⤷ Title: How a Broken “Preview” Button Exposed 800,000 Private Documents for a $8,500 Bounty
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:36:01 GMT
════════════════════════
⌗ Tags: #ai #security #bug_bounty #pentesting #cybersecurity
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:36:01 GMT
════════════════════════
⌗ Tags: #ai #security #bug_bounty #pentesting #cybersecurity
Medium
How a Broken “Preview” Button Exposed 800,000 Private Documents for a $8,500 Bounty
If there’s one lesson every bug hunter learns the hard way, it’s this: The most dangerous features are often the ones built purely for user…
⤷ Title: Bypassing Keyword and Character Filters to Achieve Reflected XSS
════════════════════════
𐀪 Author: Bahmed Boumriga
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:26:56 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #xss_attack #web_security #cybersecurity
════════════════════════
𐀪 Author: Bahmed Boumriga
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:26:56 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #xss_attack #web_security #cybersecurity
Medium
Bypassing Keyword and Character Filters to Achieve Reflected XSS
A Bug Bounty Writeup | HackerOne Report
⤷ Title: From Bug Bounties to “Pay-to-Report”: The Absurd Rise of Bureaucracy and Cash-Grabbing in Web3…
════════════════════════
𐀪 Author: Jwadmohamd
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:59:17 GMT
════════════════════════
⌗ Tags: #cryptocurrency #web3_security #bug_bounty
════════════════════════
𐀪 Author: Jwadmohamd
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:59:17 GMT
════════════════════════
⌗ Tags: #cryptocurrency #web3_security #bug_bounty
Medium
From Bug Bounties to “Pay-to-Report”: The Absurd Rise of Bureaucracy and Cash-Grabbing in Web3 Security
How Web3 security platforms turned ethical hackers into cash cows, added gaming credentials for identity verification, and killed the true…
⤷ Title: How AI Is Transforming Bug Bounty Hunting: My AI-Powered Vulnerability Research Workflow
════════════════════════
𐀪 Author: cyber security
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:40:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #bug_bounty #artificial_intelligence
════════════════════════
𐀪 Author: cyber security
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:40:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #bug_bounty #artificial_intelligence
Medium
How AI Is Transforming Bug Bounty Hunting: My AI-Powered Vulnerability Research Workflow
Life in cybersecurity moves fast. And in bug bounty, that speed matters even more.
⤷ Title: We Found Authorization Vulnerabilities in Two of GitHub’s Most-Starred Java Repositories — Semgrep…
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #spring_boot #application_security #java #static_analysis
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #spring_boot #application_security #java #static_analysis
Medium
We Found Authorization Vulnerabilities in Two of GitHub’s Most-Starred Java Repositories — Semgrep and CodeQL Both Missed Them
110,000 combined stars. Zero authorization findings from the industry-standard scanners. Here’s what a purpose-built tool found instead.
⤷ Title: Ağ Dünyasının Görünmez Mimarisini Anlamak: Kritik Protokoller, Hangi Katmanda Ne Çalışır?
════════════════════════
𐀪 Author: Aslıhan Zeynep Koç
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #network_security #networking
════════════════════════
𐀪 Author: Aslıhan Zeynep Koç
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #network_security #networking
⤷ Title: BebopC2 — A First Look at the New Open Source C2 Framework
════════════════════════
𐀪 Author: aw0ken
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:13:44 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #red_team #hacking #penetration_testing
════════════════════════
𐀪 Author: aw0ken
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:13:44 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #red_team #hacking #penetration_testing
Medium
BebopC2 — A First Look at the New Open Source C2 Framework
BebopC2 is open source — the framework and official documentation are both available through the author’s GitHub at…
⤷ Title: Team | TryHackMe Walkthrough
════════════════════════
𐀪 Author: ANWAR1
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:11:49 GMT
════════════════════════
⌗ Tags: #team #team_ctf #tryhackme_writeup #team_walkthrough #tryhackme
════════════════════════
𐀪 Author: ANWAR1
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:11:49 GMT
════════════════════════
⌗ Tags: #team #team_ctf #tryhackme_writeup #team_walkthrough #tryhackme
Medium
Team | TryHackMe Walkthrough
First we started from Scanning,
⤷ Title: TryHackMe | Snort Challenge-The Basics
════════════════════════
𐀪 Author: Mazen El-Mekawy
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:05:08 GMT
════════════════════════
⌗ Tags: #id #tryhackme_walkthrough #challenge #tryhackme #snort
════════════════════════
𐀪 Author: Mazen El-Mekawy
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:05:08 GMT
════════════════════════
⌗ Tags: #id #tryhackme_walkthrough #challenge #tryhackme #snort
Medium
TryHackMe | Snort Challenge-The Basics
A Walk-through of the Snort Challenge room, where we’ll create rules, troubleshoot rule syntax errors, and investigate PCAP files.
⤷ Title: Include (THM) — From “Guest” to Root Flag: A Chain of Small Mistakes
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:02:37 GMT
════════════════════════
⌗ Tags: #include #ctf #idor #tryhackme #web_security
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:02:37 GMT
════════════════════════
⌗ Tags: #include #ctf #idor #tryhackme #web_security
Medium
Include (THM) — From “Guest” to Root Flag: A Chain of Small Mistakes
A web exploitation writeup covering IDOR, forced authentication bypass, base64-leaked credentials, Local File Inclusion, and SSH password…
⤷ Title: THM: Phishing Emails in Action — by MONISH KUMAR S S
════════════════════════
𐀪 Author: Monishkumar SS
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:32:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #soc #blue_team #phishing_awareness #tryhackme
════════════════════════
𐀪 Author: Monishkumar SS
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:32:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #soc #blue_team #phishing_awareness #tryhackme
Medium
THM: Phishing Emails in Action —
how i analyzed realistic phishing emails in THM,identified malicious links,spoofed senders,suspicious attachments ,credential harvest
⤷ Title: Report Writing for SOC L2
════════════════════════
𐀪 Author: FireWolf
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:10:14 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #ctf_walkthrough
════════════════════════
𐀪 Author: FireWolf
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:10:14 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #ctf_walkthrough
Medium
Report Writing for SOC L2
Explore a vital skill for any senior role in a SOC: report writing.
⤷ Title: Lab: SQL injection attack, listing the database contents on non-Oracle databases
════════════════════════
𐀪 Author: Youssef AlaaEldin
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:04 GMT
════════════════════════
⌗ Tags: #administration #portswigger_lab #sqli #portswigger #data_extraction
════════════════════════
𐀪 Author: Youssef AlaaEldin
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:04 GMT
════════════════════════
⌗ Tags: #administration #portswigger_lab #sqli #portswigger #data_extraction
Medium
Lab: SQL injection attack, listing the database contents on non-Oracle databases
Portswigger Lab
⤷ Title: Brief Intro to Real-world SQLi breaches
════════════════════════
𐀪 Author: Nene
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:54:23 GMT
════════════════════════
⌗ Tags: #sql_injection #sql #case_study #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Nene
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:54:23 GMT
════════════════════════
⌗ Tags: #sql_injection #sql #case_study #cybersecurity #cyber_security_awareness
Medium
Brief Intro to Real-world SQLi breaches
Despite being older than Wikipedia itself, this vulnerability is nonetheless ranked highly on the OWASP Top 10 list of web application…
⤷ Title: Hacker Holidays Day 8: Towel on the Sunbed
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
Medium
Hacker Holidays Day 8: Towel on the Sunbed
The setup
⤷ Title: Modern web applications depend heavily on JavaScript.
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:48:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:48:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
Medium
Modern web applications depend heavily on JavaScript.
That makes JavaScript files an important source of attack-surface intelligence for security researchers and bug bounty hunters.
⤷ Title: How I Systematically Find XSS Bugs in Bug Bounty Programs (Step-by-Step Method)
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:58:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #cybersecurity #bug_bounty_tips #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:58:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #cybersecurity #bug_bounty_tips #bug_bounty #bug_bounty_writeup
Medium
How I Systematically Find XSS Bugs in Bug Bounty Programs (Step-by-Step Method)
A repeatable recon-to-report process for hunting Cross-Site Scripting ,the vulnerability class that still pays out more than almost…
⤷ Title: Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
Medium
🚨 Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
In early August 2026, a maximum-severity security flaw tracked as CVE-2026–72898 (GitHub Advisory: GHSA-vwf4-m7j8-wcjf) was publicly…
⤷ Title: De copilotos a operadores digitales: cómo adoptar agentes de IA sin perder el control
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:43:29 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #ethical_hacking #agentic_ai #hacking
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:43:29 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #ethical_hacking #agentic_ai #hacking
⤷ Title: Coercing WSUS Computer Accounts to Own the Update Server Database
════════════════════════
𐀪 Author: coy0te
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:31:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity
════════════════════════
𐀪 Author: coy0te
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:31:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity
Medium
Coercing WSUS Computer Accounts to Own the Update Server Database
WSUS pushes signed content to every managed endpoint in the environment. If you own the mechanism that decides which files those endpoints…
⤷ Title: How I Took Over a Metabase Admin Panel
════════════════════════
𐀪 Author: samael0x4
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:19:41 GMT
════════════════════════
⌗ Tags: #account_takeover #metabase #cve_2026_72898 #hacking #sql_injection
════════════════════════
𐀪 Author: samael0x4
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:19:41 GMT
════════════════════════
⌗ Tags: #account_takeover #metabase #cve_2026_72898 #hacking #sql_injection
Medium
How I Took Over a Metabase Admin Panel 🥷
One HTTP request. Zero credentials. Full administrator access.