This media is not supported in your browser
VIEW IN TELEGRAM
๐ด Another serious security vulnerability has been discovered in Redis 8.8.0, and no POC has been released yet for this bidirectional RCE found by v12sec.
๐4
Forwarded from Brut Security
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฅTORLINK: A torrent finder that runs right from your terminal with zero setup and nothing to configure.
One search checks a small curated list of sources at once. Pick what you want, and it downloads directly to your computer.
GitHub: https://github.com/baairon/torlink
One search checks a small curated list of sources at once. Pick what you want, and it downloads directly to your computer.
GitHub: https://github.com/baairon/torlink
โค1๐ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฅ Chrome RCE PoC: CVE-2026-6307
A working renderer RCE Proof of Concept for CVE-2026-6307 โ a V8 type-confusion bug (JS-to-Wasm deoptimization) patched in Chrome 147.0.7727.101.
โ Full primitives (addrof/fakeobj, out-of-cage, in-cage r/w)
โ No-ASLR RCE that patches JIT code to pop xcalc
โ Based on Nebula Security writeup
โ Heavily improved with frontier LLMs + human direction (4-day experiment)
This is renderer-only and still far from fully weaponized, but great for learning and research.
๐ฅ PoC + scripts:
https://github.com/0xsha/CVE-2026-6307
#Chrome #V8 #Exploit #CVE #SecurityResearch
A working renderer RCE Proof of Concept for CVE-2026-6307 โ a V8 type-confusion bug (JS-to-Wasm deoptimization) patched in Chrome 147.0.7727.101.
โ Full primitives (addrof/fakeobj, out-of-cage, in-cage r/w)
โ No-ASLR RCE that patches JIT code to pop xcalc
โ Based on Nebula Security writeup
โ Heavily improved with frontier LLMs + human direction (4-day experiment)
This is renderer-only and still far from fully weaponized, but great for learning and research.
๐ฅ PoC + scripts:
https://github.com/0xsha/CVE-2026-6307
#Chrome #V8 #Exploit #CVE #SecurityResearch
โค6
๐ฅ Just dropped โ 2026 Bug Bounty Guide
๐ 86 pages. 25 chapters. Built on real data.
What's inside:
โ The AI shift โ what it means for your bounties
โ Full recon workflow (subfinder โ puredns โ httpx โ nuclei)
โ Every major vuln class with payloads โ XSS, SSRF, IDOR, SSTI, SQLi, LFI, XXE
โ LLM & AI attack surface โ prompt injection, MCP, indirect injection
โ WAF bypass techniques for CloudFlare, Akamai, AWS
โ 9 real HackerOne reports โ PayPal $18,900 ยท Dropbox $17,576 ยท GitLab $12K ยท HackerOne $20K
โ Full payload cheatsheet you'll actually use mid-hunt
โ A-to-Z methodology checklist
โ Cloud security โ AWS SSRF, S3, IAM escalation
โ Mobile app testing (Android + iOS)
โ Career roadmap from first VDP to private programs
๐ https://topmate.io/saumadip/2187710
โ Saumadip | Brut Security
@brutsecurity
๐ 86 pages. 25 chapters. Built on real data.
What's inside:
โ The AI shift โ what it means for your bounties
โ Full recon workflow (subfinder โ puredns โ httpx โ nuclei)
โ Every major vuln class with payloads โ XSS, SSRF, IDOR, SSTI, SQLi, LFI, XXE
โ LLM & AI attack surface โ prompt injection, MCP, indirect injection
โ WAF bypass techniques for CloudFlare, Akamai, AWS
โ 9 real HackerOne reports โ PayPal $18,900 ยท Dropbox $17,576 ยท GitLab $12K ยท HackerOne $20K
โ Full payload cheatsheet you'll actually use mid-hunt
โ A-to-Z methodology checklist
โ Cloud security โ AWS SSRF, S3, IAM escalation
โ Mobile app testing (Android + iOS)
โ Career roadmap from first VDP to private programs
๐ https://topmate.io/saumadip/2187710
โ Saumadip | Brut Security
@brutsecurity
topmate.io
Bug Bounty Guide 2026 with Saumadip Mandal
Master modern bug bounty hunting with 86 pages, 25 chapter
โค1
Brut Security 2.0 pinned ยซ๐ฅ Just dropped โ 2026 Bug Bounty Guide ๐ 86 pages. 25 chapters. Built on real data. What's inside: โ The AI shift โ what it means for your bounties โ Full recon workflow (subfinder โ puredns โ httpx โ nuclei) โ Every major vuln class with payloads โ XSSโฆยป
Forwarded from Brut Security
I am sharing 10 additional coupons on LinkedIn upon reaching 12,000 followers (60 remaining). ๐ซ๐
https://www.linkedin.com/posts/mandal-saumadip_cybersecurity-bugbounty-ethicalhacking-share-7479612184960909313-sG9F/
Please follow and like; the coupon will be available in the comments after reaching 12k followers. โฑ๏ธ๐ฌ
Thank you to everyone who participated today! ๐
https://www.linkedin.com/posts/mandal-saumadip_cybersecurity-bugbounty-ethicalhacking-share-7479612184960909313-sG9F/
Please follow and like; the coupon will be available in the comments after reaching 12k followers. โฑ๏ธ๐ฌ
Thank you to everyone who participated today! ๐
LinkedIn
2026 Bug Bounty Guide - Brut Security | Saumadip Mandal posted on the topic | LinkedIn
๐ฅ Just dropped โ 2026 Bug Bounty Guide
๐ 86 pages. 25 chapters. Built on real data.
๐ขWhat's inside:
โ The AI shift โ what it means for your bounties
โ Full recon workflow (subfinder โ puredns โ httpx โ nuclei)
โ Every major vuln class with payloads โ XSSโฆ
๐ 86 pages. 25 chapters. Built on real data.
๐ขWhat's inside:
โ The AI shift โ what it means for your bounties
โ Full recon workflow (subfinder โ puredns โ httpx โ nuclei)
โ Every major vuln class with payloads โ XSSโฆ
Forwarded from Brut Security
This media is not supported in your browser
VIEW IN TELEGRAM
The feeling of relief ๐ฎโ๐จ
Cybersecurity Tools Collection (Pentesting โข Recon โข Web Security โข Network Analysis) ๐
Download Link : https://drive.google.com/drive/u/0/mobile/folders/1lGnd9YAzE5-Nes8NAsDDMpd-Aq3GES3p
Download Link : https://drive.google.com/drive/u/0/mobile/folders/1lGnd9YAzE5-Nes8NAsDDMpd-Aq3GES3p
โค1
Media is too big
VIEW IN TELEGRAM
โผ๏ธ CVE-2025-26529: Moodle XSS to RCE Exploit
GitHub: https://github.com/Astroo18/PoC-CVE-2025-26529
GitHub: https://github.com/Astroo18/PoC-CVE-2025-26529
โค2
Happy Rath Yatra! ๐
May Lord Jagannath bless you with unwavering faith, the strength to overcome every challenge, and the wisdom to choose the right path.
Just as the sacred chariot moves forward with purpose, may your life and journey always move toward growth, success, and peace.
Wishing you and your family a joyful, prosperous, and blessed Rath Yatra.
Jai Jagannath! โค๏ธ๐โ๏ธ
May Lord Jagannath bless you with unwavering faith, the strength to overcome every challenge, and the wisdom to choose the right path.
Just as the sacred chariot moves forward with purpose, may your life and journey always move toward growth, success, and peace.
Wishing you and your family a joyful, prosperous, and blessed Rath Yatra.
Jai Jagannath! โค๏ธ๐โ๏ธ
๐5โค4
Forwarded from Brut Security
โ๏ธSpideyX a multipurpose Web Penetration Testing tool with asynchronous concurrent performance with multiple mode and configurations.
https://github.com/RevoltSecurities/Spideyx
https://github.com/RevoltSecurities/Spideyx
โผ๏ธ CVE-2026-3891: A critical Unauthenticated Arbitrary File Upload vulnerability found in the Pix for WooCommerce WordPress plugin in versions up to and including 1.5.0.
PoC: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
PoC: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit