⤷ Title: Sharing my SSRF (Server-Side Request Forgery) blog
════════════════════════
𐀪 Author: Priyesh Pahade
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:53:49 GMT
════════════════════════
⌗ Tags: #ssrf_bug #ssrf #web_application_security #ssrf_attack #ssrf_vulnerability
════════════════════════
𐀪 Author: Priyesh Pahade
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:53:49 GMT
════════════════════════
⌗ Tags: #ssrf_bug #ssrf #web_application_security #ssrf_attack #ssrf_vulnerability
Medium
🚀 Sharing my SSRF (Server-Side Request Forgery) blog
I’ve been working on understanding SSRF deeply — not just finding it, but understanding why it’s dangerous, how it leads to real impact…
⤷ Title: The Cybersecurity Side of AI Crypto Bots: What Users Need to Know
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:19:27 +0000
════════════════════════
⌗ Tags: #Cryptocurrency #AI #Artificial Intelligence #Crypto #Cryptocurency #Cybersecurity #Technology
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:19:27 +0000
════════════════════════
⌗ Tags: #Cryptocurrency #AI #Artificial Intelligence #Crypto #Cryptocurency #Cybersecurity #Technology
Hackread
The Cybersecurity Side of AI Crypto Bots: What Users Need to Know
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #osint #cybersecurity_writeups
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #osint #cybersecurity_writeups
Medium
Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems 🧠💰
After years in bug bounty, here’s something most beginners don’t realize:
⤷ Title: $2,500 Bounty: How a Simple Race Condition Let Me Get Paid Multiple Times by HackerOne
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:31 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #cybersecurity #tech #bug_bounty
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:31 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #cybersecurity #tech #bug_bounty
Medium
$2,500 Bounty: How a Simple Race Condition Let Me Get Paid Multiple Times by HackerOne
When Clicking “Confirm Retest” Faster Than the Server Could Think Turned Into Free Money
⤷ Title: What is API Security and Why Should Everyday People Care About it?
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:46:34 GMT
════════════════════════
⌗ Tags: #application #api_security #application_security #api
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:46:34 GMT
════════════════════════
⌗ Tags: #application #api_security #application_security #api
Medium
What is API Security and Why Should Everyday People Care About it?
Ever wondered what really happens behind the scenes when you tap “Sign in with Google” and, in seconds, the app knows who you are, without…
⤷ Title: Lab: 2FA broken logic
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:23:05 GMT
════════════════════════
⌗ Tags: #pentesting #ctf #hacking #medium #ctf_writeup
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:23:05 GMT
════════════════════════
⌗ Tags: #pentesting #ctf #hacking #medium #ctf_writeup
Medium
Lab: 2FA broken logic
Bu lab’da, iki faktörlü kimlik doğrulama (2FA) mekanizmasının hatalı bir mantıkla uygulanması nedeniyle nasıl bypass edilebildiğini…
⤷ Title: SNORT WALKTHROUGH (TRY HACK ME )
════════════════════════
𐀪 Author: The Commoness
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:42:31 GMT
════════════════════════
⌗ Tags: #incident_response #tryhackme_walkthrough #tryhackme_snort #tryhackme #tryhackme_writeup
════════════════════════
𐀪 Author: The Commoness
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:42:31 GMT
════════════════════════
⌗ Tags: #incident_response #tryhackme_walkthrough #tryhackme_snort #tryhackme #tryhackme_writeup
Medium
SNORT WALKTHROUGH (TRY HACK ME )
https://tryhackme.com/room/snort
TASK-2
TASK-2
⤷ Title: HackTheBox — File Uploads-Whitelist Filters
════════════════════════
𐀪 Author: 415141
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:27:18 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_security #file_upload #hackthebox
════════════════════════
𐀪 Author: 415141
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:27:18 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_security #file_upload #hackthebox
Medium
HackTheBox — File Uploads-Whitelist Filters
This module covers whitelist filters, which only allow specific file types. It is possible to bypass with double extensions…
⤷ Title: “Script” Engellemek Yetmez: Reflected XSS Gerçeği
════════════════════════
𐀪 Author: Melih Yılmaz
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:09:33 GMT
════════════════════════
⌗ Tags: #xss_attack #web_security #cybersecurity #web_application_security #ethical_hacking
════════════════════════
𐀪 Author: Melih Yılmaz
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:09:33 GMT
════════════════════════
⌗ Tags: #xss_attack #web_security #cybersecurity #web_application_security #ethical_hacking
Medium
“Script” Engellemek Yetmez: Reflected XSS Gerçeği
XSS saldırıları, web uygulamalarında sıkça karşılaşılan ve temelde bir enjeksiyon zafiyeti olarak değerlendirilen güvenlik açıklarıdır. Bu…
⤷ Title: Vulnhub Deathnote: 1 Walkthrough
════════════════════════
𐀪 Author: Luke Gearty
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:06:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerable_machine #ethical_hacking #hack_to_learn #vulnhub_walkthrough
════════════════════════
𐀪 Author: Luke Gearty
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:06:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerable_machine #ethical_hacking #hack_to_learn #vulnhub_walkthrough
Medium
Vulnhub Deathnote: 1 Walkthrough
“Deathnote: 1” is a vulnerable machine on Vulnhub, rated as easy. This post will be a walkthrough of hacking the machine and escalating…
⤷ Title: The Invisible Glue of the Internet: What Is API Security and Why It Matters to You
════════════════════════
𐀪 Author: Ngobirifalyne
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:51:32 GMT
════════════════════════
⌗ Tags: #api_introduction #api_security #api #getting_started_with_api #api_usage
════════════════════════
𐀪 Author: Ngobirifalyne
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:51:32 GMT
════════════════════════
⌗ Tags: #api_introduction #api_security #api #getting_started_with_api #api_usage
Medium
The Invisible Glue of the Internet: What Is API Security and Why It Matters to You
Imagine you are sitting in a restaurant. You are the customer, and the kitchen is the system that prepares your food. But how does the…
⤷ Title: Solving OIDC Integration Challenges with Kong API Gateway and Angular UI
════════════════════════
𐀪 Author: Amanuel Eshete
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:48:41 GMT
════════════════════════
⌗ Tags: #kong_api_gateway #api_security #openid_connect #microservices #angular
════════════════════════
𐀪 Author: Amanuel Eshete
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:48:41 GMT
════════════════════════
⌗ Tags: #kong_api_gateway #api_security #openid_connect #microservices #angular
Medium
Solving OIDC Integration Challenges with Kong API Gateway and Angular UI
Integrating OpenID Connect (OIDC) into a microservices platform can feel straightforward — until subtle issues put your UI, APIs, and…
⤷ Title: France Arrests 22 Year Old After Hack of Interior Ministry Systems
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:26:27 +0000
════════════════════════
⌗ Tags: #Cyber Crime #BreachForums #Cyber Attack #Cybersecurity #data breach #France #hacking #ShinyHunters
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:26:27 +0000
════════════════════════
⌗ Tags: #Cyber Crime #BreachForums #Cyber Attack #Cybersecurity #data breach #France #hacking #ShinyHunters
Hackread
France Arrests 22 Year Old After Hack of Interior Ministry Systems
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: $5,000 Bounty: How I Hijacked Google Gemini’s UI via Python Code Execution
════════════════════════
𐀪 Author: janet zech
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:05:51 GMT
════════════════════════
⌗ Tags: #technology #ai #security #llm #bug_bounty
════════════════════════
𐀪 Author: janet zech
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:05:51 GMT
════════════════════════
⌗ Tags: #technology #ai #security #llm #bug_bounty
Medium
$5,000 Bounty: How I Hijacked Google Gemini’s UI via Python Code Execution
This exploit can be weaponized to target anyone,no user is beyond its reach.
⤷ Title: SSRF Vulnerability Tryhackme Walkthrough
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:42:44 GMT
════════════════════════
⌗ Tags: #ssrf_walkthrough #tryhackme_walkthrough #cybersecurity #web_hacking #hacking
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:42:44 GMT
════════════════════════
⌗ Tags: #ssrf_walkthrough #tryhackme_walkthrough #cybersecurity #web_hacking #hacking
Medium
SSRF Vulnerability Tryhackme Walkthrough
SSRF is a web application security vulnerability that allows the attacker to force the server to make unauthorised requests to any local or…
⤷ Title: CTF Flow| HackingClub
════════════════════════
𐀪 Author: Henrique
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:09:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #hacking #offensive_security #pentesting
════════════════════════
𐀪 Author: Henrique
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:09:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #hacking #offensive_security #pentesting
Medium
CTF Flow | HackingClub
Máquina : Flow
⤷ Title: Testability vs. Automatability: Why Most Automation Efforts Fail Before They Begin
════════════════════════
𐀪 Author: tanvi mittal
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 01:02:38 GMT
════════════════════════
⌗ Tags: #testing #penetration_testing #software_testing #software_development #test_automation
════════════════════════
𐀪 Author: tanvi mittal
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 01:02:38 GMT
════════════════════════
⌗ Tags: #testing #penetration_testing #software_testing #software_development #test_automation
Medium
Testability vs. Automatability: Why Most Automation Efforts Fail Before They Begin
Test automation rarely fails because teams chose the wrong tool.
It fails much earlier often before the first test is written when…
It fails much earlier often before the first test is written when…
⤷ Title: GPO Stealth: Turn Active Directory Into Your C2 With the New GroupPolicyBackdoor Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:59:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #DEF CON 33 #GPO Abuse #GroupPolicyBackdoor #LDAP #privilege escalation #python #red teaming #SMB #Stealth Exploitation #Synacktiv
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:59:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #DEF CON 33 #GPO Abuse #GroupPolicyBackdoor #LDAP #privilege escalation #python #red teaming #SMB #Stealth Exploitation #Synacktiv
Penetration Testing Tools
GPO Stealth: Turn Active Directory Into Your C2 With the New GroupPolicyBackdoor Framework
Presented at DEF CON 33, GroupPolicyBackdoor is a Python framework for stealthy GPO manipulation, link poisoning, and AD privilege escalation.
⤷ Title: The Plagiarism Trap: How ForumTroll APT is Holding Academic Careers Hostage to Deploy Spyware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:55:26 +0000
════════════════════════
⌗ Tags: #Cyber Security #Academic Espionage #COM Hijacking #Dante Spyware #ForumTroll #Kaspersky Lab #LeetAgent #phishing #Russian Universities #threat intelligence #Tuoni Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:55:26 +0000
════════════════════════
⌗ Tags: #Cyber Security #Academic Espionage #COM Hijacking #Dante Spyware #ForumTroll #Kaspersky Lab #LeetAgent #phishing #Russian Universities #threat intelligence #Tuoni Framework
Penetration Testing Tools
The Plagiarism Trap: How ForumTroll APT is Holding Academic Careers Hostage to Deploy Spyware
In October 2025, experts at Kaspersky Lab uncovered a new wave of targeted attacks attributed to the ForumTroll
⤷ Title: The Invisible Roommate: How the GhostPairing Scam Steals Your WhatsApp Without a Password
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:53:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Cybersecurity 2025 #Device Pairing #Gen Digital #GhostPairing #phishing #privacy #QR Code Scam #Social Engineering #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:53:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Cybersecurity 2025 #Device Pairing #Gen Digital #GhostPairing #phishing #privacy #QR Code Scam #Social Engineering #WhatsApp
Penetration Testing Tools
The Invisible Roommate: How the GhostPairing Scam Steals Your WhatsApp Without a Password
Researchers at Gen have reported a new WhatsApp account-takeover technique dubbed GhostPairing. The attack appears mundane and arouses
⤷ Title: The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:52:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Check Point Research #Cyber Espionage #Earth Alux #European Security #FINALDRAFT #IIS Malware #Ink Dragon #ShadowPad #SharePoint Exploit
Penetration Testing Tools
The Living Mesh: Ink Dragon Turns European Government Servers into a Global ShadowPad Relay Network
Researchers at Check Point Research have uncovered a large-scale espionage operation conducted by the Chinese APT group Ink