REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'Rocket.Chat'
disclosed a bug submitted by
b'button142857'
b"Unauthenticated SSRF in Voxtelesys integration ('checkUrlForSsrf' Bypass via DNS rebinding)"
29 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'Sandbox User Can Inject Rogue CA Certificate into OS Trust Store via Sudo-Allowed deploy-certificates.sh'
28 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'nick_frichette_dd'
b'Non-Production API Endpoints for the Amazon Cloudwatch Fails to Log to CloudTrail Resulting in Silent Permission Enumeration'
27 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'0jayden'
b'Authentication Bypass via XML Signature Wrapping in SAML SSO'
27 Jul 2026
b'Monero'
disclosed a bug submitted by
b'redlobsterzzz'
b'ZMQ RPC Log Injection and Untrusted Payload Persistence'
24 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'notnotnotveg'
b'AWS *.a2z.com | Unauthenticated Clickhouse UI : Database access + SSRF'
22 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'GitHub user to server tokens can create issues in any public repository'
22 Jul 2026
b'8x8'
disclosed a bug submitted by
b'kyotozzx'
b'connect.8x8.com/api/v1: JWT Algorithm Confusion Vulnerability'
22 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'ahacker1'
b'OAuth redirect uri validation bypass for :proxima_first_party_sync apps'
21 Jul 2026
b'Monero'
disclosed a bug submitted by
b'int0ha_'
b'Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes'
20 Jul 2026
b'Rocket.Chat'
disclosed a bug submitted by
b'olidayw'
b'Stored XSS in Rocket.Chat HTML File Export Unauthenticated Entry via LiveChat'
16 Jul 2026
b'GitHub'
disclosed a bug submitted by
b'vaib25vicky'
b'Able to bypass authorization logic and gain more access then intended'
15 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'Bedrock AgentCore Starter Toolkit Creates Gateway IAM Roles Without Confused Deputy Protections'
15 Jul 2026
b'Basecamp'
disclosed a bug submitted by
b'newbiefromcoma'
b'Stored XSS on Trix Editor version latest (2.1.16) - Sanitizer Bypass '
14 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'bedrock-mantle.api.aws accepts Bedrock API keys outside the IAM Deny, CloudTrail signal, and invocation logging AWS publishes for Bedrock keys'
14 Jul 2026
b'SingleStore'
disclosed a bug submitted by
b'bisht-ji'
b'SELECT ... INTO OUTFILE does not enforce the FILE WRITE privilege unprivileged arbitrary file write on the server'
13 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'mistercloudsec'
b'Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)'
09 Jul 2026
b'AWS VDP'
disclosed a bug submitted by
b'kaporia'
b'OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)'
06 Jul 2026
b'Basecamp'
disclosed a bug submitted by
b'zerodaysec_xyz'
b'Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity'
04 Jul 2026
1
2
3
...
770
BY DENIS WERNER - @NOBBD -
IMPRESSUM