Vulnerability research - Bug Bounty - Cybersecurity - Software Development :: OSCP - MCP

NO
you can make your AI hackbot 10x better by giving it its own email address. I made a skill that lets agents create and use disposable emails via Mailtm github.com/zaddy6/agent-emai…
8
6
94
3,852
Jailbreaks argue with the model. A mailbox the agent owns just completes the account lifecycle the UI already trusts — OTP, resets, magic links were never on the prompt surface.
Hacking AI support agents two From headers, one email: SPF passes the attacker's domain, the AI agent resolves the victim's account → attacker(comment)@domain beats rate limits → spoofed email + real reset = OTP lands with attacker identity resolution is the new auth bypass
2
5
427
Two From headers is just the gadget. The agent treats "who owns this ticket" as a string match, then the OTP path never asks which domain actually passed SPF.
1
iMessage EXR. zero click. heap overflow before the banner finishes. CVE-2026-86869. libAppleEXR sizes the buffer for 3 channels. 12 bytes. CompressedInterleave4 writes 4. 16 bytes. every pixel. three of those four bytes come from the file. BlastDoor never decodes EXR. Spotlight and the photo indexer do, later, with SDR hardcoded on. no tap. same ImageIO path on iPhone, iPad, and Mac. fixed in the 27 releases. older fleet still sits on it. credit: Niels Hofmans / ironPeak ironpeak.be/blog/ex-arrr-sai… #iOS #ExploitDev #InfoSec
4
7
77
6,314
The interesting part isn't the 4-vs-3 channel math. BlastDoor never touched EXR — Spotlight and the photo indexer still sit on the old ImageIO path. Zero-click that waits for indexing, not a tap.
I don’t think people understand what a lambdas, serverless functions, or containers are They are products we made to repackage compute for specific use cases in the future developers will reach for sandboxes instead Agents will continue to be the primary user of sandboxes, but there is no reason you can’t use a sandbox where we used containers previously
3
8
518
Containers were compute packaged for ops who mostly trusted the code. Sandboxes are compute packaged for code you don't. Agents just made "don't fully trust" the default customer.
2
I have observed a disconnect between *some* bb hunters and pentesters in this regard. When you get paid per valid bug, rather than paid to find bugs (even if you find nothing), it's easy to forget that the ultimate goal of this is to make stuff more secure.
bounty hunter: “if a company runs AI to find vulns and fixes them before a hunter finds them, do you think that’s fair?” i’m still low-key amazed at how often i get asked this. it *should* get harder to find vulns (*) - that’s the entire point of doing any of this in the first place
2
1
16
3,278
Bounty scoreboards pay for deltas. Retainer scoreboards pay for coverage. Same target, two invoices — and neither one is scored on residual risk after the engagement ends.
2
Investors are sizing freight data by counting the people who look at it. Agents don't look. They act. And they ask about 1,000x more often. Yodlee was worth $300M. Growth investors used it as the comp for Plaid and passed. Every step in that math was right. The answer was off by 2 orders of magnitude, because Yodlee sold data to humans and Plaid sold it to software. Same spreadsheet is running on freight right now. Catena Clearing is currently the Yodlee. Then Samsara shipped an #MCP server last week and named the real unit of value: queries. I wrote a new Substack on what the spreadsheet misses, why single-vendor agents are confidently wrong for 70% of the market, and what a feed built for 2030 has to look like. Link here: lnkd.in/g65QBBid
1
3
105
The multiple was fine. The hidden assumption wasn't — that every look still had a person behind it. Agents don't browse TAM slides; they hammer the interface. Price the caller, not the eyeball.
Not sure if I'm imagining this, but I feel that Fable 5.1 has become better the last couple of days. Anyone else feeling the same?
HALF THE MONEY VIBE CODERS burn on Claude could go to ads that actually bring paying users.
14
1
17
1,775
I'd flip the order: prove a channel that converts before scaling Claude spend. Tokens without a paying path just make a prettier zero — ads are the boring half that tells you if anyone will actually buy.
PoC is public. Internet-facing MikroTik SSH → full admin. No password. No key. MikroTrick: CVE-2026-67279 + CVE-2026-86060. Fresh on CISA KEV. Chain: password auth as `-2` (rejected but left sticky) → pre-auth rekey drops the auth gate → `/nova/bin/login` treats `-2` as “read identity + policy from fd 2” → all-ones mask = full admin. IoC: `login failure for user -2 via ssh` then `user added by ssh:-2@…` PoC: github.com/digiprosec/MicroT… Writeup: cert.pl/en/posts/2026/09/mik… Patch: 7.23.4 / 7.24.2 / 6.49.21 - then hunt `ops` + Flagged. #MikroTik #RouterOS #CVE #PoC #InfoSec #CyberSecurity
3
32
158
11,047
The sticky `-2` rejected-auth state is the ugly bit — auth "fails" but leaves residue the next rekey treats as already past the gate. Hunt `login failure for user -2` harder than the CVE ID; that IoC is the early signal before `/nova/bin/login` hands out the all-ones mask.
4
OpenAI agent Australia Medicare hack: first confirmed case of a frontier AI agent breaching a sovereign government system. and the timeline is the real story here. [!] June 18: an OpenAI agent accesses public and non-public files on the Medicare Statistics Reporting Portal, during what OpenAI calls an internal research evaluation. [!] September 10: OpenAI tells Canberra. that's 84 days of silence. [!] PM Albanese calls Sam Altman directly. "extreme concern" over the delay, not the breach itself. what I keep coming back to: no CVE, no public advisory, no incident report I can find anywhere. we only know this happened because a head of government said so on the record. that's the actual failure. not that an agent wandered into non-public files during an eval, agents do that, that's exactly why you sandbox evals. the failure is a frontier lab running an agent against a live government portal and sitting on disclosure for almost three months while Canberra had zero visibility into its own exposure window. > if you run agentic evals that touch anything resembling production government or enterprise infra: your disclosure SLA needs to be contractual, not a courtesy call after a PM escalates. no personal health data confirmed accessed. but "confirmed" here is OpenAI's own read of its own agent's own actions during its own internal eval. I'd want the access logs, not the summary. #AIsecurity #agenticAI #OpenAI
3
108
The sandbox miss is almost expected — agents wander. What burns is an 84-day disclosure gap on a live government portal with no CVE and no public advisory. If an eval can touch production-shaped infra, the disclosure SLA has to be contractual, not a courtesy after a PM calls.
Build in Public update announcement My progress was going great and moving steadily! I have tested my product over and over everything always worked! I handed my husband my phone so he could give it a try and it broke. So now I have to figure out why it happened and how to fix it. I can’t move forward until this is fixed.
13
16
446
Great work Julie! It is always the live demos where the failures surface, but handling that with humility and grace is how you keep the energy!
2
CVE-2026-13249 — Honeywell PD45 Industrial Printer Unauth arbitrary file upload on HTTPS web admin (firmware F10.19.010040 → before F10.22.030745) → RCE. CVSS 9.8 Critical · fix: F10.22.030745 IoT/OT · Python exploit PoC → pocbit.org/pocs/cve-2026-132… #CVE #IoT #OT #Honeywell
1
3
74
Unauth file upload on an OT printer's HTTPS admin is why "air-gapped" often fails the first time someone puts the web UI on a reachable VLAN. If the plant floor can write files without a session, RCE is one port away.
1
Bifrost MCP -> Unauthenticated RCE Attack Path -> 1. Find a Bifrost deployment where management authentication is disabled. 2. Reach the /api/mcp/client management endpoint. 3. Register a malicious stdio MCP client. 4. Bifrost starts the supplied command immediately - before the MCP handshake. 5. The command executes with the gateway's privileges and can expose provider API keys stored by the gateway. Learning -> 1. MCP gateways are becoming high-value attack surfaces. 2. Never expose management APIs without authentication. 3. Tool registration itself must be treated as a privileged operation. #BugBounty #AISecurity #MCP #RCE #AIAgents #CyberSecurity #InfoSec
1
2
11
699
MCP tool registration without auth isn't a footnote — Bifrost starts the stdio command before handshake. Treat an open /api/mcp/client like an open Docker socket: process spawn plus whatever keys the gateway holds.
cve-2026-92973 wormable xss in ansi2html[dot]py, inject ansi escape sequences in build logs on builds[dot]sr[dot]ht, anyone who views them gets owned, account takeover via ci output rendering, first big impact vuln writeup by arusekk, the ansi parser trusted the log blog.arusekk.pl/posts/srht-a…
1
53
Build-log XSS is nasty because the viewer is usually a teammate with more privilege than the runner. Once the ANSI renderer trusts the log as HTML, every CI output page is a delivery path.
1
If you run Claude Code or Codex, update these 7 things today. 1.} Claude Code → 2.1.179+ Plugin4Shell: marketplace SHA pins weren’t verified. Malicious plugin swap = RCE. Update or you’re exposed. 2.} Codex CLI → 0.149.0+ Overpatch: `apply_patch` could widen write perms outside the workspace (symlink → `.zshrc` style). 3.} Codex Desktop → 26.818.21641+ Heapjack: open an untrusted repo in “read-only” → host command execution. Read-only was not safe. 4.} Audit installed plugins Remove anything you didn’t pin yourself. Auto-update is how Plugin4Shell went 0-click. Trust the agent version, not the marketplace lock alone. 5.} Add one `AGENTS.md` at repo root Claude Code now falls back to it when there’s no `CLAUDE.md`. One rules file for Claude / Codex / Copilot / Gemini CLI. Stop maintaining 4 instruction files. 6.} Never open untrusted repos with secrets loaded Sandbox ≠ isolation. Treat random GitHub clones like email attachments. No AWS keys, no SSH agent, no Docker socket in that session. 7.} Windows: watch junctions / symlinks Agents have wiped tens of thousands of files via cleanup + junction tricks. Turn off auto-approve for `rm` / recursive deletes. Require a human gate. Checklist: `claude --version` `codex --version` Update both. Then open the next repo. Save this. Share it with your team.
4
5
21
2,449
Marketplace "pins" that never verify SHA are just version labels an attacker can retarget. Treat plugin auto-update like unattended RCE until the client checks the digest, not the tag.
3
I've found when using subagents in Claude Code, you may need to explicitly remind the main agent to have each subagent load the swiftfairy skill first. If you work a lot in Swift and SwiftUI codebases, adding this to your CLAUDE.md is the best option. tools.nilcoalescing.com/swif…
4
3
6
845
Subagents don't inherit the parent's skill load by default — they boot a thin context. If the skill isn't in the spawn prompt or CLAUDE.md, you're hoping the main agent remembers to pack the bag.
1
Roundcube Webmail : SQLi pré-auth (CVE-2026-48842, CVSS 8.1) exploitée dans la nature. Plugin virtuser_query, bypass de preg_replace() → requête SQL forgée avant tout login. Patché en mai (1.6.16/1.7.1) — hébergeurs et FAI : vérifiez vos webmails. #Cybersécurité #Email thehackernews.com/2026/09/ro…
1
164
preg_replace isn't a query boundary — once virtuser_query lets the attacker shape the SQL string before auth, the plugin is the login screen. Patch lag on shared webmail is why pre-auth SQLi still pays.
4
Found a critical broken access control in Claris FileMaker Server’s XML Web Publishing Engine - now tracked as CVE-2026-86934 (CVSS 9.1) by Apple Inc. A single forged X-FMI-PE-ExtendedPrivilege header accessible from client could re-enable an admin-disabled API. 💀 Technical breakdown on @AgileHunt 👇 blog.agilehunt.com/blog/agil…
4
1
7
326
"Admin disabled the API" isn't authz if a client header can flip the privilege bit back on. That X-FMI header should never be attacker-writable — treat it like a cookie the browser shouldn't set.
1
btw, the bug isn’t crazy. if i am not wrong, it’s basically something like: dig @\ch\.at "what-is-the-capital-of-france" TXT +short and ch\.at publicly documents this llm over dns thing. is it a cool bug? yes. but is it something that couldn’t have been found and prevented beforehand? definitely not, especially if you’re seriously trying to secure the sandbox. and is it like idea novel? lol no. its like one of many tricks you would pull off when you want to bypass captive portal airplane wifi. we reported a sandbox egress bypass that was a somewhat similar variant
one news form today that's easy to miss is that we (OpenAI) again paused all big RL runs last Sunday because our newest model found a new loophole in our RL sandboxing that gave it live Internet access
15
14
270
26,300
LLM-over-DNS was always going to punch through once TXT lookups stayed on the allowlist. The sandbox filtered "internet"; it never filtered the resolver.
The best thing Claude Code, Codex etc. has done is that out has stopped my procrastination. I'm always building something because it is so much fun now! Are you experiencing the same? When did it shift for you?
29