⤷ Title: Business Logic Vulnerability Leading to Negative Cart Values and Massive Price Manipulation
════════════════════════
𐀪 Author: 0xKemzx
════════════════════════
ⴵ Time: Sun, 17 May 2026 19:43:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #security_research #information_security
════════════════════════
𐀪 Author: 0xKemzx
════════════════════════
ⴵ Time: Sun, 17 May 2026 19:43:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #security_research #information_security
Medium
Business Logic Vulnerability Leading to Negative Cart Values and Massive Price Manipulation
اللهم صل وسلم وبارك علي نبينا محمد
⤷ Title: Two Signatures, One Nonce, Zero Secrets: A FROST Crypto Bug Story
════════════════════════
𐀪 Author: TrffnSec
════════════════════════
ⴵ Time: Sat, 23 May 2026 12:17:56 GMT
════════════════════════
⌗ Tags: #security_research #bug_bounty #web3_security #cryptography #cybersecurity
════════════════════════
𐀪 Author: TrffnSec
════════════════════════
ⴵ Time: Sat, 23 May 2026 12:17:56 GMT
════════════════════════
⌗ Tags: #security_research #bug_bounty #web3_security #cryptography #cybersecurity
Medium
Two Signatures, One Nonce, Zero Secrets: A FROST Crypto Bug Story
This is a sanitized technical writeup based on a responsibly disclosed and resolved bug bounty report. Vendor-identifying details, exact…
⤷ Title: How I Hacked a Live Chatbot and Earned My First $$$$ (4-Digit) Bounty
════════════════════════
𐀪 Author: Mahbubur Rahman Soraf
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 04:52:33 GMT
════════════════════════
⌗ Tags: #security_research #ethical_hacking #information_security #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Mahbubur Rahman Soraf
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 04:52:33 GMT
════════════════════════
⌗ Tags: #security_research #ethical_hacking #information_security #cybersecurity #bug_bounty
Medium
How I Hacked a Live Chatbot and Earned My First $$$$ (4-Digit) Bounty
Assalamu Alaikum. I’m Mahbubur Rahman Soraf, a part-time bug bounty hunter from Bangladesh.
⤷ Title: From CVE Matching to Exploit Validation: How Vulnerability Scanners Are Evolving
════════════════════════
𐀪 Author: Pyshawon
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 14:55:20 GMT
════════════════════════
⌗ Tags: #security_researchers #security_research #cybersecurity #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Pyshawon
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 14:55:20 GMT
════════════════════════
⌗ Tags: #security_researchers #security_research #cybersecurity #bug_bounty_tips #bug_bounty
Medium
From CVE Matching to Exploit Validation: How Vulnerability Scanners Are Evolving
I’ve been integrating OnScanner into my workflow recently as part of external security assessment and bug bounty reconnaissance, and it…
⤷ Title: When “Typically Identical to Production” Isn’t Enough
════════════════════════
𐀪 Author: PaulHaykeens
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 06:11:00 GMT
════════════════════════
⌗ Tags: #security_research #ethical_hacking #hackerone #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: PaulHaykeens
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 06:11:00 GMT
════════════════════════
⌗ Tags: #security_research #ethical_hacking #hackerone #bug_bounty #cybersecurity
Medium
When “Typically Identical to Production” Isn’t Enough
A bug bounty story about account ownership, asset-transfer impact, and the Informative closure that never quite explained itself.
⤷ Title: The AI Attack Surface in 2026 Is Larger Than Most Defenders Realize
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #security_research #ethical_hacking #penetration_testing #hacking
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 13:56:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #security_research #ethical_hacking #penetration_testing #hacking
Medium
The AI Attack Surface in 2026 Is Larger Than Most Defenders Realize
Bug bounty hunters are still writing XSS reports. Meanwhile, the LLMs running enterprise workflows are accepting arbitrary instructions…
⤷ Title: I Wrote 30 Lines of C and Watched My CPU Leak Secrets
════════════════════════
𐀪 Author: ZarxhNebula
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 14:43:11 GMT
════════════════════════
⌗ Tags: #programming #computer_architecture #hacking #cybersecurity #security_research
════════════════════════
𐀪 Author: ZarxhNebula
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 14:43:11 GMT
════════════════════════
⌗ Tags: #programming #computer_architecture #hacking #cybersecurity #security_research
Medium
I Wrote 30 Lines of C and Watched My CPU Leak Secrets
I spent my day measuring how many CPU cycles it takes to fetch a single byte from memory.
⤷ Title: Unauthenticated IDOR on NASA’s GitLab Instance — From Recon to Bypass
════════════════════════
𐀪 Author: Ghaddarittoo
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:57:29 GMT
════════════════════════
⌗ Tags: #nasa #bug_bounty #security_research #bugcrowd #broken_access_control
════════════════════════
𐀪 Author: Ghaddarittoo
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:57:29 GMT
════════════════════════
⌗ Tags: #nasa #bug_bounty #security_research #bugcrowd #broken_access_control
Medium
Unauthenticated IDOR on NASA’s GitLab Instance — From Recon to Bypass
Target: gitlab.smce.nasa.gov Program: NASA VDP (Bugcrowd) Severity: P3 — Broken Access Control / IDOR Status: Resolved
⤷ Title: The MFA Bypass That Wasn’t an MFA Problem: A Lesson in Broken API Authorization
════════════════════════
𐀪 Author: Hangga Aji Sayekti
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 01:29:56 GMT
════════════════════════
⌗ Tags: #mfa_bypass #bug_bounty_writeup #security_research #hacking #bug_bounty
════════════════════════
𐀪 Author: Hangga Aji Sayekti
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 01:29:56 GMT
════════════════════════
⌗ Tags: #mfa_bypass #bug_bounty_writeup #security_research #hacking #bug_bounty
Medium
The MFA Bypass That Wasn’t an MFA Problem: A Lesson in Broken API Authorization
A bug bounty story about frontend trust, missing backend enforcement, and why attackers never use your UI.
⤷ Title: I Opened a Settings Page… and Found Everyone’s Personal Data Sitting Behind a URL
════════════════════════
𐀪 Author: Kanishkdadhich
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:51:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #piiexposure #appsec #broken_access_control #security_research
════════════════════════
𐀪 Author: Kanishkdadhich
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:51:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #piiexposure #appsec #broken_access_control #security_research
Medium
I Opened a Settings Page… and Found Everyone’s Personal Data Sitting Behind a URL
I Opened a Settings Page… and Found Everyone’s Personal Data Sitting Behind a URL