⤷ Title: Towel on the Sunbed — Tryhackme write-up
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 05:28:58 GMT
════════════════════════
⌗ Tags: #business_logic #burpsuite #tryhackme #web_hacking #api
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 05:28:58 GMT
════════════════════════
⌗ Tags: #business_logic #burpsuite #tryhackme #web_hacking #api
Medium
Towel on the Sunbed — Tryhackme write-up
Solution:
⤷ Title: API Testing Essentials: A Beginner’s Guide to Finding Bugs Before Users Do
════════════════════════
𐀪 Author: Jyotivarshney
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:52:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #software_engineering #api #software_testing #quality_assurance
════════════════════════
𐀪 Author: Jyotivarshney
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:52:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #software_engineering #api #software_testing #quality_assurance
Medium
API Testing Essentials: A Beginner’s Guide to Finding Bugs Before Users Do
Modern applications rely heavily on APIs to exchange data between clients, servers, and third-party services. While users interact with the…
⤷ Title: 7 JWT Authentication Mistakes I Keep Seeing in Production
════════════════════════
𐀪 Author: CodeX Lancers
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 08:31:01 GMT
════════════════════════
⌗ Tags: #software_development #cybersecurity #api_security #jwt #authentication
════════════════════════
𐀪 Author: CodeX Lancers
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 08:31:01 GMT
════════════════════════
⌗ Tags: #software_development #cybersecurity #api_security #jwt #authentication
Medium
🔐 7 JWT Authentication Mistakes I Keep Seeing in Production
JSON Web Tokens (JWTs) are one of the most popular authentication methods for modern web and mobile applications. Whether you’re building…
⤷ Title: Behind Every Great Rate Limiter: Choosing the Right Algorithm
════════════════════════
𐀪 Author: Gertrude Abagale
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 12:35:15 GMT
════════════════════════
⌗ Tags: #design_systems #secure_by_design #redis #api_security #distributed_systems
════════════════════════
𐀪 Author: Gertrude Abagale
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 12:35:15 GMT
════════════════════════
⌗ Tags: #design_systems #secure_by_design #redis #api_security #distributed_systems
Medium
Behind Every Great Rate Limiter: Choosing the Right Algorithm
In the first article, we explored why rate limiting is one of the most important security controls protecting modern applications. Now…
⤷ Title: Your Auth Middleware Is Too Late. Here’s What Should Run Before It.
════════════════════════
𐀪 Author: Yoosuf Husain
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:51:35 GMT
════════════════════════
⌗ Tags: #backend_development #api_security #engineering #nodejs #software_architecture
════════════════════════
𐀪 Author: Yoosuf Husain
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:51:35 GMT
════════════════════════
⌗ Tags: #backend_development #api_security #engineering #nodejs #software_architecture
Medium
Your Auth Middleware Is Too Late. Here’s What Should Run Before It.
Most Node.js apps have an auth middleware. You write a protect function, drop it on your routes and call it done. That works fine until you…
⤷ Title: IDOR with a $150 Bonus Just by Changing PATCH -> PUT
════════════════════════
𐀪 Author: Muhammad Wageh
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 18:51:13 GMT
════════════════════════
⌗ Tags: #api #hacking #cybersecurity
════════════════════════
𐀪 Author: Muhammad Wageh
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 18:51:13 GMT
════════════════════════
⌗ Tags: #api #hacking #cybersecurity
Medium
IDOR with a $150 Bonus Just by Changing PATCH -> PUT
In this SaaS application, the app is very complex, and I really love this type of application to test!
⤷ Title: Why Your API Can Still Crash Despite Rate Limiting: What Most Developers Miss
════════════════════════
𐀪 Author: Hafiz Muhammad Asad
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 15:53:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #backend_development #api_security #software_architecture #api_rate_limiting
════════════════════════
𐀪 Author: Hafiz Muhammad Asad
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 15:53:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #backend_development #api_security #software_architecture #api_rate_limiting
Medium
Why Your API Can Still Crash Despite Rate Limiting: What Most Developers Miss
Rate limiting is one of the first security mechanisms developers implement. Yet APIs still go down every day because modern attackers know…
⤷ Title: Locking the Front Door: How We Secured a Partner API Before Publishing It
════════════════════════
𐀪 Author: MUKKU CHANDRASEKHAR REDDY
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:45:26 GMT
════════════════════════
⌗ Tags: #azure #tlm #backend_development #api #api_security
════════════════════════
𐀪 Author: MUKKU CHANDRASEKHAR REDDY
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:45:26 GMT
════════════════════════
⌗ Tags: #azure #tlm #backend_development #api #api_security
Medium
Locking the Front Door: How We Secured a Partner API Before Publishing It
An internal API has an easy life. It sits inside a private network, and only our own services call it. Nobody outside the company can reach…
⤷ Title: Top 25 Website Security Misconfigurations (2026)
════════════════════════
𐀪 Author: Vaibhavk
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 04:35:18 GMT
════════════════════════
⌗ Tags: #api_security #ai_or_llm_security #sbom #website_misconfigurations #data_breach_response_plan
════════════════════════
𐀪 Author: Vaibhavk
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 04:35:18 GMT
════════════════════════
⌗ Tags: #api_security #ai_or_llm_security #sbom #website_misconfigurations #data_breach_response_plan
Medium
Top 25 Website Security Misconfigurations (2026)
Security misconfigurations remain the #1 most exploited vulnerability class — not because developers don’t care, but because modern web…
⤷ Title: Your API Is Not Your System
════════════════════════
𐀪 Author: Andrews Ferreira
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #application_security #offensive_security #api_security #threat_modeling #api_security_testing
════════════════════════
𐀪 Author: Andrews Ferreira
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #application_security #offensive_security #api_security #threat_modeling #api_security_testing
Medium
Your API Is Not Your System
Why attackers model workflows while engineers secure endpoints