← Back to BugBunny.ai

Editorial Research

Blog

Long-form writing from BugBunny on offensive research, disclosure quality, AI-native security work, and the operating standards behind our public results.

Track Record

89

CVEs disclosed in the BugBunny hall of fame.

Open Hall of Fame →
WordPressCritical RCECVE-2026-63030CVE-2026-60137

July 18, 202620 min read

How Two WordPress Core Bugs Chained into Pre-Auth RCE

How REST batch-route confusion, a scalar SQL injection, WordPress's object cache, the Customizer, and a nested REST dispatch formed an unauthenticated path to code execution—and how defenders should respond.

BugBunny.aiRead article →
Product GuideGetting StartedBest Practices

July 13, 20265 min read

How to Use BugBunny

Our recommended BugBunny workflow: point a fresh scan at an authorized target, provide the original, unsanitized HAR when login context matters, and let the agents work autonomously.

BugBunny.aiRead article →
Compliance AutomationGRCEvidence

June 30, 20266 min read

Compliance Automation Software: Automating Evidence Without Automating Assumptions

How compliance automation software should collect evidence, monitor control drift, manage exceptions, and stay connected to security validation.

BugBunny.aiRead article →
SSDLCSecure DevelopmentAppSec

June 29, 20266 min read

Secure Software Development Lifecycle: Building Security Into the Work

A practical secure software development lifecycle guide covering requirements, threat modeling, code review, testing, release, and feedback loops.

BugBunny.aiRead article →
Open SourceDependenciesVulnerability Management

June 28, 20266 min read

Open Source Vulnerability Management: Fixing Dependency Risk Without Alert Fatigue

How to manage open-source vulnerabilities using SBOMs, SCA, reachability, ownership, patching, exceptions, and supply-chain validation.

BugBunny.aiRead article →
Attack SurfaceASM ToolsExposure Management

June 27, 20266 min read

Attack Surface Management Tools: How to Evaluate Discovery, Context, and Validation

How to choose attack surface management tools that find exposed assets, assign owners, prioritize risk, and support validation.

BugBunny.aiRead article →
IAMAccess ControlIdentity Security

June 26, 20266 min read

Identity and Access Management Security: The Control Plane Attackers Target

A practical guide to IAM security across users, service accounts, roles, tokens, cloud permissions, reviews, and monitoring.

BugBunny.aiRead article →
Penetration TestingContinuous TestingAppSec

June 25, 20266 min read

Continuous Penetration Testing: Keeping Security Testing Close to Change

How continuous penetration testing differs from annual testing and how to use it for APIs, cloud, code, and attack-surface changes.

BugBunny.aiRead article →
API SecurityScannerDAST

June 24, 20266 min read

API Vulnerability Scanner: What to Automate and What to Validate Manually

How to evaluate an API vulnerability scanner for authenticated coverage, schema testing, authorization, abuse cases, and remediation.

BugBunny.aiRead article →
Supply ChainCI/CDDependencies

June 23, 20266 min read

Software Supply Chain Security: Protecting the Path From Commit to Production

A practical software supply chain security guide for dependencies, CI/CD, build systems, artifacts, secrets, provenance, and developer tooling.

BugBunny.aiRead article →
CSPMCloud SecurityMisconfiguration

June 22, 20266 min read

Cloud Security Posture Management: From Misconfigurations to Attack Paths

How cloud security posture management should prioritize misconfigurations by identity, exposure, data sensitivity, and exploitability.

BugBunny.aiRead article →
Vulnerability ScannerAutomationValidation

June 21, 20266 min read

Automated Vulnerability Scanner: What It Can Find and What It Will Miss

How to use an automated vulnerability scanner for coverage while avoiding false confidence around auth, logic, chained impact, and context.

BugBunny.aiRead article →
API SecurityProductionChecklist

June 20, 20266 min read

API Security Best Practices for Production APIs

A production-focused API security checklist covering auth, object access, schemas, rate limits, secrets, logging, and testing.

BugBunny.aiRead article →
Cloud NativeKubernetesSecurity Platform

June 19, 20266 min read

Cloud Native Security Solution: What to Demand Before You Buy

How to evaluate a cloud native security solution across identity, workloads, Kubernetes, APIs, CI/CD, posture, and runtime validation.

BugBunny.aiRead article →
ISO 27001ComplianceISMS

June 18, 20266 min read

ISO 27001 Compliance: Turning an ISMS Into Working Security Controls

A practical ISO 27001 compliance guide for risk assessment, control selection, evidence, audits, and technical validation.

BugBunny.aiRead article →
API SecurityBest PracticesAppSec

June 17, 20266 min read

Best Practices for API Security That Reduce Real Abuse

API security best practices for authentication, authorization, rate limiting, schema validation, logging, and abuse-case testing.

BugBunny.aiRead article →
SASTDASTAppSec Testing

June 16, 20266 min read

SAST and DAST: How to Combine Static and Dynamic Testing

How SAST and DAST complement each other, what each misses, and how to build a high-signal application security workflow.

BugBunny.aiRead article →
DockerContainer SecurityRuntime

June 15, 20266 min read

Docker Container Security: Hardening Images, Runtime, and Delivery

A practical Docker container security guide for base images, users, secrets, capabilities, registries, CI/CD, and runtime validation.

BugBunny.aiRead article →
DevSecOpsAutomation ToolsPipeline Security

June 14, 20266 min read

DevSecOps Automation Tools: What to Put in the Pipeline and What to Keep Out

A practical guide to DevSecOps automation tools for secrets, SAST, SCA, containers, IaC, DAST, API security, and remediation workflows.

BugBunny.aiRead article →
Software AuditComplianceEngineering Evidence

June 13, 20266 min read

Software Audit Compliance: Making Engineering Evidence Audit-Ready

How software audit compliance connects code, dependencies, change management, vulnerability remediation, and control evidence.

BugBunny.aiRead article →
Vulnerability ManagementRemediationRisk

June 12, 20266 min read

Vulnerability Management Best Practices for Fixing What Matters First

Practical vulnerability management best practices for prioritization, ownership, remediation, exceptions, and validation.

BugBunny.aiRead article →
SASTStatic AnalysisCode Security

June 11, 20266 min read

What Is Static Code Analysis? A Security-Focused Explanation

What static code analysis does, where it helps, where it fails, and how to use it for high-signal application security.

BugBunny.aiRead article →
Risk AssessmentSecurity ProgramRemediation

June 10, 20266 min read

Security Risk Assessment: How to Turn Unknowns Into Owned Work

A practical security risk assessment workflow for assets, threats, vulnerabilities, controls, impact, likelihood, and remediation.

BugBunny.aiRead article →
AutomationAI SecuritySecurity Operations

June 9, 20266 min read

Autonomous vs Automated Security: What the Difference Means in Practice

A practical comparison of autonomous vs automated security workflows, including review gates, context, control, and accountability.

BugBunny.aiRead article →
NIST SP 800-53ControlsCompliance

June 8, 20266 min read

NIST SP 800-53 Controls: Turning a Large Catalog Into Operational Security

How to work with NIST SP 800-53 controls without losing the connection to systems, owners, evidence, and technical validation.

BugBunny.aiRead article →
ComplianceAuditGRC

June 7, 20266 min read

Audit and Compliance Software: What It Should Prove, Not Just Store

How audit and compliance software should manage controls, evidence, exceptions, policies, owners, and security validation.

BugBunny.aiRead article →
Web SecurityAppSecSecure Development

June 6, 20266 min read

Web Application Security: The Controls That Still Matter Most

A practical web application security guide for authentication, authorization, input handling, session safety, headers, logging, and testing.

BugBunny.aiRead article →
Attack SurfaceExposureASM

June 5, 20266 min read

Continuous Attack Surface Management: What to Watch After the Inventory

How continuous attack surface management helps teams find exposed assets, stale services, shadow APIs, and risky changes.

BugBunny.aiRead article →
Vulnerability ManagementRemediationRisk

June 4, 20266 min read

Vulnerability Management Platforms: How to Choose for Signal, Ownership, and Fix Velocity

How vulnerability management platforms should prioritize findings, assign owners, track remediation, and reduce real exposure.

BugBunny.aiRead article →
DASTPenetration TestingAppSec

June 3, 20266 min read

DAST vs Penetration Testing: What Each Finds and When to Use Both

A clear comparison of DAST and penetration testing for application security programs that need coverage and exploit validation.

BugBunny.aiRead article →
NISTComplianceControls

June 2, 20266 min read

NIST Control Families: A Practical Reference for Security Teams

A practical reference to NIST control families and how to turn framework language into testable security controls.

BugBunny.aiRead article →
API SecurityTestingAuthorization

June 1, 20266 min read

Security Testing for API: A Practical Workflow for Modern Teams

How to run security testing for API endpoints across authentication, authorization, rate limits, input validation, and business logic.

BugBunny.aiRead article →
IDORAuthorizationAPI Security

May 31, 20266 min read

Insecure Direct Object Reference: The Authorization Bug Hiding in Plain Sight

What insecure direct object reference means, how IDOR bugs happen, and how to test object-level authorization before release.

BugBunny.aiRead article →
Secure Code ReviewAppSecEngineering

May 30, 20266 min read

Secure Code Review: How to Find Boundary Failures Before Release

A practical guide to secure code review focused on authentication, authorization, injection, data flow, secrets, and business logic.

BugBunny.aiRead article →
DevSecOpsCI/CDSecure Delivery

May 29, 20266 min read

DevSecOps Best Practices for Teams That Ship Every Week

A practical DevSecOps best-practices guide covering pull requests, CI/CD, secrets, dependencies, cloud configuration, and feedback loops.

BugBunny.aiRead article →
SCADependenciesSupply Chain

May 28, 20266 min read

Software Composition Analysis: Beyond Dependency CVE Lists

How software composition analysis helps teams manage open-source dependency, license, supply-chain, and reachability risk.

BugBunny.aiRead article →
Database SecurityData ProtectionAccess Control

May 27, 20266 min read

Database Security Best Practices That Survive Real Incidents

A concise database security checklist for access control, encryption, backups, query exposure, secrets, logging, and incident readiness.

BugBunny.aiRead article →
Code ReviewDeveloper WorkflowAutomation

May 26, 20266 min read

Automating Code Review Without Training Developers to Ignore It

A step-by-step guide to automating code review with high-signal checks, security context, and sane pull-request workflow design.

BugBunny.aiRead article →
ContainersVulnerability ManagementDevSecOps

May 25, 20266 min read

Container Vulnerability Scanning: Finding the Issues That Actually Ship

How to use container vulnerability scanning to reduce exploitable image, package, secret, and runtime risk without drowning in CVEs.

BugBunny.aiRead article →
Code ReviewAppSecAutomation

May 24, 20266 min read

Automated Code Review: What to Trust, What to Verify, and What to Keep Human

A practical security guide to automated code review for engineering teams that need faster feedback without shallow findings.

BugBunny.aiRead article →
Incident ResponseAutomationSOAR

May 23, 20266 min read

Incident Response Automation: Where Speed Helps and Where Humans Still Matter

How to use incident response automation for containment, enrichment, evidence preservation, and repeatable security operations.

BugBunny.aiRead article →
DetectionSOCTelemetry

May 22, 20266 min read

Intrusion Detection Systems: What They Catch and Where They Fail

A practical guide to intrusion detection systems, including telemetry quality, detection coverage, false positives, and response handoff.

BugBunny.aiRead article →
SOC 2ComplianceEvidence

May 21, 20266 min read

SOC 2 Compliance Software: A Practical Guide for 2026

How to evaluate SOC 2 compliance software by evidence quality, control ownership, audit readiness, and continuous security validation.

BugBunny.aiRead article →
PostmortemVS CodeSupply Chain

May 20, 20268 min read

GitHub's VS Code Extension Breach Was a Developer-Device Failure

A technical postmortem on the May 2026 GitHub internal repository breach, poisoned IDE extensions, workspace trust, and how BugBunny helps prevent developer-tooling incidents before they become repository breaches.

BugBunny.aiRead article →
BugBunnyHackerOneNo. 1 Business

March 20266 min read

Precision Over Volume: Why BugBunny's Signal Stands Out

BugBunny's public record is defined by precision: 89+ CVEs, No. 1 HackerOne Business ranking, and disciplined disclosure that emphasizes relevance over noise.

BugBunny.aiRead article →
Featured Research5 RCEGoogle VRP

January 202612 min read

How We Found 5 Ways to Hack Any Developer Using Google Gemini CLI

Clone a repo. Type gemini. In 3 seconds, an attacker has your AWS keys, GitHub tokens, and everything else in your environment.

BugBunny.aiRead article →
Blog | BugBunny.ai | BugBunny.ai