Black Lantern Security (BLSOPS)
By analyzing and simulating the most relevant attacks, Black Lantern Security delivers solutions that provide immediate reductions in organizational risk.
Our AI chatbot passed every prompt injection test we threw at it. Then we just asked it nicely for customer data, and it happily obliged.
New from our ASMOC team, how a vibe-coded website with LLM became a high-risk finding on a client's attack surface.
https://blog.blacklanternsecurity.com/p/artificial-foolishness-the-hidden
It's time for the next question of our OSINT insight quest!
Q2: What is the single biggest missing feature you would like to see in BBOT?
Thx for sharing!
Over the next few weeks we're hoping to gain some insight from the novice & veteran users of subdomain enumeration / OSINT tools via polls.
Q1: What's your favorite OSINT tool?
If your favorite isn't listed, post feedback in the comments.
Thx for participating!
🚨CVE-2026-2103: Infor Syteline ERP hard-codes encryption keys in binaries. One copy = universal decryption of ALL passwords, DB creds & API keys across every install. No patch.
#CVE
https://blog.blacklanternsecurity.com/p/cve-2026-2103-infor-syteline-erp
👀 Recon friends, stop guessing your target’s infra.
CloudCheck is LIVE — 56+ providers, daily-updated sigs, Rust/Python/CLI & a FREE REST API.
BBOT now fingerprints cloud / CDN / WAF in milliseconds.
https://blog.blacklanternsecurity.com/p/introducing-cloudcheck-comprehensive
#OSINT #BugBounty #Infosec #ASM
📢New drop in our #ASM series! Shadow IT, rogue subdomains, leaked creds—your attack surface is exploding! Discover the 3 goals for Attack Surface Management: 24/7 discovery, risk-based triage, measurable fixes. Read now 👇 https://blog.blacklanternsecurity.com/p/attack-surface-management-asm-goals #Infosec
🚨 ALERT! 🚨 Over 260,000 #Joomla sites at risk due to TWO newly discovered #zeroday vulnerabilities! 😱 Learn how our team uncovered these critical flaws in a popular Joomla extension and how you can protect yourself. Read the full story: https://blog.blacklanternsecurity.com/p/doomla-zero-days #cybersecurity #websecurity #CVE
🚨CVE-2026-10880: OSNEXUS QuantaStor up to v6.6.1 has an unauthenticated blind SQL injection in the login form. No credentials required. Attackers can recover stored password hashes one character at a time using differing login error responses.
https://blog.blacklanternsecurity.com/p/cve-2026-10880-osnexus-quantastor
📢 Now hiring: Senior Software Engineer - Python Developer (Remote)
We're looking for someone with deep Python async experience, Rust chops, & a real open-source track record to build security tooling.
Details & apply → https://www.blacklanternsecurity.com/careers/
🚀red-run 2.0 is live. Key updates:
Claude Code agent teams: each agent in its own tmux pane; hit Esc to pause or redirect in real time
New state-mgr teammate tracks findings and keeps the attack graph current
Still a lean, lab-focused CTF solver.
We've made it to the last question of the month!
We'd like to know: Have you used BBOT's web modules such as spider or lightfuzz? Give us some feedback on those modules if you have.
Swag give-away next week!
From customer to admin takeover in one request—Amelia Booking Pro flaw enables full WordPress compromise. #CVE-2026-2931 is on the BLS Blog now!
https://blog.blacklanternsecurity.com/p/amelia-booking-pro-912-authenticated
This week, we want to know: Were there any obstacles during your first experience with BBOT? If so, what were they?
We also want to share some swag with this month. We'll enter survey participants (one entry per question) into a drawing for a chance at some sweet BLS merch💜.
New post on the BLS Blog! Red Run walks through designing a compact native .NET loader that starts fast & keeps a low profile. The write-up covers inner workings & build steps.
Dive in: https://blog.blacklanternsecurity.com/p/red-run?r=qkvb8&utm_campaign=post&utm_medium=web&triedRedirect=true
Manspider 2.0 Release
New features include:
1) Better text extraction with Kreuzberg
2) Unit tests for stability
3) uv + ruff
4) Filtering on file modification time (thanks to https://github.com/probird5)
Install with: uv tool install man-spider
https://github.com/blacklanternsecurity/manspider
We’ve rolled out BBOT 2.8, packed with major updates since 2.3New module: gitdumper by @Domwhewell
New module: lightfuzz by @paulmmueller(replaces dastardly)
New module: medusa by @ChristianFl (for SNMP brute forcing)
New module: github_usersearch by @Domwhewell
New module: aspnet_bin_exposure by @paulmmueller
New module: graphql_introspection by @mukesh-dream11
New module: retire.js by @paulmmueller
New module: legba by @ChristianFl and @fuzikowski (for brute-forcing tons of services)
Countless improvements + fixes
Release history: https://www.blacklanternsecurity.com/bbot/Stable/release_history/
#BBOT #opensource #cybersecurity
🚨 TREVORspray 2.4 drops w/ TENANT ENUM!
Big thanks to Sprocket Security for uncovering the secret API — details: https://sprocketsecurity.com/blog/tenant-enumeration-is-back
Update to the latest version with pipx upgrade trevorspray
Spray smarter, not harder. #RedTeam #InfoSec
🚨 CVE-2025-12463: an unauth’d SQL injection that, when skillfully weaponized, can leak or overwrite critical data.
PoC + full teardown + hardening tips are live.
Full details👇https://blog.blacklanternsecurity.com/p/cve-2025-12463-98-unauthenticated
🚨Still on TecCom TecConnect 4.1? Blind XXE (CVE-2025-10183) in OpenMessaging lets unauth attackers:
• exfil any file (PoC: win.ini) via OOB
• snag & relay NTLM hashes
• own the box with one SOAP request
Upgrade to Connect 5. Full details➡️BLS Blog👇https://blog.blacklanternsecurity.com/p/teccom-tecconnect-41-xml-external?r=1cn8gh
🎉 BBOT just hit 1 MILLION downloads in 3 years!
From a small idea to a powerful recursive OSINT tool, this journey was only possible because of YOU — the users, contributors, & community who shared, tested, & believed. 💜🖤
Thank you🙏. We’re just getting started.







