⤷ Title: TryHackMe Smol Room / WordPress Penetration Testing
════════════════════════
𐀪 Author: Md. Raihan
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:50:15 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #wordpress #ethical_hacking #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Md. Raihan
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:50:15 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #wordpress #ethical_hacking #penetration_testing #bug_bounty
Medium
TryHackMe Smol Room / WordPress Penetration Testing
WordPress Security Assessment & Penetration Testing Report
⤷ Title: Logic Flaw to Race Condition to Four Digit Bounty
════════════════════════
𐀪 Author: PARADOX
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:37:46 GMT
════════════════════════
⌗ Tags: #infosec #hacking #penetration_testing #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: PARADOX
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:37:46 GMT
════════════════════════
⌗ Tags: #infosec #hacking #penetration_testing #bug_bounty #cybersecurity
Medium
Logic Flaw to Race Condition to Four Digit Bounty
Hey there, back again with another post! 😄
⤷ Title: Image XSS ATTACK on Exif.tools | Hacking exif.tools via image injection by CYBER KALKI #Livepoc
════════════════════════
𐀪 Author: ElonMuskTheAntichrist
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:22:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: ElonMuskTheAntichrist
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:22:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
Medium
Image XSS ATTACK on Exif.tools | Hacking exif.tools via image injection by CYBER KALKI #Livepoc
Image XSS ATTACK on Exif.tools | Hacking exif.tools via image injection by CYBER KALKI #Livepoc (Rewriting Deleted article originally published in oct 2025) I uncovered and demonstrated a …
⤷ Title: Akamai WAF Bypass: Escalating SSRF into Internal Port Scanning
════════════════════════
𐀪 Author: toast
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:06:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hackerone #bug_bounty_writeup #ethical_hacking
════════════════════════
𐀪 Author: toast
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:06:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hackerone #bug_bounty_writeup #ethical_hacking
Medium
Akamai WAF Bypass: Escalating SSRF into Internal Port Scanning
This issue came from an endpoint that looked completely harmless. It was a download API that fetched a URL on the server and returned the…
⤷ Title: Infinity Learning lab: Function’s Backdoor Route — Writeup
════════════════════════
𐀪 Author: Hubert
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #cloud_security #ctf_writeup #ctf #hacking #cybersecurity
════════════════════════
𐀪 Author: Hubert
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #cloud_security #ctf_writeup #ctf #hacking #cybersecurity
Medium
Infinity Learning lab: Function’s Backdoor Route — Writeup
This is a description of the steps I took to solve the Infinity Learning lab: Function’s Backdoor Route [1]. It is classified as a hard…
⤷ Title: Critical Authentication Bypass Vulnerability in GL.iNet GL-AXT1800 Router Firmware
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:00:05 GMT
════════════════════════
⌗ Tags: #zero_day_vulnerability #router #vpn #hacking
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:00:05 GMT
════════════════════════
⌗ Tags: #zero_day_vulnerability #router #vpn #hacking
Medium
Critical Authentication Bypass Vulnerability in GL.iNet GL-AXT1800 Router Firmware
Summary
⤷ Title: Authentication Bypass, Command Injection Vulnerability, and Race Condition in GL.iNet
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:59:53 GMT
════════════════════════
⌗ Tags: #mitre_attack #security #defcon #hacking #zero_day
════════════════════════
𐀪 Author: Aleksa Zatezalo
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:59:53 GMT
════════════════════════
⌗ Tags: #mitre_attack #security #defcon #hacking #zero_day
Medium
Authentication Bypass, Command Injection Vulnerability, and Race Condition in GL.iNet
⤷ Title: A Comprehensive Guide to Hooking Clients to BEEF and Stealing Passwords
════════════════════════
𐀪 Author: Vignesh R
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:32:47 GMT
════════════════════════
⌗ Tags: #passwords #hacking #password_stealing #beef #ethical_hacking
════════════════════════
𐀪 Author: Vignesh R
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:32:47 GMT
════════════════════════
⌗ Tags: #passwords #hacking #password_stealing #beef #ethical_hacking
Medium
A Comprehensive Guide to Hooking Clients to BEEF and Stealing Passwords
ARP spoofing & Man In The Middle Attacks Execution & Detection
⤷ Title: SecurityOnion — Installation on VMware [Home Lab]
════════════════════════
𐀪 Author: DeshmukhVinit
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:45:50 GMT
════════════════════════
⌗ Tags: #blue_team #information_security #defensive_security #infosec #cybersecurity
════════════════════════
𐀪 Author: DeshmukhVinit
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:45:50 GMT
════════════════════════
⌗ Tags: #blue_team #information_security #defensive_security #infosec #cybersecurity
Medium
SecurityOnion — Installation on VMware [Home Lab]
Security Onion is a powerful open-source platform for network security monitoring, intrusion detection, and log management, widely used by…
⤷ Title: 217,000+ VNC Attack Attempts Observed on a Public Honeypot in 10+ days
════════════════════════
𐀪 Author: berke bodur
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:41:12 GMT
════════════════════════
⌗ Tags: #network_security #infosec #threat_intelligence #cybersecurity #information_technology
════════════════════════
𐀪 Author: berke bodur
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:41:12 GMT
════════════════════════
⌗ Tags: #network_security #infosec #threat_intelligence #cybersecurity #information_technology
Medium
217,000+ VNC Attack Attempts Observed on a Public Honeypot in 10+ days
Exposing services directly to the internet still comes with significant risk, even today. To better understand real-world attack behavior…
⤷ Title: Android Pentesting — Part 1: Getting Started with a Vulnerable Android App
════════════════════════
𐀪 Author: Mscmkn
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:24:15 GMT
════════════════════════
⌗ Tags: #mobileapplicationsecurity #android_security #penetration_testing #reverse_engineering #cybersecurity
════════════════════════
𐀪 Author: Mscmkn
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:24:15 GMT
════════════════════════
⌗ Tags: #mobileapplicationsecurity #android_security #penetration_testing #reverse_engineering #cybersecurity
Medium
Android Pentesting — Part 1: Getting Started with a Vulnerable Android App
Android Pentesting Series
⤷ Title: HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough)
════════════════════════
𐀪 Author: Andrey Pautov
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:34:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #hexstrike #cursor #cybersecurity #ai
════════════════════════
𐀪 Author: Andrey Pautov
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:34:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #hexstrike #cursor #cybersecurity #ai
Medium
HexStrike + Cursor (MCP): From Single Target → Full Subnet Compromise (Lab PT Walkthrough)
A real end-to-end lab engagement: recon → credential discovery → share abuse → lateral movement → multi-host compromise → reporting
⤷ Title: Digital Travel App TripBFF Exposed Location Data Way Too Accurately
════════════════════════
𐀪 Author: Jonathan Leitschuh
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:50 GMT
════════════════════════
⌗ Tags: #information_security #security #travel #penetration_testing
════════════════════════
𐀪 Author: Jonathan Leitschuh
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:50 GMT
════════════════════════
⌗ Tags: #information_security #security #travel #penetration_testing
Medium
Digital Travel App TripBFF Exposed Location Data Way Too Accurately
TripBFF exposed recent live latitude & longitude data and birth date for every user on their platform
⤷ Title: CyberHeroes THM Writeup
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:31:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cyberheros_thm #exposed_javascript #broken_authentication #tryhackme
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:31:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cyberheros_thm #exposed_javascript #broken_authentication #tryhackme
Medium
CyberHeroes THM Writeup
Understanding Broken Authentication Through Exposed JavaScript Logic
⤷ Title: Snapped Phish-ing Line — TryHackMe Walkthrough | Romedix
════════════════════════
𐀪 Author: Romedix
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:11 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #ctf_writeup #tryhackme #red_team
════════════════════════
𐀪 Author: Romedix
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:02:11 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #ctf_writeup #tryhackme #red_team
Medium
Snapped Phish-ing Line — TryHackMe Walkthrough | Romedix
Introduction
⤷ Title: The Puppet Master Hack The Box Lab
════════════════════════
𐀪 Author: Mylescorey
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:59:05 GMT
════════════════════════
⌗ Tags: #osint_investigation #hackthebox #hackthebox_writeup #osint
════════════════════════
𐀪 Author: Mylescorey
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 13:59:05 GMT
════════════════════════
⌗ Tags: #osint_investigation #hackthebox #hackthebox_writeup #osint
Medium
The Puppet Master Hack The Box Lab
Challenge Scenario
⤷ Title: Comprehensive Open Redirect Methodology: From Discovery to Advanced Exploitation
════════════════════════
𐀪 Author: N0aziXss
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:55:29 GMT
════════════════════════
⌗ Tags: #ethical_hacking #open_redirect #bug_bounty #vulnerability #web_security
════════════════════════
𐀪 Author: N0aziXss
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:55:29 GMT
════════════════════════
⌗ Tags: #ethical_hacking #open_redirect #bug_bounty #vulnerability #web_security
Medium
Comprehensive Open Redirect Methodology: From Discovery to Advanced Exploitation
Subtitle: A Systematic Framework for Identifying, Verifying, and Exploiting Open Redirect Vulnerabilities
⤷ Title: Cyber Security: Threats, Vulnerabilities & Countermeasures
════════════════════════
𐀪 Author: Fiza saleem
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:40:48 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #ethical_hacking #online_safety
════════════════════════
𐀪 Author: Fiza saleem
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:40:48 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #ethical_hacking #online_safety
Medium
Cyber Security: Threats, Vulnerabilities & Countermeasures
Introduction:
⤷ Title: CVE-2025–63611: Stored Cross-Site Scripting(XSS) in Hostel Management System v2.1
════════════════════════
𐀪 Author: Tanush Kushwah
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:16:07 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #cve
════════════════════════
𐀪 Author: Tanush Kushwah
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 15:16:07 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #cve
Medium
CVE-2025–63611: Stored Cross-Site Scripting(XSS) in Hostel Management System v2.1
Web Application Description
⤷ Title: WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 22:40:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 22:40:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: US Man Jailed After FBI Traced 1,100 IP Addresses in Cyberstalking Case
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 17:39:16 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Cybersecurity #CyberStalking #FBI #IP Address #Spying
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 17:39:16 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Cybersecurity #CyberStalking #FBI #IP Address #Spying
Hackread
US Man Jailed After FBI Traced 1,100 IP Addresses in Cyberstalking Case
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread