⤷ Title: When .. Costs You Everything: A Path Traversal in Gemini CLI's Skill Installer
════════════════════════
𐀪 Author: Farhad Sajid Barbhuiya
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:48:09 GMT
════════════════════════
⌗ Tags: #gemini_cli #cybersecurity #bug_bounty #agents #ai
════════════════════════
𐀪 Author: Farhad Sajid Barbhuiya
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:48:09 GMT
════════════════════════
⌗ Tags: #gemini_cli #cybersecurity #bug_bounty #agents #ai
Medium
When .. Costs You Everything: A Path Traversal in Gemini CLI's Skill Installer
TL;DR — A single missing character in a sanitizer regex allowed a malicious SKILL.md to recursively delete ~/.gemini and replace it with…
⤷ Title: The Brutal Truth About Bug Bounty in India (My First $150 Story)
════════════════════════
𐀪 Author: Aman Kumar (ak)
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:32:08 GMT
════════════════════════
⌗ Tags: #self_improvement #bug_bounty #cybersecurity #india #career_advice
════════════════════════
𐀪 Author: Aman Kumar (ak)
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:32:08 GMT
════════════════════════
⌗ Tags: #self_improvement #bug_bounty #cybersecurity #india #career_advice
Medium
The Brutal Truth About Bug Bounty in India (My First $150 Story)
320 government acknowledgments. National recognition. Zero dollars in my account. This is the story Indian beginners need to hear before…
⤷ Title: The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:45 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #bug_bounty #github_actions #ci_cd_pipeline
Medium
The Trojan PR: Achieving Code Execution in GitHub Actions via Pipeline Poisoning
Introduction
⤷ Title: Strix | Open-Source AI for Finding App Vulnerabilities
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Fri, 15 May 2026 11:26:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #hacking #artificial_intelligence #bug_bounty
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Fri, 15 May 2026 11:26:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #hacking #artificial_intelligence #bug_bounty
Medium
Strix | Open-Source AI for Finding App Vulnerabilities
Open-Source AI for Finding & Fixing Application Vulnerabilities
⤷ Title: How Internal Application Paths Were Exposed Without Login
════════════════════════
𐀪 Author: Shravanigolait
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:17:26 GMT
════════════════════════
⌗ Tags: #application_security #ethical_hacking #owasp #web_security #cybersecurity
════════════════════════
𐀪 Author: Shravanigolait
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:17:26 GMT
════════════════════════
⌗ Tags: #application_security #ethical_hacking #owasp #web_security #cybersecurity
Medium
How Internal Application Paths Were Exposed Without Login
Introduction
⤷ Title: Broken Access Control in SourceCodester Online Boat Reservation System 1.0
════════════════════════
𐀪 Author: Hemant Raj Bhati
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:06:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #web_security #application_security #web_penetration_testing
════════════════════════
𐀪 Author: Hemant Raj Bhati
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:06:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #web_security #application_security #web_penetration_testing
Medium
Broken Access Control in SourceCodester Online Boat Reservation System 1.0
Summary
⤷ Title: I Watched an AI Hack a Home Network in Under 10 Minutes
════════════════════════
𐀪 Author: Jazz Cyber Shield
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:37:51 GMT
════════════════════════
⌗ Tags: #technology #artificial_intelligence #cybersecurity #home_network #hacking
════════════════════════
𐀪 Author: Jazz Cyber Shield
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:37:51 GMT
════════════════════════
⌗ Tags: #technology #artificial_intelligence #cybersecurity #home_network #hacking
Medium
I Watched an AI Hack a Home Network in Under 10 Minutes. I’m Still Shaking.
AI hacking tools now break into home routers automatically in minutes. I saw it happen live. Here's what works — and what doesn't — in 2026.
⤷ Title: 5 erreurs de cybersécurité que font (presque) tous les particuliers
════════════════════════
𐀪 Author: Christophe Serres
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:56 GMT
════════════════════════
⌗ Tags: #hacking #sécurité_informatique #cybersécurité #internet
════════════════════════
𐀪 Author: Christophe Serres
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:18:56 GMT
════════════════════════
⌗ Tags: #hacking #sécurité_informatique #cybersécurité #internet
Medium
5 erreurs de cybersécurité que font (presque) tous les particuliers
On pense souvent que les cyberattaques, c’est pour les grandes entreprises... Faux. Depuis ce début d’année, entre les vols de données des…
⤷ Title: Galaxy Dash (IDOR) Bugforge.io
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Fri, 15 May 2026 11:31:00 GMT
════════════════════════
⌗ Tags: #ctf_writeup #ctf #idor #hacking #bugforge
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Fri, 15 May 2026 11:31:00 GMT
════════════════════════
⌗ Tags: #ctf_writeup #ctf #idor #hacking #bugforge
Medium
Galaxy Dash (IDOR) Bugforge.io
Lab can be found at: https://bugforge.io
⤷ Title: Critical Data Exposure in the Academic Network (IUCC/Eduroam) — Security Analysis.
════════════════════════
𐀪 Author: LockerHacker
════════════════════════
ⴵ Time: Fri, 15 May 2026 08:38:49 GMT
════════════════════════
⌗ Tags: #hacking
════════════════════════
𐀪 Author: LockerHacker
════════════════════════
ⴵ Time: Fri, 15 May 2026 08:38:49 GMT
════════════════════════
⌗ Tags: #hacking
Medium
ritical Data Exposure in the Academic Network (IUCC/Eduroam) — Security Analysis.
BREAKING: Major security breach in the Israeli Inter-University Computation Center (IUCC). Critical infrastructure files for #Eduroam…
⤷ Title: Penetration Testing Training Guide for Cyber Security Careers
════════════════════════
𐀪 Author: Application Security Master
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:14:09 GMT
════════════════════════
⌗ Tags: #web_applications #penetration_testing #penetration_training
════════════════════════
𐀪 Author: Application Security Master
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:14:09 GMT
════════════════════════
⌗ Tags: #web_applications #penetration_testing #penetration_training
Medium
Penetration Testing Training Guide for Cyber Security Careers
It helps learners understand how attackers think and how defenses can be strengthened effectively. This field is now one of the most…
⤷ Title: Improper Session Invalidation in Online Boat Reservation System using PHP
════════════════════════
𐀪 Author: Hemant Raj Bhati
════════════════════════
ⴵ Time: Fri, 15 May 2026 11:41:42 GMT
════════════════════════
⌗ Tags: #vapt #penetration_testing #trending #cybersecurity #web_security
════════════════════════
𐀪 Author: Hemant Raj Bhati
════════════════════════
ⴵ Time: Fri, 15 May 2026 11:41:42 GMT
════════════════════════
⌗ Tags: #vapt #penetration_testing #trending #cybersecurity #web_security
Medium
Improper Session Invalidation in Online Boat Reservation System using PHP
Vulnerability Title
⤷ Title: Bounty Hacker — TryHackMe WalkThrough
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Fri, 15 May 2026 10:52:34 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #tryhackme #cybersecurity #tryhackme_writeup
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Fri, 15 May 2026 10:52:34 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #tryhackme #cybersecurity #tryhackme_writeup
Medium
Bounty Hacker — TryHackMe WalkThrough
Date: 27/08/2025
⤷ Title: How I Turned a ‘Low Severity’ Reflected XSS into Full Account Takeover
════════════════════════
𐀪 Author: Ashar Mahmood
════════════════════════
ⴵ Time: Thu, 14 May 2026 14:26:29 GMT
════════════════════════
⌗ Tags: #infosec #info_sec_writeups #hacking #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Ashar Mahmood
════════════════════════
ⴵ Time: Thu, 14 May 2026 14:26:29 GMT
════════════════════════
⌗ Tags: #infosec #info_sec_writeups #hacking #bug_bounty #bug_bounty_writeup
Medium
How I Turned a ‘Low Severity’ Reflected XSS into Full Account Takeover
Hello hackers! It’s me Ashar, here again. 👨💻
⤷ Title: 【 Java Persistence API 】- 複雜查詢只能退回寫原生 SQL?掌握 JPQL 寫出優雅的物件導向查詢
════════════════════════
𐀪 Author: CoreyLi
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:01:00 GMT
════════════════════════
⌗ Tags: #sql_injection #orm #jpa #java #spring_data_jpa
════════════════════════
𐀪 Author: CoreyLi
════════════════════════
ⴵ Time: Fri, 15 May 2026 12:01:00 GMT
════════════════════════
⌗ Tags: #sql_injection #orm #jpa #java #spring_data_jpa
Medium
【 Java Persistence API 】- 複雜查詢只能退回寫原生 SQL?掌握 JPQL 寫出優雅的物件導向查詢
I. 查詢的轉捩點
⤷ Title: RaccoonLine Publishes 2026 Report on Global VPN Blocking and DPI Enforcement
════════════════════════
𐀪 Author: cybernewswire
════════════════════════
ⴵ Time: Fri, 15 May 2026 14:57:09 +0000
════════════════════════
⌗ Tags: #Press Release
════════════════════════
𐀪 Author: cybernewswire
════════════════════════
ⴵ Time: Fri, 15 May 2026 14:57:09 +0000
════════════════════════
⌗ Tags: #Press Release
Daily CyberSecurity
RaccoonLine Publishes 2026 Report on Global VPN Blocking and DPI Enforcement
Rome, Italy, 15th May 2026, CyberNewswire
⤷ Title: Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program
════════════════════════
𐀪 Author: Natalie Guevara
════════════════════════
ⴵ Time: Fri, 15 May 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Security #bug bounty #security research
════════════════════════
𐀪 Author: Natalie Guevara
════════════════════════
ⴵ Time: Fri, 15 May 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Security #bug bounty #security research
The GitHub Blog
Raising the bar: Quality, shared responsibility, and the future of GitHub's bug bounty program
We're updating our bug bounty program standards to prioritize quality submissions and clarify shared responsibility boundaries.
⤷ Title: $900 IDOR: Unauthorized Access to Form Attachments via Direct API
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Fri, 15 May 2026 13:31:00 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #idor #bug_bounty #security
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Fri, 15 May 2026 13:31:00 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #idor #bug_bounty #security
Medium
$900 IDOR: Unauthorized Access to Form Attachments via Direct API
Hi Everyone! While testing a SaaS platform (ExampleCenter), I discovered an authorization bypass vulnerability that allowed a…
⤷ Title: ⚡ Recon → Exploit Pipeline — How I Turn Raw Recon Into Real Findings
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Fri, 15 May 2026 13:09:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #bug_bounty #hacking #linux
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Fri, 15 May 2026 13:09:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #bug_bounty #hacking #linux
Medium
⚡ Recon → Exploit Pipeline — How I Turn Raw Recon Into Real Findings
🎯 Series
⤷ Title: The MCP package looked clean. The installed tree did not.
════════════════════════
𐀪 Author: Oleg Grishanovich
════════════════════════
ⴵ Time: Fri, 15 May 2026 14:29:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #security_research #application_security #ai #ai_agent
════════════════════════
𐀪 Author: Oleg Grishanovich
════════════════════════
ⴵ Time: Fri, 15 May 2026 14:29:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #security_research #application_security #ai #ai_agent
Medium
The MCP package looked clean. The installed tree did not.
We audited 31 MCP server packages across npm and PyPI.
⤷ Title: I Mistyped a URL and a Hacker Set Up Camp in My Browser
════════════════════════
𐀪 Author: Eileenhope
════════════════════════
ⴵ Time: Fri, 15 May 2026 13:32:59 GMT
════════════════════════
⌗ Tags: #socialengineeringattack #cybersecurity #hacking #typosquatting #cyberattack
════════════════════════
𐀪 Author: Eileenhope
════════════════════════
ⴵ Time: Fri, 15 May 2026 13:32:59 GMT
════════════════════════
⌗ Tags: #socialengineeringattack #cybersecurity #hacking #typosquatting #cyberattack
Medium
I Mistyped a URL and a Hacker Set Up Camp in My Browser
How a single typo, an invisible clipboard hijack, and one wrong keystroke gave a stranger a front-row seat to everything on my computer.