⤷ Title: findme — picoCTF Write-up | Finding a Flag Hidden in HTTP Redirects
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 05:38:07 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #redirection #cybersecurity #web_security
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 05:38:07 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #redirection #cybersecurity #web_security
Medium
findme — picoCTF Write-up | Finding a Flag Hidden in HTTP Redirects
Introduction
⤷ Title: From Finding Bugs to Getting CVEs: My Journey of How I Got 2 CVEs
════════════════════════
𐀪 Author: Aruvasaga chithan A
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 05:07:54 GMT
════════════════════════
⌗ Tags: #cve #ethical_hacking #bug_bounty #info_sec_writeups #cybersecurity
════════════════════════
𐀪 Author: Aruvasaga chithan A
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 05:07:54 GMT
════════════════════════
⌗ Tags: #cve #ethical_hacking #bug_bounty #info_sec_writeups #cybersecurity
Medium
From Finding Bugs to Getting CVEs: My Journey of How I Got 2 CVEs
Table of Contents
⤷ Title: Mr. Robot CTF Walkthrough | THM
════════════════════════
𐀪 Author: Kerolos Iskander (ker0los)
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 04:33:08 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #ethical_hacking #cybersecurity #mr_robot
════════════════════════
𐀪 Author: Kerolos Iskander (ker0los)
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 04:33:08 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #ethical_hacking #cybersecurity #mr_robot
Medium
Mr. Robot CTF Walkthrough | THM
Written by Kerolos Iskander | Jr. Penetration Tester
⤷ Title: Finding a $200 CRLF Injection Bug: A Walkthrough of Mozilla’s OAuth Redirect Flaw
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 07:36:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #hacking #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 07:36:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #hacking #bug_bounty #bug_bounty_tips
Medium
Finding a $200 CRLF Injection Bug: A Walkthrough of Mozilla’s OAuth Redirect Flaw
How a Researcher Spotted CRLF Injection in Bugzilla’s OAuth Endpoint
⤷ Title: How to Sell Exploits Without Going to Jail
════════════════════════
𐀪 Author: Owais
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 07:31:39 GMT
════════════════════════
⌗ Tags: #hacking #infosec #darkweb #exploit_development #bug_bounty
════════════════════════
𐀪 Author: Owais
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 07:31:39 GMT
════════════════════════
⌗ Tags: #hacking #infosec #darkweb #exploit_development #bug_bounty
Medium
How to Sell Exploits Without Going to Jail 🔓
You found a vulnerability. It’s real. It works. You have a solid proof of concept.
⤷ Title: My Input Wasn’t the Payload. It Was the Address.
════════════════════════
𐀪 Author: Adhamkhairy
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 07:01:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackerone #bugbounty_writeup #bug_bounty #pentesting
════════════════════════
𐀪 Author: Adhamkhairy
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 07:01:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackerone #bugbounty_writeup #bug_bounty #pentesting
Medium
My Input Wasn’t the Payload. It Was the Address.
The bug class where there’s nothing to filter, because you never sent anything to filter.
⤷ Title: Windows File History Bug Disrupts Data Backups
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 08:45:08 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #File History #Windows 10 #Windows 11
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 08:45:08 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #File History #Windows 10 #Windows 11
Daily CyberSecurity
Windows File History Bug Disrupts Data Backups
The routine September update released by Microsoft has already triggered numerous complications. While users have discovered several of these anomalies, the corporation has yet to officially ackno…
⤷ Title: One Hidden JSON Field Turned My User Ticket into an Admin Ticket
════════════════════════
𐀪 Author: arshiahex
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 09:03:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #mass_assignment #bug_bounty_tips
════════════════════════
𐀪 Author: arshiahex
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 09:03:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #mass_assignment #bug_bounty_tips
Medium
One Hidden JSON Field Turned My User Ticket into an Admin Ticket 🚨
Sometimes, the most interesting vulnerabilities are hidden in plain sight.
⤷ Title: One Missing await = Log In as Anyone: The Rocket.Chat Auth Bypass, Explained
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 08:20:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_tips #infosec #auth_bypass
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 08:20:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_tips #infosec #auth_bypass
Medium
One Missing await = Log In as Anyone: The Rocket.Chat Auth Bypass, Explained 🚨
In March 2026, GitHub Security Lab dropped three advisories on Rocket.Chat that expose a familiar security problem: re-implementing…
⤷ Title: They Allowed Five Image Formats. Four Were Pictures.
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #xss_attack #bug_bounty #security #pentesting #cybersecurity
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Tue, 22 Sep 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #xss_attack #bug_bounty #security #pentesting #cybersecurity
Medium
They Allowed Five Image Formats. Four Were Pictures.
The developer’s list said images only. SVG is XML, and the browser parses it as a document.