⤷ Title: How a CORS Misconfiguration Exposed Sensitive Data Across Multiple GraphQL Queries
════════════════════════
𐀪 Author: yOnly
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 15:52:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cors #cybersecurity #graphql
════════════════════════
𐀪 Author: yOnly
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 15:52:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cors #cybersecurity #graphql
Medium
How a CORS Misconfiguration Exposed Sensitive Data Across Multiple GraphQL Queries
Bug bounty hunting has a funny way of turning something that looks completely ordinary into something much more interesting.
⤷ Title: AI Agents Have a Token Problem: When Valid Access Becomes Dangerous
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 16:45:30 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #ai #agents #information_security
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 16:45:30 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #ai #agents #information_security
Medium
AI Agents Have a Token Problem: When Valid Access Becomes Dangerous
NIST and CISA are tightening token security, but AI agents expose a deeper problem: a valid token does not mean a valid action.
⤷ Title: How I Found an Undocumented GraphQL Endpoint Leaking Home Addresses of French Company Owners (EUR…
════════════════════════
𐀪 Author: anshh.bohara
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 16:10:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bounties
════════════════════════
𐀪 Author: anshh.bohara
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 16:10:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bounties
Medium
How I Found an Undocumented GraphQL Endpoint Leaking Home Addresses of French Company Owners (EUR 1,000 Bounty)
The documented unauthenticated endpoint had 1 query. The undocumented one had 7 queries and 7 mutations. One of those queries returned…
⤷ Title: Resolve Microsoft Excel Copy Paste Issues Now
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:45:47 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #Microsoft Excel #software update
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:45:47 +0000
════════════════════════
⌗ Tags: #Windows #bug fix #Microsoft Excel #software update
Daily CyberSecurity
Resolve Microsoft Excel Copy Paste Issues Now
Earlier, the routine September 2026 update released by Microsoft caused multiple unexpected issues in Excel. For many office workers, this spreadsheet application remains a critically essential da…
⤷ Title: Password Reset Tokens That Never Die: Testing Invalidation, Not Just Generation
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:50:08 GMT
════════════════════════
⌗ Tags: #weak_password_recovery #session_expiration #password_reset_token #bug_bounty
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:50:08 GMT
════════════════════════
⌗ Tags: #weak_password_recovery #session_expiration #password_reset_token #bug_bounty
Medium
Password Reset Tokens That Never Die: Testing Invalidation, Not Just Generation
CWE-640: Weak Password Recovery Mechanism CWE-613: Insufficient Session Expiration CVSS 3.1: 7.4 (High) —…
⤷ Title: Broken Session Revocation: Proving That Logout Doesn’t Actually Log You Out
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:49:42 GMT
════════════════════════
⌗ Tags: #session_expiration #improper_authentication #bug_bounty #broken_session_revocation
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:49:42 GMT
════════════════════════
⌗ Tags: #session_expiration #improper_authentication #bug_bounty #broken_session_revocation
Medium
Broken Session Revocation: Proving That Logout Doesn’t Actually Log You Out
CWE-613: Insufficient Session Expiration CWE-287: Improper Authentication CVSS 3.1: 8.1 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
⤷ Title: $7,200 for One Request, Thousands of Guesses: Brute-Forcing MFA Through GraphQL Batching
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 18:56:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #hacking #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 18:56:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #hacking #bug_bounty_tips #bug_bounty
Medium
$7,200 for One Request, Thousands of Guesses: Brute-Forcing MFA Through GraphQL Batching
Rate limiting is one of those controls that looks solid in a screenshot and falls apart the moment you understand what it’s actually…
⤷ Title: How a Silent Websocket Led Me to Unauthenticated Uploads on a University’s Exam Platform
════════════════════════
𐀪 Author: Priyansh
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 17:55:46 GMT
════════════════════════
⌗ Tags: #bug_bounty #growth_hacking #hacking #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Priyansh
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 17:55:46 GMT
════════════════════════
⌗ Tags: #bug_bounty #growth_hacking #hacking #bug_bounty_tips #bug_bounty_writeup
Medium
The Anonymous 5-GB File Host That Almost Wasn’t: How a Silent Websocket Led Me to Unauthenticated Uploads on a University’s Exam…
Intro: The Wall
⤷ Title: The Report Nobody Read (And What I Learned From It)
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:51:01 GMT
════════════════════════
⌗ Tags: #medium #learning #bug_bounty_writeup #cybersecurity #writing
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 19:51:01 GMT
════════════════════════
⌗ Tags: #medium #learning #bug_bounty_writeup #cybersecurity #writing
Medium
The Report Nobody Read (And What I Learned From It)
A few years into my career as a security engineer, I finished what I thought was the best pentest of my life. I had chained three separate…
⤷ Title: The Anonymous 5-GB File Host That Almost Wasn’t: How a Silent Websocket Led Me to Unauthenticated…
════════════════════════
𐀪 Author: Priyansh
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 17:55:46 GMT
════════════════════════
⌗ Tags: #bug_bounty #growth_hacking #hacking #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Priyansh
════════════════════════
ⴵ Time: Sun, 20 Sep 2026 17:55:46 GMT
════════════════════════
⌗ Tags: #bug_bounty #growth_hacking #hacking #bug_bounty_tips #bug_bounty_writeup
Medium
How a Silent Websocket Led Me to Unauthenticated Uploads on a University’s Exam Platform
Intro: The Wall