⤷ Title: Broken Access Control Is a Trust Problem
════════════════════════
𐀪 Author: Cleo
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:59:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #idor #bug_bounty #technology #information_security
════════════════════════
𐀪 Author: Cleo
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:59:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #idor #bug_bounty #technology #information_security
Medium
Broken Access Control Is a Trust Problem
How misplaced trust quietly breaks authorization
⤷ Title: A Tiny CORS Header That Quietly Undid Years of Security Work
════════════════════════
𐀪 Author: 1$ Mistake
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:27:45 GMT
════════════════════════
⌗ Tags: #cors #programming #bug_bounty #bugs #hacking
════════════════════════
𐀪 Author: 1$ Mistake
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:27:45 GMT
════════════════════════
⌗ Tags: #cors #programming #bug_bounty #bugs #hacking
Medium
A Tiny CORS Header That Quietly Undid Years of Security Work
On a Friday afternoon, a developer pushed a tiny change to a config file. It was the kind of update nobody expects to matter — a single…
⤷ Title: Everything About Cloud Bucket Hacking ( S3 & GCS & Azure & Firebase )
════════════════════════
𐀪 Author: Anas NadY
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:49:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty_writeup #cybersecurity #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Anas NadY
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:49:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty_writeup #cybersecurity #bug_bounty_tips #bug_bounty
Medium
Everything About Cloud Bucket Hacking ( S3 & GCS & Azure & Firebase )
Hunting the Big 4: A Complete Guide to Cloud Bucket Hacking
⤷ Title: Local File Inclusion(LFI) Vulnerability
════════════════════════
𐀪 Author: Md. Raihan
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:43:40 GMT
════════════════════════
⌗ Tags: #lfi_vulnerability #bug_bounty #lfi #ethical_hacking #pentesting
════════════════════════
𐀪 Author: Md. Raihan
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:43:40 GMT
════════════════════════
⌗ Tags: #lfi_vulnerability #bug_bounty #lfi #ethical_hacking #pentesting
Medium
Local File Inclusion(LFI) Vulnerability
What is LFI Vulnerability?
⤷ Title: Race condition leading to multiple refunds and cash re
════════════════════════
𐀪 Author: Excessium
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 11:58:56 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #race_condition
════════════════════════
𐀪 Author: Excessium
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 11:58:56 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #race_condition
Medium
Race condition leading to multiple refunds and cash re
In the name of Allah, the Most Merciful, the Most Compassionate.
⤷ Title: HTML Smuggling
════════════════════════
𐀪 Author: NITYA NAND JHA(Shunux)
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:46:18 GMT
════════════════════════
⌗ Tags: #hacking #red_teaming #application_security #html_smuggling #cybersecurity
════════════════════════
𐀪 Author: NITYA NAND JHA(Shunux)
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:46:18 GMT
════════════════════════
⌗ Tags: #hacking #red_teaming #application_security #html_smuggling #cybersecurity
Medium
HTML Smuggling
For a long time, we have relied on firewalls, secure web gateways (SWGs), and email scanners to inspect traffic “on the wire.” If a user…
⤷ Title: OSWE Hazırlık İlk Makine — SecureCode WriteUp
════════════════════════
𐀪 Author: OnurDemir-Dev
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:16:17 GMT
════════════════════════
⌗ Tags: #application_security #oswe #ctf #cybersecurity #ctf_writeup
════════════════════════
𐀪 Author: OnurDemir-Dev
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:16:17 GMT
════════════════════════
⌗ Tags: #application_security #oswe #ctf #cybersecurity #ctf_writeup
Medium
OSWE Hazırlık İlk Makine — SecureCode WriteUp
Herkese merhaba, şu sıralar OSWE sertifikasının sınavına hazırlandığım bu dönemde çözebileceğim makineler arıyordum. Başlangıç olarak da…
⤷ Title: Hackers Exploiting VMware ESXi for gaining RCE
════════════════════════
𐀪 Author: Akchhat
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:46:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #hypervisor_security #active_directory #security_research #vmware_esxi
════════════════════════
𐀪 Author: Akchhat
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:46:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #hypervisor_security #active_directory #security_research #vmware_esxi
Medium
Hackers Exploiting VMware ESXi for gaining RCE
Hi Everyone and welcome to my first Blog post which I am writing as I discovered a Topic which hasn’t been discussed in the wild. I’m…
⤷ Title: MOST COMMON AND UNCOMMON VULNERABILITIES I HAVE UNCOVERED IN SOME E-COMMERCE WEBSITES
════════════════════════
𐀪 Author: Maxwell
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:38:17 GMT
════════════════════════
⌗ Tags: #ecommerce #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Maxwell
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:38:17 GMT
════════════════════════
⌗ Tags: #ecommerce #cybersecurity #penetration_testing
Medium
MOST COMMON AND UNCOMMON VULNERABILITIES I HAVE UNCOVERED IN SOME E-COMMERCE WEBSITES
After building your beautiful E-commerce website, the next question that comes to your mind should be; “Is this website secured/strong…
⤷ Title: Padelify — THM Writeup
════════════════════════
𐀪 Author: Avyukt Security
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:20:02 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #penetration_testing #cybersecurity #ctf_walkthrough
════════════════════════
𐀪 Author: Avyukt Security
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:20:02 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #penetration_testing #cybersecurity #ctf_walkthrough
Medium
Padelify — THM Writeup
By: Kavin Jindal (@Klevr)
⤷ Title: Network Traffic Basics Walkthrough | Tryhackme ( Bahasa Indonesia ) FULL GUIDE
════════════════════════
𐀪 Author: Mat3s
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:17:58 GMT
════════════════════════
⌗ Tags: #gui̇de #red_team #networking #tryhackme #bahasa_indonesia
════════════════════════
𐀪 Author: Mat3s
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:17:58 GMT
════════════════════════
⌗ Tags: #gui̇de #red_team #networking #tryhackme #bahasa_indonesia
Medium
Network Traffic Basics Walkthrough | Tryhackme ( Bahasa Indonesia ) FULL GUIDE
Tryhackme Rooms <- Click here to join this room
⤷ Title: TryHackMe Poster Room — Full Walkthrough (PostgreSQL to Root)
════════════════════════
𐀪 Author: Md. Anis Molla
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:32:10 GMT
════════════════════════
⌗ Tags: #postgresql #tryhackme #posters #privilege_escalation #easy
════════════════════════
𐀪 Author: Md. Anis Molla
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:32:10 GMT
════════════════════════
⌗ Tags: #postgresql #tryhackme #posters #privilege_escalation #easy
Medium
TryHackMe Poster Room (PostgreSQL to Root)
🧠 ROOM FULL WALKTHROUGH
⤷ Title: HexStrike + Cursor for OSINT: From One Email to a Full Exposure Map
════════════════════════
𐀪 Author: Andrey Pautov
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:12:00 GMT
════════════════════════
⌗ Tags: #osint #cybersecurity #ai #hexstrike #ethical_hacking
════════════════════════
𐀪 Author: Andrey Pautov
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 12:12:00 GMT
════════════════════════
⌗ Tags: #osint #cybersecurity #ai #hexstrike #ethical_hacking
Medium
HexStrike + Cursor for OSINT: From One Email to a Full Exposure Map
Why OSINT is harder than “hack the box,” what an AI-assisted workflow looks like in practice, and how to publish a real report without…
⤷ Title: Your Node.js API Isn’t Secure Yet: JWT vs OAuth2 Done Right
════════════════════════
𐀪 Author: Syntal
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:02:51 GMT
════════════════════════
⌗ Tags: #oauth2 #api_security #jwt #nodejs #backend_development
════════════════════════
𐀪 Author: Syntal
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 13:02:51 GMT
════════════════════════
⌗ Tags: #oauth2 #api_security #jwt #nodejs #backend_development
Medium
Your Node.js API Isn’t Secure Yet: JWT vs OAuth2 Done Right
Learn when to use JWT vs OAuth2, how to implement both safely in Node.js, and the gotchas that quietly break “secure” APIs in production.
⤷ Title: This Endpoint Was “Read-Only” — Until I Read Everything
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 15:28:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #infosec #hacking #bug_bounty
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 15:28:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #infosec #hacking #bug_bounty
Medium
This Endpoint Was “Read-Only” — Until I Read Everything 📖🚨
Hey there!😁
⤷ Title: Zero Click ATO via Systemic Mass Assignment: The Phantom Hand
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:39:33 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #cybersecurity #infosec #ethical_hacking
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:39:33 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #cybersecurity #infosec #ethical_hacking
Medium
Zero Click ATO via Systemic Mass Assignment: The Phantom Hand
Zero Click ATO via Systemic Mass Assignment: The Phantom Hand Most researchers? They’re just scrolling. They see some random JSON field in a proxy log that isn’t in the UI and think, “Whatever …
⤷ Title: Building the Ultimate Android Bug Bounty Lab: The Network Nightmare (Part 3)
════════════════════════
𐀪 Author: Rezaul Hasan
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:21:46 GMT
════════════════════════
⌗ Tags: #android_pentesting #mobsf #bug_bounty #pentesting #android
════════════════════════
𐀪 Author: Rezaul Hasan
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:21:46 GMT
════════════════════════
⌗ Tags: #android_pentesting #mobsf #bug_bounty #pentesting #android
Medium
Building the Ultimate Android Bug Bounty Lab: The Network Nightmare (Part 3)
In Part 1, we built the foundation: a lightning-fast Genymotion emulator linked to a Dockerized MobSF instance. In Part 2, we became…
⤷ Title: BUSINESS LOGIC ISSUES
════════════════════════
𐀪 Author: Cybernight
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 15:54:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #hacking #cybersecurity
════════════════════════
𐀪 Author: Cybernight
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 15:54:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #hacking #cybersecurity
Medium
BUSINESS LOGIC ISSUES
Business logic issues have become increasingly common in cybersecurity. They arise when a company makes assumptions about how users will…
⤷ Title: Furhire Writeup (BugForge)
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 15:43:16 GMT
════════════════════════
⌗ Tags: #hacking #ctf #ctf_writeup #cybersecurity #information_technology
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 15:43:16 GMT
════════════════════════
⌗ Tags: #hacking #ctf #ctf_writeup #cybersecurity #information_technology
Medium
Furhire Writeup (BugForge)
🍺 Quick message to readers: if my writeups help you, please consider a small donation to my buymeacoffee link here. This is not required…
⤷ Title: Mirror-Dog:A TCP stream replay attack analysis and exploitation verification tool.
════════════════════════
𐀪 Author: Мартин.
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:05:12 GMT
════════════════════════
⌗ Tags: #s_h4ck13 #linux #hacking #pentesting
════════════════════════
𐀪 Author: Мартин.
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:05:12 GMT
════════════════════════
⌗ Tags: #s_h4ck13 #linux #hacking #pentesting
Medium
Mirror-Dog:A TCP stream replay attack analysis and exploitation verification tool.
Sniffs and mirrors authorized TCP sessions, reconstructs payloads, and automatically identifies and highlights sensitive data.
⤷ Title: How I Passed the eMAPT Certification (January 2026)
════════════════════════
𐀪 Author: Marco Alfan
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:07:06 GMT
════════════════════════
⌗ Tags: #certification #cybersecurity #mobile_security #penetration_testing #appsec
════════════════════════
𐀪 Author: Marco Alfan
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 14:07:06 GMT
════════════════════════
⌗ Tags: #certification #cybersecurity #mobile_security #penetration_testing #appsec
Medium
How I Passed the eMAPT Certification (January 2026)
INE Security’s Mobile Application Penetration Tester (eMAPT) — Issued January 10, 2026