⤷ Title: 7 API Security Mistakes I’ve Seen in Almost Every Python Backend
════════════════════════
𐀪 Author: Anas Issath
════════════════════════
ⴵ Time: Wed, 06 May 2026 16:45:24 GMT
════════════════════════
⌗ Tags: #backend_development #django #api_security #fastapi #owasp
════════════════════════
𐀪 Author: Anas Issath
════════════════════════
ⴵ Time: Wed, 06 May 2026 16:45:24 GMT
════════════════════════
⌗ Tags: #backend_development #django #api_security #fastapi #owasp
Medium
7 API Security Mistakes I’ve Seen in Almost Every Python Backend
Your API works. An attacker just needs it to work differently once.
⤷ Title: ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:28:28 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #Anodot #Canvas #Cyber Attack #Cyber Crime #Cybersecurity #data breach #Instructure #Privacy #ShinyHunters #Vimeo #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:28:28 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #Anodot #Canvas #Cyber Attack #Cyber Crime #Cybersecurity #data breach #Instructure #Privacy #ShinyHunters #Vimeo #Vulnerability
Hackread
ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users
ShinyHunters breached Instructure and Vimeo, exposing millions of student and user records through direct and supply chain attacks.
⤷ Title: Following the Supply Chain: How Vendor Leaks Exposed the Real Target
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:19:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #info_sec_writeups #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:19:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #info_sec_writeups #bug_bounty #bug_bounty_tips
Medium
Following the Supply Chain: How Vendor Leaks Exposed the Real Target 🏭🔗
Free Link 🎈
⤷ Title: I Found !! Full Account Takeover via OAuth Linking CSRF bugs
════════════════════════
𐀪 Author: Skysenz
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:00:55 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: Skysenz
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:00:55 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
I Found !! Full Account Takeover via OAuth Linking CSRF bugs
Halo semua, saya mau sharing bug Full Account Takeover lewat celah OAuth Linking CSRF yang baru saja masuk tahap Pending Program Review
⤷ Title: Copy Fail (CVE-2026–31431): Why this is worse than Dirty Cow and Dirty Pipe
════════════════════════
𐀪 Author: Nomit Vyas
════════════════════════
ⴵ Time: Wed, 06 May 2026 16:57:48 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity #linux #bug_bounty
════════════════════════
𐀪 Author: Nomit Vyas
════════════════════════
ⴵ Time: Wed, 06 May 2026 16:57:48 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity #linux #bug_bounty
Medium
Copy Fail (CVE-2026–31431): Why this is worse than Dirty Cow and Dirty Pipe
A walkthrough of CVE-2026–31431 — the page-cache write that turns the kernel’s crypto API into a privilege-escalation primitive.
⤷ Title: OAuth 2.0 & OIDC — How modern authentication actually works under the hood
════════════════════════
𐀪 Author: Reuben Lim
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:17:15 GMT
════════════════════════
⌗ Tags: #authentication #oauth2 #openid_connect #application_security #web_development
════════════════════════
𐀪 Author: Reuben Lim
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:17:15 GMT
════════════════════════
⌗ Tags: #authentication #oauth2 #openid_connect #application_security #web_development
Medium
OAuth 2.0 & OIDC — How modern authentication actually works under the hood
I once spent three hours debugging an authentication flow where a client was sending the client_secret in the URL query parameters. It…
⤷ Title: OffSec Proving Grounds “EvilBox-One” Writeup
════════════════════════
𐀪 Author: sabR
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:47:18 GMT
════════════════════════
⌗ Tags: #hackthebox #ethical_hacking #hacking #ctf #penetration_testing
════════════════════════
𐀪 Author: sabR
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:47:18 GMT
════════════════════════
⌗ Tags: #hackthebox #ethical_hacking #hacking #ctf #penetration_testing
Medium
OffSec Proving Grounds “EvilBox-One” Writeup
Step 1: Reconnaissance
⤷ Title: The Mirai Botnet: How a Few College Kids Broke the Internet with Your Security Camera
════════════════════════
𐀪 Author: Uladzislau Bayouski
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:16:01 GMT
════════════════════════
⌗ Tags: #internet_of_things #cybersecurity #technology #privacy #hacking
════════════════════════
𐀪 Author: Uladzislau Bayouski
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:16:01 GMT
════════════════════════
⌗ Tags: #internet_of_things #cybersecurity #technology #privacy #hacking
Medium
The Mirai Botnet: How a Few College Kids Broke the Internet with Your Security Camera
On October 21, 2016, millions of people sat down at their computers and found that half the internet simply didn’t work.
⤷ Title: From the Terminal to the Browser: Building a Modern OSINT Platform on Top of recon-ng
════════════════════════
𐀪 Author: Mirko
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:23:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #docker #cybersecurity #osint_tool #information_gathering
════════════════════════
𐀪 Author: Mirko
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:23:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #docker #cybersecurity #osint_tool #information_gathering
Medium
From the Terminal to the Browser: Building a Modern OSINT Platform on Top of recon-ng
recon-ng-ui: The Web Interface Professional OSINT Was Missing
⤷ Title: Intercepting Flutter App Traffic: Bypassing Anti-Proxy & SSL Pinning on Android
════════════════════════
𐀪 Author: 5xyj : ]
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:03:47 GMT
════════════════════════
⌗ Tags: #android_security #cybersecurity #penetration_testing #flutter #mobile_security
════════════════════════
𐀪 Author: 5xyj : ]
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:03:47 GMT
════════════════════════
⌗ Tags: #android_security #cybersecurity #penetration_testing #flutter #mobile_security
Medium
Intercepting Flutter App Traffic: Bypassing Anti-Proxy & SSL Pinning on Android
A practical VAPT walkthrough — how I intercepted a Flutter-based Android app using reFlutter, iptables, and Burp Suite on an Android…
⤷ Title: Writing Your First NSE Script
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:03:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #ethical_hacking #lua #nmap
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:03:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #ethical_hacking #lua #nmap
Medium
Writing Your First NSE Script
You don’t need to be a developer to write your own Nmap scripts. You just need 30 lines of Lua and something to automate.
⤷ Title: Windows PrivEsc (THM) Tryhackme Writeup Answer
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:03:07 GMT
════════════════════════
⌗ Tags: #privilege_escalation #windows #tryhackme #windows_privilege_esc #cybersecurity
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Wed, 06 May 2026 18:03:07 GMT
════════════════════════
⌗ Tags: #privilege_escalation #windows #tryhackme #windows_privilege_esc #cybersecurity
Medium
Windows PrivEsc (THM) Tryhackme Writeup Answer
Description : Practice your Windows Privilege Escalation skills on an intentionally misconfigured Windows VM with multiple ways to get…
⤷ Title: Social Sharing Center
════════════════════════
𐀪 Author: Gil Nobodi
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:04:37 GMT
════════════════════════
⌗ Tags: #sharing #xs #substack #medium #social_media
════════════════════════
𐀪 Author: Gil Nobodi
════════════════════════
ⴵ Time: Wed, 06 May 2026 17:04:37 GMT
════════════════════════
⌗ Tags: #sharing #xs #substack #medium #social_media
Medium
Social Sharing Center
I want to start this update with the obvious. A common notion among writers is that they are too busy to explore multiple sites or apps…
⤷ Title: Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 07 May 2026 01:51:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 07 May 2026 01:51:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:02:52 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Google #Cybersecurity #Gemini CLI #GitHub #Pillar Security #RCE #Technology #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:02:52 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #Google #Cybersecurity #Gemini CLI #GitHub #Pillar Security #RCE #Technology #Vulnerability
Hackread
Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE
Google patches a CVSS 10 Gemini CLI vulnerability that allowed hackers to use prompt injection and privilege escalation for a full supply chain compromise.
⤷ Title: Automating High-Risk Database Info Disclosure via GraphQL Misconfiguration
════════════════════════
𐀪 Author: m00nissmiling
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:25:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #cybersecurity #graphql #pentesting
════════════════════════
𐀪 Author: m00nissmiling
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:25:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #cybersecurity #graphql #pentesting
Medium
Automating High-Risk Database Info Disclosure via GraphQL Misconfiguration
Let's automate the graphql misconfiguration using this tool !
⤷ Title: 1.5 Million Websites Got Hacked in 2026 — And Most Owners Still Don’t Know
════════════════════════
𐀪 Author: Jazz Cyber Shield
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:57:38 GMT
════════════════════════
⌗ Tags: #hacking #web_hosting #cybersecurity #technology
════════════════════════
𐀪 Author: Jazz Cyber Shield
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:57:38 GMT
════════════════════════
⌗ Tags: #hacking #web_hosting #cybersecurity #technology
Medium
1.5 Million Websites Got Hacked in 2026 — And Most Owners Still Don’t Know
Your hosting panel has a hole so wide that attackers walked in months before anyone noticed. Here’s what happened, and what you must do…
⤷ Title: Critical Apache HTTP Server Flaw CVE-2026–23918 — DoS and RCE With Two HTTP/2 Frames. Patch Now.
════════════════════════
𐀪 Author: Sai kiran
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:37:18 GMT
════════════════════════
⌗ Tags: #vulnerability #infosec #apache #cybersecurity #web_security
════════════════════════
𐀪 Author: Sai kiran
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:37:18 GMT
════════════════════════
⌗ Tags: #vulnerability #infosec #apache #cybersecurity #web_security
Medium
Critical Apache HTTP Server Flaw CVE-2026–23918 — DoS and RCE With Two HTTP/2 Frames. Patch Now.
CVSS 8.8. One TCP connection. Two crafted HTTP/2 frames. No authentication. Worker process crashed. And in the right conditions — full…
⤷ Title: Critical Apache HTTP Server RCE and DoS Vulnerability (CVE-2026–23918)
════════════════════════
𐀪 Author: RealSec.io
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:26:43 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #infosec
════════════════════════
𐀪 Author: RealSec.io
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:26:43 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #infosec
Medium
Critical Apache HTTP Server RCE and DoS Vulnerability (CVE-2026–23918)
The Apache Software Foundation has just released a critical security update addressing an important flaw (CVE-2026–23918) impacting the…
⤷ Title: Understanding Darknet Drug Scams: Why Visibility Does Not Equal Trust
════════════════════════
𐀪 Author: Tor BBB
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:13:02 GMT
════════════════════════
⌗ Tags: #osint #darkweb #cybersecurity #infosec
════════════════════════
𐀪 Author: Tor BBB
════════════════════════
ⴵ Time: Wed, 06 May 2026 19:13:02 GMT
════════════════════════
⌗ Tags: #osint #darkweb #cybersecurity #infosec
Medium
Understanding Darknet Drug Scams: Why Visibility Does Not Equal Trust
Discussions about darknet drug scams often focus on obvious fraud. However, the more useful lesson is how trust gets created in anonymous…
⤷ Title: API Pen Testing : Zero to Hero Hands on Labs
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:01:01 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #owasp_api_security_top_10 #web_security #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Wed, 06 May 2026 20:01:01 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #owasp_api_security_top_10 #web_security #penetration_testing #cybersecurity
Medium
API Pen Testing : Zero to Hero Hands on Labs
1. Introduction