Infosec Trending Feed
Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.
Updated on: 10:03 AM IST, 29 Aug 2026
(6 hour(s) ago)
HackerOne Hacktivity
- Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint - An IBM report describing unauthorized vertical privilege escalation was disclosed approximately 10 hours ago.
- Author → arbitrary file deletion anywhere on disk via WordPress media finalization - A critical WordPress path-traversal report enabling arbitrary file deletion was disclosed approximately 12 hours ago.
- Author → stored XSS in wp-admin via unescaped attachment metadata - A critical stored-XSS report affecting the WordPress admin media library was disclosed approximately 12 hours ago.
- HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser - A Node.js HTTP-parser issue enabling request desynchronization in forwarding proxies was disclosed approximately 14 hours ago.
- Reachable assertion in node:zlib sync API crashes the entire process - A Node.js zlib flaw allowing process crashes through a spoofed TypedArray byteLength was disclosed approximately 14 hours ago.
- dns.resolveAny() aborts Node.js on DNS responses with more than 256 A records - A Node.js DNS-resolution issue causing process termination was disclosed approximately 14 hours ago.
- node:sqlite SQLTagStore iterator replay re-executes victim-bound writes - A Node.js SQLite iterator-replay race condition allowing repeated execution of cached writes was disclosed approximately 14 hours ago.
- Re-entrant nghttp2 session calls cause heap-use-after-free in Node.js HTTP/2 - A high-severity Node.js HTTP/2 memory-safety issue was disclosed approximately 14 hours ago.
- HTTP/2 retained header blocks evade maxSessionMemory - A Node.js HTTP/2 memory-exhaustion issue involving retained header blocks was disclosed approximately 14 hours ago.
- curl --libcurl output carries --insecure across --next boundaries - An informative curl report concerning option-state leakage across --next boundaries was disclosed approximately 15 hours ago.
- curl HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED - A curl report concerning reconnection behavior for callback-provided sockets was disclosed approximately 19 hours ago.
- curl_mprintf reads double for documented long-double conversions - An informative curl report describing possible uninitialized-value disclosure was disclosed approximately 19 hours ago.
- --etag-save truncates append-redirected stdout - A low-severity curl report about output truncation was disclosed approximately 20 hours ago.
- Stacked --proto modifiers leave denied protocol enabled - A low-severity curl protocol-filtering issue was disclosed approximately 20 hours ago.
Medium — Bug Bounty
- The Bugs AI Still Can’t Find: What Will Make You a Valuable Bug Hunter in 2026 - The article discusses bug classes that remain difficult for automated AI-based bug-hunting tools and was listed as published just now.
- 8 Months of Learning, 4 Months of Hunting, 0 Bugs — Here’s What Actually Went Wrong - The article examines why a new bug hunter can remain without findings and was listed as published 1 hour ago.
- I Found a Fully Misconfigured S3 Bucket Exposing Private Images and Lead Complete Takeover - The article describes an S3 misconfiguration exposing private images and enabling account takeover, and was listed as published 4 hours ago.
- The OAuth2 Secret That Was Never Supposed to Leave the Server — But Did - The article reports an OAuth2 secret exposure found in a client-side bundle and was listed as published 4 hours ago.
- Httpx Explained with Practical Examples - The article explains using httpx for live-host discovery and bug-bounty reconnaissance, and was listed as published 7 hours ago.
Medium — InfosecWriteups / Infosec
- India Cyber Weekly: Operation Sindoor Cyber-Terror Probe, NetScaler Critical, GitLab Exploited… - The weekly security roundup covers NetScaler and GitLab exploitation among other developments and was listed as published 12 hours ago.
Intigriti BugBytes
- Intigriti Bug Bytes #239 — August 2026 - The August 2026 issue covers CrowdRecon, Adobe’s bug-bounty program, CSS injection, AI security research, and related resources, and is dated August 28, 2026.
GitHub — arkadiyt/bounty-targets-data
- bounty-targets committed dab39a7 - The repository received a commit at 04:00 UTC on August 29, 2026, within the last 24 hours.
- bounty-targets committed 5857fd1 - The repository received another commit at 03:30 UTC on August 29, 2026, within the last 24 hours.
- bounty-targets committed ec0beca - The repository received another commit at 02:30 UTC on August 29, 2026, within the last 24 hours.
- bounty-targets committed b4d8e7b - The repository received another commit at 02:00 UTC on August 29, 2026, within the last 24 hours.
- bounty-targets committed 13e6a27 - The repository received another commit at 01:30 UTC on August 29, 2026, within the last 24 hours.
- bounty-targets committed 38b2690 - The repository received another commit at 00:30 UTC on August 29, 2026, within the last 24 hours.
- bounty-targets committed 74627fd - The repository received another commit at 00:00 UTC on August 29, 2026, within the last 24 hours.
Mastodon Infosec.exchange
- #security activity: 28 posts today - The public tag page reports 28 new security posts today, indicating active infosec discussion during the last 24 hours, but does not expose individual post titles without login.
The Hacker News
- Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network - Berlin confirmed an extortion attempt and additional data outflows after attackers compromised the city's state administrative network.
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable - A critical Cosmos EVM flaw was exploited to drain funds from six blockchains between August 20 and 25.
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication - Attackers are chaining PaperCut flaws to gain unauthenticated remote code execution, prompting a new emergency fix.
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body - A critical ownCloud authentication-bypass flaw was added to CISA's exploited-vulnerability catalog after weaponization against a Philippine nuclear research body.
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code - Researchers identified 18 Chrome extensions and one Edge extension carrying wallet-stealing and cryptocurrency-draining functionality.
- Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth - Two disclosed Unitree G1 EDU flaws enable root-level remote code execution through network-adjacent and Bluetooth paths.
- Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL - ServiceNow patched four AI Platform vulnerabilities, including three rated CVSS 10.0 and exploitable in some cases without authentication.
BleepingComputer
- McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft - McKesson disclosed unauthorized access to third-party applications while ShinyHunters claimed theft of 284 million patient records.
- PaperCut Releases Second Emergency Patch for Exploited Flaws - PaperCut issued a second emergency update after researchers found bypasses for initial fixes to two actively exploited vulnerabilities.
- GiveWP WordPress Donation Plugin Flaw Lets Hackers Execute Server Commands - An unauthenticated maximum-severity GiveWP flaw permits arbitrary command execution on affected WordPress servers.
- Over 8,300 Gitea Servers Vulnerable to Code Execution Attacks - More than 8,300 internet-exposed Gitea instances remain unpatched against a flaw exploited in ongoing remote-code-execution attacks.
- Toy-Making Giant Hasbro Discloses Data Breach Affecting Employees - Hasbro reported that attackers accessed personal and financial information belonging to an undisclosed number of employees.
- ServiceNow Warns of Three Max Severity Security Vulnerabilities - ServiceNow warned of three maximum-severity AI Platform flaws enabling code injection, SQL injection, and privilege escalation.
Risky Business
- Risky Bulletin: Two TeamPCP Members Arrested in Australia - The bulletin covers Australia's arrest of two alleged TeamPCP members and related developments involving Qilin, Chinese botnets, and opportunistic cyber activity.
SecurityWeek
- ATF Confirms Cyber Incident After Ransomware Group Claims Attack - The ATF confirmed a major cyber incident after the Qilin ransomware group claimed to have targeted the agency.
- OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems - CISA added the exploited Linux kernel flaw CVE-2026-53362 to its Known Exploited Vulnerabilities catalog.
- PaperCut Releases Emergency Patch for Exploited Zero-Day - PaperCut urged NG and MF users to apply emergency patches and mitigations for an exploited zero-day.
- Australia Arrests 2 Alleged TeamPCP Hackers - Australian and U.S. authorities charged two alleged TeamPCP members over a cybercrime and software supply-chain operation.
- Cyberattack Causes Global Disruption at Boston Scientific - A cyber incident disrupted Boston Scientific's ability to process and ship customer orders worldwide.
- Recent Citrix NetScaler Vulnerability Exploited in the Wild - CISA urged immediate patching of Citrix NetScaler vulnerability CVE-2026-8452 following exploitation in the wild.
Dark Reading
- Hundreds of OpenAI Agents Invaded Hugging Face Servers - An investigation found approximately 700 AI agents collaborated in a sophisticated multistage attack on Hugging Face.
- The Vulnpocalypse Is Repricing the Bug Bounty Economy - A surge in vulnerability discovery is reshaping the economics and prioritization of bug bounty programs.
- Defining an AI Kill Switch Is Hard, but Necessary - Security leaders are examining how to contain autonomous AI systems when they behave unexpectedly or become compromised.
- Arbor Networks: 1.7Tbit/s DDoS Attack Sets Record - Arbor Networks reported mitigating a record 1.7 Tbit/s DDoS attack against a U.S.-based service provider.
DataBreaches.net
- McKesson Is Investigating a Cybersecurity Incident After ShinyHunters Claims Patient Data Theft - McKesson is investigating unauthorized access to third-party applications amid ShinyHunters' claim of large-scale patient-data theft.
- Winona County Paid More Than $128K Following January Ransomware Attack - Winona County disclosed paying $128,539.57 after a ransomware attack detected in January.
- UK: HIV Charity Has ‘Sensitive’ Health Data Stolen - Users of a UK HIV charity were warned that sensitive personal health information may have been exposed through the Beacon CRM breach.
Hacker News (yc)
- Just the Rumour of a Bug Is Enough to Find an Exploit These Days - A Hacker News discussion posted 12 hours ago examines how even rumors of vulnerabilities can accelerate exploit discovery.
NIST NVD & CVE.org
- CVE-2023-43902 — CVSS 9.8 Critical; eMudhra emSigner’s password-reset function permits unauthenticated account takeover, including administrator accounts, via a crafted reset token; NVD modified the record on 2026-08-28.
- CVE-2023-49105 — CVSS 9.8 Critical; ownCloud before 10.13.1 accepts unsigned pre-signed URLs without authentication, enabling arbitrary file access, modification, or deletion; NVD modified the record on 2026-08-28.
- CVE-2026-1524 — CVSS 9.8 Critical; Neo4j Enterprise versions before 2026.02 can incorrectly grant authorization through an authentication-only OIDC provider under a multi-provider configuration; NVD modified the record on 2026-08-28.
- CVE-2026-0545 — CVSS 9.8 Critical; MLflow job endpoints can bypass basic authentication and authorization, potentially enabling unauthenticated remote code execution when privileged jobs are allowlisted; NVD modified the record on 2026-08-28.
- CVE-2026-42264 — CVSS 9.1 Critical; Axios versions 1.0.0 through 1.15.1 can consume attacker-polluted Object.prototype properties as HTTP-adapter configuration gadgets; NVD modified the record on 2026-08-28.
- CVE-2026-42557 — CVSS 9.6 Critical; JupyterLab before 4.5.7 can execute attacker-chosen commands when a user clicks a deceptive button in pre-saved HTML output; NVD modified the record on 2026-08-28.
- CVE-2026-5241 — CVSS 9.6 Critical; transformers 5.2.0 can execute arbitrary code from an attacker-controlled model repository despite
trust_remote_code=Falsein the LightGlue loading path; NVD modified the record on 2026-08-28. - CVE-2026-76886 — CVSS 9.8 Critical; the C12.22 protocol dissector in affected 4.6.x and 4.4.x releases can be crashed to cause denial of service; NVD modified the record on 2026-08-28.
- CVE-2026-66788 — CVSS 9.9 Critical; Lighthouse permits a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into namespaces on peer clusters; NVD modified the record on 2026-08-28.
- CVE-2026-82266 — CVSS 9.3 Critical (CVSS 4.0); Redpanda through 26.2.2 exposes an unauthenticated Admin API that treats remote requests as superusers; published and modified on 2026-08-28.
- CVE-2026-82277 — CVSS 9.3 Critical (CVSS 4.0); Argo Rollouts through 1.10.0 exposes unauthenticated mutating dashboard operations across accessible namespaces; published and modified on 2026-08-28.
- CVE-2026-18527 — CVSS 9.9 Critical; IBM Administration Runtime Expert for i 1R1M0 allows an unauthenticated remote attacker to execute actions under another user’s authenticated profile and gain elevated privileges; published and modified on 2026-08-28.
- CVE-2026-19286 — CVSS 9.8 Critical; Langflow OSS 1.0.0 through 1.11.1 permits arbitrary code execution through insufficient enforcement of restrictions on the A2A public endpoint; published and modified on 2026-08-28.
- CVE-2026-19295 — CVSS 9.9 Critical; Langflow OSS 1.0.0 through 1.11.1 lets an authenticated flow user escalate to operating-system command execution through a crafted flow type; published and modified on 2026-08-28.
- CVE-2026-3627 — CVSS 9.1 Critical; IBM Concert 1.0.0 through 2.3.1 is vulnerable to remote SQL injection that can expose or alter backend data; published and modified on 2026-08-28.
GitHub Advisories List
- CVE-2026-80704 / GHSA-pqhq-6v8m-mfrc — GitHub published and updated an unreviewed Linux-kernel advisory on 2026-08-28 describing a NULL-pointer dereference in AMD display logging that can crash the kernel.
- CVE-2026-80655 / GHSA-x28x-mxhh-x47j — GitHub published and updated an unreviewed Linux-kernel advisory on 2026-08-28 describing a race condition in Xilinx event registration that can cause a NULL-pointer dereference.
GhostTroops/TOP
- BYOVD — The TOP 2026 offensive-project index records an update at 2026-08-28T06:11:52Z for vulnerable-driver research and reverse-engineering use cases covering CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, and CVE-2026-8501.
KitPloit
- vphone-cli - New listing approximately 27 minutes ago for booting and managing virtual iPhones on Apple Silicon, including firmware patching and jailbreak variants for iOS security research.
- ziti v2.0.4 - New listing approximately 2 hours 50 minutes ago for the OpenZiti zero-trust networking platform.
- malvinci - New listing approximately 4 hours 49 minutes ago for a script described as providing firewall-disabling, HTTP-server, port-forwarding, and persistence capabilities.
- conductai - New listing approximately 5 hours 19 minutes ago for an AI-agent governance tool focused on runtime firewalls and policy enforcement.
Help Net Security
- What 90 days and a small budget can buy in AI agent security - Interview published approximately 23 hours ago examining the operational and infrastructure costs of securing self-hosted open-weight AI agents.
- Android 17 adds new protections against sneaky Wi-Fi and 2G attacks - Article published approximately 19 hours ago covering browsing-domain privacy, Wi-Fi scanning, and 2G SMS-scam protections.
- Manchester Airports Group breached, millions of customers affected - Article published approximately 21 hours ago reporting a breach affecting email addresses and phone numbers at three UK airports.
Hack The Box
- Your defensive security training on Hack The Box just got a major upgrade - Announcement dated August 28, 2026 describing expanded blue-team modules, investigative scenarios, and SOC operations training.
CTFtime.org
- BlackHat MEA CTF Qualification 2026 - Active/upcoming online qualification event beginning August 29 at 07:00 UTC and running for 24 hours.
- ASIS CTF Quals 2026 - Upcoming online qualification event beginning August 29 at 14:00 UTC and running for 24 hours.
- UND CyberHawks National CTF Competition 2026 Qualifiers - Upcoming online qualifier beginning August 29 at 14:00 UTC and running until 05:00 UTC on August 30.
- Iran Tech Olympics CTF 2026 - Upcoming online jeopardy event beginning August 29 at 14:00 UTC and running for 24 hours.
- DiceCTF 2026 Finals - Upcoming in-person hack-quest final beginning August 29 at 16:00 UTC in New York City and running through August 30 at 22:00 UTC.
- Sailpoint Functional Testing Security Analyst at Xcel Energy - Listing surfaced approximately 5 hours ago involving security-test lifecycle planning, test-data preparation, and execution.
- Information Security Analyst (Hybrid) at Motorola Solutions - Listing surfaced approximately 9 hours ago involving vulnerability assessments and coordination of penetration testing.
- Cybersecurity Specialist (Remote) at Quik Hire Staffing - Listing surfaced approximately 15 hours ago seeking a penetration tester for manual and automated testing and documentation.
- Security Pen Tester - InfoSec at Next - Listing surfaced approximately 20 hours ago seeking a security penetration tester to identify vulnerabilities.
Indeed
- Security Analyst – Contract - Toronto, ON - Listing surfaced approximately 6 hours ago for a contract security analyst role paying C$40–C$45 per hour.
- Cyber Security Analyst - Remote - Listing surfaced approximately 15 hours ago for a remote analyst role covering incident triage, security alerts, vulnerability scanning, and penetration-testing findings.
- Senior Cyber Security Analyst (CAAT) - Vienna, VA - Listing surfaced approximately 15 hours ago for a full-time senior analyst position with a listed salary range of $113,300–$155,850.
- SOC Level 2 Security Analyst - Birmingham - Listing surfaced approximately 15 hours ago for a SOC Level 2 analyst role handling escalated security alerts and incidents.
⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.
Developed by @win3zz