We've reproduced the pre-auth RCE chain in Wordpress (wp2shell). It's real, patch!
Shoutout to @hash_kitten at Assetnote for catching such an awesome bug!
Claude Code Full Sandbox Escape (CVE-2026-55607)
writeup: https://t.co/kzJ04Fqu4Y
prompt injection -> code execution on the host.
works even in read-only permissions mode + full sandbox
(it could be my Pwn2Own bug, but p2o was weird this year lol)
🚨 WARNING — New HTTP/2 Bomb exploit targets NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
A single client can consume 32GB of server memory in roughly 20 seconds, causing remote DoS conditions.
Details here: https://t.co/58xDxAKRcZ
when react2shell hit last year, i think vercel handled it brilliantly.
to protect their users, they paid $50,000 for every bypass researchers could find. we decided to participate, and ended up earning $170,000.
read how we did it here: https://t.co/2dM6Mf9PHU
Obfuscated #WebSocket backdoors are injecting credit card skimmers into hundreds of compromised websites. The payload sends stolen card information back to attacker's C2 domains. Details at: https://t.co/3UIzhZXYCv
Sure, I could publish everything and force them to fix it within hours... but I won’t. I did my part: I tested the app, found the issues, and reported them responsibly. I can live with that. If anything happens, it’s on them for failing to act.
This happened to me a few months ago. I tested an app because I was a regular user, and I ended up discovering several serious vulnerabilities, millions of chats, hundreds of thousands of users, their PII, and numerous files were exposed.
if you've ever used Reframe to get sober, your private journals, your craving logs, what triggered you, how bad it got, your name, your email, all of it is sitting in a database that anyone can read without logging in
i unzipped the app and found a database key in a config file. thats it. thats all it took
357,939 users exposed. disclosed april 7, no response