⤷ Title: Is Your Authentication Secure? Auditing HS256 JWTs the Right Way
════════════════════════
𐀪 Author: writtenbyniv
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 11:57:54 GMT
════════════════════════
⌗ Tags: #cryptography #application_security #jwt #cybersecurity #python
════════════════════════
𐀪 Author: writtenbyniv
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 11:57:54 GMT
════════════════════════
⌗ Tags: #cryptography #application_security #jwt #cybersecurity #python
Medium
Is Your Authentication Secure? Auditing HS256 JWTs the Right Way
JSON Web Tokens (JWTs) are the backbone of modern web authentication. They handle everything from user sessions to granular API access…
⤷ Title: Proving Grounds Apex Walkthrough By Ryan Cham
════════════════════════
𐀪 Author: Ryan Cham Rui Yang
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:00:37 GMT
════════════════════════
⌗ Tags: #hacking #oscp
════════════════════════
𐀪 Author: Ryan Cham Rui Yang
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:00:37 GMT
════════════════════════
⌗ Tags: #hacking #oscp
Medium
Proving Grounds Apex Walkthrough By Ryan Cham
port 80 → http
⤷ Title: Anatomy of a Modern Phishing-as-a-Service Operation: How Credential Harvesting Campaigns Actually…
════════════════════════
𐀪 Author: Yassin Hamada
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 13:45:45 GMT
════════════════════════
⌗ Tags: #threat_intelligence #cybercrime #cybersecurity #infosec
════════════════════════
𐀪 Author: Yassin Hamada
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 13:45:45 GMT
════════════════════════
⌗ Tags: #threat_intelligence #cybercrime #cybersecurity #infosec
Medium
Anatomy of a Modern Phishing-as-a-Service Operation: How Credential Harvesting Campaigns Actually Work
A threat intelligence breakdown of how commoditized phishing kits have industrialized credential theft — and what defenders should actually…
⤷ Title: TryHackMe — Tardigrage — Incident Response Room
════════════════════════
𐀪 Author: Efe Özel
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 12:34:44 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cybersecurity #threat_hunting #incident_response #tryhackme
════════════════════════
𐀪 Author: Efe Özel
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 12:34:44 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cybersecurity #threat_hunting #incident_response #tryhackme
Medium
TryHackMe — Tardigrage — Incident Response Room
Scenario: A server has been compromised, and the security team has decided to isolate the machine until it’s been thoroughly cleaned up…
⤷ Title: TryHackMe — Hunt Me II: Typo Squatters
════════════════════════
𐀪 Author: Efe Özel
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 12:25:52 GMT
════════════════════════
⌗ Tags: #threat_hunting #tryhackme #tryhackme_walkthrough #cybersecurity #incident_response
════════════════════════
𐀪 Author: Efe Özel
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 12:25:52 GMT
════════════════════════
⌗ Tags: #threat_hunting #tryhackme #tryhackme_walkthrough #cybersecurity #incident_response
Medium
TryHackMe — Hunt Me II: Typo Squatters
Scenario: Just working on a typical day as a software engineer, Perry received an encrypted 7z archive from his boss containing a snippet…
⤷ Title: Why Experienced Linux Users Rarely Panic
════════════════════════
𐀪 Author: Fateyaly
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 13:39:32 GMT
════════════════════════
⌗ Tags: #programming #technology #ethical_hacking #cybersecurity #coding
════════════════════════
𐀪 Author: Fateyaly
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 13:39:32 GMT
════════════════════════
⌗ Tags: #programming #technology #ethical_hacking #cybersecurity #coding
Medium
Why Experienced Linux Users Rarely Panic
Because they trust observability, understand failure modes, and know that nearly every Linux problem leaves evidence behind.
⤷ Title: CVE-2026-10120: Unpatchable Stack Overflow in End-of-Life TRENDnet Router
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 13:01:02 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cwe_121 #cybersecurity #cve_2026_10120 #cwe_119
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 13:01:02 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cwe_121 #cybersecurity #cve_2026_10120 #cwe_119
Medium
CVE-2026-10120: Unpatchable Stack Overflow in End-of-Life TRENDnet Router
CVE-2026–10120: Unpatchable Stack Overflow in End-of-Life TRENDnet Router A remotely exploitable stack-based buffer overflow in the TRENDnet TEW-432BRP wireless router will never receive an …
⤷ Title: Career Opportunities After Completing a Cyber Security Diploma Course
════════════════════════
𐀪 Author: cybersecuritycourse
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 12:12:02 GMT
════════════════════════
⌗ Tags: #ai #education #ethical_hacking #cybersecurity #cyberattack
════════════════════════
𐀪 Author: cybersecuritycourse
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 12:12:02 GMT
════════════════════════
⌗ Tags: #ai #education #ethical_hacking #cybersecurity #cyberattack
Medium
Career Opportunities After Completing a Cyber Security Diploma Course
Cybersecurity has become one of the fastest-growing industries as businesses increasingly rely on digital technologies. From startups to…
⤷ Title: Don’t Trust the Token — The Art of JWT Attacks
════════════════════════
𐀪 Author: Muhab A.
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:38:49 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #cybersecurity #jwt #jwt_token
════════════════════════
𐀪 Author: Muhab A.
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:38:49 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #cybersecurity #jwt #jwt_token
Medium
Don’t Trust the Token — The Art of JWT Attacks
One token. Every door open.
⤷ Title: Zero Requiem: The $5,000 Blind SSRF Chain That Owned Lelouch Lamperouge
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:31:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #rce
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:31:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #rce
Medium
🎭 Zero Requiem: The $5,000 Blind SSRF Chain That Owned Lelouch Lamperouge
From blind SSRF to cloud root, internal pivot to full infrastructure compromise — the final bounty that proved the impossible was possible
⤷ Title: Authorization Bypass via Privilege Persistence After Role Downgrade in Hasura PromptQL
════════════════════════
𐀪 Author: Ahmed Embaby
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:12:35 GMT
════════════════════════
⌗ Tags: #web_security #authorization #bug_bounty #cybersecurity #graphql
════════════════════════
𐀪 Author: Ahmed Embaby
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:12:35 GMT
════════════════════════
⌗ Tags: #web_security #authorization #bug_bounty #cybersecurity #graphql
Medium
Authorization Bypass via Privilege Persistence After Role Downgrade in Hasura PromptQL
Still an Admin. Just Not Officially
⤷ Title: It Worked, Then It Didn’t, Then I Understood Why: A Bug Bounty Story on Authorization Bypass
════════════════════════
𐀪 Author: Atharv Chawan
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:51:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Atharv Chawan
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:51:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_writeup
Medium
It Worked, Then It Didn’t, Then I Understood Why: A Bug Bounty Story on Authorization Bypass
Hello seniors! I am Atharv Chawan, a cybersecurity enthusiast and bug bounty hunter. Today, I want to share a wild ride of a bug hunt on a…
⤷ Title: Prompt Injection Is Just SSRF for Text. MCP Security → Part 3
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:30:16 GMT
════════════════════════
⌗ Tags: #ssrf #mcp_security #bug_bounty_tips #bug_bounty #prompt_injection_attack
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:30:16 GMT
════════════════════════
⌗ Tags: #ssrf #mcp_security #bug_bounty_tips #bug_bounty #prompt_injection_attack
Medium
Prompt Injection Is Just SSRF for Text.
The MCP Bug Bounty Field Guide · Part 3 of 5 — the mental model that makes MCP prompt injection click for a bug bounty hunter, with two…
⤷ Title: Bypass TryHackMe Lab
════════════════════════
𐀪 Author: Gamuchirai
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:29:29 GMT
════════════════════════
⌗ Tags: #website #hacking #authentication_bypass #red_team #web3
════════════════════════
𐀪 Author: Gamuchirai
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:29:29 GMT
════════════════════════
⌗ Tags: #website #hacking #authentication_bypass #red_team #web3
Medium
Bypass TryHackMe Lab
The network security team has implemented an Intrusion Detection System (IDS) using Suricata to protect the company’s CCTV web panel. My…
⤷ Title: The 16-Year Wait is Over: Meet the New HTTP QUERY Method
════════════════════════
𐀪 Author: Sushil Ram
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:36:29 GMT
════════════════════════
⌗ Tags: #infosec #api #web_development #cybersecurity #software_development
════════════════════════
𐀪 Author: Sushil Ram
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:36:29 GMT
════════════════════════
⌗ Tags: #infosec #api #web_development #cybersecurity #software_development
Medium
The 16-Year Wait is Over: Meet the New HTTP QUERY Method
HTTP finally gets a new method
⤷ Title: Vulnhub: Twilight Walkthrough
════════════════════════
𐀪 Author: Farid Narimanov
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:33:07 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking #vulnhub #infosec
════════════════════════
𐀪 Author: Farid Narimanov
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:33:07 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking #vulnhub #infosec
Medium
Vulnhub: Twilight Walkthrough
From a broken DHCP interface to root via a world-writable /etc/passwd
⤷ Title: CTF: Jump TryhackMe Room
════════════════════════
𐀪 Author: Duong
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:22:11 GMT
════════════════════════
⌗ Tags: #privilege_escalation #ctf #tryhackme
════════════════════════
𐀪 Author: Duong
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 14:22:11 GMT
════════════════════════
⌗ Tags: #privilege_escalation #ctf #tryhackme
Medium
CTF: Jump TryhackMe Room
Misconfigured internal automation pipeline
⤷ Title: [POC] Cara Saya Menemukan Celah User Enumeration & Missing Rate Limiting (Universitas Brawijaya)
════════════════════════
𐀪 Author: xenzuu7
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #bug_bounty_writeup #web_security
════════════════════════
𐀪 Author: xenzuu7
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 17:05:53 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #bug_bounty_writeup #web_security
Medium
Cara Saya Menemukan Celah User Enumeration & Missing Rate Limiting (Universitas Brawijaya)
Perkenalan
⤷ Title: PentesterLab — Recon 10: Visual Reconnaissance
════════════════════════
𐀪 Author: Yosef
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:13:45 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #recon
════════════════════════
𐀪 Author: Yosef
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 15:13:45 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #recon
Medium
PentesterLab — Recon 10: Visual Reconnaissance
A walkthrough of PentesterLab Recon 10, covering hexadecimal enumeration, Python automation, and visual reconnaissance using GoWitness.
⤷ Title: US Justice Department Approves TikTok for Government Devices
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 17:24:55 +0000
════════════════════════
⌗ Tags: #Technology #ByteDance #cybersecurity #DOJ #Government Policy #TikTok
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 17:24:55 +0000
════════════════════════
⌗ Tags: #Technology #ByteDance #cybersecurity #DOJ #Government Policy #TikTok
Daily CyberSecurity
US Justice Department Approves TikTok for Government Devices
The United States Department of Justice recently announced a major policy shift. Federal workers can now legally download TikTok on state-owned devices. According to leaders, TikTok went through h…
⤷ Title: Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 16:21:07 +0000
════════════════════════
⌗ Tags: #Data Leak #AI agent #AI security #autonomous attack #Credential Theft #Data Breach #GLM #Hugging Face #Incident Response
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 16:21:07 +0000
════════════════════════
⌗ Tags: #Data Leak #AI agent #AI security #autonomous attack #Credential Theft #Data Breach #GLM #Hugging Face #Incident Response
Daily CyberSecurity
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent
At a glance Organization Hugging Face Data exposed A limited set of internal datasets and several service credentials Records affected Not disclosed; review of partner and customer data ongoing Ca…