⤷ Title: OTPs For Everyone: The Simplest $OTP Leak$ You’ll Ever Find
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 11:13:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #otp_bypass #parameter_pollution #bug_bounty_writeup #hackerone
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 11:13:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #otp_bypass #parameter_pollution #bug_bounty_writeup #hackerone
Medium
OTPs For Everyone: The Simplest $OTP Leak$ You’ll Ever Find
Akwaaba! The application processed user request data in a weird way. All requests were made with the GET method but no parameters. The…
⤷ Title: GhostGrab Android Malware Combines Covert Monero Mining with Financial Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Banking Trojan #Cryptojacking #Firebase C2 #GhostGrab #Hybrid Threat #Monero mining #OTP Interception
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Banking Trojan #Cryptojacking #Firebase C2 #GhostGrab #Hybrid Threat #Monero mining #OTP Interception
Daily CyberSecurity
GhostGrab Android Malware Combines Covert Monero Mining with Financial Credential Theft
GhostGrab is a hybrid Android malware that steals banking credentials and OTPs via phishing WebView overlays while secretly running a Monero miner in the background to monetize the victim's device.
⤷ Title: Scammers Abuse WhatsApp Screen Sharing to Steal OTPs and Funds
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 17:15:15 +0000
════════════════════════
⌗ Tags: #Scams and Fraud #Security #AnyDesk #Cybersecurity #eset #Facebook #Fraud #OTP #Privacy #Scam #TeamViewer #Vulnerability #WhatsApp
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 17:15:15 +0000
════════════════════════
⌗ Tags: #Scams and Fraud #Security #AnyDesk #Cybersecurity #eset #Facebook #Fraud #OTP #Privacy #Scam #TeamViewer #Vulnerability #WhatsApp
Hackread
Scammers Abuse WhatsApp Screen Sharing to Steal OTPs and Funds
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Breaking Authentication: How I Bypassed Email Verification by Changing One Word in the Response
════════════════════════
𐀪 Author: Madanu Akash
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 17:51:16 GMT
════════════════════════
⌗ Tags: #otp_bypass #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Madanu Akash
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 17:51:16 GMT
════════════════════════
⌗ Tags: #otp_bypass #bug_bounty #cybersecurity
Medium
Breaking Authentication: How I Bypassed Email Verification by Changing One Word in the Response
A deep dive into client-side authentication vulnerabilities and why trusting the browser is never a good idea.
⤷ Title: Android 16 QPR2: New Minor SDK Brings 3-Hour OTP SMS Delay & Icon Customization
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 03:58:38 +0000
════════════════════════
⌗ Tags: #Android #Google #Android 16 QPR2 #Android Security #Custom Icons #dark theme #Health Connect #Linux GUI #Minor SDK #OTP Delay
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 03:58:38 +0000
════════════════════════
⌗ Tags: #Android #Google #Android 16 QPR2 #Android Security #Custom Icons #dark theme #Health Connect #Linux GUI #Minor SDK #OTP Delay
Penetration Testing Tools
Android 16 QPR2: New Minor SDK Brings 3-Hour OTP SMS Delay & Icon Customization
Google has released the Android 16 QPR2 update, introducing substantial refinements across the interface, developer tooling, and system
⤷ Title: New WordPress Phishing Scam Steals Credit Cards via Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #3_D Secure bypass #Anurag #credit card theft #cyber fraud #DMARC #Domain Renewal Scam #Exfiltration #OTP Harvesting #phishing #soyfix[.]com #Telegram bot #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #3_D Secure bypass #Anurag #credit card theft #cyber fraud #DMARC #Domain Renewal Scam #Exfiltration #OTP Harvesting #phishing #soyfix[.]com #Telegram bot #wordpress
Daily CyberSecurity
New WordPress Phishing Scam Steals Credit Cards via Telegram
Researcher Anurag uncovers a WordPress phishing campaign that steals credit cards and 3-D Secure OTPs, exfiltrating data directly via Telegram bots.
⤷ Title: One Token to Rule Them All: Persistent MFA Bypass via Trusted Client Abuse
════════════════════════
𐀪 Author: Bavly Zaher
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 07:30:11 GMT
════════════════════════
⌗ Tags: #otp_bypass #mfa #authentication_bypass #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Bavly Zaher
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 07:30:11 GMT
════════════════════════
⌗ Tags: #otp_bypass #mfa #authentication_bypass #bug_bounty_tips #bug_bounty
Medium
One Token to Rule Them All: Persistent MFA Bypass via Trusted Client Abuse
🐦🔥 Platform Overview
⤷ Title: 2FA Bypass via OTP Reuse Across Multiple Authentication Flows
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
Medium
2FA Bypass via OTP Reuse Across Multiple Authentication Flows
Hello everyone, I’m Jeet. I used to hunt bugs regularly, but due to some personal reasons I couldn’t stay consistent for a while. Now I’m…
⤷ Title: 2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
Medium
2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
Hello Hackers 👋
⤷ Title: My First Bug Bounty: A Simple OTP Flaw That Led to Account Takeover
════════════════════════
𐀪 Author: montaser mohsen
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 18:41:04 GMT
════════════════════════
⌗ Tags: #authentication #brute_force #account_takeover #bug_bounty #otp_bypass
════════════════════════
𐀪 Author: montaser mohsen
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 18:41:04 GMT
════════════════════════
⌗ Tags: #authentication #brute_force #account_takeover #bug_bounty #otp_bypass
Medium
My First Bug Bounty: A Simple OTP Flaw That Led to Account Takeover
Who Am I?