Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Breaking Into a Bank’s Database (Ethically!) — My Wild Cybersecurity Ride

👋 Greetings, Fellow Hackers and Cyber Enthusiasts! I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium »
Read more...
Exploiting NoSQL injection to extract admin credentials from a MongoDB-backed application using BurpSuite and Boolean-based payloads.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/from-recon-to-root-a-mongodb-nosql-injection-bug-bounty-journey-18e9cb309cac?source=rss------bug_bounty-5)
️ How I Found FTP Credentials in a Python Script on a NASA Subdomain
https://medium.com/@divyasai2629/%EF%B8%8F-how-i-found-ftp-credentials-in-a-python-script-on-a-nasa-subdomain-dc7f4676444c?source=rss------bug_bounty-5

A real-world bug bounty story of how FTP credentials, internal IPs, and paths were discovered in a Python script hosted on a NASA…Continue reading on Medium » (https://medium.com/@divyasai2629/%EF%B8%8F-how-i-found-ftp-credentials-in-a-python-script-on-a-nasa-subdomain-dc7f4676444c?source=rss------bug_bounty-5)
This write-up details an SSRF vulnerability that allowed unauthorized access to millions of sensitive data and internal services.Continue reading on Medium » (https://medium.com/@skycer_00/full-blown-ssrf-to-gain-access-to-millions-of-users-records-and-multiple-internal-panels-3719d9b802e9?source=rss------bug_bounty-5)
👋 Greetings, Fellow Hackers and Cyber Enthusiasts!
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium » (https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5)
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)

Vulnerability OverviewContinue reading on Medium »
Read more...
More than 1,500 AI projects are now vulnerable to a silent exploit
https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/

<!-- SC_OFF -->According to the latest research by ARIMLABS[.]AI, a critical security vulnerability (CVE-2025-47241) has been discovered in the widely used Browser Use framework — a dependency leveraged by more than 1,500 AI projects. The issue enables zero-click agent hijacking, meaning an attacker can take control of an LLM-powered browsing agent simply by getting it to visit a malicious page — no user interaction required. This raises serious concerns about the current state of security in autonomous AI agents, especially those that interact with the web. What’s the community’s take on this? Is AI agent security getting the attention it deserves? (all links in the comments) <!-- SC_ON --> submitted by /u/0xm3k (https://www.reddit.com/user/0xm3k)
[link] (https://arimlabs.ai/news/the-hidden-dangers-of-browsing-ai-agents) [comments] (https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/)
I Slipped an Item Into a Stranger’s Cart(Well, Almost)

It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium »
Read more...
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium » (https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5)