⤷ Title: 2FA Bypass via OTP Reuse Across Multiple Authentication Flows
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
Medium
2FA Bypass via OTP Reuse Across Multiple Authentication Flows
Hello everyone, I’m Jeet. I used to hunt bugs regularly, but due to some personal reasons I couldn’t stay consistent for a while. Now I’m…
⤷ Title: Account Takeover using Improper Authorization in “Check Availability” Feature
════════════════════════
𐀪 Author: Ronak Patel
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:21:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #bug_bounty #account_takeover
════════════════════════
𐀪 Author: Ronak Patel
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:21:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #bug_bounty #account_takeover
Medium
Account Takeover using Improper Authorization in “Check Availability” Feature
Hello Guys!!!!
⤷ Title: Active Session Hijacking via Authentication session_id Exposed in URL
════════════════════════
𐀪 Author: Sohan
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:07:11 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #bug_bounty #api_penetration_testing #cybersecurity #security
════════════════════════
𐀪 Author: Sohan
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:07:11 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #bug_bounty #api_penetration_testing #cybersecurity #security
Medium
Active Session Hijacking via Authentication session_id Exposed in URL
Yo hackers! I’m back with another interesting bug write-up 😈🔥
Today’s issue is about session hijacking caused by an authentication…
Today’s issue is about session hijacking caused by an authentication…
⤷ Title: GraphQL Root Operation Types
════════════════════════
𐀪 Author: Shivam Bathla
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 05:55:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking #information_technology #graphql
════════════════════════
𐀪 Author: Shivam Bathla
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 05:55:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking #information_technology #graphql
Medium
GraphQL Root Operation Types
Let’s take a look at the fundamental operations that you get in GraphQL!
⤷ Title: Prompt Injection: Defenses Teams Actually Ship
════════════════════════
𐀪 Author: Vectorlane
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:00 GMT
════════════════════════
⌗ Tags: #prompt_injection_attack #llm_security #application_security #llmops #ai_agents_in_action
════════════════════════
𐀪 Author: Vectorlane
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:00 GMT
════════════════════════
⌗ Tags: #prompt_injection_attack #llm_security #application_security #llmops #ai_agents_in_action
Medium
Prompt Injection: Defenses Teams Actually Ship
Tool-using LLMs are powerful — and painfully easy to steer. Here’s the layered, real-world playbook teams are deploying to keep agents…
⤷ Title: Your Agent Has Git. Now It’s a Perimeter
════════════════════════
𐀪 Author: Hash Block
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:00 GMT
════════════════════════
⌗ Tags: #devops #llm_security #ai_agents_in_action #software_engineering #application_security
════════════════════════
𐀪 Author: Hash Block
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:00 GMT
════════════════════════
⌗ Tags: #devops #llm_security #ai_agents_in_action #software_engineering #application_security
Medium
Your Agent Has Git. Now It’s a Perimeter
Why tool access — not prompts — is the new boundary, and how to design Git-enabled agents that don’t turn your repo into an incident.
⤷ Title: H3C CVM auth bypass & information disclosure
════════════════════════
𐀪 Author: suicidal_teddy
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:48:18 GMT
════════════════════════
⌗ Tags: #zero_day_vulnerability #hacking #exploit #poc
════════════════════════
𐀪 Author: suicidal_teddy
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:48:18 GMT
════════════════════════
⌗ Tags: #zero_day_vulnerability #hacking #exploit #poc
Medium
H3C CVM auth bypass & information disclosure
Here is a narrative based on your findings.
⤷ Title: As always in every penetration testing engagements we start by reconnaissance and information…
════════════════════════
𐀪 Author: Cyb0rgBytes
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:01:04 GMT
════════════════════════
⌗ Tags: #hacking #ctf_walkthrough #pentesting #infosec #cybersecurity
════════════════════════
𐀪 Author: Cyb0rgBytes
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:01:04 GMT
════════════════════════
⌗ Tags: #hacking #ctf_walkthrough #pentesting #infosec #cybersecurity
Medium
As always in every penetration testing engagements we start by reconnaissance and information…
We can achieve that by using various of tools and techniques to obtain foothold on the target, by using enumeration, scanning and other…
⤷ Title: LOGICAL LIMITATIONS OF AI MODELS IN THREAT INTELLIGENCE
════════════════════════
𐀪 Author: Rakesh Krishnan
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:57:02 GMT
════════════════════════
⌗ Tags: #threat_intelligence #llm #artificial_intelligence #cybersecurity #infosec
════════════════════════
𐀪 Author: Rakesh Krishnan
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:57:02 GMT
════════════════════════
⌗ Tags: #threat_intelligence #llm #artificial_intelligence #cybersecurity #infosec
Medium
LOGICAL LIMITATIONS OF AI MODELS IN THREAT INTELLIGENCE
NOTE: This is an experimental overview of various Threat Intelligence parameters designed to evaluate the performance of AI Agents (LLM…
⤷ Title: TryHackMe SEC1 vs COMPTIA Sec+ vs HTB CJCA
════════════════════════
𐀪 Author: Motasem Hamdan
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:13:32 GMT
════════════════════════
⌗ Tags: #technology #tech #infosec #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Motasem Hamdan
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:13:32 GMT
════════════════════════
⌗ Tags: #technology #tech #infosec #tryhackme #cybersecurity
Medium
TryHackMe SEC1 vs COMPTIA Sec+ vs HTB CJCA
For decades, the path to a cybersecurity career was linear: buy a 600-page textbook, memorize port numbers and acronyms, pass a…
⤷ Title: Authentication and Authorization in 2026: A Practical Overview of the Technologies
════════════════════════
𐀪 Author: Anton Minin Baranovskii
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:12:38 GMT
════════════════════════
⌗ Tags: #authorization #access_control #product_design #infosec #authentication
════════════════════════
𐀪 Author: Anton Minin Baranovskii
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:12:38 GMT
════════════════════════
⌗ Tags: #authorization #access_control #product_design #infosec #authentication
Medium
Authentication and Authorization in 2026: A Practical Overview of the Technologies
Authentication and authorization are no longer just technical components. They define trust boundaries, risk distribution, and failure…
⤷ Title: Bypassing Disabled PHP Functions via File Upload (LD_PRELOAD Technique)
════════════════════════
𐀪 Author: Omarelsayedkhalef
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:45:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup #ctf #tryhackme #web_exploitation
════════════════════════
𐀪 Author: Omarelsayedkhalef
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:45:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup #ctf #tryhackme #web_exploitation
Medium
Bypassing Disabled PHP Functions via File Upload (LD_PRELOAD Technique)
Reconnaissance & Initial Access The assessment started with basic reconnaissance using Nmap, which revealed an HTTP service running on the…
⤷ Title: Monitoring AWS Logins
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:35:04 GMT
════════════════════════
⌗ Tags: #tryhackme #aws #tryhackme_writeup #tryhackme_walkthrough #aws_login
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:35:04 GMT
════════════════════════
⌗ Tags: #tryhackme #aws #tryhackme_writeup #tryhackme_walkthrough #aws_login
Medium
Monitoring AWS Logins
Explore AWS authentication, common IAM threats, and SIEM detection options.
⤷ Title: The Future of Cybersecurity Will Be Written by Hackers and Quantum Computers
════════════════════════
𐀪 Author: Darksynthhacker
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:48:15 GMT
════════════════════════
⌗ Tags: #ethical_hacking #artificial_intelligence #technology #quantum_computing #cybersecurity
════════════════════════
𐀪 Author: Darksynthhacker
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:48:15 GMT
════════════════════════
⌗ Tags: #ethical_hacking #artificial_intelligence #technology #quantum_computing #cybersecurity
Medium
The Future of Cybersecurity Will Be Written by Hackers and Quantum Computers
By [Thetrustedhacker] | Cybersecurity | Future Tech | Quantum | Ethical Hacking
⤷ Title: How OAuth 2.0 Actually Works Behind the Scenes
════════════════════════
𐀪 Author: Cynox Security LLP.
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:54 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #ethical_hacking #information_technology #web_development
════════════════════════
𐀪 Author: Cynox Security LLP.
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:54 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #ethical_hacking #information_technology #web_development
Medium
How OAuth 2.0 Actually Works Behind the Scenes
Authorization Code Flow — A Technical Deep Dive
⤷ Title: Why Quantum Computing Will Force Companies to Hire Professional Hackers
════════════════════════
𐀪 Author: Darksynthhacker
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:52 GMT
════════════════════════
⌗ Tags: #quantum_computing #future_of_security #technology #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Darksynthhacker
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:31:52 GMT
════════════════════════
⌗ Tags: #quantum_computing #future_of_security #technology #cybersecurity #ethical_hacking
Medium
Why Quantum Computing Will Force Companies to Hire Professional Hackers
Quantum computing isn’t a distant theory anymore.
⤷ Title: JWT in Spring Boot: Supporting Both Users and Services the Right Way
════════════════════════
𐀪 Author: Sriram Mahalingam
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:40:03 GMT
════════════════════════
⌗ Tags: #software_architecture #backend_development #api_security #spring_boot #jwt
════════════════════════
𐀪 Author: Sriram Mahalingam
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:40:03 GMT
════════════════════════
⌗ Tags: #software_architecture #backend_development #api_security #spring_boot #jwt
Medium
JWT in Spring Boot: Supporting Both Users and Services the Right Way
Why user tokens and service tokens are not the same — and how to design for both safely in Spring Boot
⤷ Title: Y Type Pneumatic Valve Exporters in the World Industry
════════════════════════
𐀪 Author: Reconvalves
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:08:00 GMT
════════════════════════
⌗ Tags: #typesy #recon #exporters #valve #pneumatic
════════════════════════
𐀪 Author: Reconvalves
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 07:08:00 GMT
════════════════════════
⌗ Tags: #typesy #recon #exporters #valve #pneumatic
Medium
Y Type Pneumatic Valve Exporters in the World Industry
The Y type pneumatic valve exporters are significant in providing credible flow control systems to the global industries. They are designed…
⤷ Title: From niche to necessity: global bug bounty adoption accelerates, led by the U.S.
════════════════════════
𐀪 Author: Eleanor Barlow
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 00:00:00 GMT
════════════════════════
⌗ Tags: #Business Insights
════════════════════════
𐀪 Author: Eleanor Barlow
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 00:00:00 GMT
════════════════════════
⌗ Tags: #Business Insights
Intigriti
From niche to necessity: global bug bounty adoption accelerates, led by the U.S.
Bug bounty programs have evolved from a niche security tactic into a core component of US defense strategies. Organizations, driven by higher security maturity, are increasingly using bug bounty to uncover complex vulnerabilities that traditional testing…
⤷ Title: Cross-Domain IDOR in Email Preferences Management via Reusable emailaddress Identifier
════════════════════════
𐀪 Author: Bavly Zaher
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 09:53:17 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #information_security #broken_access_control #idor #bug_bounty
════════════════════════
𐀪 Author: Bavly Zaher
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 09:53:17 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #information_security #broken_access_control #idor #bug_bounty
Medium
Cross-Domain IDOR in Email Preferences Management via Reusable emailaddress Identifier
🐦🔥 Platform Overview
⤷ Title: $XXX Privilege Escalation Vulnerability Led me to be Application admin
════════════════════════
𐀪 Author: Nyx0r
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 08:33:56 GMT
════════════════════════
⌗ Tags: #web_hacking #bug_bounty #privilege_escalation #cybersecurity #access_control
════════════════════════
𐀪 Author: Nyx0r
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 08:33:56 GMT
════════════════════════
⌗ Tags: #web_hacking #bug_bounty #privilege_escalation #cybersecurity #access_control
Medium
$XXX Privilege Escalation Vulnerability Led me to be Application admin
Hi Hackers, today we are gonna talk about a basic broken access control vulnerability i have found on a production-based closed project…