⤷ Title: How a Simple GraphQL Scope Bypass Led to an Account Takeover ($4,500 Bounty)
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 13:41:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #bug_bounty #hacking #bug_bounty_writeup
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 13:41:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #bug_bounty #hacking #bug_bounty_writeup
Medium
How a Simple GraphQL Scope Bypass Led to an Account Takeover ($4,500 Bounty)
Discover how analyzing GraphQL schema mutations and nested query parameters revealed a critical access control failure on a major target.
⤷ Title: I Called Myself “Admin” and the Site Let Me
════════════════════════
𐀪 Author: Hunter0x0
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 07:13:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: Hunter0x0
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 07:13:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips
Medium
I Called Myself “Admin” and the Site Let Me
I was hunting on a platform and signed up for a test account. Everything normal email, password, then pick a username.
⤷ Title: How to Start Bug Bounty Hunting in 2026: A Complete Beginner’s Guide
════════════════════════
𐀪 Author: ATNO For Cybersecurity | Hacking
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 23:41:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #cybersecurity #bug_bounty_writeup
════════════════════════
𐀪 Author: ATNO For Cybersecurity | Hacking
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 23:41:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #cybersecurity #bug_bounty_writeup
Medium
How to Start Bug Bounty Hunting in 2026: A Complete Beginner’s Guide 🐛💰
What Bug Bounty Hunting Actually Is 🎯
⤷ Title: ₹4,000 for a 2-Minute Google Search: Publicly Exposed Invoice Leaking Customer PII
════════════════════════
𐀪 Author: WhoAdnan
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 06:41:32 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_hunter #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: WhoAdnan
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 06:41:32 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_hunter #bug_bounty_tips #bug_bounty
Medium
💸 ₹4,000 for a 2-Minute Google Search: Publicly Exposed Invoice Leaking Customer PII
Introduction
⤷ Title: alg:none and Friends — A JWT Hacking Field Guide
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sat, 29 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty_writeup #infosec #bug_bounty
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sat, 29 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty_writeup #infosec #bug_bounty
Medium
alg:none and Friends — A JWT Hacking Field Guide
What’s up everyone! Nitin here 👋
⤷ Title: The Subdomain Recon Chain: subfinder → httpx → dnsx
════════════════════════
𐀪 Author: Muneebahmedkhan
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 15:25:58 GMT
════════════════════════
⌗ Tags: #tutorial #recon #bug_bounty #cybersecurity #infosec
════════════════════════
𐀪 Author: Muneebahmedkhan
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 15:25:58 GMT
════════════════════════
⌗ Tags: #tutorial #recon #bug_bounty #cybersecurity #infosec
Medium
The Subdomain Recon Chain: subfinder → httpx → dnsx
Turn a root domain into a short list of live hosts worth testing. subfinder finds candidate hosts, httpx keeps the ones answering on HTTP…
⤷ Title: Managing Scan Results in Metasploit
════════════════════════
𐀪 Author: Ryan Ryan
════════════════════════
ⴵ Time: Fri, 21 Aug 2026 10:55:32 GMT
════════════════════════
⌗ Tags: #pentesting #penetration_testing #recon #red_team #metasploit
════════════════════════
𐀪 Author: Ryan Ryan
════════════════════════
ⴵ Time: Fri, 21 Aug 2026 10:55:32 GMT
════════════════════════
⌗ Tags: #pentesting #penetration_testing #recon #red_team #metasploit
Medium
Managing Scan Results in Metasploit
In this post, let’s go through managing scan results using Metasploit’s database. Covering everything from setup, workspaces, importing…
⤷ Title: The Interceptor That Fetched Anything: 1-Click Native Takeover in a Capacitor App
════════════════════════
𐀪 Author: Hussein Ayoub
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 07:24:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #android #security
════════════════════════
𐀪 Author: Hussein Ayoub
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 07:24:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #android #security
Medium
The Interceptor That Fetched Anything: 1-Click Native Takeover in a Capacitor App
On hybrid apps, the bugs usually live in the gap between two features that are both fine by themselves: a WebView serving the app’s own…
⤷ Title: Web Cache Poisoning: One Response, Every Victim
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Wed, 26 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bugbounty_writeup #bug_bounty #hacking #infosec
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Wed, 26 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bugbounty_writeup #bug_bounty #hacking #infosec
Medium
Web Cache Poisoning: One Response, Every Victim
What’s up everyone! Nitin here 👋
⤷ Title: Finding Sensitive Backend Information Through GraphQL Errors
════════════════════════
𐀪 Author: Ananya Rathod
════════════════════════
ⴵ Time: Tue, 25 Aug 2026 19:22:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #graphql #bugbounty_writeup #bug_bounty_writeup
════════════════════════
𐀪 Author: Ananya Rathod
════════════════════════
ⴵ Time: Tue, 25 Aug 2026 19:22:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #graphql #bugbounty_writeup #bug_bounty_writeup
Medium
Finding Sensitive Backend Information Through GraphQL Errors
While testing a web application, I was looking at its GraphQL endpoint and started checking how it handled invalid queries.
⤷ Title: Power Cookie — picoCTF Writeup
════════════════════════
𐀪 Author: mayhack
════════════════════════
ⴵ Time: Mon, 24 Aug 2026 14:21:54 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bugbounty_writeup #ctf_writeup
════════════════════════
𐀪 Author: mayhack
════════════════════════
ⴵ Time: Mon, 24 Aug 2026 14:21:54 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bugbounty_writeup #ctf_writeup
Medium
Power Cookie — picoCTF Writeup
Challenge Description
⤷ Title: You Can’t Become a Great Bug Bounty Hunter Without Understanding Networking
════════════════════════
𐀪 Author: SAYEM-EH
════════════════════════
ⴵ Time: Sun, 23 Aug 2026 15:08:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bugbounty_writeup #bug_hunting #networking
════════════════════════
𐀪 Author: SAYEM-EH
════════════════════════
ⴵ Time: Sun, 23 Aug 2026 15:08:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bugbounty_writeup #bug_hunting #networking
Medium
You Can’t Become a Great Bug Bounty Hunter Without Understanding Networking
Introduction
⤷ Title: API Security: The Vulnerabilities Most Developers Miss
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Fri, 21 Aug 2026 17:46:04 GMT
════════════════════════
⌗ Tags: #api_development #bugbounty_writeup #cybersecurity
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Fri, 21 Aug 2026 17:46:04 GMT
════════════════════════
⌗ Tags: #api_development #bugbounty_writeup #cybersecurity
Medium
API Security: The Vulnerabilities Most Developers Miss
APIs have become the backbone of modern applications. Mobile apps, single-page applications, SaaS platforms, payment systems, cloud…
⤷ Title: Termux + NetHunter on Android: Complete Guide + $7,500 SQLi Bug Bounty Story
════════════════════════
𐀪 Author: Bearded Viking
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 23:59:53 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_penetration_testing #hacking #bug_bounty_tips
════════════════════════
𐀪 Author: Bearded Viking
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 23:59:53 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_penetration_testing #hacking #bug_bounty_tips
Medium
Termux + NetHunter on Android: Complete Guide + $7,500 SQLi Bug Bounty Story
Termux… What?
⤷ Title: How an Unsanitized EXIF Metadata Parser Led to Command Injection and a $10,000 Bounty
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 13:36:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #cybersecurity #security #hacking
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 13:36:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #cybersecurity #security #hacking
Medium
How an Unsanitized EXIF Metadata Parser Led to Command Injection and a $10,000 Bounty
When building media-heavy web applications, developers frequently rely on background image processing utilities (such as ImageMagick…
⤷ Title: 15 Hidden Nmap Techniques Every Hacker Should Know
════════════════════════
𐀪 Author: Bugitrix
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 02:56:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #tools #nmap #bug_bounty_tips
════════════════════════
𐀪 Author: Bugitrix
════════════════════════
ⴵ Time: Sun, 30 Aug 2026 02:56:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #tools #nmap #bug_bounty_tips
Medium
15 Hidden Nmap Techniques Every Hacker Should Know
Nmap Isn’t Just a Scanner — It’s a Mindset
⤷ Title: One parameter & Two IDORs
════════════════════════
𐀪 Author: Omer Mohsen
════════════════════════
ⴵ Time: Sat, 29 Aug 2026 14:45:29 GMT
════════════════════════
⌗ Tags: #bug_bounty #idor #bug_bounty_tips #cybersecurity #vulnerability
════════════════════════
𐀪 Author: Omer Mohsen
════════════════════════
ⴵ Time: Sat, 29 Aug 2026 14:45:29 GMT
════════════════════════
⌗ Tags: #bug_bounty #idor #bug_bounty_tips #cybersecurity #vulnerability
Medium
One parameter & Two IDORs
بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلم
⤷ Title: How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 29 Aug 2026 13:31:01 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #cybersecurity #bug_bounty_tips #pentesting
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 29 Aug 2026 13:31:01 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #cybersecurity #bug_bounty_tips #pentesting
Medium
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…
⤷ Title: You Can Have Two Factor Authentication and Still Get Hacked
════════════════════════
𐀪 Author: Chandana
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 22:19:08 GMT
════════════════════════
⌗ Tags: #privacy #hacking #artificial_intelligence #technology #cybersecurity
════════════════════════
𐀪 Author: Chandana
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 22:19:08 GMT
════════════════════════
⌗ Tags: #privacy #hacking #artificial_intelligence #technology #cybersecurity
Medium
You Can Have Two Factor Authentication and Still Get Hacked
You do not always need to lose your password to lose your account. Here is how stolen browser sessions can give attackers a way in and how…
⤷ Title: HacktheBox Linux Fundamentals: Working with Files and Directories
════════════════════════
𐀪 Author: Sudo Make Me a Hacker | By Isioma
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 22:23:15 GMT
════════════════════════
⌗ Tags: #linux_tutorial #hackthebox_writeup #hackthebox_walkthrough #linux #hackthebox
════════════════════════
𐀪 Author: Sudo Make Me a Hacker | By Isioma
════════════════════════
ⴵ Time: Tue, 01 Sep 2026 22:23:15 GMT
════════════════════════
⌗ Tags: #linux_tutorial #hackthebox_writeup #hackthebox_walkthrough #linux #hackthebox
Medium
HacktheBox Linux Fundamentals: Working with Files and Directories
Linux Commands Explored in this Lesson:
⤷ Title: Why I Built a Deterministic CPG-to-Nuclei Compiler in Rust
════════════════════════
𐀪 Author: Tarek Mhiri/ spicesformind.com
════════════════════════
ⴵ Time: Wed, 02 Sep 2026 01:18:00 GMT
════════════════════════
⌗ Tags: #appsec #software_engineering #rust #cybersecurity #application_security
════════════════════════
𐀪 Author: Tarek Mhiri/ spicesformind.com
════════════════════════
ⴵ Time: Wed, 02 Sep 2026 01:18:00 GMT
════════════════════════
⌗ Tags: #appsec #software_engineering #rust #cybersecurity #application_security
Medium
Why I Built a Deterministic CPG-to-Nuclei Compiler in Rust
My background is in mechanical engineering. When I transitioned into cybersecurity, I brought a physical mindset with me: a system only…