⤷ Title: Uber Eats BOLA (IDOR) Vulnerability | $2,000 Bounty | Technical Write-up
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Mon, 11 May 2026 19:04:42 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #idor #bug_bounty_tips #idor_vulnerability
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Mon, 11 May 2026 19:04:42 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #idor #bug_bounty_tips #idor_vulnerability
Medium
Uber Eats BOLA (IDOR) Vulnerability | $2,000 Bounty | Technical Write-up
1. Introduction
⤷ Title: How I Found Critical Security Issues in a Major HR and Payroll Platform and Tried to Report Them…
════════════════════════
𐀪 Author: Tes Sal
════════════════════════
ⴵ Time: Mon, 11 May 2026 19:23:56 GMT
════════════════════════
⌗ Tags: #responsible_disclosure #hacking #ethical_hacking
════════════════════════
𐀪 Author: Tes Sal
════════════════════════
ⴵ Time: Mon, 11 May 2026 19:23:56 GMT
════════════════════════
⌗ Tags: #responsible_disclosure #hacking #ethical_hacking
Medium
How I Found Critical Security Issues in a Major HR and Payroll Platform and Tried to Report Them…
A few weeks ago, I found a set of security issues in a major HR and payroll platform, and the deeper I went, the worse it got.
⤷ Title: KALI LINUX SETUP IN VMWARE
════════════════════════
𐀪 Author: Nayshana.A
════════════════════════
ⴵ Time: Mon, 11 May 2026 20:51:00 GMT
════════════════════════
⌗ Tags: #ethical_hacking #kali_linux_vmware #beginners_guide #cybersecurity #cloud_computing
════════════════════════
𐀪 Author: Nayshana.A
════════════════════════
ⴵ Time: Mon, 11 May 2026 20:51:00 GMT
════════════════════════
⌗ Tags: #ethical_hacking #kali_linux_vmware #beginners_guide #cybersecurity #cloud_computing
Medium
KALI LINUX SETUP IN VMWARE
A simple guide to installing Kali Linux in VMware Workstation for cybersecurity practice.
⤷ Title: Você provavelmente está implementando filtros errado na sua API REST
════════════════════════
𐀪 Author: Erik Barroso
════════════════════════
ⴵ Time: Thu, 07 May 2026 22:11:41 GMT
════════════════════════
⌗ Tags: #filtros #sql_injection #sql #api #rest_api
════════════════════════
𐀪 Author: Erik Barroso
════════════════════════
ⴵ Time: Thu, 07 May 2026 22:11:41 GMT
════════════════════════
⌗ Tags: #filtros #sql_injection #sql #api #rest_api
Medium
Você provavelmente está implementando filtros errado na sua API REST
Filtros parecem apenas query params, mas envolvem validação, segurança, autorização, performance, paginação, cache e consistência de…
⤷ Title: Google Says Hackers Used AI to Develop a Zero-Day Exploit
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:41 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #0day #AI #Android #backdoor #Cyber Attack #Cybersecurity #GitHub #Google #Malware #PyPI #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:41 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #0day #AI #Android #backdoor #Cyber Attack #Cybersecurity #GitHub #Google #Malware #PyPI #Vulnerability
Hackread
Google Says Hackers Used AI to Develop a Zero-Day Exploit
Google researchers say hackers used AI to develop zero-day exploits, Android backdoors, and automated supply chain attacks targeting GitHub and PyPI.
⤷ Title: I found a secret door into an admin panel — and got paid $750 for it
════════════════════════
𐀪 Author: Syedfaiz
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #burp #bug_bounty_writeup
════════════════════════
𐀪 Author: Syedfaiz
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #burp #bug_bounty_writeup
Medium
I found a secret door into an admin panel — and got paid $750 for it
The website said “you can’t sign up.” I found out that was only half true.
⤷ Title: Decentralised Digital Security E-book Out Now (Open Access)
════════════════════════
𐀪 Author: Kelsie Nabben
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:19:35 GMT
════════════════════════
⌗ Tags: #cryptocurrency #hacking #security #blockchain #white_hat_hacker
════════════════════════
𐀪 Author: Kelsie Nabben
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:19:35 GMT
════════════════════════
⌗ Tags: #cryptocurrency #hacking #security #blockchain #white_hat_hacker
Medium
Decentralised Digital Security E-book Out Now (Open Access)
In a world of hacks, scams, freezes, phishing, funding, incident research, and rescues, April 2026 was one of the worst months for…
⤷ Title: The ESP32 Has Quietly Become One of the Most Interesting Hacker Devices Alive
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:17:17 GMT
════════════════════════
⌗ Tags: #esp32 #hacking_tools #cybersecurity #hacking #embedded_systems
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:17:17 GMT
════════════════════════
⌗ Tags: #esp32 #hacking_tools #cybersecurity #hacking #embedded_systems
Medium
The ESP32 Has Quietly Become One of the Most Interesting Hacker Devices Alive
Rainwater was dripping through a hole in the gas station awning onto a plastic patio chair that nobody ever sat in. Beside the propane…
⤷ Title: My Backpack Is Slowly Turning Into a Mobile Recon Lab
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:03:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #embedded_systems #esp32 #makers
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:03:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #embedded_systems #esp32 #makers
Medium
My Backpack Is Slowly Turning Into a Mobile Recon Lab
The zipper gave up before I did.
⤷ Title: Turning a Helpdesk Escalation Into a ShinyHunters Threat Intelligence Investigation
════════════════════════
𐀪 Author: Tijan Hydara
════════════════════════
ⴵ Time: Mon, 11 May 2026 21:54:40 GMT
════════════════════════
⌗ Tags: #canvas #infosec #cybersecurity #higher_education #shinyhunters
════════════════════════
𐀪 Author: Tijan Hydara
════════════════════════
ⴵ Time: Mon, 11 May 2026 21:54:40 GMT
════════════════════════
⌗ Tags: #canvas #infosec #cybersecurity #higher_education #shinyhunters
⤷ Title: Breaking CalBot: Exploiting Indirect Prompt Injection in TryHackMe’s LLMborghini Room
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
ⴵ Time: Mon, 11 May 2026 21:13:12 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #ai #tryhackme_walkthrough #ctf_writeup
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
ⴵ Time: Mon, 11 May 2026 21:13:12 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #ai #tryhackme_walkthrough #ctf_writeup
Medium
Breaking CalBot: Exploiting Indirect Prompt Injection in TryHackMe’s LLMborghini Room
The TryHackMe room “LLMborghini” is a short but clever AI security challenge focused on indirect prompt injection against an AI-powered…
⤷ Title: Guía de Inyección NoSQL: Fundamentos, Tipos, Explotación y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 12 May 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #nosql #technology #bug_bounty #hacking #cybersecurity
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 12 May 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #nosql #technology #bug_bounty #hacking #cybersecurity
Medium
Guía de Inyección NoSQL: Fundamentos, Tipos, Explotación y Mitigación
Aprende los fundamentos de la inyección NoSQL, vectores de ataque en MongoDB y estrategias avanzadas de explotación y defensa.
⤷ Title: OverTheWire Bandit Walkthrough — Level 0 → 1 | 30-Day Cybersecurity Learning Journey (Day 1)
════════════════════════
𐀪 Author: William | Cybersecurity & SOC Analyst
════════════════════════
ⴵ Time: Mon, 11 May 2026 23:29:51 GMT
════════════════════════
⌗ Tags: #linux #cybersecurity #ctf #infosec #security
════════════════════════
𐀪 Author: William | Cybersecurity & SOC Analyst
════════════════════════
ⴵ Time: Mon, 11 May 2026 23:29:51 GMT
════════════════════════
⌗ Tags: #linux #cybersecurity #ctf #infosec #security
Medium
OverTheWire Bandit Walkthrough — Level 0 → 1 | 30-Day Cybersecurity Learning Journey (Day 1)
Reading your first file over SSH and why knowing your way around a remote Linux terminal is the foundation of every SOC skill that follows.
⤷ Title: Your Router Is Leaking More Than Wi-Fi: What I Found While Exploring RF Signals
════════════════════════
𐀪 Author: Michael Preston
════════════════════════
ⴵ Time: Tue, 12 May 2026 00:06:00 GMT
════════════════════════
⌗ Tags: #wifihacking #networking #radio #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Michael Preston
════════════════════════
ⴵ Time: Tue, 12 May 2026 00:06:00 GMT
════════════════════════
⌗ Tags: #wifihacking #networking #radio #cybersecurity #ethical_hacking
Medium
Your Router Is Leaking More Than Wi-Fi: What I Found While Exploring RF Signals
A deep dive into hidden wireless communications, insecure protocols, and why the spectrum reveals more than most networks ever will.
⤷ Title: HackTheBox Walkthrough — Overwatch
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Mon, 11 May 2026 23:19:20 GMT
════════════════════════
⌗ Tags: #adidns_poisoning #mssql_linked_server #htb_overwatch_walkthrough #ethical_hacking #hacking_windows_ad
════════════════════════
𐀪 Author: Indigo Shadow
════════════════════════
ⴵ Time: Mon, 11 May 2026 23:19:20 GMT
════════════════════════
⌗ Tags: #adidns_poisoning #mssql_linked_server #htb_overwatch_walkthrough #ethical_hacking #hacking_windows_ad
Medium
HackTheBox Walkthrough — Overwatch
#ADIDNS-Poisoning #MSSQL-Linked-server #Windows-Domain-Controller #Decompile-dot-net-application #Analyse-dot-net-application #WCF-service…
⤷ Title: Critical PrestaShop Flaw Allows Hijacking via “Contact Us” Form
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:11:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Back_office Hijacking #Cross_Site Scripting #CVE_2026_44212 #e_commerce security #infosec #Patch Alert #PHP Security #PrestaShop #Stored XSS #Web Security #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:11:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Back_office Hijacking #Cross_Site Scripting #CVE_2026_44212 #e_commerce security #infosec #Patch Alert #PHP Security #PrestaShop #Stored XSS #Web Security #XSS
Daily CyberSecurity
Critical PrestaShop Flaw Allows Hijacking via “Contact Us” Form
PrestaShop, the global open-source e-commerce powerhouse known for its highly customizable PHP architecture and responsive design, has issued an urgent security update. Used by merchants worldwide…
⤷ Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Daily CyberSecurity
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
Urgent: 84 TanStack npm packages hijacked to harvest GitHub Actions secrets. Over 12M weekly downloads impacted. Audit your CI/CD pipelines and rotate tokens.
⤷ Title: 9.6 Severity: Critical “Cline” AI Agent Flaw Allows Stealthy RCE via Your Browser
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:20:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cline AI #CVE_2026_44211 #DevSecOps #infosec #Localhost Vulnerability #npm Security #rce #Remote Code Execution #Web Security #WebSocket Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:20:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cline AI #CVE_2026_44211 #DevSecOps #infosec #Localhost Vulnerability #npm Security #rce #Remote Code Execution #Web Security #WebSocket Hijacking
Daily CyberSecurity
9.6 Severity: Critical "Cline" AI Agent Flaw Allows Stealthy RCE via Your Browser
Critical Alert: CVE-2026-44211 (CVSS 9.6) in Cline AI allows malicious sites to hijack your terminal and steal data via WebSockets. Update your CLI tools now.
⤷ Title: Proof-of-Concept Disclosed: New “BitUnlocker” Attack Bypasses Patched Windows 11 BitLocker via Certificate Downgrade
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:01:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #bitlocker #BitUnlocker #CVE_2025_48804 #downgrade attack #github #infosec #Intrinsec #Microsoft STORM #PoC #Secure Boot #TPM #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:01:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #bitlocker #BitUnlocker #CVE_2025_48804 #downgrade attack #github #infosec #Intrinsec #Microsoft STORM #PoC #Secure Boot #TPM #Windows 11
Daily CyberSecurity
Proof-of-Concept Disclosed: New "BitUnlocker" Attack Bypasses Patched Windows 11 BitLocker via Certificate Downgrade
Public PoC Alert: The BitUnlocker Downgrade Attack bypasses BitLocker on patched Windows 11 machines in under 5 minutes. Learn how to secure your TPM with a PIN.
⤷ Title: Software Supply Chain Failures — The #3 Risk in Modern Applications
════════════════════════
𐀪 Author: loopXvedant
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:31:00 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #cybersecurity #owasp_top_10
════════════════════════
𐀪 Author: loopXvedant
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:31:00 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #cybersecurity #owasp_top_10
Medium
Software Supply Chain Failures — The #3 Risk in Modern Applications 📦
When the code you trust becomes the weapon used against you.
⤷ Title: Kenapa Laporan Celah Keamanan di Kampus Sering Cuma Berakhir Di-”Read”? Sebuah Catatan Pinggir
════════════════════════
𐀪 Author: Gempur budi anarki
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:15:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #information_security #education #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Gempur budi anarki
════════════════════════
ⴵ Time: Tue, 12 May 2026 02:15:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #information_security #education #ethical_hacking #cybersecurity
Medium
Kenapa Laporan Celah Keamanan di Kampus Sering Cuma Berakhir Di-”Read”? Sebuah Catatan Pinggir
Disclaimer: Tulisan ini dibuat murni untuk tujuan edukasi dan kesadaran keamanan siber (Security Awareness). Saya tidak akan menyebutkan…