SECURITY CIPHER · BLOG

Piyush Kumawat

Posts from Security Cipher.

PIYUSH KUMAWAT · July 12, 2026

Actively Exploited CVEs in June 2026: A Practical Patch-Now Briefing (SimpleHelp, Citrix, ColdFusion, Defender)

June 2026 was a brutal month for anyone who runs internet-facing infrastructure. A run of critical, actively-exploited vulnerabilities landed one after another,…

PIYUSH KUMAWAT · July 10, 2026

IDOR Hunting in 2026: A Practical Playbook for Finding Broken Access Control

IDOR is the bug that pays rent for a lot of bug bounty hunters, and it is still the one developers ship…

PIYUSH KUMAWAT · July 8, 2026

MCP Server Security (2026): A Practical Pentester’s Testing Playbook

If you are running Cursor, Claude Desktop, Windsurf, or a home-grown agent stack in 2026, you almost certainly have MCP servers in…

PIYUSH KUMAWAT · July 7, 2026

From Prompts to AI Security Loops: A Practical Playbook

Most teams are still treating AI like a better prompt box. "Review this code for vulnerabilities." "Write a Sigma rule for this…

PIYUSH KUMAWAT · July 6, 2026

Bug Bounty Recon Workflow (2026): A Practical, Copy-Paste Playbook

A practical bug bounty recon workflow for 2026 - the exact commands for subdomains, live hosts, URLs, JS analysis and content discovery,…

PIYUSH KUMAWAT · July 1, 2026

AI Bug Bounty in 2026: How Hunters Use Claude Code and Automation to Find Bugs Faster

AI bug bounty in 2026: how hunters use Claude Code, Burp MCP and automation to find bugs faster, with honest accuracy numbers…

PIYUSH KUMAWAT · June 30, 2026

Agentjacking: How Attackers Hijack AI Coding Agents Like Cursor and Claude

Agentjacking lets attackers hijack AI coding agents like Cursor, Claude Code and Codex via poisoned error data. Here's how it works and…

PIYUSH KUMAWAT · June 21, 2026

AutoJack: How One Web Page Can Hijack Your AI Agent and Own Your Machine

Microsoft's AutoJack shows how a single malicious web page can hijack an AI agent and run code on your machine. Here's how…

PIYUSH KUMAWAT · August 14, 2024

🛠️ Reconnaissance and Vulnerability Scanning Script🛡️

In the fast-paced world of cybersecurity, staying ahead of potential threats requires thorough reconnaissance and vulnerability assessments. This blog post introduces you…

PIYUSH KUMAWAT · February 22, 2024

LLM Agents can Autonomously Hack Websites ?

Based on the research paper (https://arxiv.org/pdf/2402.06664.pdf), the study delves into the autonomous hacking capabilities of Large Language Models (LLMs), particularly focusing on…