⤷ Title: Exploiting CSRF in GraphQL APIs: Achieving Unauthorized CRUD Operations ( $$$ Bounty )
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 06:42:12 GMT
════════════════════════
⌗ Tags: #computer_science #cybersecurity #ethical_hacking #bug_bounty #information_security
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 06:42:12 GMT
════════════════════════
⌗ Tags: #computer_science #cybersecurity #ethical_hacking #bug_bounty #information_security
Medium
Exploiting CSRF in GraphQL APIs: Achieving Unauthorized CRUD Operations ( $$$ Bounty )
Hello Community👋, I’m Divyank Sitapara, an Application Security Researcher and Bug Bounty Hunter. This is my 3rd write-up, where I’ll…
⤷ Title: Sol in the shade: benchmarking Opus 4.6 and GPT-5.6 Sol for finding zero-days
════════════════════════
𐀪 Author: 0xdead4f
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 09:32:04 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #bug_bounty #cybersecurity #security_research #ai
════════════════════════
𐀪 Author: 0xdead4f
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 09:32:04 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #bug_bounty #cybersecurity #security_research #ai
Medium
Sol in the shade: benchmarking Opus 4.6 and GPT-5.6 Sol for finding zero-days
I pointed Opus 4.6 and GPT-5.6 Sol at a big, hardened open source project and told them to hunt for zero-days. Opus 4.6 out-counted GPT-5.6…
⤷ Title: Check-Then-Act: The Timing Bug Hiding in Every Money Endpoint
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #hacking #bug_bounty #infosec
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #hacking #bug_bounty #infosec
Medium
Check-Then-Act: The Timing Bug Hiding in Every Money Endpoint
What’s up everyone! Nitin here 👋
⤷ Title: From Zero to 100+ Reports: My Bug Bounty Journey So Far
════════════════════════
𐀪 Author: s0ham
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 10:24:35 GMT
════════════════════════
⌗ Tags: #infosec #carrer #hacking #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: s0ham
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 10:24:35 GMT
════════════════════════
⌗ Tags: #infosec #carrer #hacking #bug_bounty #cybersecurity
Medium
From Zero to 100+ Reports: My Bug Bounty Journey So Far
I started bug bounty hunting two years ago knowing absolutely nothing. No formal training, no course just YouTube. I didn’t grind through…
⤷ Title: A Fast Recon Workflow for Spotting XSS Candidates
════════════════════════
𐀪 Author: MD Fahad Hosen
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 11:35:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cross_site_scripting
════════════════════════
𐀪 Author: MD Fahad Hosen
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 11:35:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cross_site_scripting
Medium
A Fast Recon Workflow for Spotting XSS Candidates
A practical pipeline for narrowing thousands of URLs down to the handful worth manually testing for Cross-Site Scripting.
⤷ Title: Web Encoding for Beginners: URL, HTML, Unicode, Base64 & Hex
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:45:45 GMT
════════════════════════
⌗ Tags: #hacking #web_development #bug_bounty #hacker #cybersecurity
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:45:45 GMT
════════════════════════
⌗ Tags: #hacking #web_development #bug_bounty #hacker #cybersecurity
Medium
Encoding in Web Applications
Learn web encoding with practical examples of URL, HTML, Unicode, UTF-8,Base64, Hex, and serialization for web security
⤷ Title: Microsoft Bounty Hunt: From Contacts to Invoices via Guest User Misconfigurations
════════════════════════
𐀪 Author: Mustafa Mohamed (d3sca)
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:16:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #react #infosec #salesforce #cybersecurity
════════════════════════
𐀪 Author: Mustafa Mohamed (d3sca)
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:16:04 GMT
════════════════════════
⌗ Tags: #bug_bounty #react #infosec #salesforce #cybersecurity
Medium
Microsoft Bounty Hunt: From Contacts to Invoices via Guest User Misconfigurations
Introduction
⤷ Title: Critical Exposure Of Algolia Key That Led to Production, Staging, and Draft Data
════════════════════════
𐀪 Author: Adham Mohamed
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:09:43 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Adham Mohamed
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:09:43 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty
Medium
Critical Exposure Of Algolia Key That Led to Production, Staging, and Draft Data
While testing a public bug bounty program, I came across an interesting file:
⤷ Title: OAuth 2.0 Vulnerability Hunting: A Pentester’s Field Guide
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:57:41 GMT
════════════════════════
⌗ Tags: #oauth #cybersecurity #application_security #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Dev
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:57:41 GMT
════════════════════════
⌗ Tags: #oauth #cybersecurity #application_security #penetration_testing #bug_bounty
Medium
OAuth 2.0 Vulnerability Hunting: A Pentester’s Field Guide
OAuth 2.0 is everywhere — “Login with Google,” “Login with Microsoft,” third-party API integrations. It’s an authorization framework, not…
⤷ Title: How a Forgotten “Export to Excel” Feature Exfiltrated a Bank’s Database for $5,000
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #bug_bounty_writeup
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 15:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #bug_bounty_writeup
Medium
How a Forgotten “Export to Excel” Feature Exfiltrated a Bank’s Database for $5,000
If there is a golden rule in bug bounty hunting, it’s this: The most secure platforms in the world almost always leave their back door…