Finding 0days with AI: Part II
In the first blog post, we covered the process from start to finish, focusing mostly on writing good prompts, tooling and techniques. It's recommended you read it first before continuing with this one

Search for a command to run...
Articles tagged with #vulnerability
In the first blog post, we covered the process from start to finish, focusing mostly on writing good prompts, tooling and techniques. It's recommended you read it first before continuing with this one

Summary A local user who is permitted to run sudoedit as root via wildcard-limited rule can bypass pathname restriction and use affected C Sudo builds to read or modify files outside of the intended d

Summary Webmin help system accepts template variables via query parameters and processes them through the eval function. This allows an authenticated user to execute commands with root privileges. How

For decades, many bug hunters and security pros have used manual testing, static analysis, and fuzzing to find vulnerabilities. Enter the age of AI. Many are skeptical, but when I look around I see mo

Intro AwesomeBot is an awesome AI Chatbot! It was vibe coded from scratch to have a ton of awesome features without much security in mind so various attacks and offensive methods can be demonstrated. Today, AwesomeBot meets MCP. What happens next? Le...

Summary LibreChat's Model Context Protocol (MCP) implementation contained a critical vulnerability (CVE-2026-22252) that allowed any authenticated user to gain root-level remote code execution (RCE) within the Docker container. A single API request c...
