⤷ Title: Open Redirect via Base64-Encoded state Parameter in OAuth Flow (returnTo field)
════════════════════════
𐀪 Author: Hussein Elturkey
════════════════════════
ⴵ Time: Fri, 16 May 2025 21:10:28 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #duplicate #open_redirect #bugcrowd #bug_bounty
════════════════════════
𐀪 Author: Hussein Elturkey
════════════════════════
ⴵ Time: Fri, 16 May 2025 21:10:28 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #duplicate #open_redirect #bugcrowd #bug_bounty
Medium
Open Redirect via Base64-Encoded state Parameter in OAuth Flow (returnTo field)
Hi there, It is me Hussein, I Bug Bounty Hunter (Former Web Developer), I will tell you about an Open Redirect bug I found last month.
⤷ Title: Misconfigured OAuth = Instant Account Takeover (Even Before Signup!)
════════════════════════
𐀪 Author: Ashok kumar pareek
════════════════════════
ⴵ Time: Mon, 26 May 2025 20:50:10 GMT
════════════════════════
⌗ Tags: #bug_bounty #duplicate #pre_account_takeover #account_takeover #happy_hunting
════════════════════════
𐀪 Author: Ashok kumar pareek
════════════════════════
ⴵ Time: Mon, 26 May 2025 20:50:10 GMT
════════════════════════
⌗ Tags: #bug_bounty #duplicate #pre_account_takeover #account_takeover #happy_hunting
Medium
Misconfigured OAuth = Instant Account Takeover (Even Before Signup!)
🕵️♂️ How I Took Over Accounts Before Users Even Registered — Thanks to a Misconfigured OAuth System
⤷ Title: How I Found 5 OAuth Misconfigurations Leading to Pre-Account Takeover in Public Bug Bounty Programs…
════════════════════════
𐀪 Author: KhaledAhmed107
════════════════════════
ⴵ Time: Sun, 24 Aug 2025 09:48:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #pre_account_takeover #bug_bounty #account_takeover #duplicate
════════════════════════
𐀪 Author: KhaledAhmed107
════════════════════════
ⴵ Time: Sun, 24 Aug 2025 09:48:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #pre_account_takeover #bug_bounty #account_takeover #duplicate
Medium
How I Found 5 OAuth Misconfigurations Leading to Pre-Account Takeover in Public Bug Bounty Programs…
السلام عليكم ورحمة الله وبركاته
⤷ Title: Full Disclosure: How Bugcrowd Marked a TEE Authentication Bypass as a Duplicate — Of a Finding They…
════════════════════════
𐀪 Author: Levi
════════════════════════
ⴵ Time: Thu, 14 May 2026 12:40:18 GMT
════════════════════════
⌗ Tags: #duplicate #bug_bounty #triage #bugcrowdfail #bugcrowd
════════════════════════
𐀪 Author: Levi
════════════════════════
ⴵ Time: Thu, 14 May 2026 12:40:18 GMT
════════════════════════
⌗ Tags: #duplicate #bug_bounty #triage #bugcrowdfail #bugcrowd
Medium
Full Disclosure: How Bugcrowd Marked a TEE Authentication Bypass as a Duplicate — Of a Finding They Closed as Not Applicable
Preface
⤷ Title: Linus Torvalds Slams AI Bug Hunters for Clogging Linux Security Pipelines
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:09:03 +0000
════════════════════════
⌗ Tags: #Linux #AI Bug Reports #Drive_By Bug Hunting #Duplicate Vulnerabilities #Greg Kroah_Hartman #Linus Torvalds #Linux 7.1 Release Candidate #Linux Security Mailing List #Open Source Documentation #Patch Management #Vulnerability Triage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:09:03 +0000
════════════════════════
⌗ Tags: #Linux #AI Bug Reports #Drive_By Bug Hunting #Duplicate Vulnerabilities #Greg Kroah_Hartman #Linus Torvalds #Linux 7.1 Release Candidate #Linux Security Mailing List #Open Source Documentation #Patch Management #Vulnerability Triage
Penetration Testing Tools
Linus Torvalds Slams AI Bug Hunters for Clogging Linux Security Pipelines
Linus Torvalds has once again given voice to a sentiment that had been quietly permeating the developer community