Loading…

Whats The Hax?

Daily intelligence on threats, breaches, and defenders

What's New

Top 5 Across All Sources
  1. What syscall-layer tooling cannot see in P2P infrastructure

    Technical Information Security Content & Discussion · 8d ago
  2. Announcing the External Penetration Testing Program Pack

    Technical Information Security Content & Discussion · 8d ago
  3. The way AI voice phishing gets demonstrated is making people worse at spotting it

    Technical Information Security Content & Discussion · 9d ago
  4. Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

    Technical Information Security Content & Discussion · 9d ago
  5. XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search

    Technical Information Security Content & Discussion · 9d ago
Latest
Technical Information Security Content & DiscussionWhat syscall-layer tooling cannot see in P2P infrastructureTechnical Information Security Content & DiscussionAnnouncing the External Penetration Testing Program PackTechnical Information Security Content & DiscussionThe way AI voice phishing gets demonstrated is making people worse at spotting itTechnical Information Security Content & DiscussionEscaping Claude Cowork’s local VM sandbox via CVE-2026-46331Technical Information Security Content & DiscussionXBOW Agents found three RCEs as SYSTEM (and root) on Bing Image SearchTechnical Information Security Content & DiscussionThailand's Ministry of Finance targeted with an AI agent running with approval prompts disabledTechnical Information Security Content & DiscussionOpen Evaluation Framework for AI Pentesting Agents on Real-World TargetsTechnical Information Security Content & DiscussionDevice Code Phishing: The Microsoft 365 Attack That Walks Past MFATechnical Information Security Content & DiscussionGitHub issues $100,000 bounty for critical RCE vulnerabilityTechnical Information Security Content & DiscussionCVE-2026-50458: Finding a UAF in the Windows Brokering File SystemTechnical Information Security Content & DiscussionI was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)Technical Information Security Content & DiscussionThe Hidden CCS2 Attack Surface on EV ChargersTechnical Information Security Content & DiscussionWriteup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)Technical Information Security Content & DiscussionLeaking internal headers in Flask Ninja with deserializationTechnical Information Security Content & DiscussionCrawling the Complete IPv4 Reverse DNS SpaceTechnical Information Security Content & DiscussionEscalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)Technical Information Security Content & DiscussionExploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25Technical Information Security Content & DiscussionMultiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverableTechnical Information Security Content & Discussionwp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source ScannerTechnical Information Security Content & DiscussionPixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys DowningTechnical Information Security Content & DiscussionWhat syscall-layer tooling cannot see in P2P infrastructureTechnical Information Security Content & DiscussionAnnouncing the External Penetration Testing Program PackTechnical Information Security Content & DiscussionThe way AI voice phishing gets demonstrated is making people worse at spotting itTechnical Information Security Content & DiscussionEscaping Claude Cowork’s local VM sandbox via CVE-2026-46331Technical Information Security Content & DiscussionXBOW Agents found three RCEs as SYSTEM (and root) on Bing Image SearchTechnical Information Security Content & DiscussionThailand's Ministry of Finance targeted with an AI agent running with approval prompts disabledTechnical Information Security Content & DiscussionOpen Evaluation Framework for AI Pentesting Agents on Real-World TargetsTechnical Information Security Content & DiscussionDevice Code Phishing: The Microsoft 365 Attack That Walks Past MFATechnical Information Security Content & DiscussionGitHub issues $100,000 bounty for critical RCE vulnerabilityTechnical Information Security Content & DiscussionCVE-2026-50458: Finding a UAF in the Windows Brokering File SystemTechnical Information Security Content & DiscussionI was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)Technical Information Security Content & DiscussionThe Hidden CCS2 Attack Surface on EV ChargersTechnical Information Security Content & DiscussionWriteup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)Technical Information Security Content & DiscussionLeaking internal headers in Flask Ninja with deserializationTechnical Information Security Content & DiscussionCrawling the Complete IPv4 Reverse DNS SpaceTechnical Information Security Content & DiscussionEscalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)Technical Information Security Content & DiscussionExploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25Technical Information Security Content & DiscussionMultiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverableTechnical Information Security Content & Discussionwp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source ScannerTechnical Information Security Content & DiscussionPixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing

By Source

Feeds organized so you can skim by site.

Density Sort
What syscall-layer tooling cannot see in P2P infrastructure 8d ago Announcing the External Penetration Testing Program Pack 8d ago The way AI voice phishing gets demonstrated is making people worse at spotting it 9d ago Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 9d ago XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search 9d ago Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled 9d ago Open Evaluation Framework for AI Pentesting Agents on Real-World Targets 10d ago Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA 10d ago GitHub issues $100,000 bounty for critical RCE vulnerability 10d ago CVE-2026-50458: Finding a UAF in the Windows Brokering File System 10d ago
318 loaded
CY
cybersecurity
51d ago · 1867 items
Any solutions we can use? 51d ago Possible targeted attack 51d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline 51d ago Facebook messenger to text 51d ago Managing Solution Agents 52d ago Nottingham University data breach affects over 450,000 students 52d ago SWGs that support 3rd party external DNS resolver 52d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers 52d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG 52d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch 52d ago
1867 loaded
HS
hacking: security in practice
51d ago · 241 items
DIY pwnagotchi-like device on esp32 51d ago Flipper Blackhat + Bjorn 52d ago Do you think AI is making hacking easier or harder 52d ago What can i do left? PSN 52d ago Proxmark5 campaign ending in less than 18 hours. 52d ago How to bypass speed queen coin slot for washer and dryer 52d ago Self-hosting stuff for when things get ugly 52d ago Malware Includes Taboo In Text To Prevent LLM Analysis 52d ago added Mac support for my corporate hacking game, demo on Steam 52d ago Catfished 52d ago
241 loaded
RE
Reverse Engineering
51d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it 51d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) 51d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) 51d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game 52d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened 52d ago Drive Firmware Security - Phison S11 52d ago IDA 9.4 Beta | Hex-Rays Docs 52d ago Trane Tracer HVAC cybersecurity issues 53d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) 53d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. 53d ago
181 loaded
US charges suspected Russian hacker with facilitating cyber campaign 51d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia 52d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 52d ago GreatXML: GreatXML bitlocker bypass vulnerability 52d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan 52d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue 52d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion 52d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default 52d ago Miasma-style supply chain attacks 52d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet 52d ago
603 loaded
MA
Malware Analysis & Reports
52d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened 52d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper 52d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap 53d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace 53d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment 54d ago 73 Microsoft GitHub repositories impacted by Miasma malware 55d ago Unauthorized Onlyfans Payment 55d ago Building A Malware Lab From Scratch Part 2! 57d ago Detecting npm Native Addon Malware: node-gyp Abuse 57d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links 58d ago
115 loaded

No matching sources found.