⤷ Title: How I Found an Unprotected Login Portal on a Federal VDP (and Why It Still Got P5)
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:04:39 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #ethical_hacking #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:04:39 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #ethical_hacking #penetration_testing #cybersecurity
Medium
How I Found an Unprotected Login Portal on a Federal VDP (and Why It Still Got P5)
So I want to walk you through this one because I think the lessons matter more than the finding itself. I’m under NDA on the actual…
⤷ Title: No Salt, Weak Security — How a Cookie Design Flaw Led to Account Takeover
════════════════════════
𐀪 Author: Vamsikandukuru
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:22:10 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #bug_bounty #hashing #cybersecurity
════════════════════════
𐀪 Author: Vamsikandukuru
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:22:10 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #bug_bounty #hashing #cybersecurity
Medium
No Salt, Weak Security — How a Cookie Design Flaw Led to Account Takeover
Hello everyone! My name is Vamsi Kandukuru, a Cybersecurity graduate. In this blog we discuss the importance of salting and how its absence…
⤷ Title: How I Found an Unprotected Login Portal on a Federal VDP (and Why It Still Got P5)
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:04:38 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #ethical_hacking #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:04:38 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #ethical_hacking #penetration_testing #cybersecurity
Medium
How I Found an Unprotected Login Portal on a Federal VDP (and Why It Still Got P5)
So I want to walk you through this one because I think the lessons matter more than the finding itself. I’m under NDA on the actual…
⤷ Title: Software Supply Chain Under Attack: Malicious npm Packages Target Developer Secrets
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:24:20 GMT
════════════════════════
⌗ Tags: #application_security #github #ai_security #cloud_security #cybersecurity
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:24:20 GMT
════════════════════════
⌗ Tags: #application_security #github #ai_security #cloud_security #cybersecurity
Medium
Software Supply Chain Under Attack: Malicious npm Packages Target Developer Secrets
A new software supply chain attack has emerged, where threat actors weaponized npm packages linked to SAP ecosystems to steal sensitive…
⤷ Title: Stop Using JWT for Authentication the Way You Learned It
════════════════════════
𐀪 Author: Mayank Jain
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:43:47 GMT
════════════════════════
⌗ Tags: #nodejs #software_engineering #hacking #software_development #technology
════════════════════════
𐀪 Author: Mayank Jain
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:43:47 GMT
════════════════════════
⌗ Tags: #nodejs #software_engineering #hacking #software_development #technology
Medium
Stop Using JWT for Authentication the Way You Learned It
The pattern most JWT tutorials teach is dangerous. Here’s what’s actually wrong with it, and what authentication should look like in a…
⤷ Title: Penetration Testing: Strengthening Digital Defenses in a Threat-Filled World
════════════════════════
𐀪 Author: BlackHat
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:08:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #tech #artificial_intelligence #business #hacking
════════════════════════
𐀪 Author: BlackHat
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:08:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #tech #artificial_intelligence #business #hacking
Medium
Penetration Testing: Strengthening Digital Defenses in a Threat-Filled World
Penetration Testing: Strengthening Digital Defenses in a Threat-Filled World Penetration testing, commonly known as pentesting, is a simulated cyber attack performed by ethical hackers to identify …
⤷ Title: 0day — TryHacM Writeup
════════════════════════
𐀪 Author: sudo_0xksh
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:01:42 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #hacking #ctf #cybersecurity
════════════════════════
𐀪 Author: sudo_0xksh
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:01:42 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #hacking #ctf #cybersecurity
⤷ Title: Pyrat — TryHackMe Writeup / Walkt
════════════════════════
𐀪 Author: sudo_0xksh
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:00:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #pentesting #hacking #ctf
════════════════════════
𐀪 Author: sudo_0xksh
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:00:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #pentesting #hacking #ctf
⤷ Title: Unmasking SHub Stealer: A Deep Dive into a Sophisticated macOS Info-Stealer Masquerading as GitHub…
════════════════════════
𐀪 Author: Aqua
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:55:51 GMT
════════════════════════
⌗ Tags: #malware_analysis #threat_intelligence #infosec #cybersecurity
════════════════════════
𐀪 Author: Aqua
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:55:51 GMT
════════════════════════
⌗ Tags: #malware_analysis #threat_intelligence #infosec #cybersecurity
Medium
Unmasking SHub Stealer: A Deep Dive into a Sophisticated macOS Info-Stealer Masquerading as GitHub…
Overview
Recently, I uncovered a highly deceptive phishing campaign. The site flawlessly mimics the official GitHub Desktop download page…
Recently, I uncovered a highly deceptive phishing campaign. The site flawlessly mimics the official GitHub Desktop download page…
⤷ Title: NSE: The Script Engine Most People Use Without Understanding
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:45:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #nmap #ethical_hacking #network_security
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:45:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #nmap #ethical_hacking #network_security
Medium
NSE: The Script Engine Most People Use Without Understanding
You’ve been running -sC without knowing what actually fired. Here's everything that happens behind that flag.
⤷ Title: ‘Active’ Machine write-up
════════════════════════
𐀪 Author: Zeyadmahmoud Zm
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:44:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #htb_writeup #penetration_testing #ctf
════════════════════════
𐀪 Author: Zeyadmahmoud Zm
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:44:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #htb_writeup #penetration_testing #ctf
Medium
‘Active’ Machine write-up
Machine Information
⤷ Title: Token Impersonation with Incognito in Active Directory Lab
════════════════════════
𐀪 Author: Basithmohammedali
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:59:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #active_directory #networking #metasploitable
════════════════════════
𐀪 Author: Basithmohammedali
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:59:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #active_directory #networking #metasploitable
Medium
Token Impersonation with Incognito in Active Directory Lab
Introduction
⤷ Title: Reading Responses: Status Codes, Headers, and Body Forensics
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:06:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #ethical_hacking #cybersecurity #web_security
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:06:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #ethical_hacking #cybersecurity #web_security
Medium
Reading Responses: Status Codes, Headers, and Body Forensics
A 403 and a 404 look similar. They mean completely different things.
⤷ Title: From Anonymous to Administrator: A Chain of Quiet Mistakes
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:05:28 GMT
════════════════════════
⌗ Tags: #technology #ethical_hacking #penetration_testing #azure_active_directory #cybersecurity
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:05:28 GMT
════════════════════════
⌗ Tags: #technology #ethical_hacking #penetration_testing #azure_active_directory #cybersecurity
Medium
From Anonymous to Administrator: A Chain of Quiet Mistakes
From Anonymous RPC Enumeration to Domain Admin via Azure AD Connect
⤷ Title: TryHackMe | Detecting AD Initial Access | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:49:14 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #tryhackme_walkthrough #active_directory
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Mon, 04 May 2026 14:49:14 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #tryhackme_walkthrough #active_directory
Medium
TryHackMe | Detecting AD Initial Access | WriteUp
Detect AD initial access attacks by analyzing IIS, NPS, and Windows Security logs.
⤷ Title: Operating Systems: Introduction — TryHackMe Answers | by Deepti Gupta
════════════════════════
𐀪 Author: Deepti Gupta
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:13:54 GMT
════════════════════════
⌗ Tags: #operating_systems #tryhackme #tryhackme_walkthrough #tryhackme_writeup #tryhackme_pre_security
════════════════════════
𐀪 Author: Deepti Gupta
════════════════════════
ⴵ Time: Mon, 04 May 2026 13:13:54 GMT
════════════════════════
⌗ Tags: #operating_systems #tryhackme #tryhackme_walkthrough #tryhackme_writeup #tryhackme_pre_security
Medium
Operating Systems: Introduction — TryHackMe Answers | by Deepti Gupta
Platform: TryHackMe
Room: Operating Systems: Introduction
Room URL: https://tryhackme.com/room/operatingsystemsintroduction
Difficulty…
Room: Operating Systems: Introduction
Room URL: https://tryhackme.com/room/operatingsystemsintroduction
Difficulty…
⤷ Title: ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 04 May 2026 19:53:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 04 May 2026 19:53:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 04 May 2026 15:08:40 +0000
════════════════════════
⌗ Tags: #Security #Cybersecurity #Google #MariaDB #PostgreSQL #Technology #Vulnerability #Wiz #ZeroDay.Cloud
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 04 May 2026 15:08:40 +0000
════════════════════════
⌗ Tags: #Security #Cybersecurity #Google #MariaDB #PostgreSQL #Technology #Vulnerability #Wiz #ZeroDay.Cloud
Hackread
Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
Researchers revealed 20-year-old PostgreSQL flaws at Wiz ZeroDay.Cloud event, exposing critical bugs in pgcrypto and prompting urgent patches for database security.
⤷ Title: Building BB-Recon: My Bug Bounty Recon Automation Pipeline | Cyber Tamarin
════════════════════════
𐀪 Author: Cyber Tamarin
════════════════════════
ⴵ Time: Mon, 04 May 2026 16:40:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #python #automation #penetration_testing
════════════════════════
𐀪 Author: Cyber Tamarin
════════════════════════
ⴵ Time: Mon, 04 May 2026 16:40:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #python #automation #penetration_testing
Medium
Building BB-Recon: My Bug Bounty Recon Automation Pipeline | Cyber Tamarin
How I built a reconnaissance automation tool to speed up attack surface mapping, endpoint discovery, and vulnerability hunting. (Best for…
⤷ Title: From Client-Side Validation to Unauthorized Internal Access
════════════════════════
𐀪 Author: Ahmed ali Omar
════════════════════════
ⴵ Time: Mon, 04 May 2026 16:36:20 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #bug_bounty #broken_access_control #auth_bypass
════════════════════════
𐀪 Author: Ahmed ali Omar
════════════════════════
ⴵ Time: Mon, 04 May 2026 16:36:20 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #bug_bounty #broken_access_control #auth_bypass
Medium
From Client-Side Validation to Unauthorized Internal Access
Overview
⤷ Title: Breaking to find bugs on an Android Attendance App: VA Walkthrough
════════════════════════
𐀪 Author: MR SHAN
════════════════════════
ⴵ Time: Mon, 04 May 2026 10:33:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #bugbounty_tips #mobile_security #cybersecurity
════════════════════════
𐀪 Author: MR SHAN
════════════════════════
ⴵ Time: Mon, 04 May 2026 10:33:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #bugbounty_tips #mobile_security #cybersecurity
Medium
Breaking an Android Attendance App: VA Walkthrough
Hey folks,