⤷ Title: AWS Cognito Refresh Tokens: The Hidden Security Risk Behind Long-Lived User Sessions
════════════════════════
𐀪 Author: Dikhyant Krishna Dalai
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 12:05:52 GMT
════════════════════════
⌗ Tags: #aws #refresh_token #ethical_hacking #cybersecurity #authentication
════════════════════════
𐀪 Author: Dikhyant Krishna Dalai
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 12:05:52 GMT
════════════════════════
⌗ Tags: #aws #refresh_token #ethical_hacking #cybersecurity #authentication
Medium
AWS Cognito Refresh Tokens: The Hidden Security Risk Behind Long-Lived User Sessions
Most engineering teams focus on access token expiry. The credential that can silently own your users’ accounts for 30 days is quietly…
⤷ Title: I Popped Admin on a SaaS Platform in 2 HTTP Requests — Here’s the Whole Kill Chain
════════════════════════
𐀪 Author: Nayan Acharya
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:34:40 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bug_bounty #infosec #programming
════════════════════════
𐀪 Author: Nayan Acharya
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:34:40 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bug_bounty #infosec #programming
Medium
I Popped Admin on a SaaS Platform in 2 HTTP Requests — Here’s the Whole Kill Chain
Free account → full data breach → 1,630 private documents → CEO account takeover. All before my coffee got cold.
⤷ Title: Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 14:35:54 GMT
════════════════════════
⌗ Tags: #akamai #xss_attack #bug_bounty #xs #bugbounty_writeup
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 14:35:54 GMT
════════════════════════
⌗ Tags: #akamai #xss_attack #bug_bounty #xs #bugbounty_writeup
Medium
Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account Takeover
One click, eight seconds, nine webhook hits. It started with a single bracket character that broke an Akamai WAF rule.
⤷ Title: Lab 5: Blind OS Command Injection with Out-of-Band Data Exfiltration — PortSwigger Web Security…
════════════════════════
𐀪 Author: Nitish Mukhiya
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 14:03:39 GMT
════════════════════════
⌗ Tags: #ethical_hacking #os_command_injection #portswigger_lab #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Nitish Mukhiya
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 14:03:39 GMT
════════════════════════
⌗ Tags: #ethical_hacking #os_command_injection #portswigger_lab #bug_bounty #cybersecurity
Medium
Lab 5: Blind OS Command Injection with Out-of-Band Data Exfiltration — PortSwigger Web Security Academy Walkthrough (Part 5 of…
The grand finale: smuggling command output inside a DNS query to steal data from a completely silent, fully blind vulnerability.
⤷ Title: Inside the Command, Control, and Exploitation of North Korea’s Disguised IT Workforce
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:17:31 GMT
════════════════════════
⌗ Tags: #espionage #cybercrime #hacking #cybersecurity #north_korea
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:17:31 GMT
════════════════════════
⌗ Tags: #espionage #cybercrime #hacking #cybersecurity #north_korea
Medium
Inside the Command, Control, and Exploitation of North Korea’s Disguised IT Workforce
The Digital Assembly Line
⤷ Title: Jump Challenger: My Beginner-Friendly TryHackMe CTF Walkthrough
════════════════════════
𐀪 Author: C09N1T1V3
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:10:34 GMT
════════════════════════
⌗ Tags: #tryhackme #cyber_security_awareness #ctf #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: C09N1T1V3
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:10:34 GMT
════════════════════════
⌗ Tags: #tryhackme #cyber_security_awareness #ctf #penetration_testing #cybersecurity
Medium
Jump Challenger: My Beginner-Friendly TryHackMe CTF Walkthrough
recon_user → dev_user → monitor_user → ops_user → root
⤷ Title: # OWASP WrongSecrets — Here’s What Every Developer Should Know About Secret Management Before…
════════════════════════
𐀪 Author: The Project Adversary
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:08:21 GMT
════════════════════════
⌗ Tags: #security #owasp #penetration_testing #secrets #information_security
════════════════════════
𐀪 Author: The Project Adversary
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:08:21 GMT
════════════════════════
⌗ Tags: #security #owasp #penetration_testing #secrets #information_security
⤷ Title: MITRE ATT&CK Execution Tactic: Understanding How Adversaries Run Malicious Code
════════════════════════
𐀪 Author: Shalu
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:46:23 GMT
════════════════════════
⌗ Tags: #ethical_hacking #blue_team #cybersecurity #soc_analyst #threat_hunting
════════════════════════
𐀪 Author: Shalu
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 15:46:23 GMT
════════════════════════
⌗ Tags: #ethical_hacking #blue_team #cybersecurity #soc_analyst #threat_hunting
Medium
MITRE ATT&CK Execution Tactic: Understanding How Adversaries Run Malicious Code
Introduction
⤷ Title: Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 22:57:11 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 22:57:11 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: How a Single Google Dork Exposed 17 WordPress Users — and What We Can Learn
════════════════════════
𐀪 Author: Aser Ahmed
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:47:55 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Aser Ahmed
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:47:55 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Medium
How a Single Google Dork Exposed 17 WordPress Users — and What We Can Learn
A real‑world case of CSV exposure, password hashes, and responsible disclosure
⤷ Title: Stored XSS via SVG File Upload in a Project Management Application
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bug_bounty #file_upload #seurity #xss_attack
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #bug_bounty #file_upload #seurity #xss_attack
Medium
Stored XSS via SVG File Upload in a Project Management Application
Bug Bounty Write-up | Stored XSS | File Upload Security
⤷ Title: When Missing Rate Limiting Leads to a Critical Authentication Finding: A Real-World Case Study
════════════════════════
𐀪 Author: YURI
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:01:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_hunter #bug_bounty_writeup #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: YURI
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:01:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_hunter #bug_bounty_writeup #bug_bounty_tips #hacking
Medium
When Missing Rate Limiting Leads to a Critical Authentication Finding: A Real-World Case Study
Hey It’s been quite a while since my last article, but I’m excited to start publishing consistently again, covering web application…
⤷ Title: HOW I FOUND IP IP LEAK IN API RESPOSNE WORTH 300$
════════════════════════
𐀪 Author: cyberblack222
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 16:36:08 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: cyberblack222
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 16:36:08 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
Medium
HOW I FOUND IP IP LEAK IN API RESPOSNE WORTH 300$
BUG BY AI ASSISTANT
⤷ Title: How I Accidentally Stumbled Into a 225,000-Record Data Leak (And Got Paid For It)
════════════════════════
𐀪 Author: Nayan Acharya
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 16:15:13 GMT
════════════════════════
⌗ Tags: #threat_hunting #hacking #bug_bounty #programming #cybersecurity
════════════════════════
𐀪 Author: Nayan Acharya
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 16:15:13 GMT
════════════════════════
⌗ Tags: #threat_hunting #hacking #bug_bounty #programming #cybersecurity
Medium
How I Accidentally Stumbled Into a 225,000-Record Data Leak (And Got Paid For It)
“The best bugs aren’t found. They find you — usually at 2 AM when you’re half-asleep and the coffee has gone cold.”
⤷ Title: OWASP Top 10 for .NET Developers - Part 5: Preventing Security Misconfiguration
════════════════════════
𐀪 Author: Surya Raj Ghimire
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:11:48 GMT
════════════════════════
⌗ Tags: #web_security #owasp #application_security #dotnet #cybersecurity
════════════════════════
𐀪 Author: Surya Raj Ghimire
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:11:48 GMT
════════════════════════
⌗ Tags: #web_security #owasp #application_security #dotnet #cybersecurity
Medium
OWASP Top 10 for .NET Developers - Part 5: Preventing Security Misconfiguration
Security vulnerabilities are not always created by bad code. Sometimes, the code is secure, the logic is correct, and the authentication is…
⤷ Title: WingData Writeup (HackTheBox Easy Machine)
════════════════════════
𐀪 Author: Ivan Daňo
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 16:18:35 GMT
════════════════════════
⌗ Tags: #hacking #ctf #linux #hackthebox_writeup #cybersecurity
════════════════════════
𐀪 Author: Ivan Daňo
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 16:18:35 GMT
════════════════════════
⌗ Tags: #hacking #ctf #linux #hackthebox_writeup #cybersecurity
Medium
WingData Writeup (HackTheBox Easy Machine)
Overview
⤷ Title: The NIS2 Domino Effect: Why the Regulation Is Paralyzing Small Suppliers and How to React…
════════════════════════
𐀪 Author: Max Kristmann
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:52:01 GMT
════════════════════════
⌗ Tags: #nis2 #infosec #grc #cybersecurity #information_security
════════════════════════
𐀪 Author: Max Kristmann
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:52:01 GMT
════════════════════════
⌗ Tags: #nis2 #infosec #grc #cybersecurity #information_security
Medium
The NIS2 Domino Effect: Why the Regulation Is Paralyzing Small Suppliers and How to React…
At IT security events and in professional discussions, I am currently seeing the following picture: More and more decision-makers at small…
⤷ Title: Four CI/CD assumptions that turned into attack paths
════════════════════════
𐀪 Author: Maram Raboudi
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:25:59 GMT
════════════════════════
⌗ Tags: #devsecops #penetration_testing #jenkins #ci_cd_pipeline
════════════════════════
𐀪 Author: Maram Raboudi
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:25:59 GMT
════════════════════════
⌗ Tags: #devsecops #penetration_testing #jenkins #ci_cd_pipeline
Medium
Four CI/CD assumptions that turned into attack paths
Part 3 of my CICD-Goat pentest: overprivileged tokens, controller-node execution, fail-open security checks, and mutable Docker images
⤷ Title: TryHackMe write-up: Bounty Hacker
════════════════════════
𐀪 Author: Viktor Chalyi
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:53:24 GMT
════════════════════════
⌗ Tags: #information_security #ctf #tryhackme #ctf_writeup #cybersecurity
════════════════════════
𐀪 Author: Viktor Chalyi
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:53:24 GMT
════════════════════════
⌗ Tags: #information_security #ctf #tryhackme #ctf_writeup #cybersecurity
Medium
TryHackMe write-up: Bounty Hacker
From anonymous FTP to root shell: privilege escalation in action
⤷ Title: Netanix CTF Writeup: Digital Archaeology (Forensics)
════════════════════════
𐀪 Author: Jinx
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:03:29 GMT
════════════════════════
⌗ Tags: #ctf #netanix #netanix_writeup #digital_forensics #ethical_hacking
════════════════════════
𐀪 Author: Jinx
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 17:03:29 GMT
════════════════════════
⌗ Tags: #ctf #netanix #netanix_writeup #digital_forensics #ethical_hacking
Medium
Netanix CTF Writeup: Digital Archaeology (Forensics)
Every disk image tells a story. In this challenge, what started as a simple forensic investigation quickly turned into a hunt through…
⤷ Title: How to Pick Your First Bug Bounty Program Without Burning Out
════════════════════════
𐀪 Author: Masood Nfc
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 18:30:38 GMT
════════════════════════
⌗ Tags: #hacking #beginner #web_security #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Masood Nfc
════════════════════════
ⴵ Time: Sat, 27 Jun 2026 18:30:38 GMT
════════════════════════
⌗ Tags: #hacking #beginner #web_security #cybersecurity #bug_bounty
Medium
How to Pick Your First Bug Bounty Program Without Burning Out
The wrong first program quits more beginners than the difficulty does.