2 operations for LLM inference are failing with expensive GPUs. Time to automate your strategy with @RedHat_AI to lower costs and optimize performance. Read how: https://t.co/BFcVJ1Lrr5