1. X
  2. shubs
Log inSign up
shubs
2,219 posts
user avatar
shubs
@infosec_au
Co-founder, security researcher. Building an attack surface management platform, @assetnote
halcyon
assetnote.io
Joined August 2013
1,959
Following
58.7K
Followers
RepliesRepliesMediaMedia
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

  • user avatar
    shubs
    @infosec_au
    Jul 18
    Note on WordPress pre-auth RCE (CVE-2026-63030). There are SQLi poc's out there, but RCE PoC has not yet been exploited in the wild. Will only release our technical post if we have proof of exploitation. Our RCE payload does NOT require poorly configured MySQL.
    135K
  • user avatar
    shubs
    @infosec_au
    Jul 14
    Our research team at @SLCyberSec discovered a pre-auth RCE in ServiceNow by bypassing their sandbox. Read @hash_kitten's write up here:
    Smashing the ServiceNow Sandbox – Pre Authentication RCE › Searchlight Cyber
    From slcyber.io
    12K
  • user avatar
    shubs
    @infosec_au
    Jun 25
    i always find that the more obscure the industry and niche is, the more vulnerable the software is. we found some critical issues in WiseTech’s CargoWise software that leads to pre auth RCE. they have a tight grip on the logistics industry. read more here:
    CargoWise WebTracker – The Keys Were in the Cargo › Searchlight Cyber
    From slcyber.io
    4.4K
  • user avatar
    shubs
    @infosec_au
    Jun 23
    we're hiring two full stack engineers at @assetnote - tight knit team that's extremely passionate and capable, scanning millions of assets hourly for security issues. need to be located in australia, but fully remote. if you're interested, apply:
    Company logo
    Full Stack Engineer
    From searchlight.bamboohr.com
    4.8K
  • user avatar
    shubs
    @infosec_au
    Jun 12
    bugcrowd.com/blog/savant-bu… so the bug bounty community freaked out a few weeks ago when hackerone had a single slide that talked about using AI agents for testing based off our reports. bugcrowd's new strategy sounds even more brazen, sly and egregious. submit reports -> your
    31K