We've just released a high fidelity scanner for CVE-2026-41940 (cPanel/WHM authentication bypass). All public PoCs so far lead to false negatives, and are not reliable. @SLCyberSec's research team's notes on this here: slcyber.io/research-cente… & tool here: github.com/assetnote/cpan…
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push
The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
My challenge is actually based on a bug I found in Apollo Server; in its default configuration, it uses the same blacklist-based approach to prevent CSRF. I was able to bypass it and use it as an XS-Leak in default configs.
I’ll be writing a detailed write-up soon about it :)
New research just dropped by @alien2exe on hijacking OAuth popups via predictable window. open() targets.
The chain uses iframe name collision forcing the auth flow into a controlled context, eventually linking an attacker-controlled addon to leak workspace PII and config data
lab.ctbb.show/research/can-a…
GraphQL Introspection Bypass via Field Suggestions
Even with introspection disabled, GraphQL APIs leak schema information through error messages.
When introspection returns errors, exploit the suggestion feature:
> Send queries with intentional typos
> GraphQL suggests similar field names in error responses
> Tools like Clairvoyance can automate schema reconstruction
> Build a complete schema map from suggestions alone
Source👇
assetnote.io/resources/rese…
🔒 Want to move beyond passwords?
Check out this beginner's guide to Cross-Device Passkeys! Learn how "Hybrid transport" uses QR codes and Bluetooth to let you sign in securely on any device – even public ones – without ever sharing your private keys.
bughunters.google.com/blog/passkeys
172 Followers 3K FollowingTrust in His plan | God's love makes even the hardest journeys worthwhile | His love is the compass guiding your life's purpose |
4K Followers 11 FollowingHacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO
25K Followers 938 Followingعلاقهمند به کامپیوتر و شبکه | در حال تقویت حل مسئله با Rust&Go🦀 و یادگیری System Design
دونیت: https://t.co/7EJsO3DInu (Consider What I said above)
24K Followers 1K FollowingHacker. T̶h̶i̶n̶k̶i̶n̶g̶ Doing outside the box.
Founder @d_vuln
Breaking frontier AI models at https://t.co/GnRR2W3Nza
Building the worlds most dangerous AI @tryaether_ai
5K Followers 648 FollowingHacker, scientist, and most things in between.
PPP (@PlaidCTF) member for life. prev @theori_io @mayhemsec
he/his
maybe at @[email protected]
164 Followers 4 FollowingWirebrowser is a CDP-based runtime instrumentation platform for the browser. Think Frida, but for JavaScript running in Chrome — without monkeypatching.