⤷ Title: HACKING JULY DAY 1: JUICE-SHOP INJECTION
════════════════════════
𐀪 Author: Given Quincy
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 14:55:29 GMT
════════════════════════
⌗ Tags: #owasp_web_top_10 #cybersecurity #sql_injection #owasp_juice_shop #owasp_top_10
════════════════════════
𐀪 Author: Given Quincy
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 14:55:29 GMT
════════════════════════
⌗ Tags: #owasp_web_top_10 #cybersecurity #sql_injection #owasp_juice_shop #owasp_top_10
Medium
HACKING JULY DAY 1: JUICE-SH.OP INJECTION
As per OWASP Top 10 2025, injection is ranked top 5 categorizing the likes of SQL injection and command injection.
⤷ Title: With Great Access Comes Great Responsibility
════════════════════════
𐀪 Author: Has
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 02:28:16 GMT
════════════════════════
⌗ Tags: #aws_s3 #security #bug_bounty_writeup
════════════════════════
𐀪 Author: Has
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 02:28:16 GMT
════════════════════════
⌗ Tags: #aws_s3 #security #bug_bounty_writeup
Medium
With Great Access Comes Great Responsibility
Access control is the most boring topic in tech, right up until one bad setting leaks thousands of people’s private data. AWS S3 makes…
⤷ Title: How an Insecure Deserialization Flaw in a Cache Layer Triggered an $4,500 Remote Code Execution…
════════════════════════
𐀪 Author: Tanvi Chauhan
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 11:21:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #security #pentesting
════════════════════════
𐀪 Author: Tanvi Chauhan
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 11:21:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #security #pentesting
Medium
How an Insecure Deserialization Flaw in a Cache Layer Triggered an $4,500 Remote Code Execution…
When we talk about hunting for Remote Code Execution (RCE), we usually look at the file upload components or the main input fields of an…
⤷ Title: 2FA Bypass via Switching Between Email OTP and TOTP During Authentication
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 20:29:33 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #otp_bypass #2fa_bypass #2fa_authentication
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 20:29:33 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #otp_bypass #2fa_bypass #2fa_authentication
Medium
2FA Bypass via Switching Between Email OTP and TOTP During Authentication
Hello Hackers 👋
⤷ Title: Methodology over Automation: Deconstructing E-commerce Checkout Logic
════════════════════════
𐀪 Author: Sahil
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 14:00:04 GMT
════════════════════════
⌗ Tags: #pentesting #bugbounty_writeup #cybersecurity #hackerone #vulnerability
════════════════════════
𐀪 Author: Sahil
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 14:00:04 GMT
════════════════════════
⌗ Tags: #pentesting #bugbounty_writeup #cybersecurity #hackerone #vulnerability
Medium
Methodology over Automation: Deconstructing E-commerce Checkout Logic
Introduction In application security, the most critical vulnerabilities often reside in business logic — flaws that automated scanners…
⤷ Title: Is the Android Lock Screen an Illusion? How I Bypassed It via the Gemini App
════════════════════════
𐀪 Author: Mustafa Salih Berk
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 10:17:03 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #cybersecurity #bugbounty_writeup #vulnerability
════════════════════════
𐀪 Author: Mustafa Salih Berk
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 10:17:03 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #cybersecurity #bugbounty_writeup #vulnerability
Medium
Is the Android Lock Screen an Illusion? How I Bypassed It via the Gemini App
Technical analysis of a logical lock screen bypass I discovered in Google Gemini and reported via Google VRP.
⤷ Title: Subscription Enforcement Bypass Leading to Unauthorized Full Application Access
════════════════════════
𐀪 Author: 0xMo7areb
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #innovation #bug_bounty #technology
════════════════════════
𐀪 Author: 0xMo7areb
════════════════════════
ⴵ Time: Thu, 02 Jul 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #innovation #bug_bounty #technology
Medium
🫏Subscription Enforcement Bypass Leading to Unauthorized Full Application Access
الحمد لله الذي عَلَّمَ بالقلم، عَلَّمَ الإنسانَ ما لم يعلم، والصلاة والسلام على سيدنا محمد ﷺ
⤷ Title: U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 18:17:53 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 18:17:53 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: The Lean Expansion Playbook AI Startups Are Using to Build Global Teams
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:24:26 +0000
════════════════════════
⌗ Tags: #Technology #Artificial Intelligence #Business #AI #Startups
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:24:26 +0000
════════════════════════
⌗ Tags: #Technology #Artificial Intelligence #Business #AI #Startups
Hackread
The Lean Expansion Playbook AI Startups Are Using to Build Global Teams
Learn how AI startups use global hiring, EOR partners, and remote systems to access talent, stay compliant, and extend runway efficiently for sustainable growth.
⤷ Title: How I Found a Data Deletion Bypass via Subdomain Synchronization
════════════════════════
𐀪 Author: Viperblitzz
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:49:09 GMT
════════════════════════
⌗ Tags: #business_logic_error #bug_bounty_tips #bug_bounty #infosec #cybersecurity
════════════════════════
𐀪 Author: Viperblitzz
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:49:09 GMT
════════════════════════
⌗ Tags: #business_logic_error #bug_bounty_tips #bug_bounty #infosec #cybersecurity
Medium
How I Found a Data Deletion Bypass via Subdomain Synchronization
This is what I did after my lunch break and immediately got enough cash to buy stuff in the premium store
⤷ Title: ReconX: A Lightweight Bash-Based Reconnaissance Framework for Ethical Hackers
════════════════════════
𐀪 Author: A.C.HARIHARAN
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:48:20 GMT
════════════════════════
⌗ Tags: #bug_bounty #reconnaissance
════════════════════════
𐀪 Author: A.C.HARIHARAN
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:48:20 GMT
════════════════════════
⌗ Tags: #bug_bounty #reconnaissance
Medium
ReconX: A Lightweight Bash-Based Reconnaissance Framework for Ethical Hackers
Introduction
⤷ Title: BladeRecon Explained | Next-Generation Recon for Bug Bounty Hunters
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:17:17 GMT
════════════════════════
⌗ Tags: #web_development #artificial_intelligence #hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:17:17 GMT
════════════════════════
⌗ Tags: #web_development #artificial_intelligence #hacking #cybersecurity #bug_bounty
Medium
🚀 BladeRecon Explained | Next-Generation Recon for Bug Bounty Hunters 🔥
Automating Reconnaissance for Faster and More Efficient Security Assessments
⤷ Title: Sensitive Information Disclosure: What It Is and the Top 10 Tools to Find It in 2026
════════════════════════
𐀪 Author: Hrishikesh Dahale
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:07:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #information_disclosure #technology #cybersecurity
════════════════════════
𐀪 Author: Hrishikesh Dahale
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:07:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #information_disclosure #technology #cybersecurity
Medium
Sensitive Information Disclosure: What It Is and the Top 10 Tools to Find It in 2026
A practical primer on one of the most common — and most underestimated — classes of web vulnerability, plus the current toolkit security…
⤷ Title: Wonderland (THM) Tryhackme Medium Challenge
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:08:34 GMT
════════════════════════
⌗ Tags: #hacking #steganography #privilege_escalation #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:08:34 GMT
════════════════════════
⌗ Tags: #hacking #steganography #privilege_escalation #cybersecurity #tryhackme
Medium
Wonderland (THM) Tryhackme Medium Challenge
Description : Fall down the rabbit hole and enter wonderland.
⤷ Title: Lab: Exploiting server-side parameter pollution in a query string (API testing) #lab 2
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:51:12 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity #hacking #portswigger_lab #apihacking
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:51:12 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity #hacking #portswigger_lab #apihacking
Medium
Lab: Exploiting server-side parameter pollution in a query string (API testing) #lab 2
Solution:
⤷ Title: Nobody Was Looking at the Wrong Number Until It Mattered
════════════════════════
𐀪 Author: Faruk Ahmed
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:01:00 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #system_administration #infosec #linux
════════════════════════
𐀪 Author: Faruk Ahmed
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 12:01:00 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #system_administration #infosec #linux
Medium
Nobody Was Looking at the Wrong Number Until It Mattered
The dashboard looked perfect.
⤷ Title: Bugged CTF Walkthrough (TryHackMe)
════════════════════════
𐀪 Author: Vanessa3
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:34:45 GMT
════════════════════════
⌗ Tags: #ethical_hacking #tryhackme #cybersecurity #ctf #iot_security
════════════════════════
𐀪 Author: Vanessa3
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:34:45 GMT
════════════════════════
⌗ Tags: #ethical_hacking #tryhackme #cybersecurity #ctf #iot_security
Medium
Bugged CTF Walkthrough (TryHackMe)
A Beginner friendly Guide to solving the Bugged Room on TryHackMe
⤷ Title: CVE-2026–10091: Stored XSS in Email JavaScript Cloak WordPress Plugin
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #wordpress_security #xs #wordpress_security_plugin #security_plugin #cve
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #wordpress_security #xs #wordpress_security_plugin #security_plugin #cve
Medium
CVE-2026–10091: Stored XSS in Email JavaScript Cloak WordPress Plugin
When a simple shortcode becomes a persistent script injection vector
⤷ Title: Account Deletion — Password Confirmation Bypass — bug bounty
════════════════════════
𐀪 Author: so vode
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 15:01:41 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: so vode
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 15:01:41 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
Account Deletion — Password Confirmation Bypass — bug bounty
# Account Deletion — Password Confirmation Bypass
⤷ Title: How I Hunt Zero-Days: The 10-Part System That Replaced Luck
════════════════════════
𐀪 Author: Muhammad Haider Tallal
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 14:27:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability_research #infosec #zero_day #cybersecurity
════════════════════════
𐀪 Author: Muhammad Haider Tallal
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 14:27:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability_research #infosec #zero_day #cybersecurity
Medium
How I Hunt Zero-Days: The 10-Part System That Replaced Luck
A working methodology for finding bugs and writing exploits in browsers, hypervisors, and other hardened software, plus why the same system…
⤷ Title: XML External Entity (XXE) Injection — Arbitrary Local File Disclosure
════════════════════════
𐀪 Author: Ethical Hacker
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 14:22:08 GMT
════════════════════════
⌗ Tags: #application_security #security_research #bug_bounty #web_security #ethical_hacking
════════════════════════
𐀪 Author: Ethical Hacker
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 14:22:08 GMT
════════════════════════
⌗ Tags: #application_security #security_research #bug_bounty #web_security #ethical_hacking
Medium
XML External Entity (XXE) Injection — Arbitrary Local File Disclosure
Recently, I identified and successfully validated an **XML External Entity (XXE)** vulnerability caused by an insecure XML parser…