⤷ Title: Authorization Failures in Authenticated APIs A Practical Analysis
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:02:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #api #bug_bounty #web3
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:02:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #api #bug_bounty #web3
Medium
Authorization Failures in Authenticated APIs A Practical Analysis
Authorization bugs rarely announce themselves. They do not crash applications or trigger obvious errors. Most of the time everything…
⤷ Title: Using MITMf Against Real Networks: A Comprehensive Guide
════════════════════════
𐀪 Author: Vignesh R
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:33:00 GMT
════════════════════════
⌗ Tags: #spoofing #mitm #man_in_the_middle_attack #hacking #mitm_attacks
════════════════════════
𐀪 Author: Vignesh R
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:33:00 GMT
════════════════════════
⌗ Tags: #spoofing #mitm #man_in_the_middle_attack #hacking #mitm_attacks
Medium
Using MITMf Against Real Networks: A Comprehensive Guide
ARP spoofing & Man In The Middle Attacks Execution & Detection
⤷ Title: Why Crypto Crime Victims Prefer to Stay Silent
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:22:46 GMT
════════════════════════
⌗ Tags: #cryptocurrency #bitcoin #cybercrime #cybersecurity #hacking
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:22:46 GMT
════════════════════════
⌗ Tags: #cryptocurrency #bitcoin #cybercrime #cybersecurity #hacking
Medium
Why Crypto Crime Victims Prefer to Stay Silent
The cryptocurrency revolution promised financial freedom and anonymity, but it has also given rise to a shadow industry of fraud that…
⤷ Title: CTF Writeup: Breaking the Cave Lab through LFI and SUID Misconfigurations
════════════════════════
𐀪 Author: Ankush Prasad Sah
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:21:43 GMT
════════════════════════
⌗ Tags: #red_team #tryhackme #web_app_pentesting #pentesting #hacking
════════════════════════
𐀪 Author: Ankush Prasad Sah
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:21:43 GMT
════════════════════════
⌗ Tags: #red_team #tryhackme #web_app_pentesting #pentesting #hacking
Medium
CTF Writeup: Breaking the Cave Lab through LFI and SUID Misconfigurations
Hacking the “Cave”: A Web-Application Penetration Testing Writeup
⤷ Title: UART Debug Isn’t Harmless: Serial Port Privilege Escalation in Hikvision DVRs
════════════════════════
𐀪 Author: Aaronjjose
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:03:04 GMT
════════════════════════
⌗ Tags: #hardware #hikvision #cve #electronics #hacking
════════════════════════
𐀪 Author: Aaronjjose
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:03:04 GMT
════════════════════════
⌗ Tags: #hardware #hikvision #cve #electronics #hacking
Medium
UART Debug Isn’t Harmless: Serial Port Privilege Escalation in Hikvision DVRs
Introduction
⤷ Title: Cracking the Split-APK Code
════════════════════════
𐀪 Author: bineeg
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:25:47 GMT
════════════════════════
⌗ Tags: #android_pentesting #infosec #infosec_write_ups #decompile
════════════════════════
𐀪 Author: bineeg
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:25:47 GMT
════════════════════════
⌗ Tags: #android_pentesting #infosec #infosec_write_ups #decompile
Medium
Cracking the Split-APK Code
My Name is Bineeg, and this time I want to discuss an Android application pentest hurdle I have faced.
⤷ Title: A 2009 PowerPoint Bug Is Back in 2026: Why “Old CVEs” Still Beat Modern Defenses
════════════════════════
𐀪 Author: Suleiman Tawil
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:14:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #phishing #microsoft_office #infosec #malware
════════════════════════
𐀪 Author: Suleiman Tawil
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:14:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #phishing #microsoft_office #infosec #malware
Medium
A 2009 PowerPoint Bug Is Back in 2026: Why “Old CVEs” Still Beat Modern Defenses
A weird thing happened in January 2026: a PowerPoint bug from 2009 showed up again on a government “actively exploited” list.
⤷ Title: Nmap: Setup, Core Scans, and Practical Use Cases
════════════════════════
𐀪 Author: Little_Sun4lower
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:22:07 GMT
════════════════════════
⌗ Tags: #penetration_testing #cyber_security_assessment #nmap #cybersecurity #network_security
════════════════════════
𐀪 Author: Little_Sun4lower
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:22:07 GMT
════════════════════════
⌗ Tags: #penetration_testing #cyber_security_assessment #nmap #cybersecurity #network_security
Medium
Nmap: Setup, Core Scans, and Practical Use Cases
Nmap (Network Mapper) is an open-source tool used to discover hosts and services on a network. It answers two fundamental questions in…
⤷ Title: [HackTheBox — Machine] Postman (Blind Writeup)
════════════════════════
𐀪 Author: 0xr35p3c7
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:41:46 GMT
════════════════════════
⌗ Tags: #red_team #penetration_testing
════════════════════════
𐀪 Author: 0xr35p3c7
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:41:46 GMT
════════════════════════
⌗ Tags: #red_team #penetration_testing
⤷ Title: Intermediate Nmap— TryHackMe CTF Walkthrough
════════════════════════
𐀪 Author: Karim Hesham
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:09:00 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme
════════════════════════
𐀪 Author: Karim Hesham
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:09:00 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme
Medium
Intermediate Nmap— TryHackMe CTF Walkthrough
Can you combine your great nmap skills with other tools to log in to this machine?
⤷ Title: API Security Across Generations: From Traditional APIs to MCP Servers
════════════════════════
𐀪 Author: Gajanan Tayde
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:05:22 GMT
════════════════════════
⌗ Tags: #api #rest_api #api_security #api_development #owasp_api_security_top_10
════════════════════════
𐀪 Author: Gajanan Tayde
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:05:22 GMT
════════════════════════
⌗ Tags: #api #rest_api #api_security #api_development #owasp_api_security_top_10
Medium
API Security Across Generations: From Traditional APIs to MCP Servers
There was a time when securing an application meant securing a screen. You worried about login pages, form validation, and maybe a firewall…
⤷ Title: How I Lost My Entire $450,000 Crypto Portfolio to a Phishing Scam on Twitter
════════════════════════
𐀪 Author: Ghosted Coins
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:02:53 GMT
════════════════════════
⌗ Tags: #phishing #xs #crypto #twitter #scam
════════════════════════
𐀪 Author: Ghosted Coins
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 14:02:53 GMT
════════════════════════
⌗ Tags: #phishing #xs #crypto #twitter #scam
Medium
How I Lost My Entire $450,000 Crypto Portfolio to a Phishing Scam on Twitter
I never imagined that a simple click could wipe out everything I had worked for — my entire $450,000 crypto portfolio vanished in minutes…
⤷ Title: SSRF in PDF Generators
════════════════════════
𐀪 Author: Fatimahasan
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:36:38 GMT
════════════════════════
⌗ Tags: #ssrf #web_app_pentesting #pentesting #web_application_security
════════════════════════
𐀪 Author: Fatimahasan
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 15:36:38 GMT
════════════════════════
⌗ Tags: #ssrf #web_app_pentesting #pentesting #web_application_security
Medium
SSRF in PDF Generators
PDF generators are widely used in modern web applications to automatically create documents such as invoices, receipts, tickets, reports…
⤷ Title: Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 20:58:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 20:58:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Byaku: Automation of recon for bug hunting and vibe coding
════════════════════════
𐀪 Author: Alberto Villasante
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:40:42 GMT
════════════════════════
⌗ Tags: #reconnaissance #bug_bounty #pentesting
════════════════════════
𐀪 Author: Alberto Villasante
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:40:42 GMT
════════════════════════
⌗ Tags: #reconnaissance #bug_bounty #pentesting
Medium
Byaku: Automation of recon for bug hunting and vibe coding
As usual, even though I hate it, it’s been a long time since my last post. In the same vein, I’m not here to “reinvent” the wheel. I’m just…
⤷ Title: Soft-Fail Security Tips That Protect PHP Without Breaking UX
════════════════════════
𐀪 Author: Asian Digital Hub
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:42:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #php #php_development #backend_development #application_security
════════════════════════
𐀪 Author: Asian Digital Hub
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:42:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #php #php_development #backend_development #application_security
Medium
Soft-Fail Security Tips That Protect PHP Without Breaking UX
Security disasters rarely arrive with sirens.
⤷ Title: How I Hacked My College’s Website and Found a CVE Affecting 100+ Institutions across India
════════════════════════
𐀪 Author: Mohammed Afnaan Ahmed
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:47:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #cve #information_security #security
════════════════════════
𐀪 Author: Mohammed Afnaan Ahmed
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:47:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #cve #information_security #security
Medium
How I Hacked My College’s Website and Found a CVE Affecting 100+ Institutions across India
Disclaimer: This research was conducted responsibly, in good faith, and coordinated through CERT/CC. No sensitive details, exploit…
⤷ Title: DOM XSS Using jQuery Selector & hashchange — When # Becomes Dangerous(PortSwigger lab 6)
════════════════════════
𐀪 Author: Sanjivani Dobhal
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:27:07 GMT
════════════════════════
⌗ Tags: #hacking #web_penetration_testing #portswigger_lab #portswigger
════════════════════════
𐀪 Author: Sanjivani Dobhal
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:27:07 GMT
════════════════════════
⌗ Tags: #hacking #web_penetration_testing #portswigger_lab #portswigger
Medium
DOM XSS Using jQuery Selector & hashchange — When # Becomes Dangerous(PortSwigger lab 6)
For a long time, I thought XSS needed input fields or query parameters.
⤷ Title: Mandiant Attack Cycle Nedir? Siber Saldırıların Adım Adım İncelenmesi
════════════════════════
𐀪 Author: Arda Derya
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 16:50:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
════════════════════════
𐀪 Author: Arda Derya
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 16:50:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
Medium
Mandiant Attack Cycle Nedir? Siber Saldırıların Adım Adım İncelenmesi
Mandiant Attack Cycle bir siber saldırganın hedef sisteme ilk girişi yapmasından başlayarak hedef üzerinde kalıcı hale gelmesine ve…
⤷ Title: You wouldn’t wanna escape this security ni8mare: Exploiting n8n CVE-2026–21858 & CVE-2025–68613
════════════════════════
𐀪 Author: Sachin Verlekar
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 16:42:57 GMT
════════════════════════
⌗ Tags: #exploit #penetration_testing #cybersecurity #information_security #ethical_hacking
════════════════════════
𐀪 Author: Sachin Verlekar
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 16:42:57 GMT
════════════════════════
⌗ Tags: #exploit #penetration_testing #cybersecurity #information_security #ethical_hacking
Medium
You wouldn’t wanna escape this security ni8mare: Exploiting n8n CVE-2026–21858 & CVE-2025–68613
What started as quiet reports in November has now turned into a Ni8mare, as n8n rushes out security updates with potentially severe…
⤷ Title: Dig Dug
════════════════════════
𐀪 Author: Karim Hesham
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:05:15 GMT
════════════════════════
⌗ Tags: #tryhackme #security #tryhackme_walkthrough #tryhackme_writeup #cybersecurity
════════════════════════
𐀪 Author: Karim Hesham
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 17:05:15 GMT
════════════════════════
⌗ Tags: #tryhackme #security #tryhackme_walkthrough #tryhackme_writeup #cybersecurity
Medium
Dig Dug — TryHackMe CTF Challenge Walkthrough
Turns out this machine is a DNS server — it’s time to get your shovels out!