⤷ Title: The Hacker Didn’t Hack the Website. They Tricked the Cache.
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:22:35 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:22:35 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking
Medium
The Hacker Didn’t Hack the Website. They Tricked the Cache.
A strange web attack where the attacker doesn’t break the application. They convince the cache to store something it shouldn’t.
⤷ Title: VulnHub: Mr. Robot — Full Walkthrough
════════════════════════
𐀪 Author: Ahmed Osman
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:21:37 GMT
════════════════════════
⌗ Tags: #penetration_testing #mr_robot #cybersecurity #vulnhub #ethical_hacking
════════════════════════
𐀪 Author: Ahmed Osman
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:21:37 GMT
════════════════════════
⌗ Tags: #penetration_testing #mr_robot #cybersecurity #vulnhub #ethical_hacking
Medium
Vulnhub: Mr.Robot — Writeup
A practical VulnHub Mr. Robot walkthrough covering reconnaissanc,web enumeration,WordPress authentication,Linux privilege escalation
⤷ Title: TargetVeil: A Local-First Pentest Data Sanitizer for Safer AI-Assisted Security Work
════════════════════════
𐀪 Author: Ilias Georgopoulos
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:08:05 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #penetration_testing #open_source #privacy #cybersecurity
════════════════════════
𐀪 Author: Ilias Georgopoulos
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:08:05 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #penetration_testing #open_source #privacy #cybersecurity
Medium
TargetVeil: A Local-First Pentest Data Sanitizer for Safer AI-Assisted Security Work
Redact PII, client infrastructure, credentials, and engagement identifiers before sharing penetration-testing evidence with public AI tools
⤷ Title: I Found 500 Subdomains. Then I Realized I Hadn’t Found the Attack Surface Yet
════════════════════════
𐀪 Author: Fateyaly
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #ethical_hacking #coding #cybersecurity #programming #technology
════════════════════════
𐀪 Author: Fateyaly
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #ethical_hacking #coding #cybersecurity #programming #technology
Medium
I Found 500 Subdomains. Then I Realized I Hadn’t Found the Attack Surface Yet
Why a giant subdomain list means almost nothing until DNS, ports, TLS, and HTTP tell you what’s actually alive
⤷ Title: How I stumbled into my first “AI-powered” bug bounty target and found that an AI chatbot’s memory…
════════════════════════
𐀪 Author: GAURAV RN
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:19:05 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #ai_chatbot_security #ai_security
════════════════════════
𐀪 Author: GAURAV RN
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:19:05 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #ai_chatbot_security #ai_security
Medium
How I stumbled into my first “AI-powered” bug bounty target and found that an AI chatbot’s memory had no lock on it 🤷
For years, my bug bounty muscle memory looked the same: pick a web app, poke the API, look for the usual suspects — broken auth, XXS …
⤷ Title: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 22:00:18 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 22:00:18 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 21:45:29 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 21:45:29 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: One Parameter. One Script Tag. One CVE.
════════════════════════
𐀪 Author: Mohammed ElKhateb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:53:24 GMT
════════════════════════
⌗ Tags: #xs #red_team #bug_bounty #cybersecurity #web_security
════════════════════════
𐀪 Author: Mohammed ElKhateb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:53:24 GMT
════════════════════════
⌗ Tags: #xs #red_team #bug_bounty #cybersecurity #web_security
Medium
🔐 One Parameter. One Script Tag. One CVE.
> 🧠 TL;DR — I found a reflected XSS in TechStore v1.0. One GET parameter, `id`, gets dropped straight into the page with no encoding and…
⤷ Title: One .svg and a CDN: How a File Extension Leaked Strangers' PII
════════════════════════
𐀪 Author: Abhinabshrestha
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:20:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web_cache_deception #bug_bounty_writeup
════════════════════════
𐀪 Author: Abhinabshrestha
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:20:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web_cache_deception #bug_bounty_writeup
Medium
One .svg and a CDN: How a File Extension Leaked Strangers' PII
A walkthrough of a Web Cache Deception bug that turned a private profile API into a public one — and the story of how it got closed as a…
⤷ Title: Dari Activity Log ke Pelanggaran Privasi: Mengeksploitasi Broken Object Level Authorization
════════════════════════
𐀪 Author: 0xHunter
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:09:38 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #application_security #penetration_testing
════════════════════════
𐀪 Author: 0xHunter
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:09:38 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #application_security #penetration_testing
Medium
Dari Activity Log ke Pelanggaran Privasi: Mengeksploitasi Broken Object Level Authorization
Riwayat aktivitas akun merupakan komponen kritis dalam arsitektur keamanan aplikasi modern. Fitur ini dirancang untuk memberikan…
⤷ Title: OSAI (AI-300) and the Future of Pentesting
════════════════════════
𐀪 Author: Raad Haddad
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:02:48 GMT
════════════════════════
⌗ Tags: #security #hacking #osai #red_team #ai
════════════════════════
𐀪 Author: Raad Haddad
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:02:48 GMT
════════════════════════
⌗ Tags: #security #hacking #osai #red_team #ai
Medium
OSAI (AI-300) and the Future of Pentesting
I recently completed the OSAI certification, and for me, this was one of those certifications that immediately felt relevant to where…
⤷ Title: How I Found an Account Takeover Hiding in a ‘Scan to Upload’ Button
════════════════════════
𐀪 Author: chiheb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:27:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
════════════════════════
𐀪 Author: chiheb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:27:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
Medium
How I Found an Account Takeover Hiding in a ‘Scan to Upload’ Button
Program name, domain, and a few other identifying details in this writeup have been redacted at my request — the rest is exactly how it…
⤷ Title: thisisunsafe: o “atalho” escondido do Chrome que todo profissional de segurança deveria conhecer
════════════════════════
𐀪 Author: 3SC0133
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:20:53 GMT
════════════════════════
⌗ Tags: #information_security #bug_bounty #web_security #cybersecurity_news #penetration_testing
════════════════════════
𐀪 Author: 3SC0133
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:20:53 GMT
════════════════════════
⌗ Tags: #information_security #bug_bounty #web_security #cybersecurity_news #penetration_testing
⤷ Title: A WebSocket, a Shell, and a Critical CVE: Discovering CVE-2026–39987
════════════════════════
𐀪 Author: julichaan
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:32:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #vulnerability #hackthebox
════════════════════════
𐀪 Author: julichaan
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:32:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #vulnerability #hackthebox
Medium
A WebSocket, a Shell, and a Critical CVE: Discovering CVE-2026–39987
There are vulnerabilities that require chaining multiple weaknesses, bypassing filters, and spending hours building an exploitation path.
⤷ Title: Ataques a DNS: Zone Transfer, Subdomain Takeover y DNS Cache Poisoning | HTB Academy
════════════════════════
𐀪 Author: Matías González
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:46:36 GMT
════════════════════════
⌗ Tags: #writeup #dns #ethical_hacking #hacking #hackthebox
════════════════════════
𐀪 Author: Matías González
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:46:36 GMT
════════════════════════
⌗ Tags: #writeup #dns #ethical_hacking #hacking #hackthebox
Medium
Ataques a DNS: Zone Transfer, Subdomain Takeover y DNS Cache Poisoning | HTB Academy
¿Qué es el DNS?
⤷ Title: Windows Fundamentals Skills Assessment
════════════════════════
𐀪 Author: Matías González
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:24:04 GMT
════════════════════════
⌗ Tags: #hackthebox #writeup #hacking #hack_the_box_writeup #ethical_hacking
════════════════════════
𐀪 Author: Matías González
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:24:04 GMT
════════════════════════
⌗ Tags: #hackthebox #writeup #hacking #hack_the_box_writeup #ethical_hacking
Medium
Windows Fundamentals Skills Assessment
Introducción
⤷ Title: From Zero Context to Alert Triage: My TryHackMe SOC Level 1 Journey
════════════════════════
𐀪 Author: Johnpaul Ehiemere
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:34:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #information_security #tryhackme
════════════════════════
𐀪 Author: Johnpaul Ehiemere
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:34:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #information_security #tryhackme
Medium
From Zero Context to Alert Triage: My TryHackMe SOC Level 1 Journey
A breakdown of what I actually learned, built, and got wrong on the way to becoming SOC-ready — with the receipts to prove it.
⤷ Title: Agent Sudo — TryHackMe
════════════════════════
𐀪 Author: SSecNotes
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:25:52 GMT
════════════════════════
⌗ Tags: #agent_sudo_walkthrough #agent_sudo #bug_bounty_writeup #agent_sudo_thm #tryhackme
════════════════════════
𐀪 Author: SSecNotes
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:25:52 GMT
════════════════════════
⌗ Tags: #agent_sudo_walkthrough #agent_sudo #bug_bounty_writeup #agent_sudo_thm #tryhackme
Medium
Agent Sudo — TryHackMe
Room Link: https://tryhackme.com/room/agentsudoctf
⤷ Title: Network Traffic Analysis: Infection at the Japanese Office
════════════════════════
𐀪 Author: Rama
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:02:43 GMT
════════════════════════
⌗ Tags: #information_security #technology #cybersecurity #ethical_hacking #networking
════════════════════════
𐀪 Author: Rama
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:02:43 GMT
════════════════════════
⌗ Tags: #information_security #technology #cybersecurity #ethical_hacking #networking
Medium
Network Traffic Analysis: Infection at the Japanese Office
This is a walkthrough of the Malware-Traffic-Analysis.net exercise “Infection at the Japan Field Office” (2017–06–28). The exercise —…
⤷ Title: Second-Order SQL Injection: The Payload That Waits
════════════════════════
𐀪 Author: OopsSec Store
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:01:01 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #sql_injection #programming #ethical_hacking
════════════════════════
𐀪 Author: OopsSec Store
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:01:01 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #sql_injection #programming #ethical_hacking
Medium
Second-Order SQL Injection: The Payload That Waits
Your review sits quietly in the database until an admin clicks the wrong filter
⤷ Title: Remote Android Access & Wireless ADB Security Lab
════════════════════════
𐀪 Author: SIAM AHMED
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:37:49 GMT
════════════════════════
⌗ Tags: #adb #ethical_hacking #learning #cybersecurity #remote_access
════════════════════════
𐀪 Author: SIAM AHMED
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:37:49 GMT
════════════════════════
⌗ Tags: #adb #ethical_hacking #learning #cybersecurity #remote_access
Medium
🔐 Remote Android Access & Wireless ADB Security Lab
Introduction