⤷ Title: Exploiting Misconfigured GraphQL
════════════════════════
𐀪 Author: Ghost
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:38:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: Ghost
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:38:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #ethical_hacking
Medium
Exploiting Misconfigured GraphQL
Theory:
It’s all about API testing. I’m not going to explain it — go do some research, hehehe.
It’s all about API testing. I’m not going to explain it — go do some research, hehehe.
⤷ Title: BUG-BOUNTY SERIES 6: Google Dorking untuk Reconnaissance — Menggali Informasi Sensitif Secara…
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:18:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #linux
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:18:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #linux
Medium
BUG-BOUNTY SERIES 6: Google Dorking untuk Reconnaissance — Menggali Informasi Sensitif Secara Efektif
Dalam proses Bug Bounty, tidak semua celah ditemukan melalui scanning atau eksploitasi langsung. Banyak kerentanan justru berasal dari…
⤷ Title: BUG-BOUNTY SERIES 5: Strategi Meningkatkan Skill dan Konsistensi dalam Bug Bounty Hunting
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:13:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #linux
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:13:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #linux
Medium
BUG-BOUNTY SERIES 5: Strategi Meningkatkan Skill dan Konsistensi dalam Bug Bounty Hunting
Dalam dunia Bug Bounty, kemampuan teknis saja tidak cukup. Banyak hunter yang memahami teori dan tools, namun gagal mendapatkan hasil…
⤷ Title: I Found a Stored XSS in an API Explorer — Here’s Exactly How I Did It
════════════════════════
𐀪 Author: Sada devre
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:05:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #xs #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: Sada devre
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:05:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #xs #bug_bounty #penetration_testing
Medium
I Found a Stored XSS in an API Explorer — Here’s Exactly How I Did It
Sometimes the juiciest bugs hide in the tools developers use to test their own APIs.
⤷ Title: How I Turned a “Harmless” Self-XSS into a Full Account Takeover
════════════════════════
𐀪 Author: Sada devre
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #account_takeover #xss_attack #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: Sada devre
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #account_takeover #xss_attack #bug_bounty_writeup #bug_bounty_tips
Medium
How I Turned a “Harmless” Self-XSS into a Full Account Takeover
Triagers call Self-XSS informational. Here’s how I used it to steal accounts — and collected a critical bounty for it.
⤷ Title: Prevent Deserialization Attacks by Eliminating Dynamic Instantiation Paths
════════════════════════
𐀪 Author: Asian Digital Hub
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:16:37 GMT
════════════════════════
⌗ Tags: #web_security #php #php_development #application_security #cybersecurity
════════════════════════
𐀪 Author: Asian Digital Hub
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:16:37 GMT
════════════════════════
⌗ Tags: #web_security #php #php_development #application_security #cybersecurity
Medium
Prevent Deserialization Attacks by Eliminating Dynamic Instantiation Paths
There’s a quiet trap sitting inside a lot of modern backends and it doesn’t scream when it breaks. It whispers.
⤷ Title: DiceForge (RCE) Bugforge
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:13:53 GMT
════════════════════════
⌗ Tags: #ctf #rce #bugforge #hacking #ctf_writeup
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:13:53 GMT
════════════════════════
⌗ Tags: #ctf #rce #bugforge #hacking #ctf_writeup
Medium
DiceForge (RCE) Bugforge
A new playground appeared. DiceForge! Let’s give it a go!
⤷ Title: Cybersecurity & the CIA Triad: The Foundation of Digital Protection
════════════════════════
𐀪 Author: Mickeymouse
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:37:35 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #cybersecurity_awareness #cia_triad #beginner_guide
════════════════════════
𐀪 Author: Mickeymouse
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:37:35 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #cybersecurity_awareness #cia_triad #beginner_guide
Medium
Cybersecurity & the CIA Triad: The Foundation of Digital Protection
A beginner-friendly guide to understanding how data stays safe in the real world
⤷ Title: From One Workstation to Domain: Dumping LSASS Credentials in a Home Lab
════════════════════════
𐀪 Author: Will Giles | Cybersecurity
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:37:48 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #cybersecurity #active_directory #active_directory_security
════════════════════════
𐀪 Author: Will Giles | Cybersecurity
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:37:48 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #cybersecurity #active_directory #active_directory_security
Medium
From One Workstation to Domain: Dumping LSASS Credentials in a Home Lab
Walking through credential dumping in an Active Directory lab — from initial foothold to domain pivot
⤷ Title: Importing Results into Metasploit (MSF)
════════════════════════
𐀪 Author: Geerhan Sentanu, CH, CHt. | Offensive Security
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:24:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #metasploit #cybersecurity #ethical_hacking #offensive_security
════════════════════════
𐀪 Author: Geerhan Sentanu, CH, CHt. | Offensive Security
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:24:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #metasploit #cybersecurity #ethical_hacking #offensive_security
Medium
Importing Results into Metasploit (MSF)
Follow these steps to move your Nmap data into the Metasploit database.
⤷ Title: THM — light
════════════════════════
𐀪 Author: 0xEnzoSantana
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:30:27 GMT
════════════════════════
⌗ Tags: #ctf #thm_writeup #ethical_hacking #cybersecurity #tryhackme
════════════════════════
𐀪 Author: 0xEnzoSantana
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:30:27 GMT
════════════════════════
⌗ Tags: #ctf #thm_writeup #ethical_hacking #cybersecurity #tryhackme
Medium
THM — light
link: https://tryhackme.com/room/lightroom
⤷ Title: TryHackMe | Masquerade | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:02:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #ai
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:02:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #ai
Medium
TryHackMe | Masquerade | WriteUp
Our company may have been compromised, we need your help ASAP.
⤷ Title: TryHackMe | Supply Chain Attack Vectors | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:01:33 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #tryhackme_walkthrough #tryhackme_writeup #ai
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:01:33 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #tryhackme_walkthrough #tryhackme_writeup #ai
Medium
TryHackMe | Supply Chain Attack Vectors | WriteUp
Learn how trusted ML components can be turned into attack vectors.
⤷ Title: El Bandito CTF Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:58:55 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #tryhackme_walkthrough #tryhackme_writeup #ctf_walkthrough
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 17:58:55 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #tryhackme_walkthrough #tryhackme_writeup #ctf_walkthrough
Medium
El Bandito CTF Notes | TryHackMe
El Bandito walkthrough covering SSRF, smuggling, credentials, and flags.
⤷ Title: HTB — Perfection Machine
════════════════════════
𐀪 Author: 0xEnzoSantana
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:31:21 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #cybersecurity #hackthebox #htb
════════════════════════
𐀪 Author: 0xEnzoSantana
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 18:31:21 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #cybersecurity #hackthebox #htb
Medium
HTB — Perfection Machine
Meu primeiro passo é iniciar um portscan para descobrir os serviços rodando na máquina. Gosto de rodar o rustscan para descobrir mais…
⤷ Title: Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:21:35 +0000
════════════════════════
⌗ Tags: #Security #Microsoft #Agentic AI #AI #Cyber Attack #Cybersecurity #Identity theft #Microsoft Entra #Silverfort #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:21:35 +0000
════════════════════════
⌗ Tags: #Security #Microsoft #Agentic AI #AI #Cyber Attack #Cybersecurity #Identity theft #Microsoft Entra #Silverfort #Vulnerability
Hackread
Microsoft Entra Agent ID Flaw Enabled Tenant Takeover via Privilege Escalation
Microsoft Entra Agent ID flaw allowed privilege escalation and tenant takeover via Service Principal abuse, now fully patched by Microsoft.
⤷ Title: 12:04:21.882 POST /login DATA: [email protected]&password=MyBank#2024!
════════════════════════
𐀪 Author: CAISD
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:19:09 GMT
════════════════════════
⌗ Tags: #hacking #caisd #security #owasp #bug_bounty
════════════════════════
𐀪 Author: CAISD
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:19:09 GMT
════════════════════════
⌗ Tags: #hacking #caisd #security #owasp #bug_bounty
Medium
12:04:21.882 POST /login DATA: [email protected]&password=MyBank#2024!
Failure 2 — MD5 Password Hashing
⤷ Title: Hijack (THM) Tryhackme Writeup and Answer
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 20:37:59 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #ctf_writeup #hacking #cybersecurity
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 20:37:59 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #ctf_writeup #hacking #cybersecurity
Medium
Hijack (THM) Tryhackme Writeup and Answer
Description : Misconfigs conquered, identities claimed.
⤷ Title: OWASP Top 10: The Developer’s Guide to Not Getting Hacked
════════════════════════
𐀪 Author: Pentesty
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 20:36:23 GMT
════════════════════════
⌗ Tags: #owasp #cybersecurity #pentesty #hacking #pentesting
════════════════════════
𐀪 Author: Pentesty
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 20:36:23 GMT
════════════════════════
⌗ Tags: #owasp #cybersecurity #pentesty #hacking #pentesting
Medium
OWASP Top 10: The Developer’s Guide to Not Getting Hacked
Reading time: ~12 minutes
⤷ Title: How I Passed OSWE: The System That Actually Worked for Me
════════════════════════
𐀪 Author: ABDELKARIM MOUCHQUELITA
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:45:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ethical_hacking #offsec #oscp
════════════════════════
𐀪 Author: ABDELKARIM MOUCHQUELITA
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:45:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ethical_hacking #offsec #oscp
Medium
How I Passed OSWE: The System That Actually Worked for Me
The OSWE exam is not a bug bounty. You don’t find one vulnerability, write it up, and move on. The exam wants a full compromise, and if you…
⤷ Title: HTB Footprinting Lab — Hard
════════════════════════
𐀪 Author: Youssef Ezzat
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:41:46 GMT
════════════════════════
⌗ Tags: #hackthebox #cybersecurity #penetration_testing #ctf #ethical_hacking
════════════════════════
𐀪 Author: Youssef Ezzat
════════════════════════
ⴵ Time: Sun, 26 Apr 2026 19:41:46 GMT
════════════════════════
⌗ Tags: #hackthebox #cybersecurity #penetration_testing #ctf #ethical_hacking
Medium
HTB Footprinting Lab — Hard
HTB Footprinting Lab — Hard Hey everyone! Today I’m tackling the Footprinting (Hard) lab on Hack The Box Academy. This one was a real challenge because it required digging into services that …