⤷ Title: How a Simple Reset Password Button Bypassed 2FA Entirely
════════════════════════
𐀪 Author: Omar Zaky
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:17:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #web_security #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: Omar Zaky
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:17:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #web_security #bug_bounty #ethical_hacking
Medium
How a Simple Reset Password Button Bypassed 2FA Entirely 🤯
Ever had that moment where you find a bug so simple, you just sit back and laugh at how easy it was?
⤷ Title: From Bug to Schema: Exploring Error-Based SQL Injection on an Authenticating Portal
════════════════════════
𐀪 Author: 0x7ipher
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:11:03 GMT
════════════════════════
⌗ Tags: #vulnerability_disclosure #sql_injection #penetration_testing #web_security #bug_bounty
════════════════════════
𐀪 Author: 0x7ipher
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:11:03 GMT
════════════════════════
⌗ Tags: #vulnerability_disclosure #sql_injection #penetration_testing #web_security #bug_bounty
Medium
From Bug to Schema: Exploring Error-Based SQL Injection on an Authenticating Portal
Case Study Analysis of how I identified an Error-Based SQL Injection vulnerability in a production environment via (VDP).
⤷ Title: HTTP Request Smuggling: The Silent Killer Hiding in Your Proxy Chain
════════════════════════
𐀪 Author: Umair Majeed
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 19:21:25 GMT
════════════════════════
⌗ Tags: #httpsmuggling #hacking #bug_bounty_writeup #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Umair Majeed
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 19:21:25 GMT
════════════════════════
⌗ Tags: #httpsmuggling #hacking #bug_bounty_writeup #cybersecurity #bug_bounty
Medium
HTTP Request Smuggling: The Silent Killer Hiding in Your Proxy Chain
How a decades-old ambiguity in the HTTP specification still lets attackers hijack sessions, poison caches, and bypass security controls.
⤷ Title: Spoofing Super Admins: An IDOR Vulnerability in Enterprise Message Forwarding By Savan Chotaliya
════════════════════════
𐀪 Author: savan-025
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 18:58:52 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #bug_bounty #idor
════════════════════════
𐀪 Author: savan-025
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 18:58:52 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #bug_bounty #idor
Medium
Spoofing Super Admins: An IDOR Vulnerability in Enterprise Message Forwarding By Savan Chotaliya
During a recent bug bounty engagement on a corporate workspace platform, I discovered an Insecure Direct Object Reference (IDOR)…
⤷ Title: Finding Hidden Parameters with Arjun
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 15:33:54 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty_writeup #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 15:33:54 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty_writeup #cybersecurity #bug_bounty
Medium
Finding Hidden Parameters with Arjun
Learn how I use Arjun to discover hidden HTTP parameters and improve my bug bounty reconnaissance with practical examples.
⤷ Title: Bad Reception: how a forgotten JSONP endpoint beat a strict CSP
════════════════════════
𐀪 Author: h0und
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 13:37:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #intigriti #ctf #xs
════════════════════════
𐀪 Author: h0und
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 13:37:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #intigriti #ctf #xs
Medium
Bad Reception: how a forgotten JSONP endpoint beat a strict CSP
Solving Intigriti’s August 2026 XSS challenge by turning a same-origin JSONP endpoint into code execution behind a strict…
⤷ Title: Business Logic Vulnerabilities via Unrestricted GraphQL API Mutations Allow Bypass of Platform…
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 12:28:25 GMT
════════════════════════
⌗ Tags: #computer_science #bug_bounty #security #information_security #cybersecurity
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 12:28:25 GMT
════════════════════════
⌗ Tags: #computer_science #bug_bounty #security #information_security #cybersecurity
Medium
Business Logic Vulnerabilities via Unrestricted GraphQL API Mutations Allow Bypass of Platform Restrictions and Logic
HHello community 👋,I’m Divyank Sitapara, a Bug Bounty Hunter and Application Security Researcher. I hope you’re all doing well. I’m back…
⤷ Title: The Review That Deleted Carlos: What Seven PortSwigger LLM Labs Teach About Trusting the Chat
════════════════════════
𐀪 Author: Jonathan (PardaL)
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 12:01:02 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #prompt_injection_attack #application_security #llm #cybersecurity
════════════════════════
𐀪 Author: Jonathan (PardaL)
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 12:01:02 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #prompt_injection_attack #application_security #llm #cybersecurity
Medium
The Review That Deleted Carlos: What Seven PortSwigger LLM Labs Teach About Trusting the Chat
After mapping the stack with SpyAI, it was time to cross the trust boundary without touching the victim’s session.
⤷ Title: From a Hidden Directory to Admin Account Takeover: A Password Reset Story
════════════════════════
𐀪 Author: Yousfyous
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 10:03:20 GMT
════════════════════════
⌗ Tags: #ethical_hacking #application_security #penetration_testing #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Yousfyous
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 10:03:20 GMT
════════════════════════
⌗ Tags: #ethical_hacking #application_security #penetration_testing #bug_bounty #cybersecurity
Medium
From a Hidden Directory to Admin Account Takeover: A Password Reset Story
Severity: Critical
⤷ Title: Detecting Frida/Xposed at Runtime (Android)
════════════════════════
𐀪 Author: Khizar Khan
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 09:08:45 GMT
════════════════════════
⌗ Tags: #rasp #application_security #android_development #cybersecurity #mobile_security
════════════════════════
𐀪 Author: Khizar Khan
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 09:08:45 GMT
════════════════════════
⌗ Tags: #rasp #application_security #android_development #cybersecurity #mobile_security
Medium
Detecting Frida/Xposed at Runtime (Android)
Part 14, closing out Phase 3 of our Android security series. Part 13 covered R8/ProGuard hardening — static defenses. This post covers the…
⤷ Title: I Audited 300 MCP-Related npm Packages. My Scanner Couldn’t Inspect Runtime Code in 217 .
════════════════════════
𐀪 Author: Abdalhafeez Bushara
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 08:20:08 GMT
════════════════════════
⌗ Tags: #ai_security #software_supply_chain #model_context_protocol #mcp_server #application_security
════════════════════════
𐀪 Author: Abdalhafeez Bushara
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 08:20:08 GMT
════════════════════════
⌗ Tags: #ai_security #software_supply_chain #model_context_protocol #mcp_server #application_security
Medium
I Audited 300 MCP-Related npm Packages. My Scanner Couldn’t Inspect Runtime Code in 217. So I created Driftward
I Audited 300 MCP-Related npm Packages. My Scanner Couldn’t Inspect Runtime Code in 217. So I created Driftward This is not a malware count. It is a warning about security reports that say “zero …
⤷ Title: API Penetration Testing Methodology: A 16-Phase Professional Framework
════════════════════════
𐀪 Author: Mohamed Basil
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 07:24:40 GMT
════════════════════════
⌗ Tags: #api_security #kraxx #ethical_hacking #application_security #cybersecurity
════════════════════════
𐀪 Author: Mohamed Basil
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 07:24:40 GMT
════════════════════════
⌗ Tags: #api_security #kraxx #ethical_hacking #application_security #cybersecurity
Medium
API Penetration Testing Methodology: A 16-Phase Professional Framework
A rigorous API penetration test requires a repeatable, structured methodology.
⤷ Title: DevSecOps — Shifting Security Left in the Software Development Life Cycle
════════════════════════
𐀪 Author: Bahadır Şahin
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 07:20:07 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #sdlc #software_development #cybersecurity
════════════════════════
𐀪 Author: Bahadır Şahin
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 07:20:07 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #sdlc #software_development #cybersecurity
Medium
DevSecOps — Shifting Security Left in the Software Development Life Cycle
As the software development world grows with greater momentum than ever, DevOps processes and CI/CD (Continuous Integration/Continuous…
⤷ Title: curl Me Maybe? ➡️ ⬅️Hacking APIs & Web Apps From the Terminal
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 04:56:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #api_security #bug_bounty_tips #application_security
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 04:56:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #api_security #bug_bounty_tips #application_security
⤷ Title: The OWASP Top 10 2025 is Here: Why Your AppSec Strategy Needs a Reboot
════════════════════════
𐀪 Author: Abdullah Umar Nasib
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 02:22:50 GMT
════════════════════════
⌗ Tags: #security #application_security #owasp_top_10 #quality_assurance
════════════════════════
𐀪 Author: Abdullah Umar Nasib
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 02:22:50 GMT
════════════════════════
⌗ Tags: #security #application_security #owasp_top_10 #quality_assurance
Medium
The OWASP Top 10 2025 is Here: Why Your AppSec Strategy Needs a Reboot
For over two decades, the OWASP Top 10 has been the North Star for application security. But if you look closely at the newly released 2025…
⤷ Title: I Built a DevSecOps Pipeline From Threat Model to Production
════════════════════════
𐀪 Author: Jude Anewuoh
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 19:58:34 GMT
════════════════════════
⌗ Tags: #application_security #secure_coding #devsecops #software_engineering #cybersecurity
════════════════════════
𐀪 Author: Jude Anewuoh
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 19:58:34 GMT
════════════════════════
⌗ Tags: #application_security #secure_coding #devsecops #software_engineering #cybersecurity
Medium
I Built a DevSecOps Pipeline From Threat Model to Production
So I aspire to be an application security engineer and one of the common terms you will ever hear in the industry is shift left.
⤷ Title: I Thought I Found a Critical IDOR. I Was Wrong.
════════════════════════
𐀪 Author: Lh1l0v3
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 19:51:02 GMT
════════════════════════
⌗ Tags: #application_security #software_engineering #bug_bounty #web_development #cybersecurity
════════════════════════
𐀪 Author: Lh1l0v3
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 19:51:02 GMT
════════════════════════
⌗ Tags: #application_security #software_engineering #bug_bounty #web_development #cybersecurity
Medium
I Thought I Found a Critical IDOR. I Was Wrong.
I have been spending more time doing vulnerability research lately, and one of the things I have started doing differently is looking at…
⤷ Title: Understanding WHOIS Lookup: My Visual Cybersecurity Notes
When learning cybersecurity, it’s easy…
════════════════════════
𐀪 Author: saurabh
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 21:29:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bugbounty_writeup #ethical_hacking #hacking
When learning cybersecurity, it’s easy…
════════════════════════
𐀪 Author: saurabh
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 21:29:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bugbounty_writeup #ethical_hacking #hacking
Medium
Understanding WHOIS Lookup: My Visual Cybersecurity Notes When learning cybersecurity, it’s easy…
Understanding WHOIS Lookup: My Visual Cybersecurity Notes When learning cybersecurity, it’s easy to memorize commands without actually understanding what they do. I’m trying to take a different …
⤷ Title: Orion — Hack The Box Write-up
════════════════════════
𐀪 Author: Ishengoma
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 21:02:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #infosec #ethical_hacking #pentesting
════════════════════════
𐀪 Author: Ishengoma
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 21:02:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #infosec #ethical_hacking #pentesting
Medium
Orion — Hack The Box Write-up
Machine Information Orion is a simple Linux machine that focuses on two main vulnerabilities. The initial access is gained through a…
⤷ Title: They talk pensioners through emptying their own bank accounts
════════════════════════
𐀪 Author: CypherNova1337
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:53:02 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #scam #infosec
════════════════════════
𐀪 Author: CypherNova1337
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:53:02 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #scam #infosec
Medium
They talk pensioners through emptying their own bank accounts
I built a free tool that hunts their infrastructure and burns their phone numbers. Here is why hacking them back doesn’t work — and why…
⤷ Title: 700 AI Agents Hacked Hugging Face. The Part That Should Scare You Isn’t the Hack.
════════════════════════
𐀪 Author: Leandro Calado
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:52:35 GMT
════════════════════════
⌗ Tags: #hugging_face #ai_hallucination #automous_agents #ai_agent #hacking
════════════════════════
𐀪 Author: Leandro Calado
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 20:52:35 GMT
════════════════════════
⌗ Tags: #hugging_face #ai_hallucination #automous_agents #ai_agent #hacking
Medium
700 AI Agents Hacked Hugging Face. The Part That Should Scare You Isn’t the Hack.
They found one another, built an unauthorized coordination channel, divided the work, and tried to manipulate the record. The age of the…