Cybersecurity Engineer | OSCP | CRTO I do offensive cybersecurity content, maybe not the best, but it's free :) #infosec #cybersecurity #hacking You can find me at https://www.kayssel.com/
Automated Cybersecurity News Feed • CVE alerts & vulnerability disclosures • Bug bounty program updates • Threat intelligence & APT tracking • Zero-day exploit notifications Powered by AI | Curated for security professionals
Cybersecurity Engineer | OSCP | CRTO I do offensive cybersecurity content, maybe not the best, but it's free :) #infosec #cybersecurity #hacking You can find me at https://www.kayssel.com/
Bot publikujący najnowsze wiadomości sekurak.pl
https://sekurak.pl Account by @kkrenski
Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk
Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. 🤦
What I found:
- Email disclosure via XMPP (username→email)
- Auth bypass (email→account takeover, no password)
History of ignoring researchers:
- 2017: First recorded case of someone reporting XMPP email leak.
- 2022: Someone else reports XMPP email leak, ignored
- Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
- 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
- March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
- Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
- July 28: I go public
- July 30: Both fixed in 48 hours
Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.
News covered it but my blog has the full technical details: https://bobdahacker.com/blog/lovense-still-leaking-user-emails/
#InfoSec #BugBounty #ResponsibleDisclosure #Security #Vulnerability #IoT #cybersecurity
Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Hier geht es um Cybersecurity – aktuell, kompakt und fachlich. # Sicherheitslücken & #Cyberangriffe #KI & #Security #Ransomware, #Phishing & #Threats Identity, Access & #Netzwerksicherheit Fachartikel & Video-Podcasts Wir teilen aktuelle Entwicklungen und relevantes Security-Wissen für alle, die IT-Sicherheit im Blick behalten müssen. Gebt uns Feedback! Schreibt, kommentiert, widersprecht! Eure Sicht interessiert uns.
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Automated Cybersecurity News Feed • CVE alerts & vulnerability disclosures • Bug bounty program updates • Threat intelligence & APT tracking • Zero-day exploit notifications Powered by AI | Curated for security professionals
Top stories from Hacker News See old posts. I am a bot that mirrors an RSS feed. Source: https://news.ycombinator.com/rss
Automated Cybersecurity News Feed • CVE alerts & vulnerability disclosures • Bug bounty program updates • Threat intelligence & APT tracking • Zero-day exploit notifications Powered by AI | Curated for security professionals
Cybersecurity Engineer | OSCP | CRTO I do offensive cybersecurity content, maybe not the best, but it's free :) #infosec #cybersecurity #hacking You can find me at https://www.kayssel.com/
Automated Cybersecurity News Feed • CVE alerts & vulnerability disclosures • Bug bounty program updates • Threat intelligence & APT tracking • Zero-day exploit notifications Powered by AI | Curated for security professionals