I ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn't make money, so here's the code, the model and 13k real bypass attempts
https://ift.tt/ANlUSMY
Submitted July 22, 2026 at 11:41PM by BordairAPI
via reddit https://ift.tt/zC0JN62
https://ift.tt/ANlUSMY
Submitted July 22, 2026 at 11:41PM by BordairAPI
via reddit https://ift.tt/zC0JN62
huggingface.co
Bordair/bordair-detector · Hugging Face
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
GitHub issues $100,000 bounty for critical RCE vulnerability
https://ift.tt/kj41l0y
Submitted July 23, 2026 at 03:51AM by ryanmerket
via reddit https://ift.tt/bXhal6z
https://ift.tt/kj41l0y
Submitted July 23, 2026 at 03:51AM by ryanmerket
via reddit https://ift.tt/bXhal6z
RuntimeWire
GitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_
Researcher @sagitz_ disclosed a remote code execution vulnerability in GitHub, earning a $100,000 bounty—the largest payout in the platform's bug bounty program.
PE OopsSec: Mind your PE, guard your OPSEC
https://ift.tt/Af1KzbT
Submitted July 23, 2026 at 05:42AM by Cold-Dinosaur
via reddit https://ift.tt/rEKh26S
https://ift.tt/Af1KzbT
Submitted July 23, 2026 at 05:42AM by Cold-Dinosaur
via reddit https://ift.tt/rEKh26S
Zerosalarium
PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE
https://ift.tt/KorT0vl
Submitted July 23, 2026 at 01:15PM by No_Zookeepergame7552
via reddit https://ift.tt/NkXMpfd
https://ift.tt/KorT0vl
Submitted July 23, 2026 at 01:15PM by No_Zookeepergame7552
via reddit https://ift.tt/NkXMpfd
Uphack
WP2Shell: Pre Authentication RCE in WordPress Core | Uphack
Reproduce the wp2shell unauth WP RCE that combines REST batch-route confusion (CVE-2026-63030) and WP_Query SQL injection (CVE-2026-60137).
Open Evaluation Framework for AI Pentesting Agents on Real-World Targets
https://ift.tt/4RN2d0G
Submitted July 23, 2026 at 06:54PM by ZealousidealHunter80
via reddit https://ift.tt/6LvwPEA
https://ift.tt/4RN2d0G
Submitted July 23, 2026 at 06:54PM by ZealousidealHunter80
via reddit https://ift.tt/6LvwPEA
arXiv.org
From Controlled to the Wild: Evaluation of Pentesting Agents for...
AI pentesting agents are increasingly credible as offensive security systems, but current benchmarks still provide limited guidance on which will perform best in real-world targets. Existing...
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
https://ift.tt/d4VunxK
Submitted July 23, 2026 at 06:45PM by scamdrill
via reddit https://ift.tt/LyzpPRc
https://ift.tt/d4VunxK
Submitted July 23, 2026 at 06:45PM by scamdrill
via reddit https://ift.tt/LyzpPRc
ScamDrill
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
It needs no password and breaks no MFA. How device code phishing hijacks Microsoft 365 with a single code, and the one Entra setting that blocks it.
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
https://ift.tt/JO2fXkz
Submitted July 24, 2026 at 12:03AM by Straight-Practice-99
via reddit https://ift.tt/Rew9ijl
https://ift.tt/JO2fXkz
Submitted July 24, 2026 at 12:03AM by Straight-Practice-99
via reddit https://ift.tt/Rew9ijl
hunt.io
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
https://ift.tt/OmUfSoh
Submitted July 24, 2026 at 03:41AM by fede_k
via reddit https://ift.tt/qjpXmEo
https://ift.tt/OmUfSoh
Submitted July 24, 2026 at 03:41AM by fede_k
via reddit https://ift.tt/qjpXmEo
XBOW
Bing Images RCEs: How XBOW Found Three Critical Flaws | XBOW
See how XBOW autonomously uncovered three critical Microsoft RCEs by tracing ordinary image-processing and file-upload paths to proven code execution.
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
https://ift.tt/7gpL4l2
Submitted July 24, 2026 at 11:23AM by natcoba
via reddit https://ift.tt/N1DK5HC
https://ift.tt/7gpL4l2
Submitted July 24, 2026 at 11:23AM by natcoba
via reddit https://ift.tt/N1DK5HC
Accomplish
SharedRoot; Escaping the Claude Cowork sandbox — Accomplish Blog
Untrusted content in a Claude Cowork session can escape the VM it's sandboxed in and read and write files anywhere on your Mac. The kernel bug that makes it possible isn't the interesting part. Four design decisions are, and they'd have stopped the next kernel…
The way AI voice phishing gets demonstrated is making people worse at spotting it
https://ift.tt/IFWCcXH
Submitted July 24, 2026 at 05:42PM by gyanchawdhary
via reddit https://ift.tt/mq2XDfa
https://ift.tt/IFWCcXH
Submitted July 24, 2026 at 05:42PM by gyanchawdhary
via reddit https://ift.tt/mq2XDfa
Callstrike
Free Voice Phishing Simulator | Callstrike
Hear your own voice cloned in real time and understand why your team is vulnerable to vishing.
DEF CON Middle East Postponed
https://ift.tt/SCyEVfr
Submitted July 24, 2026 at 09:11PM by mepper
via reddit https://ift.tt/SO0uR41
https://ift.tt/SCyEVfr
Submitted July 24, 2026 at 09:11PM by mepper
via reddit https://ift.tt/SO0uR41
defcon.org
DEF CON® Hacking Conference - Recent News
Get the latest updates concerning DEF CON and the next DEF CON Conference!
Announcing the External Penetration Testing Program Pack
https://ift.tt/9CaUn6f
Submitted July 24, 2026 at 11:35PM by SecTemplates
via reddit https://ift.tt/2THLkeh
https://ift.tt/9CaUn6f
Submitted July 24, 2026 at 11:35PM by SecTemplates
via reddit https://ift.tt/2THLkeh
What syscall-layer tooling cannot see in P2P infrastructure
https://ift.tt/LflNgc0
Submitted July 25, 2026 at 01:21AM by differentialwidget
via reddit https://ift.tt/2MBcYol
https://ift.tt/LflNgc0
Submitted July 25, 2026 at 01:21AM by differentialwidget
via reddit https://ift.tt/2MBcYol
NullRabbit
What syscall-layer tooling cannot see in P2P infrastructure: a technique-by-technique analysis
If you run Falco, an EDR, or a generic host agent on a validator and a network-DoS attack against the node went undetected, this explains why. A technique-by-technique analysis of five reproduced P2P-infrastructure attacks against the syscall detection surface.…
A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network
https://ift.tt/YZFdSti
Submitted July 25, 2026 at 03:53PM by Huge-Skirt-6990
via reddit https://ift.tt/b8iFODK
https://ift.tt/YZFdSti
Submitted July 25, 2026 at 03:53PM by Huge-Skirt-6990
via reddit https://ift.tt/b8iFODK
malext.io
RoguePlanet - 2 million installs, one hijacked search bar - MalExt Sentry
Threat intelligence report: RoguePlanet - 2 million installs, one hijacked search bar. Research by MalExt Sentry.
Pentesting vibe-coded applications: JWT flaws, exposed secrets, and broken authorization
https://ift.tt/sV5bj7q
Submitted July 25, 2026 at 07:42PM by Mindless-Study1898
via reddit https://ift.tt/r1FXDVW
https://ift.tt/sV5bj7q
Submitted July 25, 2026 at 07:42PM by Mindless-Study1898
via reddit https://ift.tt/r1FXDVW
Cred Relay
Pentesting Vibe Coded Applications
Practical pentesting notes for vibe-coded apps, covering JWT flaws, exposed secrets, broken authorization, SSRF, and other boundary failures.
Use Protocols, Not Services
https://ift.tt/HFviwnT
Submitted July 26, 2026 at 07:30PM by fagnerbrack
via reddit https://ift.tt/XdouhK3
https://ift.tt/HFviwnT
Submitted July 26, 2026 at 07:30PM by fagnerbrack
via reddit https://ift.tt/XdouhK3
Notnotp
Use Protocols, Not Services
The Internet is almost anonymous and privacy-preserving by design. I mean, unless some administrator actively tries to track you, there is no built-in...
From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share.
https://ift.tt/MlyekSW
Submitted July 27, 2026 at 11:55AM by dinkoism
via reddit https://ift.tt/ROo4Qmr
https://ift.tt/MlyekSW
Submitted July 27, 2026 at 11:55AM by dinkoism
via reddit https://ift.tt/ROo4Qmr
Substack
How a fake Claude Code install guide delivered the MacSync malware
A technical analysis of a live Google Ads malvertising campaign abusing Claude AI, Base64-obfuscated shell commands and trusted domains to deliver the MacSync infostealer.
New vBulletin Vulnerability!
https://ift.tt/aPidLqQ
Submitted July 27, 2026 at 07:30PM by SSDisclosure
via reddit https://ift.tt/TFeLBD7
https://ift.tt/aPidLqQ
Submitted July 27, 2026 at 07:30PM by SSDisclosure
via reddit https://ift.tt/TFeLBD7
SSD Secure Disclosure
vBulletin Runtime Template runMaths Preauth RCE - SSD Secure Disclosure
Summary A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server. Vendor Response The vendor has issued a fix available at: https://foru…
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
https://ift.tt/DFIzOwV
Submitted July 27, 2026 at 08:37PM by EatonZ
via reddit https://ift.tt/lE6Yvto
https://ift.tt/DFIzOwV
Submitted July 27, 2026 at 08:37PM by EatonZ
via reddit https://ift.tt/lE6Yvto
Eaton-Works
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
VE Commercial Vehicles’ My Eicher platform had a critical vulnerability that let you take over anyone’s account and gain control over their vehicle fleets.
BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
https://ift.tt/y0b7z1L
Submitted July 27, 2026 at 09:59PM by Huge-Skirt-6990
via reddit https://ift.tt/r7YsWDT
https://ift.tt/y0b7z1L
Submitted July 27, 2026 at 09:59PM by Huge-Skirt-6990
via reddit https://ift.tt/r7YsWDT
malext.io
BrainDrain - SecondBrain's Prompt Optimizer Collects Your AI Chats - MalExt Sentry
Threat intelligence report: BrainDrain - SecondBrain's Prompt Optimizer Collects Your AI Chats. Research by MalExt Sentry.
Pollard's P-1 Factoring Algorithm in Plain C
https://ift.tt/gQcU2M3
Submitted July 28, 2026 at 03:24AM by DataBaeBee
via reddit https://ift.tt/Ns1wfbn
https://ift.tt/gQcU2M3
Submitted July 28, 2026 at 03:24AM by DataBaeBee
via reddit https://ift.tt/Ns1wfbn
Substack
Pollard's P-1 Factoring Algorithm in Plain C
Coding Pollard's 1974 Paper on Factoring Within P-1 Multiplicative Subgroups