1/16 I believe there are people facing the same concerns as our team, so I want to share this publicly. Our team recently went through a major period of stagnation. The core problem was that fewer people wanted to participate in technical research.
Our long-standing RewriteLab research pages have been completely redesigned!
A huge thanks to @OpenAI for helping with the design! ❤️
You can now check out the new look at:
rewritelab.org/research
Stay tuned for the new research we'll be publishing in the future as well : )
🚨 Bounty Update
Someone solved the challenge in just 58 minutes using an unintended solution. (It was a completely unexpected approach—seriously impressive!)
However, they kindly said the bounty should go to the first person who solves it via the intended path, and voluntarily declined the reward. (Huge thanks for the incredible sportsmanship!)
The bounty is still open. 🎉
That said, I'm adding one new rule:
✅ The challenge must be solved via the intended solution path. (The current unintended path will be patched soon.)
If you solve the challenge, please open a ticket and explain your solution. If it matches the intended path, you'll receive the bounty.
🚨 OPEN BOUNTY — $300
Can your AI agent solve an unsolved CTF challenge?
We launched the damn-vulnerable-web on February 1st, and one challenge has remained at 0 solves for over 5 months despite the rise of LLM slopping.
This bounty is only available until the end of July.
🚨 OPEN BOUNTY — $300
Can your AI agent solve an unsolved CTF challenge?
We launched the damn-vulnerable-web on February 1st, and one challenge has remained at 0 solves for over 5 months despite the rise of LLM slopping.
This bounty is only available until the end of July.
Challenge: chronostasis
First Blood: 200 USDT
300 USDT if you solve it using a fully autonomous LLM agent ("pure slopping") and can demonstrate the complete solving process.
Still sitting at 0 solves.
Huge respect to @icesfont2 for creating such an insane challenge 👏
Bring your best agent. Let it cook!
We published a new research article on the Chromium 146 Renderer Process!
In this article, we start from the CVE-2026-3910 Maglev write barrier elision bug and walk through the full exploit chain: building a V8 heap R/W primitive via a GC-induced UAF, achieving an out-of-sandbox read using WebAssembly internals, abusing JSPI UAF and StackMemory / JumpBuffer, and ultimately reaching renderer process RCE.
Our goal was to provide a structured explanation of how modern V8 exploitation works in practice, from compiler-level bug analysis to sandbox-boundary primitives and final code execution. Huge thanks to our team member @m411k_ for conducting this research!
Check out the PoC!
Full article:
research.rewritelab.org/2026/06/11/%5B…
@PallavTrip9276 Thank you for your interest in our research
I do not believe permission segmentation and HITL can prevent prompt injection attacks themselves. However, they are necessary risk management strategies for limiting the impact when a prompt injection attack occurs
We published a new research article on prompt injection in modern agentic systems
This write-up covers:
- direct and indirect prompt injection
- multi-turn attack methodology
- tool-calling and MCP-related abuse cases
- case studies including WhatsApp MCP, GitHub MCP, and OpenClaw
mitigation strategies such as permission segmentation, - sandboxing, PTC, and HITL
Our goal was to provide a structured overview of how these attacks work and how they can be addressed in practice
Full write-up:
research.rewritelab.org/2026/04/03/%5B…
[ RewriteLab Web Security Research Team, 2026 First Half Researcher Recruitment ]
Rewrite is a specialized web security research team composed of web hackers from around the world.
Researchers from various regions including Korea, Europe, Asia, and Africa collaborate to conduct
We have successfully published a new research article!
This research takes an in-depth look at several interesting security incidents that occurred in 2025 and analyzes them in detail
While some of these incidents were already widely known, this research focuses more closely on cases that people may have only glanced over without examining thoroughly
Special thanks to One, TCP/IP, and @filime_sec for conducting this research!
We hope it receives a lot of interest! : )
research.rewritelab.org/2026/03/09/%5B…
[ RewriteLab Web Security Research Team, 2026 First Half Researcher Recruitment ]
Rewrite is a specialized web security research team composed of web hackers from around the world.
Researchers from various regions including Korea, Europe, Asia, and Africa collaborate to conduct in-depth research on the latest web exploitation techniques and technologies, while also working on a range of web security related projects
We are now publicly recruiting new researchers who would like to join RewriteLab and conduct research together with us
For detailed information about the recruitment requirements and the application process, please refer to the recruitment page below!
recruit.rewritelab.org
Hello! We’ve just launched a new wargame site called damn vulnerable web!
It consists only of web challenges, primarily designed for intermediate to advanced players rather than beginners.
We hope this wargame helps more people gain deeper and broader knowledge in web hacking :)
For now, we’re planning to accept only 300 users initially for open beta testing and capacity checks.
Starting from this tweet, we’ll gradually increase the number of allowed sign-ups each week. Your interest and support will be a huge help to our future activities
We’ll do our best to deliver even better work going forward. Thank you!
Wargame site: wargame.rewritelab.org
Join our Discord: discord.gg/wYAm2n4M4J
We’ve published a new article! This is a full writeup of the web challenges from the SECCON 14 Qual round. It has been written in detail so that readers can understand the core concepts and techniques even if they did not attempt the challenges themselves.
We would like to express our sincere gratitude to the researchers @Predic02 , @masamunee2003 , @ElleuchX1 , and @ irogir for their hard work on this writeup.
To everyone reading this, we wish you a very happy New Year 2026! We’re planning to release something new that we’ve been preparing between January and February, so please stay tuned and show lots of interest : )
454 Followers 4K FollowingLeading Product for CoreML Group @yelp Prev: ML Researcher @McMasterU, ML EM @etsy | Investing and Building at the Frontier @frontier_fund
167 Followers 1K FollowingSoy una persona entusiasta, autodidacta y empírico,apasionado por la [IN]Seguridad Informática, lo que pienso, lo que hago,significa luchar por un mundo mejor.
3K Followers 410 Followinghave been playing CTFs as binja leader (DEFCON Finals'14 '16 '18 '20 '22-'26; Google Finals'17) and competitive programming also(ICPC WF'19 '20)
608 Followers 314 FollowingI profit from people's mistakes, ctfs, browsers, 6cves, poetry, public pgp in my blog, free palestine until its backwards, opinions are my own.
39K Followers 261 FollowingWe help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
342K Followers 3K FollowingHackerOne makes security continuous.
We unite AI and human insight through a unified platform to expose risk and eliminate it.
2K Followers 2K FollowingMuslim web security artist 👨🎨, Pwn N00b 🤔 ACU🇨🇦 Graduated, Developing and breaking codes since 2020&Captin of @0xL4ugh and flagger @idekCTF. 💻