⤷ Title: Improper Authentication in a famous Trading website
════════════════════════
𐀪 Author: Anonymousshetty
════════════════════════
ⴵ Time: Tue, 14 Jan 2025 14:59:48 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #ethical_hacking #improper_access_control #bug_bounty_tips
════════════════════════
𐀪 Author: Anonymousshetty
════════════════════════
ⴵ Time: Tue, 14 Jan 2025 14:59:48 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #ethical_hacking #improper_access_control #bug_bounty_tips
Medium
Improper Authentication in a famous Trading website
**disclaimer: please take permission before testing any website and do not perform actions without understanding its impact ;)
⤷ Title: OWASP LLM Top 10 — Improper Output Handling in AI Systems
════════════════════════
𐀪 Author: Anil Kumar Nandibhatla
════════════════════════
ⴵ Time: Fri, 31 Jan 2025 05:29:45 GMT
════════════════════════
⌗ Tags: #llm #best_practices #owasp #improper_output_handling #cybersecurity
════════════════════════
𐀪 Author: Anil Kumar Nandibhatla
════════════════════════
ⴵ Time: Fri, 31 Jan 2025 05:29:45 GMT
════════════════════════
⌗ Tags: #llm #best_practices #owasp #improper_output_handling #cybersecurity
Medium
OWASP LLM Top 10 — Improper Output Handling in AI Systems
Large Language Models (LLMs) generate responses based on complex probability calculations, but without proper safeguards, these outputs…
⤷ Title: $200 Easy Bounty: Improper Rate Limiting Exploit
════════════════════════
𐀪 Author: It4chis3c
════════════════════════
ⴵ Time: Thu, 06 Feb 2025 05:54:29 GMT
════════════════════════
⌗ Tags: #bounties #rate_limit_bypass #bug_bounty_writeup #improper_access_control #secrets
════════════════════════
𐀪 Author: It4chis3c
════════════════════════
ⴵ Time: Thu, 06 Feb 2025 05:54:29 GMT
════════════════════════
⌗ Tags: #bounties #rate_limit_bypass #bug_bounty_writeup #improper_access_control #secrets
Medium
💰 $200 Easy Bounty: Improper Rate Limiting Exploit
Hi geeks, it4chis3c (Twitter) came-up with the write-up on Improper Rate Limiting Vulnerability found on one of the target’s internal login…
⤷ Title: CVE-2025-2492: Critical ASUS Router Vulnerability Requires Immediate Firmware Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Apr 2025 00:33:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #AiCloud #ASUS #CVE_2025_2492 #cybersecurity #firmware update #improper authentication #Remote Access #router security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Apr 2025 00:33:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #AiCloud #ASUS #CVE_2025_2492 #cybersecurity #firmware update #improper authentication #Remote Access #router security
Daily CyberSecurity
CVE-2025-2492: Critical ASUS Router Vulnerability Requires Immediate Firmware Update
ASUS routers have a critical vulnerability (CVE-2025-2492) allowing unauthorized access. Update firmware and strengthen security now.
⤷ Title: How I Registered an Account Using Someone Else’s Email (Without Ever Verifying It)
════════════════════════
𐀪 Author: ASC Lages
════════════════════════
ⴵ Time: Wed, 30 Apr 2025 02:48:17 GMT
════════════════════════
⌗ Tags: #improper_authentication #bugbounty_story #authentication_bypass #api_security
════════════════════════
𐀪 Author: ASC Lages
════════════════════════
ⴵ Time: Wed, 30 Apr 2025 02:48:17 GMT
════════════════════════
⌗ Tags: #improper_authentication #bugbounty_story #authentication_bypass #api_security
Medium
🔐 How I Registered an Account Using Someone Else’s Email (Without Ever Verifying It)
Assalamwalaikum wr wb, Greetings ! 🙏 It’s me again guys,….. 😁
⤷ Title: Breaking Boundaries: Vertical Privilege Escalation to Admin via Insecure Direct Request
════════════════════════
𐀪 Author: Asad Ullah Evan
════════════════════════
ⴵ Time: Tue, 27 May 2025 17:32:30 GMT
════════════════════════
⌗ Tags: #hunting #web_penetration_testing #privilege_escalation #bug_bounty #improper_access_control
════════════════════════
𐀪 Author: Asad Ullah Evan
════════════════════════
ⴵ Time: Tue, 27 May 2025 17:32:30 GMT
════════════════════════
⌗ Tags: #hunting #web_penetration_testing #privilege_escalation #bug_bounty #improper_access_control
Medium
Breaking Boundaries: Vertical Privilege Escalation to Admin via Insecure Direct Request
I’m excited to share a recent finding during a web application penetration test. The application was fully API-based, and during my…
⤷ Title: Leak of Internal Reference Name at Multiple Locations.
════════════════════════
𐀪 Author: xploiterr
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:15:29 GMT
════════════════════════
⌗ Tags: #improper_access_control #bug_bounty #bugbounty_tips
════════════════════════
𐀪 Author: xploiterr
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:15:29 GMT
════════════════════════
⌗ Tags: #improper_access_control #bug_bounty #bugbounty_tips
Medium
Leak of Internal Reference Name at Multiple Locations.
Hi Everyone,
⤷ Title: QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 18:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52856 #CVE_2025_52861 #cybersecurity #improper authentication #NVR #Path Traversal #QNAP #QVR #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 18:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52856 #CVE_2025_52861 #cybersecurity #improper authentication #NVR #Path Traversal #QNAP #QVR #Vulnerability
Daily CyberSecurity
QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3
QNAP has patched a critical improper authentication flaw (CVE-2025-52856) in its QVR firmware with a CVSS score of 9.3, allowing remote attackers to bypass security.
⤷ Title: API9:2023 — Improper Inventory Management
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 07:38:11 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #apifort #owasp_api_security_top_10 #improper_inventory
════════════════════════
𐀪 Author: Apifort
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 07:38:11 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #apifort #owasp_api_security_top_10 #improper_inventory
Medium
🔍 API9:2023 — Improper Inventory Management
API Güvenliğinde Envanter Yönetiminin Kritik Rolü
⤷ Title: GitLab Patches High Runner Hijacking Flaw (CVE-2025-11702) and Multiple DoS Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 09:20:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #CVE_2025_11702 #dos #gitlab #Improper Access Control #Runner Hijacking #security patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 09:20:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #CVE_2025_11702 #dos #gitlab #Improper Access Control #Runner Hijacking #security patch
Daily CyberSecurity
GitLab Patches High Runner Hijacking Flaw (CVE-2025-11702) and Multiple DoS Vulnerabilities
GitLab patched a critical runner hijacking flaw (CVE-2025-11702) allowing authenticated users to compromise CI/CD pipelines, plus three unauthenticated DoS vulnerabilities.
⤷ Title: Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
Daily CyberSecurity
Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
Elastic patched a Critical EoP flaw (CVE-2025-37736) in ECE (v3.8.3/4.0.3) where the readonly user can create admin users and inject new API keys by bypassing authorization checks.
⤷ Title: Critical Dell Data Lakehouse Vulnerability (CVE-2025-46608) Allows Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:47:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_46608 #Dell Data Lakehouse #Improper Access Control #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:47:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_46608 #Dell Data Lakehouse #Improper Access Control #privilege escalation
Daily CyberSecurity
Critical Dell Data Lakehouse Vulnerability (CVE-2025-46608) Allows Privilege Escalation
Dell patched a Critical (CVSS 9.1) flaw (CVE-2025-46608) in Dell Data Lakehouse that allows a high-privileged remote attacker to escalate privileges and gain unauthorized administrative control. Update to v1.6.0.0.
⤷ Title: 2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
Medium
2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
Hello Hackers 👋
⤷ Title: Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 01:35:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_35616 #Enterprise Security #exploited in the wild #FortiClient EMS #Fortinet #Hotfix #Improper Access Control #infosec #rce #security patch #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 01:35:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_35616 #Enterprise Security #exploited in the wild #FortiClient EMS #Fortinet #Hotfix #Improper Access Control #infosec #rce #security patch #zero_day
Daily CyberSecurity
Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
Security teams are on high alert as Fortinet confirms that a critical vulnerability in its FortiClient EMS (Endpoint Management Server) is currently being leveraged by attackers in active campaign…
⤷ Title: Bug Bounty Journey — Valid Report Part 11
════════════════════════
𐀪 Author: 0xF3r4t
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 18:58:02 GMT
════════════════════════
⌗ Tags: #web_application_security #bug_bounty #improper_access_control #intigriti
════════════════════════
𐀪 Author: 0xF3r4t
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 18:58:02 GMT
════════════════════════
⌗ Tags: #web_application_security #bug_bounty #improper_access_control #intigriti
Medium
Bug Bounty Journey — Valid Report Part 11
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities. 😊…
⤷ Title: How a Throwaway Email Walked Me Into Someone Else’s Tenant — Unauthorized PII Information Access
════════════════════════
𐀪 Author: Thamotharan Vajramani
════════════════════════
ⴵ Time: Wed, 20 May 2026 16:41:42 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #unauthorized_access #improper_access_control #bug_bounty
════════════════════════
𐀪 Author: Thamotharan Vajramani
════════════════════════
ⴵ Time: Wed, 20 May 2026 16:41:42 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #unauthorized_access #improper_access_control #bug_bounty
Medium
How a Throwaway Email Walked Me Into Someone Else’s Tenant — Unauthorized PII Information Access
By Thamotharan Vajramani