⤷ Title: The GraphQL Loophole Hiding in Airline Booking Systems
════════════════════════
𐀪 Author: Luciano Paccella
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:51:03 GMT
════════════════════════
⌗ Tags: #aviation #graphql #bug_bounty #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Luciano Paccella
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:51:03 GMT
════════════════════════
⌗ Tags: #aviation #graphql #bug_bounty #ethical_hacking #cybersecurity
Medium
The GraphQL Loophole Hiding in Airline Booking Systems
An anonymized case study of alias-based query batching, response oracles, and why request-level rate limits may not measure the real work.
⤷ Title: DOM Clobbering: Turning Plain HTML Into JavaScript Variables
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #cybersecurity #infosec #hacking
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #cybersecurity #infosec #hacking
Medium
DOM Clobbering: Turning Plain HTML Into JavaScript Variables
Sanitizers strip event handlers and keep id and name. Those two attributes are enough to overwrite the page’s own variables.
⤷ Title: From Dead SQLi To Live Session Hijack.
════════════════════════
𐀪 Author: Darshan Narayan
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:25:13 GMT
════════════════════════
⌗ Tags: #application_security #web_security #infosec #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Darshan Narayan
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:25:13 GMT
════════════════════════
⌗ Tags: #application_security #web_security #infosec #bug_bounty #cybersecurity
Medium
From Dead SQLi To Live Session Hijack.
Introduction:
⤷ Title: 15 Cybersecurity Resume Mistakes That Get Candidates Ignored: Master the Art of Standing Out
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:10:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #penetration_testing #hacking #ethical_hacking
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:10:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #penetration_testing #hacking #ethical_hacking
⤷ Title: HTB — Beep — OSCP Practice Lab
════════════════════════
𐀪 Author: CYBER_delta
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:52:22 GMT
════════════════════════
⌗ Tags: #linux #hacking #cybersecurity #pentesting #htb
════════════════════════
𐀪 Author: CYBER_delta
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:52:22 GMT
════════════════════════
⌗ Tags: #linux #hacking #cybersecurity #pentesting #htb
Medium
HTB — Beep — OSCP Practice Lab
TLS/SSL enumeration → Recon → LFI → Credential Reuse → Shellshock → Privilege Escalation → Root
⤷ Title: What Are C2 Frameworks?
════════════════════════
𐀪 Author: InfosecTrain
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:48:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #c2_framework
════════════════════════
𐀪 Author: InfosecTrain
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 11:48:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #c2_framework
Medium
What Are C2 Frameworks?
In cybersecurity, attackers rarely “hack once and leave.” After gaining access to a system, they often need a way to stay connected, issue…
⤷ Title: The home lab mistakes that waste your first six months
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:06:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #laboratory #security #infosec
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:06:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #laboratory #security #infosec
Medium
The home lab mistakes that waste your first six months
You don’t need more tutorials. You need to stop doing these things.
⤷ Title: Learn Cross Site Scripting (XSS) With Me as a Beginner
════════════════════════
𐀪 Author: Jessica Shrestha
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:14:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_attack #cross_site_scripting #beginners_guide #xs
════════════════════════
𐀪 Author: Jessica Shrestha
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 10:14:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_attack #cross_site_scripting #beginners_guide #xs
Medium
Learn Cross Site Scripting (XSS) With Me as a Beginner
Let’s start from learning what XSS actually is, its type such as reflected, stored, DOM based, mutated XSS….wait wait wait what was that?
⤷ Title: Your Critical Vulnerabilities Might Not Be Your Biggest Risk
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:00:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:00:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Massive Data Leak Exposes Vietnam Aviation Records
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:13:14 +0000
════════════════════════
⌗ Tags: #Data Leak #Aviation Security #data leak #Elasticsearch #Vietnam
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:13:14 +0000
════════════════════════
⌗ Tags: #Data Leak #Aviation Security #data leak #Elasticsearch #Vietnam
Information Security News
Massive Data Leak Exposes Vietnam Aviation Records
One of the most sensitive aviation databases proved to be guarded less securely than a rudimentary web service. On June 3, Kinryū Labs uncovered a staggering 220,783,700 records concerning passeng…
⤷ Title: Passkey Phishing Attacks Compromise Microsoft Identity Cloud
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:11:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Microsoft #Passkey #phishing #Social Engineering
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:11:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Microsoft #Passkey #phishing #Social Engineering
Information Security News
Passkey Phishing Attacks Compromise Microsoft Identity Cloud
Passkeys were originally conceived as the ultimate cure for phishing, yet threat actors have ingeniously discovered a darker role for this technology. Currently, an attacker merely needs to teleph…
⤷ Title: CVE-2026-89049 (CVSS 9.9): AWS SSM Agent SSRF Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:55:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS SSM Agent #AWS Systems Manager #CVE_2026_89049 #Server_Side Request Forgery #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:55:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS SSM Agent #AWS Systems Manager #CVE_2026_89049 #Server_Side Request Forgery #Vulnerability
Daily CyberSecurity
CVE-2026-89049 (CVSS 9.9): AWS SSM Agent SSRF Flaw
Amazon released a security update addressing a critical server-side request forgery vulnerability in the AWS Systems Manager Agent. This severe security flaw, tracked as CVE-2026-89049, allows aut…
⤷ Title: CVE-2026-89094 Forgejo Remote Code Execution Hits CVSS 9.9
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:07:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_89094 #Forgejo #git #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:07:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_89094 #Forgejo #git #Remote Code Execution #Vulnerability
Daily CyberSecurity
CVE-2026-89094 Forgejo Remote Code Execution Hits CVSS 9.9
Forgejo developers released version 16.0.4 on September 11, 2026, to address a critical flaw. This severe bug enables a Forgejo remote code execution attack through malicious template repositories…
⤷ Title: Breaking Semantica: From Unchecked Graph Imports to Stored Header Injection & Memory DoS
════════════════════════
𐀪 Author: Sunil
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:29:13 GMT
════════════════════════
⌗ Tags: #web_security #appsec #artificial_intelligence #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Sunil
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:29:13 GMT
════════════════════════
⌗ Tags: #web_security #appsec #artificial_intelligence #cybersecurity #bug_bounty
Medium
Breaking Semantica: From Unchecked Graph Imports to Stored Header Injection & Memory DoS
Modern AI & Graph systems often focus heavily on model logic while standard web security slip-throughs create devastating attack surfaces.
⤷ Title: From N/A to $$$: How a 4-Month Dead Report Became My First Bug Bounty Win
════════════════════════
𐀪 Author: Brian Bange
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:00:02 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #web_security #web_app_pentesting #hacking #bug_bounty
════════════════════════
𐀪 Author: Brian Bange
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:00:02 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #web_security #web_app_pentesting #hacking #bug_bounty
Medium
From N/A to 💰$$$: How a 4-Month Dead Report Became My First Bug Bounty Win
If you’re grinding your first year in bug bounty, you know the feeling. You spend hours hunting, finally submit what looks like a great…
⤷ Title: Why I Chose Cybersecurity: Learning to Think Like an Attacker
════════════════════════
𐀪 Author: Oltionshumolli
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:13:50 GMT
════════════════════════
⌗ Tags: #hacking #information_security #programming #technology #cybersecurity
════════════════════════
𐀪 Author: Oltionshumolli
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:13:50 GMT
════════════════════════
⌗ Tags: #hacking #information_security #programming #technology #cybersecurity
Medium
Why I Chose Cybersecurity: Learning to Think Like an Attacker
From curiosity about technology to discovering a field that changed the way I see computers, networks, and the internet.
⤷ Title: Wireshark: The Basics
════════════════════════
𐀪 Author: Himanshu
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:46:26 GMT
════════════════════════
⌗ Tags: #security #wireshark #cybersecurity #tools #hacking
════════════════════════
𐀪 Author: Himanshu
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:46:26 GMT
════════════════════════
⌗ Tags: #security #wireshark #cybersecurity #tools #hacking
Medium
Wireshark: The Basics
Task 1 : Introduction
⤷ Title: Post-Quantum Readiness Starts With an Inventory: How to Build a CBOM in 2026
════════════════════════
𐀪 Author: Rimlauf
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:03:16 GMT
════════════════════════
⌗ Tags: #cryptography #security #compliance #infosec #post_quantum
════════════════════════
𐀪 Author: Rimlauf
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:03:16 GMT
════════════════════════
⌗ Tags: #cryptography #security #compliance #infosec #post_quantum
Medium
Post-Quantum Readiness Starts With an Inventory: How to Build a CBOM in 2026
The first task in preparing for post-quantum cryptography is not swapping out algorithms. It is finding out what is already in place, where…
⤷ Title: Your Security Key Doesn’t Work If Your Microsoft 365 Account Still Accepts a Text
════════════════════════
𐀪 Author: S6 Tech
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:01:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #ransomware #cyber_security_awareness #infosec #small_business
════════════════════════
𐀪 Author: S6 Tech
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 13:01:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #ransomware #cyber_security_awareness #infosec #small_business
Medium
Your Security Key Doesn’t Work If Your Microsoft 365 Account Still Accepts a Text
A rented phishing service beat MFA at 258 organizations by switching hardware keys off inside the browser and letting the login drop back…
⤷ Title: Perché l’analisi dei log di Windows è il superpotere di ogni SOC Analyst
════════════════════════
𐀪 Author: Porcu Marcooo
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:49:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #soc_analyst #tryhackme #windows
════════════════════════
𐀪 Author: Porcu Marcooo
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:49:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #soc_analyst #tryhackme #windows
⤷ Title: NMAP: The Basics
════════════════════════
𐀪 Author: Kamatchibalu
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:43:00 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_pre_security #tryhackme #tryhackme_nmap #tryhackme_writeup
════════════════════════
𐀪 Author: Kamatchibalu
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 12:43:00 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_pre_security #tryhackme #tryhackme_nmap #tryhackme_writeup
Medium
NMAP: The Basics
When we are connected to a network and using various network resources, such as email and web browsing. Two questions arise. The first is…