Producción betaLa plataforma está en fase de pruebas y transformación continua. Puedes subir cursos y usar el campus con normalidad; disculpa cualquier ajuste temporal mientras consolidamos la experiencia.
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malwa...
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry...
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The v...
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so...
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from...
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through...
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families...
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affec...
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBlo...
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks...
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes k...
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threa...
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which s...
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own....
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader....
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together severa...
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development version...
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone num...
RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, F...
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (C...
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating...
This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has ass...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS...
We use technical cookies to keep sessions secure and, only with your permission, academy measurement and communications. You can accept all, keep only essentials, or configure each preference.
Cookie preference center
VulnHunters Academy uses cookies and local storage to keep sessions secure, remember preferences, and measure site performance. Non-essential cookies are enabled only after consent.
Strictly necessary cookies
Required for login, CSRF-protected forms, consent records, interface preferences such as light/dark mode, and misuse prevention.
Performance analytics cookies
Help us understand performance, navigation errors, most consulted sections, and technical quality. Data is handled in aggregate whenever possible and is not used for automated academic decisions.
Communication and campaign cookies
Measure the effectiveness of academy communications, admission notices, course updates, and internal campaigns. You can browse and buy courses with these disabled.
Consent management
You can change preferences at any time from the footer. Rejecting non-essential cookies does not limit basic content, registration, or required academic features.
Terms and conditions
1. Authorized use
All learning is oriented toward defense, authorized auditing, responsible research, and improvement of systems you own or have explicit permission to assess.
2. Ethical conduct
Using academy knowledge, labs, or materials to access third-party systems, bypass controls, or cause harm is prohibited.
3. Intellectual property
Materials, guides, challenges, and templates belong to VulnHunters Academy or their authors. Commercial redistribution is not allowed without permission.
4. Payments and access
Paid-course access is activated after transaction confirmation. Refund policies are communicated before enrollment is completed.
5. Privacy
We process personal data under GDPR/LOPD. Until an official mailbox is enabled, access, rectification, or deletion requests are handled through the internal contact form.
6. Responsibility
Students are legally responsible for any misuse outside environments authorized by the academy.
7. Certification
Certificates are issued after rubrics, minimum attendance, and deliverables are completed. The academy may revoke them in case of academic fraud.
Privacy policy
VulnHunters Academy collects registration data, preferences, academic activity, and payment information to provide the educational service. We do not sell personal data or disclose information to third parties except where legally required or necessary providers operate the platform.
Data is retained while an account remains active or during applicable legal periods. Until an official mailbox is enabled, rights requests are handled through the internal contact form.
We apply reasonable technical measures: HttpOnly session cookies, CSRF validation, activity logs, data minimization, and separation of sensitive folders.
Professional cookie policy
Last updated: May 2026.
This policy explains how VulnHunters Academy uses cookies, local storage, and equivalent technologies on the web platform. Its purpose is transparency, user control, and safe operation of courses, marketplace, chat, profiles, and private panels.
1. What cookies are
Cookies are small files or technical records stored by the browser when you visit a website. We may also use local browser storage to remember language, consent, or interface preferences.
2. Controller
The controller is VulnHunters Academy. For privacy, consent, or rights requests, use the internal contact form until an official mailbox is enabled.
3. Strictly necessary cookies
These cookies are essential to provide the requested service: session continuity, CSRF protection, basic preferences, security measures, consent state, and private-area navigation.
4. Performance analytics cookies
These cookies help measure stability, load times, technical errors, visited pages, and aggregated use of features. They are enabled only with consent.
5. Communication and campaign cookies
These cookies measure internal academy communications, admission forms, course promotions, marketplace updates, and informative campaigns. You may reject them without losing essential features.
6. Specific purposes
We use cookies for authentication, security, fraud prevention, user preferences, consent management, technical analytics, content improvement, campaign measurement, and interactive features such as chat and marketplace.
7. Legal basis
Technical cookies are based on the need to provide the requested service. Analytics and communication cookies are based on consent, which can be granted, rejected, or withdrawn at any time.
8. Retention and providers
Session cookies are normally deleted when the browser closes or the session expires. Where payment, security, analytics, email, or hosting providers are involved, access is limited to the contracted purpose.
9. Withdrawing consent
You can change preferences from the Cookie settings link in the footer. You can also remove or block cookies from your browser settings.
10. Policy changes
We may update this policy to reflect legal, technical, or functional changes. When a change is relevant, the platform may request consent again.
VulnHunters AssistantAvailable now
Hello. I am the VulnHunters Academy assistant. Select an option and I will direct you to the right resource.