Research & Notes
Field notes on AI and the economics of exploitation.
CVE-2026-61511: vBulletin Unauthenticated RCE (Template Eval Injection), Reproduced for $1.61
CVE-2026-61511 is a critical (CVSS 9.8) pre-auth remote code execution bug in vBulletin's template engine. Here is what it is, how the exploit works, and how our lab reproduced it in 12m 36s for $1.61.
CVE-2026-66066: Rails ActiveStorage Arbitrary File Read (XXE), Reproduced for $0.87
CVE-2026-66066 is a critical (CVSS 9.5) arbitrary file read in Rails ActiveStorage via libvips. We reproduced a working XXE exploit in 7m 29s for $0.87 — and why 'we've seen no AI-driven attacks' is a lagging indicator.
Introducing Vulnerability Research Labs (VRL)
Why we started VRL: to fight FUD with actual research and data, build in the open, and hand defenders practical tools. Independently verified in partnership with Loginsoft.