The attack abuses parameter pollution techniques and was found by security firm ETHIACK.
It was tested against 9 WAFs in 17 different configurations.
blog.ethiack.com/blog/bypassi...
The attack abuses parameter pollution techniques and was found by security firm ETHIACK.
It was tested against 9 WAFs in 17 different configurations.
blog.ethiack.com/blog/bypassi...
KindaRails2Shell - discovered by the Ethiack research team.
Any app using Active Storage with the default vips processor and accepting image uploads from untrusted users is affected.
CVE-2026-66066
ethiack.com/info-hub/res...
KindaRails2Shell - discovered by the Ethiack research team.
Any app using Active Storage with the default vips processor and accepting image uploads from untrusted users is affected.
CVE-2026-66066
ethiack.com/info-hub/res...
Most AFWs get downgraded because nobody could prove RCE 🥷
Some research we've been doing for years just dropped!
Most AFWs get downgraded because nobody could prove RCE 🥷
Some research we've been doing for years just dropped!
Check out the full blog by Ben Lampere for tips, tricks, and tools to supercharge your bug bounty game ➡️ blog.ethiack.com/blog/superch...
Stay tuned for more in the Hacking with AI series! 👀
#bugbounty #ethiack
Check out the full blog by Ben Lampere for tips, tricks, and tools to supercharge your bug bounty game ➡️ blog.ethiack.com/blog/superch...
Stay tuned for more in the Hacking with AI series! 👀
#bugbounty #ethiack
Check out the contents from my workshop on Github!
You'll find:
✅ Workshop guide
✅ Scripts
✅ Tools
✅ CTF Challenges
Get stuck in (feedback welcome!) at
Check out the contents from my workshop on Github!
You'll find:
✅ Workshop guide
✅ Scripts
✅ Tools
✅ CTF Challenges
Get stuck in (feedback welcome!) at
https://www.ispreview.co.uk/index.php/2026/04/ethiack-claims-1-in-5-uk-telco-servers-exposed-to-cyber-risk.html
A new survey conducted by agentic AI pentesting firm Ethiack claims to have found that 19% of the web servers used by UK […]
https://www.ispreview.co.uk/index.php/2026/04/ethiack-claims-1-in-5-uk-telco-servers-exposed-to-cyber-risk.html
A new survey conducted by agentic AI pentesting firm Ethiack claims to have found that 19% of the web servers used by UK […]
It’s not a one-shot RCE, but the preconditions are kinda common under default configurations.
Patch your applications now!
CVE-2026-66066
ethiack.com/info-hub/res...
It’s not a one-shot RCE, but the preconditions are kinda common under default configurations.
Patch your applications now!
CVE-2026-66066
ethiack.com/info-hub/res...
ethiack.com/info-hub/res...
ethiack.com/info-hub/res...
That’s CVE-2026-66066: a .mat file declared as image/png, arbitrary file read, then RCE.
Full chain👇
ethiack.com/info-hub/res...
That’s CVE-2026-66066: a .mat file declared as image/png, arbitrary file read, then RCE.
Full chain👇
ethiack.com/info-hub/res...
Ground truth and code available here: https://github.com/ethiack/ethibench
Ground truth and code available here: https://github.com/ethiack/ethibench
Just dropped our workshop on AI for Ethical Hacking.
Full materials 👇
github.com/ethiack/ai4e...
Blog post: blog.ethiack.com/blog/dont-fe...
Just dropped our workshop on AI for Ethical Hacking.
Full materials 👇
github.com/ethiack/ai4e...
Blog post: blog.ethiack.com/blog/dont-fe...
We've put together some introductory hands-on examples including:
🔍 Recon & Discovery
⚡ Exploit Development
🤖 Hackbots
🧠 Integrations & Plugins
🏆 CTF Challenges
Check it out: https://github.com/ethiack/ai4eh
We've put together some introductory hands-on examples including:
🔍 Recon & Discovery
⚡ Exploit Development
🤖 Hackbots
🧠 Integrations & Plugins
🏆 CTF Challenges
Check it out: https://github.com/ethiack/ai4eh
@ethiack.com Hackian hackbot compromised a genetics platform in <4h, finding critical bugs humans missed.
Key takeaway: AI finds different vulnerabilities. Test before “bad guys” do.
@ethiack.com Hackian hackbot compromised a genetics platform in <4h, finding critical bugs humans missed.
Key takeaway: AI finds different vulnerabilities. Test before “bad guys” do.