⤷ Title: Entra ID Monitoring Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 17:34:33 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #entra_id #tryhackme_walkthrough #blue_team #tryhackme
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 17:34:33 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #entra_id #tryhackme_walkthrough #blue_team #tryhackme
Medium
Entra ID Monitoring Walkthrough Notes | TryHackMe
Simple Splunk queries to detect Entra ID attacks and threats
⤷ Title: Walkthrough: Hacking An Enterprise Network
════════════════════════
𐀪 Author: Daryl Brooks
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 17:27:13 GMT
════════════════════════
⌗ Tags: #ssh #pivoting #ethical_hacking #https #wireshark
════════════════════════
𐀪 Author: Daryl Brooks
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 17:27:13 GMT
════════════════════════
⌗ Tags: #ssh #pivoting #ethical_hacking #https #wireshark
Medium
Walkthrough: Hacking An Enterprise Network
In this project, I put on my “black hat” and simulate a data breach of a fake company’s network by exploiting several vulnerabilities. My…
⤷ Title: SQL Injection: The Cause, Attack Types & The Fixes
════════════════════════
𐀪 Author: Cbrnex
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 18:52:22 GMT
════════════════════════
⌗ Tags: #sqli #web_security #cybersecurity
════════════════════════
𐀪 Author: Cbrnex
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 18:52:22 GMT
════════════════════════
⌗ Tags: #sqli #web_security #cybersecurity
Medium
SQL Injection: The Cause, Attack Types & The Fixes
I’ve spent countless hours exploiting SQL injection flaws, and it always comes down to one stupid-simple mistake: pasting user input…
⤷ Title: SQL Injection Attack: Querying Database Type & Version (Oracle) — PortSwigger Lab Write-up
════════════════════════
𐀪 Author: shivam sharma
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 17:38:37 GMT
════════════════════════
⌗ Tags: #portswigger_lab #cybersecurity #sql_injection
════════════════════════
𐀪 Author: shivam sharma
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 17:38:37 GMT
════════════════════════
⌗ Tags: #portswigger_lab #cybersecurity #sql_injection
Medium
SQL Injection Attack: Querying Database Type & Version (Oracle) — PortSwigger Lab Write-up
Introduction
⤷ Title: Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:46:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:46:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: 54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:22:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:22:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
════════════════════════
𐀪 Author: McCaulay Hudson
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:21:07 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: McCaulay Hudson
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:21:07 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
A long, long time ago, in a land free of binary exploit mitigations, when Unix still roamed the Earth, there lived a pre-authentication Telnetd vulnerability.
In fact, this vulnerability was born so long ago (way back in 1994) that it may even be older than…
In fact, this vulnerability was born so long ago (way back in 1994) that it may even be older than…
⤷ Title: The Developer Called Me: How an IDOR Leaked 403 Users and Led to Account Takeover
════════════════════════
𐀪 Author: Gaurang Jethva
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:24:20 GMT
════════════════════════
⌗ Tags: #bug_bounty #information_security #cybersecurity #software_development #hacking
════════════════════════
𐀪 Author: Gaurang Jethva
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:24:20 GMT
════════════════════════
⌗ Tags: #bug_bounty #information_security #cybersecurity #software_development #hacking
Medium
The Developer Called Me: How an IDOR Leaked 403 Users and Led to Account Takeover
Short story
⤷ Title: Client security, runtime tampering, and why SPKI and TLS do not prove trusted execution
════════════════════════
𐀪 Author: Mark Solo
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:36:57 GMT
════════════════════════
⌗ Tags: #application_security #information_security #mobile_app_architecture #ssl_pinning #cybersecurity
════════════════════════
𐀪 Author: Mark Solo
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:36:57 GMT
════════════════════════
⌗ Tags: #application_security #information_security #mobile_app_architecture #ssl_pinning #cybersecurity
Medium
Client security, runtime tampering, and why SPKI and TLS do not prove trusted execution
SPKI pinning and TLS can prove that a mobile app reached the correct backend over a protected channel. They cannot prove that the client…
⤷ Title: DAST on Any Infrastructure: Open Source Dynamic Scanning with a Reproducible Test Environment
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:09:00 GMT
════════════════════════
⌗ Tags: #application_security
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:09:00 GMT
════════════════════════
⌗ Tags: #application_security
Medium
DAST on Any Infrastructure: Open Source Dynamic Scanning with a Reproducible Test Environment
The pipeline from post one catches a lot. SAST finds insecure code patterns before they ship. Dependency scanning finds vulnerable…
⤷ Title: Writing Semgrep Rules That Actually Matter
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:07:57 GMT
════════════════════════
⌗ Tags: #information_security #application_security
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:07:57 GMT
════════════════════════
⌗ Tags: #information_security #application_security
Medium
Writing Semgrep Rules That Actually Matter
Community Semgrep rulesets are a good starting point. The OWASP Top 10 pack, the secrets detection rules, the language-specific security…
⤷ Title: Spotting a Malicious Workday Sign‑In: A Practical Breakdown
════════════════════════
𐀪 Author: Vonte Sewell
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:53:00 GMT
════════════════════════
⌗ Tags: #hacking #microsoft #cybersecurity #security #cloud_computing
════════════════════════
𐀪 Author: Vonte Sewell
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:53:00 GMT
════════════════════════
⌗ Tags: #hacking #microsoft #cybersecurity #security #cloud_computing
Medium
Spotting a Malicious Workday Sign‑In: A Practical Breakdown
A would-be credential stuffing thwarted
⤷ Title: The Spy Who Checked Into Paradise
════════════════════════
𐀪 Author: O. J. Okpabi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:32:19 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #hacking #true_crime #technology
════════════════════════
𐀪 Author: O. J. Okpabi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:32:19 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #hacking #true_crime #technology
Medium
The Spy Who Checked Into Paradise
How The FBI Caught A Russian Hacker Sleeping On A Thai Beach
⤷ Title: Assessment Methodologies: Enumeration CTF 1 (2026)
════════════════════════
𐀪 Author: Vanshaj Kumar
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:08:33 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #ejpt #penetration_testing #ethical_hacking
════════════════════════
𐀪 Author: Vanshaj Kumar
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:08:33 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #ejpt #penetration_testing #ethical_hacking
Medium
Assessment Methodologies: Enumeration CTF 1 (2026)
Hey everyone.
⤷ Title: Protecting Your Node.js API with Rate Limiting
════════════════════════
𐀪 Author: Okwudili onyido
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 18:59:11 GMT
════════════════════════
⌗ Tags: #api_security #programming #nodejs #mongodb #web_development
════════════════════════
𐀪 Author: Okwudili onyido
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 18:59:11 GMT
════════════════════════
⌗ Tags: #api_security #programming #nodejs #mongodb #web_development
Medium
Protecting Your Node.js API with Rate Limiting
How to prevent brute-force attacks and server overload using scalable middleware.
⤷ Title: How I Earned $76,000 From a Single Program on Bugcrowd
════════════════════════
𐀪 Author: Sharik Khan
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:46:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #hackerone #bug_bounty #bugcrowd
════════════════════════
𐀪 Author: Sharik Khan
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:46:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #hackerone #bug_bounty #bugcrowd
Medium
How I Earned $76,000 From a Single Program on Bugcrowd
Consistency and patience are not soft skills in bug bounty. They are the strategy.
⤷ Title: Hacking SmartCard Only AD Environments
════════════════════════
𐀪 Author: Zumi Yumi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:38:53 GMT
════════════════════════
⌗ Tags: #hacking #red_teaming #phishing #smart_cards #active_directory
════════════════════════
𐀪 Author: Zumi Yumi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:38:53 GMT
════════════════════════
⌗ Tags: #hacking #red_teaming #phishing #smart_cards #active_directory
Medium
Hacking SmartCard Only AD Environments
Recently I have been involved heavily into researching PKI PIV secured Smart Cards, which has led to my discovery of a “new” TTP I will be…
⤷ Title: Voyage writeup — TryHackMe
════════════════════════
𐀪 Author: 0xH1S
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:33:56 GMT
════════════════════════
⌗ Tags: #ctf #hacking #tryhackme_walkthrough #tryhackme #ctf_writeup
════════════════════════
𐀪 Author: 0xH1S
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:33:56 GMT
════════════════════════
⌗ Tags: #ctf #hacking #tryhackme_walkthrough #tryhackme #ctf_writeup
Medium
Voyage writeup — TryHackMe
Writeup of the "Voyage" machine of tryhackme
⤷ Title: Abusing a vulnerable driver BYOVD to gain arbitrary kernel R/W and bypass PPL protection
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:30:22 GMT
════════════════════════
⌗ Tags: #hacking #malware #cybersecurity #hackthebox #pentesting
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:30:22 GMT
════════════════════════
⌗ Tags: #hacking #malware #cybersecurity #hackthebox #pentesting
Medium
Abusing a vulnerable driver BYOVD to gain arbitrary kernel R/W and bypass PPL protection
Welcome to this new Medium post. In this one, we will explore a powerful technique used in offensive security that allows us to bypass…
⤷ Title: Active Directory for Pentesters — Part 2: Active Directory Enumeration
════════════════════════
𐀪 Author: Azzam Mohammed (WHHacker)
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:01:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #windows #ethical_hacking #penetration_testing #active_directory
════════════════════════
𐀪 Author: Azzam Mohammed (WHHacker)
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:01:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #windows #ethical_hacking #penetration_testing #active_directory
Medium
Active Directory for Pentesters — Part 2: Active Directory Enumeration
In the previous article, we explored the fundamental concepts of Active Directory, including domains, domain controllers, forests, trees…
⤷ Title: I Spent 15 Years in Cybersecurity. Here’s Why AI Is Finally Changing Penetration Testing for Real.
════════════════════════
𐀪 Author: Viktor
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:24:15 GMT
════════════════════════
⌗ Tags: #ai #vibe_coding #security #ai_agent #penetration_testing
════════════════════════
𐀪 Author: Viktor
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:24:15 GMT
════════════════════════
⌗ Tags: #ai #vibe_coding #security #ai_agent #penetration_testing
Medium
I Spent 15 Years in Cybersecurity. Here’s Why AI Is Finally Changing Penetration Testing for Real.
Let me start with an honest confession: I was skeptical about AI in security for a long time.