⤷ Title: HTB Bobby’s Bistro Writeup
════════════════════════
𐀪 Author: Shenyuchao
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:01:03 GMT
════════════════════════
⌗ Tags: #htb #htb_writeup #jwt_token #sql_injection
════════════════════════
𐀪 Author: Shenyuchao
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:01:03 GMT
════════════════════════
⌗ Tags: #htb #htb_writeup #jwt_token #sql_injection
Medium
HTB Bobby’s Bistro Writeup
Challenge Scenario
⤷ Title: File Upload Bypass On Indrive
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
Medium
File Upload Bypass Using a Pre-Signed S3 URL
welcome to my first write-up. I started bug hunting about 3 months ago, and this was one of my first findings, so I would love to share it.
⤷ Title: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 12:12:23 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 12:12:23 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SingGuard-NSFA: Ant Group Open-Sources a Guardrail to Stop Malicious AI Agent Commands After the JadePuffer Attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:45:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #AI security #Ant Group #JadePuffer #SingGuard_NSFA
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:45:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #AI security #Ant Group #JadePuffer #SingGuard_NSFA
Information Security News
SingGuard-NSFA: Ant Group Open-Sources a Guardrail to Stop Malicious AI Agent Commands After the JadePuffer Attack
Merely twelve days after the first fully automated data-encryption attack came to light, Ant Group has unveiled a free tool designed to halt dangerous artificial intelligence commands before they …
⤷ Title: Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:59:04 +0000
════════════════════════
⌗ Tags: #Technology #AI #Gemini #Gemini Notebook #google #NotebookLM
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:59:04 +0000
════════════════════════
⌗ Tags: #Technology #AI #Gemini #Gemini Notebook #google #NotebookLM
Daily CyberSecurity
Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution
NotebookLM, Google’s deep-research and AI note-taking tool beloved by professionals and students alike, has officially undergone a rebrand. To align its naming with the rest of Google’…
⤷ Title: Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:02:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #Chromium #CVE_2026_15899 #CVE_2026_15900 #CVE_2026_15901 #google chrome #use after free #V8
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:02:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #Chromium #CVE_2026_15899 #CVE_2026_15900 #CVE_2026_15901 #google chrome #use after free #V8
Daily CyberSecurity
Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network
TL;DR Google pushed Chrome 150.0.7871.128/.129 to the Stable channel on July 16, 2026. The release fixes seven flaws, and three of them carry a Critical rating. Google reports no exploitation in t…
⤷ Title: Supply Chain Trojan Targets Software Developers Through Project Files
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:04:07 +0000
════════════════════════
⌗ Tags: #Malware #crypto wallet theft #developer security #Doctor Web #malware #Software Supply Chain #Supply Chain Trojan #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:04:07 +0000
════════════════════════
⌗ Tags: #Malware #crypto wallet theft #developer security #Doctor Web #malware #Software Supply Chain #Supply Chain Trojan #XMRig
Daily CyberSecurity
Supply Chain Trojan Targets Software Developers Through Project Files
At a glance Malware family Multi-stage trojan (Doctor Web: Trojan.DownLoader49, BackDoor.Siggen2.5906, Trojan.BtcMine.3956) Threat actor Unknown; not attributed Target / victims Software developer…
⤷ Title: Zero Credentials, Full Access: Inside a Complete Authorization Failure
════════════════════════
𐀪 Author: 0x-elfateh
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:36 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #authentication #api #bug_bounty
════════════════════════
𐀪 Author: 0x-elfateh
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:36 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #authentication #api #bug_bounty
Medium
Zero Credentials, Full Access: Inside a Complete Authorization Failure
Bounty Case Files #01 How multiple trust-boundary failures allowed anonymous access to premium functionality in a production API
⤷ Title: How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:31 GMT
════════════════════════
⌗ Tags: #technology #wordpress #bug_bounty #walkthrough #cybersecurity
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:31 GMT
════════════════════════
⌗ Tags: #technology #wordpress #bug_bounty #walkthrough #cybersecurity
Medium
How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
Author: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzads Type: Independent Security Research | WordPress Plugin CVE Research
⤷ Title: SAR 2,629 For Stored XSS via svg Image Leading to ATO
════════════════════════
𐀪 Author: Anas NadY
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:18:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #penetration_testing #bug_bounty_writeup
════════════════════════
𐀪 Author: Anas NadY
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:18:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #penetration_testing #bug_bounty_writeup
Medium
SAR 2,629 For Stored XSS via svg Image Leading to ATO
REPORT BOUNTY
⤷ Title: Lab Walkthrough: Exploiting Username Enumeration via Different Responses
════════════════════════
𐀪 Author: 5um1t0x
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:09:47 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #burpsuite #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: 5um1t0x
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:09:47 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #burpsuite #penetration_testing #cybersecurity
Medium
Lab Walkthrough: Exploiting Username Enumeration via Different Responses
Introduction
⤷ Title: Finding Reflected XSS Parameters Fast: A Deep Dive into RefleX
════════════════════════
𐀪 Author: whoami_404
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:04:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #python
════════════════════════
𐀪 Author: whoami_404
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:04:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #python
Medium
Finding Reflected XSS Parameters Fast: A Deep Dive into RefleX
How a multi-threaded Python scanner turns manual parameter testing into an automated, context-aware workflow
⤷ Title: Room 8 Is Live: Why Server-Side Request Forgery Still Challenges Modern Security Teams
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:28:36 GMT
════════════════════════
⌗ Tags: #web_security #owasp #bug_bounty #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:28:36 GMT
════════════════════════
⌗ Tags: #web_security #owasp #bug_bounty #cybersecurity #penetration_testing
Medium
Room 8 Is Live: Why Server-Side Request Forgery Still Challenges Modern Security Teams
Friendly Link:
⤷ Title: When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
════════════════════════
𐀪 Author: Aleens-labs
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:20:03 GMT
════════════════════════
⌗ Tags: #open_source #bug_bounty #cybersecurity #cve #information_security
════════════════════════
𐀪 Author: Aleens-labs
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:20:03 GMT
════════════════════════
⌗ Tags: #open_source #bug_bounty #cybersecurity #cve #information_security
Medium
When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matter
⤷ Title: US Penetration Testing Market Size, Trends & Growth Forecast to 2031
════════════════════════
𐀪 Author: Sheetalbhusari
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:09:26 GMT
════════════════════════
⌗ Tags: #us_penetration_testing #penetration_testing
════════════════════════
𐀪 Author: Sheetalbhusari
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:09:26 GMT
════════════════════════
⌗ Tags: #us_penetration_testing #penetration_testing
Medium
US Penetration Testing Market Size, Trends & Growth Forecast to 2031
According to MarketsandMarkets™, the US Penetration Testing Market is projected to grow from USD 1.98 billion in 2025 to USD 4.38 billion…
⤷ Title: From Shell to Domain: Binary Exploitation, Network Pivoting, and Lateral Movement in a Single…
════════════════════════
𐀪 Author: Odai Mherat
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:08:22 GMT
════════════════════════
⌗ Tags: #ethical_hacking #active_directory #binary_exploitation #pivoting #penetration_testing
════════════════════════
𐀪 Author: Odai Mherat
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:08:22 GMT
════════════════════════
⌗ Tags: #ethical_hacking #active_directory #binary_exploitation #pivoting #penetration_testing
Medium
From Shell to Domain: Binary Exploitation, Network Pivoting, and Lateral Movement in a Single Engagement
By Odai Mherat
⤷ Title: How Enterprise Security Leaders Evaluate AI Pentesting Platforms for Long-Term Success
════════════════════════
𐀪 Author: Nicholas James
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:00:46 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ai_pentesting #ai_penetration_testing
════════════════════════
𐀪 Author: Nicholas James
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:00:46 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ai_pentesting #ai_penetration_testing
Medium
How Enterprise Security Leaders Evaluate AI Pentesting Platforms for Long-Term Success
Artificial intelligence is reshaping cybersecurity, but it is also reshaping how organizations evaluate security tools. As attack surfaces…
⤷ Title: Guided Pentest: Web (Penetration Testing Foundations)
════════════════════════
𐀪 Author: Vineet Pratap Singh
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:40:59 GMT
════════════════════════
⌗ Tags: #tryhackme #thm_writeup
════════════════════════
𐀪 Author: Vineet Pratap Singh
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:40:59 GMT
════════════════════════
⌗ Tags: #tryhackme #thm_writeup
Medium
Guided Pentest: Web (Penetration Testing Foundations)
This room is a guided pentesting path for the web applications that contains following engagements/topics:
⤷ Title: Session Management | TryHackMe WalkThrough
════════════════════════
𐀪 Author: Cyrus Isaac
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:57:38 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #session_management #tryhackme_writeup
════════════════════════
𐀪 Author: Cyrus Isaac
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:57:38 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #session_management #tryhackme_writeup
Medium
Session Management | TryHackMe WalkThrough
Task1: Introduction
⤷ Title: Intro to Malware…… | THM Walkthrough | by Dharavath Nagaraju
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:40:16 GMT
════════════════════════
⌗ Tags: #sandboxing #static_and_dynamic #malware_analysis #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:40:16 GMT
════════════════════════
⌗ Tags: #sandboxing #static_and_dynamic #malware_analysis #cybersecurity #tryhackme
Medium
Intro to Malware…… | THM Walkthrough | by Dharavath Nagaraju
This room introduces the fundamentals of malware analysis and the techniques used to safely investigate malicious software. It covers the…
⤷ Title: Misconfigured Server Exposes Three AiTM Phishing Operators
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
Daily CyberSecurity
Misconfigured Server Exposes Three AiTM Phishing Operators
At a glance Actor / group codemado, mail-argenta, saroula01 (online aliases) Activity AiTM phishing and OAuth Device Code Flow abuse Targets / victims Corporate Microsoft 365 accounts, plus crypto…