⤷ Title: A Fast Recon Workflow for Spotting XSS Candidates
════════════════════════
𐀪 Author: MD Fahad Hosen
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 11:35:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cross_site_scripting
════════════════════════
𐀪 Author: MD Fahad Hosen
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 11:35:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cross_site_scripting
Medium
A Fast Recon Workflow for Spotting XSS Candidates
A practical pipeline for narrowing thousands of URLs down to the handful worth manually testing for Cross-Site Scripting.
⤷ Title: Web Encoding for Beginners: URL, HTML, Unicode, Base64 & Hex
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:45:45 GMT
════════════════════════
⌗ Tags: #hacking #web_development #bug_bounty #hacker #cybersecurity
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:45:45 GMT
════════════════════════
⌗ Tags: #hacking #web_development #bug_bounty #hacker #cybersecurity
Medium
Encoding in Web Applications
Learn web encoding with practical examples of URL, HTML, Unicode, UTF-8,Base64, Hex, and serialization for web security
⤷ Title: Microsoft Bounty Hunt: From Contacts to Invoices via Guest User Misconfigurations
════════════════════════
𐀪 Author: Mustafa Mohamed (d3sca)
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:16:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #react #infosec #salesforce #cybersecurity
════════════════════════
𐀪 Author: Mustafa Mohamed (d3sca)
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:16:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #react #infosec #salesforce #cybersecurity
Medium
Microsoft Bounty Hunt: From Contacts to Invoices via Guest User Misconfigurations
Introduction
⤷ Title: Critical Exposure Of Algolia Key That Led to Production, Staging, and Draft Data
════════════════════════
𐀪 Author: Adham Mohamed
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:09:43 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Adham Mohamed
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:09:43 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty
Medium
Critical Exposure Of Algolia Key That Led to Production, Staging, and Draft Data
While testing a public bug bounty program, I came across an interesting file:
⤷ Title: OAuth 2.0 Vulnerability Hunting: A Pentester’s Field Guide
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:57:41 GMT
════════════════════════
⌗ Tags: #oauth #cybersecurity #application_security #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:57:41 GMT
════════════════════════
⌗ Tags: #oauth #cybersecurity #application_security #penetration_testing #bug_bounty
Medium
OAuth 2.0 Vulnerability Hunting: A Pentester’s Field Guide
OAuth 2.0 is everywhere — “Login with Google,” “Login with Microsoft,” third-party API integrations. It’s an authorization framework, not…
⤷ Title: How a Forgotten “Export to Excel” Feature Exfiltrated a Bank’s Database for $5,000
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #bug_bounty_writeup
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #bug_bounty_writeup
Medium
How a Forgotten “Export to Excel” Feature Exfiltrated a Bank’s Database for $5,000
If there is a golden rule in bug bounty hunting, it’s this: The most secure platforms in the world almost always leave their back door…
⤷ Title: SS7, STUN & VoIP Explained | How P2P IP Address Discovery Works
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:14:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #bug_bounty #web_development #ss7
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:14:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #bug_bounty #web_development #ss7
Medium
🔥 SS7, STUN & VoIP Explained | How P2P IP Address Discovery Works
Modern communication systems rely on several layers of networking technology that most users never see.
⤷ Title: Decoding a URL: Paths, Parameters, and the Art of Finding What’s Hidden
════════════════════════
𐀪 Author: Shruti Vijay Shinde
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 14:54:16 GMT
════════════════════════
⌗ Tags: #vapt #cybersecurity #bug_bounty #penetration_testing #bug_hunting
════════════════════════
𐀪 Author: Shruti Vijay Shinde
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 14:54:16 GMT
════════════════════════
⌗ Tags: #vapt #cybersecurity #bug_bounty #penetration_testing #bug_hunting
Medium
Decoding a URL: Paths, Parameters, and the Art of Finding What’s Hidden
If you’re getting into bug bounty hunting or web security, the URL is where everything starts. Most people glance past it. But a URL is…
⤷ Title: subfaster Review: The Subfinder Fork Built for Faster Bug Bounty Recon
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 17:29:57 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #bug_bounty #cybersecurity #osint
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 17:29:57 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #bug_bounty #cybersecurity #osint
Medium
subfaster Review: The Subfinder Fork Built for Faster Bug Bounty Recon
Most bug bounty hunters are still running subdomain recon the slow way — and it’s costing them time on every single scan.
⤷ Title: I Read the Top 20 IDOR Reports on HackerOne.
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 19:01:41 GMT
════════════════════════
⌗ Tags: #infosec #hacking #idor #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 19:01:41 GMT
════════════════════════
⌗ Tags: #infosec #hacking #idor #bug_bounty_tips #bug_bounty
Medium
I Read the Top 20 IDOR Reports on HackerOne. Nearly Half of Them Delete Data Instead of Stealing It.
30-second version: I pulled the 20 highest-upvoted IDOR reports on HackerOne. Three are no longer publicly readable, so the dataset is 17…