[CVE-2026-48731] AI-Assisted Discovery of Command Injection in Warp TerminalDisclosure status: Reported to vendor and coordinated through a private fix path. I. Introduction Warp is an agentic development environment, born out of the terminal. Use Warp's built-in coding agentJun 8, 2026·7 min read
AI-Assisted on RASP AnalysisI. Introduction Disclaimer: This blog does not cover bypassing BShield. It is simply a summary of how I used AI as a tool to assist with analysis, debugging, environment setup, and attempting to reverMay 29, 2026·16 min read
Reasoning-First vulnerability research: How I built an AI Agent that found multiples bugs in Open Source project Subtitle: A practical look at building an AI-assisted vulnerability research workflow that reasons through code, traces trust boundaries, and helps discover real security issues responsibly on multiplMay 27, 2026·11 min read
AI-Powered Vulnerability Hunting in WordPress Plugins/Themes<7 days spare time 100 plugins scanned 524 candidate findings 16 confirmed vulns 5 scanner patches This is not a vulnerability disclosure. It's a methodology. I want to share how to build an AI pipMay 26, 2026·17 min read
Firmware Emulation With an Automated Skill SetFirmware Emulation With an Automated Skill Set tags: firmware, emulation, qemu, reverse-engineering, cybersecurity Khoa Hoang Anh, May 25, 2026 Link repo: https://github.com/9wteam/firmware-emulation-May 26, 2026·20 min read
From Privilege Escalation to RCE in Wiki.jsA tale of privilege escalation, command injection, and the humbling art of responsible disclosureMay 21, 2026·11 min read
AI-Assisted Discovery of SQL Injection & Stored XSS in Cacti Network MonitorDisclosure status: Both vulnerabilities reported to vendor on 2026-05-13 via GitHub Pull Request. Author: Nguyen Cong Tu (iaohkut) Published: May 2026 I. Introduction This post is about a methodologMay 21, 2026·13 min read