⤷ Title: When Strong Password Hashing Isn’t Enough: Chaining SQL Injection into Account Takeover
════════════════════════
𐀪 Author: Hossein Zarei
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:31:09 GMT
════════════════════════
⌗ Tags: #account_takeover #cybersecurity #sql_injection #pentesting #ethical_hacking
════════════════════════
𐀪 Author: Hossein Zarei
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:31:09 GMT
════════════════════════
⌗ Tags: #account_takeover #cybersecurity #sql_injection #pentesting #ethical_hacking
Medium
When Strong Password Hashing Isn’t Enough: Chaining SQL Injection into Account Takeover
Hello everyone 👋
⤷ Title: Finding SQL Injection in a Government Website
════════════════════════
𐀪 Author: Ahmad Farel Pratama
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 06:27:28 GMT
════════════════════════
⌗ Tags: #ethical_hacking #sql_injection #bug_bounty_tips #bug_bounty_writeup #cybersecurity
════════════════════════
𐀪 Author: Ahmad Farel Pratama
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 06:27:28 GMT
════════════════════════
⌗ Tags: #ethical_hacking #sql_injection #bug_bounty_tips #bug_bounty_writeup #cybersecurity
Medium
Finding SQL Injection in a Government Website
Finding SQL Injection
⤷ Title: When the Database Becomes the Attacker: The khunt Oracle SQL Injection Incident
════════════════════════
𐀪 Author: GraySentinel- Cyber Defence Lab
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 06:14:56 GMT
════════════════════════
⌗ Tags: #oracle #database #cybersecurity #threat_intelligence #sql_injection
════════════════════════
𐀪 Author: GraySentinel- Cyber Defence Lab
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 06:14:56 GMT
════════════════════════
⌗ Tags: #oracle #database #cybersecurity #threat_intelligence #sql_injection
Medium
When the Database Becomes the Attacker: The khunt Oracle SQL Injection Incident
How a classic SQL injection flaw led to SYSTEM-level compromise through Oracles Java engine
⤷ Title: (BAC)Insecure direct object references
════════════════════════
𐀪 Author: Abdallh Mohamed
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:14:39 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #penetration_testing #web_security #broken_access_control #bug_bounty_writeup
════════════════════════
𐀪 Author: Abdallh Mohamed
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:14:39 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #penetration_testing #web_security #broken_access_control #bug_bounty_writeup
Medium
(BAC)Insecure direct object references
firstly we explain what of the Insecure direct object references???
⤷ Title: Bypassing Filters to Achieve UNION-Based SQL Injection on a Search Endpoint
════════════════════════
𐀪 Author: Samet Yiğit
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 08:11:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Samet Yiğit
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 08:11:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #bug_bounty
Medium
Bypassing Filters to Achieve UNION-Based SQL Injection on a Search Endpoint
Friend Link
⤷ Title: MariaDB CVE-2026–49261: Pre-Authentication Remote Code Execution via wsrep_notify_cmd
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 06:31:01 GMT
════════════════════════
⌗ Tags: #security #letchupkt #bug_bounty_writeup #cve_2026_49261 #cve
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 06:31:01 GMT
════════════════════════
⌗ Tags: #security #letchupkt #bug_bounty_writeup #cve_2026_49261 #cve
Medium
MariaDB CVE-2026–49261: Pre-Authentication Remote Code Execution via wsrep_notify_cmd
How an attacker-controlled Galera node name resulted in arbitrary OS command execution across cluster members.
⤷ Title: Smali By bithowl: Chapter 5 Smali File Structure
════════════════════════
𐀪 Author: bithowl
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 05:31:01 GMT
════════════════════════
⌗ Tags: #bithowl #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: bithowl
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 05:31:01 GMT
════════════════════════
⌗ Tags: #bithowl #bug_bounty_writeup #bug_bounty
Medium
Smali By bithowl: Chapter 5 Smali File Structure
(“Every Smali File Tells a Story… If You Know How to Read It”)
⤷ Title: Uncovering a Privacy Bug in Proton Meet — How a Simple Logic ‘Typo’ Earned Me $100
════════════════════════
𐀪 Author: Kenjisubagja
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 00:15:51 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #proton #bug_bounty #bug_bounty_hunter
════════════════════════
𐀪 Author: Kenjisubagja
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 00:15:51 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #proton #bug_bounty #bug_bounty_hunter
Medium
Uncovering a Privacy Bug in Proton Meet — How a Simple Logic ‘Typo’ Earned Me $100
this is the second bug bounty received by Proton 🔥
⤷ Title: The SSRF That Wasn’t Supposed to Work Twice
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 20:16:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #pentesting #bug_bounty_writeup #security
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 20:16:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #pentesting #bug_bounty_writeup #security
Medium
The SSRF That Wasn’t Supposed to Work Twice
This one has a twist in it, so bear with the setup. The bug wasn’t hard to find. Getting it accepted was the actual fight.
⤷ Title: MariaDB CVE-2026–48165: Authenticated Remote Code Execution through WSREP State Snapshot Transfer
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 16:37:09 GMT
════════════════════════
⌗ Tags: #security #letchupkt #cve #bug_bounty_writeup #cve202648165
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 16:37:09 GMT
════════════════════════
⌗ Tags: #security #letchupkt #cve #bug_bounty_writeup #cve202648165
Medium
MariaDB CVE-2026–48165: Authenticated Remote Code Execution through WSREP State Snapshot Transfer
How a missing validation check in Galera’s SST implementation allowed authenticated OS command execution.
⤷ Title: How to Build a Recon Workflow That Actually Finds Bugs (Not Just Data)
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:02:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #infosec #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:02:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #infosec #bug_bounty_tips #bug_bounty
Medium
How to Build a Recon Workflow That Actually Finds Bugs (Not Just Data)
10,000 subdomains is not recon. It’s noise. Here is the pipeline that turns raw output into testable findings.
⤷ Title: CRTA - da Aplicação Web ao Domain Admin
════════════════════════
𐀪 Author: Roger Zeferino
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:08:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #enumeration #red_team #recon #penetration_testing
════════════════════════
𐀪 Author: Roger Zeferino
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:08:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #enumeration #red_team #recon #penetration_testing
⤷ Title: The Lesser-Known Art of Recon Using Favicon Hashes
════════════════════════
𐀪 Author: Nothing
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:49:45 GMT
════════════════════════
⌗ Tags: #recon #osint #bug_bounty #cybersecurity #web_penetration_testing
════════════════════════
𐀪 Author: Nothing
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:49:45 GMT
════════════════════════
⌗ Tags: #recon #osint #bug_bounty #cybersecurity #web_penetration_testing
Medium
The Lesser-Known Art of Recon Using Favicon Hashes
A practical guide to fingerprinting technology stacks at scale — and why one tiny, forgotten image file can leak more about a target’s…
⤷ Title: When Your AI Assistant Has More Permissions Than You Do: An Access Control Bypass Story
════════════════════════
𐀪 Author: Ferdus Alam
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 12:13:49 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bugs #ai_security #bug_bounty_tips #ai_bug
════════════════════════
𐀪 Author: Ferdus Alam
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 12:13:49 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bugs #ai_security #bug_bounty_tips #ai_bug
Medium
When Your AI Assistant Has More Permissions Than You Do: An Access Control Bypass Story
The Setup
⤷ Title: How I Almost Made $1,000 with a Pre-Account Takeover
════════════════════════
𐀪 Author: Ahmad Farel Pratama
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:17:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #ethical_hacking #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: Ahmad Farel Pratama
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:17:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #ethical_hacking #bug_bounty #bugbounty_writeup
Medium
How I Almost Made $1,000 with a Pre-Account Takeover
While testing the authentication functionality on redacted.com, I came across something quite interesting involving the combination of…
⤷ Title: How I Use AI as a Bug Bounty Hunter — Part 1: My Real Setup
════════════════════════
𐀪 Author: BadYasser
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:22:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips
════════════════════════
𐀪 Author: BadYasser
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:22:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips
Medium
How I Use AI as a Bug Bounty Hunter — Part 1: My Real Setup
Introduction
⤷ Title: How I Escalated Privileges by Manipulating a Client-Side Permission Matrix
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 06:38:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #penetration_testing #broken_access_control #bug_bounty
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 06:38:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #penetration_testing #broken_access_control #bug_bounty
Medium
How I Escalated Privileges by Manipulating a Client-Side Permission Matrix
A Tale of Broken Access Control
⤷ Title: PoC Vault by CyberSecPlayground
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 19:50:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #hacking #penetration_testing #proof_of_concept
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 19:50:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #hacking #penetration_testing #proof_of_concept
Medium
PoC Vault by CyberSecPlayground
🚀 PoC Vault is Now Live!
⤷ Title: Apostrophe Has Abolished the Password
════════════════════════
𐀪 Author: Leonardo R Cavalcante
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 03:56:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_app_pentesting #bug_bounty_tips #bug_bounty #pentesting
════════════════════════
𐀪 Author: Leonardo R Cavalcante
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 03:56:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_app_pentesting #bug_bounty_tips #bug_bounty #pentesting
Medium
Apostrophe Has Abolished the Password
The password was present.
⤷ Title: CVE-2026-64564: SCTP Flaw Enables Container Escape
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_64564 #Linux Kernel #privilege escalation #SCTPhantom #use after free
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_64564 #Linux Kernel #privilege escalation #SCTPhantom #use after free
Daily CyberSecurity
CVE-2026-64564: SCTP Flaw Enables Container Escape
TL;DR A Linux kernel use-after-free in SCTP, tracked as CVE-2026-64564, allows local attackers to gain root. Researchers demonstrated privilege escalation and container-to-host escape on five dist…
⤷ Title: PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:01:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_63077 #exploited in the wild #JetBrains #Remote Code Execution #TeamCity #unsafe deserialization
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:01:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_63077 #exploited in the wild #JetBrains #Remote Code Execution #TeamCity #unsafe deserialization
Daily CyberSecurity
PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild
TL;DR CVE-2026-63077 is a critical unauthenticated remote code execution flaw in JetBrains TeamCity. An attacker who reaches the server can run OS commands without credentials. CISA confirmed the …