CVE-2026-56291: Trivial Unauth RCE in Balbooa Forms
- Core flaw: Unauthenticated file upload in Joomla's com_baforms accepts any filename with no extension allow-list or CSRF, landing .php files in...

Created by Deji Akeuebue
Actionable exploit research, red-team case studies, and advanced pentesting techniques
Explore the latest content tracked by Offensive Security Digest
Two converging vectors are widening the offensive perimeter against AI systems.
AI now drives both concrete attacks and systemic risk expansion that offensive teams must monitor.
Red teams face immediate exposure when using AI coding agents for reviews.
Red teams must test LLM integrations for excessive agency—where models abuse backend APIs to perform unauthorized actions.
Key attack flow from the...
ZDI reports a 490% spike in vulnerability submissions this month versus last April, overwhelming triage teams and shuttering programs like Internet...
Mythos-class models erode the assumed edge of Chinese hardware backdoors and manufacturer knowledge by accelerating vulnerability discovery for...
A classic Unix symlink attack named GhostApproval tricks AI assistants including Claude Code, Cursor, and Amazon Q into following deceptive links to...
Public zero-day dumps like Exploitarium force offensive teams to rapidly triage credibility before any testing or operationalization begins.
-...
AI agents are accelerating both offensive attacks and defensive research at machine speed.
Cavern Manticore's .NET-based framework shows a clean modular design worth emulating for targeted operations.