RSS Parrot

BETA

🦜 pwn.ai / @pwn_ai

@nitter.poast.org.pwn.ai@rss-parrot.net

I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline! Brought to you by the RSS Parrot.

---

Twitter feed for: @pwn_ai. Generated by https://nitter.poast.org

Your feed and you don't want it here? Just e-mail the birb.

Site URL: nitter.poast.org/pwn_ai

Feed URL: nitter.poast.org/pwn_ai/rss

Posts: 21

Followers: 1

WordPress just released another emergency update (after XSS2Shell) patching another RCE chain reported by @pwn_ai: CVE-2026-65640 https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ This one lets anyone with the lowest privilege (Author) execute system commands. This is based on our previous ImageMagick research. This is under a week after our preauth XSS chain was patched. Kudos to the team. More on this soon

Published: August 13, 2026 19:22

WordPress just released another emergency update (after XSS2Shell) patching another RCE chain reported by @pwn_ai: CVE-2026-65640 wordpress.org/news/2026/08/w… This one lets anyone with the lowest privilege (Author) execute system commands. This is based…

Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. https://pwn.ai/blog/xss2shell Please patch CVE-2026-64638 as soon as possible!

Published: August 7, 2026 12:23

Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. pwn.ai/blog/xss2shell Please patch CVE-2026-64638 as soon…

Chrome just fixed a very cute URL spoofing vulnearbility on its latest release found by Pwn: CVE-2026-14077 A tall partly above the viewport made Chrome paint over its omnibox. Details below

Published: July 20, 2026 14:04

Chrome just fixed a very cute URL spoofing vulnearbility on its latest release found by Pwn: CVE-2026-14077 A tall <select> partly above the viewport made Chrome paint over its omnibox. Details below Video

http://Pwn.ai just used a novel mitigation bypass technique to capture a Google kernelCTF flag autonomously. We gave it the most hardened kernel mitigation target. It came back with root execution and a clean flag capture. Blog post after the patch lands soon.

Published: June 24, 2026 14:18

Pwn.ai just used a novel mitigation bypass technique to capture a Google kernelCTF flag autonomously. We gave it the most hardened kernel mitigation target. It came back with root execution and a clean flag capture. Blog post after the patch lands soon.

RT by @pwn_ai: The Search for AGI through Security: Introducing the World's First AI-Based Novel Attack Vector Researcher - @pwn_ai https://pwn.ai/blog/the-search-for-agi-through-security-and-novelity

Published: May 17, 2026 14:57

The Search for AGI through Security: Introducing the World's First AI-Based Novel Attack Vector Researcher - @pwn_ai pwn.ai/blog/the-search-for-a…

RT by @pwn_ai: Are we gonna see the new Attack Vectors in OWASP Top 10?

Published: April 14, 2026 00:34

Are we gonna see the new Attack Vectors in OWASP Top 10? pwn.ai (@pwn_ai) Today we’re announcing something new in offensive security: the first AI system for novel vulnerability class discovery. An architecture built to discover undocumented…

Today we’re announcing something new in offensive security: the first AI system for novel vulnerability class discovery. An architecture built to discover undocumented exploit-building behaviors and previously unknown novel attack vectors that can later yield zero-days across real-world targets. The Search for AGI through Security is here. Read more: https://pwn.ai/blog/the-search-for-agi-through-security-and-novelity

Published: April 10, 2026 13:23

Today we’re announcing something new in offensive security: the first AI system for novel vulnerability class discovery. An architecture built to discover undocumented exploit-building behaviors and previously unknown novel attack vectors that can later…

🚨 ZERODAY: ImageMagick 🚨 Our autonomous pentester http://pwn.ai just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). 🤯 💥 Affects Ubuntu, Debian, WordPress & millions of servers globally. Happy Monday and Happy Hunting! 🥰 https://pwn.ai/blog/imagemagick-from-arbitrary-file-read-to-rce-in-every-policy-zeroday

Published: March 30, 2026 18:44

🚨 ZERODAY: ImageMagick 🚨 Our autonomous pentester pwn.ai just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). 🤯 💥 Affects…

Pinned: 🎄🎁 Here is a 0day unauthenticated root RCE affecting over 70,000 devices on the internet. https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts For our first post, we show how pwnai autonomously found a root rce affecting XSpeeder, over 8 months ago. To our knowledge, this is the first agent-found, remotely exploitable 0day RCE published. Merry Christmas & Happy New Year 🎅💥

Published: December 26, 2025 14:04

🎄🎁 Here is a 0day unauthenticated root RCE affecting over 70,000 devices on the internet. pwn.ai/blog/cve-2025-54322-z… For our first post, we show how pwnai autonomously found a root rce affecting XSpeeder, over 8 months ago. To our knowledge, this is…

Looks like nation-state actors are utilizing fully autonomous hacking engines. Wild to see them finally doing what we’ve already built, tested, and pushed way further at @pwn_ai. The future of hacking is autonomous!

Published: November 14, 2025 07:27

Looks like nation-state actors are utilizing fully autonomous hacking engines. Wild to see them finally doing what we’ve already built, tested, and pushed way further at @pwn_ai. The future of hacking is autonomous! Anthropic (@AnthropicAI) We disrupted…

What we are building is insane. If vendors patched quicker, we would've showed you already. The sort of vulnerabilities http://pwn.ai is finding is on par with the top security researchers. preauth RCE after preauth RCE fully autonomously. Will drop a blog post soon.

Published: July 30, 2025 16:05

What we are building is insane. If vendors patched quicker, we would've showed you already. The sort of vulnerabilities pwn.ai is finding is on par with the top security researchers. preauth RCE after preauth RCE fully autonomously. Will drop a blog post…

RT by @pwn_ai: 🚨 Octagon Networks has reproduced an unpatched SharePoint zero-day (CVE-2025-53770) now under active attack. Exploits leak MachineKey secrets, letting attackers hijack __VIEWSTATE for persistent code execution. If your SharePoint is exposed online, assume it’s compromised, take it offline and begin forensic analysis while awaiting a patch.

Published: July 20, 2025 11:59

🚨 Octagon Networks has reproduced an unpatched SharePoint zero-day (CVE-2025-53770) now under active attack. Exploits leak MachineKey secrets, letting attackers hijack __VIEWSTATE for persistent code execution. If your SharePoint is exposed online, assume…

We hacked @cluely's “Cheat on Everything” tool… and took full control of the cheaters computer. When a cheater uses Cluely, not only are we able to detect they are using Cluely but execute full commands on their computer. ‼️ Watch the full video 👇

Published: June 24, 2025 22:17

We hacked @cluely's “Cheat on Everything” tool… and took full control of the cheaters computer. When a cheater uses Cluely, not only are we able to detect they are using Cluely but execute full commands on their computer. ‼️ Watch the full video 👇 …

This is insane! @Pwndotai has autonomously discovered an unauthenticated remote command execution vulnerability affecting over 70,000 servers. It found the entry point, developed the entire chain, created a proof of concept, iterated through the right issues and entirely on its own got a complex root RCE shell. Reporting to the affected vendors right now

Published: June 24, 2025 16:12

This is insane! @Pwndotai has autonomously discovered an unauthenticated remote command execution vulnerability affecting over 70,000 servers. It found the entry point, developed the entire chain, created a proof of concept, iterated through the right…

With little help with @pwndotai , which is an agentic hacking ecosystem we are building, we are able to get 1-click RCE in Cluely (@cluely). The exploit takes time to setup but it's straight forward and can be reached via many techniques, and an indirect prompt injection. The full technical report is sent to Cluely team and we expect them to address it in a timely manner. In the meantime go follow @Pwndotai for upcoming announcements and advisories using our agentic tools

Published: June 22, 2025 20:38

With little help with @pwndotai , which is an agentic hacking ecosystem we are building, we are able to get 1-click RCE in Cluely (@cluely). The exploit takes time to setup but it's straight forward and can be reached via many techniques, and an indirect…

R to @pwn_ai: One can use one of the many classes that ship with Roundcube to call a __destruct based deserialization RCE. For example using Roundcube\File\TemporaryFile, Crypt_GPG_Engine or other classes Full request PoC: https://pastebin.com/TrPWfh6f

Published: June 6, 2025 13:06

One can use one of the many classes that ship with Roundcube to call a __destruct based deserialization RCE. For example using Roundcube\File\TemporaryFile, Crypt_GPG_Engine or other classes Full request PoC: pastebin.com/TrPWfh6f

🚨 Heads up! We just reproduced CVE-2025-49113 affecting Roundcube. This vulnerability lets users run arbitrary commands via PHP object deserialization. If you’re using Roundcube, patch it right away as its not that hard to repo! #bugbountytips

Published: June 6, 2025 12:30

🚨 Heads up! We just reproduced CVE-2025-49113 affecting Roundcube. This vulnerability lets users run arbitrary commands via PHP object deserialization. If you’re using Roundcube, patch it right away as its not that hard to repo! #bugbountytips Video

For the last year and a half we have been secretly working on multiple products that will shake and transform cyber security as we know it. From vulnerability detection, source code audit and penetration testing, to bug bounty and offensive security research. Stay tuned! 🤫

Published: June 2, 2025 13:32

For the last year and a half we have been secretly working on multiple products that will shake and transform cyber security as we know it. From vulnerability detection, source code audit and penetration testing, to bug bounty and offensive security…

RT by @pwn_ai: Introducing DoubleClickjacking 🧌: a widespread timing-based vulnerability class that slips between your first & second click — evading modern mitigations leading to account takeover vulnerabilities in almost all major websites. https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html #bugbountytips #infosec

Published: December 31, 2024 16:25

Introducing DoubleClickjacking 🧌: a widespread timing-based vulnerability class that slips between your first & second click — evading modern mitigations leading to account takeover vulnerabilities in almost all major websites. …