Breaking Into a Bank’s Database (Ethically!) — My Wild Cybersecurity Ride
👋 Greetings, Fellow Hackers and Cyber Enthusiasts! I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium »
Read more...
👋 Greetings, Fellow Hackers and Cyber Enthusiasts! I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium »
Read more...
Medium
🔓 Breaking Into a Bank’s Database (Ethically!) — My Wild Cybersecurity Ride
👋 Greetings, Fellow Hackers and Cyber Enthusiasts!
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…
From Recon to Root: A MongoDB NoSQL Injection Bug Bounty Journey
https://infosecwriteups.com/from-recon-to-root-a-mongodb-nosql-injection-bug-bounty-journey-18e9cb309cac?source=rss------bug_bounty-5
https://infosecwriteups.com/from-recon-to-root-a-mongodb-nosql-injection-bug-bounty-journey-18e9cb309cac?source=rss------bug_bounty-5
Exploiting NoSQL injection to extract admin credentials from a MongoDB-backed application using BurpSuite and Boolean-based payloads.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/from-recon-to-root-a-mongodb-nosql-injection-bug-bounty-journey-18e9cb309cac?source=rss------bug_bounty-5)
️ How I Found FTP Credentials in a Python Script on a NASA Subdomain
https://medium.com/@divyasai2629/%EF%B8%8F-how-i-found-ftp-credentials-in-a-python-script-on-a-nasa-subdomain-dc7f4676444c?source=rss------bug_bounty-5
A real-world bug bounty story of how FTP credentials, internal IPs, and paths were discovered in a Python script hosted on a NASA…Continue reading on Medium » (https://medium.com/@divyasai2629/%EF%B8%8F-how-i-found-ftp-credentials-in-a-python-script-on-a-nasa-subdomain-dc7f4676444c?source=rss------bug_bounty-5)
https://medium.com/@divyasai2629/%EF%B8%8F-how-i-found-ftp-credentials-in-a-python-script-on-a-nasa-subdomain-dc7f4676444c?source=rss------bug_bounty-5
A real-world bug bounty story of how FTP credentials, internal IPs, and paths were discovered in a Python script hosted on a NASA…Continue reading on Medium » (https://medium.com/@divyasai2629/%EF%B8%8F-how-i-found-ftp-credentials-in-a-python-script-on-a-nasa-subdomain-dc7f4676444c?source=rss------bug_bounty-5)
Full-Blown SSRF to Gain Access to Millions of Users’ Records and Multiple Internal Panels
https://medium.com/@skycer_00/full-blown-ssrf-to-gain-access-to-millions-of-users-records-and-multiple-internal-panels-3719d9b802e9?source=rss------bug_bounty-5
https://medium.com/@skycer_00/full-blown-ssrf-to-gain-access-to-millions-of-users-records-and-multiple-internal-panels-3719d9b802e9?source=rss------bug_bounty-5
This write-up details an SSRF vulnerability that allowed unauthorized access to millions of sensitive data and internal services.Continue reading on Medium » (https://medium.com/@skycer_00/full-blown-ssrf-to-gain-access-to-millions-of-users-records-and-multiple-internal-panels-3719d9b802e9?source=rss------bug_bounty-5)
Breaking Into a Bank’s Database (Ethically!) — My Wild Cybersecurity Ride
https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5
https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5
👋 Greetings, Fellow Hackers and Cyber Enthusiasts!
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium » (https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5)
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium » (https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5)
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)
Vulnerability OverviewContinue reading on Medium »
Read more...
Vulnerability OverviewContinue reading on Medium »
Read more...
Medium
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)
Vulnerability Overview
How Adversary Telegram Bots Help to Reveal Threats: Case Study
https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/
submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/adversary-telegram-bot-abuse/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/)
https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/
submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/adversary-telegram-bot-abuse/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/)
More than 1,500 AI projects are now vulnerable to a silent exploit
https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/
<!-- SC_OFF -->According to the latest research by ARIMLABS[.]AI, a critical security vulnerability (CVE-2025-47241) has been discovered in the widely used Browser Use framework — a dependency leveraged by more than 1,500 AI projects. The issue enables zero-click agent hijacking, meaning an attacker can take control of an LLM-powered browsing agent simply by getting it to visit a malicious page — no user interaction required. This raises serious concerns about the current state of security in autonomous AI agents, especially those that interact with the web. What’s the community’s take on this? Is AI agent security getting the attention it deserves? (all links in the comments) <!-- SC_ON --> submitted by /u/0xm3k (https://www.reddit.com/user/0xm3k)
[link] (https://arimlabs.ai/news/the-hidden-dangers-of-browsing-ai-agents) [comments] (https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/)
https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/
<!-- SC_OFF -->According to the latest research by ARIMLABS[.]AI, a critical security vulnerability (CVE-2025-47241) has been discovered in the widely used Browser Use framework — a dependency leveraged by more than 1,500 AI projects. The issue enables zero-click agent hijacking, meaning an attacker can take control of an LLM-powered browsing agent simply by getting it to visit a malicious page — no user interaction required. This raises serious concerns about the current state of security in autonomous AI agents, especially those that interact with the web. What’s the community’s take on this? Is AI agent security getting the attention it deserves? (all links in the comments) <!-- SC_ON --> submitted by /u/0xm3k (https://www.reddit.com/user/0xm3k)
[link] (https://arimlabs.ai/news/the-hidden-dangers-of-browsing-ai-agents) [comments] (https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/)
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)
https://medium.com/@salaheddine_kalada/my-first-cve-privilege-escalation-possible-account-takeover-in-froxlor-cve-2025-29773-c111469d74b0?source=rss------bug_bounty-5
https://medium.com/@salaheddine_kalada/my-first-cve-privilege-escalation-possible-account-takeover-in-froxlor-cve-2025-29773-c111469d74b0?source=rss------bug_bounty-5
Vulnerability OverviewContinue reading on Medium » (https://medium.com/@salaheddine_kalada/my-first-cve-privilege-escalation-possible-account-takeover-in-froxlor-cve-2025-29773-c111469d74b0?source=rss------bug_bounty-5)
I Slipped an Item Into a Stranger’s Cart(Well, Almost)
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium »
Read more...
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium »
Read more...
Medium
I Slipped an Item Into a Stranger’s Cart(Well, Almost)
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.
I Slipped an Item Into a Stranger’s Cart(Well, Almost)
https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5
https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium » (https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5)