⤷ Title: How I Took Over Any Employee Account With Just a Username
════════════════════════
𐀪 Author: reox17
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:27:10 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #bug_bounty_writeup #bugcrowd #bug_bounty
════════════════════════
𐀪 Author: reox17
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:27:10 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #bug_bounty_writeup #bugcrowd #bug_bounty
Medium
How I Took Over Any Employee Account With Just a Username
Note: the real domain is redacted throughout this write-up and replaced with example.com.
⤷ Title: The Cache That Trusted Too Much
════════════════════════
𐀪 Author: lolidkmyname
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:24:05 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: lolidkmyname
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:24:05 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
The Cache That Trusted Too Much
Summary
⤷ Title: Bug Bounty: When a “Random” UUID Wasn’t Random Enough — Cross-Tenant Credential Leak in an ATS…
════════════════════════
𐀪 Author: Pulga (bettercallme)
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:16:53 GMT
════════════════════════
⌗ Tags: #bug_bounty #idor #bug_bounty_tips
════════════════════════
𐀪 Author: Pulga (bettercallme)
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:16:53 GMT
════════════════════════
⌗ Tags: #bug_bounty #idor #bug_bounty_tips
Medium
Bug Bounty: When a “Random” UUID Wasn’t Random Enough — Cross-Tenant Credential Leak in an ATS Integration Layer
بسم الله الرحمن الرحيم، والصلاة والسلام على أشرف المرسلين سيدنا محمد ﷺ.
⤷ Title: Bug Bounty Recon & Vulnerability Cheat Sheet
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:01:01 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #pentesting #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:01:01 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #pentesting #bug_bounty_writeup #bug_bounty
Medium
Bug Bounty Recon & Vulnerability Cheat Sheet
A quick-reference guide to the specific headers, payloads, commands, and logic bypasses featured in the writeups.
⤷ Title: Session Hijacking: The Silent Takeover
════════════════════════
𐀪 Author: SH4D0W SL4V3
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 17:57:36 GMT
════════════════════════
⌗ Tags: #xss_attack #hacking #session_hijacking #oauth #account_takeover
════════════════════════
𐀪 Author: SH4D0W SL4V3
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 17:57:36 GMT
════════════════════════
⌗ Tags: #xss_attack #hacking #session_hijacking #oauth #account_takeover
Medium
Session Hijacking: The Silent Takeover
Why stealing a session can be more valuable than stealing a password.
⤷ Title: Internal CTF TryHackMe — Walktrough
════════════════════════
𐀪 Author: Qasimov Davud
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:54:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #ctf #infosec #ctf_writeup
════════════════════════
𐀪 Author: Qasimov Davud
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:54:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #ctf #infosec #ctf_writeup
Medium
Internal CTF TryHackMe — Walktrough
Engagement Overview
⤷ Title: DNS Zone Transfer to Root — RatCTF Write-up
════════════════════════
𐀪 Author: 0xnay33m
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:33:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #ctf #privilege_escalation #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: 0xnay33m
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:33:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #ctf #privilege_escalation #penetration_testing #cybersecurity
Medium
DNS Zone Transfer to Root — Lab Walkthrough
How a misconfigured BIND server exposed credentials and led to complete system compromise.
⤷ Title: Exploring Wazuh | TryHackMe Walkthrough
════════════════════════
𐀪 Author: Muhammad Roman Khan
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 18:56:09 GMT
════════════════════════
⌗ Tags: #ctf #wazuh #tryhackme #tryhackme_writeup #tryhackme_walkthrough
════════════════════════
𐀪 Author: Muhammad Roman Khan
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 18:56:09 GMT
════════════════════════
⌗ Tags: #ctf #wazuh #tryhackme #tryhackme_writeup #tryhackme_walkthrough
Medium
Exploring Wazuh | TryHackMe Walkthrough
Wazuh is one of the most popular open-source Security Information and Event Management (SIEM) and Extended Detection and Response (XDR)…
⤷ Title: Natas Web Security Challenges (OverTheWire)-Levels 0 to 10 Walkthrough
════════════════════════
𐀪 Author: Linara
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 18:38:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #natas #ethical_hacking #overthewire #web_security
════════════════════════
𐀪 Author: Linara
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 18:38:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #natas #ethical_hacking #overthewire #web_security
Medium
Natas Web Security Challenges (OverTheWire)-Levels 0 to 10 Walkthrough
Natas 0 → Natas 1
⤷ Title: Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 02:33:04 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 02:33:04 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Hacker Holidays 2026: Day 8 Walkthrough (Towel on the Sunbed)
════════════════════════
𐀪 Author: Dhanush N
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:42:23 GMT
════════════════════════
⌗ Tags: #tryhackme #bug_bounty #cybersecurity #race_condition #hacker_holidays_2026
════════════════════════
𐀪 Author: Dhanush N
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:42:23 GMT
════════════════════════
⌗ Tags: #tryhackme #bug_bounty #cybersecurity #race_condition #hacker_holidays_2026
Medium
Hacker Holidays 2026: Day 8 Walkthrough (Towel on the Sunbed)
A rewards system let you claim 50 points every 24 hours. We claimed it three times in the same millisecond. Welcome to race conditions.
⤷ Title: Everything a Domain Will Tell a Stranger: DNS Enumeration With dig
════════════════════════
𐀪 Author: Muneebahmedkhan
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 21:43:04 GMT
════════════════════════
⌗ Tags: #networking #dns #cybersecurity #bug_bounty #tutorial
════════════════════════
𐀪 Author: Muneebahmedkhan
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 21:43:04 GMT
════════════════════════
⌗ Tags: #networking #dns #cybersecurity #bug_bounty #tutorial
Medium
Everything a Domain Will Tell a Stranger: DNS Enumeration With dig
Query five record types for a domain, decode an SOA field by field, and attempt a zone transfer, so you know what a domain publishes to…
⤷ Title: How an Unauthenticated API Endpoint Exposed 19,990 User Records
════════════════════════
𐀪 Author: Hangga Aji Sayekti
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:38:12 GMT
════════════════════════
⌗ Tags: #pii #security #sensitive_data_exposure #hacking #bugbounty_writeup
════════════════════════
𐀪 Author: Hangga Aji Sayekti
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:38:12 GMT
════════════════════════
⌗ Tags: #pii #security #sensitive_data_exposure #hacking #bugbounty_writeup
Medium
I Changed One URL Parameter and Found PII Exposed Across 19,990 User Profiles
How a missing authorization check turned a profile API into a data exposure risk.
⤷ Title: AI Governance Is Becoming a Business Continuity Issue
════════════════════════
𐀪 Author: Taher Amine ELHOUARI
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:05:16 GMT
════════════════════════
⌗ Tags: #ai_security #ai #information_security_risk #cybersecurity #infosec
════════════════════════
𐀪 Author: Taher Amine ELHOUARI
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:05:16 GMT
════════════════════════
⌗ Tags: #ai_security #ai #information_security_risk #cybersecurity #infosec
Medium
AI Governance Is Becoming a Business Continuity Issue
Why boards must treat AI dependency, agentic authority and model concentration as operational-resilience risks..
⤷ Title: Proving Grounds — Practice — Authby
════════════════════════
𐀪 Author: Makoyi
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:38:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #oscp #ctf #oscp_preparation #ethical_hacking
════════════════════════
𐀪 Author: Makoyi
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:38:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #oscp #ctf #oscp_preparation #ethical_hacking
Medium
Proving Grounds — Practice — Authby
Offsec’s Proving Grounds Practice box Authby is rated intermediate, however the community disagrees and has given the box a rating of hard…
⤷ Title: DNS Zone Transfer to Root — Lab Walkthrough
════════════════════════
𐀪 Author: 0xnay33m
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:33:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #ctf #privilege_escalation #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: 0xnay33m
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 19:33:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #ctf #privilege_escalation #penetration_testing #cybersecurity
Medium
DNS Zone Transfer to Root — Lab Walkthrough
How a misconfigured BIND server exposed credentials and led to complete system compromise.
⤷ Title: Practical OWASP API Security Testing: Finding Broken Object Level Authorization (BOLA)
════════════════════════
𐀪 Author: Chimezirim Oti
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:03:02 GMT
════════════════════════
⌗ Tags: #web_security #information_security #software_security #cybersecurity #api_security
════════════════════════
𐀪 Author: Chimezirim Oti
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 20:03:02 GMT
════════════════════════
⌗ Tags: #web_security #information_security #software_security #cybersecurity #api_security
Medium
Practical OWASP API Security Testing: Finding Broken Object Level Authorization (BOLA)
A practical approach to identifying object-level authorization weaknesses in modern APIs
⤷ Title: The 10 Best Bug Bounty Tools in 2026 (What Actual Hunters Use for Manual Testing)
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:52:21 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #bug_bounty #bugbounty_writeup #cybersecurity
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:52:21 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #bug_bounty #bugbounty_writeup #cybersecurity
Medium
The 10 Best Bug Bounty Tools in 2026 (What Actual Hunters Use for Manual Testing)
Beyond the generic “run a scanner” lists — the toolkit built around finding access control and business logic bugs, the kind automated…
⤷ Title: The Bug Bounty Meat Grinder: Why Platforms Are Broken And How to Actually Win
════════════════════════
𐀪 Author: CypherNova1337
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:46:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #bug_bounty #infosec #cybersecurity
════════════════════════
𐀪 Author: CypherNova1337
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:46:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #bug_bounty #infosec #cybersecurity
Medium
The Bug Bounty Meat Grinder: Why Platforms Are Broken And How to Actually Win
This is a long one but it is very important to understand the process of platforms like Hackerone.
⤷ Title: Open, Closed, Filtered: Reading an Nmap Scan Properly
════════════════════════
𐀪 Author: Muneebahmedkhan
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:18:21 GMT
════════════════════════
⌗ Tags: #nmap #tutorial #bug_bounty #cybersecurity #networking
════════════════════════
𐀪 Author: Muneebahmedkhan
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:18:21 GMT
════════════════════════
⌗ Tags: #nmap #tutorial #bug_bounty #cybersecurity #networking
Medium
Open, Closed, Filtered: Reading an Nmap Scan Properly
Scan a legal practice host for eight specific services, tell a closed port apart from a filtered one, and pull an exact software version…
⤷ Title: SpiderHack: Away From The Flag — Official Writeup
════════════════════════
𐀪 Author: Khaled Ebrahem
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:29:03 GMT
════════════════════════
⌗ Tags: #ctf #ascwg #ctf_writeup #hacking
════════════════════════
𐀪 Author: Khaled Ebrahem
════════════════════════
ⴵ Time: Mon, 17 Aug 2026 22:29:03 GMT
════════════════════════
⌗ Tags: #ctf #ascwg #ctf_writeup #hacking
Medium
🕷SpiderHack: Away From The Flag — Official Writeup
“With great power comes great vulnerability scanning.” — Uncle Ben