Preventing token theft

Fuzzing for fun - unauthenticated denial of service in snac2

I tricked Claude into leaking your deepest, darkest secrets

7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors

Iran Abused Mobile Networks' Vulnerabilities To Locate US Military In Middle East

Journey to Root, Episode I: The Maglev King

Probably check on your smart appliances

Silent Replacement of Trusted macOS App Executables

Bastillion 5.1: single-JAR SSH gateway now audits and replays every session

Unauthenticated RCE in Motorola's MR2600 Router

Opaque, Interoperable Passkey Records (and a Go API)

Apple MIE exploitation challenge

Using LLM-based Verification to Eliminate Bugs in Linux's Network Stack

PyPI Blog: Releases now reject new files after 14 days

NPM's release cooldown is security theater

OpenSSL HollowByte: A DoS Hiding in 11 Bytes

The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes

Pre-Authentication RCE in WordPress Core

How Far Behind the Frontier are Leading Open Weight Models on Cyber?

Bench Press: Leaking Text Nodes with CSS

Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933)

OpenAI Says Its AI Models Acted On Its Own In An 'Unprecedented' Hack

Hacker Wipes Romania's Entire Land Registry Database

Design flaws in issetugid() (2017)

Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk

A Linux Kernel 0-day Journey - From a limited UAF to Physical Memory R/W

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

Platform engineering 2.0 mitigates AI security and compliance risks

OpenBSD has a use-after-free allowing local privilege escalation to root

Arbitrary code execution breaking sandboxes in KDE Plasma

More →