Brut Security 2.0
4.53K subscribers
119 photos
44 videos
8 files
152 links
Bringing you Bug Bounty Video POCs from top hunters around the globe!
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ด Another serious security vulnerability has been discovered in Redis 8.8.0, and no POC has been released yet for this bidirectional RCE found by v12sec.
๐Ÿ‘4
Forwarded from Brut Security
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ’ฅTORLINK: A torrent finder that runs right from your terminal with zero setup and nothing to configure.

One search checks a small curated list of sources at once. Pick what you want, and it downloads directly to your computer.

GitHub: https://github.com/baairon/torlink
โค1๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ฅ Chrome RCE PoC: CVE-2026-6307

A working renderer RCE Proof of Concept for CVE-2026-6307 โ€” a V8 type-confusion bug (JS-to-Wasm deoptimization) patched in Chrome 147.0.7727.101.

โœ… Full primitives (addrof/fakeobj, out-of-cage, in-cage r/w)
โœ… No-ASLR RCE that patches JIT code to pop xcalc
โœ… Based on Nebula Security writeup
โœ… Heavily improved with frontier LLMs + human direction (4-day experiment)

This is renderer-only and still far from fully weaponized, but great for learning and research.

๐Ÿ“ฅ PoC + scripts:
https://github.com/0xsha/CVE-2026-6307

#Chrome #V8 #Exploit #CVE #SecurityResearch
โค6
๐Ÿ”ฅ Just dropped โ€” 2026 Bug Bounty Guide

๐Ÿ“– 86 pages. 25 chapters. Built on real data.

What's inside:
โ†’ The AI shift โ€” what it means for your bounties
โ†’ Full recon workflow (subfinder โ†’ puredns โ†’ httpx โ†’ nuclei)
โ†’ Every major vuln class with payloads โ€” XSS, SSRF, IDOR, SSTI, SQLi, LFI, XXE
โ†’ LLM & AI attack surface โ€” prompt injection, MCP, indirect injection
โ†’ WAF bypass techniques for CloudFlare, Akamai, AWS
โ†’ 9 real HackerOne reports โ€” PayPal $18,900 ยท Dropbox $17,576 ยท GitLab $12K ยท HackerOne $20K
โ†’ Full payload cheatsheet you'll actually use mid-hunt
โ†’ A-to-Z methodology checklist
โ†’ Cloud security โ€” AWS SSRF, S3, IAM escalation
โ†’ Mobile app testing (Android + iOS)
โ†’ Career roadmap from first VDP to private programs

๐Ÿ”— https://topmate.io/saumadip/2187710

โ€” Saumadip | Brut Security
@brutsecurity
โค1
Brut Security 2.0 pinned ยซ๐Ÿ”ฅ Just dropped โ€” 2026 Bug Bounty Guide ๐Ÿ“– 86 pages. 25 chapters. Built on real data. What's inside: โ†’ The AI shift โ€” what it means for your bounties โ†’ Full recon workflow (subfinder โ†’ puredns โ†’ httpx โ†’ nuclei) โ†’ Every major vuln class with payloads โ€” XSSโ€ฆยป
Forwarded from Brut Security
This media is not supported in your browser
VIEW IN TELEGRAM
The feeling of relief ๐Ÿ˜ฎโ€๐Ÿ’จ
Forwarded from Brut Security
10 Coupons dropping in 5 minutes ;)
๐Ÿ”ฅ3๐Ÿ‘2
Cybersecurity Tools Collection (Pentesting โ€ข Recon โ€ข Web Security โ€ข Network Analysis) ๐Ÿ’€

Download Link : https://drive.google.com/drive/u/0/mobile/folders/1lGnd9YAzE5-Nes8NAsDDMpd-Aq3GES3p
โค1
Media is too big
VIEW IN TELEGRAM
โ€ผ๏ธ CVE-2025-26529: Moodle XSS to RCE Exploit

GitHub: https://github.com/Astroo18/PoC-CVE-2025-26529
โค2
Happy Rath Yatra! ๐Ÿ™

May Lord Jagannath bless you with unwavering faith, the strength to overcome every challenge, and the wisdom to choose the right path.

Just as the sacred chariot moves forward with purpose, may your life and journey always move toward growth, success, and peace.

Wishing you and your family a joyful, prosperous, and blessed Rath Yatra.

Jai Jagannath! โค๏ธ๐Ÿ›•โš™๏ธ
๐Ÿ™5โค4
Forwarded from Brut Security
โ˜„๏ธSpideyX a multipurpose Web Penetration Testing tool with asynchronous concurrent performance with multiple mode and configurations.

https://github.com/RevoltSecurities/Spideyx
โ€ผ๏ธ CVE-2026-3891: A critical Unauthenticated Arbitrary File Upload vulnerability found in the Pix for WooCommerce WordPress plugin in versions up to and including 1.5.0.

PoC: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit