⤷ Title: The use of an Open Redirect in Server Side Request Forgery (SSRF) — A Portsw
════════════════════════
𐀪 Author: ShiftLeftSec
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:48:42 GMT
════════════════════════
⌗ Tags: #ssrf #ssrf_attack #open_redirect #burp #appsec
════════════════════════
𐀪 Author: ShiftLeftSec
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:48:42 GMT
════════════════════════
⌗ Tags: #ssrf #ssrf_attack #open_redirect #burp #appsec
Medium
The use of an Open Redirect in Server Side Request Forgery (SSRF) — A Portsw
In previous articles, we’ve already covered what Server-Side Request Forgery (SSRF) is. In this post, we’ll look at how open redirects can…
⤷ Title: Blind Server Side Request Forgery — A Portswigger
════════════════════════
𐀪 Author: ShiftLeftSec
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:48:25 GMT
════════════════════════
⌗ Tags: #appsec #burp #ssrf_attack #burpsuite #ssrf
════════════════════════
𐀪 Author: ShiftLeftSec
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:48:25 GMT
════════════════════════
⌗ Tags: #appsec #burp #ssrf_attack #burpsuite #ssrf
Medium
Blind Server Side Request Forgery — A Portswigger
We have already looked at Server-Side Request Forgery (SSRF) and found that exploitation usually relied on one key advantage: visibility…
⤷ Title: China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 20:24:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 20:24:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Fake ChatGPT and DeepSeek Extensions Spied on Over 1 Million Chrome Users
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:06:32 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #Malware #Security #AI #Chatbot #ChatGPT #Chrome #Chrome Extension #Cybersecurity #DeepSeek #Fraud #Google #Privacy #Scam
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:06:32 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #Malware #Security #AI #Chatbot #ChatGPT #Chrome #Chrome Extension #Cybersecurity #DeepSeek #Fraud #Google #Privacy #Scam
Hackread
Fake ChatGPT and DeepSeek Extensions Spied on Over 1 Million Chrome Users
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: I Found a P2 Bug on a Live Target Using a CTF Trick—You Won’t Believe This.
════════════════════════
𐀪 Author: Rajankumarbarik
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:16:08 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #technology #bug_bounty #programming
════════════════════════
𐀪 Author: Rajankumarbarik
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:16:08 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #technology #bug_bounty #programming
Medium
I Found a P2 Bug on a Live Target Using a CTF Trick—You Won’t Believe This. 🫨
Free Link
⤷ Title: TryHackMe Smol Room / WordPress Penetration Testing
════════════════════════
𐀪 Author: Md. Raihan
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:50:15 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #wordpress #ethical_hacking #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Md. Raihan
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:50:15 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #wordpress #ethical_hacking #penetration_testing #bug_bounty
Medium
TryHackMe Smol Room / WordPress Penetration Testing
WordPress Security Assessment & Penetration Testing Report
⤷ Title: Logic Flaw to Race Condition to Four Digit Bounty
════════════════════════
𐀪 Author: PARADOX
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:37:46 GMT
════════════════════════
⌗ Tags: #infosec #hacking #penetration_testing #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: PARADOX
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:37:46 GMT
════════════════════════
⌗ Tags: #infosec #hacking #penetration_testing #bug_bounty #cybersecurity
Medium
Logic Flaw to Race Condition to Four Digit Bounty
Hey there, back again with another post! 😄
⤷ Title: Image XSS ATTACK on Exif.tools | Hacking exif.tools via image injection by CYBER KALKI #Livepoc
════════════════════════
𐀪 Author: ElonMuskTheAntichrist
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:22:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: ElonMuskTheAntichrist
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:22:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
Medium
Image XSS ATTACK on Exif.tools | Hacking exif.tools via image injection by CYBER KALKI #Livepoc
Image XSS ATTACK on Exif.tools | Hacking exif.tools via image injection by CYBER KALKI #Livepoc (Rewriting Deleted article originally published in oct 2025) I uncovered and demonstrated a …
⤷ Title: Akamai WAF Bypass: Escalating SSRF into Internal Port Scanning
════════════════════════
𐀪 Author: toast
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:06:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hackerone #bug_bounty_writeup #ethical_hacking
════════════════════════
𐀪 Author: toast
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:06:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hackerone #bug_bounty_writeup #ethical_hacking
Medium
Akamai WAF Bypass: Escalating SSRF into Internal Port Scanning
This issue came from an endpoint that looked completely harmless. It was a download API that fetched a URL on the server and returned the…
⤷ Title: Infinity Learning lab: Function’s Backdoor Route — Writeup
════════════════════════
𐀪 Author: Hubert
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #cloud_security #ctf_writeup #ctf #hacking #cybersecurity
════════════════════════
𐀪 Author: Hubert
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #cloud_security #ctf_writeup #ctf #hacking #cybersecurity
Medium
Infinity Learning lab: Function’s Backdoor Route — Writeup
This is a description of the steps I took to solve the Infinity Learning lab: Function’s Backdoor Route [1]. It is classified as a hard…
⤷ Title: Critical Authentication Bypass Vulnerability in GL.iNet GL-AXT1800 Router Firmware
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:00:05 GMT
════════════════════════
⌗ Tags: #zero_day_vulnerability #router #vpn #hacking
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:00:05 GMT
════════════════════════
⌗ Tags: #zero_day_vulnerability #router #vpn #hacking
Medium
Critical Authentication Bypass Vulnerability in GL.iNet GL-AXT1800 Router Firmware
Summary
⤷ Title: Authentication Bypass, Command Injection Vulnerability, and Race Condition in GL.iNet
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:59:53 GMT
════════════════════════
⌗ Tags: #mitre_attack #security #defcon #hacking #zero_day
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:59:53 GMT
════════════════════════
⌗ Tags: #mitre_attack #security #defcon #hacking #zero_day
Medium
Authentication Bypass, Command Injection Vulnerability, and Race Condition in GL.iNet
⤷ Title: A Comprehensive Guide to Hooking Clients to BEEF and Stealing Passwords
════════════════════════
𐀪 Author: Vignesh R
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:32:47 GMT
════════════════════════
⌗ Tags: #passwords #hacking #password_stealing #beef #ethical_hacking
════════════════════════
𐀪 Author: Vignesh R
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:32:47 GMT
════════════════════════
⌗ Tags: #passwords #hacking #password_stealing #beef #ethical_hacking
Medium
A Comprehensive Guide to Hooking Clients to BEEF and Stealing Passwords
ARP spoofing & Man In The Middle Attacks Execution & Detection
⤷ Title: SecurityOnion — Installation on VMware [Home Lab]
════════════════════════
𐀪 Author: DeshmukhVinit
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:45:50 GMT
════════════════════════
⌗ Tags: #blue_team #information_security #defensive_security #infosec #cybersecurity
════════════════════════
𐀪 Author: DeshmukhVinit
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:45:50 GMT
════════════════════════
⌗ Tags: #blue_team #information_security #defensive_security #infosec #cybersecurity
Medium
SecurityOnion — Installation on VMware [Home Lab]
Security Onion is a powerful open-source platform for network security monitoring, intrusion detection, and log management, widely used by…
⤷ Title: 217,000+ VNC Attack Attempts Observed on a Public Honeypot in 10+ days
════════════════════════
𐀪 Author: berke bodur
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:41:12 GMT
════════════════════════
⌗ Tags: #network_security #infosec #threat_intelligence #cybersecurity #information_technology
════════════════════════
𐀪 Author: berke bodur
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:41:12 GMT
════════════════════════
⌗ Tags: #network_security #infosec #threat_intelligence #cybersecurity #information_technology
Medium
217,000+ VNC Attack Attempts Observed on a Public Honeypot in 10+ days
Exposing services directly to the internet still comes with significant risk, even today. To better understand real-world attack behavior…
⤷ Title: Android Pentesting — Part 1: Getting Started with a Vulnerable Android App
════════════════════════
𐀪 Author: Mscmkn
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:24:15 GMT
════════════════════════
⌗ Tags: #mobileapplicationsecurity #android_security #penetration_testing #reverse_engineering #cybersecurity
════════════════════════
𐀪 Author: Mscmkn
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:24:15 GMT
════════════════════════
⌗ Tags: #mobileapplicationsecurity #android_security #penetration_testing #reverse_engineering #cybersecurity
Medium
Android Pentesting — Part 1: Getting Started with a Vulnerable Android App
Android Pentesting Series
⤷ Title: HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough)
════════════════════════
𐀪 Author: Andrey Pautov
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:34:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #hexstrike #cursor #cybersecurity #ai
════════════════════════
𐀪 Author: Andrey Pautov
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:34:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #hexstrike #cursor #cybersecurity #ai
Medium
HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough)
A real end-to-end lab engagement: recon → credential discovery → share abuse → lateral movement → multi-host compromise → reporting
⤷ Title: Digital Travel App TripBFF Exposed Location Data Way Too Accurately
════════════════════════
𐀪 Author: Jonathan Leitschuh
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:50 GMT
════════════════════════
⌗ Tags: #information_security #security #travel #penetration_testing
════════════════════════
𐀪 Author: Jonathan Leitschuh
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:50 GMT
════════════════════════
⌗ Tags: #information_security #security #travel #penetration_testing
Medium
Digital Travel App TripBFF Exposed Location Data Way Too Accurately
TripBFF exposed recent live latitude & longitude data and birth date for every user on their platform
⤷ Title: CyberHeroes THM Writeup
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:31:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cyberheros_thm #exposed_javascript #broken_authentication #tryhackme
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:31:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cyberheros_thm #exposed_javascript #broken_authentication #tryhackme
Medium
CyberHeroes THM Writeup
Understanding Broken Authentication Through Exposed JavaScript Logic
⤷ Title: Snapped Phish-ing Line — TryHackMe Walkthrough | Romedix
════════════════════════
𐀪 Author: Romedix
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:11 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #ctf_writeup #tryhackme #red_team
════════════════════════
𐀪 Author: Romedix
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:11 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #ctf_writeup #tryhackme #red_team
Medium
Snapped Phish-ing Line — TryHackMe Walkthrough | Romedix
Introduction
⤷ Title: The Puppet Master Hack The Box Lab
════════════════════════
𐀪 Author: Mylescorey
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:59:05 GMT
════════════════════════
⌗ Tags: #osint_investigation #hackthebox #hackthebox_writeup #osint
════════════════════════
𐀪 Author: Mylescorey
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:59:05 GMT
════════════════════════
⌗ Tags: #osint_investigation #hackthebox #hackthebox_writeup #osint
Medium
The Puppet Master Hack The Box Lab
Challenge Scenario