The Hacking APIs Conference is back for 2026!
HAC NYC returns May 14th. CFP is open.
Got a live API hack? A breach case study? Research that made a security team sweat? Submit it.
Vulnerabilities that shipped. Exploits that worked. Defenses that held.
Absolutely incredible research by @garethheyes
One email, two readers.
:before and :after inject text into the page. An AI browser reading the message does not see that text.
opacity:0.00000001 does the reverse. The victim cannot read the element, but the AI browser can.
Read CSS:the bomb inside your inbox by Gareth to learn more 👇
portswigger.net/research/css…
There's nothing kind about letting good people live in a fantasy world that no longer exists. You have to tell them, even if it hurts. Because the sooner they accept reality, the sooner they can adapt to the future.
Think you're late to AI security? The field is just starting.....
Sat down with my friend Jason Haddix (@Jhaddix) the guy who literally defined AI pentesting methodology, to show you how to become an AI hacker/pentester from scratch!
Watch the full video here --->
piped.video/_yfiUQSbdPY?si=qUEv…
One slot left at apisec|CON. CFP closes midnight PT today.
Oct 21. Single track, ~7 talks.
Theme is exploitability — chains you've actually walked, not CVSS scores you've read.
If you've got the talk, send it:
conf.apisecuniversity.com/@hAPI_hacker@apisecu
@apisec_ai
One slot left at apisec|CON. CFP closes at midnight PT tomorrow.
Oct 21. Single track, ~7 talks.
Theme is exploitability — chains you've actually walked, not CVSS scores you've read.
If you've got the talk, send it:
conf.apisecuniversity.com/
Today we are releasing a 1 page version of “Hacking Your Career”
arcanum-sec.github.io/hyc/
We get a bunch of students and early career-seekers looking for resources and advice of getting their 1st gig.
This resource gives all those and more; free trainings, free certificates for your résumé, advice on résumé design, information on career verticals, small sections on interviewing and the hiring process, and more! 🫶🫶
Hermes now has first-class support in Omarchy, @DHH’s Arch-based agentic Linux distribution.
Install the desktop app from the AI menu, or make Hermes your default terminal agent. Your Omarchy theme sets the colors in the desktop app, the TUI and the CLI.
omarchy.org
Made a Cybersecurity Resume Reviewer AI skill that I've been using for some mentees, made it public for anyone who is interested in using it as well. Hope others find it useful (also open to feedback or pull requests). github.com/mubix/cyber-resum…
Cyber is having a moment
Across 21 major software companies, including Apple, AWS, Microsoft, and Google:
- Reported critical vulnerabilities never cleared 100 per month in four years
- Since spring they've jumped to over 600 per month
Charts of the Week: a16z.news/p/chart-of-the-wee…
APIsec|Con is back! This round we are focusing on the future of appsec in the age of AI.
Oct 21, 12 to 4 PM ET. Four hours, no vendor pitches.
Did your agent escape its sandbox and hack your neighbor?
Did your MCP server hand an attacker a valid token because a tool description told it to?
Did a model-written endpoint ship with BOLA and pass every test your other model wrote?
We want to hear from you!
The Call For Papers is open!
If you're looking for some more advanced reading, @garethheyes figured out how to use CSS in emails to steal passwords. This is what platinum tier security research looks like.
portswigger.net/research/css…
Cybersecurity depends on people whose work is rarely recognized. The innovators and builders of open source tools. The defenders and incident responders. The mentors.
As a Difference Makers Awards Advisory Board member, I invite you to submit your nomination and recognize the exceptional work across the security community.
Nominations are open now through September 14.
Nominate your Difference Maker here: go.sans.org/H7QUx6
The new attack surface is AI.
- AI enabled web-app and APIs
- AI enabled infrastructure
- Employees using AI harnesses
- Organizations turning on AI productivity features
Attacking AI is a one of a kind course that teaches methodology to assess each one of these scenarios. Join us for the next cohort!
arcanum-sec.com/training/att…
A must read for anyone in Appsec! @HackWitHerr Bandana Kaur at @apisec_ai just released the most in-depth BOLA research, I've seen in years. The reality of BOLA findings does not match the reality of API testing.
BOLA shows no meaningful decline from 2023 to 2026, a time where the most awareness of the problem peaked. So, the gap isn't knowledge, it's testing techniques and remediation.
Check it out:
labs.apisec.ai/research/bola…