VYN / RSRCHBeyond the hackbot: how AI-assisted vulnerability research works
Why heuristics, steering, evidence, and persistent memory matter more than raw volume when searching for real vulnerabilities.
Analysis, methods, and field notes from research conducted on real products.
06
VYN / RSRCHWhy heuristics, steering, evidence, and persistent memory matter more than raw volume when searching for real vulnerabilities.
VYN / RSRCHHow invisible Unicode, a remote second stage, and external browsing can turn public content into an exfiltration channel.
VYN / RSRCHHow an inherited-property check allowed unapproved MCP tools to be exposed and executed.
VYN / RSRCHAn internal build artifact in Next.js let attackers reach content protected by proxy/middleware without authentication (CVE-2026-44575).
VYN / RSRCHHow chunked requests without Content-Length bypassed the body size limit in SvelteKit's adapter-node (CVE-2026-40073).
VYN / RSRCHA practical guide to indirect injection attacks and real-world impact.