zast ai

zast ai @zast_ai_0day

About: AI security researcher, who can find zero-days with zero false positives, as fast as other AI developers write code.

Location:
United States
Joined:
Aug 19, 2025

zast ai
articles - 25 total

ZAST.AI Security Advisory: Critical SSRF Resolved in ClawdBot.

While the community focused on general configuration risks, ZAST verified the actual code. Our...

Learn More 0 0Jan 27

A Stored XSS (CVE-2026-0693) in the "Allow HTML in Category Descriptions" @WordPress plugin.

We verified a Stored XSS (CVE-2026-0693) in the "HTML in Category Descriptions" @WordPress...

Learn More 0 0Jan 24

2025 Annual Report: 153 Publicly Disclosed Vulnerabilities & 0 False Positives

In 2025, ZAST.AI redefined what’s possible in static analysis. It successfully identified and...

Learn More 0 0Jan 14

CRITICAL ALERT: Apache Struts2 XXE Exposed (CVE-2025-68493)

ZAST.AI discovered a high severity XXE vulnerability in XWork-Core allows threat actors steal files...

Learn More 0 0Jan 13

ZAST.AI vs. Burp Suite: The Signal vs. Noise Challenge 🥊

We pitted our AI engine against the industry standard to find a critical IDOR vulnerability in an...

Learn More 0 0Dec 23 '25

🚨 MAJOR DISCOVERY: 7 WordPress Plugin Vulnerabilities, ZERO False Positives!

Our AI security research agent just uncovered 7 verified stored XSS flaws in WordPress plugins —...

Learn More 0 0Dec 9 '25

🔥 1-Month DEV CHALLENGE: Test ZAST Express (IDE Extension) in 3 Min, Win $100 & Credits!

Tired of switching between your IDE and security dashboards? Dealing with false alerts and slow...

Learn More 0 0Dec 1 '25

🎊 [New Feature] ZAST EXPRESS - Official Release

Our IDE extension is now officially available: ✨ Zero-false-positive AI engine integrated into your...

Learn More 0 0Nov 24 '25

🚀 GitHub Codespaces + ZAST.AI: Assess Apps in Minutes!

No local setup—build, package, and secure your projects in the cloud ⚡ • Zero-false-positive...

Learn More 0 0Nov 18 '25

ZAST.AI identified 6+ vulnerabilities in JeeSite

🔍ZAST.AI identified 6+ vulnerabilities in JeeSite <=5.12.0 b522b3f: • SSRF (CVE-2025-7759) •...

Learn More 0 0Nov 11 '25

The Same Feature That Makes a Component Powerful Can Also Make It Dangerous.

A documented feature became a weapon with #Log4Shell. The blurry line between function and flaw is...

Learn More 0 0Nov 4 '25

ZAST.AI found Insecure File Upload & CSP bypass issues in CodiMD

• Low version (CVE-2025-46654) • High version (CVE-2025-46655) These vulnerabilities could allow...

Learn More 0 0Oct 28 '25

Think your code is secure? 🧐

Our client patched a command injection flaw with: 🔨- Base64 encoding 🛠️- A secret prefix Both times,...

Learn More 0 0Oct 22 '25

Vulnerability Discovery #3 Security Flaws in "Mall" CVE-2025-8191

🔍 ZAST.AI discovered vulnerabilities in mall <=1.0.3 7a1ca5d: • DOM XSS (CVE-2025-8191) These...

Learn More 0 0Oct 14 '25

Quick Tunnel: Local Web to Public Domain

🔒 Having trouble exposing local services publicly or using temporary domains for ZAST? No...

Learn More 0 0Oct 7 '25

Remote Code Execution vulnerabilities uncovered in Apache Commons Configuration

🔍 ZAST.AI uncovered Remote Code Execution vulnerabilities in Apache Commons Configuration: • Version...

Learn More 0 0Sep 30 '25

😫Tired of fake vulnerabilities + slow checks?

Zast.ai fixes it—with actual working POCs! ⚡Talk is cheap, show me the POC! Dive in:...

Learn More 0 0Sep 23 '25

ZAST.AI discovered vulnerabilities in Node-formidable

🔍 ZAST.AI discovered vulnerabilities in Node-formidable (10M+ weekly downloads): • Insecure File...

Learn More 0 0Sep 18 '25

[Sneak Peek] ZAST EXPRESS is Almost Here!

[Sneak Peek] ZAST EXPRESS is Almost Here! ZAST EXPRESS plugin brings our zero false positive AI...

Learn More 0 0Sep 17 '25

Zast.ai now can find 0-day in Python code with ZERO false positives

[Sneak Peek] Progress Update 🎯 Zast.ai now can find 0-day in Python code with ZERO false positives -...

Learn More 0 0Sep 12 '25

🎯Hundreds of zero-day vulnerabilities from dozens of open-source projects.

🎯Hundreds of zero-day vulnerabilities from dozens of open-source projects. By AI agent: Zast.ai....

Learn More 0 0Sep 10 '25

We’ve won the Google Startup Award with $250K in Cloud Credits

Thrilled to announce we've won the Google Startup Award with $250K in Cloud Credits, which enhances...

Learn More 0 0Sep 8 '25

🚀 Building a more secure open source world by AI agent Zast.ai!

The AI agent Zast.ai has disclosure these POCed 0-day vulnerabilities until September 1st, all shared...

Learn More 0 0Sep 5 '25

Vulnerability Disclosure Challenges in Open Source Projects

Can we trust our npm dependencies? Ever wonder about the challenges of responsibly disclosing...

Learn More 0 0Sep 4 '25

How to Use ZAST.AI

Use Zast.ai to assess vulnerabilities in 3 steps: 1️⃣ Visit https://zast.ai & signup/signin 2️⃣...

Learn More 0 0Aug 26 '25