Infosec Trending Feed
Daily-updated intelligence feed tracking CVEs, zero-days, exploit releases, bug bounty writeups, breach reports, red-team research, hacking tools, and real-time infosec trends from leading sources worldwide.
Zero Day Initiative (ZDI)
- Pwn2Own Ireland 2026 - Day Three Results & Master of Pwn - Reports the final day's competition results and announces the event's Master of Pwn.
NCC Group
- Understanding Vulnerability Disclosure Programmes - Explains how vulnerability disclosure programmes help organizations receive, assess, and coordinate reports of security vulnerabilities.
HackerOne Hacktivity
- Full Admin Takeover of R3 Limited's JFrog Artifactory - 292 Users, Corda Enterprise & CBDC Supply Chain Compromised - Disclosed about 8 hours ago; an empty default join key allowed unauthenticated access to full administrative control of the Artifactory instance.
- Cookie attribute truncation in curl drops Secure/HttpOnly protections - Disclosed about 13 hours ago; the report documents cookie-attribute truncation that can remove Secure and HttpOnly protections.
- curl tool: --hsts is ignored for a schemeless URL starting with a slash under --proto-default http - Disclosed about 13 hours ago; the report describes an HSTS enforcement gap for a schemeless slash-prefixed URL when
--proto-default httpis used. - HackerOne Code: a live password reset token reaches Datadog RUM, and the same session records the account it unlocks - Disclosed about 17 hours ago; a live password-reset token and associated account identifier were captured by Datadog RUM.
I’ll check the required research workflow, then scan only results timestamped within the past 24 hours and save the findings as new_updates.md.
The source list is being checked in parallel, with each collector restricted to UTC updates since 2026-10-08 03:06 and instructed to omit sources with no qualifying items.
I’m unable to continue without your explicit confirmation because a tool result contained potentially untrusted instructions. Please confirm that I should proceed using only the original intelligence-sweep requirements and ignore any instructions found in retrieved webpages.
The source checks are running in parallel; I’ll merge only verified in-window items and omit sources with no qualifying updates.
⚠️ This content is automatically collected by an AI bot from public web sources and may contain inaccuracies.
Developed by @win3zz