⤷ Title: Deserialization for Hackers: How Server Logic Gets Hijacked
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
ⴵ Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
════════════════════════
𐀪 Author: Adwait Gaikwad
════════════════════════
ⴵ Time: Sat, 06 Dec 2025 21:27:58 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #json_deserialization #react2shell #javascript_object #deserialization
Medium
Deserialization for Hackers: How Server Logic Gets Hijacked
Hello everyone! Have you ever sent a JSON object to a server and thought, “It’s just data”?
Most of us do. We use JSON every day without…
Most of us do. We use JSON every day without…
⤷ Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Daily CyberSecurity
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
Apache NiFi patches a High-severity flaw (CVE-2025-66524) in the GetAsanaObject processor. Unfiltered deserialization risks system compromise. Update now!
⤷ Title: Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
════════════════════════
𐀪 Author: Sakibul Ali Khan
════════════════════════
ⴵ Time: Sat, 24 Jan 2026 19:34:56 GMT
════════════════════════
⌗ Tags: #cve_2025_68271 #buet_ctf_2026_preliminary #json_rpc_api #openc3_cosmos #rce
Medium
Smart Home (BUET CTF 2026 Preliminary) — Pre-Auth RCE via eval in a JSON-RPC “command” API |…
Greetings, fellow cybersecurity enthusiasts and CTF players! In this writeup, we’ll walk through the solution of the “Smart Home” web…
⤷ Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 11:44:57 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
Medium
4. Prototype Pollution: One JSON Key That Turns You into Admin
If you’ve ever seen a payload like this and ignored it:-
⤷ Title: HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 03:54:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2026_25639 #Denial of Service #HTTP Client #JavaScript Security #JSON Parsing #Node.js #Patch Alert #Prototype Pollution #web development
Daily CyberSecurity
HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
A high-severity vulnerability has been discovered in Axios, the immensely popular HTTP client used by millions of developers for Node.js and browser-based applications. The flaw, tracked as CVE-20…
⤷ Title: 4. Prototype Pollution: One JSON Key That Turns You into Admin
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 07:04:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #json #bug_bounty_tips #hacking
Medium
4. Prototype Pollution: One JSON Key That Turns You into Admin
If you’ve ever seen a payload like this and ignored it:-
⤷ Title: Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the “End-of-Life” Security Gap
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
⌗ Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Feb 2026 16:10:28 +0000
════════════════════════
⌗ Tags: #Information Security #BOD 26_02 #CISA #CSAF #cybersecurity compliance #End of Life #EOL security #JSON schema #OpenEoX #perimeter defense #SBOM #Tech News 2026
Penetration Testing Tools
Ghosted No More: CISA Unleashes BOD 26-02 and OpenEoX to Kill the "End-of-Life" Security Gap
The proliferation of “abandoned” technologies at the periphery of corporate networks has increasingly evolved into an auspicious point
⤷ Title: JSON.parse(JSON.stringify()) VS structuredClone()
════════════════════════
𐀪 Author: Gutu Galuppo
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 11:43:49 GMT
════════════════════════
⌗ Tags: #hacking #javascript #json #json_stringify #object_oriented
════════════════════════
𐀪 Author: Gutu Galuppo
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 11:43:49 GMT
════════════════════════
⌗ Tags: #hacking #javascript #json #json_stringify #object_oriented
Medium
JSON.parse(JSON.stringify()) VS structuredClone()
A forma certa (e a forma gambiarra) de clonar objetos em JavaScript
⤷ Title: JSON Injection: The Silent API Killer You’re Probably Ignoring
════════════════════════
𐀪 Author: Tejas Shirsat
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 16:14:58 GMT
════════════════════════
⌗ Tags: #json #appsec #api_security #cybersecurity
════════════════════════
𐀪 Author: Tejas Shirsat
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 16:14:58 GMT
════════════════════════
⌗ Tags: #json #appsec #api_security #cybersecurity
Medium
JSON Injection: The Silent API Killer You’re Probably Ignoring
We’ve spent a decade obsessing over SQL Injection and XSS. We’ve sanitized our database queries and escaped our HTML. But while we were…
⤷ Title: Top Technology Stacks for MVP Development in 2026
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 13:53:40 +0000
════════════════════════
⌗ Tags: #Technology #API #Developers #Freshcode #javascript #JSON #MVP #React
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 13:53:40 +0000
════════════════════════
⌗ Tags: #Technology #API #Developers #Freshcode #javascript #JSON #MVP #React
Hackread
Top Technology Stacks for MVP Development in 2026
Top technology stacks for MVP development in 2026, best tools for fast launch, scalability, cost efficiency, and proven frameworks for startups building products.
⤷ Title: Unsafe Deserialization in Ruby Background Workers Leading to Deterministic Remote Code Execution
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:57:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup #json #bug_bounty #ruby
════════════════════════
𐀪 Author: NullSecurityX
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 16:57:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup #json #bug_bounty #ruby
Medium
Unsafe Deserialization in Ruby Background Workers Leading to Deterministic Remote Code Execution
Object Injection via Oj.load Allows Command Execution in RubitMQ Job Workers
⤷ Title: Critical 10.0 CVSS Flaw in pac4j-jwt Lets Hackers Forge Admin Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 02:00:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CodeAnt AI #CVE_2026_29000 #CVSS 10.0 #infosec #Java security #JSON Web Tokens #JWT Security #pac4j_jwt #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 02:00:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CodeAnt AI #CVE_2026_29000 #CVSS 10.0 #infosec #Java security #JSON Web Tokens #JWT Security #pac4j_jwt #Vulnerability
Daily CyberSecurity
Critical 10.0 CVSS Flaw in pac4j-jwt Lets Hackers Forge Admin Tokens
A critical 10.0 CVSS flaw (CVE-2026-29000) in the pac4j-jwt library allows attackers to forge JWTs and bypass authentication. Patch immediately.
⤷ Title: The Null-Signature Trap: Unmasking the 10.0 CVSS Authentication Bypass in pac4j-jwt
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 08:13:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication bypass #CodeAnt AI #CVE_2026_29000 #identity theft #Java security #JSON Web Encryption #JWE #JWT #pac4j_jwt #RSA #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 08:13:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication bypass #CodeAnt AI #CVE_2026_29000 #identity theft #Java security #JSON Web Encryption #JWE #JWT #pac4j_jwt #RSA #Tech News 2026
Penetration Testing Tools
The Null-Signature Trap: Unmasking the 10.0 CVSS Authentication Bypass in pac4j-jwt
A critical vulnerability has been unearthed within the widely utilized Java authentication library, pac4j-jwt, empowering a malicious actor
⤷ Title: Couch (THM) Tryhackme WriteUp And Answer
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Sun, 15 Mar 2026 03:36:42 GMT
════════════════════════
⌗ Tags: #ctf_writeup #json #cybersecurity #hacking #tryhackme
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Sun, 15 Mar 2026 03:36:42 GMT
════════════════════════
⌗ Tags: #ctf_writeup #json #cybersecurity #hacking #tryhackme
Medium
Couch (THM) Tryhackme WriteUp And Answer
Description : Hack into a vulnerable database server that collects and stores data in JSON-based document formats, in this semi-guided…
⤷ Title: How JWT Authentication Actually Works (Step-by-Step Guide)
════════════════════════
𐀪 Author: Santhosh Kumar
════════════════════════
ⴵ Time: Sat, 11 Apr 2026 07:05:31 GMT
════════════════════════
⌗ Tags: #web_security #json_web_token #jwt_authentication #stateless_authentication #application_security
════════════════════════
𐀪 Author: Santhosh Kumar
════════════════════════
ⴵ Time: Sat, 11 Apr 2026 07:05:31 GMT
════════════════════════
⌗ Tags: #web_security #json_web_token #jwt_authentication #stateless_authentication #application_security
Medium
How JWT Authentication Actually Works (Step-by-Step Guide)
Authentication is everywhere, from logging into your email to accessing APIs. One of the most popular modern methods is JWT (JSON Web…
⤷ Title: JWT Attacks You Should Know (Beyond the Basics)
════════════════════════
𐀪 Author: Santhosh Kumar
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 15:58:40 GMT
════════════════════════
⌗ Tags: #web_application_security #security #json_web_token #jwt_authentication #hacking
════════════════════════
𐀪 Author: Santhosh Kumar
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 15:58:40 GMT
════════════════════════
⌗ Tags: #web_application_security #security #json_web_token #jwt_authentication #hacking
Medium
JWT Attacks You Should Know (Beyond the Basics)
JWT authentication is everywhere but most implementations are insecure.
⤷ Title: Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 01:01:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache OFBiz #Authentication Bypass #CVE_2026_31378 #CVE_2026_45434 #Cyber Security #infosec #JSON Attribute Manipulation #Patch Alert #Remote Code Execution #Server Side Template Injection #ssti
Daily CyberSecurity
Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
Apache OFBiz releases version 24.09.06 to patch severe RCE flaws, token forgery, and a critical password-reset authentication bypass. Upgrade now!
⤷ Title: Hacking JSON Web Tokens: How Attackers Exploit API Authentication
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Thu, 28 May 2026 17:53:25 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_penetration_testing #api_attack #api_pentesting #json_web_token
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Thu, 28 May 2026 17:53:25 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_penetration_testing #api_attack #api_pentesting #json_web_token
Medium
Hacking JSON Web Tokens: How Attackers Exploit API Authentication
JWTs are trusted by millions of APIs worldwide: yet one small misconfiguration can turn a security feature into an attacker’s gateway
⤷ Title: Hacking JSON Web Tokens: How Attackers Exploit API Authentication
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:15:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_penetration_testing #api_attack #api_pentesting #json_web_token
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Fri, 29 May 2026 09:15:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_penetration_testing #api_attack #api_pentesting #json_web_token
Medium
Hacking JSON Web Tokens: How Attackers Exploit API Authentication
JWTs are trusted by millions of APIs worldwide: yet one small misconfiguration can turn a security feature into an attacker’s gateway
⤷ Title: JSON_EXTRACT Injection: When Prepared Statements Aren’t Enough
════════════════════════
𐀪 Author: Isuka sanuj
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 15:15:27 GMT
════════════════════════
⌗ Tags: #json #sql_injection #jsonpath
════════════════════════
𐀪 Author: Isuka sanuj
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 15:15:27 GMT
════════════════════════
⌗ Tags: #json #sql_injection #jsonpath
Medium
JSON_EXTRACT Injection: When Prepared Statements Aren’t Enough
Hey folks! Welcome back to my blog. Today, we’re diving into JSON Path Injection — a sneaky vulnerability that targets the JSON_* family of…