⤷ Title: How I Got My Highest Payout
════════════════════════
𐀪 Author: Adhamkhairy
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 21:01:01 GMT
════════════════════════
⌗ Tags: #pentesting #security #bug_bounty #hackerone #cybersecurity
════════════════════════
𐀪 Author: Adhamkhairy
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 21:01:01 GMT
════════════════════════
⌗ Tags: #pentesting #security #bug_bounty #hackerone #cybersecurity
Medium
How I Got My Highest Payout
The target was an application portal. You register, you fill out a genuinely ENORMOUS form, and at the end it generates a PDF of everything…
⤷ Title: When the Lock Comes With the Key: Bypassing Client-Side Encryption to Find an IDOR
════════════════════════
𐀪 Author: Jobson
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 09:54:18 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #penetration_testing #hacking #pentesting
════════════════════════
𐀪 Author: Jobson
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 09:54:18 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #penetration_testing #hacking #pentesting
Medium
When the Lock Comes With the Key: Bypassing Client-Side Encryption to Find an IDOR
Hello world, this write-up covers an interesting IDOR vulnerability I discovered during a web application security assessment. What made…
⤷ Title: Introducing Pathfinder: An Open-Source CLI for Organizing Reconnaissance URLs
════════════════════════
𐀪 Author: Akshatshirsat
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 09:03:56 GMT
════════════════════════
⌗ Tags: #bug_bounty #reconnaissance #pentesting #security #osint
════════════════════════
𐀪 Author: Akshatshirsat
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 09:03:56 GMT
════════════════════════
⌗ Tags: #bug_bounty #reconnaissance #pentesting #security #osint
Medium
Introducing Pathfinder: An Open-Source CLI for Organizing Reconnaissance URLs
Every penetration tester and bug bounty hunter eventually runs into the same problem.
⤷ Title: Subdomain Enumeration Master Guide
════════════════════════
𐀪 Author: Mohamed Algabry
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 08:54:17 GMT
════════════════════════
⌗ Tags: #subdomains_enumeration #pentesting #scanning_enumeration #bug_bounty_tips #cheatsheet
════════════════════════
𐀪 Author: Mohamed Algabry
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 08:54:17 GMT
════════════════════════
⌗ Tags: #subdomains_enumeration #pentesting #scanning_enumeration #bug_bounty_tips #cheatsheet
Medium
Subdomain Enumeration Master Guide
Complete Cheat Sheet for Bug Bounty & Pentesting
⤷ Title: Authenticated API & SSO Penetration Testing at Machine Speed
════════════════════════
𐀪 Author: Ivan Vereshchaha
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 12:17:29 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_penetration_testing #cybersecurity #pentesting #cyber_security_awareness
════════════════════════
𐀪 Author: Ivan Vereshchaha
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 12:17:29 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_penetration_testing #cybersecurity #pentesting #cyber_security_awareness
Medium
Authenticated API & SSO Penetration Testing at Machine Speed
The market challenge
⤷ Title: The Visma Case Study Part 3 Cross Account State Manipulation and Administrative Bypass
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 19:51:01 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #hacking #pentesting #bug_bounty
════════════════════════
𐀪 Author: Jawad Momani
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 19:51:01 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #hacking #pentesting #bug_bounty
Medium
The Visma Case Study Part 3 Cross Account State Manipulation and Administrative Bypass
In my previous disclosures I talked about how Visma and Intigriti turned critical data leaks into a normal day at the office and completely…
⤷ Title: AMSI Write Raid
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 02 Aug 2026 20:28:26 GMT
════════════════════════
⌗ Tags: #hacking #infosec #pentesting #cybersecurity #malware
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 02 Aug 2026 20:28:26 GMT
════════════════════════
⌗ Tags: #hacking #infosec #pentesting #cybersecurity #malware
Medium
AMSI Write Raid
Welcome to this new Medium post, in this one we will see a remote process AMSI bypass that does not touch AmsiScanBuffer directly. Instead…
⤷ Title: TryHackMe Guided Pentest Web Writeup — Real-World VAPT Methodology
════════════════════════
𐀪 Author: Arc3mis
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 09:11:44 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #vapt #tryhackme #web_security
════════════════════════
𐀪 Author: Arc3mis
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 09:11:44 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #vapt #tryhackme #web_security
Medium
TryHackMe Guided Pentest Web Writeup — Real-World VAPT Methodology
Room: https://tryhackme.com/room/guidedpentestweb
⤷ Title: Bug Bounty #1 — Que tester sur une application web avant même de créer un compte ?
════════════════════════
𐀪 Author: gngoma
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 01:05:15 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #offensive_security
════════════════════════
𐀪 Author: gngoma
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 01:05:15 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #offensive_security
⤷ Title: Skills Assessment — Password Attacks HackTheBox
════════════════════════
𐀪 Author: Cajebo
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 08:28:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox_writeup #password_security #pentesting
════════════════════════
𐀪 Author: Cajebo
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 08:28:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox_writeup #password_security #pentesting
Medium
Skills Assessment — Password Attacks HackTheBox
#Contexte: Betty Jayde works at Nexura LLC. We know she uses the password Texas123!@# on multiple websites, and we believe she may reuse it…