All Articles
78 guides, CVE analyses, and security research articles — page 4 of 7.
-
Stop getting your bug bounty reports marked Informative: a submission guide for Intigriti, HackerOne, Bugcrowd, and YesWeHack
Submit bug bounty findings without getting marked Informative. Platform-specific guide for Intigriti, HackerOne, Bugcrowd, and YesWeHack severity taxonomies.
Read article → -
How to use CVE intel before you scan
Stop treating NVD as a passive reference. Pull a target's tech stack, query the NVD API, cross-reference Exploit-DB, and arrive at your campaign with a ranked hit-list.
Read article → -
The CORS + OAuth compound chain: how misconfigured origins become account takeovers
A CORS wildcard and an OAuth endpoint in the same scope often means a chained account takeover. Here's how SecurityClaw mapped the full attack path on Wolt.
Read article → -
What's hiding in your target's JavaScript bundles
What JS bundle scanning found on five EU bug bounty targets: dev hostnames, 22 API paths, a Webflow leak, and what that's actually worth in a report.
Read article → -
Why you can't find subdomain takeovers on mature bug bounty programs (and where to look instead)
451 subdomains checked across 6 EU bug bounty targets. Zero CNAME dangles. Here's why that's normal, what we found instead, and where subdomain takeovers actually live in 2026.
Read article → -
CT Log Recon on bol.com: Two Subdomains, Two Dead Ends, One Useful Map
SecurityClaw's CT log sweep found hipstershop.stg.bol.com and recruitment-git.bol.com. Neither was exploitable. Here's what we found and why it still mattered.
Read article → -
Before You Send a Single Packet: How CT Logs Mapped 79 Superdrug Subdomains in 12 Seconds
Certificate Transparency logs expose every SSL certificate ever issued — and 12+ years of your infrastructure history. SecurityClaw found 79 subdomains on a live bug bounty target before sending a single packet.
Read article → -
17 Findings in 4 Seconds: SecurityClaw's Web Scanner Finds Everything We Hid
SecurityClaw ran Nikto against a server we deliberately misconfigured. 5/5 planted misconfigs found in 4 seconds — plus 12 real issues we hadn't even planted. Including the one that hands attackers your entire codebase.
Read article → -
15 Vulnerabilities in Your package.json. 2 Seconds to Find Them.
We loaded a Node.js project with 8 deliberately outdated packages and ran SecurityClaw's npm audit skill against it. 15 vulnerabilities. 2 critical. Zero false positives. One package with no patch — not now, not ever. Here's what that means.
Read article → -
We Planted SQL Injection in 4 Places. SecurityClaw Found 2 — and Emptied the Database in 4 Seconds.
SQL injection has been on the OWASP Top 10 since 2003. We planted 4 SQLi vulnerabilities in a controlled Flask app and ran SecurityClaw's sqlmap skill against it. Two detected in under a second. Full database dump in 4.1 seconds. Here's why the other two weren't found — and why that matters more than the ones that were.
Read article → -
The Packagist RAT and the npm Worm: SecurityClaw Caught One While the Other Hid in Plain Sight
A PHP RAT hit Packagist on March 5. The same attack pattern hit npm in February. SecurityClaw's supply-chain-scanner found 7/7 planted threats — including two confirmed SANDWORM_MODE packages — in 0.19 seconds.
Read article → -
We Deleted the Key. Gitleaks Found It Anyway. Here's Why.
A developer deleted a private RSA key from their git repo. Three commits later, SecurityClaw found it in 13.2ms. Here's what happened and what it means for your codebase.
Read article →