Webhook SSRF filter bypass: many servers block 301/302 redirects but follow 303 See Other.
Host a PHP script returning 303 to the internal target:
ex.👇
Source: Omise #508459 (AWS keys leaked in webhook delivery log).
We just got a new post by @avlidienbrunn on the lab!
He brought it up in the #researchers exclusive chat and we HAD to post it.
Go check it out!
https://t.co/v2yNzTTYNK
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer!
The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below:
https://t.co/nY20Anz0VO
(and thanks @garethheyes for making Shazzer!)
My first research with Ethiack just came out. Abusing redirect discrepancies to leak secrets in URLs by using the browser's fragment handling. Hope you like it
https://t.co/0Gd5wQlkZo
HackerNotes TLDR for episode 174: https://t.co/KiOUyb0VVg
►⠀Salesforce Marketing Cloud got popped through Ampscript template injection plus an unauthenticated CBC bit-flipping attack. The 8 null-byte trick to leak the IV is the kind of crypto move you should keep in mind.
►⠀cPanel WHM auth bypass (CVE-2026-41940) chains a CRLF injection into a session file on disk with two different auth methods, then beats a cache to land a pre-auth session.
►⠀A single .git directory delete on Google Cloud Looker leads to RCE because git falls back to reading config from the working directory when .git is missing. Variant goldmine for any code sandbox that lets you touch the filesystem.
►⠀Skill optimizer from Tessl, prompt injection to deterministic XSS, and GPT-5.5 actually competing with Claude on black-box hacking. Lots of moving pieces this week.