All Updates
Saturday, October 3, 2026 · Bug Bounty news feed snapshots · with LLM summaries
Sat, October 3
Fri, October 2

How could OpenAI be hacked with a vulnerability that had already been fixed for a year? Follow the dependency chain from Discourse through ImageMagick, libheif, and Debian to see why security fixes can take so long to reach the applications that depend on them. SPONSOR This video is sponsored by Hextree.io, our cybersecurity learning platform. Join the Hextree Discord: https://discord.gg/xgQpCQCpvy RESOURCES Previous video, How OpenAI got hacked with an image: https://www.youtube.com/watch?v=gjHh9g7yo9Y Harsh on X: https://x.com/rootxharsh xkcd, Dependency: https://xkcd.com/2347/ Per video:…
Thu, October 1
Episode 194: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph cover Faav’s Microsoft hack, Salesforce adjusting their scope, and if/how Jev can be used for Bug Bounty Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: [email protected] Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x
Wed, September 30
OpenAI just doubled the price of the plan we all rely on, and the others will follow. This week: what the Codex price hike means, where I think bug bounty is heading as models get expensive, and why I started vlogging my weeks.
Tue, September 29
Part 1 of this week's saga can be found here. This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the  watchTowr Platform. What Is A Citrix NetScaler? NetScaler, from Citrix (now under Cloud
In the summer of 2026, Intigriti celebrated a major milestone: its 10th anniversary! To mark the occasion, the team came together from around the globe. This article shares what they had to say about a decade of Intigriti! A note from CEO and Founder, Stijn Jans What 10 years of evolution looks like Intigriti’s journey shows how a bold idea evolved into a global cybersecurity company combining innovation, strategic investment, and a deeply rooted hacker-first culture. For ove
Mon, September 28

Local AI for Offensive Security: Models, Harnesses & Human Judgment Hamid from XBOW ended our last episode with a wish for better local models. So we invited Thomas Olofsson, aka Skjortan, to tell us what he can already do with them. Thomas brings his own models into sensitive client environments and uses them to help find, verify and reproduce vulnerabilities without sending the client’s data to a cloud model. Together with STÖK and KUGG, he gets into the hardware, the specialist agents and the skills that make smaller models useful for real penetration tests. The conversation goes beyond…

📚 Learn bug bounty hunting from me: https://bugbounty.nahamsec.training 💻 Practice some of my free labs and challenges: https://app.hackinghub.io If I Started Bug Bounty Hunting in 2024, I'd Do this - https://youtu.be/z6O6McIDYhU 2023 How to Bug Bounty - https://youtu.be/FDeuOhE5MhU Bug Bounty Hunting Full Time - https://youtu.be/watch?v=ukb79vAgRiY Hacking An Online Casino - https://youtu.be/watch?v=2eIDxVrk4a8 WebApp Pentesting/Hacking Roadmap - https://youtu.be/watch?v=doFo0I_KU0o 🌍 My website - https://www.nahamsec.com/ 👨💻 My free labs - https://app.hackinghub.io/ 🐦 Twitter - htt…
God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up
Sun, September 27
Sat, September 26
Fri, September 25
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month's issue, we'll be featuring: Compromising OpenAI, Slack, Meta, and more via a vulnerable image library Hacking OpenAI employee accounts in under 72 hours Breaking into Google's GFile for $100K Hacking AI CX agents Turbo Intruder 2 surpassing 100K requests per second over HTTP/3 And so much more! Let's dive in! Reconnaissance unleashed: meet CrowdRecon CrowdRecon is officially here! CrowdRecon brings crowd-l