⤷ Title: From “Access Denied” to Remote Code Execution: Bypassing Authorization Through a Webhook Trigger
════════════════════════
𐀪 Author: M0n3m
════════════════════════
ⴵ Time: Sat, 11 Jul 2026 15:13:09 GMT
════════════════════════
⌗ Tags: #appsec #cybersecurity #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: M0n3m
════════════════════════
ⴵ Time: Sat, 11 Jul 2026 15:13:09 GMT
════════════════════════
⌗ Tags: #appsec #cybersecurity #bug_bounty #ethical_hacking
Medium
From “Access Denied” to Remote Code Execution: Bypassing Authorization Through a Webhook Trigger
TL;DR: A standard authenticated user on an enterprise marketplace platform could create a server-side Node.js function, block direct…
⤷ Title: The Evolution of Application Security: From Perimeter Defense to Proactive Resilience
════════════════════════
𐀪 Author: N0aziXss
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 07:14:52 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #devsecops #appsec #cybersecurity #application_security
════════════════════════
𐀪 Author: N0aziXss
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 07:14:52 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #devsecops #appsec #cybersecurity #application_security
Medium
The Evolution of Application Security: From Perimeter Defense to Proactive Resilience
Subtitle:
⤷ Title: The Token That Wouldn’t Die
════════════════════════
𐀪 Author: Krypto
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 14:10:49 GMT
════════════════════════
⌗ Tags: #appsec #bug_bounty #authentication #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: Krypto
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 14:10:49 GMT
════════════════════════
⌗ Tags: #appsec #bug_bounty #authentication #cybersecurity #bug_bounty_tips
Medium
The Token That Wouldn’t Die
A high-severity bug I found by testing the one thing almost nobody checks
⤷ Title: How a Simple Profile Update Led to Cross-Tenant Data Exposure
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 09:31:41 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #api #appsec #owasp
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 09:31:41 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #api #appsec #owasp
Medium
How a Simple Profile Update Led to Cross-Tenant Data Exposure
Free Article Link: Click for free!
⤷ Title: SSRF (Server-Side Request Forgery): How It Works, Bypass Techniques, and AI Risks
════════════════════════
𐀪 Author: Alperen
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 15:03:33 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #ssrf #appsec #cloud_security
════════════════════════
𐀪 Author: Alperen
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 15:03:33 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #ssrf #appsec #cloud_security
Medium
SSRF (Server-Side Request Forgery): How It Works, Bypass Techniques, and AI Risks
A web application is a lot like a castle. It’s got WAFs, firewalls, and encryption guarding the front door. This leads many developers to…
⤷ Title: Getting Started with Docker for Application Security: Deploying OWASP crAPI
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:52:14 GMT
════════════════════════
⌗ Tags: #crapi_owasp #docker #application_security #api_security #appsec
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:52:14 GMT
════════════════════════
⌗ Tags: #crapi_owasp #docker #application_security #api_security #appsec
Medium
Getting Started with Docker for Application Security: Deploying OWASP crAPI
Learn how to deploy a deliberately vulnerable API using Docker and begin your API Security journey.
⤷ Title: How a Simple Profile Update Led to Cross-Tenant Data Exposure
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 09:23:41 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #api #appsec #owasp
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 09:23:41 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #api #appsec #owasp
Medium
How a Simple Profile Update Led to Cross-Tenant Data Exposure
Free Article Link: Click for free!
⤷ Title: Inside Web Auth: Unpacking Enumeration, Logic Flaws, and Rate Limits
════════════════════════
𐀪 Author: Bharat Kumar Grover
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 07:57:54 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #penetration_testing #ethical_hacking #appsec
════════════════════════
𐀪 Author: Bharat Kumar Grover
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 07:57:54 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #penetration_testing #ethical_hacking #appsec
Medium
Inside Web Auth: Unpacking Enumeration, Logic Flaws, and Rate Limits
A practical guide to how login mechanisms get exploited in the wild
⤷ Title: Server-Side Request Forgery (SSRF)
════════════════════════
𐀪 Author: Yusufbarut
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 15:04:25 GMT
════════════════════════
⌗ Tags: #owasp #ssrf #cybersecurity #appsec #web_security
════════════════════════
𐀪 Author: Yusufbarut
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 15:04:25 GMT
════════════════════════
⌗ Tags: #owasp #ssrf #cybersecurity #appsec #web_security
Medium
Server-Side Request Forgery (SSRF)
Web Güvenliği Serisi — Bölüm 4
⤷ Title: Unlocking Cybersecurity: What Really Is a Vulnerability? (Part 0)
════════════════════════
𐀪 Author: Zahra Alizada
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 12:27:56 GMT
════════════════════════
⌗ Tags: #software_engineering #infosec #appsec #cybersecurity
════════════════════════
𐀪 Author: Zahra Alizada
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 12:27:56 GMT
════════════════════════
⌗ Tags: #software_engineering #infosec #appsec #cybersecurity
Medium
Unlocking Cybersecurity: What Really Is a Vulnerability? (Part 0)
Beyond code flaws: Why understanding system weaknesses is the cornerstone of modern enterprise defense.
⤷ Title: Testing Authorization Boundaries in Multi-Region, Multi-Tenant Applications
════════════════════════
𐀪 Author: Mdporschaa
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:16:01 GMT
════════════════════════
⌗ Tags: #application_security #appsec #cybersecurity #privilege_escalation
════════════════════════
𐀪 Author: Mdporschaa
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:16:01 GMT
════════════════════════
⌗ Tags: #application_security #appsec #cybersecurity #privilege_escalation
Medium
Testing Authorization Boundaries in Multi-Region, Multi-Tenant Applications
How I approach authorization boundary testing when the same application serves multiple accounts and multiple regions from a shared…