⤷ Title: How I Earned a $300 Bug Bounty by Finding an Authorization Bypass in a Private Program
════════════════════════
𐀪 Author: ameensec
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 06:19:51 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bugbounty_writeup
════════════════════════
𐀪 Author: ameensec
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 06:19:51 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bugbounty_writeup
Medium
How I Earned a $300 Bug Bounty by Finding an Authorization Bypass in a Private Program
Authorization vulnerabilities are often overlooked because they don’t always involve complex exploits. Sometimes, a single…
⤷ Title: How a Simple Profile Setting Revealed Sensitive Credentials in a Bug Bounty Program
════════════════════════
𐀪 Author: Mazen Rady
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 08:09:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #information_disclosure #web_penetration_testing #bugbounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Mazen Rady
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 08:09:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #information_disclosure #web_penetration_testing #bugbounty_writeup #bug_bounty
Medium
How a Simple Profile Setting Revealed Sensitive Credentials in a Bug Bounty Program
.اللهم انفعنا بما علَّمتنا، وعلِّمنا ما ينفعنا، وزِدنا علمًا وفقهًا وفهمًا يا رب العالمين
⤷ Title: How a Simple Google Dork Led Me to Find Reflected XSS & HTML Injection on NASA and Earn a Letter of…
════════════════════════
𐀪 Author: ItsS4LEH
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 15:07:34 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_tips #bug_bounty_writeup #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: ItsS4LEH
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 15:07:34 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_tips #bug_bounty_writeup #bug_bounty #bugbounty_writeup
Medium
How a Simple Google Dork Led Me to Find Reflected XSS & HTML Injection on NASA and Earn a Letter of Recognition [April 2026]
Disclaimer
⤷ Title: Smali By bithowl: Chapter 3 Android Bytecode Fundamentals
════════════════════════
𐀪 Author: bithowl
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 13:04:01 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bug_bounty #bithowl
════════════════════════
𐀪 Author: bithowl
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 13:04:01 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bug_bounty #bithowl
Medium
Smali By bithowl: Chapter 3 Android Bytecode Fundamentals
(“Every Android App Speaks a Language Your Phone Understands”)
⤷ Title: Account Takeover Across Multiple Programs via Featurebase Integration
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 05:23:30 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bugbounty_writeup #bug_bounty_tips #account_takeover
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 05:23:30 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bugbounty_writeup #bug_bounty_tips #account_takeover
Medium
Account Takeover Across Multiple Programs via Featurebase Integration
In this blog, I am going to share an account takeover vulnerability in a third-party provider widely used by many bug bounty programs.
⤷ Title: Account Takeover Across Multiple Programs via Featurebase Integration
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 07:16:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bugbounty_writeup #bug_bounty_tips #account_takeover
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 07:16:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bugbounty_writeup #bug_bounty_tips #account_takeover
Medium
Account Takeover Across Multiple Programs via Featurebase Integration
In this blog, I am going to share an account takeover vulnerability in a third-party provider widely used by many bug bounty programs.
⤷ Title: Security Researcher | Cybersecurity Student | Ethical Hacking | Network Security
════════════════════════
𐀪 Author: Malaika Nasir
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 11:51:51 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #bugbounty_writeup #security_researchers #bug_bounty
════════════════════════
𐀪 Author: Malaika Nasir
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 11:51:51 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #bugbounty_writeup #security_researchers #bug_bounty
Medium
Security Researcher | Cybersecurity Student | Ethical Hacking | Network Security
I am Malaika Nasir, a cybersecurity student and security researcher passionate about ethical hacking, network security, Linux, and…
⤷ Title: Found a Security Vulnerability? Here’s How to Report It (with R-Disclosure)
════════════════════════
𐀪 Author: RivuDon
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 06:27:14 GMT
════════════════════════
⌗ Tags: #osint #bugbounty_writeup #bug_bounty #infosec #bug_bounty_tips
════════════════════════
𐀪 Author: RivuDon
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 06:27:14 GMT
════════════════════════
⌗ Tags: #osint #bugbounty_writeup #bug_bounty #infosec #bug_bounty_tips
Medium
Found a Security Vulnerability? Here’s How to Report It (with R-Disclosure)
Learn how to report and use this time-saving tool.
⤷ Title: Bypassing Account Sign-up Restrictions with a Unicode Character
════════════════════════
𐀪 Author: ͏ ͏Dukrov
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 19:14:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #bugbounty_tips
════════════════════════
𐀪 Author: ͏ ͏Dukrov
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 19:14:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #bugbounty_tips
Medium
Bypassing Account Sign-up Restrictions with a Unicode Character
It’s been a while since I put a writeup up here, so I’m dusting off one of my favorites. The target was a user-management / identity…
⤷ Title: Zero-click Admin Takeover via Unguarded login_email
════════════════════════
𐀪 Author: ͏ ͏Dukrov
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 19:12:34 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: ͏ ͏Dukrov
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 19:12:34 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup
Medium
Zero-click Admin Takeover via Unguarded login_email
Been meaning to write this one up since December. It’s a HR platform, name left out, and the bug is one of those ones where you can tell…