⤷ Title: SOC127 — SQL Injection Detected
════════════════════════
𐀪 Author: Mistermanuniq
════════════════════════
ⴵ Time: Sun, 07 Jun 2026 15:39:35 GMT
════════════════════════
⌗ Tags: #sql_injection #soc127 #letsdefendio #lets_defend #letsdefend_writeup
════════════════════════
𐀪 Author: Mistermanuniq
════════════════════════
ⴵ Time: Sun, 07 Jun 2026 15:39:35 GMT
════════════════════════
⌗ Tags: #sql_injection #soc127 #letsdefendio #lets_defend #letsdefend_writeup
Medium
SOC127 — SQL Injection Detected
Today , we are going to investigate the SOC127 alert in LetsDefend.
⤷ Title: Easy 150$ Bounty: Delete all votes
════════════════════════
𐀪 Author: Musab Sarı
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 15:31:56 GMT
════════════════════════
⌗ Tags: #hackerone #cybersecurity #bug_bounty #bug_bounty_writeup #broken_access_control
════════════════════════
𐀪 Author: Musab Sarı
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 15:31:56 GMT
════════════════════════
⌗ Tags: #hackerone #cybersecurity #bug_bounty #bug_bounty_writeup #broken_access_control
Medium
Easy 150$ Bounty: Delete all votes
I have been hunting for a while on the Hackerone public program and what I learned is If you choose the right program and spend more time…
⤷ Title: IDOR allows non-group members to add any group to favorites on their Facebook profile
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:47:33 GMT
════════════════════════
⌗ Tags: #meta_bug_bounty #facebook_bug_bounty #idor #bug_bounty_writeup
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:47:33 GMT
════════════════════════
⌗ Tags: #meta_bug_bounty #facebook_bug_bounty #idor #bug_bounty_writeup
Medium
IDOR allows non-group members to add any group to favorites on their Facebook profile
Allows users who are not members of a group to add any group to their favorites on their Facebook profile.
⤷ Title: Non-group members can be added to projects even though the “Users cannot be added to projects in…
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:31:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #business_logic_flaw #gitlab
════════════════════════
𐀪 Author: Rohmad Hidayah
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 12:31:47 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #business_logic_flaw #gitlab
Medium
Non-group members can be added to projects even though the “Users cannot be added to projects in…
https://gitlab.com/gitlab-org/gitlab/-/work_items/551267
⤷ Title: These Low-Hanging Fruit bugs Made Me $120+ in 30 Minutes — Bugs That 80% of Hunters Ignore
════════════════════════
𐀪 Author: Bhavishthakral
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:38:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_writeup
════════════════════════
𐀪 Author: Bhavishthakral
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:38:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_writeup
Medium
These Low-Hanging Fruit bugs Made Me $120+ in 30 Minutes — Bugs That 80% of Hunters Ignore
These Low-Hanging Fruits Made Me $120+ in 30 Minutes — Bugs That 80% of Hunters Ignore Hi everyone , bhavish here When people think about bug bounty, they imagine critical RCEs, SQL injections, and …
⤷ Title: How I Found a Critical OAuth Misconfiguration That Led to Account Takeover
════════════════════════
𐀪 Author: Shafayat Ahmed Alif
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:21:17 GMT
════════════════════════
⌗ Tags: #account_takeover #bug_bounty_tips #bug_bounty #cybersecurity #bug_bounty_writeup
════════════════════════
𐀪 Author: Shafayat Ahmed Alif
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 09:21:17 GMT
════════════════════════
⌗ Tags: #account_takeover #bug_bounty_tips #bug_bounty #cybersecurity #bug_bounty_writeup
Medium
How I Found a Critical OAuth Misconfiguration That Led to Account Takeover
A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues chained together into a critical account…
⤷ Title: API Hacking Sounds Scary Until You Realize It’s Just Changing Numbers
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 04:03:40 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 04:03:40 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bugbounty_writeup #bug_bounty #bug_bounty_writeup
Medium
API Hacking Sounds Scary Until You Realize It’s Just Changing Numbers
No complex setups. No secret tools. Just you and your browser.
⤷ Title: Broken Access Control leads to delete any user’s comment
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 21:34:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #penetration_testing
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 21:34:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #penetration_testing
Medium
Broken Access Control leads to delete any user’s comment
Hello Raccoonians,
⤷ Title: AI Security: explanation to Exploitation || Part 1
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 13:45:52 GMT
════════════════════════
⌗ Tags: #jailbreak #bugbounty_writeup #cybersecurity #ai_security #bug_bounty
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 13:45:52 GMT
════════════════════════
⌗ Tags: #jailbreak #bugbounty_writeup #cybersecurity #ai_security #bug_bounty
Medium
AI Security: explanation to Exploitation || Part 1
Hello Everyone,
⤷ Title: How I Found a User That Couldn’t Be Removed From an Organization
════════════════════════
𐀪 Author: Ahmed Mahmoud
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 23:51:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #broken_access_control #bugbounty_writeup #penetration_testing
════════════════════════
𐀪 Author: Ahmed Mahmoud
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 23:51:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #broken_access_control #bugbounty_writeup #penetration_testing
Medium
How I Found a User That Couldn’t Be Removed From an Organization
“سُبْحَانَكَ لا عِلْمَ لَنَا إِلَّا مَا عَلَّمْتَنَا إِنَّكَ أَنْتَ الْعَلِيمُ الْحَكِيمُ”
⤷ Title: Tanuki: Admin Account Takeover via Mass Password Update
════════════════════════
𐀪 Author: Dennis Sev7n
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 18:51:35 GMT
════════════════════════
⌗ Tags: #web_application_security #cybersecurity #bugbounty_writeup
════════════════════════
𐀪 Author: Dennis Sev7n
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 18:51:35 GMT
════════════════════════
⌗ Tags: #web_application_security #cybersecurity #bugbounty_writeup
Medium
Tanuki: Admin Account Takeover via Mass Password Update
Platform: BugForge
Category: Broken Access Control / Mass Assignment
Category: Broken Access Control / Mass Assignment
⤷ Title: I Got Rejected 12 Times Before My First Bounty
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 02:16:20 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bug_bounty #bugbounty_writeup #bug_bounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 02:16:20 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_tips #bug_bounty #bugbounty_writeup #bug_bounty_writeup
Medium
I Got Rejected 12 Times Before My First Bounty
Here’s what I was doing wrong and how I fixed it.
⤷ Title: Why I Finally Built bugbountyscam.com Graveyard for Fake Bug Bounty Programs
════════════════════════
𐀪 Author: afaqain
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 16:27:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #bug_bounty_writeup #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: afaqain
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 16:27:29 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #bug_bounty_writeup #bug_bounty #bugbounty_writeup
Medium
Why I Finally Built bugbountyscam.com Graveyard for Fake Bug Bounty Programs
30 Years in Bug Hunting and I’ve Had Enough of the Scams 😤🔥
⤷ Title: Why Some Hunters Make $10k a Month and Others Make Nothing
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 02:53:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #bug_hunting #bugbounty_writeup #bug_bounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Sat, 06 Jun 2026 02:53:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #bug_hunting #bugbounty_writeup #bug_bounty_writeup
Medium
Why Some Hunters Make $10k a Month and Others Make Nothing
It’s not skill. It’s not luck. Here’s the actual difference.
⤷ Title: From Chicken McNuggets to a Bug Bounty: How a Viral Meme Started My Best Finding
════════════════════════
𐀪 Author: C0deRevenant
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 16:53:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #bug_bounty #cybersecurity #ai_agent
════════════════════════
𐀪 Author: C0deRevenant
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 16:53:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #bug_bounty #cybersecurity #ai_agent
Medium
From Chicken McNuggets to a Bug Bounty: How a Viral Meme Started My Best Finding
“No methodology. No fancy tools. Just a meme, a hunch, and a chatbot that really should have stayed in its lane.”
⤷ Title: BBP#3: The Boat Speaker— From Shopping Cart to Account Takeover
════════════════════════
𐀪 Author: Devender Rao
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 07:41:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hacking #security #penetration_testing
════════════════════════
𐀪 Author: Devender Rao
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 07:41:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #hacking #security #penetration_testing
Medium
BBP#3: The Boat Speaker— From Shopping Cart to Account Takeover
How a lazy Sunday shopping session turned into finding two critical vulnerabilities in a checkout SDK used by 400+ merchants
⤷ Title: From LFI to Database Takeover and the RCE That Almost Was
════════════════════════
𐀪 Author: Elahe
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 06:35:46 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #cybersecurity #bug_bounty #pentesting
════════════════════════
𐀪 Author: Elahe
════════════════════════
ⴵ Time: Tue, 09 Jun 2026 06:35:46 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #cybersecurity #bug_bounty #pentesting
Medium
From LFI to Database Takeover and the RCE That Almost Was
In a recent pentest project I tackled with my friend Sajad, we found a perfect example of how small cracks can break a whole system. By…
⤷ Title: How i found race conditions leading to premium subscribtion bypass via concurrent user addition
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 20:29:23 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #bug_bounty #penetration_testing #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: Raccoon
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 20:29:23 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #bug_bounty #penetration_testing #bug_bounty_writeup #bug_bounty_tips
Medium
How i found race conditions leading to premium subscribtion bypass via concurrent user addition
Hello raccoonians,
⤷ Title: How I Forced A/B Experiments on Any User via an Unauthenticated Endpoint (Missing Auth)
════════════════════════
𐀪 Author: httpzuz
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 19:56:38 GMT
════════════════════════
⌗ Tags: #authentication #bug_bounty #bug_bounty_tips #bug_bounty_writeup #bugs
════════════════════════
𐀪 Author: httpzuz
════════════════════════
ⴵ Time: Mon, 08 Jun 2026 19:56:38 GMT
════════════════════════
⌗ Tags: #authentication #bug_bounty #bug_bounty_tips #bug_bounty_writeup #bugs
Medium
How I Forced A/B Experiments on Any User via an Unauthenticated Endpoint (Missing Auth)
Hey Guys and Welcome Back 👋
⤷ Title: China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 21:38:42 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 21:38:42 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 17:24:16 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #Cyber Attack #Cyber Crime #Cybersecurity #Fraud #Infostealer #Instagram #MS Word #Scam #security #Spotify #TikTok #Vidar
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 10 Jun 2026 17:24:16 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #Cyber Attack #Cyber Crime #Cybersecurity #Fraud #Infostealer #Instagram #MS Word #Scam #security #Spotify #TikTok #Vidar
Hackread
Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer
ReversingLabs reveals how hackers exploit social media engagement metrics to deliver Vidar infostealer malware to thousands of unsuspecting users.