⤷ Title: How I pwned a production app from the dev playground
════════════════════════
𐀪 Author: Abdullah Hammad
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 10:27:37 GMT
════════════════════════
⌗ Tags: #broken_access_control #cybersecurity #account_takeover #pentesting #penetration_testing
════════════════════════
𐀪 Author: Abdullah Hammad
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 10:27:37 GMT
════════════════════════
⌗ Tags: #broken_access_control #cybersecurity #account_takeover #pentesting #penetration_testing
Medium
How I pwned a production app from the dev playground
The simple chain that turned a dev user into a production account takeover.
⤷ Title: Building a Vulnerable Active Directory Lab for Penetration Testing: A Practical Walkthrough
════════════════════════
𐀪 Author: Beri Contraster
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 10:17:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #active_directory #windows_security #penetration_testing
════════════════════════
𐀪 Author: Beri Contraster
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 10:17:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #active_directory #windows_security #penetration_testing
Medium
Building a Vulnerable Active Directory Lab for Penetration Testing: A Practical Walkthrough
Why You Should Learn Active Directory
⤷ Title: Tryhackme — Moniker Link (CVE-2024–21413)
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 11:12:13 GMT
════════════════════════
⌗ Tags: #moniker_link #tryhackmemonikerlink #cve_202421413 #tryhackme
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 11:12:13 GMT
════════════════════════
⌗ Tags: #moniker_link #tryhackmemonikerlink #cve_202421413 #tryhackme
Medium
Tryhackme — Moniker Link (CVE-2024–21413)
Task 1 — Introduction
⤷ Title: Lab 4: DOM XSS in `innerHTML` Sink Using Source `location.search`
════════════════════════
𐀪 Author: Apexium Technologies Ltd
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 11:03:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking #xss_attack
════════════════════════
𐀪 Author: Apexium Technologies Ltd
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 11:03:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking #xss_attack
Medium
Lab 4: DOM XSS in `innerHTML` Sink Using Source `location.search`
A DOM-based XSS vulnerability was found where the app inserts location.search into the page using innerHTML without sanitization. By…
⤷ Title: Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 18:34:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 18:34:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SAP Pushes Emergency Patch for 9.9 Rated CVE-2025-42887 After Full Takeover Risk
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:10:24 +0000
════════════════════════
⌗ Tags: #Security #Cybersecurity #Microsoft #SAP #SecurityBridge #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:10:24 +0000
════════════════════════
⌗ Tags: #Security #Cybersecurity #Microsoft #SAP #SecurityBridge #Vulnerability
Hackread
SAP Pushes Emergency Patch for 9.9 Rated CVE-2025-42887 After Full Takeover Risk
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Top 3 Malware Families in Q4: How to Keep Your SOC Ready
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 12:05:34 +0000
════════════════════════
⌗ Tags: #Malware #Security #Agent Tesla #ANY RUN #Cybersecurity #Lumma Stealer #SOC #Threat Intelligence #Vulnerability #XWorm
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 12:05:34 +0000
════════════════════════
⌗ Tags: #Malware #Security #Agent Tesla #ANY RUN #Cybersecurity #Lumma Stealer #SOC #Threat Intelligence #Vulnerability #XWorm
Hackread
Top 3 Malware Families in Q4: How to Keep Your SOC Ready
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: When Among Us Meets Academia: An OSINT Challenge That’s Not Sus At All | v1t CTF OSINT Challenge
════════════════════════
𐀪 Author: Chetan Chinchulkar
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:39:32 GMT
════════════════════════
⌗ Tags: #infosec #ctf #osint #ctf_writeup #bug_bounty
════════════════════════
𐀪 Author: Chetan Chinchulkar
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:39:32 GMT
════════════════════════
⌗ Tags: #infosec #ctf #osint #ctf_writeup #bug_bounty
Medium
When Among Us Meets Academia: An OSINT Challenge That’s Not Sus At All | v1t CTF OSINT Challenge
Finding university acronyms in the most unexpected places
⤷ Title: Privilege Escalation From Guest To Admin
════════════════════════
𐀪 Author: Mado
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:35:37 GMT
════════════════════════
⌗ Tags: #bug_bounty #privilege_escalation #hacking #bug_bounty_tips #infosec
════════════════════════
𐀪 Author: Mado
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:35:37 GMT
════════════════════════
⌗ Tags: #bug_bounty #privilege_escalation #hacking #bug_bounty_tips #infosec
Medium
Privilege Escalation From Guest To Admin👑
Privilege Escalation Guest user escalates To full project access after project visibility is switched to Public
⤷ Title: CORS Vulnerability with Trusted Null Origin
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:34:10 GMT
════════════════════════
⌗ Tags: #cors_attack #bug_bounty #cors_exploit #null_origin_attack #cors_misconfiguration
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:34:10 GMT
════════════════════════
⌗ Tags: #cors_attack #bug_bounty #cors_exploit #null_origin_attack #cors_misconfiguration
Medium
CORS Vulnerability with Trusted Null Origin
Discover how a simple CORS misconfiguration can leak sensitive data across origins.
⤷ Title: CORS Vulnerability with Trusted Insecure Protocols
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:27:49 GMT
════════════════════════
⌗ Tags: #cors_misconfiguration #cors_vulnerability #cors_bypass #bug_bounty #cors_exploit
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:27:49 GMT
════════════════════════
⌗ Tags: #cors_misconfiguration #cors_vulnerability #cors_bypass #bug_bounty #cors_exploit
Medium
CORS Vulnerability with Trusted Insecure Protocols
Understanding how insecure CORS configurations can expose sensitive data across subdomains.
⤷ Title: How to Find P1 Bugs using Google in your Target — (Part-2)
════════════════════════
𐀪 Author: RivuDon
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:27:14 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #bug_bounty_writeup #bug_bounty_tips #infosec
════════════════════════
𐀪 Author: RivuDon
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:27:14 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #bug_bounty_writeup #bug_bounty_tips #infosec
Medium
How to Find P1 Bugs using Google in your Target — (Part-2)
Earn rewards with this simple method.
⤷ Title: I Could Change Anyone’s Email Preferences — Without Logging In
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:20:57 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty #cybersecurity #hacking #inspiration
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:20:57 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty #cybersecurity #hacking #inspiration
Medium
I Could Change Anyone’s Email Preferences — Without Logging In 😳
How a single overlooked API made every user’s inbox mine to control — and how a second endpoint let me confirm it instantly. BOOM.
⤷ Title: How I Found a Reflected XSS Using ParamSpider & Kxss
════════════════════════
𐀪 Author: mohamed metwally
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:54:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #hacking #xss_attack #bug_bounty
════════════════════════
𐀪 Author: mohamed metwally
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:54:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #hacking #xss_attack #bug_bounty
Medium
How I Found a Reflected XSS Using ParamSpider & Kxss
بسم الله الرحمن الرحيم والحمد لله رب العالمين، والصلاة والسلام على أشرف الأنبياء والمرسلين، نبيّنا محمد وعلى آله وصحبه أجمعين.
⤷ Title: When Among Us Meets Academia: An OSINT Challenge That’s Not Sus At All | v1t CTF OSINT Challenge
════════════════════════
𐀪 Author: Chetan Chinchulkar
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:39:31 GMT
════════════════════════
⌗ Tags: #infosec #ctf #osint #ctf_writeup #bug_bounty
════════════════════════
𐀪 Author: Chetan Chinchulkar
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:39:31 GMT
════════════════════════
⌗ Tags: #infosec #ctf #osint #ctf_writeup #bug_bounty
Medium
When Among Us Meets Academia: An OSINT Challenge That’s Not Sus At All | v1t CTF OSINT Challenge
Finding university acronyms in the most unexpected places
⤷ Title: How I Found a 0-Click Flaw That Compromised Any Account
════════════════════════
𐀪 Author: Ibtissam
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:32:04 GMT
════════════════════════
⌗ Tags: #ethical_hacking #vulnerability #bug_bounty #web_security #cybersecurity
════════════════════════
𐀪 Author: Ibtissam
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:32:04 GMT
════════════════════════
⌗ Tags: #ethical_hacking #vulnerability #bug_bounty #web_security #cybersecurity
Medium
How I Found a 0-Click Flaw That Compromised Any Account
The 302 Redirect response stared back at me from the screen, and for a second, my heart seemed to stop.
⤷ Title: How to Find P1 Bugs using Google in your Target — (Part-2)
════════════════════════
𐀪 Author: RivuDon
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:27:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #bug_bounty_writeup #bug_bounty_tips #infosec
════════════════════════
𐀪 Author: RivuDon
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:27:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #bug_bounty_writeup #bug_bounty_tips #infosec
Medium
How to Find P1 Bugs using Google in your Target — (Part-2)
Earn rewards with this simple method.
⤷ Title: I Could Change Anyone’s Email Preferences — Without Logging In
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:20:56 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty #cybersecurity #hacking #inspiration
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:20:56 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty #cybersecurity #hacking #inspiration
Medium
I Could Change Anyone’s Email Preferences — Without Logging In 😳
How a single overlooked API made every user’s inbox mine to control — and how a second endpoint let me confirm it instantly. BOOM.
⤷ Title: The Code You Didn’t Write: How Transitive Dependencies Became Your Greatest Security Liability
════════════════════════
𐀪 Author: Patrick Lefler
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 12:58:33 GMT
════════════════════════
⌗ Tags: #software_development #transitive_dependencies #application_security
════════════════════════
𐀪 Author: Patrick Lefler
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 12:58:33 GMT
════════════════════════
⌗ Tags: #software_development #transitive_dependencies #application_security
Medium
The Code You Didn’t Write: How Transitive Dependencies Became Your Greatest Security Liability
When a developer types “npm install lodash” or “pip install requests,” they believe they’re adding a single, well-understood library to…
⤷ Title: Gallery — TryHackMe Walkthrough
════════════════════════
𐀪 Author: devmorav
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:57:53 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #ctf_writeup #hacking #tryhackme
════════════════════════
𐀪 Author: devmorav
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:57:53 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #ctf_writeup #hacking #tryhackme
Medium
Gallery — TryHackMe Walkthrough
Hello! Today, we will try to hack into the Gallery machine. Without further ado, let’s start machines and get to it!
⤷ Title: PortSwigger: Web LLM attacks LABS
════════════════════════
𐀪 Author: Abdelhamid Elbouz
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:39:07 GMT
════════════════════════
⌗ Tags: #portswigger #hacking #cybersecurity #llm #penetration_testing
════════════════════════
𐀪 Author: Abdelhamid Elbouz
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 13:39:07 GMT
════════════════════════
⌗ Tags: #portswigger #hacking #cybersecurity #llm #penetration_testing
Medium
PortSwigger: Web LLM attacks LABS
Lab: Exploiting LLM APIs with excessive agency