𝕏 Bug Bounty Writeups 𝕏[verified]@bountywriteupsPatch
The brief report points out incomplete fixes for a few CVEs and provides links to HackerOne, but it does not discuss PoCs, active exploitation, or detailed technical data.
𝕏 Bug Bounty Writeups 𝕏[verified]@bountywriteupsPatch
The brief report lists several HackerOne findings, noting technical details of each vulnerability and indicating that the existing vendor patches are incomplete.
ROHIT@rynosecPatch
The post highlights an incomplete vendor fix for CVE-2026-7009, noting that GCC/SecTrust builds silently discard stapled OCSP responses, and it references a HackerOne bug bounty report.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The KUSANAGI release notes announce a module update that addresses multiple CVEs by deploying curl 8.20.0-1, indicating a patch release.
ROHIT@rynosecPatch
The tweet indicates that the fix for CVE-2026-7009 in AWS‑LC is incomplete, but no PoC, exploit, or active exploitation is discussed.
H1 Disclosed - Public Disclosures@h1DisclosedPoC
CVE‑2026‑7009 is an OCSP stapling bypass affecting Apple SecTrust, with a PoC linked via HackerOne that likely uses curl; no exploit code, patch, or active exploitation evidence is provided.
Open Source Security mailing list@oss_securityDisclosure
The text lists four newly disclosed CVEs, each accompanied by a concise description of the vulnerability type (credential leak, OCSP stapling bypass, cookie leak, and digest auth state leak), but it provides no PoC, exploit code, active exploitation evidence, or patch information.
草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The statement announces a module update that patches a list of CVE vulnerabilities in kusanagi‑curl 8.20.0‑1, with no evidence of PoCs, exploitation, or false claims.