⤷ Title: From Prompt Injection to XSS: My First Night Attacking AI and Web Systems
════════════════════════
𐀪 Author: Nilanjan Chowdhury
════════════════════════
ⴵ Time: Sat, 02 May 2026 18:44:01 GMT
════════════════════════
⌗ Tags: #prompt_engineering #sql_injection #ethical_hacking #agentic_ai_security #cybersecurity
════════════════════════
𐀪 Author: Nilanjan Chowdhury
════════════════════════
ⴵ Time: Sat, 02 May 2026 18:44:01 GMT
════════════════════════
⌗ Tags: #prompt_engineering #sql_injection #ethical_hacking #agentic_ai_security #cybersecurity
Medium
From Prompt Injection to XSS: My First Night Attacking AI and Web Systems
Author: Nilanjan Chowdhury
⤷ Title: Find SQL injection with burp Suite scanner
════════════════════════
𐀪 Author: Awais Nazeer
════════════════════════
ⴵ Time: Sat, 02 May 2026 18:26:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #burpsuite #bug_bounty_writeup #sql_injection
════════════════════════
𐀪 Author: Awais Nazeer
════════════════════════
ⴵ Time: Sat, 02 May 2026 18:26:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #burpsuite #bug_bounty_writeup #sql_injection
Medium
Find SQL injection with burp Suite scanner
During a testing, we came across this situation:
⤷ Title: “Machine Learning-Based Detection of SQL Injection Attacks: A Classification Approach”
════════════════════════
𐀪 Author: Sumathigowda
════════════════════════
ⴵ Time: Fri, 01 May 2026 18:53:36 GMT
════════════════════════
⌗ Tags: #python #owasp_top_10 #cyber_security_awareness #sql_injection #machine_learning
════════════════════════
𐀪 Author: Sumathigowda
════════════════════════
ⴵ Time: Fri, 01 May 2026 18:53:36 GMT
════════════════════════
⌗ Tags: #python #owasp_top_10 #cyber_security_awareness #sql_injection #machine_learning
Medium
“Machine Learning-Based Detection of SQL Injection Attacks: A Classification Approach”
SQL injection was first documented in 1998. Google was two months old. And yet this ancient trick is still the #3 most critical web…
⤷ Title: Parameter Index Manipulation Leading to Unauthorized Field Injection
════════════════════════
𐀪 Author: 0xoroot
════════════════════════
ⴵ Time: Sun, 03 May 2026 11:01:27 GMT
════════════════════════
⌗ Tags: #hackerone #bug_bounty_writeup #bug_bounty #hacking #bug_bounty_tips
════════════════════════
𐀪 Author: 0xoroot
════════════════════════
ⴵ Time: Sun, 03 May 2026 11:01:27 GMT
════════════════════════
⌗ Tags: #hackerone #bug_bounty_writeup #bug_bounty #hacking #bug_bounty_tips
Medium
Parameter Index Manipulation Leading to Unauthorized Field Injection
Introduction
⤷ Title: The Ghost in the Machine: A Bug Bounty Short Story
════════════════════════
𐀪 Author: Mohamed Adel
════════════════════════
ⴵ Time: Sun, 03 May 2026 09:14:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #recon #bug_bounty_writeup #penetration_testing
════════════════════════
𐀪 Author: Mohamed Adel
════════════════════════
ⴵ Time: Sun, 03 May 2026 09:14:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #recon #bug_bounty_writeup #penetration_testing
Medium
The Ghost in the Machine: A Bug Bounty Short Story
It was 2:00 AM, and my terminal was a blur of scrolling green text. I was deep into a private bug bounty program for a massive corporate…
⤷ Title: تێپەرێنم eWPTX چۆن توانیم تاقیکردنەوەی
════════════════════════
𐀪 Author: error-01
════════════════════════
ⴵ Time: Sat, 02 May 2026 17:18:27 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #bug_bounty_writeup #infosec #ethical_hacking
════════════════════════
𐀪 Author: error-01
════════════════════════
ⴵ Time: Sat, 02 May 2026 17:18:27 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #bug_bounty_writeup #infosec #ethical_hacking
Medium
تێپەرێنم eWPTX چۆن توانیم تاقیکردنەوەی
بسم الله الرحمن الرحيم, السلام علیکم
⤷ Title: Hunting on Government Infrastructure: WAF Bypasses, OAuth Testing, and Knowing When to Pivot
════════════════════════
𐀪 Author: Sathya Boobalan
════════════════════════
ⴵ Time: Sat, 02 May 2026 16:41:40 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #penetration_testing #infosec #writeup
════════════════════════
𐀪 Author: Sathya Boobalan
════════════════════════
ⴵ Time: Sat, 02 May 2026 16:41:40 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #penetration_testing #infosec #writeup
Medium
Hunting on Government Infrastructure: WAF Bypasses, OAuth Testing, and Knowing When to Pivot
Introduction
⤷ Title: Unauthorized Admin Panel Access via JavaScript Recon
════════════════════════
𐀪 Author: Rahimahaq
════════════════════════
ⴵ Time: Sat, 02 May 2026 15:20:28 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #web_penetration_testing #bug_bounty_writeup #womenincyber
════════════════════════
𐀪 Author: Rahimahaq
════════════════════════
ⴵ Time: Sat, 02 May 2026 15:20:28 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #web_penetration_testing #bug_bounty_writeup #womenincyber
⤷ Title: How I Ended Up in the WHO Hall of Fame via Google Dorking
════════════════════════
𐀪 Author: Gouri Sankar A
════════════════════════
ⴵ Time: Sat, 02 May 2026 11:24:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #bug_bounty_writeup
════════════════════════
𐀪 Author: Gouri Sankar A
════════════════════════
ⴵ Time: Sat, 02 May 2026 11:24:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #bug_bounty_writeup
Medium
How I Ended Up in the WHO Hall of Fame via Google Dorking
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…
⤷ Title: How I discovered my first valid Bug
════════════════════════
𐀪 Author: cipher
════════════════════════
ⴵ Time: Fri, 01 May 2026 20:58:37 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: cipher
════════════════════════
ⴵ Time: Fri, 01 May 2026 20:58:37 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_writeup #bug_bounty
Medium
How I discovered my first valid Bug
This was the first bug I discovered in a employee managment web application. After discovering the bug, I responsibly reported it to the…
⤷ Title: Your AI Stack is Publicly Searchable
════════════════════════
𐀪 Author: Tanmay Bhattacharjee
════════════════════════
ⴵ Time: Sun, 03 May 2026 07:35:55 GMT
════════════════════════
⌗ Tags: #reconnaissance #ai_security #cybersecurity #bugbounty_writeup
════════════════════════
𐀪 Author: Tanmay Bhattacharjee
════════════════════════
ⴵ Time: Sun, 03 May 2026 07:35:55 GMT
════════════════════════
⌗ Tags: #reconnaissance #ai_security #cybersecurity #bugbounty_writeup
Medium
Your AI Stack is Publicly Searchable
A practical Shodan recon guide for every component in the modern ML serving pipeline from model servers to vector databases to notebook…
⤷ Title: Signature Bypass via Control Character Injection → Arbitrary File Access
════════════════════════
𐀪 Author: Ussef
════════════════════════
ⴵ Time: Sat, 02 May 2026 15:14:37 GMT
════════════════════════
⌗ Tags: #ethical_hacking #websec #bugbounty_writeup #cybersecurity #path_traversal
════════════════════════
𐀪 Author: Ussef
════════════════════════
ⴵ Time: Sat, 02 May 2026 15:14:37 GMT
════════════════════════
⌗ Tags: #ethical_hacking #websec #bugbounty_writeup #cybersecurity #path_traversal
Medium
🔥 Signature Bypass via Control Character Injection → Arbitrary File Access
🧠 Introduction
⤷ Title: I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took
════════════════════════
𐀪 Author: Krithick
════════════════════════
ⴵ Time: Sat, 02 May 2026 14:02:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bugbounty_writeup #rewards #bug_bounty
════════════════════════
𐀪 Author: Krithick
════════════════════════
ⴵ Time: Sat, 02 May 2026 14:02:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bugbounty_writeup #rewards #bug_bounty
Medium
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…
⤷ Title: Proving Grounds |Pelican | OSCP Preparation
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Sat, 02 May 2026 18:54:51 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #tech #ethical_hacking #technology
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Sat, 02 May 2026 18:54:51 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #tech #ethical_hacking #technology
Medium
Proving Grounds |Pelican | OSCP Preparation
As part of my OSCP preparation series; I will be covering walk throughs for all the boxes on the TJ null list. Today we are looking at…
⤷ Title: The “Invite Only” Loophole That Led to a $3,000 Payout
════════════════════════
𐀪 Author: Tanvi Chauhan
════════════════════════
ⴵ Time: Sat, 02 May 2026 17:29:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #cyberattack #pentesting
════════════════════════
𐀪 Author: Tanvi Chauhan
════════════════════════
ⴵ Time: Sat, 02 May 2026 17:29:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #cyberattack #pentesting
Medium
The “Invite Only” Loophole That Led to a $3,000 Payout
There is a specific kind of adrenaline that hits when you find a bug in a system that’s supposed to be “Invite Only.” It feels like finding…
⤷ Title: How I Turned $3 Into 8 Paid Bugs
════════════════════════
𐀪 Author: Saif Eldin
════════════════════════
ⴵ Time: Fri, 01 May 2026 18:07:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_hunter #bug_bounty_tips #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Saif Eldin
════════════════════════
ⴵ Time: Fri, 01 May 2026 18:07:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_hunter #bug_bounty_tips #bug_bounty_writeup #bug_bounty
Medium
How I Turned $3 Into 8 Paid Bugs
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ اللَّهُمَّ صَلِّ وَسَلِّمْ وَبَارِكْ عَلَى سَيِّدِنَا مُحَمَّدٍ
⤷ Title: How I Discovered 5 broken Access Control Bugs in a Single Web Application
════════════════════════
𐀪 Author: 0xyz
════════════════════════
ⴵ Time: Fri, 01 May 2026 17:36:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #cybersecurity
════════════════════════
𐀪 Author: 0xyz
════════════════════════
ⴵ Time: Fri, 01 May 2026 17:36:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #cybersecurity
Medium
How I Discovered 5 broken Access Control Bugs in a Single Web Application
Hi Hunters,
⤷ Title: The boring method that got me paid in bug bounty (while others chased hype) helped me find critical vulnerabilities
════════════════════════
𐀪 Author: DEep
════════════════════════
ⴵ Time: Fri, 01 May 2026 16:44:48 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #cybersecurity #hacking #bug_bounty_tips
════════════════════════
𐀪 Author: DEep
════════════════════════
ⴵ Time: Fri, 01 May 2026 16:44:48 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #cybersecurity #hacking #bug_bounty_tips
Medium
How focusing on a single bug bounty program for months helped me find critical vulnerabilities
Most bug hunters jump from one program to another.
⤷ Title: Apache MINA Fixes Critical RCE Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 02:30:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache MINA #CVE_2026_42778 #CVE_2026_42779 #Deserialization #infosec #IoBuffer #Java security #patch management #rce #Vulnerability Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 02:30:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache MINA #CVE_2026_42778 #CVE_2026_42779 #Deserialization #infosec #IoBuffer #Java security #patch management #rce #Vulnerability Research
Daily CyberSecurity
Apache MINA Fixes Critical RCE Vulnerabilities
Apache MINA issues emergency patches for two 9.8 CVSS RCE flaws left behind by mistake. Unauthenticated attackers can bypass filters via deserialization.
⤷ Title: MOVEit Automation Alert: Critical Authentication Bypass Hits CVSS 9.8
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 02:02:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Backend Security #CVE_2026_4670 #CVE_2026_5174 #Data Security #infosec #MOVEit Automation #Patch Alert #privilege escalation #Progress Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 02:02:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Backend Security #CVE_2026_4670 #CVE_2026_5174 #Data Security #infosec #MOVEit Automation #Patch Alert #privilege escalation #Progress Software
Daily CyberSecurity
MOVEit Automation Alert: Critical Authentication Bypass Hits CVSS 9.8
MOVEit Automation faces a critical 9.8 CVSS flaw (CVE-2026-4670). Attackers can bypass auth to seize admin control and expose data. Patch immediately.
⤷ Title: The CVE Watchtower: Weekly Threat Intelligence Briefing (April 27 – May 3, 2026)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 01:57:05 +0000
════════════════════════
⌗ Tags: #Weekly Recap #CISA KEV #CPanel #CVE_2026_41940 #CVSS 10 #cybersecurity #Express.js #infosec #patch management #Vulnerability Digest #WHM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 01:57:05 +0000
════════════════════════
⌗ Tags: #Weekly Recap #CISA KEV #CPanel #CVE_2026_41940 #CVSS 10 #cybersecurity #Express.js #infosec #patch management #Vulnerability Digest #WHM
Daily CyberSecurity
The CVE Watchtower: Weekly Threat Intelligence Briefing (April 27 – May 3, 2026)
Weekly Triage: 1,134 new vulnerabilities found, including a 9.8 critical bypass in cPanel/WHM and active Express.js logic flaws. Patch your systems now.