DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini
Can AI do novel security research? Meet the HTTP Terminator
Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems
The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking
The AI refused to steal the secrets. So we handed it a form.
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
DEF CON 34 :: Weaponizing Windows PnP
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
Design System Analysis: Notion
Capture the Narrative - Social Media Manipulation Wargaming for Cyberliteracy and Research
Token Injection: Crashing LLM Inference With Special Tokens
Watching GPT-5.6 Sol Ultra Write a Chrome Exploit: Exploit Development as We Know It Is Dead
펌웨어 추출 방법
A New Attack Surface on MS Exchange Part 1 - ProxyLogon!
ACDC 2025 AI 해킹방어대회 Attack&Defense 후기
Production-grade DESIGN.md collection
Hermes Agent — The Agent That Grows With You
Yeachan-Heo/oh-my-codex
Harness engineering: leveraging Codex in an agent-first world
The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program
EXPMON detected sophisticated zero-day fingerprinting attack targeting Adobe Reader users
How Claude Code works
The Cognitive Dark Forest
보안 담당자라면 꼭 알아야 할 점검 전략 가이드 | 모의해킹 vs 모의침투 vs 취약점 진단
ENKI Redteam CTF Writeup : Jeopardy
Remote Command Execution in Google Cloud with Single Directory Deletion
Livewire: remote command execution through unmarshaling
How a supply chain attack on PyPI got us through a Cursor-launched MCP server the old-fashioned way
IPv4 Obfuscation of Shellcode
3 Papers Regarding Side-Channel Attacks Against LLMs
Verify Email Addresses Without Sending a Single Email
GatewayToHeaven: Finding a Critical Cross-Tenant Exploit in GCP’s Apigee
1nfin1ty Web challenge ( 0xL4ugh CTF v5 )
Chrome Browser Exploitation, Part 1: Introduction to V8 and JavaScript Internals
CloudFlare WAF Bypass Through ACME Path
Breakdown of Dead Startups
Threat Model case study - Pick & place with a ROS2 manipulator
On the Coming Industrialisation of Exploit Generation with LLMs
Using BMP Polyglots to get RCE
https://flatt.tech/research/posts/pwning-claude-code-in-8-different-ways
Hacking does not confirm to just a computer, take a wilder approach.
News: There Were BGP Anomalies During The Venezuela Blackout
https://blog.harold.kim/2018/04/asisctf-2018-moehost-solution
프롬프팅 대신 프로그래밍 - DSPy를 활용한 프롬프트 자동 최적화
LLM 으로 Django 0day 찾은 썰 👑
https://nanimokangaeteinai.hateblo.jp/entry/2025/09/08/043631
https://labs.watchtowr.com/you-already-have-our-personal-data-take-our-phone-calls-too-freepbx-cve-2025-57819/
https://canalun.company/posts/domdomtimes_iframe_is_not_secure_escape_hatch_en
https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/
https://www.slcyber.io/research/novel-ssrf-technique-involving-http-redirect-loops
https://blog.slonser.info/posts/make-self-xss-great-again/
https://www.reddit.com/r/websecurityresearch/comments/1kqk5nn/using_random_peoples_browsers_to_ddos_others/
https://syssec.kaist.ac.kr/pub/2025/Too_Much_Good.pdf
https://krebsonsecurity.com/2025/06/inside-a-dark-adtech-empire-fed-by-fake-captchas/
https://localmess.github.io/
https://blog.includesecurity.com/2025/04/cross-site-websocket-hijacking-exploitation-in-2025/
https://www.youtube.com/watch?v=EuHQZyTa91E
https://medium.com/@sharon.brizinov/how-i-made-64k-from-deleted-files-a-bug-bounty-story-c5bd3a6f5f9b
https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
https://bishopfox.com/blog/unredacter-tool-never-pixelation
Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc’s iconv()
https://blog.lexfo.fr/lightyear-file-dump.html
https://swarm.ptsecurity.com/impossible-xxe-in-php/
https://blog.trailofbits.com/2019/07/08/fuck-rsa/
https://blog.ethiack.com/blog/supercharging-bug-bounty-hunting-with-ai
https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie
https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
https://projectdiscovery.io/blog/guide-to-dns-takeovers
https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw
https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/
https://www.invicti.com/blog/security-labs/first-tokens-the-achilles-heel-of-llms/
https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/
https://joaxcar.com/blog/2024/12/20/sideloading-external-scripts-a-code-golf-challenge/
https://www.jmeiners.com/lc3-vm/
https://blog.orange.tw/posts/2018-10-hitcon-ctf-2018-one-line-php-challenge/
https://blo.zbss.site/jsp-webshell-免杀/
https://securitybynature.fr/post/hacking-cryptolib
https://thottysploity.github.io/posts/cve-2024-53375/
https://portswigger.net/research/exploiting-cors-misconfigurations-for-bitcoins-and-bounties
https://outpost24.com/blog/exploiting-permissive-cors-configurations/
https://aem1k.com/invisible/
https://samcurry.net/hacking-kia#http-request-to-search-vin-using-kia-dealer-apigw-endpoint-with-dda-access-token
https://vulncat.fortify.com/ko/weakness
https://www.hackerone.com/blog/gdpr-and-pentesting-what-you-need-know
https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610
https://github.com/strellic/my-ctf-challenges
https://www.synacktiv.com/en/publications/github-actions-exploitation-self-hosted-runners
https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase
https://github.com/smxiazi/xia_Liao
https://medium.com/@proseizala/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-92a004f1cbe8
https://embracethered.com/blog/posts/2024/chatgpt-persistent-denial-of-service/
https://projectzero.google/2024/06/project-naptime.html
https://github.com/blacklanternsecurity/bbot
https://github.com/yogeshojha/rengine
https://ios.cfw.guide/get-started/
https://aszx87410.github.io/beyond-xss/en/
https://browser.engineering/
https://mrd0x.com/progressive-web-apps-pwa-phishing/
https://nickguitar.medium.com/hacking-nasa-critical-ssrf-subdomain-takeover-xss-699be0ce3c06
https://github.com/m4ll0k/SecretFinder
https://www.alignmentforum.org/posts/vERGLBpDE8m5mpT6t/autonomous-replication-and-adaptation-an-attempt-at-a
https://github.com/zgzhang/cve-2024-6387-poc/
https://arxiv.org/html/2404.14082v1
https://openai.com/index/introducing-superalignment/
https://github.com/h4r5h1t/webcopilot
https://bughunters.google.com/blog/enabling-trusted-types-in-a-complex-web-application-a-case-study-of-appsheet
https://www.qualys.com/regresshion-cve-2024-6387/
https://projectdiscovery.io/blog/hacking-apple-with-sql-injection
https://projectdiscovery.io/blog/secret-token-scanning-with-nuclei
https://str.lc/posts/sekaictf_2022_challenges/
https://drive.google.com/file/d/1W33xHPBeqEkPf-FcvPWuXC4JGWar8wHt/view
https://www.freebuf.com/articles/web/255717.html
https://github.com/xcanwin/CVE-2023-4357-Chrome-XXE
https://github.com/blackbird-eu/community-scripts/tree/main/GTM-subdomain-enum
https://medium.com/@osamaavvan/breaking-down-dom-based-xss-a-practical-exploration-929d44f10906
https://samcurry.net/hacking-millions-of-modems
https://security.lauritz-holtmann.de/post/sso-security-redirect-uri-iii/
https://securitylab.github.com/advisories/GHSL-2023-235_GHSL-2023-237_Open_Metadata/
https://www.sonarsource.com/blog/pitfalls-of-desanitization-leaking-customer-data-from-osticket
https://x.com/arekfurt/status/1754274004049801443
https://x.com/arkark_/status/1761943059040989581
https://x.com/hugopicanzo/status/1792490934090760410
https://x.com/aszx87410/status/1756941975201468774
https://www.youtube.com/watch?v=3WS4Iy14U3o
https://portswigger.net/burp/documentation/desktop/tools/dom-invader/settings/canary
https://github.com/advisories/GHSA-mw2w-2hj2-fg8q
https://labs.watchtowr.com/xxe-you-can-depend-on-me-opencms/
https://ufo.stealien.com/2023-07-31/bughunting-vulnerability-chaining-ko
https://blog.torproject.org/security-audit-report-tor-browser-ooni/
https://developer.mozilla.org/en-US/docs/Web/API/HTML_Sanitizer_API
https://cloud.google.com/blog/topics/threat-intelligence/hunting-deserialization-exploits/
https://omergil.blogspot.com/2017/02/web-cache-deception-attack.html
https://portswigger.net/research/bypassing-dompurify-again-with-mutation-xss
https://www.sonarsource.com/blog/why-orms-and-prepared-statements-cant-always-win/
https://speakerdeck.com/pwntester/attacking-net-serialization
https://thehackernews.com/2023/03/openai-reveals-redis-bug-behind-chatgpt.html?m=1
https://www.bentasker.co.uk/posts/documentation/linux/310-building-a-tor-hidden-service-from-scratch-part-3-general-user-anonymity-and-security.html
https://github.com/geeknik/the-nuclei-templates
https://gogilove.wordpress.com/2019/05/07/tor-onion-deep-web-faq/
https://httpoxy.org/
https://www.schneier.com/blog/archives/2023/01/the-fbi-identified-a-tor-user.html
https://www.theguardian.com/world/interactive/2013/oct/04/tor-stinks-nsa-presentation-document
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
https://www.youtube.com/watch?v=v45_tkKCJ54
https://blog.munsiwoo.kr/2023/03/blind-postgresql-injection-in-dapp-interface-20000-bounty/
https://fireshellsecurity.team/sekaictf-frog-waf-and-chunky/#challenge-frog-waf-29-solves
https://github.com/Contrast-Security-OSS/Spring-Kafka-POC-CVE-2023-34040
https://portswigger.net/research/browser-powered-desync-attacks
https://x.com/kevin_mizu/status/1701922141791211776
https://community.hpe.com/t5/hpe-threat-labs/cve-2023-33246-apache-rocketmq-remote-code-execution/ba-p/7266244
https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a
https://portswigger.net/web-security/request-smuggling
https://www.synacktiv.com/en/publications/finding-a-pop-chain-on-a-common-symfony-bundle-part-1
https://blog.huli.tw/2023/01/10/en/security-of-encrypt-or-hash-password-in-client-side/
https://blog.huli.tw/2022/12/26/en/ctf-2022-web-js-summary/
https://blog.s1r1us.ninja/CTF/site-isolation
https://gist.github.com/parrot409/09688d0bb81acbe8cd1a10cfdaa59e45
https://github.blog/security/vulnerability-research/mtls-when-certificate-authentication-is-done-wrong/
https://onlydev.tistory.com/157
https://auth0.com/blog/preventing-https-downgrade-attacks/
https://projectdiscovery.io/blog/nuclei-interactsh-integration
https://github.com/corelan/mona/blob/master/mona.py
https://github.com/jas502n/cve-2019-2618
https://huntr.com/bounties/1eef5a72-f6ab-4f61-b31d-fc66f5b4b467
https://matan-h.com/one-lfi-bypass-to-rule-them-all-using-base64/
https://portswigger.net/web-security/cross-site-scripting/contexts/lab-html-context-with-most-tags-and-attributes-blocked
https://portswigger.net/research/exploiting-xss-in-hidden-inputs-and-meta-tags
https://sakurity.com/blog/2015/03/15/authy_bypass.html
https://securitytrails.com/blog/jarm-fingerprinting-tool
https://www.youtube.com/watch?v=skbKjO8ahCI
https://projectdiscovery.io/blog/moveit-transfer-sql-injection
https://devco.re/blog/2023/07/07/a-journey-into-hacking-google-search-appliance-en/
https://www.embeeresearch.io/shodan-censys-queries/
https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads
https://mohemiv.com/all/exploiting-xxe-with-local-dtd-files/
https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/