⤷ Title: From iframe Injection to Account Takeover (Full Exploit Chain)
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 06:24:04 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #xss_vulnerability #bug_bounty_writeup #bug_bounty #account_takeover_attacks
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Mon, 23 Mar 2026 06:24:04 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #xss_vulnerability #bug_bounty_writeup #bug_bounty #account_takeover_attacks
Medium
From iframe Injection to Account Takeover (Full Exploit Chain)🔥
How can I escalate the impact of an iframe injection vulnerability to account takeover via XSS?
⤷ Title: Stored DOM XSS to Account Takeover
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Sat, 21 Mar 2026 13:15:25 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #account_takeover #bug_bounty_writeup #xss_attack #bug_bounty_tips
════════════════════════
𐀪 Author: 0xRedFox29
════════════════════════
ⴵ Time: Sat, 21 Mar 2026 13:15:25 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #account_takeover #bug_bounty_writeup #xss_attack #bug_bounty_tips
Medium
Stored DOM XSS to Account Takeover
bagaimana teknik melewati XSS filter dengan payload yang whitelist untuk memaksimalkan fitur dan menaikan dampaknya ke account takeover
⤷ Title: How Do Concrete Vaults Actually Work?
════════════════════════
𐀪 Author: Hirabauldas
════════════════════════
ⴵ Time: Fri, 27 Mar 2026 03:49:06 GMT
════════════════════════
⌗ Tags: #zcf #rce_vulnerability #werewolves #book_recommendations #c
════════════════════════
𐀪 Author: Hirabauldas
════════════════════════
ⴵ Time: Fri, 27 Mar 2026 03:49:06 GMT
════════════════════════
⌗ Tags: #zcf #rce_vulnerability #werewolves #book_recommendations #c
Medium
How Do Concrete Vaults Actually Work?
You open a DeFi app, deposit your funds into a vault, and suddenly you see new terms appear — vault shares, eRate, and NAV. Your balance…
⤷ Title: CVE-2026–33139 How I Found My First CVE: Bypassing PySpector’s Plugin Security Sandbox
════════════════════════
𐀪 Author: Shinigami81
════════════════════════
ⴵ Time: Wed, 25 Mar 2026 17:00:00 GMT
════════════════════════
⌗ Tags: #python #cybersecurity #security_research #pyspector #rce_vulnerability
════════════════════════
𐀪 Author: Shinigami81
════════════════════════
ⴵ Time: Wed, 25 Mar 2026 17:00:00 GMT
════════════════════════
⌗ Tags: #python #cybersecurity #security_research #pyspector #rce_vulnerability
Medium
CVE-2026–33139 How I Found My First CVE: Bypassing PySpector’s Plugin Security Sandbox
Where it started
⤷ Title: SQL Injection UNION Attack: Retrieving Multiple Values in a Single Column
════════════════════════
𐀪 Author: Mohamed Ahmed
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 00:20:31 GMT
════════════════════════
⌗ Tags: #websecurity_testing #penetration_testing #cybersecurity #sql_injection #bug_bounty
════════════════════════
𐀪 Author: Mohamed Ahmed
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 00:20:31 GMT
════════════════════════
⌗ Tags: #websecurity_testing #penetration_testing #cybersecurity #sql_injection #bug_bounty
Medium
SQL injection UNION attack, retrieving multiple values in a single column
A practical PortSwigger lab walkthrough for UNION-based SQL injection
⤷ Title: SQL Injection: How a Single Line of Code Can Make Your Website Vulnerable
════════════════════════
𐀪 Author: Dalila Zitouni
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 02:26:14 GMT
════════════════════════
⌗ Tags: #ethical_hacking #data_protection #sql_injection #cybersecurity #web_security
════════════════════════
𐀪 Author: Dalila Zitouni
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 02:26:14 GMT
════════════════════════
⌗ Tags: #ethical_hacking #data_protection #sql_injection #cybersecurity #web_security
Medium
SQL Injection: How a Single Line of Code Can Make Your Website Vulnerable
This article was written to share my knowledge about web security and demonstrate my technical skills in cybersecurity.
⤷ Title: Juice Shop Write-up: Login Admin Challenge
════════════════════════
𐀪 Author: ~ Jeff ~
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 01:50:44 GMT
════════════════════════
⌗ Tags: #web_security #sql_injection #owasp_juice_shop #ethical_hacking #web_penetration_testing
════════════════════════
𐀪 Author: ~ Jeff ~
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 01:50:44 GMT
════════════════════════
⌗ Tags: #web_security #sql_injection #owasp_juice_shop #ethical_hacking #web_penetration_testing
Medium
Juice Shop Write-up: Login Admin Challenge
The goal of this challenge is to exploit an SQL Injection vulnerability in the login functionality to gain unauthorized access to the…
⤷ Title: Cybersecurity 101 for Backend Devs: Preventing Injection Beyond SQL
════════════════════════
𐀪 Author: Rahul Kaklotar
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 00:16:01 GMT
════════════════════════
⌗ Tags: #sql #data_science #sql_injection #cybersecurity #database
════════════════════════
𐀪 Author: Rahul Kaklotar
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 00:16:01 GMT
════════════════════════
⌗ Tags: #sql #data_science #sql_injection #cybersecurity #database
Medium
Cybersecurity 101 for Backend Devs: Preventing Injection Beyond SQL
Most Devs Miss This Security Gap!
⤷ Title: SQL Injection Attack
════════════════════════
𐀪 Author: Arunoday Tiwari
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 22:34:14 GMT
════════════════════════
⌗ Tags: #sql_injection #cybersecurity #hacking #ctf_writeup
════════════════════════
𐀪 Author: Arunoday Tiwari
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 22:34:14 GMT
════════════════════════
⌗ Tags: #sql_injection #cybersecurity #hacking #ctf_writeup
Medium
SQL Injection Attack
Hack the Logic: How ' OR 1=1 -- Breaks the Internet
⤷ Title: Lab: SQL injection attack, listing the database contents on Oracle
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 18:43:56 GMT
════════════════════════
⌗ Tags: #sql_injection #pentesting #hacking #ctf #pentest_web
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 18:43:56 GMT
════════════════════════
⌗ Tags: #sql_injection #pentesting #hacking #ctf #pentest_web
Medium
Lab: SQL injection attack, listing the database contents on Oracle
Bu lab’de, product category filter üzerinden oluşan bir SQL Injection zafiyetini kullanarak veritabanı üzerinde ilerliyorum. Uygulama…
⤷ Title: Day 16–17 of PortSwigger Academy Lab Practitioner Walkthrough: SQL injection (Part 2).
════════════════════════
𐀪 Author: ALESSANDRO FARREL GERRARD WIJAYA
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:43:58 GMT
════════════════════════
⌗ Tags: #sql_injection #portswigger_academy_labs
════════════════════════
𐀪 Author: ALESSANDRO FARREL GERRARD WIJAYA
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:43:58 GMT
════════════════════════
⌗ Tags: #sql_injection #portswigger_academy_labs
Medium
Day 16–17 of PortSwigger Academy Lab Practitioner Walkthrough: SQL injection (Part 2).
Focuses on performing step by step tutorials on solving all practitioner levels SQL Injection.
⤷ Title: Day 16–17 of PortSwigger Academy Lab Practitioner Walkthrough: SQL injection.
════════════════════════
𐀪 Author: ALESSANDRO FARREL GERRARD WIJAYA
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:31:28 GMT
════════════════════════
⌗ Tags: #portswigger_academy_labs #sql_injection
════════════════════════
𐀪 Author: ALESSANDRO FARREL GERRARD WIJAYA
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:31:28 GMT
════════════════════════
⌗ Tags: #portswigger_academy_labs #sql_injection
Medium
Day 16–17 of PortSwigger Academy Lab Practitioner Walkthrough: SQL injection.
Focuses on performing step by step tutorials on solving all practitioner levels SQL Injection.
⤷ Title: Exposed .env File Leads To API Key Leak & Financial Impact
════════════════════════
𐀪 Author: 1sherlok
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 15:11:10 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #bug_bounty_tips #bug_bounty_writeup #cybersecurity
════════════════════════
𐀪 Author: 1sherlok
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 15:11:10 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #bug_bounty_tips #bug_bounty_writeup #cybersecurity
Medium
Exposed .env File Leads To API Key Leak & Financial Impact
Hello everyone, I’m Sherlok, and today I’d like to share how I discovered an exposed .env file that led to leaked API credentials and real…
⤷ Title: How I Found a Critical SAML Authentication Bypasson a Major Automotive Company's Dealer Portal
════════════════════════
𐀪 Author: Ousski
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 19:03:43 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #cybersecurity #bug_hunting
════════════════════════
𐀪 Author: Ousski
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 19:03:43 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #cybersecurity #bug_hunting
Medium
How I Found a Critical SAML Authentication Bypasson a Major Automotive Company's Dealer Portal
INTRODUCTION:
⤷ Title: How to Hunt IDORs When IDs Are UUIDs (Not Integers) Lab: User ID controlled by request parameter…
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 23:00:30 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #ethical_hacking #owasp #cyber_security_solutions
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 23:00:30 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #ethical_hacking #owasp #cyber_security_solutions
Medium
How to Hunt IDORs When IDs Are UUIDs (Not Integers) Lab: User ID controlled by request parameter, with unpredictable user IDs
Most guides teach you to change /user/1 to /user/2. Real apps use UUIDs. Here is how to find them.
⤷ Title: Breaking It During a Hackathon
════════════════════════
𐀪 Author: debang5hu
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 20:08:39 GMT
════════════════════════
⌗ Tags: #api #bug_bounty_writeup #cybersecurity #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: debang5hu
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 20:08:39 GMT
════════════════════════
⌗ Tags: #api #bug_bounty_writeup #cybersecurity #bug_bounty #penetration_testing
Medium
Breaking It During a Hackathon
Worked on security testing for target.com with a team of four, this write-up highlights the bugs I found and how I approached them.
⤷ Title: BAC: THE Money-Making Machine
════════════════════════
𐀪 Author: Rajveer
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:40:14 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #broken_access_control
════════════════════════
𐀪 Author: Rajveer
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:40:14 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #broken_access_control
Medium
BAC: THE Money-Making Machine
BAC is always my favorite and most of my bounties come from this vulnerability.
It always fascinates me to bypass the intended flow and…
It always fascinates me to bypass the intended flow and…
⤷ Title: GitHub is a Search Engine for Secrets — and Nobody Told You
════════════════════════
𐀪 Author: Shah kaif
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:01:53 GMT
════════════════════════
⌗ Tags: #github_dork #bug_bounty_tips #osint #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Shah kaif
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 06:01:53 GMT
════════════════════════
⌗ Tags: #github_dork #bug_bounty_tips #osint #bug_bounty_writeup #bug_bounty
Medium
GitHub is a Search Engine for Secrets — and Nobody Told You
By Shah kaif | “Every leaked API key started as a commit someone thought was private.” | LinkedIn | Youtube
⤷ Title: Hi ReadMe.io
════════════════════════
𐀪 Author: shesha sai_c
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 17:10:15 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #vulnerability_management #vulnerability
════════════════════════
𐀪 Author: shesha sai_c
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 17:10:15 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #vulnerability_management #vulnerability
Medium
Hi ReadMe.io
Summary:
⤷ Title: How Bug Bounty Hunters Are Using Claude Code.
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 09:01:57 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #claude_code #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 09:01:57 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #claude_code #bug_bounty_tips #bug_bounty_writeup
Medium
How Bug Bounty Hunters Are Using Claude Code.
The community has been quietly building something powerful. I went and found it.
⤷ Title: ️ This Vulnerability Was Sitting in Front of Everyone — But No One Noticed
════════════════════════
𐀪 Author: Sukhveer Singh
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 05:37:38 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #cybersecurity #bug_bounty_writeup #bug_hunting
════════════════════════
𐀪 Author: Sukhveer Singh
════════════════════════
ⴵ Time: Tue, 31 Mar 2026 05:37:38 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #cybersecurity #bug_bounty_writeup #bug_hunting
Medium
🕵️ This Vulnerability Was Sitting in Front of Everyone — But No One Noticed
Most bugs are hidden.