Application Security Feed's Avatar

Application Security Feed

@appsecfeed.bsky.social

โš ๏ธ Bot Account โš ๏ธ Follow for my hand-curated application security feed. Contains multiple newsletters, blogs, HackerNews feeds, and more. ๐Ÿ’ฌ Run by @alp1n3.dev. Reach out with any suggestions for improvement!

44 Followers  |  1 Following  |  288 Posts  |  Joined: 07.05.2025  |  1.4233

Latest posts by appsecfeed.bsky.social on Bluesky

๐Ÿ—ž๏ธ cURL stopped HackerOne bug bounty program due to excessive slop reports

๐Ÿ”— https://github.com/curl/curl/pull/20312

20.01.2026 12:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ How we mitigated a vulnerability in Cloudflareโ€™s ACME validation logic

๐Ÿ”— https://blog.cloudflare.com/acme-path-vulnerability/

20.01.2026 12:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ OWASP PTK add-on for ZAP is now released

๐Ÿ”— https://www.zaproxy.org/blog/2026-01-19-owasp-ptk-add-on/

20.01.2026 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Research Worth Reading Week 03/2026

๐Ÿ”— https://pentesterlab.com/blog/research-worth-reading-week03-2026

19.01.2026 12:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Scaling developer content production at Snyk

๐Ÿ”— https://developerrelations.com/case-studies/snyk-content-scaling/

19.01.2026 12:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ CVEFinder โ€“ Fast CVE lookup with product-level mapping

๐Ÿ”— https://news.ycombinator.com/item?id=46676994

19.01.2026 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ CVE-2026-0915: GNU C Library Fixes a Security Issue Present Since 1996

๐Ÿ”— https://www.phoronix.com/news/Glibc-Security-Fix-For-1996-Bug

18.01.2026 12:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Crypto holder loses $283 million to scammer impersonating wallet support

๐Ÿ”— https://web3isgoinggreat.com/single/trezor-support-scam

18.01.2026 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ ๐ŸŽ“๏ธ Vulnerable U | #151

๐Ÿ”— https://www.vulnu.com/p/vulnerable-u-151

17.01.2026 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ New Vulnerability in n8n โ€“ CVE-2026-21858

๐Ÿ”— https://www.schneier.com/blog/archives/2026/01/new-vulnerability-in-n8n.html

16.01.2026 12:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Analysis of ServiceNow's AI Vulnerability (85% of Fortune 500 Affected)

๐Ÿ”— https://opena2a.org/blogs/servicenow-ai-vulnerability

16.01.2026 12:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ WinBoat: Drive by Client RCE and Sandbox Escape

๐Ÿ”— https://hack.do/posts/winboat-guest-service-host-rce/

16.01.2026 12:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ StackWarp Vulnerability

๐Ÿ”— https://stackwarpattack.com/

16.01.2026 12:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Last Week in AppSec for 15. January 2026

๐Ÿ”— https://checkmarx.com/zero-post/last-week-in-appsec-for-15-january-2026/

16.01.2026 12:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ [tl;dr sec] #311 - Slack's Security Agents, Cloud-Native Detection Engineering, Trail of Bits' Claude Skills

๐Ÿ”— https://tldrsec.com/p/tldr-sec-311

16.01.2026 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Building the Talent Engine Behind TRM's Mission to Protect Billions | TRM Blog

๐Ÿ”— https://www.trmlabs.com/resources/blog/building-the-talent-engine-behind-trms-mission-to-protect-billions

15.01.2026 14:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Community-powered security with AI: an open source framework for security research

๐Ÿ”— https://github.blog/security/community-powered-security-with-ai-an-open-source-framework-for-security-research/

15.01.2026 14:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Curl to end Bug Bounty program due to overwhelming number of AI submissions

๐Ÿ”— https://github.com/curl/curl-www/pull/538

15.01.2026 14:15 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Determinate Secure Packages: Nixpkgs with SBOMs, FIPS, and SLA'd CVE Patching

๐Ÿ”— https://determinate.systems/blog/determinate-secure-packages/

15.01.2026 14:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ $250K+ XSS in Meta Conversion API Leading to Zero-Click Account Takeover

๐Ÿ”— https://ysamm.com/uncategorized/2025/01/13/capig-xss.html

15.01.2026 14:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ DoS Vulnerability in Node.js for React, Next.js, and APM Users

๐Ÿ”— https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks

15.01.2026 14:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Stop trusting torch.load() โ€“ I built a tool to scan AI models for RCE

๐Ÿ”— https://github.com/ArseniiBrazhnyk/Veritensor

15.01.2026 14:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Blacksmith โ€“ AI Powered Penetration Testing

๐Ÿ”— https://github.com/yohannesgk/blacksmith

15.01.2026 14:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Former NYC Mayor Eric Adams accused of rug pull as NYC Token crashes

๐Ÿ”— https://web3isgoinggreat.com/single/nyc-token-crash

14.01.2026 12:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Building the Talent Engine Behind TRM's Mission to Protect Billions | TRM Blog

๐Ÿ”— https://www.trmlabs.com/resources/blog/building-the-talent-engine-behind-trms-mission-to-protect-billions

14.01.2026 12:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Exploiting LLM Write Primitives: System Prompt Extraction When Chat Output Is Locked Down

๐Ÿ”— https://www.praetorian.com/blog/exploiting-llm-write-primitives-system-prompt-extraction-when-chat-output-is-locked-down/

14.01.2026 12:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Mitigating DoS Vulnerability from Unrecoverable Stack Space Exhaustion

๐Ÿ”— https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks

14.01.2026 12:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Claude Code CVE-2025-66032: Why Allowlists Aren't Enough

๐Ÿ”— https://niyikiza.com/posts/cve-2025-66032/

14.01.2026 12:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Tackling Technical Debt before It Owns Your Roadmap

๐Ÿ”— https://www.netspi.com/blog/executive-blog/ciso-perspectives/tackling-technical-debt-before-it-owns-your-roadmap/

13.01.2026 12:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ—ž๏ธ Sift or Get Off the PoC: Vulnerability Research via Information Retrieval

๐Ÿ”— https://arxiv.org/abs/2512.06155

13.01.2026 12:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@appsecfeed is following 1 prominent accounts