Hey there!

You may notice a bit of a change in my content this year compared to last year. Disclosed is becoming a lot more AI-focused, but still through the bug bounty lens.

I think the reason is pretty obvious, but I’m sorry if that’s not what you were hoping to get out of this. This is still a bug bounty newsletter first and foremost, and I promise I’m not going to spam you with the same AI hype everyone else does. Everything I post here should tie back to bug bounty in some way.

Speaking of AI, I’ve started playing around with GLM 5.3 after hearing good things about it for security testing, although I’m just now getting it up and running.

Also, wtf is happening with the price of DGX Sparks? The cheapest I can find right now is around $6k, so I’m kinda regretting not jumping on one a couple of months ago when I first started considering it.

To me, one of the biggest benefits of relying on open-weight models is becoming less dependent on the frontier labs. It also gives us more control over the models we use for security research, especially when cutting-edge hosted models still place restrictions on a lot of the work we actually want to do.

Anyway, let’s dive in.

P.S. You may want to open the web version of this, as the email version gets truncated.

Nothing to promote. Just happy you’re here!

GLM-5.3 and the Spread of Advanced Cyber Capabilities [📓 Blog]

by Anthropic (@AnthropicAI)

Anthropic evaluates Zhipu AI’s GLM-5.3 and reports that it can generate end-to-end exploitation workflows, with simple jailbreaks bypassing its safeguards in a large fraction of simulated attempts. The piece contrasts that posture with Claude models that resisted the same bypasses, and argues for stronger release practices and cross-stakeholder coordination given the dual-use lift for both attackers and defenders.

PageBreak: Real-World Findings [📓 Blog]

by Google Bug Hunters

Google shares three vulnerabilities found by PageBreak, an agentic scanner that couples LLM-driven hypothesis generation with deterministic, live-site validation to keep false positives near zero. Case studies include cache poisoning on apis.google.com (missing cache-key input), an admin.google.com XSS via signature generation abuse, and a Chrome extension UXSS chain abusing origin checks and a nonce handshake. The common thread is that “reasoning” only matters if payloads are proven against real flows and boundaries (cache keys, auth/signing, extension messaging) are enforced end-to-end.

HackerOne announced an official Discord for researchers, positioned as a hub for community discussion and platform updates. The post includes an invite link for researchers who want a real-time channel alongside the platform.

Have something you want to Spotlight? Tell me.

Google VRP is temporarily pausing product vulnerability submissions for OSS VRP after a surge of automated, mostly invalid reports. Supply-chain reports and previously submitted issues are unaffected, with further updates expected in Q1 2027.

Wiz announced a 2026 bug bounty with a $6.5M pool focused on vulnerabilities in open-source components that underpin cloud infrastructure. Submissions are routed via the linked program page, framing this as an incentive push for high-impact OSS findings.

HackerOne’s new quarterly researcher update highlights platform changes through July, with a focus on clearer scope and reward expectations. Notably, a new API endpoint (structured-scopes) exposes report categories a program excludes from rewards, making it easier to wire exclusions into automation and recon workflows.

ESCAL8 2026: Agentic Hacking in Singapore [📓 Blog]

by Google Bug Hunters

Google announced ESCAL8 2026 (Oct 23–25, Singapore) spanning bugSWAT live-hacking, Hackceler8 CTF finals, and student workshops. The agenda emphasizes agentic AI security work aligned to SAIF, including indirect prompt injection, data poisoning, tool-use privilege escalation, and agent sandbox/memory integrity.

Bugcrowd published Vinted’s public engagement brief, including in-scope web and mobile assets, severity-based bounty ranges, and testing rules. The page is heavy on exclusions and reward eligibility requirements, with clear guidance on evidence quality, safe testing, and the provided test-account process.

Introducing Claude Sonnet 5.5 [📓 Blog]

by Anthropic (@AnthropicAI)

Anthropic introduced Claude Sonnet 5.5, positioning it as a faster, lower-cost option in the Claude 5.5 lineup with claims of large benchmark gains and improved image/document handling. The announcement is product-focused (performance, pricing, safety notes) and does not include security-specific guidance or new offensive/defensive workflows.

Omarchy announced a HackerOne program backed by a $100,000 bounty pool, with reports accepted via the platform and a security@ email fallback. The post also notes a security leadership hire to run the program, signaling a more formal triage and remediation pipeline.

10 Years of Intigriti [📓 Blog]

by Intigriti

The linked page resolves to a cookie/privacy policy listing cookie categories, names, and retention periods rather than an anniversary announcement. There’s no bug bounty or security-research content to extract beyond compliance details.

Did I miss an important update? Tell me.

Zurp is a Meta-focused toolkit for vetted researchers that combines a Burp extension with MCP stdio servers to make captures more replayable and automation/agent workflows more reliable. It includes token placeholdering for fb_dtsg/lsd/CSRF-style values, helpers for resolving internal identifiers, and utilities for fetching test accounts and labeling context. The repo documents setup, access gating, and integration patterns for using the same primitives from Burp or from agent runtimes.

Living off Someone Else's Inference [📓 Blog]

by Sentry Security

Sentry describes “infreerence,” an open-source approach for finding exposed inference endpoints and leaked provider credentials that enable unauthorized “free inference.” The post covers measurement results, YAML-driven search/probe templates, and live verification heuristics to distinguish real infrastructure from honeypots and attribute keys/providers.

This browser extension exports bug bounty scopes and policies as Markdown/JSON with provenance metadata for diff-friendly tracking. It canonicalizes captured sections, strips volatile data, and generates SHA-256 fingerprints so researchers can detect meaningful scope/policy changes without noise. Adapters and tests are included to support multiple platforms and consistent captures.

0sec-labs’ “0” is a research-preview agent that targets end-to-end vuln discovery and reproduction, shipping as a CLI with prebuilt workflows and test targets. The repo emphasizes repeatable validation via a local workbench and CI, aiming to keep agent outputs grounded in reproducible artifacts rather than pure model assertions. It’s still experimental, but the engineering focus is clearly on safe, local reproduction and regression-style checking.

This post analyzes CVE-2026-88771, a pre-auth command injection in Citrix NetScaler exploited in the wild, using patch diffing to pinpoint the vulnerable shelling-out pattern and the safer list-form execution fix. It includes a concrete trigger payload and practical notes for defenders racing to validate and mitigate exposure.

Have a favorite tool? Tell me.

Johann Rehberger details attacks against SQL Copilot in SSMS (CVE-2026-65669), showing that “read-only” enforcement can collapse into regex-based intent classification with multiple practical bypasses. The write-up also demonstrates indirect prompt injection via persistent database metadata to influence higher-privilege sessions and escalate to sysadmin, with mitigations focused on enforcing permission invariants and constraining privileged agent connections.

Mehmet İnce examines how “security-hardening” PostgreSQL extensions can create brief superuser windows that attackers can reliably abuse for escalation. The post provides a concrete primitive—abusing name resolution around CREATE FOREIGN DATA WRAPPER to execute a validator under elevated context—and frames it as a systemic class affecting multiple managed Postgres vendors. The main defensive message is to eliminate privilege-borrowing code paths or make them non-bypassable under adversarial input and timing.

Hijacking an AI Agent Platform with a Single Email (Manus) [📓 Blog]

by Salt Labs (@SaltSecurity)

Salt Labs reports a prompt-injection style takeover of Manus via its Gmail integration, where attacker-controlled email content was interpreted as executable agent instructions. The researchers describe bypassing content guardrails with encoding/obfuscation (including JSFuck) to reach downstream actions across connected services. The takeaway is that prompt filtering is not a control boundary unless execution, tool permissions, and side effects are constrained at the integration layer.

SalesBleed: 0-Click Data Exfiltration in Salesforce Agentforce [📓 Blog]

by Zenity Labs (@zenitysec_labs)

Zenity Labs details “SalesBleed,” a 0-click data exfiltration chain against Salesforce Agentforce starting from a public Web-to-Lead submission and ending in a covert DNS-based leak. The write-up focuses on how prompt sources and URL “trust” controls were bypassed to smuggle exfil instructions into the agent context, and what Salesforce changed to harden those paths. It’s a strong case study in why outbound channels and tool egress need first-class policy enforcement for agents.

watchTowr breaks down CVE-2026-88772, a pre-auth DTLS overflow in NetScaler’s nsppe, tying the bug to record reassembly and unsafe memcpy into a fixed-size scratch buffer. The post walks through the full exploitation path from handshake shaping to code execution, and includes patch diffing plus build-level guidance for identifying fixed versions.

SEC Consult describes two iCloud Mail spoofing issues by exploiting parsing discrepancies they call “header smuggling,” building on SMTP smuggling-style primitives. The post shows how crafted messages can be processed in a way that forges iCloud identities despite common checks, with technical examples and mitigation discussion for mail pipeline hardening.

oxship walks through finding an unauthenticated SQLi in an exposed SOAP (ASMX) integration backed by production MSSQL, including recon and error-driven validation without pulling customer data. The write-up highlights practical reporting lessons—clear evidence, per-operation retest tracking—and ends with a blunt remediation: the unused integration was shut down.

Cloudflare: Cross-Tenant Data Exposure in Containers [📓 Blog]

by Cloudflare (@cloudflare)

Cloudflare details a cross-tenant data exposure in Containers/Sandboxes where residual disk blocks could be recovered opportunistically by another tenant on the same host. The post explains constraints that limited targeting, describes the fleet-wide remediation to sanitize residual data, and notes no evidence of malicious exploitation in telemetry.

Did I miss something? Tell me.

This Dojo solution demonstrates a Unicode/byte-length mismatch in a Node.js session parser where validation happens on UTF-8 bytes but iteration occurs over characters. A multibyte character is used to smuggle JSON that manipulates a Sequelize where clause, forcing a lookup that returns user ID 1. The write-up includes payload construction and hardening notes around input validation and safer ORM usage.

Learn AI Security: Hands-On Series [📓 Blog]

by GenAI Security Lab (@genaiseclab)

GenAI Security Lab’s curriculum provides hands-on modules for testing LLM and agent systems using live targets, organized around common failure modes like prompt injection, data leakage, and RAG/embedding weaknesses. Each section pairs offensive exercises with concrete defensive controls and verification steps, mapping content to frameworks like OWASP LLM Top 10 and agent/MCP threat models.

This episode recap covers Turbo Intruder 2’s HTTP/3/QUIC throughput and what that changes for brute-force feasibility, plus a practical rate-limit bypass using matrix path parameters. It also introduces Jev, a small “ranker” model and workflow (siftrank) meant to prioritize large candidate sets before handing execution to bigger models or tooling. The latter half discusses bounty-economy pressure signals and the need for human-in-the-loop harnesses and stronger systems thinking on remediation.

Free 21-Chapter Course on Breaking AI Systems [𝕏 Tweet]

by Deepak Dhiman (@Virdoex_hunter)

Deepak Dhiman shared a free 21-chapter course covering offensive and defensive techniques for AI systems, spanning prompt injection, jailbreaks, RAG poisoning, agent RCE, and training-time backdoors. The thread claims the material includes real CVEs and hands-on labs with at least one end-to-end exploit walkthrough.

Building an XSS Scanner That I Can Actually Trust [📓 Blog]

by Arthur Johann Wilmsen Witt

Arthur Johann Wilmsen Witt outlines a context-aware approach to XSS scanning that treats reflection as a starting signal, not a finding. The design emphasizes context classification, character-survival testing, and targeted payload generation, with headless browser validation reserved for high-confidence cases. It’s a practical blueprint for reducing false positives while still catching transformation-driven edge cases.

This profile interviews Issam Rabhi (rabhi) on a workflow centered on manual testing, with automation largely confined to reconnaissance. He discusses preferred bug classes (access control, XSS, SQLi), tooling habits, and how he evaluates targets over time, along with candid notes on sustainability and mental health in long-running bounty work.

Did I miss something? Tell me.

WordPress Core Bug Leading to RCE (CVE-2026-87902) [🎥 Video]

by Ben Sadeghipour (@NahamSec)

Ben Sadeghipour walks through CVE-2026-87902, a WordPress core issue that can be driven to remote code execution under the right conditions. The video focuses on the practical exploit path and what to look for when validating impact across real deployments.

Using Jev for Bug Bounty (Ep. 194) [🎥 Video]

by Critical Thinking Podcast

This episode explores Jev, a small ranker model used to prioritize large candidate sets (payloads, endpoints, ideas) before spending time or tokens on deeper analysis. It also touches on pairing rankers with larger models and automation to keep bug bounty workflows throughput-oriented and reproducible.

Hackbots (DEF CON 34, BBV Masterclass) [🎥 Video]

by Bug Bounty Village

Jason Haddix presents an “agent harness” approach for scaling recon and exploitation with repeatable, testable skills driven by LLMs like Claude Code. The talk covers skill decomposition, guardrails for skipped steps/refusals, and war stories that show where agentic workflows can realistically pay off. Practical guidance focuses on checklists, output conventions, multi-run strategies, and verification discipline.

Nextcloud Bug Bypassing Privacy Settings [🎥 Video]

by Logan-sec (Logan-sec)

Logan-sec analyzes a Nextcloud issue where authenticated users could bypass admin-configured privacy restrictions and enumerate users beyond intended groups. The walkthrough emphasizes a reliable bounty pattern: identify a promised control, then enumerate adjacent features/endpoints to find inconsistent enforcement. A linked report provides additional context for validation and remediation.

Hacking IDE Extensions (DEF CON 34, BBV Workshop) [🎥 Video]

by Bug Bounty Village

This workshop demonstrates how a malicious or vulnerable VS Code extension can compromise a developer environment before trust prompts are resolved. The presenter shows a live exploit chain against a deliberately vulnerable .vsix lab and connects the risks to extension supply chain realities, including AI coding assistants. The main defensive theme is treating extensions as executable code with strict vetting and isolation requirements.

Leaking Private WordPress Posts Without Login [🎥 Video]

by Medusa (@medusa_0xf)

Medusa demonstrates an unauthenticated information disclosure in a WordPress plugin that allowed private posts to be retrieved without authentication. The video walks through endpoint discovery, request shaping, and how similar exposures can be identified across other installs. It’s a reminder that “private” content hinges on consistent access control across every plugin surface area.

Going From Bug Bounty Bugs to More Secure Systems (ASW #402) [🎥 Video]

by Security Weekly (@SCMagazine)

Shlomie Liberow discusses why high-impact bounty fixes often require systemic changes rather than localized patches, using recent incidents and bug patterns as examples. The conversation touches on how automation and LLMs are changing research workflows, and what that means for triage, vulnerability management, and durable mitigations.

Did I miss something? Tell me.

Chrome’s <camera> Tag Introduces a New XSS Vector [𝕏 Tweet]

by Gareth Heyes (@garethheyes)

Gareth Heyes points to research showing Chrome’s new <camera> element can be abused as an XSS primitive. The technique was added to an XSS cheat sheet, making it a useful edge-case payload source for filter-bypass testing.

Unicode Dash Bypass: curl.exe Argument Injection on Windows [𝕏 Tweet]

by André Baptista (@0xacb)

André Baptista highlights a filter bypass where a full-width Unicode dash (-) slips past “block '-'” checks, then gets normalized back to '-' by Windows curl.exe. In practice, that can turn input into an injected -o write, enabling webshell-style file drops where curl output is attacker-controlled.

Sandboxed Iframes as an XSS Helper (Blocking Auto-Submits) [𝕏 Tweet]

by Critical Thinking Podcast

The thread suggests using a sandboxed iframe to control target behavior during testing: omitting allow-forms blocks auto-submitting forms and omitting allow-scripts disables page JS while still rendering HTML/CSS. That setup can preserve a click path for javascript: links that would otherwise be disrupted by redirects or scripted navigation.

Use AI to Write Automation, Not to Replace It [𝕏 Tweet]

by Jason Haddix (@Jhaddix)

Jason Haddix argues that LLMs are better used to generate scripts than to run repeatable actions directly in a loop. The point is operational: scripts are deterministic, composable, and less likely to get derailed by refusals or classification behavior in automated pipelines.

Did I miss something? Tell me.

Did you like this week's drop?

Please share feedback.

Login or Subscribe to participate

Because Disclosure Matters: This newsletter was produced with the assistance of AI. While I strive for accuracy and quality, not all content has been independently vetted or fact-checked. Please allow for a reasonable margin of error. The views expressed are my own and do not reflect those of my employer.