⤷ Title: Account Takeover via Broken Password Reset Validation
════════════════════════
𐀪 Author: Mohamed Abd almalek
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 12:00:58 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #websecurity_testing #bug_bounty_writeup #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Mohamed Abd almalek
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 12:00:58 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #websecurity_testing #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Medium
Account Takeover via Broken Password Reset Validation
Severity: Critical
Type: Authentication Bypass / Account Takeover (ATO)
CWE: CWE-640: Weak Password Recovery Mechanism for Forgotten…
Type: Authentication Bypass / Account Takeover (ATO)
CWE: CWE-640: Weak Password Recovery Mechanism for Forgotten…
⤷ Title: Account Lockout Abuse: How a Login Protection Mechanism Became a Potential DoS Vector
════════════════════════
𐀪 Author: Mazen Rady
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 16:40:59 GMT
════════════════════════
⌗ Tags: #account_locked #bug_bounty #bug_bounty_writeup #web_penetration_testing #dos_attack
════════════════════════
𐀪 Author: Mazen Rady
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 16:40:59 GMT
════════════════════════
⌗ Tags: #account_locked #bug_bounty #bug_bounty_writeup #web_penetration_testing #dos_attack
Medium
Account Lockout Abuse: How a Login Protection Mechanism Became a Potential DoS Vector
.اللهم انفعنا بما علَّمتنا، وعلِّمنا ما ينفعنا، وزِدنا علمًا وفقهًا وفهمًا يا رب العالمين
⤷ Title: The Bug Bounty Recon Workflow I Use Before Opening Burp Suite
════════════════════════
𐀪 Author: Michael Oscar
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 16:22:49 GMT
════════════════════════
⌗ Tags: #burpsuite #web_penetration_testing #bug_bounty #cybersecurity #reconnaissance
════════════════════════
𐀪 Author: Michael Oscar
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 16:22:49 GMT
════════════════════════
⌗ Tags: #burpsuite #web_penetration_testing #bug_bounty #cybersecurity #reconnaissance
Medium
The Bug Bounty Recon Workflow I Use Before Opening Burp Suite
Why great bug bounty hunters spend more time understanding an application than attacking it.
⤷ Title: Invitation Link doesn’t expire after used .
════════════════════════
𐀪 Author: David Demean
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:27:07 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #hackerone #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: David Demean
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:27:07 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #hackerone #cybersecurity #bug_bounty
Medium
Invitation Link doesn’t expire after used .
Hi Hackers , I’m David Demean .
I work as a penetration tester on HackerOne.
I work as a penetration tester on HackerOne.
⤷ Title: Week 4 of My Thunder Cipher Cybersecurity Internship: Diving Deep into Web Application Security
════════════════════════
𐀪 Author: cyb3rPh03n1x
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 06:52:01 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #cybersecurity #owasp #web_penetration_testing
════════════════════════
𐀪 Author: cyb3rPh03n1x
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 06:52:01 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #cybersecurity #owasp #web_penetration_testing
Medium
Week 4 of My Thunder Cipher Cybersecurity Internship: Diving Deep into Web Application Security
Cybersecurity isn’t just about knowing vulnerabilities — it’s about understanding why they exist, how they’re exploited in controlled…
⤷ Title: Trustworthy Supply-Chain Security with Audit-Ready Reports
════════════════════════
𐀪 Author: Ivan Vereshchaha
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #pentesting #cybersecurity #web_penetration_testing #cybersecurity_awareness
════════════════════════
𐀪 Author: Ivan Vereshchaha
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #pentesting #cybersecurity #web_penetration_testing #cybersecurity_awareness
Medium
Trustworthy Supply-Chain Security with Audit-Ready Reports
Disclaimer: This document is partner-advertisement material produced to promote the Scry APT AI security framework by Scry.pro. It…
⤷ Title: Reflected XSS in E-Commerce Search — Bug Bounty Writeup
════════════════════════
𐀪 Author: Hassan Elsayed
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 01:25:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #web_penetration_testing
════════════════════════
𐀪 Author: Hassan Elsayed
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 01:25:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #web_penetration_testing
Medium
Reflected XSS in E-Commerce Search — Bug Bounty Writeup
Hassan Elsayed
⤷ Title: How I Bypassed APK Signature Verification in an Android Application(And Why Client-Side Integrity…
════════════════════════
𐀪 Author: Iamshivamdwivedi
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 05:53:04 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #android_security #reverse_engineering #penetration_testing
════════════════════════
𐀪 Author: Iamshivamdwivedi
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 05:53:04 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #android_security #reverse_engineering #penetration_testing
Medium
How I Bypassed APK Signature Verification in an Android Application(And Why Client-Side Integrity Checks Are Not Enough)
APK signature verification is commonly implemented in Android applications to detect tampering and ensure that only the original…
⤷ Title: OWASP Top 10 Isn’t Enough: Security Tests Every Pentester Should Perform
════════════════════════
𐀪 Author: Dharrunkrish
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 11:40:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #application_security #web_penetration_testing #ethical_hacking
════════════════════════
𐀪 Author: Dharrunkrish
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 11:40:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #application_security #web_penetration_testing #ethical_hacking
Medium
OWASP Top 10 Isn’t Enough: Security Tests Every Pentester Should Perform
A field guide to the vulnerability classes that separate a checklist tester from a professional penetration tester
⤷ Title: 5 Affordable Penetration Testing Companies I Actually Outsourced to as a Startup
════════════════════════
𐀪 Author: N .J
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 10:55:39 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #penetration_testing #pentesting
════════════════════════
𐀪 Author: N .J
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 10:55:39 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #penetration_testing #pentesting
Medium
5 Affordable Penetration Testing Companies I Actually Outsourced to as a Startup
Nearly half of small businesses have no cybersecurity budget at all, and only one in five ever runs an annual penetration test, according…