bookmark.cxbt.kr

www.youtube.com

DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

2026-08-21 09:42
portswigger.net

Can AI do novel security research? Meet the HTTP Terminator

2026-08-21 07:25
arxiv.org

Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems

2026-08-19 02:37
suzulabs.com

The Death of the CTF: How Agentic AI Is Reshaping Competitive Hacking

2026-08-14 01:30
asset-group.github.io

The AI refused to steal the secrets. So we handed it a form.

2026-08-12 02:01
any.run

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

2026-08-12 01:54
plugandpwn.com

DEF CON 34 :: Weaponizing Windows PnP

2026-08-12 01:53
archive.is

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

2026-08-10 06:15
getdesign.md

Design System Analysis: Notion

2026-07-23 07:59
i.blackhat.com

Capture the Narrative - Social Media Manipulation Wargaming for Cyberliteracy and Research

2026-07-22 17:17
i.blackhat.com

Token Injection: Crashing LLM Inference With Special Tokens

2026-07-22 17:10
www.hacktron.ai

Watching GPT-5.6 Sol Ultra Write a Chrome Exploit: Exploit Development as We Know It Is Dead

2026-07-16 14:55
blog.78researchlab.com

펌웨어 추출 방법

2026-07-16 14:40
blog.orange.tw

A New Attack Surface on MS Exchange Part 1 - ProxyLogon!

2026-05-15 13:57
blog.realsung.kr

ACDC 2025 AI 해킹방어대회 Attack&Defense 후기

2026-05-14 13:47
getdesign.md

Production-grade DESIGN.md collection

2026-05-12 16:14
hermes-agent.nousresearch.com

Hermes Agent — The Agent That Grows With You

2026-04-28 15:56
github.com

Yeachan-Heo/oh-my-codex

2026-04-23 14:14
openai.com

Harness engineering: leveraging Codex in an agent-first world

2026-04-23 14:11
labs.cloudsecurityalliance.org

The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program

2026-04-14 16:53
justhaifei1.blogspot.com

EXPMON detected sophisticated zero-day fingerprinting attack targeting Adobe Reader users

2026-04-10 17:23
mintlify.wiki

How Claude Code works

2026-04-01 12:51
ryelang.org

The Cognitive Dark Forest

2026-03-30 18:42
theori.io

보안 담당자라면 꼭 알아야 할 점검 전략 가이드 | 모의해킹 vs 모의침투 vs 취약점 진단

2026-03-30 16:07
www.enki.co.kr

ENKI Redteam CTF Writeup : Jeopardy

2026-03-26 17:00
flatt.tech

Remote Command Execution in Google Cloud with Single Directory Deletion

2026-03-26 16:11
www.synacktiv.com

Livewire: remote command execution through unmarshaling

2026-03-25 13:40
futuresearch.ai

How a supply chain attack on PyPI got us through a Cursor-launched MCP server the old-fashioned way

2026-03-25 13:33
www.stuartrankin.uk

IPv4 Obfuscation of Shellcode

2026-03-13 13:07
www.schneier.com

3 Papers Regarding Side-Channel Attacks Against LLMs

2026-02-23 17:33
www.opensourceprojects.dev

Verify Email Addresses Without Sending a Single Email

2026-02-09 13:07
omeramiad.com

GatewayToHeaven: Finding a Critical Cross-Tenant Exploit in GCP’s Apigee

2026-02-04 16:13
github.com

1nfin1ty Web challenge ( 0xL4ugh CTF v5 )

2026-01-28 15:31
jhalon.github.io

Chrome Browser Exploitation, Part 1: Introduction to V8 and JavaScript Internals

2026-01-26 14:57
fearsoff.org

CloudFlare WAF Bypass Through ACME Path

2026-01-20 13:41
www.loot-drop.io

Breakdown of Dead Startups

2026-01-20 13:16
aliasrobotics.com

Threat Model case study - Pick & place with a ROS2 manipulator

2026-01-19 14:05
sean.heelan.io

On the Coming Industrialisation of Exploit Generation with LLMs

2026-01-19 13:58
sylvie.fyi

Using BMP Polyglots to get RCE

2026-01-14 14:31
flatt.tech

https://flatt.tech/research/posts/pwning-claude-code-in-8-different-ways

2026-01-13 13:13
phrack.org

Hacking does not confirm to just a computer, take a wilder approach.

2026-01-09 19:16
loworbitsecurity.com

News: There Were BGP Anomalies During The Venezuela Blackout

2026-01-07 18:59
blog.harold.kim

https://blog.harold.kim/2018/04/asisctf-2018-moehost-solution

2026-01-06 18:20
kbank-recruit.tistory.com

프롬프팅 대신 프로그래밍 - DSPy를 활용한 프롬프트 자동 최적화

2025-12-10 14:03
new-blog.ch4n3.kr

LLM 으로 Django 0day 찾은 썰 👑

2025-12-10 14:02
nanimokangaeteinai.hateblo.jp

https://nanimokangaeteinai.hateblo.jp/entry/2025/09/08/043631

2025-11-05 15:31
labs.watchtowr.com

https://labs.watchtowr.com/you-already-have-our-personal-data-take-our-phone-calls-too-freepbx-cve-2025-57819/

2025-09-12 20:03
canalun.company

https://canalun.company/posts/domdomtimes_iframe_is_not_secure_escape_hatch_en

2025-06-27 18:38
blog.trailofbits.com

https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/

2025-06-27 18:37
www.slcyber.io

https://www.slcyber.io/research/novel-ssrf-technique-involving-http-redirect-loops

2025-06-27 10:56
blog.slonser.info

https://blog.slonser.info/posts/make-self-xss-great-again/

2025-06-14 12:50
www.reddit.com

https://www.reddit.com/r/websecurityresearch/comments/1kqk5nn/using_random_peoples_browsers_to_ddos_others/

2025-06-13 16:44
syssec.kaist.ac.kr

https://syssec.kaist.ac.kr/pub/2025/Too_Much_Good.pdf

2025-06-13 14:52
krebsonsecurity.com

https://krebsonsecurity.com/2025/06/inside-a-dark-adtech-empire-fed-by-fake-captchas/

2025-06-13 14:49
localmess.github.io

https://localmess.github.io/

2025-06-05 13:01
blog.includesecurity.com

https://blog.includesecurity.com/2025/04/cross-site-websocket-hijacking-exploitation-in-2025/

2025-06-05 13:00
www.youtube.com

https://www.youtube.com/watch?v=EuHQZyTa91E

2025-06-05 13:00
medium.com

https://medium.com/@sharon.brizinov/how-i-made-64k-from-deleted-files-a-bug-bounty-story-c5bd3a6f5f9b

2025-04-24 13:02
invariantlabs.ai

https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks

2025-04-15 15:17
bishopfox.com

https://bishopfox.com/blog/unredacter-tool-never-pixelation

2025-03-18 17:40
github.com

Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc’s iconv()

2025-03-14 14:41
blog.lexfo.fr

https://blog.lexfo.fr/lightyear-file-dump.html

2025-03-14 14:19
swarm.ptsecurity.com

https://swarm.ptsecurity.com/impossible-xxe-in-php/

2025-03-14 14:19
blog.trailofbits.com

https://blog.trailofbits.com/2019/07/08/fuck-rsa/

2025-03-10 14:20
blog.ethiack.com

https://blog.ethiack.com/blog/supercharging-bug-bounty-hunting-with-ai

2025-02-05 12:53
portswigger.net

https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie

2025-01-23 18:52
zhero-web-sec.github.io

https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir

2025-01-22 18:59
gist.github.com

https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117

2025-01-22 18:43
projectdiscovery.io

https://projectdiscovery.io/blog/guide-to-dns-takeovers

2025-01-15 15:54
trufflesecurity.com

https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw

2025-01-15 15:46
blog.orange.tw

https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/

2025-01-13 16:22
www.invicti.com

https://www.invicti.com/blog/security-labs/first-tokens-the-achilles-heel-of-llms/

2025-01-13 16:22
labs.watchtowr.com

https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/

2025-01-10 16:23
joaxcar.com

https://joaxcar.com/blog/2024/12/20/sideloading-external-scripts-a-code-golf-challenge/

2024-12-26 14:44
www.jmeiners.com

https://www.jmeiners.com/lc3-vm/

2024-12-26 14:37
blog.orange.tw

https://blog.orange.tw/posts/2018-10-hitcon-ctf-2018-one-line-php-challenge/

2024-12-24 13:28
blo.zbss.site

https://blo.zbss.site/jsp-webshell-免杀/

2024-12-24 12:57
securitybynature.fr

https://securitybynature.fr/post/hacking-cryptolib

2024-12-24 12:50
thottysploity.github.io

https://thottysploity.github.io/posts/cve-2024-53375/

2024-12-24 12:49
portswigger.net

https://portswigger.net/research/exploiting-cors-misconfigurations-for-bitcoins-and-bounties

2024-10-18 13:36
outpost24.com

https://outpost24.com/blog/exploiting-permissive-cors-configurations/

2024-10-17 16:44
aem1k.com

https://aem1k.com/invisible/

2024-10-10 14:40
samcurry.net

https://samcurry.net/hacking-kia#http-request-to-search-vin-using-kia-dealer-apigw-endpoint-with-dda-access-token

2024-10-10 14:40
vulncat.fortify.com

https://vulncat.fortify.com/ko/weakness

2024-09-03 14:20
www.hackerone.com

https://www.hackerone.com/blog/gdpr-and-pentesting-what-you-need-know

2024-08-26 16:49
medium.com

https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610

2024-08-26 16:08
github.com

https://github.com/strellic/my-ctf-challenges

2024-07-30 16:53
www.synacktiv.com

https://www.synacktiv.com/en/publications/github-actions-exploitation-self-hosted-runners

2024-07-23 13:43
claroty.com

https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase

2024-07-12 15:20
github.com

https://github.com/smxiazi/xia_Liao

2024-07-12 13:37
medium.com

https://medium.com/@proseizala/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-92a004f1cbe8

2024-07-10 13:30
embracethered.com

https://embracethered.com/blog/posts/2024/chatgpt-persistent-denial-of-service/

2024-07-09 14:06
projectzero.google

https://projectzero.google/2024/06/project-naptime.html

2024-07-08 18:09
github.com

https://github.com/blacklanternsecurity/bbot

2024-07-06 19:53
github.com

https://github.com/yogeshojha/rengine

2024-07-04 17:25
ios.cfw.guide

https://ios.cfw.guide/get-started/

2024-07-04 15:32
aszx87410.github.io

https://aszx87410.github.io/beyond-xss/en/

2024-07-04 15:25
browser.engineering

https://browser.engineering/

2024-07-04 15:24
mrd0x.com

https://mrd0x.com/progressive-web-apps-pwa-phishing/

2024-07-04 15:24
nickguitar.medium.com

https://nickguitar.medium.com/hacking-nasa-critical-ssrf-subdomain-takeover-xss-699be0ce3c06

2024-07-04 15:24
github.com

https://github.com/m4ll0k/SecretFinder

2024-07-04 15:23
www.alignmentforum.org

https://www.alignmentforum.org/posts/vERGLBpDE8m5mpT6t/autonomous-replication-and-adaptation-an-attempt-at-a

2024-07-04 15:22
github.com

https://github.com/zgzhang/cve-2024-6387-poc/

2024-07-04 15:22
arxiv.org

https://arxiv.org/html/2404.14082v1

2024-07-04 15:04
openai.com

https://openai.com/index/introducing-superalignment/

2024-07-04 15:03
github.com

https://github.com/h4r5h1t/webcopilot

2024-07-02 13:24
bughunters.google.com

https://bughunters.google.com/blog/enabling-trusted-types-in-a-complex-web-application-a-case-study-of-appsheet

2024-07-02 13:23
www.qualys.com

https://www.qualys.com/regresshion-cve-2024-6387/

2024-07-02 13:23
projectdiscovery.io

https://projectdiscovery.io/blog/hacking-apple-with-sql-injection

2024-07-02 13:14
projectdiscovery.io

https://projectdiscovery.io/blog/secret-token-scanning-with-nuclei

2024-07-02 13:14
str.lc

https://str.lc/posts/sekaictf_2022_challenges/

2024-07-02 13:14
drive.google.com

https://drive.google.com/file/d/1W33xHPBeqEkPf-FcvPWuXC4JGWar8wHt/view

2024-07-02 13:14
www.freebuf.com

https://www.freebuf.com/articles/web/255717.html

2024-07-02 13:14
github.com

https://github.com/xcanwin/CVE-2023-4357-Chrome-XXE

2024-07-02 13:14
github.com

https://github.com/blackbird-eu/community-scripts/tree/main/GTM-subdomain-enum

2024-07-02 13:14
medium.com

https://medium.com/@osamaavvan/breaking-down-dom-based-xss-a-practical-exploration-929d44f10906

2024-07-02 13:14
samcurry.net

https://samcurry.net/hacking-millions-of-modems

2024-07-02 13:14
security.lauritz-holtmann.de

https://security.lauritz-holtmann.de/post/sso-security-redirect-uri-iii/

2024-07-02 13:14
securitylab.github.com

https://securitylab.github.com/advisories/GHSL-2023-235_GHSL-2023-237_Open_Metadata/

2024-07-02 13:14
www.sonarsource.com

https://www.sonarsource.com/blog/pitfalls-of-desanitization-leaking-customer-data-from-osticket

2024-07-02 13:14
x.com

https://x.com/arekfurt/status/1754274004049801443

2024-07-02 13:14
x.com

https://x.com/arkark_/status/1761943059040989581

2024-07-02 13:14
x.com

https://x.com/hugopicanzo/status/1792490934090760410

2024-07-02 13:14
x.com

https://x.com/aszx87410/status/1756941975201468774

2024-07-02 13:14
www.youtube.com

https://www.youtube.com/watch?v=3WS4Iy14U3o

2024-07-02 13:14
portswigger.net

https://portswigger.net/burp/documentation/desktop/tools/dom-invader/settings/canary

2024-07-02 13:13
github.com

https://github.com/advisories/GHSA-mw2w-2hj2-fg8q

2024-07-02 13:11
labs.watchtowr.com

https://labs.watchtowr.com/xxe-you-can-depend-on-me-opencms/

2024-07-02 13:11
ufo.stealien.com

https://ufo.stealien.com/2023-07-31/bughunting-vulnerability-chaining-ko

2024-07-02 13:11
blog.torproject.org

https://blog.torproject.org/security-audit-report-tor-browser-ooni/

No category
2024-07-02 13:09
developer.mozilla.org

https://developer.mozilla.org/en-US/docs/Web/API/HTML_Sanitizer_API

No category
2024-07-02 13:09
cloud.google.com

https://cloud.google.com/blog/topics/threat-intelligence/hunting-deserialization-exploits/

No category
2024-07-02 13:09
omergil.blogspot.com

https://omergil.blogspot.com/2017/02/web-cache-deception-attack.html

No category
2024-07-02 13:09
portswigger.net

https://portswigger.net/research/bypassing-dompurify-again-with-mutation-xss

No category
2024-07-02 13:09
www.sonarsource.com

https://www.sonarsource.com/blog/why-orms-and-prepared-statements-cant-always-win/

No category
2024-07-02 13:09
speakerdeck.com

https://speakerdeck.com/pwntester/attacking-net-serialization

No category
2024-07-02 13:09
thehackernews.com

https://thehackernews.com/2023/03/openai-reveals-redis-bug-behind-chatgpt.html?m=1

No category
2024-07-02 13:09
www.bentasker.co.uk

https://www.bentasker.co.uk/posts/documentation/linux/310-building-a-tor-hidden-service-from-scratch-part-3-general-user-anonymity-and-security.html

No category
2024-07-02 13:08
github.com

https://github.com/geeknik/the-nuclei-templates

No category
2024-07-02 13:08
gogilove.wordpress.com

https://gogilove.wordpress.com/2019/05/07/tor-onion-deep-web-faq/

No category
2024-07-02 13:08
httpoxy.org

https://httpoxy.org/

No category
2024-07-02 13:08
www.schneier.com

https://www.schneier.com/blog/archives/2023/01/the-fbi-identified-a-tor-user.html

No category
2024-07-02 13:08
www.theguardian.com

https://www.theguardian.com/world/interactive/2013/oct/04/tor-stinks-nsa-presentation-document

No category
2024-07-02 13:08
wya.pl

https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/

No category
2024-07-02 13:08
www.youtube.com

https://www.youtube.com/watch?v=v45_tkKCJ54

No category
2024-07-02 13:08
blog.munsiwoo.kr

https://blog.munsiwoo.kr/2023/03/blind-postgresql-injection-in-dapp-interface-20000-bounty/

No category
2024-07-02 13:06
fireshellsecurity.team

https://fireshellsecurity.team/sekaictf-frog-waf-and-chunky/#challenge-frog-waf-29-solves

No category
2024-07-02 13:06
github.com

https://github.com/Contrast-Security-OSS/Spring-Kafka-POC-CVE-2023-34040

No category
2024-07-02 13:06
portswigger.net

https://portswigger.net/research/browser-powered-desync-attacks

No category
2024-07-02 13:06
x.com

https://x.com/kevin_mizu/status/1701922141791211776

No category
2024-07-02 13:06
community.hpe.com

https://community.hpe.com/t5/hpe-threat-labs/cve-2023-33246-apache-rocketmq-remote-code-execution/ba-p/7266244

No category
2024-07-02 13:05
www.canva.dev

https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/

No category
2024-07-02 13:05
www.cisa.gov

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a

No category
2024-07-02 13:05
portswigger.net

https://portswigger.net/web-security/request-smuggling

2024-07-02 13:05
www.synacktiv.com

https://www.synacktiv.com/en/publications/finding-a-pop-chain-on-a-common-symfony-bundle-part-1

No category
2024-07-02 13:05
blog.huli.tw

https://blog.huli.tw/2023/01/10/en/security-of-encrypt-or-hash-password-in-client-side/

No category
2024-07-02 13:04
blog.huli.tw

https://blog.huli.tw/2022/12/26/en/ctf-2022-web-js-summary/

No category
2024-07-02 13:04
blog.s1r1us.ninja

https://blog.s1r1us.ninja/CTF/site-isolation

2024-07-02 13:04
gist.github.com

https://gist.github.com/parrot409/09688d0bb81acbe8cd1a10cfdaa59e45

No category
2024-07-02 13:04
github.blog

https://github.blog/security/vulnerability-research/mtls-when-certificate-authentication-is-done-wrong/

No category
2024-07-02 13:04
onlydev.tistory.com

https://onlydev.tistory.com/157

No category
2024-07-02 13:04
auth0.com

https://auth0.com/blog/preventing-https-downgrade-attacks/

No category
2024-07-02 13:03
projectdiscovery.io

https://projectdiscovery.io/blog/nuclei-interactsh-integration

No category
2024-07-02 13:01
github.com

https://github.com/corelan/mona/blob/master/mona.py

No category
2024-07-02 13:01
github.com

https://github.com/jas502n/cve-2019-2618

2024-07-02 13:01
huntr.com

https://huntr.com/bounties/1eef5a72-f6ab-4f61-b31d-fc66f5b4b467

No category
2024-07-02 13:01
matan-h.com

https://matan-h.com/one-lfi-bypass-to-rule-them-all-using-base64/

No category
2024-07-02 13:01
portswigger.net

https://portswigger.net/web-security/cross-site-scripting/contexts/lab-html-context-with-most-tags-and-attributes-blocked

2024-07-02 13:01
portswigger.net

https://portswigger.net/research/exploiting-xss-in-hidden-inputs-and-meta-tags

2024-07-02 13:01
sakurity.com

https://sakurity.com/blog/2015/03/15/authy_bypass.html

No category
2024-07-02 13:01
securitytrails.com

https://securitytrails.com/blog/jarm-fingerprinting-tool

No category
2024-07-02 13:01
www.youtube.com

https://www.youtube.com/watch?v=skbKjO8ahCI

No category
2024-07-02 13:01
projectdiscovery.io

https://projectdiscovery.io/blog/moveit-transfer-sql-injection

2024-07-02 13:00
devco.re

https://devco.re/blog/2023/07/07/a-journey-into-hacking-google-search-appliance-en/

No category
2024-07-02 13:00
www.embeeresearch.io

https://www.embeeresearch.io/shodan-censys-queries/

2024-07-02 13:00
www.wiz.io

https://www.wiz.io/blog/pyloose-first-python-based-fileless-attack-on-cloud-workloads

No category
2024-07-02 13:00
mohemiv.com

https://mohemiv.com/all/exploiting-xxe-with-local-dtd-files/

No category
2024-07-02 12:57
www.rcesecurity.com

https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/

2024-07-02 12:57