CTBB Full-Time Hunters' Guild Member | Recovering AppSec Engineer | /((de)?bu(g+)?(ing)?)?/i Bits, bytes, and bad ideas turb0.one

It's kind of weird how numb we are now to bugs like this that would have elicited so much more excitement even a year ago. Great impact. Research Review. piped.video/XdupePzpfNc
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
10
838
I missed this episode of Detective Woltjer vs mysterious browser behaviors because of DefCon, but I'm glad I was able to catch a rerun later. 🔍 Research review. piped.video/TpXccQbOb48
We know you're all hyped with DEF CON stuff but here's one more thing to get excited about: @J0R1AN just released a new research over at the Critical Research Lab! And this time it was inspired by a discussion we had on our discord, go check it out! lab.ctbb.show/research/solvi…
3
17
2,069
More classic Azure bangers. Research Review. piped.video/cI-xxAlh2fg
A vulnerability in Azure? How about 3 of those? Uncovering 2 SSRFs + a file upload path traversal I discovered in the Azure API Management service. Attackers could send requests from the service’s proxies, access internal Azure assets, deny service and upload malicious files🧵
1
5
1,228
It's really cool to see a concrete example of a modern indirect prompt injection guardrail bypass that is technical in nature and doesn't just come from saying magic words. Also this writeup is really good and the exploit chain rules. Research Review. piped.video/vdxCdFe1bcU
Breaking Claude Code Opus 5 Auto Mode 🔥 1/ Here is a somewhat hilarious attack chain that hijacks Claude Code Opus 5 for a full system compromise via a website Hint: Security invariants are not optional 🧵
2
5
24
3,276
Some people's favorite shape is a circle. Others, a square. Mine is the shape of cross tenant cloud bugs. Research Review. piped.video/XTuk3ZTs_So
🚨 CosmosEscape: We found a single key that unlocked every database in Azure CosmosDB One key >> Platform-wide impact. Microsoft fully remediated the issue. ✅ Read the full research and see how Wiz uncovered CosmosEscape: wiz.io/blog/cosmosescape-tak…
11
2,804
Can't wait to see all the crazy new ways to achieve security impact with internet breaking techniques that get discovered by forking the approaches shared here. Research Review. piped.video/WQc46XXuKdI
The whitepaper is live! Read "Can AI Do Novel Security Research? Meet the HTTP Terminator" here -> portswigger.net/research/htt…
11
1,325
Some people are just looking for an excuse to talk about JavaScript sandboxes at all times. I'm some people. Research Review. piped.video/-de7dxdkacU
JavaScript Sandboxes: A Small and Casual Antipattern Review jamvie.net/posts/2026/07/jav…
2
8
2,238
I'm not sure which is crazier, the icy chain here or the fact that the prompt and setup was shared so freely that I can just toss at other hardened targets and get RCE. Research review. piped.video/BNm_jF4jDwc
Seems that wp2shell PoCs are now floating around the internet, so we've published our blog post including our research methodology for finding the bug as well as a deep dive into the chain itself - slcyber.io/research-center/e…
1
30
3,591
Don't miss the workshop "Hacking IDE Extensions - VSCode Workshop" by Nick Copi (@7urb01) on Fri, Aug 7 at 10:30am inside the Village. Read more at bugbountydefcon.com/agenda #BugBounty #DEFCON34
1
2
660
These kinds of bugs are cool because such small discrepancies and have such huge impact. Research review. piped.video/uzBPzMQiAE8
MAD Bugs: My Cousin Vinyl (CVE-2026-50052) So the story went like this: Squid was bleeding from a 29-year-old heap overread in her default config. Naturally, she did the only sensible thing: she called her cousin, Vinyl. It turns out Vinyl also had a family problem of his own. blog.calif.io/p/mad-bugs-my-…
6
695
Such a fun bug class to end up universal via an interesting delivery mechanism. Really liked the clever tricks used to force a working PoC without reusing precanned solutions. Research Review. piped.video/9MeXS_b_Ahw
Pleased to publish a browser-related research paper (w/@inzo____) titled: One trigram at a time: XSLeak via Universal CSS Injection and DoS in Opera (GX) The title speaks for itself. Enjoy the read! zhero-web-sec.github.io/rese…
2
28
2,993
We're excited to announce that Nick Copi (@7urb01) will be speaking at the Bug Bounty Village during DEF CON 34! Stay tuned for more details on their talk, you won't want to miss it. #BugBounty #DEFCON #BBV #BugBountyVillage
2
8
910
turb0 retweeted
That’s a wrap on our Tokyo Live Hacking Event with @Salesforce 🇯🇵 In the agentic enterprise era, collaboration matters more than ever. 10+ years of partnership. One shared mission: stronger security for the AI era. Until next time. #TogetherWeHitHarder
2
4
45
11,264
My misplaced PHPrejudice had me guess wrong on the root cause of this one. Research Review. piped.video/nrqcP5ERX1k
On June 10th, we announced a critical auth bypass in phpBB, now CVE-2026-48611. Here's the technical followup with exploit scenarios and how to detect it. All it takes is one unauthenticated request to log in as any user, admin included, on a default phpBB install, no password required. Aikido Attack caught this on a routine run. We reported it June 2nd, and phpBB shipped a fix four days later in version 3.3.17. If you haven't upgraded yet, do it now.
16
2,672
Insane hacker/feature type matchup here. 4x super effective. Great bugs, great tricks. Research Review. piped.video/SEgUNWHXxrM
We've published a new blog post by RyotaK @ryotkak He discovered 8 methods to bypass safety mechanisms in Claude Code, leading to arbitrary command execution. We recommend updating to v1.0.93 or later to fix this vulnerability (CVE-2025-66032). flatt.tech/research/posts/pw…
1
2
24
5,187
Didn't know about the buried bare repo trick here and feel like I've missed out on bugs because of it. Really clever bugs here and a lot of good tricks. Research Review. piped.video/xC9jofFUWVQ
The written version of my BSides Riga and @bsidesvilnius talks is up: exploiting git integrations in cloud services, with four bugs I found in GCP (Looker, Dataform), including the one that won me MVH. nopnop.pro/2026/06/17/exploi…
1
8
774
This writeup did a really good job establishing useful context and I now have a more clear picture of what I need to do to get a previously deadend bug reportable. So much cool work here. The title kinda undersells all the extra stuff. Research Review. piped.video/PIpLLcPtGJw
👨🏻‍💻 Did you know that it’s possible to perform RCE in Internet Explorer via clickjacking? Igor Sak-Sakovsky's (@Psych0tr1a) new article will explain how! swarm.ptsecurity.com/the-cli…
20
3,401
Very clever way of weaponizing a Bad Behavior, and an even more clever way of turning it into a zhero click SXSS. Research Review. piped.video/OtjTN3qPrsw
New short article on a real-world exploitation case rather than pure research, demonstrating how a specific mistake in Next.js can lead to a systematic zero-click SXSS on its latest versions (w/@inzo____): Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js zhero-web-sec.github.io/rese…
3
21
3,159
Found out I had this RR on my disk from March when I was getting way too excited about the RCE technique used here. I'm M̄ista bug isolation right now so we're balling out of the backlog. Research Review. piped.video/-L60zSztdCU
We've published a new blog post by RyotaK @ryotkak ! He exploited a directory deletion race condition in Google Cloud's Looker, leading to full RCE and K8s privilege escalation. Read the technical details here: flatt.tech/research/posts/re…
1
10
3,038