⤷ Title: Include (THM) — From “Guest” to Root Flag: A Chain of Small Mistakes
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:02:37 GMT
════════════════════════
⌗ Tags: #include #ctf #idor #tryhackme #web_security
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:02:37 GMT
════════════════════════
⌗ Tags: #include #ctf #idor #tryhackme #web_security
Medium
Include (THM) — From “Guest” to Root Flag: A Chain of Small Mistakes
A web exploitation writeup covering IDOR, forced authentication bypass, base64-leaked credentials, Local File Inclusion, and SSH password…
⤷ Title: THM: Phishing Emails in Action — by MONISH KUMAR S S
════════════════════════
𐀪 Author: Monishkumar SS
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:32:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #soc #blue_team #phishing_awareness #tryhackme
════════════════════════
𐀪 Author: Monishkumar SS
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:32:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #soc #blue_team #phishing_awareness #tryhackme
Medium
THM: Phishing Emails in Action —
how i analyzed realistic phishing emails in THM,identified malicious links,spoofed senders,suspicious attachments ,credential harvest
⤷ Title: Report Writing for SOC L2
════════════════════════
𐀪 Author: FireWolf
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:10:14 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #ctf_walkthrough
════════════════════════
𐀪 Author: FireWolf
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:10:14 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #ctf_walkthrough
Medium
Report Writing for SOC L2
Explore a vital skill for any senior role in a SOC: report writing.
⤷ Title: Lab: SQL injection attack, listing the database contents on non-Oracle databases
════════════════════════
𐀪 Author: Youssef AlaaEldin
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:04 GMT
════════════════════════
⌗ Tags: #administration #portswigger_lab #sqli #portswigger #data_extraction
════════════════════════
𐀪 Author: Youssef AlaaEldin
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:04 GMT
════════════════════════
⌗ Tags: #administration #portswigger_lab #sqli #portswigger #data_extraction
Medium
Lab: SQL injection attack, listing the database contents on non-Oracle databases
Portswigger Lab
⤷ Title: Brief Intro to Real-world SQLi breaches
════════════════════════
𐀪 Author: Nene
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:54:23 GMT
════════════════════════
⌗ Tags: #sql_injection #sql #case_study #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Nene
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 14:54:23 GMT
════════════════════════
⌗ Tags: #sql_injection #sql #case_study #cybersecurity #cyber_security_awareness
Medium
Brief Intro to Real-world SQLi breaches
Despite being older than Wikipedia itself, this vulnerability is nonetheless ranked highly on the OWASP Top 10 list of web application…
⤷ Title: Hacker Holidays Day 8: Towel on the Sunbed
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
Medium
Hacker Holidays Day 8: Towel on the Sunbed
The setup
⤷ Title: Modern web applications depend heavily on JavaScript.
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:48:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:48:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
Medium
Modern web applications depend heavily on JavaScript.
That makes JavaScript files an important source of attack-surface intelligence for security researchers and bug bounty hunters.
⤷ Title: How I Systematically Find XSS Bugs in Bug Bounty Programs (Step-by-Step Method)
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:58:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #cybersecurity #bug_bounty_tips #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:58:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #cybersecurity #bug_bounty_tips #bug_bounty #bug_bounty_writeup
Medium
How I Systematically Find XSS Bugs in Bug Bounty Programs (Step-by-Step Method)
A repeatable recon-to-report process for hunting Cross-Site Scripting ,the vulnerability class that still pays out more than almost…
⤷ Title: Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
Medium
🚨 Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
In early August 2026, a maximum-severity security flaw tracked as CVE-2026–72898 (GitHub Advisory: GHSA-vwf4-m7j8-wcjf) was publicly…
⤷ Title: De copilotos a operadores digitales: cómo adoptar agentes de IA sin perder el control
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:43:29 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #ethical_hacking #agentic_ai #hacking
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:43:29 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #ethical_hacking #agentic_ai #hacking
⤷ Title: Coercing WSUS Computer Accounts to Own the Update Server Database
════════════════════════
𐀪 Author: coy0te
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:31:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity
════════════════════════
𐀪 Author: coy0te
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:31:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity
Medium
Coercing WSUS Computer Accounts to Own the Update Server Database
WSUS pushes signed content to every managed endpoint in the environment. If you own the mechanism that decides which files those endpoints…
⤷ Title: How I Took Over a Metabase Admin Panel
════════════════════════
𐀪 Author: samael0x4
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:19:41 GMT
════════════════════════
⌗ Tags: #account_takeover #metabase #cve_2026_72898 #hacking #sql_injection
════════════════════════
𐀪 Author: samael0x4
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:19:41 GMT
════════════════════════
⌗ Tags: #account_takeover #metabase #cve_2026_72898 #hacking #sql_injection
Medium
How I Took Over a Metabase Admin Panel 🥷
One HTTP request. Zero credentials. Full administrator access.
⤷ Title: Linux Privilege Escalation | SUDO, LD_PRELOAD, SUID, and Capabilities
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:13:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hacking #programming
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:13:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hacking #programming
Medium
Linux Privilege Escalation | SUDO, LD_PRELOAD, SUID, and Capabilities
Hey everyone, This write-up vision puts the concept in your mind to get the less privileged user to root access to Linux. I will write a…
⤷ Title: Cuando el agente recuerda de más
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:48:57 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #inteligencia_artificial #artificial_intelligence #hacking
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:48:57 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #inteligencia_artificial #artificial_intelligence #hacking
⤷ Title: PGP BullyBox Walkthrough
════════════════════════
𐀪 Author: Wang Hao Lee
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:43:47 GMT
════════════════════════
⌗ Tags: #oscp #walkthrough #ctf_walkthrough #hacking #penetration_testing
════════════════════════
𐀪 Author: Wang Hao Lee
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:43:47 GMT
════════════════════════
⌗ Tags: #oscp #walkthrough #ctf_walkthrough #hacking #penetration_testing
Medium
PGP BullyBox Walkthrough
Hi Everyone,
⤷ Title: Five Signatures Were All They Needed. $625,000,000 Was Gone.
════════════════════════
𐀪 Author: The Laundering Room
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:22:05 GMT
════════════════════════
⌗ Tags: #financial_crime #cybersecurity #cryptocurrency #hacking #true_crime
════════════════════════
𐀪 Author: The Laundering Room
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:22:05 GMT
════════════════════════
⌗ Tags: #financial_crime #cybersecurity #cryptocurrency #hacking #true_crime
Medium
Five Signatures Were All They Needed. $625,000,000 Was Gone.
Every hack starts somewhere ordinary. In March 2022, a Sky Mavis engineer opened an email from a recruiter. He passed several rounds of…
⤷ Title: HTB FootPrinting Lab — HARD
════════════════════════
𐀪 Author: Kamith Balasooriya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox #ctf #penetration_testing #infosec
════════════════════════
𐀪 Author: Kamith Balasooriya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox #ctf #penetration_testing #infosec
Medium
HTB FootPrinting Lab — HARD
Before beginning the final lab in the Footprinting path, we are given some information about the server:
⤷ Title: 737 Fake VPN Chrome Extensions Were Secretly Spying on Millions of Users
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:11:00 GMT
════════════════════════
⌗ Tags: #vpn #data_privacy #cybersecurity #infosec #technology
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:11:00 GMT
════════════════════════
⌗ Tags: #vpn #data_privacy #cybersecurity #infosec #technology
Medium
737 Fake VPN Chrome Extensions Were Secretly Spying on Millions of Users
737 Fake VPN Chrome Extensions Were Secretly Spying on Millions of Users
⤷ Title: Hacker Holidays Day 7: Following Someone Else’s Footprints to Root
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:21 GMT
════════════════════════
⌗ Tags: #web_security #nodejs #ctf #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:21 GMT
════════════════════════
⌗ Tags: #web_security #nodejs #ctf #penetration_testing #cybersecurity
Medium
Hacker Holidays Day 7: Following Someone Else’s Footprints to Root
The setup
⤷ Title: Black-Box VAPT Walkthrough (Part 1): Building the Lab, Configuring Nessus, and Finding the Attack…
════════════════════════
𐀪 Author: Souhardya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #black_box_testing #vapt #nessus
════════════════════════
𐀪 Author: Souhardya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #black_box_testing #vapt #nessus
Medium
Black-Box VAPT Walkthrough (Part 1): Building the Lab, Configuring Nessus, and Finding the Attack Surface
How I set up an isolated pen testing lab, tuned a Nessus scan for full coverage, and surfaced three findings worth digging into further.
⤷ Title: Vulnerability Scanning vs Penetration Testing: A Straight Answer, Then the Details
════════════════════════
𐀪 Author: Consilien
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:11:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #compliance #consilien #penetration_testing #vulnerability_scanning
════════════════════════
𐀪 Author: Consilien
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:11:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #compliance #consilien #penetration_testing #vulnerability_scanning
Medium
Vulnerability Scanning vs Penetration Testing: A Straight Answer, Then the Details
A vulnerability scan is an automated check that finds and lists known weaknesses. A penetration test is a manual attack simulation that…