SECURITY CIPHER · BLOG

cybersecurity

Posts from SecurityCipher.

PIYUSH KUMAWAT · August 25, 2026

The CVE Flood Is a Lie: How to Hunt When AI Dumps 36% More Bugs But Exploitation Only Grows 10%

Your vulnerability scanner ran overnight. Your inbox has 47 new CVE alerts. Slack is pinging you about a “critical” flaw in a…

PIYUSH KUMAWAT · July 17, 2026

Is AI Killing Bug Bounty? What the 2026 CVE Flood Really Means for Hunters

Ask any bug bounty hunter how 2026 is going and you will get one of two answers. Either “I have never found…

PIYUSH KUMAWAT · July 8, 2026

MCP Server Security (2026): A Practical Pentester’s Testing Playbook

If you are running Cursor, Claude Desktop, Windsurf, or a home-grown agent stack in 2026, you almost certainly have MCP servers in…

PIYUSH KUMAWAT · July 1, 2026

AI Bug Bounty in 2026: How Hunters Use Claude Code and Automation to Find Bugs Faster

AI bug bounty in 2026: how hunters use Claude Code, Burp MCP and automation to find bugs faster, with honest accuracy numbers…

PIYUSH KUMAWAT · June 30, 2026

Agentjacking: How Attackers Hijack AI Coding Agents Like Cursor and Claude

Agentjacking lets attackers hijack AI coding agents like Cursor, Claude Code and Codex via poisoned error data. Here's how it works and…

PIYUSH KUMAWAT · June 21, 2026

AutoJack: How One Web Page Can Hijack Your AI Agent and Own Your Machine

Microsoft's AutoJack shows how a single malicious web page can hijack an AI agent and run code on your machine. Here's how…

PIYUSH KUMAWAT · January 3, 2024

Exploring Application Security with SAST, DAST, SCA, and IAST

Welcome to today’s blog, where we’ll explore the world of software security testing. In an era where cyber threats are on the…