VYN / RSRCHBeyond the hackbot: how AI-assisted vulnerability research works
Why heuristics, steering, evidence, and persistent memory matter more than raw volume when searching for real vulnerabilities.
VYN / RSRCHWhy heuristics, steering, evidence, and persistent memory matter more than raw volume when searching for real vulnerabilities.
VYN / RSRCHHow invisible Unicode, a remote second stage, and external browsing can turn public content into an exfiltration channel.
VYN / RSRCHHow an inherited-property check allowed unapproved MCP tools to be exposed and executed.
A mismatch between the authorized route and the path used by FileSystemCache exposed protected artifacts and, under specific conditions, allowed unauthenticated code execution.
Next.js derived the cache identity from a different request than the one sent upstream.
VYN / RSRCHAn internal build artifact in Next.js let attackers reach content protected by proxy/middleware without authentication (CVE-2026-44575).
VYN / RSRCHHow chunked requests without Content-Length bypassed the body size limit in SvelteKit's adapter-node (CVE-2026-40073).
VYN / RSRCHA practical guide to indirect injection attacks and real-world impact.