Marathon, Discipline, and AI

public
4 min read
Marathon, Discipline, and AI

Table of contents

It's been such a while since I last wrote here. It wasn't because I didn't want to, but these past weeks and I did not do anything very cool nor work a lot.

It was hard coming back to work and doing all that stuff again; it's frustrating each time, but when you're on it, it's working well.

Also, with the end of the Marathon training, I was more like just rest and you will see after.

Marathon

It's the end of my training, and the race is this Sunday. I did it pretty well, with no injuries this time. I also followed all of my training plans. I feel quite confident, but I'm also stressed, of course. We don't know what can happen in such a race.

So I just have to wait and see now. Get rested as fuck and taking my smile to run this 42.195 km ( or 26.1 miles ).

me actually

I already feel the after-race blues even if I did not race at all at the moment. But I know what I'm going to do after all of this, so it's nice. Just need to recover a bit.

Discipline

It's crazy how I can be fully disciplined in terms of sport or other stuff, but when it comes to hunting is by phase. Some moments, I'm fully into it, and some times, I can't stay at all in front of my computer searching for bugs.

But I think that most of them are like that, and that's why some people avoid it by doing something else when this happens. This time, I played videogames, I went out, I met new people, stuff like that.

It's always hard to come back, take another program, and focus on it. It's by phase, and I should accept it.

AI

I also tried looking at new stuff using AI. Just basic ones, like setting up some shortcuts to help me on a daily basis.

I learned more about MCP, and it looks awesome. I need to dig deeper into it. If you're interested in it ( and you understand French ), here is a nice live replay about it :

Resources

It's also been a while since I shared some technical thoughts and articles here, and I will try to do it more as I'm reading more and more articles.

There are more and more vulnerabilities on Next.js, and it's crazy as it is used by so many websites, like web3 ones and also vibe coder ones :

Next.js and the corrupt middleware: the authorizing artifact
CVE-2025-29927

I have not read it yet, but the same team also found new juicy stuff on React :

React Router and the Remix’ed path
CVE-2025-31137

Also a nice article on a Google App :

Client-side RCE via symlink following in Google Web Designer for macOS/Linux: CVE-2025-1079
Fixed in version 16.2.0.0128 — $11,250 bug bounty

Finally, a great one on Verizon

Hacking the Call Records of Millions of Americans
Imagine if anyone could punch in a phone number from the largest U.S. cell carrier and instantly retrieve a list of its recent incoming calls—complete with timestamps—without compromising the device, guessing a password, or alerting the user. Now imagine that number belongs to a journalist, a police officer, a politician, or someone fleeing an abuser. This capability wasn’t a hypothetical. I recently identified a security vulnerability in the Verizon Call Filter iOS app which made it possible for an attacker to leak call history logs of Verizon Wireless customers.

See you next week, with a probable come back on work and the result of my race!

Aituglo

Aituglo

Paris
The author of this blog, a bug bounty hunter and security researcher that shares his thoughts about the art of hacking.