⤷ Title: Hacker Holidays Day 8: Towel on the Sunbed
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
Medium
Hacker Holidays Day 8: Towel on the Sunbed
The setup
⤷ Title: Modern web applications depend heavily on JavaScript.
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:48:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:48:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
Medium
Modern web applications depend heavily on JavaScript.
That makes JavaScript files an important source of attack-surface intelligence for security researchers and bug bounty hunters.
⤷ Title: How I Systematically Find XSS Bugs in Bug Bounty Programs (Step-by-Step Method)
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:58:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #cybersecurity #bug_bounty_tips #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:58:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #cybersecurity #bug_bounty_tips #bug_bounty #bug_bounty_writeup
Medium
How I Systematically Find XSS Bugs in Bug Bounty Programs (Step-by-Step Method)
A repeatable recon-to-report process for hunting Cross-Site Scripting ,the vulnerability class that still pays out more than almost…
⤷ Title: Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:02:43 GMT
════════════════════════
⌗ Tags: #vulnerability_analysis #cybersecurity #sql_injection #cve_2026_72898 #application_security
Medium
🚨 Critical Vulnerability Alert: Unauthenticated SQL Injection in Metabase (CVE-2026–72898)
In early August 2026, a maximum-severity security flaw tracked as CVE-2026–72898 (GitHub Advisory: GHSA-vwf4-m7j8-wcjf) was publicly…
⤷ Title: De copilotos a operadores digitales: cómo adoptar agentes de IA sin perder el control
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:43:29 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #ethical_hacking #agentic_ai #hacking
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:43:29 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #ethical_hacking #agentic_ai #hacking
⤷ Title: Coercing WSUS Computer Accounts to Own the Update Server Database
════════════════════════
𐀪 Author: coy0te
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:31:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity
════════════════════════
𐀪 Author: coy0te
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:31:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity
Medium
Coercing WSUS Computer Accounts to Own the Update Server Database
WSUS pushes signed content to every managed endpoint in the environment. If you own the mechanism that decides which files those endpoints…
⤷ Title: How I Took Over a Metabase Admin Panel
════════════════════════
𐀪 Author: samael0x4
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:19:41 GMT
════════════════════════
⌗ Tags: #account_takeover #metabase #cve_2026_72898 #hacking #sql_injection
════════════════════════
𐀪 Author: samael0x4
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:19:41 GMT
════════════════════════
⌗ Tags: #account_takeover #metabase #cve_2026_72898 #hacking #sql_injection
Medium
How I Took Over a Metabase Admin Panel 🥷
One HTTP request. Zero credentials. Full administrator access.
⤷ Title: Linux Privilege Escalation | SUDO, LD_PRELOAD, SUID, and Capabilities
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:13:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hacking #programming
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:13:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hacking #programming
Medium
Linux Privilege Escalation | SUDO, LD_PRELOAD, SUID, and Capabilities
Hey everyone, This write-up vision puts the concept in your mind to get the less privileged user to root access to Linux. I will write a…
⤷ Title: Cuando el agente recuerda de más
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:48:57 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #inteligencia_artificial #artificial_intelligence #hacking
════════════════════════
𐀪 Author: TU INSIGNIA
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:48:57 GMT
════════════════════════
⌗ Tags: #ai_agent #ai #inteligencia_artificial #artificial_intelligence #hacking
⤷ Title: PGP BullyBox Walkthrough
════════════════════════
𐀪 Author: Wang Hao Lee
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:43:47 GMT
════════════════════════
⌗ Tags: #oscp #walkthrough #ctf_walkthrough #hacking #penetration_testing
════════════════════════
𐀪 Author: Wang Hao Lee
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:43:47 GMT
════════════════════════
⌗ Tags: #oscp #walkthrough #ctf_walkthrough #hacking #penetration_testing
Medium
PGP BullyBox Walkthrough
Hi Everyone,
⤷ Title: Five Signatures Were All They Needed. $625,000,000 Was Gone.
════════════════════════
𐀪 Author: The Laundering Room
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:22:05 GMT
════════════════════════
⌗ Tags: #financial_crime #cybersecurity #cryptocurrency #hacking #true_crime
════════════════════════
𐀪 Author: The Laundering Room
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:22:05 GMT
════════════════════════
⌗ Tags: #financial_crime #cybersecurity #cryptocurrency #hacking #true_crime
Medium
Five Signatures Were All They Needed. $625,000,000 Was Gone.
Every hack starts somewhere ordinary. In March 2022, a Sky Mavis engineer opened an email from a recruiter. He passed several rounds of…
⤷ Title: HTB FootPrinting Lab — HARD
════════════════════════
𐀪 Author: Kamith Balasooriya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox #ctf #penetration_testing #infosec
════════════════════════
𐀪 Author: Kamith Balasooriya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox #ctf #penetration_testing #infosec
Medium
HTB FootPrinting Lab — HARD
Before beginning the final lab in the Footprinting path, we are given some information about the server:
⤷ Title: 737 Fake VPN Chrome Extensions Were Secretly Spying on Millions of Users
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:11:00 GMT
════════════════════════
⌗ Tags: #vpn #data_privacy #cybersecurity #infosec #technology
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:11:00 GMT
════════════════════════
⌗ Tags: #vpn #data_privacy #cybersecurity #infosec #technology
Medium
737 Fake VPN Chrome Extensions Were Secretly Spying on Millions of Users
737 Fake VPN Chrome Extensions Were Secretly Spying on Millions of Users
⤷ Title: Hacker Holidays Day 7: Following Someone Else’s Footprints to Root
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:21 GMT
════════════════════════
⌗ Tags: #web_security #nodejs #ctf #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:21 GMT
════════════════════════
⌗ Tags: #web_security #nodejs #ctf #penetration_testing #cybersecurity
Medium
Hacker Holidays Day 7: Following Someone Else’s Footprints to Root
The setup
⤷ Title: Black-Box VAPT Walkthrough (Part 1): Building the Lab, Configuring Nessus, and Finding the Attack…
════════════════════════
𐀪 Author: Souhardya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #black_box_testing #vapt #nessus
════════════════════════
𐀪 Author: Souhardya
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #black_box_testing #vapt #nessus
Medium
Black-Box VAPT Walkthrough (Part 1): Building the Lab, Configuring Nessus, and Finding the Attack Surface
How I set up an isolated pen testing lab, tuned a Nessus scan for full coverage, and surfaced three findings worth digging into further.
⤷ Title: Vulnerability Scanning vs Penetration Testing: A Straight Answer, Then the Details
════════════════════════
𐀪 Author: Consilien
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:11:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #compliance #consilien #penetration_testing #vulnerability_scanning
════════════════════════
𐀪 Author: Consilien
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:11:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #compliance #consilien #penetration_testing #vulnerability_scanning
Medium
Vulnerability Scanning vs Penetration Testing: A Straight Answer, Then the Details
A vulnerability scan is an automated check that finds and lists known weaknesses. A penetration test is a manual attack simulation that…
⤷ Title: TryHackMe — Management Wants a Word | Forensics Walkthrough
════════════════════════
𐀪 Author: SYN
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:03:36 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #ctf #tryhackme_walkthrough #digital_forensics
════════════════════════
𐀪 Author: SYN
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:03:36 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #ctf #tryhackme_walkthrough #digital_forensics
Medium
TryHackMe — Management Wants a Word | Forensics Walkthrough
ROOM LINK — MANAGEMENT WANT A WORD
⤷ Title: Linux Privilege Escalation: Capabilities & PATH Hijacking | TryHackMe
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:28:00 GMT
════════════════════════
⌗ Tags: #ethical_hacking #tryhackme #privilege_escalation #capabilities #path_hijacking
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:28:00 GMT
════════════════════════
⌗ Tags: #ethical_hacking #tryhackme #privilege_escalation #capabilities #path_hijacking
Medium
Linux Privilege Escalation: Capabilities & PATH Hijacking | TryHackMe
In this TryHackMe lab, I explored two important Linux privilege-escalation techniques: Linux Capabilities and PATH Hijacking. I learned how…
⤷ Title: Prototype Pollution: From JavaScript Object Mutation to Real Security Impact
════════════════════════
𐀪 Author: CYBER MIND SPACE
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:56:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_hunting #cybersecurity #prototype_pollution #cybermindspace
════════════════════════
𐀪 Author: CYBER MIND SPACE
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:56:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_hunting #cybersecurity #prototype_pollution #cybermindspace
Medium
Prototype Pollution: From JavaScript Object Mutation to Real Security Impact
One JSON key. Every object in your Node.js process inherits the payload. The gadget decides whether that's a crash, an auth bypass, or a…
⤷ Title: I Studied Cybersecurity for a Year and a Half.
════════════════════════
𐀪 Author: Siddhesh Shinde
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:41:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #fraud_detection #cyber_security_awareness #cybercrime #ethical_hacking
════════════════════════
𐀪 Author: Siddhesh Shinde
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:41:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #fraud_detection #cyber_security_awareness #cybercrime #ethical_hacking
Medium
I Studied Cybersecurity for a Year and a Half. Fraud Detection Surprised Me More Than Anything Else!
I expected to learn about hackers. I ended up down a rabbit hole that made those problems look simple..
⤷ Title: 5 min read
════════════════════════
𐀪 Author: Rhuber
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:45:33 GMT
════════════════════════
⌗ Tags: #api #api_security #devportal #api_portal
════════════════════════
𐀪 Author: Rhuber
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 16:45:33 GMT
════════════════════════
⌗ Tags: #api #api_security #devportal #api_portal
Medium
5 min read
Your API Portal’s Biggest Threat Isn’t Hackers — It’s Visibility Without Control