Skip to main content
Scour
Browse
Getting Started
Login
Sign Up
You are offline. Trying to reconnect...
Copied to clipboard
Unable to share or copy to clipboard
Web Security
🌐 Web Security
XSS, SQLi, web application security, OWASP, HTTP
Filter Results
Timeframe
Fresh
Past Hour
Today
This Week
This Month
Feeds to Scour
Subscribed
All
Scoured
55
posts in
6.8
ms
What We Learned from a Multi-Service Vulnerability Disclosure
🐛
Vulnerability Research
labs.ripe.net
·
20h
20 hours ago
·
Hacker News
Actions for What We Learned from a Multi-Service Vulnerability Disclosure
Hacker News
Security
🛡️
Security
Content type:
Discussion
news.ycombinator.com
·
6d
6 days ago
·
Hacker News
Actions for Hacker News Security
Turning Cloudflare’s threat indicators into real-time
WAF
rules
📡
Threat Intelligence
Content type:
Blog
blog.cloudflare.com
·
2d
2 days ago
·
Hacker News
Actions for Turning Cloudflare’s threat indicators into real-time WAF rules
OWASP
Dependency-Track 5.0 Is Now Generally Available
🗄️
Databases
Content type:
Blog
owasp.org
·
2d
2 days ago
·
Hacker News
Actions for OWASP Dependency-Track 5.0 Is Now Generally Available
Matador-og/huntbot: AI offensive
security
harness for
bug
bounty
, pentesting, red teaming.
🎯
Red Teaming
Content type:
Code
github.com
·
23h
23 hours ago
·
Hacker News
Actions for Matador-og/huntbot: AI offensive security harness for bug bounty, pentesting, red teaming.
[webapps] WordPress
Contest
Gallery 28.1.4 - Unauthenticated Blind
SQL
Injection
🕵️
Penetration Testing
exploit-db.com
·
6d
6 days ago
Actions for [webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
How has use of framing protection
security
headers changed in the past 3 years?, (Wed, Jun 10th)
🧠
LSASS
Content type:
Academic
isc.sans.edu
·
21h
21 hours ago
Actions for How has use of framing protection security headers changed in the past 3 years?, (Wed, Jun 10th)
SAST vs SCA: Key Differences for AppSec Teams
🐛
Vulnerability Research
orca.security
·
2d
2 days ago
Actions for SAST vs SCA: Key Differences for AppSec Teams
Show HN: We post-trained a model that
pen
tests
instead of refusing your code
🐛
Vulnerability Research
argusred.com
·
1d
1 day ago
·
Hacker News
,
r/netsec
Actions for Show HN: We post-trained a model that pen tests instead of refusing your code
Imperva Customers Protected Against CVE-2026-49975 (
HTTP/2
Bomb) DoS
🐛
Vulnerability Research
Content type:
Blog
imperva.com
·
6d
6 days ago
Actions for Imperva Customers Protected Against CVE-2026-49975 (HTTP/2 Bomb) DoS
Personal
apps
with no back end: static
site
and OAuth PKCE and OpenRouter
🕵️
Penetration Testing
type2fun.net
·
5d
5 days ago
·
Hacker News
Actions for Personal apps with no back end: static site and OAuth PKCE and OpenRouter
local AI agents for Cursor with pre-tuned marketplace/commu
🟪
Programming
locaible.com
·
16h
16 hours ago
·
Hacker News
Actions for local AI agents for Cursor with pre-tuned marketplace/commu
Infosec News Nuggets — June 9, 2026
🛡️
Security
aboutdfir.com
·
1d
1 day ago
Actions for Infosec News Nuggets — June 9, 2026
martidu4/honey-ai: 🍯 All-in-one AI honeypot powered by local LLMs. SSH,
HTTP
, FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, RDP — with canary tokens, tarpits, GZIP bombs, and threat intel reporting.
📊
Query Optimization
Content type:
Code
github.com
·
14h
14 hours ago
·
Hacker News
Actions for martidu4/honey-ai: 🍯 All-in-one AI honeypot powered by local LLMs. SSH, HTTP, FTP, Telnet, SMTP, MySQL, Redis, Git, VNC, RDP — with canary tokens, tarpits, GZIP bombs, and threat intel reporting.
Seven Years on a Public Clipboard: Secrets, Türkiye's Exposure, and a Stored
XSS
📡
Threat Intelligence
Content type:
Blog
beyondmemory.io
·
5d
5 days ago
·
Hacker News
Actions for Seven Years on a Public Clipboard: Secrets, Türkiye's Exposure, and a Stored XSS
CVE-2026-20253: Splunk Enterprise Unauthenticated File Access via PostgreSQL Sidecar
🐛
Vulnerability Research
Content type:
Blog
hellorecon.com
·
1d
1 day ago
·
Hacker News
Actions for CVE-2026-20253: Splunk Enterprise Unauthenticated File Access via PostgreSQL Sidecar
From prompt to pwned: chaining LLM and
web
bugs to Admin
🐛
Vulnerability Research
Content type:
Blog
blog.quarkslab.com
·
6d
6 days ago
Actions for From prompt to pwned: chaining LLM and web bugs to Admin
USB Devices
🛡️
Security
Content type:
Reference
docs.orbstack.dev
·
23h
23 hours ago
·
Hacker News
Actions for USB Devices
Every breaking change in the 2026-07-28 MCP spec — and exactly how to migrate
🛡️
Security
Content type:
Blog
Content type:
Tutorial
mcpmigrate.dev
·
2d
2 days ago
·
Hacker News
Actions for Every breaking change in the 2026-07-28 MCP spec — and exactly how to migrate
Full Disclosure: [REVIVE-SA-2026-002] Revive Adserver Vulnerabilities
🐛
Vulnerability Research
seclists.org
·
6d
6 days ago
Actions for Full Disclosure: [REVIVE-SA-2026-002] Revive Adserver Vulnerabilities
Page 2 »
Log in to enable infinite scrolling
Keyboard Shortcuts
Navigation
Next / previous item
j
/
k
Open post
o
or
Enter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
g
h
Interests
g
i
Feeds
g
f
Likes
g
l
History
g
y
Changelog
g
c
Settings
g
s
Browse
g
b
Search
/
Pagination
Next page
n
Previous page
p
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc
Press
?
anytime to show this help