⤷ Title: QR Codes from the Past: How an Archive Broke Two-Factor Auth
════════════════════════
𐀪 Author: Aayush kumar
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 16:13:51 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #bug_bounty_writeup #information_security #bug_bounty_tips
════════════════════════
𐀪 Author: Aayush kumar
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 16:13:51 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #bug_bounty_writeup #information_security #bug_bounty_tips
Medium
QR Codes from the Past: How an Archive Broke Two-Factor Auth
It was a quiet Tuesday evening, the kind of stillness that lets you hear the hum of your own machine.
⤷ Title: From “Meh, It’s Just Reflected XSS” to “Sh*t, I Own the CEO”
════════════════════════
𐀪 Author: Shah kaif
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 15:17:36 GMT
════════════════════════
⌗ Tags: #xss_attack #bug_bounty #bug_bounty_writeup #bug_bounty_tips #owasp_top_10
════════════════════════
𐀪 Author: Shah kaif
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 15:17:36 GMT
════════════════════════
⌗ Tags: #xss_attack #bug_bounty #bug_bounty_writeup #bug_bounty_tips #owasp_top_10
Medium
From “Meh, It’s Just Reflected XSS” to “Sh*t, I Own the CEO” 🎭
By Shah kaif | How I went from disappointment to shock in 30 minutes | LinkedIn
⤷ Title: ⚡ 3 Tricks to Hunt Bug Faster: Stop Wasting Time, Finding Smartly
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 13:23:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 13:23:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bug_bounty_tips #hacking
Medium
⚡ 3 Tricks to Hunt Bug Faster: Stop Wasting Time, Finding Smartly
Speed isn’t about typing faster. It’s about removing friction.
⤷ Title: NETFLIX Exposed Prometheus instance exposing internal metrics closed as duplicate leaks internal…
════════════════════════
𐀪 Author: Christoscoming
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 12:49:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_writeup #red_team #infosec_write_ups
════════════════════════
𐀪 Author: Christoscoming
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 12:49:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_bounty_writeup #red_team #infosec_write_ups
Medium
NETFLIX Exposed Prometheus instance exposing internal metrics closed as duplicate leaks internal…
[Netflix] Exposed Prometheus instance exposing internal metrics closed as duplicate leaks internal ip #BugBountyScam Internal monitoring leak via Prometheus UI closed as duplicate (Big lie) still …
⤷ Title: $600 Bounty: Stored XSS in Jira Service Desk Reports
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 04:09:02 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #penetration_testing #bug_bounty #bug_bounty_writeup #vulnerability
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 04:09:02 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #penetration_testing #bug_bounty #bug_bounty_writeup #vulnerability
Medium
$600 Bounty: Stored XSS in Jira Service Desk Reports
How a simple “Question” field turned into a Stored XSS that executed inside Jira’s admin reports
⤷ Title: Information Disclosure in Revive Adserver v6.0.0
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 04:07:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #technology #vulnerability #bug_bounty_writeup
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 04:07:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #technology #vulnerability #bug_bounty_writeup
Medium
Information Disclosure in Revive Adserver v6.0.0
A single quote was all it took for verbose PHP errors to reveal MySQL versions, SQL queries, and system secrets.
⤷ Title: How Newcomers Can Automate Vulnerability Finding In Bug Bounty Hunting?
════════════════════════
𐀪 Author: Rehan Sohail
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 17:07:02 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #activated_thinker #bug_bounty_hunter #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Rehan Sohail
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 17:07:02 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #activated_thinker #bug_bounty_hunter #bug_bounty_tips #bug_bounty
Medium
How Newcomers Can Automate Vulnerability Finding In Bug Bounty Hunting?
This is dedicated to beginner hunters. Pros may not benefit from this as much
⤷ Title: Workflow: speed up visual web based external exposure recon.
════════════════════════
𐀪 Author: biero llagas
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 16:40:00 GMT
════════════════════════
⌗ Tags: #shodan #recon #nucleus #cyber_physical_systems
════════════════════════
𐀪 Author: biero llagas
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 16:40:00 GMT
════════════════════════
⌗ Tags: #shodan #recon #nucleus #cyber_physical_systems
Medium
Workflow: speed up visual web based external exposure recon.
Foreword
⤷ Title: Reconciliation Software for Banks: Compliance and Risk Management
════════════════════════
𐀪 Author: Kosh AI
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 15:23:41 GMT
════════════════════════
⌗ Tags: #kosh_ai #reconciliation #data_reconciliation #bank_reconciliation #recon
════════════════════════
𐀪 Author: Kosh AI
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 15:23:41 GMT
════════════════════════
⌗ Tags: #kosh_ai #reconciliation #data_reconciliation #bank_reconciliation #recon
Medium
Reconciliation Software for Banks: Compliance and Risk Management
Imagine a giant, complex puzzle. Every single day, thousands of new pieces flood in from different sources — ATM transactions, digital…
⤷ Title: Recon Like a Hunter: Practical Tips from Real Findings Part 2
════════════════════════
𐀪 Author: Aya Ayman(GERR4Y)
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 22:08:48 GMT
════════════════════════
⌗ Tags: #recon #bug_bounty #github #information_disclosure
════════════════════════
𐀪 Author: Aya Ayman(GERR4Y)
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 22:08:48 GMT
════════════════════════
⌗ Tags: #recon #bug_bounty #github #information_disclosure
Medium
Recon Like a Hunter: Practical Tips from Real Findings Part 2
بسم الله والصلاة والسلام على رسول الله الحمد لله الذي علم بالقلم علم الإنسان ما لم يعلم والصلاة والسلام على خير معلم الناس الخير محمد
⤷ Title: [paypal] #3438886: PayPal’s official internal sandbox REST API client ID leaked in production…
════════════════════════
𐀪 Author: Christoscoming
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:06:44 GMT
════════════════════════
⌗ Tags: #red_team #cybersecurity #bugbounty_writeup #infosec_write_ups #bug_bounty
════════════════════════
𐀪 Author: Christoscoming
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:06:44 GMT
════════════════════════
⌗ Tags: #red_team #cybersecurity #bugbounty_writeup #infosec_write_ups #bug_bounty
Medium
[paypal] #3438886: PayPal’s official internal sandbox REST API client ID leaked in production…
[paypal] #3438886: PayPal’s official internal sandbox REST API client ID leaked in production closed as Informational and patched in 48 hours LEAKING IT ALL.. THEY CLOSED THE REPORT AND DONT EVEN …
⤷ Title: Bug Bounty Hunting — Complete Guide (Part-149)
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 06:54:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #bug_bounty_tips #cybersecurity #hacking
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 06:54:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #bug_bounty_tips #cybersecurity #hacking
Medium
Bug Bounty Hunting — Complete Guide (Part-149)
The Priority HTTP header is a mechanism for the client to express its preference for the urgency and incremental handling of a requested…
⤷ Title: Bug Bounty Hunting — Complete Guide (Part-148)
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 06:52:40 GMT
════════════════════════
⌗ Tags: #hacking #ethical_hacking #cybersecurity #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 06:52:40 GMT
════════════════════════
⌗ Tags: #hacking #ethical_hacking #cybersecurity #bug_bounty #bug_bounty_tips
Medium
Bug Bounty Hunting — Complete Guide (Part-148)
The Preference-Applied HTTP response header is used by the server to inform the client which of the preferences indicated in the client's…
⤷ Title: Most Common XSS Payloads
════════════════════════
𐀪 Author: Udeshna
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 18:44:29 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty_tips #cybersecurity #xss_payload #web_security
════════════════════════
𐀪 Author: Udeshna
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 18:44:29 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty_tips #cybersecurity #xss_payload #web_security
Medium
Most Common XSS Payloads
Cross-Site Scripting (XSS) is one of the most frequent vulnerabilities encounter when learning web security. In simple terms, XSS is when…
⤷ Title: $$$ How I Discovered a Business Logic Vulnerability That Allowed Price Manipulation Through…
════════════════════════
𐀪 Author: Zyad Ibrahim
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 17:33:06 GMT
════════════════════════
⌗ Tags: #programming #cybersecurity #bug_bounty #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Zyad Ibrahim
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 17:33:06 GMT
════════════════════════
⌗ Tags: #programming #cybersecurity #bug_bounty #bug_bounty_tips #hacking
Medium
$$$ How I Discovered a Business Logic Vulnerability That Allowed Price Manipulation Through Shipping Parameters
السلام عليكم ورحمة الله وبركاته
⤷ Title: How I Hacked an AI That Was Supposed to Be Hacking For Me ⚔️
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 15:11:31 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #infosec #cybersecurity #hacking #bug_bounty
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 15:11:31 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #infosec #cybersecurity #hacking #bug_bounty
Medium
How I Hacked an AI That Was Supposed to Be Hacking For Me 🤖⚔️
Free Link 🎈
⤷ Title: Critical node-forge Flaw (CVE-2025-12816) Allows Signature Verification Bypass via ASN.1 Manipulation (21M Downloads/Week)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 01:44:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASN.1 #Critical Vulnerability #cryptography #CVE_2025_12816 #node_forge #npm #Signature Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 01:44:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASN.1 #Critical Vulnerability #cryptography #CVE_2025_12816 #node_forge #npm #Signature Bypass
Daily CyberSecurity
Critical node-forge Flaw (CVE-2025-12816) Allows Signature Verification Bypass via ASN.1 Manipulation (21M Downloads/Week)
A Critical flaw (CVE-2025-12816) in node-forge allows attackers to bypass signature verification by manipulating ASN.1 structures. The vulnerability affects 21M+ weekly downloads. Update to v1.3.2.
⤷ Title: 8 Flaws: ASUS Routers Urgently Need Patch for Authentication Bypass (CVE-2025-59366, CVSS 9.4)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:20:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AiCloud #ASUS router #Authentication Bypass #Command Injection #CVE_2025_59366 #router security #sql injection #WebDAV
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:20:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AiCloud #ASUS router #Authentication Bypass #Command Injection #CVE_2025_59366 #router security #sql injection #WebDAV
Daily CyberSecurity
8 Flaws: ASUS Routers Urgently Need Patch for Authentication Bypass (CVE-2025-59366, CVSS 9.4)
ASUS fixes 8 severe router flaws, including a critical AiCloud authentication bypass (CVSS 9.4). Users must update firmware immediately to patch vulnerabilities.
⤷ Title: Zero-Detection RelayNFC Android Malware Turns Phones Into Remote Card Readers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:15:56 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Brazil #card fraud #mobile malware #NFC relay attack #phishing #React Native #RelayNFC #VirusTotal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:15:56 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Brazil #card fraud #mobile malware #NFC relay attack #phishing #React Native #RelayNFC #VirusTotal
Daily CyberSecurity
Zero-Detection RelayNFC Android Malware Turns Phones Into Remote Card Readers
RelayNFC is a new, zero-detection Android malware targeting Brazil that turns the victim's phone into a remote card reader to steal data and complete real-time contactless payments.
⤷ Title: ASUS LPE Flaw (CVE-2025-59373): High-Severity Bug Grants SYSTEM Privileges via MyASUS Component
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:15:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASUS #CVE_2025_59373 #Local Privilege Escalation #LPE #MyASUS #security advisory #SYSTEM access #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:15:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASUS #CVE_2025_59373 #Local Privilege Escalation #LPE #MyASUS #security advisory #SYSTEM access #windows
Daily CyberSecurity
ASUS LPE Flaw (CVE-2025-59373): High-Severity Bug Grants SYSTEM Privileges via MyASUS Component
ASUS urges users to patch a high-severity LPE flaw (CVE-2025-59373) in its System Control Interface Service, which allows low-privileged users to escalate to full SYSTEM control.
⤷ Title: Cameo Wins TRO Against OpenAI: Sora Barred From Using ‘Cameo’ Trademark
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:13:42 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cameo #Lawsuit #OpenAI #Sora #Temporary Restraining Order #trademark infringement #TRO #Video Generation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 00:13:42 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cameo #Lawsuit #OpenAI #Sora #Temporary Restraining Order #trademark infringement #TRO #Video Generation
Daily CyberSecurity
Cameo Wins TRO Against OpenAI: Sora Barred From Using ‘Cameo’ Trademark
Cameo won a TRO barring OpenAI from using the name ‘Cameo’ for a feature in its Sora app, citing trademark infringement. The ban is effective until the December 19 hearing.