We care about
your security.

Nethemba is a leading Slovak IT security firm specialized in web security, penetration testing, and RFID security audits. Since 2007, we’ve been securing businesses with cutting-edge research and expertise, trusted by companies worldwide.

We care about
your security.

Nethemba is a leading Slovak IT security firm specialized in web security, penetration testing, and RFID security audits. Since 2007, we’ve been securing businesses with cutting-edge research and expertise, trusted by companies worldwide.

BLOG

Discovery of CVE-2022-24833

When on a security audit for a client it was discovered that a key component – the open-source private paste service PrivateBin contained a previously undocumented flaw. Cross-site-scripting is nothing new. I actually feel there must be prehistoric cave paintings and markings somewhere in the world containing some variation of <script>alert(1)</script>. Although XSS payloads embedded […]

Read More

Facebook

Nethemba
Nethemba2 days ago
XBOW Validation Benchmarks is a collection of web security challenges designed to test automated security testing tools.
https://github.com/xbow-engineering/validation-benchmarks
AI agent benchmark results across security platforms
https://0ca.github.io/BoxPwnr-Traces/stats/platform.html?platform=xbow
Nethemba
Nethemba3 days ago
This is big... Anthropic just announced a model so powerful they won't release it to the public out of fear over the damage it will cause 😨
Claude Mythos Preview found thousands of zero-day exploits in every major operating system and web browser...
The numbers are hard to believe:
> $50 to find a 27-year-old bug in OpenBSD, one of the most security-hardened operating systems ever built
> Under $1,000 to find AND build a fully working remote code execution exploit on FreeBSD that grants unauthenticated root access from anywhere on the internet
> Under $2,000 to chain together multiple Linux kernel vulnerabilities into a complete privilege escalation exploit
For context: these are the kinds of findings that previously required elite security researchers working for weeks.
Anthropic engineers with no formal security training asked Mythos to find exploits overnight. They woke up to working code the next morning.
The results were so impressive Anthropic assembled Apple, Google, Microsoft, Amazon, NVIDIA, and seven other organizations into Project Glasswing:
A $100M defensive coalition. They're not releasing this model publicly. Instead, they're racing to patch the world's infrastructure before models like this proliferate.
https://x.com/JoshKale/status/2041589742303649802
Nethemba
Nethemba3 days ago
Assessing Claude Mythos Preview’s cybersecurity capabilities
https://red.anthropic.com/2026/mythos-preview/