⤷ Title: JWT Authentication Bypass via JWK Header Injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 03:40:35 GMT
════════════════════════
⌗ Tags: #json_web_token #jwt_exploitation #jwt_authentication_bypass #jwk_header_injection #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 03:40:35 GMT
════════════════════════
⌗ Tags: #json_web_token #jwt_exploitation #jwt_authentication_bypass #jwk_header_injection #bug_bounty
Medium
JWT Authentication Bypass via JWK Header Injection
A detailed look at how insecure JWK handling leads to full authentication compromise.
⤷ Title: JWT Authentication Bypass via jku Header Injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:51:54 GMT
════════════════════════
⌗ Tags: #jwt_authentication_bypass #jku_header_injection #json_web_token #jwks_manipulation #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:51:54 GMT
════════════════════════
⌗ Tags: #jwt_authentication_bypass #jku_header_injection #json_web_token #jwks_manipulation #bug_bounty
Medium
JWT Authentication Bypass via jku Header Injection
Inside the JWT Misconfiguration That Lets Attackers Become Admins with a Single Header Injection
⤷ Title: Deserialization for Hackers: How Server Logic Gets Hijacked
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
ⴵ Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
ⴵ Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
Medium
Deserialization for Hackers: How Server Logic Gets Hijacked
Hello everyone! Have you ever sent a JSON object to a server and thought, “It’s just data”?
Most of us do. We use JSON every day without…
Most of us do. We use JSON every day without…
⤷ Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Daily CyberSecurity
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
Apache NiFi patches a High-severity flaw (CVE-2025-66524) in the GetAsanaObject processor. Unfiltered deserialization risks system compromise. Update now!
⤷ Title: Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
Medium
Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
Greetings, fellow cybersecurity enthusiasts and CTF players! In this writeup, we’ll walk through the solution of the “Smart Home” web…
⤷ Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
Medium
4. Prototype Pollution: One JSON Key That Turns You into Admin
If you’ve ever seen a payload like this and ignored it:-
⤷ Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Daily CyberSecurity
HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
A high-severity vulnerability has been discovered in Axios, the immensely popular HTTP client used by millions of developers for Node.js and browser-based applications. The flaw, tracked as CVE-20…
⤷ Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
Medium
4. Prototype Pollution: One JSON Key That Turns You into Admin
If you’ve ever seen a payload like this and ignored it:-
⤷ Title: Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the “End-of-Life” Security Gap
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
⌗ Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
⌗ Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
Penetration Testing Tools
Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the "End-of-Life" Security Gap
The proliferation of “abandoned” technologies at the periphery of corporate networks has increasingly evolved into an auspicious point
⤷ Title: JSON.parse(JSON.stringify()) VS structuredClone()
════════════════════════
𐀪 Author: Gutu Galuppo
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 11:43:49 GMT
════════════════════════
⌗ Tags: #hacking #javascript #json #json_stringify #object_oriented
════════════════════════
𐀪 Author: Gutu Galuppo
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 11:43:49 GMT
════════════════════════
⌗ Tags: #hacking #javascript #json #json_stringify #object_oriented
Medium
JSON.parse(JSON.stringify()) VS structuredClone()
A forma certa (e a forma gambiarra) de clonar objetos em JavaScript
⤷ Title: JSON Injection: The Silent API Killer You’re Probably Ignoring
════════════════════════
𐀪 Author: Tejas Shirsat
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 16:14:58 GMT
════════════════════════
⌗ Tags: #json #appsec #api_security #cybersecurity
════════════════════════
𐀪 Author: Tejas Shirsat
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 16:14:58 GMT
════════════════════════
⌗ Tags: #json #appsec #api_security #cybersecurity
Medium
JSON Injection: The Silent API Killer You’re Probably Ignoring
We’ve spent a decade obsessing over SQL Injection and XSS. We’ve sanitized our database queries and escaped our HTML. But while we were…
⤷ Title: Top Technology Stacks for MVP Development in 2026
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 13:53:40 +0000
════════════════════════
⌗ Tags: #Technology #API #Developers #Freshcode #javascript #JSON #MVP #React
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 13:53:40 +0000
════════════════════════
⌗ Tags: #Technology #API #Developers #Freshcode #javascript #JSON #MVP #React
Hackread
Top Technology Stacks for MVP Development in 2026
Top technology stacks for MVP development in 2026, best tools for fast launch, scalability, cost efficiency, and proven frameworks for startups building products.
⤷ Title: Unsafe Deserialization in Ruby Background Workers Leading to Deterministic Remote Code Execution
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:57:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup #json #bug_bounty #ruby
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:57:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup #json #bug_bounty #ruby
Medium
Unsafe Deserialization in Ruby Background Workers Leading to Deterministic Remote Code Execution
Object Injection via Oj.load Allows Command Execution in RubitMQ Job Workers