‼️ BREAKING: A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records.
The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav.
He says he only pulled metadata and two single rows of Bing data, never touched customer data, and reported the flaw to Microsoft the same night.
Microsoft locked the endpoint four days later, paid him $5,000, and had editorial control over his write-up, cutting sections and figures and reshaping how the impact was described before it went public.
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately.
We don't know what's exactly going on yet. Stay tuned for more info.
one of my engineers reached out to me about how they struggled to find satisfaction in their work in the age of AI. I asked them if I could publish our brief exchange, and they agreed. I know people are feeling similarly, so maybe they can relate. shubs.io/do-we-still-enjoy-s…
A malicious Twitch chat message can trigger code execution in OBS Studio.
The attack targets OBS Studio and custom Twitch chat overlays (Browser Sources) that insert unsanitized chat directly into the page and can execute JS within the overlay.
cyberinsider.com/malicious-t…
Community note
Chat alone can’t hack OBS.
The proof of concept needed a custom overlay that rendered messages as unsafe HTML, plus a flaw in OBS 32.2.2’s built-in browser. It doesn’t show Streamlabs or StreamElements are vulnerable. OBS has merged a browser update for 33.0.
blog.scrt.ch/2026/09/22/how…github.com/obsproject/obs…
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
We just published two blog posts about PageBreak, Google's AI web security scanner (that I've helped develop for the better part of the year). We share our approach and a couple of findings, enjoy!
- blog.google/security/agentic…
- bughunters.google.com/blog/p…
📢📢📢 Attention bug hunters!
Want to know more about how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage?
If yes, check out his blog post 👇
bughunters.google.com/blog/b…
i hate security disclosure so much. the number of companies that take our work for granted is insane. how about you talk to us collaboratively from the start instead of being asinine about it?
like, give us some respect, bro. we worked on this shit for weeks/months and showed you something that could have become a massive disaster if a bad guy finds it, and you don’t even seem to give a fuck and see us like some villains?
Another 0-Click ATO in Meta's AI Systems!
I recently discovered a critical vulnerability in @Muse leading to a 0-Click Full Account Takeover (ATO) on @facebook, @instagram & @Meta.
This places me in the Top 5 on Meta's Bug Bounty Leaderboard.
Thanks to the @metabugbounty Team.
I bought a Fable dataset from one of the top Chinese LLM routers yesterday.
With just 6TB data, I can take over 7 Chinese/CIS gov entities & 19 top Chinese firms like Xiaomi, Huawei, NIO, Minimax using SSH keys, VPN configs, Aliyun keys, GitLab tokens sent to the router.
26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.
We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.
Check our paper: arxiv.org/abs/2604.08407
Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.
@SLCyberSec Labs Team found a Remote Code Execution in the GoJa Javascript Sandbox that is used by a lot of products including Zendesk and Nuclei 😉
read the whole writeup here: searchlight-web-new.webflow.…
and watch Nuclei getting pwned with a template file here 👇🏻
(A)I reverse engineered Burp's project format and made a tool to extract proxy history, Repeater tabs, and Site map from project files. I've always wanted to do this.
parsiya.net/blog/burp-projec…