⚡ Latest Weekly Recap is out...
🚨 Oracle 0-Day exploited
🤖 Nation-state AI abuse on the rise
🎣 npm phishing spreading fast
💀 New ransomware cartel emerges
…and more
The threat landscape is moving fast — here’s what defenders need to know.
🔗 https://t.co/CAfkLle0V8
@golu_369@TMobile Frustrated by their responses, I exploited the unaddressed issue to demonstrate its impact by changing configuration files and deleting data. This led to my permanent ban from Bugcrowd.
@golu_369@TMobile I was banned too last year after reporting six critical vulnerabilities, including (RCE) and admin access. These were marked as P3 or P4 with no impact. While the company fixed most of the issues, one vulnerability remained unaddressed.
🚨Incognito Market Admin Arrested🚨
The United States DoD just announced the arrest of market admin ‘Pharoh’.
LE is on a roll the past couple months.
More updates later on as I dive into this indictment.
Thanks to @DoingFedTime for sharing the image below.
Hey @BitarooExchange ,I've identified a critical bug on your website, resulting in a potential account takeover. Despite reporting it two months ago, it seems the team might not have grasped the severity. Could you please provide the appropriate channel for reporting such issues?
Hello @Starbucks I have identified severe security vulnerabilities leading to user email exposure and unauthorized access to gift card information.I've validated over 100 active gift cards with loaded balances.Despite attempting to report on HackerOne, encountered issues. #bug