⤷ Title: How I Earned $76,000 From a Single Program on Bugcrowd
════════════════════════
𐀪 Author: Sharik Khan
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:46:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #hackerone #bug_bounty #bugcrowd
════════════════════════
𐀪 Author: Sharik Khan
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:46:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #hackerone #bug_bounty #bugcrowd
Medium
How I Earned $76,000 From a Single Program on Bugcrowd
Consistency and patience are not soft skills in bug bounty. They are the strategy.
⤷ Title: How I Discovered a Blind SQL Injection in a Private program
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:09:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #hackerone #hacking #bugcrowd
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:09:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #hackerone #hacking #bugcrowd
Medium
How I Discovered a Blind SQL Injection in a Private program
Hi, I’m mrx_w_ (Adem Ziane Berroudja), a bug bounty hunter on Bugcrowd. You can find me on Twitter and LinkedIn under mrx_w_. In this…
⤷ Title: When Features Do More Than They Should
════════════════════════
𐀪 Author: Asjad Butt
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 20:32:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugcrowd #security #vulnerability #hacking
════════════════════════
𐀪 Author: Asjad Butt
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 20:32:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugcrowd #security #vulnerability #hacking
Medium
When Features Do More Than They Should
Some security issues don’t come from complex systems or clever exploitation. They come from ordinary features doing slightly more than…
⤷ Title: Finding an IDOR in Tesla From the Outside
════════════════════════
𐀪 Author: Asjad Butt
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:59:27 GMT
════════════════════════
⌗ Tags: #hacking #software_development #tesla #bugcrowd #bug_bounty
════════════════════════
𐀪 Author: Asjad Butt
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:59:27 GMT
════════════════════════
⌗ Tags: #hacking #software_development #tesla #bugcrowd #bug_bounty
Medium
Finding an IDOR in Tesla From the Outside
When you’re testing applications, you’ll eventually hit a wall — a point where the intended user flow just isn’t accessible.
⤷ Title: From Recon to Letter of Recognition | NASA VDP
════════════════════════
𐀪 Author: Wahyu Priambodo
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 02:04:17 GMT
════════════════════════
⌗ Tags: #source_code_disclosure #nasa_vdp #bugcrowd #bug_bounty
════════════════════════
𐀪 Author: Wahyu Priambodo
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 02:04:17 GMT
════════════════════════
⌗ Tags: #source_code_disclosure #nasa_vdp #bugcrowd #bug_bounty
Medium
From Recon to Letter of Recognition | NASA VDP
Full Source Code Disclosure from a “.git” Repository
⤷ Title: A Critical IDOR That Allowed Me to Delete Any User Account
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:40:39 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #hackerone #bug_bounty #bugcrowd
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:40:39 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #hackerone #bug_bounty #bugcrowd
Medium
A Critical IDOR That Allowed Me to Delete Any User Account
Hi, I’m mrx_w_ (Adem Ziane Berroudja), a bug bounty hunter on Bugcrowd. You can find me on Twitter and LinkedIn under mrx_w_. In this…
⤷ Title: Full Disclosure: How Bugcrowd Marked a TEE Authentication Bypass as a Duplicate — Of a Finding They…
════════════════════════
𐀪 Author: Levi
════════════════════════
ⴵ Time: Thu, 14 May 2026 12:40:18 GMT
════════════════════════
⌗ Tags: #duplicate #bug_bounty #triage #bugcrowdfail #bugcrowd
════════════════════════
𐀪 Author: Levi
════════════════════════
ⴵ Time: Thu, 14 May 2026 12:40:18 GMT
════════════════════════
⌗ Tags: #duplicate #bug_bounty #triage #bugcrowdfail #bugcrowd
Medium
Full Disclosure: How Bugcrowd Marked a TEE Authentication Bypass as a Duplicate — Of a Finding They Closed as Not Applicable
Preface
⤷ Title: How I Found a Permanent Account Takeover Through SSO Account Linking Misconfiguration
════════════════════════
𐀪 Author: El Professor Qais
════════════════════════
ⴵ Time: Sun, 24 May 2026 21:06:27 GMT
════════════════════════
⌗ Tags: #google_sso #bugcrowd #bug_bounty #account_takeover #bug_bounty_tips
════════════════════════
𐀪 Author: El Professor Qais
════════════════════════
ⴵ Time: Sun, 24 May 2026 21:06:27 GMT
════════════════════════
⌗ Tags: #google_sso #bugcrowd #bug_bounty #account_takeover #bug_bounty_tips
Medium
How I Found a Permanent Account Takeover Through SSO Account Linking Misconfiguration
Educational write-up for security research and responsible disclosure purposes only. Founded it in BugCrowd Private Program 🔥
⤷ Title: When “One-Time” Isn’t Enough: The Case of the Reusable Magic Link
════════════════════════
𐀪 Author: Just_try_shit
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 11:36:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #passwordless #bug_bounty_writeup #bugcrowd
════════════════════════
𐀪 Author: Just_try_shit
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 11:36:12 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #passwordless #bug_bounty_writeup #bugcrowd
Medium
When “One-Time” Isn’t Enough: The Case of the Reusable Magic Link
Introduction
⤷ Title: Why Your Subdomain Takeover Reports Keep Getting Closed as N/A (And How to Fix It).
════════════════════════
𐀪 Author: Omar Mahmoud
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 11:04:39 GMT
════════════════════════
⌗ Tags: #subdomain_takeover #red_team #bug_bounty #bugcrowd #hackerone
════════════════════════
𐀪 Author: Omar Mahmoud
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 11:04:39 GMT
════════════════════════
⌗ Tags: #subdomain_takeover #red_team #bug_bounty #bugcrowd #hackerone
Medium
Why Your Subdomain Takeover Reports Keep Getting Closed as N/A (And How to Fix It).
Subdomain Takeover is often described as one of the easiest vulnerabilities to find in Bug Bounty programs. Even today, hunters continue to…