⤷ Title: RepoJacking: How 5 Unclaimed GitHub Usernames Enabled RCE on Self-Hosted Servers
════════════════════════
𐀪 Author: tushar
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 16:36:00 GMT
════════════════════════
⌗ Tags: #supply_chain #infosec #github #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: tushar
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 16:36:00 GMT
════════════════════════
⌗ Tags: #supply_chain #infosec #github #cybersecurity #bug_bounty
Medium
RepoJacking: How 5 Unclaimed GitHub Usernames Enabled RCE on Self-Hosted Servers
How I used a 3-line bash script to find 8 backdoorable plugins in an official plugin registry — and why this attack requires zero exploits.
⤷ Title: The Protocol Every Hacker Should Learn Before Touching Burp Suite
════════════════════════
𐀪 Author: Zer0trace
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 13:02:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #software_development #ethical_hacking
════════════════════════
𐀪 Author: Zer0trace
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 13:02:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #software_development #ethical_hacking
Medium
The Protocol Every Hacker Should Learn Before Touching Burp Suite
Type http://example.com into a browser and hit Enter. A page shows up — text, maybe an image or a login box — and you move on. You don't…
⤷ Title: Why Your Best XSS Is on a Param You Can’t See
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #infosec #cybersecurity #bug_bounty #hacking
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #infosec #cybersecurity #bug_bounty #hacking
Medium
Why Your Best XSS Is on a Param You Can’t See
What’s up everyone! Nitin here 👋
⤷ Title: Indirect Prompt Injection: What LLM Bounty Triagers Actually Reward
════════════════════════
𐀪 Author: Muhammad Haider Tallal
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 11:00:13 GMT
════════════════════════
⌗ Tags: #prompt_injection_attack #ai_security #bug_bounty #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Muhammad Haider Tallal
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 11:00:13 GMT
════════════════════════
⌗ Tags: #prompt_injection_attack #ai_security #bug_bounty #cybersecurity #artificial_intelligence
Medium
Indirect Prompt Injection: What LLM Bounty Triagers Actually Reward
Direct injection and jailbreaks keep getting closed as informational. The findings that pay chain a hidden instruction to a real…
⤷ Title: Unauthenticated Mass Data Deletion: When DELETE Has No Auth Check
════════════════════════
𐀪 Author: Divakarvasani
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:54:53 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Divakarvasani
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:54:53 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bug_bounty
Medium
Unauthenticated Mass Data Deletion: When DELETE Has No Auth Check
Finding and proving a cross-user resource deletion vulnerability through JS bundle analysis and sequential ID enumeration
⤷ Title: How I Chained an Unauthenticated OAuth Registration Endpoint into Full Account Takeover
════════════════════════
𐀪 Author: Divakarvasani
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:50:04 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Divakarvasani
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:50:04 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #bug_bounty
Medium
How I Chained an Unauthenticated OAuth Registration Endpoint into Full Account Takeover
A walkthrough of abusing RFC 7591 Dynamic Client Registration left open in production
⤷ Title: How I Prioritize Hundreds of Subdomains During Bug Bounty Recon
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 07:58:54 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Rakesh Joshi
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 07:58:54 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
Medium
How I Prioritize Hundreds of Subdomains During Bug Bounty Recon
Finding 500, 1,000, or even 10,000 subdomains isn’t the difficult part of bug bounty reconnaissance.
⤷ Title: Grafana Security Alert | CVE-2026–15583 & CVE-2026–21723 Explained
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 07:13:11 GMT
════════════════════════
⌗ Tags: #web_development #hacking #artificial_intelligence #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 07:13:11 GMT
════════════════════════
⌗ Tags: #web_development #hacking #artificial_intelligence #cybersecurity #bug_bounty
Medium
🚨 Grafana Security Alert | CVE-2026–15583 & CVE-2026–21723 Explained
Two Recent Grafana Security Issues Every Security Team Should Understand
⤷ Title: Taking Advantage of SQLi Vulnerability in the Login Form to Bypass Authentication (vuln-bank)
════════════════════════
𐀪 Author: Ernestosindo
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:12:25 GMT
════════════════════════
⌗ Tags: #login_bypass #vulnbank #sql_injection #cybersecurity #application_security
════════════════════════
𐀪 Author: Ernestosindo
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 09:12:25 GMT
════════════════════════
⌗ Tags: #login_bypass #vulnbank #sql_injection #cybersecurity #application_security
Medium
Taking Advantage of SQLi Vulnerability in the Login Form to Bypass Authentication (vuln-bank)
The login form is the first unauthenticated entry point to most web applications. When it’s vulnerable to SQL injection, attackers can…
⤷ Title: The Biggest Security Lie Developers Still Believe
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 05:30:33 GMT
════════════════════════
⌗ Tags: #software_development #application_security #software_engineering #cybersecurity #software_architecture
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 05:30:33 GMT
════════════════════════
⌗ Tags: #software_development #application_security #software_engineering #cybersecurity #software_architecture
Medium
The Biggest Security Lie Developers Still Believe
The Biggest Security Lie Developers Still Believe “It’s secure. We have a firewall, we use HTTPS, and we’ll run a scan before we go live.” If you’ve heard these words — or worse, said …
⤷ Title: Enterprise Security Restructuring in the Age of AI-Discovered Vulnerabilities
════════════════════════
𐀪 Author: cyber_pix
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 04:06:01 GMT
════════════════════════
⌗ Tags: #ai_security #application_security #generative_ai_security #enterprise_security #cloud_security
════════════════════════
𐀪 Author: cyber_pix
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 04:06:01 GMT
════════════════════════
⌗ Tags: #ai_security #application_security #generative_ai_security #enterprise_security #cloud_security
Medium
Enterprise Security Restructuring in the Age of AI-Discovered Vulnerabilities
Credit: Cloudanix
⤷ Title: The GenAI Security Paradox — Intelligence vs. Determinism
════════════════════════
𐀪 Author: Shiki65536@TechRoamer
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 01:10:38 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #application_security #ai_security #cybersecurity #genai
════════════════════════
𐀪 Author: Shiki65536@TechRoamer
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 01:10:38 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #application_security #ai_security #cybersecurity #genai
Medium
The GenAI Security Paradox — Intelligence vs. Determinism
This week, I attended the Melbourne Secure Software & AppSec Summit 2026.
⤷ Title: Your Agent’s Command Allowlist Is a Parser, and It Disagrees With Your Shell
════════════════════════
𐀪 Author: Krishna
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 12:15:50 GMT
════════════════════════
⌗ Tags: #application_security #software_engineering #cybersecurity #ai_agent #devops
════════════════════════
𐀪 Author: Krishna
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 12:15:50 GMT
════════════════════════
⌗ Tags: #application_security #software_engineering #cybersecurity #ai_agent #devops
Medium
Your Agent’s Command Allowlist Is a Parser, and It Disagrees With Your Shell
Six disclosed findings across Anthropic, Google, and OpenAI CI integrations share one root cause. An explanation of what it is, why each…
⤷ Title: The Request Changed. The Security Rule Didn’t.
════════════════════════
𐀪 Author: Akshit Kakani
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:55:32 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #penetration_testing #application_security #cybersecurity
════════════════════════
𐀪 Author: Akshit Kakani
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:55:32 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #penetration_testing #application_security #cybersecurity
Medium
The Request Changed. The Security Rule Didn’t.
Exploring HTTP Verb Tampering and Broken Access Control
⤷ Title: Your AI Agent Can Use a Computer. Can You Approve Its Authority?
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:30:57 GMT
════════════════════════
⌗ Tags: #ai_security #cybersecurity #application_security #ai_agent_security #penetration_testing
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:30:57 GMT
════════════════════════
⌗ Tags: #ai_security #cybersecurity #application_security #ai_agent_security #penetration_testing
Medium
Your AI Agent Can Use a Computer. Can You Approve Its Authority?
Browser-capable agents turn ordinary SaaS permissions into an execution layer. Before launch, leadership needs evidence that identity…
⤷ Title: Testing Authorization Boundaries in Multi-Region, Multi-Tenant Applications
════════════════════════
𐀪 Author: Mdporschaa
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:16:01 GMT
════════════════════════
⌗ Tags: #application_security #appsec #cybersecurity #privilege_escalation
════════════════════════
𐀪 Author: Mdporschaa
════════════════════════
ⴵ Time: Sat, 08 Aug 2026 11:16:01 GMT
════════════════════════
⌗ Tags: #application_security #appsec #cybersecurity #privilege_escalation
Medium
Testing Authorization Boundaries in Multi-Region, Multi-Tenant Applications
How I approach authorization boundary testing when the same application serves multiple accounts and multiple regions from a shared…
⤷ Title: I Built an AI-Assisted Threat Modeling Pipeline. The Hardest Part Wasn’t Finding Threats.
════════════════════════
𐀪 Author: Vinibrisola
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 21:46:53 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #ai_security #threat_modeling #security_engineering
════════════════════════
𐀪 Author: Vinibrisola
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 21:46:53 GMT
════════════════════════
⌗ Tags: #devsecops #application_security #ai_security #threat_modeling #security_engineering
Medium
I Built an AI-Assisted Threat Modeling Pipeline. The Hardest Part Wasn’t Finding Threats.
What I learned while trying to turn architecture diagrams into traceable security decisions and actionable engineering work.
⤷ Title: WriteUp: Internal — THM
════════════════════════
𐀪 Author: Vima
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 23:53:12 GMT
════════════════════════
⌗ Tags: #ctf_writeup #cybersecurity #tryhackme #hacking
════════════════════════
𐀪 Author: Vima
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 23:53:12 GMT
════════════════════════
⌗ Tags: #ctf_writeup #cybersecurity #tryhackme #hacking
Medium
WriteUp: Internal — THM
Autor: Vima Nivel: Dificil Principales Tecnicas: Explotacion WordPress — Tunelizacion SSH — Escalada de Privilegios — Abuso de Jenkins.
⤷ Title: Akıllı Süpürgeniz Hacklenebilir mi?
════════════════════════
𐀪 Author: Burak Kıraç
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 23:07:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #smart_vacuum_cleaner #ethical_hacking
════════════════════════
𐀪 Author: Burak Kıraç
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 23:07:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #smart_vacuum_cleaner #ethical_hacking
⤷ Title: From Exposed PUT Requests to chkrootkit Root: A Complete Walkthrough of SickOS 1.2
════════════════════════
𐀪 Author: Muhammad Zain
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 22:12:59 GMT
════════════════════════
⌗ Tags: #vulnhub #cybersecurity #fun #education #hacking
════════════════════════
𐀪 Author: Muhammad Zain
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 22:12:59 GMT
════════════════════════
⌗ Tags: #vulnhub #cybersecurity #fun #education #hacking
Medium
From Exposed PUT Requests to chkrootkit Root: A Complete Walkthrough of SickOS 1.2
Welcome back! In today’s walkthrough, we are tackling a particularly fun VulnHub machine. As someone who approaches cybersecurity from a…
⤷ Title: 24/7/365 Cyber Security Operations Center (CSOC) - At Smatchoicehackers.com
════════════════════════
𐀪 Author: Paul Weller
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:23:09 GMT
════════════════════════
⌗ Tags: #cyber_security_solutions #cyber_security_awareness #life_lessons #cybersecurity #hacking
════════════════════════
𐀪 Author: Paul Weller
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:23:09 GMT
════════════════════════
⌗ Tags: #cyber_security_solutions #cyber_security_awareness #life_lessons #cybersecurity #hacking
Medium
24/7/365 Cyber Security Operations Center (CSOC) - At Smatchoicehackers.com
cybersecurity-center