WTF Are Abliterated Models? Uncensored LLMs Explained https://webdecoy.com/blog/wtf-are-abliterated-models-uncensored-llms-explained/
WebDecoy
WTF Are Abliterated Models? Uncensored LLMs Explained - WebDecoy
What abliterated means in AI models: how abliteration removes the refusal direction from LLMs, why it matters for security, and which models are abliterated.
Grok’s image edits spark sexualised deepfakes and regulator probes worldwide https://thebias.co.uk/articles/grok_ai_deepfake_outrage
Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense #CybersecurityAI #GameTheory #AIAttack #AIDefense #SecurityStrategy https://arxiv.org/pdf/2601.05887
CVE-2025-64155: Three Years of Remotely Rooting the Fortinet FortiSIEM https://horizon3.ai/attack-research/disclosures/cve-2025-64155-three-years-of-remotely-rooting-the-fortinet-fortisiem/
Horizon3.ai
CVE-2025-64155: FortiSIEM Analysis
Horizon3.ai details CVE-2025-64155, revealing chained FortiSIEM vulnerabilities enabling remote code execution and root access, analysis of the root cause, and indicators of compromise.
Bad Vibes: Comparing the Secure Coding Capabilities of Popular Coding Agents https://blog.tenzai.com/bad-vibes-comparing-the-secure-coding-capabilities-of-popular-coding-agents/
Tenzai
Blog | Tenzai - AI Security Research & Pentesting Insights
Writings from Tenzai researchers on autonomous offense, AI-driven pentesting, and hard security vulnerabilities. Real case studies and research from the field.
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC #DroneHacking #FirmwareDumping #NANDFlash #ECCBruteforce #IoTResearch https://neodyme.io/en/blog/drone_hacking_part_1/
neodyme.io
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC
Desoldering a drone's flash chip and reconstructing the firmware from broken data.
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data #MicrosoftCopilot #RepromptAttack #DataTheft #SingleClickHack #AIVulnerability https://www.varonis.com/blog/reprompt
Varonis
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
Varonis Threat Labs discovered a way to bypass Copilot’s safety controls, steal users’ darkest secrets, and evade detection.
CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center #CVE202620965 #AzureWAC #TenantRCE #CymulateResearch #TokenValidation https://cymulate.com/blog/cve-2026-20965-azure-windows-admin-center-tenant-wide-rce/
Cymulate
CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center
Cymulate Research Labs uncovered CVE-2026-20965, a token validation flaw in Azure Windows Admin Center enabling tenant-wide RCE and lateral movement.
The ServiceNow AI Vulnerability: What Went Wrong and How to Secure Your AI Agents #ServiceNowAIHack #AIAgentSecurity #LegacyAISecurity #SupplyChainRisk #AIIdentity https://opena2a.org/blogs/servicenow-ai-vulnerability
OpenA2A
The ServiceNow AI Vulnerability: What Went Wrong
85% of Fortune 500 exposed. Learn how AI agents need purpose-built security, not retrofitted legacy authentication.
WinBoat: Drive by Client RCE + Sandbox escape. #WinBoat #RemoteCodeExecution #SandboxEscape #DriveByAttack #UnauthenticatedAPI https://hack.do/posts/winboat-guest-service-host-rce/
hack.do
WinBoat: Drive by Client RCE + Sandbox escape.
A remote webpage can abuse an unauthenticated guest HTTP API to compromise the Windows guest container, then feed a malicious app entry leading to Linux host code execution on click.
Multiple cross-site leaks disclosing Facebook users in third-party websites #XSLVulnerability #MetaSecurity #UserIdentification #PrivacyThreat #BugBountyProgram https://ysamm.com/uncategorized/2026/01/16/cross-site-leaks.html
Instagram account takeover via Meta Pixel script abuse #InstagramHack #MetaPixelAbuse #CrossWindowMessaging #OAuthCodeTheft #BugBounty https://ysamm.com/uncategorized/2026/01/16/leaking-fbevents-ato.html
StackWarp vulnerability #StackWarp #SEVSNP #StackManipulation #StackEngineBug #PrivilegeEscalation https://stackwarpattack.com/#home
Leaking Meta FXAuth Token leading to 2 click Account Takeover #FXAuthLeak #AccountTakeover #RedirectFlaw #MetaSecurity #BugBounty https://ysamm.com/uncategorized/2026/01/16/leaking-fxauth-token.html
How I Used an Agent to Hunt Vulns #Blazelight #TerminalUI #WebNavigation #GuestPrompt #DigitalPortfolio https://blazelight.dev/blog/agent-vuln-hunting.mdx
blazelight.dev
I do things on the computer.
Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK #FacebookAccountTakeover #InsecureRandomNumber #DOMXSS #MobileAppVulnerability #IframeExploitation https://ysamm.com/uncategorized/2026/01/17/math-random-facebook-sdk.html
After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes #DNSSinkholes #AbuseInfrastructure #PassiveDNS #TakedownAnalysis #Badbox20 https://disclosing.observer/2026/01/14/excavating-abuse-infrastructure-dns-sinkholes.html
Disclosing.Observer
After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes
A methodological analysis of how DNS sinkholes preserve abuse infrastructure at the moment of takedown, enabling post-hoc reconstruction using passive DNS data.
Cloudflare Zero-day: Accessing Any Host Globally #CloudflareZeroDay #CybersecurityResearch #FearsOffSecurity #GlobalHostAccess #DigitalProtection https://fearsoff.org/research/cloudflare-acme
fearsoff.org
Cloudflare Zero-day: Accessing Any Host Globally
Discover how a Cloudflare WAF bypass in /.well-known/acme-challenge/ exposed origins, its impact, and the fix. A must-read for security pros.
vibe coding has a 12x cost problem. maintainers are done. #VibeCoding #MaintainerBurnout #SyntheticVulnerabilities #CostAsymmetry #AICodeQuality https://webmatrices.com/post/vibe-coding-has-a-12x-cost-problem-maintainers-are-done
Webmatrices
vibe coding has a 12x cost problem. maintainers are done. | romanking
25-35% of new code in large organizations is now AI-assisted. github copilot writes ~20% of a developer's daily output. cursor and windsurf are rewriting entire architectures.everyone's shipping faster.but someone has to review that code. someone has to maintain…
Successful Errors: New Code Injection and SSTI Techniques #SSTIResearch #CodeInjection #ErrorBasedTechniques #BlindExploitation #SSTImapTool https://github.com/vladko312/Research_Successful_Errors
GitHub
GitHub - vladko312/Research_Successful_Errors: Clear and obvious name of the exploitation technique can create a false sense of…
Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads a...