πͺ² CVE-2026β44722: A Zip encryption downgrade caused by an incorrect operator β’ πͺ² Finding six NGINX vulnerabilities with open models β’ π€ Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Every few weeks, another startup announces an AI pentester. Looking at the market, it feels as though the future of AI ...
βοΈ ethiack / ethibench β’ βοΈ capitalone / VulnHunter β’ πͺ² FastJson 1.2.83 Remote Code Execution
After the Allies broke Enigma during the Second World War, they faced an unusual problem. The difficult part was no longer ...
π€ Special Token Injection (STI) Attack Guide β’ πͺ² MAD Bugs: My Cousin Vinyl (CVE-2026-50052) β’ πͺ² From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
With AI, technical interviews are becoming harder and harder to trust. Candidates now have access to automated tools designed to help ...
π₯οΈ Local AI for Penetration Testing & Research β’ π§ The context an agent needs to find the next vulnerability. β’ π€ The Bug Bounty Singularity: Our Hackbot
I have been travelling to conferences across Europe this year, running workshops and giving talks, mostly on code review and CVE ...
π©Ή Introducing Patch the Planet β’ π€ Building an AI pentesting platform β’ π€ Comparing AI Application Security Testing Platforms
π΄ DietrichGebert / ponytail β’ π€― curl summer of bliss β’ βοΈ Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
πͺ² Jupyter Enterprise Gateway β’ π€ Measuring LLMsβ impact on N-day exploits β’ π Bypassing a 3 layer SVG sanitizer: Stored XSS in Mozilla
π Letβs talk about encrypted reasoning β’ π Golang code review notes II β’ π€ The sorry state of skill distribution
A big part of what I do for PentesterLab is reading CVEs. I spend a lot of time going through them: ...