APKLeaks
Scanning APK file for URIs, endpoints & secrets.
https://github.com/dwisiswant0/apkleaks
#pentesting #infosec #bugbounty
Scanning APK file for URIs, endpoints & secrets.
https://github.com/dwisiswant0/apkleaks
#pentesting #infosec #bugbounty
❤10🤝2🔥1
17K+ strong. One community. One mission. ⚡️ ️
Thank you for being part of Brut Security.
Learn. Practice. Hack. Grow.
Here’s to the next milestone.❤️🔥
🔥 https://brutsecurity.com
☄️ https://wa.link/brutsecurity
#BrutSecurity #17K #CyberSecurity #EthicalHacking
Thank you for being part of Brut Security.
Learn. Practice. Hack. Grow.
Here’s to the next milestone.
#BrutSecurity #17K #CyberSecurity #EthicalHacking
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥9❤3👏1
Please open Telegram to view this post
VIEW IN TELEGRAM
topmate.io
Bug Bounty Guide 2026 with Saumadip Mandal
Bug Bounty Guide 2026 with Saumadip Mandal · Master modern bug bounty hunting with 86 pages, 25 chapter · Digital Product · ₹199 · Topmate
❤3🔥3👏1
Don’t only test Unicode domains. Test Unicode in email/username fields too.
Try lookalike characters such as:
a → á / other Unicode variantsThe interesting case is when:
Database: treats the values as equal
Application: identifies the victim account
SMTP: treats them as different addresses
Example:
victim@gmail.comvictim@gmáil.comIf the application finds the victim's account but sends the password-reset email to the attacker-controlled Unicode address, you may have an account-collision / account-takeover vulnerability.
Input → Validation → Database → Token generation → Email delivery
#BugBounty #IDNHomograph #Punycode #WebSecurity
Please open Telegram to view this post
VIEW IN TELEGRAM
❤7🔥3🤝2🗿1
🚨Search for all leaked keys/secrets using one regex!
✅regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59
#BugBounty #bugbountytip
✅regex: https://gist.github.com/h4x0r-dz/be69c7533075ab0d3f0c9b97f7c93a59
#BugBounty #bugbountytip
🤨6❤3🔥3🗿1
This media is not supported in your browser
VIEW IN TELEGRAM
🔥 ⛓️ Click2Shell is a one-click unauthenticated remote command execution chain (Preauth RCE) affecting every WordPress website. Wordpress rolled out a fix yesterday! The story about how one preview link made WordPress click Install, load an inactive theme's PHP, and hand us RCE is below.
⚠️ https://pwn.ai/blog/click2shell
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥4❤2😱2👏1
Brut Security
🔥 ⛓️ Click2Shell is a one-click unauthenticated remote command execution chain (Preauth RCE) affecting every WordPress website. Wordpress rolled out a fix yesterday! The story about how one preview link made WordPress click Install, load an inactive theme's…
11 new vulnerabilities in WordPress, no CVE assigned yet ❗️
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
👉 Link: https://nt.ls/s3kOE
👉 Dork: tag.name:"wordpress"
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
👉 Link: https://nt.ls/s3kOE
👉 Dork: tag.name:"wordpress"
❤5
This media is not supported in your browser
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤5🔥5🗿1
Media is too big
VIEW IN TELEGRAM
FOFA UNLIMITED
🔹 100 Fresh fofa Accounts
🔹 3,000 Credits per Account / Month
🔹 100 × 3,000 = 300,000 Credits / Month
🔹 Chrome Extension with Auto Login
💰 Price: Only $30
All account details and extension are provided together.
Interested?
📩 DM on Telegram: @fofaseller
#AD
🔹 100 Fresh fofa Accounts
🔹 3,000 Credits per Account / Month
🔹 100 × 3,000 = 300,000 Credits / Month
🔹 Chrome Extension with Auto Login
💰 Price: Only $30
All account details and extension are provided together.
Interested?
📩 DM on Telegram: @fofaseller
#AD
❤4🤣4
🚨Bypass-403 - A simple script just made for self use for bypassing 403.
https://github.com/iamj0ker/bypass-403
#bugbounty #pentesting
https://github.com/iamj0ker/bypass-403
#bugbounty #pentesting
❤7🔥4😁2
Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)
https://www.cyera.com/research/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858
https://www.cyera.com/research/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858
Cyera
Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)
Cyera Research Labs has discovered a "worst-case scenario" flaw in n8n, the industry-leading platform for AI and workflow automation. Dubbed "Ni8mare," this vulnerability (CVE-2026-21858) allows an unauthenticated remote attacker to gain full administrative…
❤3
Please open Telegram to view this post
VIEW IN TELEGRAM
😁4🤣4