⤷ Title: OAuth 2.0 Vulnerability Hunting: A Pentester’s Field Guide
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:57:41 GMT
════════════════════════
⌗ Tags: #oauth #cybersecurity #application_security #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:57:41 GMT
════════════════════════
⌗ Tags: #oauth #cybersecurity #application_security #penetration_testing #bug_bounty
Medium
OAuth 2.0 Vulnerability Hunting: A Pentester’s Field Guide
OAuth 2.0 is everywhere — “Login with Google,” “Login with Microsoft,” third-party API integrations. It’s an authorization framework, not…
⤷ Title: How a Forgotten “Export to Excel” Feature Exfiltrated a Bank’s Database for $5,000
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #bug_bounty_writeup
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #bug_bounty_writeup
Medium
How a Forgotten “Export to Excel” Feature Exfiltrated a Bank’s Database for $5,000
If there is a golden rule in bug bounty hunting, it’s this: The most secure platforms in the world almost always leave their back door…
⤷ Title: SS7, STUN & VoIP Explained | How P2P IP Address Discovery Works
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:14:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #bug_bounty #web_development #ss7
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:14:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #bug_bounty #web_development #ss7
Medium
🔥 SS7, STUN & VoIP Explained | How P2P IP Address Discovery Works
Modern communication systems rely on several layers of networking technology that most users never see.
⤷ Title: Decoding a URL: Paths, Parameters, and the Art of Finding What’s Hidden
════════════════════════
𐀪 Author: Shruti Vijay Shinde
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 14:54:16 GMT
════════════════════════
⌗ Tags: #vapt #cybersecurity #bug_bounty #penetration_testing #bug_hunting
════════════════════════
𐀪 Author: Shruti Vijay Shinde
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 14:54:16 GMT
════════════════════════
⌗ Tags: #vapt #cybersecurity #bug_bounty #penetration_testing #bug_hunting
Medium
Decoding a URL: Paths, Parameters, and the Art of Finding What’s Hidden
If you’re getting into bug bounty hunting or web security, the URL is where everything starts. Most people glance past it. But a URL is…
⤷ Title: subfaster Review: The Subfinder Fork Built for Faster Bug Bounty Recon
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 17:29:57 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #bug_bounty #cybersecurity #osint
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 17:29:57 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #bug_bounty #cybersecurity #osint
Medium
subfaster Review: The Subfinder Fork Built for Faster Bug Bounty Recon
Most bug bounty hunters are still running subdomain recon the slow way — and it’s costing them time on every single scan.
⤷ Title: I Read the Top 20 IDOR Reports on HackerOne.
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 19:01:41 GMT
════════════════════════
⌗ Tags: #infosec #hacking #idor #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 19:01:41 GMT
════════════════════════
⌗ Tags: #infosec #hacking #idor #bug_bounty_tips #bug_bounty
Medium
I Read the Top 20 IDOR Reports on HackerOne. Nearly Half of Them Delete Data Instead of Stealing It.
30-second version: I pulled the 20 highest-upvoted IDOR reports on HackerOne. Three are no longer publicly readable, so the dataset is 17…
⤷ Title: I Legally Hacked My Own WiFi in Under an Hour — Here’s Exactly How (2026 Guide)
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:41:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #cybersecurity #red_team #hacking
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:41:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #cybersecurity #red_team #hacking
Medium
I Legally Hacked My Own WiFi in Under an Hour — Here’s Exactly How (2026 Guide)
Crack your own WPA2 password, break WPS, and learn exactly where the legal line sits — before you touch a single tool
⤷ Title: Hidden URL Parameters: Finding What Web Applications Don’t Show You
════════════════════════
𐀪 Author: Alif Mortaza
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:36:24 GMT
════════════════════════
⌗ Tags: #web_application_security #ethical_hacking #bug_bounty #cybersecurity #web_security
════════════════════════
𐀪 Author: Alif Mortaza
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:36:24 GMT
════════════════════════
⌗ Tags: #web_application_security #ethical_hacking #bug_bounty #cybersecurity #web_security
Medium
Hidden URL Parameters: Finding What Web Applications Don’t Show You
In many cases, parameters are not documented or directly exposed through a web application’s user interface. Some may support internal…
⤷ Title: Injection — The #5 Vulnerability on the Web
════════════════════════
𐀪 Author: loopXvedant
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:00:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ctf #owasp #bug_bounty
════════════════════════
𐀪 Author: loopXvedant
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:00:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ctf #owasp #bug_bounty
Medium
Injection — The #5 Vulnerability on the Web 💉
When user input becomes a weapon — and the application pulls the trigger.
⤷ Title: How a Locale Path Bypass Exposed 339,000 Media Objects and Multiple Cloud Backends
════════════════════════
𐀪 Author: Tarek ElDemerdash
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:00:36 GMT
════════════════════════
⌗ Tags: #cloud_security #bug_bounty #cybersecurity #web_security #ethical_hacking
════════════════════════
𐀪 Author: Tarek ElDemerdash
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 18:00:36 GMT
════════════════════════
⌗ Tags: #cloud_security #bug_bounty #cybersecurity #web_security #ethical_hacking
Medium
How a Locale Path Bypass Exposed 339,000 Media Objects and Multiple Cloud Backends
Overview