⤷ Title: 2025 TryHackMe’s Advent of Cyber
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:34:33 GMT
════════════════════════
⌗ Tags: #tryhackme #advent_of_cyber_2025
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:34:33 GMT
════════════════════════
⌗ Tags: #tryhackme #advent_of_cyber_2025
Medium
2025 TryHackMe’s Advent of Cyber
2025 TryHackMe’s Advent of Cyber This year, I started a lot of my blog posts and YouTube channel, The Husky Hacker. So, instead of the basic write-up, I wanted to do a YouTube series on the Advent …
⤷ Title: Exploitation with cURL — Hoperation Eggsploit ~Last room of Aod-2025
════════════════════════
𐀪 Author: Mann24>
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:34:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #curl #aoc2025 #tryhackme #ethical_hacking
════════════════════════
𐀪 Author: Mann24>
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:34:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #curl #aoc2025 #tryhackme #ethical_hacking
Medium
Exploitation with cURL — Hoperation Eggsploit ~Last room of Aod-2025
HTTP Requests Using cURL
⤷ Title: TryHackMe Writeup: ColddBox Easy
════════════════════════
𐀪 Author: Berkay AĞGÜL
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:12:31 GMT
════════════════════════
⌗ Tags: #cybercrime #tryhackme #cybersecurity #tryhackme_walkthrough #tryhackme_writeup
════════════════════════
𐀪 Author: Berkay AĞGÜL
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:12:31 GMT
════════════════════════
⌗ Tags: #cybercrime #tryhackme #cybersecurity #tryhackme_walkthrough #tryhackme_writeup
Medium
TryHackMe Writeup: ColddBox Easy
Siber güvenlik operasyonlarında bazen karşımıza sadece tek bir giriş noktasının olduğu, tüm zafiyet zincirinin tek bir servis üzerine…
⤷ Title: Understanding Broken Object Level Authorization (BOLA)
════════════════════════
𐀪 Author: Chihurumnanya Ruth Godwin
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:57:23 GMT
════════════════════════
⌗ Tags: #data_security #owasp_api_security_top_10 #api_security #cybersecurity #information_security
════════════════════════
𐀪 Author: Chihurumnanya Ruth Godwin
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 18:57:23 GMT
════════════════════════
⌗ Tags: #data_security #owasp_api_security_top_10 #api_security #cybersecurity #information_security
Medium
Understanding Broken Object Level Authorization (BOLA)
Why API1:2023 Remains the Most Critical API Security Risk
⤷ Title: One Request, Ten Times: How I Broke Admin Access with a Race Condition
════════════════════════
𐀪 Author: 0xMoussa
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:49:09 GMT
════════════════════════
⌗ Tags: #infosec #race_condition #cybersecurity #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: 0xMoussa
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:49:09 GMT
════════════════════════
⌗ Tags: #infosec #race_condition #cybersecurity #bug_bounty #ethical_hacking
Medium
One Request, Ten Times: How I Broke Admin Access with a Race Condition
One Request, Ten Times: How I Broke Admin Access with a Race Condition Intrduction During a recent bug bounty program, I discovered a critical race condition vulnerability in a team invitation …
⤷ Title: How to Become a Smart Contract Bug Hunter and Get Paid in 2026
════════════════════════
𐀪 Author: PMartin
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:06:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #blockchain_development #blockchain #blockchain_technology #bug_bounty_tips
════════════════════════
𐀪 Author: PMartin
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:06:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #blockchain_development #blockchain #blockchain_technology #bug_bounty_tips
Medium
How to Become a Smart Contract Bug Hunter and Get Paid in 2026
Smart contract bug hunting remains one of the highest-paying remote skills in Web3, and 2026 is shaping up to be a banner year for security…
⤷ Title: The Day I Found a Google Sheets API Key Hidden in Plain Sight — Inside a Public JavaScript File
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 20:28:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #bug_hunting #hacking #bug_bounty_writeup
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 20:28:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #bug_hunting #hacking #bug_bounty_writeup
Medium
🔑 The Day I Found a Google Sheets API Key Hidden in Plain Sight — Inside a Public JavaScript File
Some vulnerabilities scream for attention. Others sit quietly, tucked inside lines of JavaScript, waiting for someone curious enough to…
⤷ Title: The Night I Discovered a Production Server Hiding Behind an Exposed IP — And Why It Mattered…
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 20:27:31 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #bug_bounty_tips #comolho #bug_bounty
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 20:27:31 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #bug_bounty_tips #comolho #bug_bounty
Medium
🌐 The Night I Discovered a Production Server Hiding Behind an Exposed IP — And Why It Mattered More Than It Seemed
Some bug bounty stories start with complicated payloads or clever fuzzing tricks. This one started with something much simpler:
⤷ Title: AOC 2025 DAY 24- Exploitation with cURL — Hoperation Eggsploit Solutions
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:04:20 GMT
════════════════════════
⌗ Tags: #aoc2025 #tryhackme_writeup #tryhackme_walkthrough #tryhackme #curl
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:04:20 GMT
════════════════════════
⌗ Tags: #aoc2025 #tryhackme_writeup #tryhackme_walkthrough #tryhackme #curl
Medium
AOC 2025 DAY 24- Exploitation with cURL — Hoperation Eggsploit Solutions
Make a POST request to the /post.php endpoint with the username admin and the password admin. What is the flag you receive?
⤷ Title: CompTIA Certifications changed my life
════════════════════════
𐀪 Author: GhostInject
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 20:27:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #career_change #motivation #comptia #ethical_hacking
════════════════════════
𐀪 Author: GhostInject
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 20:27:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #career_change #motivation #comptia #ethical_hacking
Medium
CompTIA Certifications changed my life
Around 4 years ago I took the Net+ and failed bad… I thought I was crazy for trying to get into cyber security and change careers, So I…
⤷ Title: The SOC Access Paradox: When Your Security Team Becomes the Risk
════════════════════════
𐀪 Author: Steve Anderson
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:52:57 GMT
════════════════════════
⌗ Tags: #infosec #identity_management #cyberattack #cybersecurity
════════════════════════
𐀪 Author: Steve Anderson
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 21:52:57 GMT
════════════════════════
⌗ Tags: #infosec #identity_management #cyberattack #cybersecurity
Medium
The SOC Access Paradox: When Your Security Team Becomes the Risk
Here’s an awkward question: Who’s the most over-permissioned group in your organisation?
⤷ Title: Hacking Juice Shop: From Recon to Admin Access in 48 Hours
════════════════════════
𐀪 Author: Mohamed Magdy
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 23:35:53 GMT
════════════════════════
⌗ Tags: #owasp_juice_shop #penetration_testing #cybersecurity #owasp
════════════════════════
𐀪 Author: Mohamed Magdy
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 23:35:53 GMT
════════════════════════
⌗ Tags: #owasp_juice_shop #penetration_testing #cybersecurity #owasp
Medium
Hacking Juice Shop: From Recon to Admin Access in 48 Hours
Disclaimer: The testing activities documented in this post were conducted with explicit authorization for educational and research purposes…
⤷ Title: AoC 2025 XSS — Merry XSSMas
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 23:25:29 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme_writeup #stored_xss #reflected_xss #xss_vulnerability
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 23:25:29 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme_writeup #stored_xss #reflected_xss #xss_vulnerability
Medium
AoC 2025 XSS — Merry XSSMas
Cross-Site Scripting (XSS) is a web app vulnerability that lets evil bunnies inject malicious code into the input fields the reflect…
⤷ Title: Subscription Bypass Leading to Full Access to Paid Features
════════════════════════
𐀪 Author: Hossam Hamada
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:14:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #writing_tips #business_logic #bugbounty_writeup
════════════════════════
𐀪 Author: Hossam Hamada
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:14:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #writing_tips #business_logic #bugbounty_writeup
Medium
Subscription Bypass Leading to Full Access to Paid Features
Hi, my name is Hossam Hamada, I’m a Bug Bounty Hunter, and today I’ll be sharing a vulnerability I discovered in a Bug Bounty program on…
⤷ Title: Thoughts about email verification process in web applications
════════════════════════
𐀪 Author: Wsxcxx
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:53:21 GMT
════════════════════════
⌗ Tags: #sign_up #programming #application_security #application_development #email_verification
════════════════════════
𐀪 Author: Wsxcxx
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:53:21 GMT
════════════════════════
⌗ Tags: #sign_up #programming #application_security #application_development #email_verification
Medium
Thoughts about email verification process in web applications
I tried to talk about the title without code or drawing in this article. I thought this is be quite nice and fine topic to talk about.
⤷ Title: TryHackMe: Year of the Owl Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:20:38 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #information_security #tryhackme
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 01:20:38 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #information_security #tryhackme
Medium
TryHackMe: Year of the Owl Writeup
This box is ranked hard difficulty on THM, it involves heaps of enumeration on both TCP/UDP, exploiting WINRM to get a foothold on the…
⤷ Title: The Patch Hunter: Automating 1-Day Exploits with DiffRays and IDA Pro
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 03:06:01 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AutoDiff #Binary Diffing #CVE #DiffRays #Exploit Development #IDA Domain API #IDA Pro #Patch Analysis #reverse engineering #Vulnerability Research #Winbindex
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 03:06:01 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AutoDiff #Binary Diffing #CVE #DiffRays #Exploit Development #IDA Domain API #IDA Pro #Patch Analysis #reverse engineering #Vulnerability Research #Winbindex
Information Security News
The Patch Hunter: Automating 1-Day Exploits with DiffRays and IDA Pro
DiffRays is a research-oriented tool for binary patch diffing, designed to aid in vulnerability research, exploit development, and reverse engineering. It leverages IDA Pro and the IDA Domain API …
⤷ Title: Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:59:14 +0000
════════════════════════
⌗ Tags: #Windows #BitLocker #CPU Offloading #Encryption #Intel Panther Lake #Microsoft Ignite 2025 #NVMe #SSD performance #Windows 11 #Windows Security #XTS_AES_256
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:59:14 +0000
════════════════════════
⌗ Tags: #Windows #BitLocker #CPU Offloading #Encryption #Intel Panther Lake #Microsoft Ignite 2025 #NVMe #SSD performance #Windows 11 #Windows Security #XTS_AES_256
Information Security News
Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS
Microsoft has introduced a new hardware-accelerated version of its built-in BitLocker encryption in Windows 11. The feature is designed to boost performance and reduce CPU load by offloading heavy…
⤷ Title: The Robot Revolter: How Hackers Turned a $14,000 Humanoid Into a Physical Attacker
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:57:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI safety #cybersecurity #DARKNAVY #GEEKCon 2025 #Humanoid Robots #IoT Security #Physical Botnet #Robot Hacking #Unitree G1 #Unitree Go2 #Voice Command Exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:57:39 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI safety #cybersecurity #DARKNAVY #GEEKCon 2025 #Humanoid Robots #IoT Security #Physical Botnet #Robot Hacking #Unitree G1 #Unitree Go2 #Voice Command Exploit
Information Security News
The Robot Revolter: How Hackers Turned a $14,000 Humanoid Into a Physical Attacker
Commercial robots have proved far less secure than many assume. Security researchers are increasingly demonstrating that certain machines can be taken over in a matter of minutes, and that flaws i…
⤷ Title: The Dark Side of Telegram: Inside the $2B/Month Crypto Laundering Bazaars
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:56:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Fraud #Dark Web #Elliptic #Huione Guarantee #Money Laundering #pig butchering #Southeast Asia #Telegram #Tether #Tudou Guarantee #USDT #Xinbi Guarantee
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:56:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Fraud #Dark Web #Elliptic #Huione Guarantee #Money Laundering #pig butchering #Southeast Asia #Telegram #Tether #Tudou Guarantee #USDT #Xinbi Guarantee
Information Security News
The Dark Side of Telegram: Inside the $2B/Month Crypto Laundering Bazaars
The world’s largest online black markets may no longer reside in the dark web, but openly on Telegram itself. According to analysts, a sprawling network of Chinese-language “guarantor markets” has…
⤷ Title: Emergency Patch: Microsoft Issues Out-of-Band Fix for Broken MSMQ Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:54:51 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #Enterprise IT #IIS #KB5074976 #Microsoft #MSMQ #Out_of_Band #Patch Tuesday #Sysadmin #Windows Server #Windows Update
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 02:54:51 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #Enterprise IT #IIS #KB5074976 #Microsoft #MSMQ #Out_of_Band #Patch Tuesday #Sysadmin #Windows Server #Windows Update
Information Security News
Emergency Patch: Microsoft Issues Out-of-Band Fix for Broken MSMQ Infrastructure
Microsoft has released an out-of-band update to address a Message Queuing issue that emerged after the December 2025 update. The newly issued patches apply to Windows 10 22H2 ESU, Windows 10 Enter…