⤷ Title: Walkthrough: TryHackMe Recruit
════════════════════════
𐀪 Author: MistressOfTheDarkweb
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 21:30:23 GMT
════════════════════════
⌗ Tags: #sql_injection #tryhackme #cybersecurity #ctf #penetration_testing
════════════════════════
𐀪 Author: MistressOfTheDarkweb
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 21:30:23 GMT
════════════════════════
⌗ Tags: #sql_injection #tryhackme #cybersecurity #ctf #penetration_testing
Medium
Walkthrough: TryHackMe Recruit
Recruit has just launched its new recruitment portal, allowing HR staff to manage candidate applications and administrators to oversee…
⤷ Title: Breach Files #006: MOVEit Transfer (2023)
════════════════════════
𐀪 Author: NullyBlissful
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 02:31:00 GMT
════════════════════════
⌗ Tags: #sql_injection #mitre_attack #cybersecurity #infosec #ransomware
════════════════════════
𐀪 Author: NullyBlissful
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 02:31:00 GMT
════════════════════════
⌗ Tags: #sql_injection #mitre_attack #cybersecurity #infosec #ransomware
Medium
Breach Files #006: MOVEit Transfer (2023)
One SQL Injection. 2,000+ Victims. The Biggest Mass-Hack in Recent History.
⤷ Title: SOC127 — SQL Injection Detected
════════════════════════
𐀪 Author: Mistermanuniq
════════════════════════
ⴵ Time: Sun, 07 Jun 2026 15:39:35 GMT
════════════════════════
⌗ Tags: #sql_injection #soc127 #letsdefendio #lets_defend #letsdefend_writeup
════════════════════════
𐀪 Author: Mistermanuniq
════════════════════════
ⴵ Time: Sun, 07 Jun 2026 15:39:35 GMT
════════════════════════
⌗ Tags: #sql_injection #soc127 #letsdefendio #lets_defend #letsdefend_writeup
Medium
SOC127 — SQL Injection Detected
Today , we are going to investigate the SOC127 alert in LetsDefend.
⤷ Title: Easy 150$ Bounty: Delete all votes
════════════════════════
𐀪 Author: Musab Sarı
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 15:31:56 GMT
════════════════════════
⌗ Tags: #hackerone #cybersecurity #bug_bounty #bug_bounty_writeup #broken_access_control
════════════════════════
𐀪 Author: Musab Sarı
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 15:31:56 GMT
════════════════════════
⌗ Tags: #hackerone #cybersecurity #bug_bounty #bug_bounty_writeup #broken_access_control
Medium
Easy 150$ Bounty: Delete all votes
I have been hunting for a while on the Hackerone public program and what I learned is If you choose the right program and spend more time…
⤷ Title: IDOR allows non-group members to add any group to favorites on their Facebook profile
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:47:33 GMT
════════════════════════
⌗ Tags: #meta_bug_bounty #facebook_bug_bounty #idor #bug_bounty_writeup
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:47:33 GMT
════════════════════════
⌗ Tags: #meta_bug_bounty #facebook_bug_bounty #idor #bug_bounty_writeup
Medium
IDOR allows non-group members to add any group to favorites on their Facebook profile
Allows users who are not members of a group to add any group to their favorites on their Facebook profile.
⤷ Title: Non-group members can be added to projects even though the “Users cannot be added to projects in…
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:31:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #business_logic_flaw #gitlab
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:31:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #business_logic_flaw #gitlab
Medium
Non-group members can be added to projects even though the “Users cannot be added to projects in…
https://gitlab.com/gitlab-org/gitlab/-/work_items/551267
⤷ Title: These Low-Hanging Fruit bugs Made Me $120+ in 30 Minutes — Bugs That 80% of Hunters Ignore
════════════════════════
𐀪 Author: Bhavishthakral
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:38:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_writeup
════════════════════════
𐀪 Author: Bhavishthakral
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:38:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_writeup
Medium
These Low-Hanging Fruit bugs Made Me $120+ in 30 Minutes — Bugs That 80% of Hunters Ignore
These Low-Hanging Fruits Made Me $120+ in 30 Minutes — Bugs That 80% of Hunters Ignore Hi everyone , bhavish here When people think about bug bounty, they imagine critical RCEs, SQL injections, and …
⤷ Title: How I Found a Critical OAuth Misconfiguration That Led to Account Takeover
════════════════════════
𐀪 Author: Shafayat Ahmed Alif
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:21:17 GMT
════════════════════════
⌗ Tags: #account_takeover #bug_bounty_tips #bug_bounty #cybersecurity #bug_bounty_writeup
════════════════════════
𐀪 Author: Shafayat Ahmed Alif
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:21:17 GMT
════════════════════════
⌗ Tags: #account_takeover #bug_bounty_tips #bug_bounty #cybersecurity #bug_bounty_writeup
Medium
How I Found a Critical OAuth Misconfiguration That Led to Account Takeover
A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues chained together into a critical account…
⤷ Title: API Hacking Sounds Scary Until You Realize It’s Just Changing Numbers
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 04:03:40 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 04:03:40 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
Medium
API Hacking Sounds Scary Until You Realize It’s Just Changing Numbers
No complex setups. No secret tools. Just you and your browser.
⤷ Title: Broken Access Control leads to delete any user’s comment
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 21:34:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #penetration_testing
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 21:34:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #penetration_testing
Medium
Broken Access Control leads to delete any user’s comment
Hello Raccoonians,
⤷ Title: AI Security: explanation to Exploitation || Part 1
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 13:45:52 GMT
════════════════════════
⌗ Tags: #jailbreak #bugbounty_writeup #cybersecurity #ai_security #bug_bounty
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 13:45:52 GMT
════════════════════════
⌗ Tags: #jailbreak #bugbounty_writeup #cybersecurity #ai_security #bug_bounty
Medium
AI Security: explanation to Exploitation || Part 1
Hello Everyone,
⤷ Title: How I Found a User That Couldn’t Be Removed From an Organization
════════════════════════
𐀪 Author: Ahmed Mahmoud
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 23:51:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #broken_access_control #bugbounty_writeup #penetration_testing
════════════════════════
𐀪 Author: Ahmed Mahmoud
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 23:51:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #broken_access_control #bugbounty_writeup #penetration_testing
Medium
How I Found a User That Couldn’t Be Removed From an Organization
“سُبْحَانَكَ لا عِلْمَ لَنَا إِلَّا مَا عَلَّمْتَنَا إِنَّكَ أَنْتَ الْعَلِيمُ الْحَكِيمُ”
⤷ Title: Tanuki: Admin Account Takeover via Mass Password Update
════════════════════════
𐀪 Author: Dennis Sev7n
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 18:51:35 GMT
════════════════════════
⌗ Tags: #web_application_security #cybersecurity #bugbounty_writeup
════════════════════════
𐀪 Author: Dennis Sev7n
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 18:51:35 GMT
════════════════════════
⌗ Tags: #web_application_security #cybersecurity #bugbounty_writeup
Medium
Tanuki: Admin Account Takeover via Mass Password Update
Platform: BugForge
Category: Broken Access Control / Mass Assignment
Category: Broken Access Control / Mass Assignment
⤷ Title: I Got Rejected 12 Times Before My First Bounty
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 02:16:20 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bug_bounty #bugbounty_writeup #bug_bounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 02:16:20 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bug_bounty #bugbounty_writeup #bug_bounty_writeup
Medium
I Got Rejected 12 Times Before My First Bounty
Here’s what I was doing wrong and how I fixed it.
⤷ Title: Why I Finally Built bugbountyscam.com Graveyard for Fake Bug Bounty Programs
════════════════════════
𐀪 Author: afaqain
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 16:27:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #bug_bounty_writeup #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: afaqain
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 16:27:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #bug_bounty_writeup #bug_bounty #bugbounty_writeup
Medium
Why I Finally Built bugbountyscam.com Graveyard for Fake Bug Bounty Programs
30 Years in Bug Hunting and I’ve Had Enough of the Scams 😤🔥
⤷ Title: Why Some Hunters Make $10k a Month and Others Make Nothing
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 02:53:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #bug_hunting #bugbounty_writeup #bug_bounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 02:53:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #bug_hunting #bugbounty_writeup #bug_bounty_writeup
Medium
Why Some Hunters Make $10k a Month and Others Make Nothing
It’s not skill. It’s not luck. Here’s the actual difference.
⤷ Title: From Chicken McNuggets to a Bug Bounty: How a Viral Meme Started My Best Finding
════════════════════════
𐀪 Author: C0deRevenant
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 16:53:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #bug_bounty #cybersecurity #ai_agent
════════════════════════
𐀪 Author: C0deRevenant
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 16:53:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #bug_bounty #cybersecurity #ai_agent
Medium
From Chicken McNuggets to a Bug Bounty: How a Viral Meme Started My Best Finding
“No methodology. No fancy tools. Just a meme, a hunch, and a chatbot that really should have stayed in its lane.”
⤷ Title: BBP#3: The Boat Speaker— From Shopping Cart to Account Takeover
════════════════════════
𐀪 Author: Devender Rao
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 07:41:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hacking #security #penetration_testing
════════════════════════
𐀪 Author: Devender Rao
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 07:41:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hacking #security #penetration_testing
Medium
BBP#3: The Boat Speaker— From Shopping Cart to Account Takeover
How a lazy Sunday shopping session turned into finding two critical vulnerabilities in a checkout SDK used by 400+ merchants
⤷ Title: From LFI to Database Takeover and the RCE That Almost Was
════════════════════════
𐀪 Author: Elahe
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 06:35:46 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #cybersecurity #bug_bounty #pentesting
════════════════════════
𐀪 Author: Elahe
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 06:35:46 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #cybersecurity #bug_bounty #pentesting
Medium
From LFI to Database Takeover and the RCE That Almost Was
In a recent pentest project I tackled with my friend Sajad, we found a perfect example of how small cracks can break a whole system. By…
⤷ Title: How i found race conditions leading to premium subscribtion bypass via concurrent user addition
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 20:29:23 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #bug_bounty #penetration_testing #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 20:29:23 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #bug_bounty #penetration_testing #bug_bounty_writeup #bug_bounty_tips
Medium
How i found race conditions leading to premium subscribtion bypass via concurrent user addition
Hello raccoonians,
⤷ Title: How I Forced A/B Experiments on Any User via an Unauthenticated Endpoint (Missing Auth)
════════════════════════
𐀪 Author: httpzuz
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 19:56:38 GMT
════════════════════════
⌗ Tags: #authentication #bug_bounty #bug_bounty_tips #bug_bounty_writeup #bugs
════════════════════════
𐀪 Author: httpzuz
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 19:56:38 GMT
════════════════════════
⌗ Tags: #authentication #bug_bounty #bug_bounty_tips #bug_bounty_writeup #bugs
Medium
How I Forced A/B Experiments on Any User via an Unauthenticated Endpoint (Missing Auth)
Hey Guys and Welcome Back 👋