⤷ Title: Common Sensitive Files You Should Look For During Web Recon
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 19:17:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #javascript #technology #hacking
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 19:17:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #javascript #technology #hacking
Medium
Common Sensitive Files You Should Look For During Web Recon
A beginner-friendly guide to finding publicly accessible files that can reveal valuable information during bug bounty reconnaissance.
⤷ Title: A Browser-Visible API Key Is Evidence, Not a Verdict
════════════════════════
𐀪 Author: Lars at Veristria
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 10:32:33 GMT
════════════════════════
⌗ Tags: #javascript #incident_response #cybersecurity #api_security #devsecops
════════════════════════
𐀪 Author: Lars at Veristria
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 10:32:33 GMT
════════════════════════
⌗ Tags: #javascript #incident_response #cybersecurity #api_security #devsecops
Medium
A Browser-Visible API Key Is Evidence, Not a Verdict
How to separate intended public identifiers from real client-side secret exposure
⤷ Title: When JavaScript Gets Confused: A Look at Chrome’s V8 Vulnerabilities
════════════════════════
𐀪 Author: Fatima Zakir
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 22:04:20 GMT
════════════════════════
⌗ Tags: #javascript #vulnerability #technology #hacking #cybersecurity
════════════════════════
𐀪 Author: Fatima Zakir
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 22:04:20 GMT
════════════════════════
⌗ Tags: #javascript #vulnerability #technology #hacking #cybersecurity
Medium
When JavaScript Gets Confused: A Look at Chrome’s V8 Vulnerabilities
Let’s talk about CVE-2026–85046
⤷ Title: vm2’s Sandbox Just Failed for the Third Time This Week.
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
Medium
vm2’s Sandbox Just Failed for the Third Time This Week. A Million Weekly Downloads Are Still Running It
Three separate CVSS 10.0 sandbox escapes landed days apart — in a library that was declared dead once already
⤷ Title: I Found an Unauthenticated XSS in a WordPress Hotel Plugin — Then Someone Beat Me to It by a Week
════════════════════════
𐀪 Author: Mr Abdullah
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 07:47:00 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #javascript #penetration_testing #bug_bounty #xss_attack
════════════════════════
𐀪 Author: Mr Abdullah
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 07:47:00 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #javascript #penetration_testing #bug_bounty #xss_attack
Medium
I Found an Unauthenticated XSS in a WordPress Hotel Plugin — Then Someone Beat Me to It by a Week
A reflected XSS in nd-booking, a display:none trap that fools most PoCs, and an honest look at what “duplicate” really means in bug bounty.
⤷ Title: Mastering Prototype Pollution: A Complete Walkthrough of PortSwigger Labs
════════════════════════
𐀪 Author: Bhanvararam choudhary
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 14:14:59 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #cybersecurity #prototype_pollution #web_security
════════════════════════
𐀪 Author: Bhanvararam choudhary
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 14:14:59 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #cybersecurity #prototype_pollution #web_security
Medium
Mastering Prototype Pollution: A Complete Walkthrough of PortSwigger Labs
From Client-Side DOM XSS to Server-Side RCE and Data Exfiltration — A deep dive into sources, gadgets, sinks, and bypassing flawed…
⤷ Title: Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 05:41:56 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #javascript #bug_bounty #ctf
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 05:41:56 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #javascript #bug_bounty #ctf
Medium
Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption
Introduction
⤷ Title: Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 04:10:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_102673 #CVE_2026_102674 #CVE_2026_102676 #desktop app security #Electron #Electron vulnerabilities #javascript #Sandbox Bypass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 04:10:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_102673 #CVE_2026_102674 #CVE_2026_102676 #desktop app security #Electron #Electron vulnerabilities #javascript #Sandbox Bypass
Daily CyberSecurity
Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
TL;DR Electron maintainers published five Electron vulnerabilities on September 29, 2026, all rated High, with CVSS scores from 7.4 to 8.3. Each flaw lets untrusted content escape a sandbox, an or…
⤷ Title: Moving YouTube Subscriptions Using Only the Browser Console and Poor Judgment
════════════════════════
𐀪 Author: Lokesh Kumar
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #javascript #ethical_hacking #youtube
════════════════════════
𐀪 Author: Lokesh Kumar
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #javascript #ethical_hacking #youtube
Medium
Moving YouTube Subscriptions Using Only the Browser Console and Poor Judgment
Reading time: 4 minutes. Regret time: ongoing.
⤷ Title: Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
Medium
Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
Java RMI (Remote Method Invocation) is a way for one Java application to ask another Java application on a different machine to perform a…