⤷ Title: Road TryHackMe Room
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 20:32:52 GMT
════════════════════════
⌗ Tags: #penetration_testing #road_tryhackme_room #web_app_pentesting #road_pentesting #tryhackme_walkthrough
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 20:32:52 GMT
════════════════════════
⌗ Tags: #penetration_testing #road_tryhackme_room #web_app_pentesting #road_pentesting #tryhackme_walkthrough
Medium
Road TryHackMe Room
Road TryHackMe Room Hii all! Welcome to our TryHackMe Room Road pentesting lab. Lab environment Target ip address: 10.201.58.9 Objective: Enumerate services on the target, capture two flags, and …
⤷ Title: When One Request Becomes Two: A Deep Dive into HTTP Request Smuggling Vulnerabilities
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 23:44:38 GMT
════════════════════════
⌗ Tags: #tech #bug_bounty #technology #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 23:44:38 GMT
════════════════════════
⌗ Tags: #tech #bug_bounty #technology #cybersecurity #penetration_testing
Medium
When One Request Becomes Two: A Deep Dive into HTTP Request Smuggling Vulnerabilities
How Desynced Frontends, Confused Backends, and Tiny Parsing Differences Lead to Cache Poisoning, Account Takeover, and Full Site Compromise
⤷ Title: An IDOR that allows user information disclosure
════════════════════════
𐀪 Author: Shahd Mk
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 22:42:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #privilege_escalation #idor
════════════════════════
𐀪 Author: Shahd Mk
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 22:42:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #privilege_escalation #idor
Medium
An IDOR that allows user information disclosure
By Shahd Qishta
⤷ Title: Hidden administrator account under Windows Server Core: demonstration and defense
════════════════════════
𐀪 Author: Devilman24
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 23:02:43 GMT
════════════════════════
⌗ Tags: #windows #blue_team #red_team #information_security #hacking
════════════════════════
𐀪 Author: Devilman24
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 23:02:43 GMT
════════════════════════
⌗ Tags: #windows #blue_team #red_team #information_security #hacking
Medium
🎭 Hidden administrator account under Windows Server Core: demonstration and defense
Understanding how an attacker can create, maintain, and hide administrator access on Windows makes it easier to detect and prevent them.
⤷ Title: Why Most People Use AI Wrong in Cybersecurity
════════════════════════
𐀪 Author: Hania Khan
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 23:44:50 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity #ai_security #machine_learning #infosec
════════════════════════
𐀪 Author: Hania Khan
════════════════════════
ⴵ Time: Sat, 20 Dec 2025 23:44:50 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity #ai_security #machine_learning #infosec
Medium
Why Most People Use AI Wrong in Cybersecurity
I watched an AI miss a simple phishing email while alerting us about a movie plot. We are asking the wrong questions.
⤷ Title: I Trusted the AI Too Early. Production Taught Me Otherwise.
════════════════════════
𐀪 Author: CodeWithYog
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 01:28:31 GMT
════════════════════════
⌗ Tags: #software_development #bug_bounty #artificial_intelligence #programming #writing
════════════════════════
𐀪 Author: CodeWithYog
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 01:28:31 GMT
════════════════════════
⌗ Tags: #software_development #bug_bounty #artificial_intelligence #programming #writing
Medium
I Trusted the AI Too Early. Production Taught Me Otherwise.
A quiet lesson from building agent systems where restraint mattered more than speed.
⤷ Title: How a Simple Token Mistake Led Me to a Full Admin Account Takeover
════════════════════════
𐀪 Author: MOAMEN REZK
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 00:20:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #pentesting #writeup #bug_bounty
════════════════════════
𐀪 Author: MOAMEN REZK
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 00:20:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #pentesting #writeup #bug_bounty
Medium
How a Simple Token Mistake Led Me to a Full Admin Account Takeover 🔓
Sometimes, the most dangerous security bugs don’t look dangerous at first glance.
⤷ Title: My New Tool, Web Surface Inspector
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 00:01:58 GMT
════════════════════════
⌗ Tags: #vulnerability_management #web_security_testing #ethical_hacking #python #ai_security
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 00:01:58 GMT
════════════════════════
⌗ Tags: #vulnerability_management #web_security_testing #ethical_hacking #python #ai_security
Medium
My New Tool, Web Surface Inspector
I wanted to build out a new tool for the cybersecurity challenge we are all facing: website security and AI security. It’s also a…
⤷ Title: Excited to announce BugHQ — An all-in-one platform for security researchers! HTB
════════════════════════
𐀪 Author: BBHunterpk
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 02:52:43 GMT
════════════════════════
⌗ Tags: #hackthebox #htb #hacking #tryhackme_writeup #ctf_writeup
════════════════════════
𐀪 Author: BBHunterpk
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 02:52:43 GMT
════════════════════════
⌗ Tags: #hackthebox #htb #hacking #tryhackme_writeup #ctf_writeup
Medium
Excited to announce BugHQ — An all-in-one platform for security researchers! HTB
After years in cybersecurity, I noticed a common problem: security professionals juggling 10+ tools to organize their work.
⤷ Title: HackTheBox DarkZero Writeup — Advanced Active Directory Exploitation & NTLM Relay
════════════════════════
𐀪 Author: BBHunterpk
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 02:49:02 GMT
════════════════════════
⌗ Tags: #htb #hackthebox #hackthebox_walkthrough #hackthebox_writeup #htb_writeup
════════════════════════
𐀪 Author: BBHunterpk
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 02:49:02 GMT
════════════════════════
⌗ Tags: #htb #hackthebox #hackthebox_walkthrough #hackthebox_writeup #htb_writeup
Medium
HackTheBox DarkZero Writeup — Advanced Active Directory Exploitation & NTLM Relay
Advanced HackTheBox DarkZero machine writeup covering Active Directory exploitation, NTLM relay attacks, PetitPotam coercion, certificate…
⤷ Title: Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 09:52:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 09:52:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SubDog : Subdomain Enumeration
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:22:16 GMT
════════════════════════
⌗ Tags: #subdomain #ethical_hacking #bug_bounty #bug_bounty_tips #pentesting
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:22:16 GMT
════════════════════════
⌗ Tags: #subdomain #ethical_hacking #bug_bounty #bug_bounty_tips #pentesting
Medium
SubDog : Subdomain Enumeration
Fetch subdomains from 16+ sources without any API Key
⤷ Title: From $0 to $125: How I Abused a GraphQL Endpoint to Bomb Inboxes (My First Bounty)
════════════════════════
𐀪 Author: Zer0Figure
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:11:44 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #security #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Zer0Figure
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:11:44 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #security #bug_bounty_tips #bug_bounty
Medium
From $0 to $125: How I Abused a GraphQL Endpoint to Bomb Inboxes (My First Bounty)
After the heartbreak of a duplicate, I dug deeper into the API, found a broken logic flaw in the “Returns” feature, and finally got paid.
⤷ Title: RCE via Insecure JS Sandbox Bypass
════════════════════════
𐀪 Author: Bipin Jitiya
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:00:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #bug_bounty #security #hacking
════════════════════════
𐀪 Author: Bipin Jitiya
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:00:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #bug_bounty #security #hacking
Medium
RCE via Insecure JS Sandbox Bypass
How an exposed JS source map led to a sandbox escape and RCE in an AI platform
⤷ Title: ShinyHunters, Scattered LAPSUS$ Hunters, and the Post-Arrest Identity Crisis: A CTI Perspective
════════════════════════
𐀪 Author: Vardhan Gss
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:48:35 GMT
════════════════════════
⌗ Tags: #threat_intelligence #threat_hunting #threat_actor #hacking
════════════════════════
𐀪 Author: Vardhan Gss
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:48:35 GMT
════════════════════════
⌗ Tags: #threat_intelligence #threat_hunting #threat_actor #hacking
Medium
ShinyHunters, Scattered LAPSUS$ Hunters, and the Post-Arrest Identity Crisis: A CTI Perspective
ShinyHunters, Scattered LAPSUS$ Hunters, and the Post-Arrest Identity Crisis: A CTI Perspective The recent wave of statements circulating in underground channels has reignited confusion around …
⤷ Title: Hands-On Exploitation of the “Sunset” Vulnerable Machine
════════════════════════
𐀪 Author: Alfykannoth
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:27:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #vulnerability #privilege_escalation #ethical_hacking
════════════════════════
𐀪 Author: Alfykannoth
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:27:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #vulnerability #privilege_escalation #ethical_hacking
Medium
Hands-On Exploitation of the “Sunset” Vulnerable Machine
Introduction
⤷ Title: Metasploitable 3 (Windows) Write-up — Part [IX]: Port 5985 — Windows Remote Management Exploitation
════════════════════════
𐀪 Author: Kalash Kundaliya
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 04:10:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #windows_security #privilege_escalation #metasploit #cyber_defense
════════════════════════
𐀪 Author: Kalash Kundaliya
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 04:10:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #windows_security #privilege_escalation #metasploit #cyber_defense
Medium
Metasploitable 3 (Windows) Write-up — Part [IX]: Port 5985 — Windows Remote Management Exploitation
This guide is strictly for educational purposes only. All demonstrations are performed in a controlled environment using Metasploitable 3…
⤷ Title: Race Conditions — Toy to The World
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:45:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #tryhackme_writeup #advent_of_cyber_2025 #race_condition
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 05:45:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #tryhackme_writeup #advent_of_cyber_2025 #race_condition
Medium
Race Conditions — Toy to The World
Learn how to exploit a race condition attack to oversell the limited-edition SleighToy.
⤷ Title: Adversary Simulation Toolkit: 20 Tools for Real Labs (Master Red Team Skills)
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 07:10:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #hacking #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 07:10:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #hacking #bug_bounty #cybersecurity
Medium
Adversary Simulation Toolkit: 20 Tools for Real Labs (Master Red Team Skills)
What if you could see inside the mind of a real attacker — automate their moves, mimic their tactics, and hone your defense using the…
⤷ Title: Traceroute: Following the Digital Breadcrumbs Across the Internet
════════════════════════
𐀪 Author: Cybeague Technologies
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 07:10:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #hacking #information_gathering #reconnaissance
════════════════════════
𐀪 Author: Cybeague Technologies
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 07:10:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #hacking #information_gathering #reconnaissance
Medium
Traceroute: Following the Digital Breadcrumbs Across the Internet
Mapping your data’s journey, one hop at a time.
⤷ Title: ICS Security Basics
════════════════════════
𐀪 Author: Kavindu Sahan
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 06:35:57 GMT
════════════════════════
⌗ Tags: #hacking #information_security #cybersecurity #ics_security #modbus
════════════════════════
𐀪 Author: Kavindu Sahan
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 06:35:57 GMT
════════════════════════
⌗ Tags: #hacking #information_security #cybersecurity #ics_security #modbus
Medium
ICS Security Basics
So first of all what is ICS?