⤷ Title: Bug Bounty Hunting Isn’t Luck — It’s a System (With Tools That Actually Work)
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:32:46 GMT
════════════════════════
⌗ Tags: #cyberattack #bug_bounty #ethical_hacking #tootkit #cybersecurity
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:32:46 GMT
════════════════════════
⌗ Tags: #cyberattack #bug_bounty #ethical_hacking #tootkit #cybersecurity
Medium
Bug Bounty Hunting Isn’t Luck — It’s a System (With Tools That Actually Work)
Most people enter bug bounty hunting believing in accidents.
⤷ Title: $12,500 Bounty: How Changing One GraphQL ID Let Me Delete Other Users’ Data
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:27:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #penetration_testing #bug_bounty #tech
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:27:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #penetration_testing #bug_bounty #tech
Medium
$12,500 Bounty: How Changing One GraphQL ID Let Me Delete Other Users’ Data
How a Simple GraphQL ID Change Allowed Deletion of Other Users’ Data on HackerOne
⤷ Title: I Found One Bug and Made $9,750
════════════════════════
𐀪 Author: Codi
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:02:46 GMT
════════════════════════
⌗ Tags: #idor #bug_bounty #cybersecurity #hacking #technology
════════════════════════
𐀪 Author: Codi
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:02:46 GMT
════════════════════════
⌗ Tags: #idor #bug_bounty #cybersecurity #hacking #technology
Medium
I Found One Bug and Made $9,750
Here’s Exactly How
⤷ Title: Reflected XSS in blog search
════════════════════════
𐀪 Author: aiden0x
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:05:06 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #application_security #owasp_top_10 #xs
════════════════════════
𐀪 Author: aiden0x
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:05:06 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #application_security #owasp_top_10 #xs
Medium
Reflected XSS in blog search
Bypassing server side filtration to get a reflected XSS
⤷ Title: Entity Authentication
════════════════════════
𐀪 Author: Ali Naghiyev
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:45:25 GMT
════════════════════════
⌗ Tags: #hacking #information_security #information_technology
════════════════════════
𐀪 Author: Ali Naghiyev
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:45:25 GMT
════════════════════════
⌗ Tags: #hacking #information_security #information_technology
Medium
Entity Authentication
Entity authentication, often simply referred to as authentication, is the process of verifying the identity of a user, system, or device…
⤷ Title: Best Post-Exploitation Tools for Active Directory Pentesting
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:32:54 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #active_directory_pentest #pentesting #tools
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:32:54 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #active_directory_pentest #pentesting #tools
Medium
Best Post-Exploitation Tools for Active Directory Pentesting
10 + crucial tools for post-exploitation
⤷ Title: Web Security Academy: Websockets— Manipulating WebSocket messages to exploit vulnerabilities
════════════════════════
𐀪 Author: Octavian I.
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:19:08 GMT
════════════════════════
⌗ Tags: #tutorial #websocket #web_security #cybersecurity #hacking
════════════════════════
𐀪 Author: Octavian I.
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:19:08 GMT
════════════════════════
⌗ Tags: #tutorial #websocket #web_security #cybersecurity #hacking
Medium
Web Security Academy: Websockets— Manipulating WebSocket messages to exploit vulnerabilities
A simple case of WebSocket message manipulation
⤷ Title: Tryhackme | Advent Of Cyber 2025 | Day 13 | YARA Rules — YARA mean one! | Walkthrough
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:27:28 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme #tryhackme_walkthrough #aoc2025 #tryhackme_writeup
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:27:28 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme #tryhackme_walkthrough #aoc2025 #tryhackme_writeup
Medium
📌🚀Tryhackme | Advent Of Cyber 2025 | Day 13 | YARA Rules — YARA mean one! | Walkthrough🔥👉
Learn how YARA rules can be used to detect anomalies.
⤷ Title: TRYHACKME AOC 2025 Containers — DoorDasher’s Demise Writeup
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:12:39 GMT
════════════════════════
⌗ Tags: #container_security #aoc2025 #tryhackme #tryhackme_walkthrough #tryhackme_writeup
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:12:39 GMT
════════════════════════
⌗ Tags: #container_security #aoc2025 #tryhackme #tryhackme_walkthrough #tryhackme_writeup
Medium
TRYHACKME AOC 2025 Containers — DoorDasher’s Demise Writeup
Continue your Advent of Cyber journey and learn about container security.
⤷ Title: Hunter by HackSmarter Labs Walkthrough
════════════════════════
𐀪 Author: Muhammad Usman Faridi
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:30:54 GMT
════════════════════════
⌗ Tags: #username_enumeration #ethical_hacking #cybersecurity #access_control #red_team
════════════════════════
𐀪 Author: Muhammad Usman Faridi
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:30:54 GMT
════════════════════════
⌗ Tags: #username_enumeration #ethical_hacking #cybersecurity #access_control #red_team
Medium
Hunter by HackSmarter Labs Walkthrough
Lab Overview
⤷ Title: VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:00:31 +0000
════════════════════════
⌗ Tags: #Malware #cmstp.exe #LOLBIN #node_modules #Rust Trojan #steganography #supply chain attack #Typosquatting #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:00:31 +0000
════════════════════════
⌗ Tags: #Malware #cmstp.exe #LOLBIN #node_modules #Rust Trojan #steganography #supply chain attack #Typosquatting #VS Code
Daily CyberSecurity
VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
19 malicious VS Code extensions bypassed detection by hiding a Rust trojan in tampered node_modules and a fake banner.png using steganography. The attack uses cmstp.exe (LOLBIN) for execution.
⤷ Title: How I discovered leaked Snowflake credentials for a Fortune 500 Manufacturing Company using…
════════════════════════
𐀪 Author: Tillson Galloway
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:36:18 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #hacking #cybersecurity
════════════════════════
𐀪 Author: Tillson Galloway
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:36:18 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #hacking #cybersecurity
Medium
How I discovered leaked Snowflake credentials for a Fortune 500 Manufacturing Company using…
In late 2025, I used GitHound to uncover a high severity security issue involving leaked Snowflake tokens and sensitive information on a…
⤷ Title: Local Privilege Escalation via Docker Misconfiguration in Linux Operating Systems
════════════════════════
𐀪 Author: Shady mulla
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:07:27 GMT
════════════════════════
⌗ Tags: #privilege_escalation #penetration_testing #linux #docker #cybersecurity
════════════════════════
𐀪 Author: Shady mulla
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:07:27 GMT
════════════════════════
⌗ Tags: #privilege_escalation #penetration_testing #linux #docker #cybersecurity
Medium
Local Privilege Escalation via Docker Misconfiguration in Linux Operating Systems
In my OSCP learning journey, I got hands-on experience with the most common misconfiguration that happens amongst developers related to…
⤷ Title: Attacking ECB Oracles
════════════════════════
𐀪 Author: Jha Divyansh
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:42:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #attacking_ecb_oracles #tryhackme_writeup
════════════════════════
𐀪 Author: Jha Divyansh
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:42:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #attacking_ecb_oracles #tryhackme_writeup
Medium
Attacking ECB Oracles
ECB mode is simple but dangerously predictable: identical plaintext blocks always yield identical ciphertext. When exposed through an…
⤷ Title: HTB CTF Write-Up: Dancing
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
Medium
HTB CTF Write-Up: Dancing
Hello, fellow nerds!
⤷ Title: Proving Grounds - Clue
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:41:50 GMT
════════════════════════
⌗ Tags: #provinggrounds #linux #penetration_testing #cybersecurity #hacking
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:41:50 GMT
════════════════════════
⌗ Tags: #provinggrounds #linux #penetration_testing #cybersecurity #hacking
Medium
Proving Grounds - Clue
Summary
⤷ Title: NVIDIA Merlin Flaws Risk AI Pipeline RCE via Unsafe Deserialization in NVTabular & Transformers4Rec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:46:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI/ML #CVE_2025_33214 #Data Tampering #Deserialization #NVIDIA Merlin #NVTabular #rce #Transformers4Rec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:46:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI/ML #CVE_2025_33214 #Data Tampering #Deserialization #NVIDIA Merlin #NVTabular #rce #Transformers4Rec
Daily CyberSecurity
NVIDIA Merlin Flaws Risk AI Pipeline RCE via Unsafe Deserialization in NVTabular & Transformers4Rec
NVIDIA patched High-severity (CVSS 8.8) deserialization flaws in Merlin's NVTabular and Transformers4Rec on Linux. Exploitation risks RCE, DoS, and data tampering in AI recommendation pipelines.
⤷ Title: Unpatched Windows RasMan Flaw Allows Unprivileged Crash, Enabling Local System Privilege Escalation Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:49:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0patch #CVE_2025_59230 #privilege escalation #RasMan #Remote Access Connection Manager #Unpatched Flaw #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:49:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0patch #CVE_2025_59230 #privilege escalation #RasMan #Remote Access Connection Manager #Unpatched Flaw #windows
Daily CyberSecurity
Unpatched Windows RasMan Flaw Allows Unprivileged Crash, Enabling Local System Privilege Escalation Exploit
0patch found an unpatched flaw in Windows RasMan that allows any user to crash the service on demand. This unprivileged crash is the necessary step to exploit the CVE-2025-59230 LPE flaw. Micropatch is available.
⤷ Title: Critical pgAdmin RCE (CVE-2025-13780) Flaw Bypasses Fix, Allowing Server Takeover Via Malicious Database Restore
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13780 #Database Restore #Meta_Command #pgAdmin #PostgreSQL #rce #Remote Code Execution #security bypass #UTF_8 BOM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13780 #Database Restore #Meta_Command #pgAdmin #PostgreSQL #rce #Remote Code Execution #security bypass #UTF_8 BOM
Daily CyberSecurity
Critical pgAdmin RCE (CVE-2025-13780) Flaw Bypasses Fix, Allowing Server Takeover Via Malicious Database Restore
A critical RCE flaw (CVSS 9.1) in pgAdmin bypasses security via a UTF-8 BOM parsing mismatch. It allows attackers to execute root commands during a database restore operation. Update immediately.
⤷ Title: New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
Daily CyberSecurity
New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
NANOREMOTE, a new Windows backdoor, leverages the Google Drive API for covert C2 and data exfiltration using OAuth 2.0 tokens. The malware shares a hard-coded AES key with the FINALDRAFT family, linking it to seasoned espionage actors.
⤷ Title: SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
Daily CyberSecurity
SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
SHADOW-VOID-042 impersonated Trend Micro via fake security advisories to breach defense, energy, and chemical firms. Tactics align with Void Rabisu (ROMCOM), using HR lures and targeted exploits.