Ethical Hacking Mission Control
This live lab is a safe space for defenders, red teamers, and curious hackers to sharpen their tradecraft using real tooling and real telemetry. Every article, lab module, and intel briefing is curated to help you practice responsible disclosure, grow your skill set, and support the security community.
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
What Is Agentic Pentesting? What It Proves, and Where It Stops.
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
Bug Bounty Radar
Hand-picked programs with live scope and standout rewards to help you focus your next responsible disclosure run.
FastAPI Cloud
HackerOne • Updated 2024-05-18
Prototype pollution in async workers and GraphQL stitching flaws.
Scope: api.fastapicloud.com, *.fastapicloud.com
Program brief →Supply Chain Monitor
Bugcrowd • Updated 2024-05-22
Dependency confusion, pipeline breakout, and artifact poisoning.
Scope: *.scm.dev, api.scm.dev
Program brief →Secure Notes
Intigriti • Updated 2024-05-17
OAuth misconfigurations, storage isolation, and advanced XSS chains.
Scope: app.securenotes.io, api.securenotes.io
Program brief →OpenTelemetry Hub
YesWeHack • Updated 2024-05-20
Collector escapes, tenant isolation bugs, and SSRF via exporters.
Scope: *.otelhub.dev
Program brief →