⤷ Title: Bypassing Enterprise SSO via a Forgotten Source Map: A Bug Bounty Story
════════════════════════
𐀪 Author: Priyansh
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:40:18 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #hacker #bug_bounty_writeup #bugs
════════════════════════
𐀪 Author: Priyansh
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:40:18 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #hacker #bug_bounty_writeup #bugs
Medium
Bypassing Enterprise SSO via a Forgotten Source Map: A Bug Bounty Story
When you look at a bug bounty scope with 15+ root domains, it’s easy to get overwhelmed. Most hunters will fire off their automated…
⤷ Title: They Gave Me $1,000 After I Found Their Entire Student Database Exposed!
════════════════════════
𐀪 Author: Anukar
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:35:57 GMT
════════════════════════
⌗ Tags: #web_development #vulnerability #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Anukar
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:35:57 GMT
════════════════════════
⌗ Tags: #web_development #vulnerability #cybersecurity #bug_bounty
Medium
They Gave Me $1,000 After I Found Their Entire Student Database Exposed!
A writeup about HTTP method override leading to massive PII exposure by Anukar.
⤷ Title: Why Bug Hunters Skip Role-Based API Testing And How I Turned a Writer Token Into an SSRF
════════════════════════
𐀪 Author: CypherNova1337
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:04:39 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #api_security #penetration_testing
════════════════════════
𐀪 Author: CypherNova1337
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:04:39 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #api_security #penetration_testing
Medium
Why Bug Hunters Skip Role-Based API Testing And How I Turned a Writer Token Into an SSRF
Almost nobody tests authorization at the role level.
⤷ Title: Why Most Bug Bounty Hunters Find Nothing — And How to Fix It
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:39:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 09:39:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
Medium
Why Most Bug Bounty Hunters Find Nothing — And How to Fix It
Most bug bounty hunters don’t fail because they lack tools. They fail because they search without a methodology.
⤷ Title: The Quiet SQLi Everyone Walks Past (And How to Catch It)
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #pentesting #bug_bounty #infosec
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #pentesting #bug_bounty #infosec
Medium
The Quiet SQLi Everyone Walks Past (And How to Catch It)
What’s up everyone! Nitin here 👋
⤷ Title: Walkthrough: PortSwigger — Password Reset Broken Logic
════════════════════════
𐀪 Author: Ayeshaaghafoor
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 10:44:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #api #penetration_testing #bug_bounty #cyber_security_awareness
════════════════════════
𐀪 Author: Ayeshaaghafoor
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 10:44:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #api #penetration_testing #bug_bounty #cyber_security_awareness
Medium
Walkthrough: PortSwigger — Password Reset Broken Logic
Executive Summary
⤷ Title: Cloud Storage Misconfigurations: Learn from 15 Real Breaches and Secure Your Data
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 10:29:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #hacking #cybersecurity #cyber
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 10:29:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #hacking #cybersecurity #cyber
Medium
Cloud Storage Misconfigurations: Learn from 15 Real Breaches and Secure Your Data
Ever scrolled the news and thought, “How did that company leak millions of records just by messing up a storage bucket?” You’re not alone…
⤷ Title: Business Logic Flaw: Refund Limit Bypass via Support Chatbot
════════════════════════
𐀪 Author: Noureldin(0x_5wf)
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 11:48:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: Noureldin(0x_5wf)
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 11:48:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips
Medium
Business Logic Flaw: Refund Limit Bypass via Support Chatbot
Target: [REDACTED] (audiobook/subscription service) Vulnerability Class: Business Logic Error / Improper Enforcement of Rate Limit…
⤷ Title: Lab: Using PHAR deserialization to deploy a custom gadget chain
════════════════════════
𐀪 Author: Amrsmooke
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:00:27 GMT
════════════════════════
⌗ Tags: #portswigger #bug_bounty #hacking #penetration_testing #burpsuite
════════════════════════
𐀪 Author: Amrsmooke
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:00:27 GMT
════════════════════════
⌗ Tags: #portswigger #bug_bounty #hacking #penetration_testing #burpsuite
Medium
Lab: Using PHAR deserialization to deploy a custom gadget chain
Forget about the exploit payload, the Blog class, or writing code. Right now, our only goal is to find a place on the website that lets us…
⤷ Title: Python Web Penetration Testing — Day 10: XML External Entity (XXE) Injection — The Forgotten Giant
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:04:07 GMT
════════════════════════
⌗ Tags: #programming #penetration_testing #bug_bounty #cybersecurity #technology
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:04:07 GMT
════════════════════════
⌗ Tags: #programming #penetration_testing #bug_bounty #cybersecurity #technology
Medium
Python Web Penetration Testing — Day 10: XML External Entity (XXE) Injection — The Forgotten Giant
I spent years ignoring XML parsers. Then I found an XXE vulnerability that exposed an entire company’s internal network. Here’s how to find…