SECURITY WORK · DOCUMENTED

The work behindthe work.

Field notes from a cybersecurity hire that investigates, fixes, and verifies—not just reports.

FIELD NOTES · 47

Research with an operational point.

Exploit chains, incident lessons, product guidance, and the reasoning behind the action.

01 / FEATUREDJuly 18, 2026 · 20 min read
WordPressCritical RCECVE-2026-63030

How Two WordPress Core Bugs Chained into Pre-Auth RCE

How REST batch-route confusion, a scalar SQL injection, WordPress's object cache, the Customizer, and a nested REST dispatch formed an unauthenticated path to code execution—and how defenders should respond.

Read the field note
VERIFIED RESEARCHFrom issue
to action.

Concrete paths, defensive response, and what the evidence changes.

02July 13, 2026
Product GuideGetting Started

How to Use BugBunny

Our recommended BugBunny workflow: point a fresh scan at an authorized target, provide the original, unsanitized HAR when login context matters, and let the agents work autonomously.

5 min read
03July 13, 2026
Product UpdatePay as you go

Pay-As-You-Go Security Scanning at BugBunny

A transparent look at BugBunny PAYG: the platform fee, usage wallet, June scan-cost distribution, and why estimated costs vary with the security work.

5 min read
04June 30, 2026
Compliance AutomationGRC

Compliance Automation Software: Automating Evidence Without Automating Assumptions

How compliance automation software should collect evidence, monitor control drift, manage exceptions, and stay connected to security validation.

6 min read
05June 29, 2026
SSDLCSecure Development

Secure Software Development Lifecycle: Building Security Into the Work

A practical secure software development lifecycle guide covering requirements, threat modeling, code review, testing, release, and feedback loops.

6 min read
06June 28, 2026
Open SourceDependencies

Open Source Vulnerability Management: Fixing Dependency Risk Without Alert Fatigue

How to manage open-source vulnerabilities using SBOMs, SCA, reachability, ownership, patching, exceptions, and supply-chain validation.

6 min read
07June 27, 2026
Attack SurfaceASM Tools

Attack Surface Management Tools: How to Evaluate Discovery, Context, and Validation

How to choose attack surface management tools that find exposed assets, assign owners, prioritize risk, and support validation.

6 min read
08June 26, 2026
IAMAccess Control

Identity and Access Management Security: The Control Plane Attackers Target

A practical guide to IAM security across users, service accounts, roles, tokens, cloud permissions, reviews, and monitoring.

6 min read
09June 25, 2026
Penetration TestingContinuous Testing

Continuous Penetration Testing: Keeping Security Testing Close to Change

How continuous penetration testing differs from annual testing and how to use it for APIs, cloud, code, and attack-surface changes.

6 min read
10June 24, 2026
API SecurityScanner

API Vulnerability Scanner: What to Automate and What to Validate Manually

How to evaluate an API vulnerability scanner for authenticated coverage, schema testing, authorization, abuse cases, and remediation.

6 min read
11June 23, 2026
Supply ChainCI/CD

Software Supply Chain Security: Protecting the Path From Commit to Production

A practical software supply chain security guide for dependencies, CI/CD, build systems, artifacts, secrets, provenance, and developer tooling.

6 min read
12June 22, 2026
CSPMCloud Security

Cloud Security Posture Management: From Misconfigurations to Attack Paths

How cloud security posture management should prioritize misconfigurations by identity, exposure, data sensitivity, and exploitability.

6 min read
13June 21, 2026
Vulnerability ScannerAutomation

Automated Vulnerability Scanner: What It Can Find and What It Will Miss

How to use an automated vulnerability scanner for coverage while avoiding false confidence around auth, logic, chained impact, and context.

6 min read
14June 20, 2026
API SecurityProduction

API Security Best Practices for Production APIs

A production-focused API security checklist covering auth, object access, schemas, rate limits, secrets, logging, and testing.

6 min read
15June 19, 2026
Cloud NativeKubernetes

Cloud Native Security Solution: What to Demand Before You Buy

How to evaluate a cloud native security solution across identity, workloads, Kubernetes, APIs, CI/CD, posture, and runtime validation.

6 min read
16June 18, 2026
ISO 27001Compliance

ISO 27001 Compliance: Turning an ISMS Into Working Security Controls

A practical ISO 27001 compliance guide for risk assessment, control selection, evidence, audits, and technical validation.

6 min read
17June 17, 2026
API SecurityBest Practices

Best Practices for API Security That Reduce Real Abuse

API security best practices for authentication, authorization, rate limiting, schema validation, logging, and abuse-case testing.

6 min read
18June 16, 2026
SASTDAST

SAST and DAST: How to Combine Static and Dynamic Testing

How SAST and DAST complement each other, what each misses, and how to build a high-signal application security workflow.

6 min read
19June 15, 2026
DockerContainer Security

Docker Container Security: Hardening Images, Runtime, and Delivery

A practical Docker container security guide for base images, users, secrets, capabilities, registries, CI/CD, and runtime validation.

6 min read
20June 14, 2026
DevSecOpsAutomation Tools

DevSecOps Automation Tools: What to Put in the Pipeline and What to Keep Out

A practical guide to DevSecOps automation tools for secrets, SAST, SCA, containers, IaC, DAST, API security, and remediation workflows.

6 min read
21June 13, 2026
Software AuditCompliance

Software Audit Compliance: Making Engineering Evidence Audit-Ready

How software audit compliance connects code, dependencies, change management, vulnerability remediation, and control evidence.

6 min read
22June 12, 2026
Vulnerability ManagementRemediation

Vulnerability Management Best Practices for Fixing What Matters First

Practical vulnerability management best practices for prioritization, ownership, remediation, exceptions, and validation.

6 min read
23June 11, 2026
SASTStatic Analysis

What Is Static Code Analysis? A Security-Focused Explanation

What static code analysis does, where it helps, where it fails, and how to use it for high-signal application security.

6 min read
24June 10, 2026
Risk AssessmentSecurity Program

Security Risk Assessment: How to Turn Unknowns Into Owned Work

A practical security risk assessment workflow for assets, threats, vulnerabilities, controls, impact, likelihood, and remediation.

6 min read
25June 9, 2026
AutomationAI Security

Autonomous vs Automated Security: What the Difference Means in Practice

A practical comparison of autonomous vs automated security workflows, including review gates, context, control, and accountability.

6 min read
26June 8, 2026
NIST SP 800-53Controls

NIST SP 800-53 Controls: Turning a Large Catalog Into Operational Security

How to work with NIST SP 800-53 controls without losing the connection to systems, owners, evidence, and technical validation.

6 min read
27June 7, 2026
ComplianceAudit

Audit and Compliance Software: What It Should Prove, Not Just Store

How audit and compliance software should manage controls, evidence, exceptions, policies, owners, and security validation.

6 min read
28June 6, 2026
Web SecurityAppSec

Web Application Security: The Controls That Still Matter Most

A practical web application security guide for authentication, authorization, input handling, session safety, headers, logging, and testing.

6 min read
29June 5, 2026
Attack SurfaceExposure

Continuous Attack Surface Management: What to Watch After the Inventory

How continuous attack surface management helps teams find exposed assets, stale services, shadow APIs, and risky changes.

6 min read
30June 4, 2026
Vulnerability ManagementRemediation

Vulnerability Management Platforms: How to Choose for Signal, Ownership, and Fix Velocity

How vulnerability management platforms should prioritize findings, assign owners, track remediation, and reduce real exposure.

6 min read
31June 3, 2026
DASTPenetration Testing

DAST vs Penetration Testing: What Each Finds and When to Use Both

A clear comparison of DAST and penetration testing for application security programs that need coverage and exploit validation.

6 min read
32June 2, 2026
NISTCompliance

NIST Control Families: A Practical Reference for Security Teams

A practical reference to NIST control families and how to turn framework language into testable security controls.

6 min read
33June 1, 2026
API SecurityTesting

Security Testing for API: A Practical Workflow for Modern Teams

How to run security testing for API endpoints across authentication, authorization, rate limits, input validation, and business logic.

6 min read
34May 31, 2026
IDORAuthorization

Insecure Direct Object Reference: The Authorization Bug Hiding in Plain Sight

What insecure direct object reference means, how IDOR bugs happen, and how to test object-level authorization before release.

6 min read
35May 30, 2026
Secure Code ReviewAppSec

Secure Code Review: How to Find Boundary Failures Before Release

A practical guide to secure code review focused on authentication, authorization, injection, data flow, secrets, and business logic.

6 min read
36May 29, 2026
DevSecOpsCI/CD

DevSecOps Best Practices for Teams That Ship Every Week

A practical DevSecOps best-practices guide covering pull requests, CI/CD, secrets, dependencies, cloud configuration, and feedback loops.

6 min read
37May 28, 2026
SCADependencies

Software Composition Analysis: Beyond Dependency CVE Lists

How software composition analysis helps teams manage open-source dependency, license, supply-chain, and reachability risk.

6 min read
38May 27, 2026
Database SecurityData Protection

Database Security Best Practices That Survive Real Incidents

A concise database security checklist for access control, encryption, backups, query exposure, secrets, logging, and incident readiness.

6 min read
39May 26, 2026
Code ReviewDeveloper Workflow

Automating Code Review Without Training Developers to Ignore It

A step-by-step guide to automating code review with high-signal checks, security context, and sane pull-request workflow design.

6 min read
40May 25, 2026
ContainersVulnerability Management

Container Vulnerability Scanning: Finding the Issues That Actually Ship

How to use container vulnerability scanning to reduce exploitable image, package, secret, and runtime risk without drowning in CVEs.

6 min read
41May 24, 2026
Code ReviewAppSec

Automated Code Review: What to Trust, What to Verify, and What to Keep Human

A practical security guide to automated code review for engineering teams that need faster feedback without shallow findings.

6 min read
42May 23, 2026
Incident ResponseAutomation

Incident Response Automation: Where Speed Helps and Where Humans Still Matter

How to use incident response automation for containment, enrichment, evidence preservation, and repeatable security operations.

6 min read
43May 22, 2026
DetectionSOC

Intrusion Detection Systems: What They Catch and Where They Fail

A practical guide to intrusion detection systems, including telemetry quality, detection coverage, false positives, and response handoff.

6 min read
44May 21, 2026
SOC 2Compliance

SOC 2 Compliance Software: A Practical Guide for 2026

How to evaluate SOC 2 compliance software by evidence quality, control ownership, audit readiness, and continuous security validation.

6 min read
45May 20, 2026
PostmortemVS Code

GitHub's VS Code Extension Breach Was a Developer-Device Failure

A technical postmortem on the May 2026 GitHub internal repository breach, poisoned IDE extensions, workspace trust, and how BugBunny helps prevent developer-tooling incidents before they become repository breaches.

8 min read
46March 2026
BugBunnyHackerOne

Precision Over Volume: Why BugBunny's Signal Stands Out

BugBunny's public record is defined by precision: 89+ CVEs, No. 1 HackerOne Business ranking, and disciplined disclosure that emphasizes relevance over noise.

6 min read
47January 2026
Featured Research5 RCE

How We Found 5 Ways to Hack Any Developer Using Google Gemini CLI

Clone a repo. Type gemini. In 3 seconds, an attacker has your AWS keys, GitHub tokens, and everything else in your environment.

12 min read

READY FOR REAL WORK

Give the next security problem an owner.

Hire BugBunny
Security Research & Field Notes | BugBunny.ai | BugBunny.ai