Beyond CVSS: rethinking scoring systems amidst AI Safety and Security
CVSS no fue diseñado para bugs de sistemas de IA. El artículo discute por qué la escala se rompe y qué alternativas hay sobre la mesa.
Archive
Every entry was verified against its original source. Bounty amounts appear only when they are public — never estimated.
35 of 35 writeups
CVSS no fue diseñado para bugs de sistemas de IA. El artículo discute por qué la escala se rompe y qué alternativas hay sobre la mesa.
CSS sanitizado en clientes de webmail resulta suficiente para exfiltrar tokens con attribute selectors, spoofear UI y montar un keylogger sin una línea de JavaScript. Afecta a Gmail, Outlook, Fastmail y ProtonMail.
Adobe empowers everyone to create through industry-leading platforms and tools that unleash creativity, productivity, and personalized customer experiences. Starting September 1, 2026, Intigriti will be the new home of the Adobe Bug Bounty Program. Why Intigriti and Adobe? As AI reshapes how organizations build and ship products, security testing needs to keep pace. Intigriti's global community of
Qué hacer cuando un reporte válido se cierra como N/A o duplicado. Proceso concreto, no consejos genéricos.
Key takeaways RAG systems expand the application’s trust boundary by adding external, mutable content to the model context. If a threat actor can influence what gets indexed and retrieved, they can influence what the model says or does. In simple QA systems, that may mean misinformation or unsafe recommendations. In agentic systems with tools and permissions, it can become data leakage, un
The lethal trifecta matters more now than ever because AI tools can read your data, absorb instructions, and act on your behalf. That means a poisoned email, webpage, or document could trick your AI into leaking information or taking actions you never approved. The more AI becomes your assistant, the more its access, permissions, and actions need guardrails. This blog takes a look at the lethal
Cómo se sostiene un ritmo de 750+ bugs en un año. Entrevista con Ads Dawson sobre proceso y automatización.
Most breaches don't begin with a zero-day but with something ordinary like a forgotten server, an unmanaged network device, a service reachable across a segment that was supposed to be isolated. Internal scanning was supposed to catch exactly that but most scanners match a host's banner and version against a CVE list and flag everything potentially affected, so the few reachable exposures sit lost
What you will learn Why faster discovery and higher volume can still leave teams blind between vulnerability reports. Why scanners and inventories are necessary, but not enough to explain attacker focus and intent. What “between-reports visibility” actually means (without the product pitch). What we believe security teams will need next: earlier signals that support action before the next repor
“Open source isn’t about perfection; it’s about putting an idea forward and improving it together as a community.” Rishi (@rxerium) If you’ve spent any time in the Nuclei Templates repository, you’ve almost certainly run something Rishi engineered. With over 500 templates merged, picked up by the likes of the UK’s National Cyber Security Center (NCSC), California Cybersecurity Integration Cente
Over the last few weeks, we’ve explored what AI is changing in security: discovery is faster (Vulnpocalypse now?), volume is higher (Common AI misconceptions debugged!), and the human layer triage (The AI Impact), judgment, and prioritization has become more important, not less (CEO Insights). But there’s a deeper implication hiding underneath all of that: most security teams still only learn from
El ranking anual de la comunidad. Punto de partida obligado para entender qué técnicas movieron la aguja el año pasado.
La superficie WebSocket queda casi sin testear en la mayoría de los programas. Esta herramienta la vuelve accesible.
Lectura obligada antes de reportar un smuggling: la mayoría de los falsos positivos vienen de confundir pipelining con desync.
Un flujo de expense report que renderiza PDF del lado del servidor termina en SSRF. Clásico del género y todavía vigente como patrón.