⤷ Title: Header Hijinks: How X-Forwarded-For Gave Me Internal Access
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:34:01 GMT
════════════════════════
⌗ Tags: #infosec #money #cybersecurity #bug_bounty #hacking
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:34:01 GMT
════════════════════════
⌗ Tags: #infosec #money #cybersecurity #bug_bounty #hacking
Medium
Header Hijinks: How X-Forwarded-For Gave Me Internal Access 🚧🧠
Hey there!😁
⤷ Title: $7,500 Bounty: Exposed Any User’s Email on HackerOne
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:32:29 GMT
════════════════════════
⌗ Tags: #bug_bounty #tips_and_tricks #technology #penetration_testing #hackerone
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:32:29 GMT
════════════════════════
⌗ Tags: #bug_bounty #tips_and_tricks #technology #penetration_testing #hackerone
Medium
$7,500 Bounty: Exposed Any User’s Email on HackerOne
A Subtle Enumeration Bug That Let Attackers Harvest Emails Before Invitations Were Accepted — $7,500 Bounty
⤷ Title: GraphQL in the Wild: Recon to RCE via Introspection, Nested Queries & Batching Attacks
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:14:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #bug_bounty_tips #penetration_testing #technology
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:14:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #bug_bounty_tips #penetration_testing #technology
Medium
GraphQL in the Wild: Recon to RCE via Introspection, Nested Queries & Batching Attacks
How Modern APIs Are Giving Hackers a Query Language for Mayhem
⤷ Title: Cracking JWTs: A Bug Bounty Hunting Guide [Part 7] — The Final P1 Boss
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:13:31 GMT
════════════════════════
⌗ Tags: #jwt_authentication #jwt #cybersecurity #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:13:31 GMT
════════════════════════
⌗ Tags: #jwt_authentication #jwt #cybersecurity #bug_bounty #bug_bounty_writeup
Medium
Cracking JWTs: A Bug Bounty Hunting Guide [Part 7] — The Final P1 Boss 🔓
JWT Authentication Bypass via Algorithm Confusion Exploit Without Key Disclosure
⤷ Title: How a Simple RECON Earned Me ₹XX,000
════════════════════════
𐀪 Author: Swarnim Bandekar
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:11:23 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_writeup #hacking #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Swarnim Bandekar
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:11:23 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_writeup #hacking #penetration_testing #bug_bounty
Medium
💰 How a Simple RECON Earned Me ₹XX,000
Security bugs aren’t always flashy. Sometimes, you don’t need to pop a shell or find an RCE to make an impact.
Sometimes… all you need is…
Sometimes… all you need is…
⤷ Title: Intigriti Bug Bytes #225 - June 2025 🚀
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
Intigriti
Intigriti Bug Bytes #225 - June 2025 🚀
Hello hackers, Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Becoming an Intigriti Pentester Exploiting CORS in 2025 (even when SameSite is set to ‘Strict’) A...
⤷ Title: What does it take to become CREST-accredited? Top 10 questions answered
════════════════════════
𐀪 Author: Eleanor Barlow
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Business Insights
════════════════════════
𐀪 Author: Eleanor Barlow
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Business Insights
Intigriti
What does it take to become CREST-accredited? Top 10 questions answered.
CREST is the gold standard for quality assurance accreditation in the cybersecurity industry. But what does it take to become accredited and, more importantly, what is the impact? In this article, Intigriti covers ten of the most asked questions surrounding…
⤷ Title: Account Takeover via Facebook OAuth Misconfiguration
════════════════════════
𐀪 Author: Ahmed Elghazaly
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 20:48:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #account_take_over #bug_bounty_tips #facebook_oauth
════════════════════════
𐀪 Author: Ahmed Elghazaly
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 20:48:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #account_take_over #bug_bounty_tips #facebook_oauth
Medium
Account Takeover via Facebook OAuth Misconfiguration
Hey everyone, Today I’m excited to share a bug I discovered in a Bugcrowd VDP target involving Facebook login — and it led to full account…
⤷ Title: From Zero to $100K in Cybersecurity in 90 Days: A Realistic, Actionable Plan
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:55:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #artificial_intelligence #cybersecurity #coding #cybercrime
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:55:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #artificial_intelligence #cybersecurity #coding #cybercrime
Medium
💻 From Zero to $100K in Cybersecurity in 90 Days: A Realistic, Actionable Plan 🔥
Hey there, future hacker! 🧑💻 If you’ve ever dreamed of breaking into the world of cybersecurity, you're not alone — and you're not too late. In fact, you're right on time. Whether you're here for…
⤷ Title: How to Test “Forgot Password” for Bugs — A Guide for BB Hunters & Pentesters
════════════════════════
𐀪 Author: Medusa
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:41:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #developer #software #pentesting #bug_bounty
════════════════════════
𐀪 Author: Medusa
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:41:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #developer #software #pentesting #bug_bounty
Medium
How to Test “Forgot Password” for Bugs — A Guide for BB Hunters & Pentesters
Introduction
⤷ Title: From Bug Bounty Blahs to Breakthroughs: Navigating the “Never Enough” Trap in Cyber
════════════════════════
𐀪 Author: Leviiatan
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:37:53 GMT
════════════════════════
⌗ Tags: #mental_health #bug_bounty #tech #cybersecurity #study
════════════════════════
𐀪 Author: Leviiatan
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:37:53 GMT
════════════════════════
⌗ Tags: #mental_health #bug_bounty #tech #cybersecurity #study
Medium
From Bug Bounty Blahs to Breakthroughs: Navigating the “Never Enough” Trap in Cyber
Medium Story
⤷ Title: ¿Qué es el Bug Bounty y por qué es tan lucrativo?
════════════════════════
𐀪 Author: Tiziano Mass
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:26:43 GMT
════════════════════════
⌗ Tags: #information_security #bug_bounty #pentesting #cybersecurity #ciberseguridad
════════════════════════
𐀪 Author: Tiziano Mass
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 19:26:43 GMT
════════════════════════
⌗ Tags: #information_security #bug_bounty #pentesting #cybersecurity #ciberseguridad
Medium
¿Qué es el Bug Bounty y por qué es tan lucrativo?
Los programas cazarrecompensas representan una de las formas más útiles de identificar y reportar vulnerabilidades a cambio de un premio…
⤷ Title: Setup a Pentesting Lab
════════════════════════
𐀪 Author: SACHIN PV
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 18:17:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #kali_linux #virtualbox #cybersecurity #pentesting
════════════════════════
𐀪 Author: SACHIN PV
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 18:17:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #kali_linux #virtualbox #cybersecurity #pentesting
Medium
Setup a Pentesting Lab
The one and most important software that we require for setting a lab is a virtual box / VM ware ,so that we can test as any VMs as we…
⤷ Title: From LFI to RCE via Log Poisoning: Hack Servers with Just Your Browser Headers ️♂️
════════════════════════
𐀪 Author: Zoningxtr
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 18:12:14 GMT
════════════════════════
⌗ Tags: #api #bug_bounty #penetration_testing #web_development #cybersecurity
════════════════════════
𐀪 Author: Zoningxtr
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 18:12:14 GMT
════════════════════════
⌗ Tags: #api #bug_bounty #penetration_testing #web_development #cybersecurity
Medium
💣 From LFI to RCE via Log Poisoning: Hack Servers with Just Your Browser Headers 🕵️♂️📝
By Zoningxtr
⤷ Title: Exposing an OAuth Token Weakness in Amazon’s Mobile App: A Responsible Disclosure Journey
════════════════════════
𐀪 Author: C. Oscar Lawshea
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 17:01:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #bug_bounty #amazon #information_security
════════════════════════
𐀪 Author: C. Oscar Lawshea
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 17:01:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #bug_bounty #amazon #information_security
Medium
Exposing an OAuth Token Weakness in Amazon’s Mobile App: A Responsible Disclosure Journey
How a Simple Burp Suite Interception Revealed Serious Risks in Token Handling and User PII Exposure
⤷ Title: From LFI to LFD: Exploiting PHP Wrappers &Countermeasures Like a Pro ️♂️
════════════════════════
𐀪 Author: Zoningxtr
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 15:04:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #application_security #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Zoningxtr
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 15:04:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #application_security #bug_bounty #cybersecurity
Medium
🧠💥 From LFI to LFD: Exploiting PHP Wrappers &Countermeasures Like a Pro 🕵️♂️📂
By Zoningxtr
⤷ Title: Unlimited Store Credit: Finding an Economy-Breaking Bug in a Digital Storefront’s Discord Bot
════════════════════════
𐀪 Author: Van Kevindo
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 14:44:58 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Van Kevindo
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 14:44:58 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #bug_bounty
Medium
Unlimited Store Credit: Finding an Economy-Breaking Bug in a Digital Storefront’s Discord Bot
A Case Study on Bypassing Admin Permissions by Exploiting a Bot’s Global State
⤷ Title: No-Cap: Securing Docker Containers — The Critical Role of Linux Capabilities
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 13:19:02 GMT
════════════════════════
⌗ Tags: #docker #cybersecurity #containers #application_security
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 13:19:02 GMT
════════════════════════
⌗ Tags: #docker #cybersecurity #containers #application_security
Medium
No-Cap: Securing Docker Containers — The Critical Role of Linux Capabilities
In Redhat’s Kubernetes adoption, security, and market trends report 42% of respondents expressed security concerns, and 9 in 10…
⤷ Title: มาลองโกงเกมด้วย Cheat Engine
════════════════════════
𐀪 Author: T S
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 10:21:20 GMT
════════════════════════
⌗ Tags: #penetration_test #pentest #application_security #reverse_engineering
════════════════════════
𐀪 Author: T S
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 10:21:20 GMT
════════════════════════
⌗ Tags: #penetration_test #pentest #application_security #reverse_engineering
Medium
มาลองโกงเกมด้วย Cheat Engine
ในโลกของเกม การแข่งขันและความท้าทายคือสิ่งที่ทำให้ผู้เล่นสนุกและตื่นเต้น…
⤷ Title: Implementing the shift left approach to application security for mid-sized organizations
════════════════════════
𐀪 Author: cyber_pix
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 09:52:06 GMT
════════════════════════
⌗ Tags: #shift_left_security #shift_left_approach #application_security #shift_left_testing #cloud_security
════════════════════════
𐀪 Author: cyber_pix
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 09:52:06 GMT
════════════════════════
⌗ Tags: #shift_left_security #shift_left_approach #application_security #shift_left_testing #cloud_security
Medium
Implementing the shift left approach to application security for mid-sized organizations
In the fast-paced world of software development, where agility often takes precedence, application security (AppSec) can sometimes feel…
⤷ Title: Portswigger Labs: Web LLM Attacks
════════════════════════
𐀪 Author: Chris-M
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 04:27:40 GMT
════════════════════════
⌗ Tags: #portswigger #application_security #web_security
════════════════════════
𐀪 Author: Chris-M
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 04:27:40 GMT
════════════════════════
⌗ Tags: #portswigger #application_security #web_security
Medium
Portswigger Labs: Web LLM Attacks
The following blog will contain write-ups of the Portswigger labs related to Web LLM Attacks.