The $0 IDOR That Was Worth More Than a $12,500 P1 by Meena 🤯🔥
👨💻 Abhishek Meena (Aacle)
🔗 https://medium.com/bugbountywriteup/the-0-idor-that-was-worth-more-than-a-12-500-p1-4444d32f2f61
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Abhishek Meena (Aacle)
🔗 https://medium.com/bugbountywriteup/the-0-idor-that-was-worth-more-than-a-12-500-p1-4444d32f2f61
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥2
AsyncAPI npm packages backdoored via GitHub Actions by Silva 🤯🔥
👨💻 Raphael Silva (Aikido Security)
🔗 https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions
👨💻 Raphael Silva (Aikido Security)
🔗 https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions
❤3
This media is not supported in your browser
VIEW IN TELEGRAM
[CVE-2026-63030/CVE-2026-60137]
wp2shell: Pre Authentication RCE in WordPress Core Searchlight Cyber Team 🤯🔥
👨💻 Adam Kues (x/hash_kitten)
🔗 https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
🔗 https://wp2shell.com/
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-60137
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-63030
wp2shell: Pre Authentication RCE in WordPress Core Searchlight Cyber Team 🤯🔥
👨💻 Adam Kues (x/hash_kitten)
🔗 https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
🔗 https://wp2shell.com/
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-60137
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-63030
🔥3🤔1
PoC:
[CVE-2026-63030/CVE-2026-60137] Pre Authentication RCE in WordPress Core 👾💥
- https://github.com/0xsha/wp2shell
- https://github.com/Icex0/wp2shell-poc
- https://github.com/sergiointel/wp2shell-poc
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
- https://nvd.nist.gov/vuln/detail/CVE-2026-60137
- https://nvd.nist.gov/vuln/detail/CVE-2026-63030
[CVE-2026-63030/CVE-2026-60137] Pre Authentication RCE in WordPress Core 👾💥
- https://github.com/0xsha/wp2shell
- https://github.com/Icex0/wp2shell-poc
- https://github.com/sergiointel/wp2shell-poc
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
- https://nvd.nist.gov/vuln/detail/CVE-2026-60137
- https://nvd.nist.gov/vuln/detail/CVE-2026-63030
❤2👍1
$1,600 Shopify Bug Bounty 🤑
Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering by saltymermaid 🤯🔥
👨💻 saltymermaid
🔗 https://hackerone.com/reports/2509022
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
Reflected XSS in AI Chat Bot Greetings at help.shopify.com via Markdown Image Rendering by saltymermaid 🤯🔥
👨💻 saltymermaid
🔗 https://hackerone.com/reports/2509022
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥5❤1
Bypassing LFI (Local File Inclusion) by Yadav 👾💥
👨💻 Abhishek Yadav (x/abhishekY495)
🔗 https://medium.com/@abhishekY495/bypassing-lfi-local-file-inclusion-ebf4274e7027
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Abhishek Yadav (x/abhishekY495)
🔗 https://medium.com/@abhishekY495/bypassing-lfi-local-file-inclusion-ebf4274e7027
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤1
$1,337 8x8 Bug Bounty 🤑
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability by Ferreira 🤯🔥
👨💻 Kauã Ferreira (x/0xkyotozx)
🔗 https://hackerone.com/reports/3800870
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability by Ferreira 🤯🔥
👨💻 Kauã Ferreira (x/0xkyotozx)
🔗 https://hackerone.com/reports/3800870
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥3❤1
0.5 XMR (175 USD) Monero Bug Bounty 🤑
ZMQ RPC Log Injection and Untrusted Payload Persistence by redlobsterz 🤯🔥
👨💻 redlobsterz (h1/redlobsterzzz)
🔗 https://hackerone.com/reports/3621606
🔗 https://github.com/monero-project/monero/pull/10388
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
ZMQ RPC Log Injection and Untrusted Payload Persistence by redlobsterz 🤯🔥
👨💻 redlobsterz (h1/redlobsterzzz)
🔗 https://hackerone.com/reports/3621606
🔗 https://github.com/monero-project/monero/pull/10388
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤2🔥2
"How I Found Open-Source 0-days with an LLM Multi-Agent Workflow" by Hyunseo Shin 🤯🔥
👨💻 Hyunseo Shin (se1en)
🔗 https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-days-with-an-LLM-Multi-Agent-Workflow
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Hyunseo Shin (se1en)
🔗 https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-days-with-an-LLM-Multi-Agent-Workflow
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
❤3👍2
This media is not supported in your browser
VIEW IN TELEGRAM
IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years 🤯🔥
👨💻 Nebula Security
🔗 https://nebusec.ai/research/ionstack-part-2/
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
👨💻 Nebula Security
🔗 https://nebusec.ai/research/ionstack-part-2/
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥5
$42,751 Ubiquiti Inc. Bug Bounty 🤑
Pre-Auth RCE in UniFi OS - CVE-2026-34909: One Request to Root Behind Seven Products by Catchify Security 🤯🔥
👨💻 Abdulaziz Almadhi (Catchify Security)
🔗 https://www.catchify.sa/post/pre-auth-rce-unifi-os-one-request-to-root
CVEs
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-34909
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50747
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50748
Pre-Auth RCE in UniFi OS - CVE-2026-34909: One Request to Root Behind Seven Products by Catchify Security 🤯🔥
👨💻 Abdulaziz Almadhi (Catchify Security)
🔗 https://www.catchify.sa/post/pre-auth-rce-unifi-os-one-request-to-root
CVEs
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-34909
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50747
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-50748
🤯4😱2👍1🔥1
Enumerable Lead ID Exposes Millions of Car-Buyer Records and Lets Anyone Overwrite Their Contact Details by Marius du Preez 🤯🔥
👨💻 Marius du Preez (mdpsec.com)
🔗 https://mdpsec.com/reports/auto-lead-platform-enumerable-id-unauth-idor-pii/
👨💻 Marius du Preez (mdpsec.com)
🔗 https://mdpsec.com/reports/auto-lead-platform-enumerable-id-unauth-idor-pii/
🔥2
$1,500 AI System Prompt Leak: Using this Burp Suite Configuration by cTino 🤯🔥
👨💻 cTino(x/tinopreter)
🔗 https://medium.com/@tinopreter/1-500-ai-system-prompt-leak-using-this-burp-suite-configuration-e1cb6ab27dc5
👨💻 cTino(x/tinopreter)
🔗 https://medium.com/@tinopreter/1-500-ai-system-prompt-leak-using-this-burp-suite-configuration-e1cb6ab27dc5
🔥5❤2
From Deep Link to Shell: Easy $3000 Android Crits by tinopreter 🤯🔥
👨💻 cTino (x/tinopreter)
🔗 https://medium.com/the-first-digit/from-deep-link-to-shell-easy-3000-android-crits-866f2a002a3c
👨💻 cTino (x/tinopreter)
🔗 https://medium.com/the-first-digit/from-deep-link-to-shell-easy-3000-android-crits-866f2a002a3c
🔥3😱1
0.25 XMR Monero Bug Bounty 🤑
👨💻 Beni Saprulah (h1/benisprlh)
🔗 https://hackerone.com/reports/3687543
🔗 https://github.com/monero-project/monero/pull/10434
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
relay_tx wallet-rpc skips --restricted-rpc guard and lets any caller corrupt wallet state via attacker-controlled pending_tx by Beni Saprulah 🤯🔥👨💻 Beni Saprulah (h1/benisprlh)
🔗 https://hackerone.com/reports/3687543
🔗 https://github.com/monero-project/monero/pull/10434
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥3
$12,000 Mozilla Bug Bounty 🤑
Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift $where) by Griffin 🤯🔥
👨💻 Griffin (x/aussinfosec)
🔗 https://hackerone.com/reports/3782701
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
Unauthenticated RCE in Taskcluster web-server via GraphQL filter argument (sift $where) by Griffin 🤯🔥
👨💻 Griffin (x/aussinfosec)
🔗 https://hackerone.com/reports/3782701
🔗 https://t.me/ZeroToBug
🔗 https://whatsapp.com/channel/0029VbCTM6RDp2QAFE8r140p
🔥6❤1
$150,000 Apple Bug Bounty 🍎
[CVE-2026-20685] Beyond Prompt Injection: Hacking Apple's Private Cloud Compute 🤯🔥
🔗 https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-20685
[CVE-2026-20685] Beyond Prompt Injection: Hacking Apple's Private Cloud Compute 🤯🔥
🔗 https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/
🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-20685
🤯6❤4