⤷ Title: MariaDB CVE-2026–49261: Pre-Authentication Remote Code Execution via wsrep_notify_cmd
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 06:31:01 GMT
════════════════════════
⌗ Tags: #security #letchupkt #bug_bounty_writeup #cve_2026_49261 #cve
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 06:31:01 GMT
════════════════════════
⌗ Tags: #security #letchupkt #bug_bounty_writeup #cve_2026_49261 #cve
Medium
MariaDB CVE-2026–49261: Pre-Authentication Remote Code Execution via wsrep_notify_cmd
How an attacker-controlled Galera node name resulted in arbitrary OS command execution across cluster members.
⤷ Title: Smali By bithowl: Chapter 5 Smali File Structure
════════════════════════
𐀪 Author: bithowl
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 05:31:01 GMT
════════════════════════
⌗ Tags: #bithowl #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: bithowl
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 05:31:01 GMT
════════════════════════
⌗ Tags: #bithowl #bug_bounty_writeup #bug_bounty
Medium
Smali By bithowl: Chapter 5 Smali File Structure
(“Every Smali File Tells a Story… If You Know How to Read It”)
⤷ Title: Uncovering a Privacy Bug in Proton Meet — How a Simple Logic ‘Typo’ Earned Me $100
════════════════════════
𐀪 Author: Kenjisubagja
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 00:15:51 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #proton #bug_bounty #bug_bounty_hunter
════════════════════════
𐀪 Author: Kenjisubagja
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 00:15:51 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #proton #bug_bounty #bug_bounty_hunter
Medium
Uncovering a Privacy Bug in Proton Meet — How a Simple Logic ‘Typo’ Earned Me $100
this is the second bug bounty received by Proton 🔥
⤷ Title: The SSRF That Wasn’t Supposed to Work Twice
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 20:16:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #pentesting #bug_bounty_writeup #security
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 20:16:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #pentesting #bug_bounty_writeup #security
Medium
The SSRF That Wasn’t Supposed to Work Twice
This one has a twist in it, so bear with the setup. The bug wasn’t hard to find. Getting it accepted was the actual fight.
⤷ Title: MariaDB CVE-2026–48165: Authenticated Remote Code Execution through WSREP State Snapshot Transfer
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 16:37:09 GMT
════════════════════════
⌗ Tags: #security #letchupkt #cve #bug_bounty_writeup #cve202648165
════════════════════════
𐀪 Author: LETCHU PKT
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 16:37:09 GMT
════════════════════════
⌗ Tags: #security #letchupkt #cve #bug_bounty_writeup #cve202648165
Medium
MariaDB CVE-2026–48165: Authenticated Remote Code Execution through WSREP State Snapshot Transfer
How a missing validation check in Galera’s SST implementation allowed authenticated OS command execution.
⤷ Title: How to Build a Recon Workflow That Actually Finds Bugs (Not Just Data)
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:02:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #infosec #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:02:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #infosec #bug_bounty_tips #bug_bounty
Medium
How to Build a Recon Workflow That Actually Finds Bugs (Not Just Data)
10,000 subdomains is not recon. It’s noise. Here is the pipeline that turns raw output into testable findings.
⤷ Title: CRTA - da Aplicação Web ao Domain Admin
════════════════════════
𐀪 Author: Roger Zeferino
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:08:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #enumeration #red_team #recon #penetration_testing
════════════════════════
𐀪 Author: Roger Zeferino
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 16:08:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #enumeration #red_team #recon #penetration_testing
⤷ Title: The Lesser-Known Art of Recon Using Favicon Hashes
════════════════════════
𐀪 Author: Nothing
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:49:45 GMT
════════════════════════
⌗ Tags: #recon #osint #bug_bounty #cybersecurity #web_penetration_testing
════════════════════════
𐀪 Author: Nothing
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:49:45 GMT
════════════════════════
⌗ Tags: #recon #osint #bug_bounty #cybersecurity #web_penetration_testing
Medium
The Lesser-Known Art of Recon Using Favicon Hashes
A practical guide to fingerprinting technology stacks at scale — and why one tiny, forgotten image file can leak more about a target’s…
⤷ Title: When Your AI Assistant Has More Permissions Than You Do: An Access Control Bypass Story
════════════════════════
𐀪 Author: Ferdus Alam
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 12:13:49 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bugs #ai_security #bug_bounty_tips #ai_bug
════════════════════════
𐀪 Author: Ferdus Alam
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 12:13:49 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bugs #ai_security #bug_bounty_tips #ai_bug
Medium
When Your AI Assistant Has More Permissions Than You Do: An Access Control Bypass Story
The Setup
⤷ Title: How I Almost Made $1,000 with a Pre-Account Takeover
════════════════════════
𐀪 Author: Ahmad Farel Pratama
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:17:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #ethical_hacking #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: Ahmad Farel Pratama
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 12:17:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #ethical_hacking #bug_bounty #bugbounty_writeup
Medium
How I Almost Made $1,000 with a Pre-Account Takeover
While testing the authentication functionality on redacted.com, I came across something quite interesting involving the combination of…
⤷ Title: How I Use AI as a Bug Bounty Hunter — Part 1: My Real Setup
════════════════════════
𐀪 Author: BadYasser
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:22:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips
════════════════════════
𐀪 Author: BadYasser
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:22:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips
Medium
How I Use AI as a Bug Bounty Hunter — Part 1: My Real Setup
Introduction
⤷ Title: How I Escalated Privileges by Manipulating a Client-Side Permission Matrix
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 06:38:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #penetration_testing #broken_access_control #bug_bounty
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 06:38:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #penetration_testing #broken_access_control #bug_bounty
Medium
How I Escalated Privileges by Manipulating a Client-Side Permission Matrix
A Tale of Broken Access Control
⤷ Title: PoC Vault by CyberSecPlayground
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 19:50:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #hacking #penetration_testing #proof_of_concept
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 19:50:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #hacking #penetration_testing #proof_of_concept
Medium
PoC Vault by CyberSecPlayground
🚀 PoC Vault is Now Live!
⤷ Title: Apostrophe Has Abolished the Password
════════════════════════
𐀪 Author: Leonardo R Cavalcante
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 03:56:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_app_pentesting #bug_bounty_tips #bug_bounty #pentesting
════════════════════════
𐀪 Author: Leonardo R Cavalcante
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 03:56:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_app_pentesting #bug_bounty_tips #bug_bounty #pentesting
Medium
Apostrophe Has Abolished the Password
The password was present.
⤷ Title: CVE-2026-64564: SCTP Flaw Enables Container Escape
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_64564 #Linux Kernel #privilege escalation #SCTPhantom #use after free
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #CVE_2026_64564 #Linux Kernel #privilege escalation #SCTPhantom #use after free
Daily CyberSecurity
CVE-2026-64564: SCTP Flaw Enables Container Escape
TL;DR A Linux kernel use-after-free in SCTP, tracked as CVE-2026-64564, allows local attackers to gain root. Researchers demonstrated privilege escalation and container-to-host escape on five dist…
⤷ Title: PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:01:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_63077 #exploited in the wild #JetBrains #Remote Code Execution #TeamCity #unsafe deserialization
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 01:01:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_63077 #exploited in the wild #JetBrains #Remote Code Execution #TeamCity #unsafe deserialization
Daily CyberSecurity
PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild
TL;DR CVE-2026-63077 is a critical unauthenticated remote code execution flaw in JetBrains TeamCity. An attacker who reaches the server can run OS commands without credentials. CISA confirmed the …
⤷ Title: BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Malware #BdThemes #supply chain attack #Wordfence #wordpress security #XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Malware #BdThemes #supply chain attack #Wordfence #wordpress security #XSS
Daily CyberSecurity
BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins
At a Glance Malware family API-driven XSS supply chain implant (Biggopti banner abuse) Threat actor Suspected; linked to the ARVE and OptinMonster campaigns Targets WordPress sites running seven B…
⤷ Title: Dopamine 3.0 Jailbreak Brings iOS 26 Support to A12 and A13 Devices
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 17:22:03 +0000
════════════════════════
⌗ Tags: #Technology #A12 A13 jailbreak #Dopamine #Dopamine 3.0 #iOS 26 jailbreak #opa334
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 17:22:03 +0000
════════════════════════
⌗ Tags: #Technology #A12 A13 jailbreak #Dopamine #Dopamine 3.0 #iOS 26 jailbreak #opa334
Daily CyberSecurity
Dopamine 3.0 Jailbreak Brings iOS 26 Support to A12 and A13 Devices
Lars Froder, the developer known as opa334, has released Dopamine 3.0, the first jailbreak to support iOS 26. This milestone iOS 26 jailbreak targets devices running iOS 26.0 through 26.0.1 on A12…
⤷ Title: Google Wallet Introduces Digital Allowance for Minors
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 10:19:50 +0000
════════════════════════
⌗ Tags: #Technology #Digital Allowance #Family Link #financial education #Google Wallet #Mobile Payments
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 10:19:50 +0000
════════════════════════
⌗ Tags: #Technology #Digital Allowance #Family Link #financial education #Google Wallet #Mobile Payments
Daily CyberSecurity
Google Wallet Introduces Digital Allowance for Minors
Google recently announced a groundbreaking new feature for the United States market. This innovative capability allows parents to safely distribute digital allowances to teenagers and children und…
⤷ Title: Metabase SQL Injection Zero-Day (CVSS 10) Exploited
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 07:59:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Business Intelligence #exploited in the wild #Metabase #sql injection #Unauthenticated Attack #zero_day
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 07:59:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Business Intelligence #exploited in the wild #Metabase #sql injection #Unauthenticated Attack #zero_day
Daily CyberSecurity
Metabase SQL Injection Zero-Day (CVSS 10) Exploited
TL;DR Metabase disclosed a critical SQL injection zero-day rated CVSS 10. An unauthenticated remote attacker can gain full administrator access to an instance. Metabase confirms active exploitatio…
⤷ Title: Multiple ClamAV Flaws Let Remote Attackers Cause DoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 07:36:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #antivirus #cisco #ClamAV #CVE_2026_20337 #Denial of Service #Secure Endpoint
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 07:36:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #antivirus #cisco #ClamAV #CVE_2026_20337 #Denial of Service #Secure Endpoint
Daily CyberSecurity
Multiple ClamAV Flaws Let Remote Attackers Cause DoS
TL;DR Cisco disclosed seven ClamAV vulnerabilities on August 7, 2026. Each lets an unauthenticated remote attacker crash the scanner with a crafted file. The result is a denial of service that sto…