Category: Mix

Discovering Negative-Days with LLM Workflows
07
Feb
2026

Discovering Negative-Days with LLM Workflows

By now, you may have Anthropic’s zero-days blogpost where an “out-of-the-box” Claude Opus 4.6 workflow was used to find 500…

[tl;dr sec] #311 - Slack's Security Agents, Cloud-Native Detection Engineering, Trail of Bits' Claude Skills
05
Feb
2026

[tl;dr sec] #314 – ClawdBot Security, Security Scorecards, Threat Framework for SDLC Infrastructure

I hope you’ve been doing well! ClawdBot Security Well… what an exciting week to be in security   ClawdBot Moltbot OpenClaw…

global bug bounty adoption accelerates, led by the U.S.
05
Feb
2026

global bug bounty adoption accelerates, led by the U.S.

Bug bounty programs have evolved from a niche security tactic into a core component of modern defense strategies worldwide. In this blog, we focus…

Introducing Detectify Internal Scanning for internal vulnerability scanning behind the firewall
03
Feb
2026

Introducing Detectify Internal Scanning for internal vulnerability scanning behind the firewall

TL;DR We’re launching Internal Scanning, bringing our proprietary security engines, research-led crawling and fuzzing engine for internal vulnerability scanning behind…

OpenSSL Profile
02
Feb
2026

Ticket Tricking OpenSSL.org with Google Groups

Over the holidays, I found some time to work on a small idea I had for a while. As a…

02
Feb
2026

InsertScript: SiteKiosk – Breakout

SiteKiosk – Breakout It has been a while since my last blog post, therefore I am going to share two…

InsertScript: Multiple PDF Vulnerabilities - Text and Pictures on Steroids
02
Feb
2026

InsertScript: Multiple PDF Vulnerabilities – Text and Pictures on Steroids

/*UPDATE */ @irsdl brought two import links to my attention: 2010 formcalc: http://t.co/6OfGLa9Cu1 2013 XXE + SOP Bypass: http://t.co/VZMSVg3HtN It seems like Adobe…

02
Feb
2026

InsertScript: MHTML: x-usc – A feature from the past

What is mhtml ? For those who have never saved a complete web page in Internet Explorer, mhtml or its…

InsertScript: PDF - How to steal PDFs by injecting JavaScript
02
Feb
2026

InsertScript: PDF – How to steal PDFs by injecting JavaScript

Intro Quite some time has passed since my last blog post, so I decided to present a nice feature of…

DLL Hijacking via URL files
02
Feb
2026

DLL Hijacking via URL files

This blogpost describes how I got annoyed by vulnerabilities in 3rd party Windows applications, which allowed to execute local files…

InsertScript: Adobe Reader - PDF callback via XSLT stylesheet in XFA
02
Feb
2026

InsertScript: Adobe Reader – PDF callback via XSLT stylesheet in XFA

I have seen on twitter that there is use for another PDF callback Proof-of-Concept in Adobe Reader. Last year a…

InsertScript: Libreoffice (CVE-2018-16858) - Remote Code Execution via Macro/Event execution
02
Feb
2026

InsertScript: Libreoffice (CVE-2018-16858) – Remote Code Execution via Macro/Event execution

I started to have a look at Libreoffice and discovered a way to achieve remote code execution as soon as…