⤷ Title: Escalating a Blind Upload to RCE via Path Traversal into Cron and DNS-Restricted Callback Bypass
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:40:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #rce #bug_bounty_writeup #bug_bounty_tips #bugs
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:40:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #rce #bug_bounty_writeup #bug_bounty_tips #bugs
Medium
Escalating a Blind Upload to RCE via Path Traversal into Cron and DNS-Restricted Callback Bypass
1. Introduction
⤷ Title: Revisiting JWT Token Forgery Attack on Recent Bounty Target
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:25:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #jwt_exploitation #token #bug_bounty_writeup
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:25:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty #jwt_exploitation #token #bug_bounty_writeup
Medium
Revisiting JWT Token Forgery Attack on Recent Bounty Target
alg=none x Attacker-Controlled Object Check
⤷ Title: Shadow AI: The Breach Nobody Approved, Signed Off On, or Even Saw Coming
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:41:01 GMT
════════════════════════
⌗ Tags: #ai #bug_bounty_writeup #bug_bounty #security #cybersecurity
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:41:01 GMT
════════════════════════
⌗ Tags: #ai #bug_bounty_writeup #bug_bounty #security #cybersecurity
Medium
Shadow AI: The Breach Nobody Approved, Signed Off On, or Even Saw Coming
A developer at a mid-sized fintech company pasted a chunk of proprietary source code into a free AI chatbot last spring, just to get a…
⤷ Title: PortSwigger File Path Traversal Lab Solution, Simple Case
════════════════════════
𐀪 Author: Arham H.B
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:26:43 GMT
════════════════════════
⌗ Tags: #portswigger #portswigger_lab #web_security #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Arham H.B
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:26:43 GMT
════════════════════════
⌗ Tags: #portswigger #portswigger_lab #web_security #cybersecurity #bug_bounty
Medium
PortSwigger File Path Traversal Lab Solution, Simple Case
Web Security Academy by PortSwigger
⤷ Title: Client-Side Web Security Essentials
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:30:03 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #ethical_hacking #bug_hunter #web_pen_testing
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:30:03 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #ethical_hacking #bug_hunter #web_pen_testing
Medium
Client-Side Web Security Essentials
Modern web apps aren’t just “pages in a browser” — they’re interactive systems where the client (browser) and the server continuously…
⤷ Title: One IDOR, Three Leaks, $3K in Payouts
════════════════════════
𐀪 Author: Ferdus Alam
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:39:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #bug_bounty_hunter #bug_fixes
════════════════════════
𐀪 Author: Ferdus Alam
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:39:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #bug_bounty_tips #bug_bounty_hunter #bug_fixes
Medium
One IDOR, Three Leaks, $3K in Payouts
A single access-control mistake across multiple sharing APIs turned into three accepted reports – and three payouts.
⤷ Title: Dorks that could get you a good bounty in 2026
════════════════════════
𐀪 Author: Deepanshu Deep
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #google_dorking #web_security #osint
════════════════════════
𐀪 Author: Deepanshu Deep
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #google_dorking #web_security #osint
Medium
Dorks that could get you a good bounty in 2026
Google can index far more than publicly intended webpages. During an authorized bug bounty assessment, search operators can help…
⤷ Title: How I Systematically Find SQL Injection Bugs in Bug Bounty Programs (Step-by-Step Method)
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:00:40 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bugs #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: b0dj0x
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:00:40 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bugs #bug_bounty_writeup #bug_bounty
Medium
How I Systematically Find SQL Injection Bugs in Bug Bounty Programs (Step-by-Step Method)
SQLi is decades old and still one of the highest-paying bug classes in 2026 — here’s the exact recon-to-report process that actually finds…
⤷ Title: Got My First $$ Bug Bounty
════════════════════════
𐀪 Author: Prajwal
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 16:13:13 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #bug_bounty #web_security #bug_bounty_tips
════════════════════════
𐀪 Author: Prajwal
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 16:13:13 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #bug_bounty #web_security #bug_bounty_tips
Medium
Got My First $$ Bug Bounty 🎉
I finally got my first bug bounty.
⤷ Title: Bug Hunting #1
════════════════════════
𐀪 Author: the_phreak
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:50:43 GMT
════════════════════════
⌗ Tags: #pentesting #mobile_pentesting #bug_bounty #pentest
════════════════════════
𐀪 Author: the_phreak
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:50:43 GMT
════════════════════════
⌗ Tags: #pentesting #mobile_pentesting #bug_bounty #pentest
Medium
Bug Hunting #1
Hello everyone,