๐๏ธ cURL stopped HackerOne bug bounty program due to excessive slop reports
๐ https://github.com/curl/curl/pull/20312
@appsecfeed.bsky.social
โ ๏ธ Bot Account โ ๏ธ Follow for my hand-curated application security feed. Contains multiple newsletters, blogs, HackerNews feeds, and more. ๐ฌ Run by @alp1n3.dev. Reach out with any suggestions for improvement!
๐๏ธ cURL stopped HackerOne bug bounty program due to excessive slop reports
๐ https://github.com/curl/curl/pull/20312
๐๏ธ How we mitigated a vulnerability in Cloudflareโs ACME validation logic
๐ https://blog.cloudflare.com/acme-path-vulnerability/
๐๏ธ OWASP PTK add-on for ZAP is now released
๐ https://www.zaproxy.org/blog/2026-01-19-owasp-ptk-add-on/
๐๏ธ Research Worth Reading Week 03/2026
๐ https://pentesterlab.com/blog/research-worth-reading-week03-2026
๐๏ธ Scaling developer content production at Snyk
๐ https://developerrelations.com/case-studies/snyk-content-scaling/
๐๏ธ CVEFinder โ Fast CVE lookup with product-level mapping
๐ https://news.ycombinator.com/item?id=46676994
๐๏ธ CVE-2026-0915: GNU C Library Fixes a Security Issue Present Since 1996
๐ https://www.phoronix.com/news/Glibc-Security-Fix-For-1996-Bug
๐๏ธ Crypto holder loses $283 million to scammer impersonating wallet support
๐ https://web3isgoinggreat.com/single/trezor-support-scam
๐๏ธ ๐๏ธ Vulnerable U | #151
๐ https://www.vulnu.com/p/vulnerable-u-151
๐๏ธ New Vulnerability in n8n โ CVE-2026-21858
๐ https://www.schneier.com/blog/archives/2026/01/new-vulnerability-in-n8n.html
๐๏ธ Analysis of ServiceNow's AI Vulnerability (85% of Fortune 500 Affected)
๐ https://opena2a.org/blogs/servicenow-ai-vulnerability
๐๏ธ WinBoat: Drive by Client RCE and Sandbox Escape
๐ https://hack.do/posts/winboat-guest-service-host-rce/
๐๏ธ StackWarp Vulnerability
๐ https://stackwarpattack.com/
๐๏ธ Last Week in AppSec for 15. January 2026
๐ https://checkmarx.com/zero-post/last-week-in-appsec-for-15-january-2026/
๐๏ธ [tl;dr sec] #311 - Slack's Security Agents, Cloud-Native Detection Engineering, Trail of Bits' Claude Skills
๐ https://tldrsec.com/p/tldr-sec-311
๐๏ธ Building the Talent Engine Behind TRM's Mission to Protect Billions | TRM Blog
๐ https://www.trmlabs.com/resources/blog/building-the-talent-engine-behind-trms-mission-to-protect-billions
๐๏ธ Community-powered security with AI: an open source framework for security research
๐ https://github.blog/security/community-powered-security-with-ai-an-open-source-framework-for-security-research/
๐๏ธ Curl to end Bug Bounty program due to overwhelming number of AI submissions
๐ https://github.com/curl/curl-www/pull/538
๐๏ธ Determinate Secure Packages: Nixpkgs with SBOMs, FIPS, and SLA'd CVE Patching
๐ https://determinate.systems/blog/determinate-secure-packages/
๐๏ธ $250K+ XSS in Meta Conversion API Leading to Zero-Click Account Takeover
๐ https://ysamm.com/uncategorized/2025/01/13/capig-xss.html
๐๏ธ DoS Vulnerability in Node.js for React, Next.js, and APM Users
๐ https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks
๐๏ธ Stop trusting torch.load() โ I built a tool to scan AI models for RCE
๐ https://github.com/ArseniiBrazhnyk/Veritensor
๐๏ธ Blacksmith โ AI Powered Penetration Testing
๐ https://github.com/yohannesgk/blacksmith
๐๏ธ Former NYC Mayor Eric Adams accused of rug pull as NYC Token crashes
๐ https://web3isgoinggreat.com/single/nyc-token-crash
๐๏ธ Building the Talent Engine Behind TRM's Mission to Protect Billions | TRM Blog
๐ https://www.trmlabs.com/resources/blog/building-the-talent-engine-behind-trms-mission-to-protect-billions
๐๏ธ Exploiting LLM Write Primitives: System Prompt Extraction When Chat Output Is Locked Down
๐ https://www.praetorian.com/blog/exploiting-llm-write-primitives-system-prompt-extraction-when-chat-output-is-locked-down/
๐๏ธ Mitigating DoS Vulnerability from Unrecoverable Stack Space Exhaustion
๐ https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks
๐๏ธ Claude Code CVE-2025-66032: Why Allowlists Aren't Enough
๐ https://niyikiza.com/posts/cve-2025-66032/
๐๏ธ Tackling Technical Debt before It Owns Your Roadmap
๐ https://www.netspi.com/blog/executive-blog/ciso-perspectives/tackling-technical-debt-before-it-owns-your-roadmap/
๐๏ธ Sift or Get Off the PoC: Vulnerability Research via Information Retrieval
๐ https://arxiv.org/abs/2512.06155