[tl;dr sec] #336 – Autonomous Vulnerability Hunting, GuardDog 3.0, Are Bug Bounties Cooked?
Amurrica Day I love how peak America the 4th of July is, with tons of outdoor grilling, people wearing red, white, and blue, and of…
Amurrica Day I love how peak America the 4th of July is, with tons of outdoor grilling, people wearing red, white, and blue, and of…
Fran Hutchings | Thursday, 9 July 2026 at 09:20 UTC PortSwigger is heading to Las Vegas for one of the biggest weeks in the cybersecurity…
Most tools will only test the domains you already know about. We’ve decided that’s not enough. TLDR: Detectify’s new Apex Discovery automatically identifies root domains…
For years, development and security practitioners have treated dynamic application security testing as a critical final safety check before code goes live. However, the external…
A quick thought on this whole “control of AI models” debate. Handguns and Fentanyl are available all over the world, but we still don’t put…
My neighbor texted me the other day and said she’d pre-ordered two AI toys for her kids that supposedly used an LLM to dynamically generate…
Wedding This past weekend I attended a friend’s wedding, and it was heartwarming. The couple have been together over a decade, and had many…
A few weeks ago I wrote about how AI is going to impact bug bounty. That post was mostly predictions. This one is about what’s…
I have been thinking about the downstream impacts of AI systems having strong cybersecurity capabilities. The United States has a lot of critical infrastructure that…
I’ve always been a fan of levelsio. He’s a serial entrepreneur who has launched a bunch of SaaS and AI products, mostly in public, one…
Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!),…
Cookies are one of the most fundamental building blocks of the modern web, and yet they are often overlooked from a security perspective. When misconfigured,…