Breaking Into a Bank’s Database (Ethically!) — My Wild Cybersecurity Ride
https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5
https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5
👋 Greetings, Fellow Hackers and Cyber Enthusiasts!
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium » (https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5)
I’m XABIT— your friendly neighborhood cybersecurity researcher, part-time bug bounty…Continue reading on Medium » (https://rootxabit.medium.com/breaking-into-a-banks-database-ethically-my-wild-cybersecurity-ride-b90c91b0b09b?source=rss------bug_bounty-5)
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)
Vulnerability OverviewContinue reading on Medium »
Read more...
Vulnerability OverviewContinue reading on Medium »
Read more...
Medium
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)
Vulnerability Overview
How Adversary Telegram Bots Help to Reveal Threats: Case Study
https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/
submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/adversary-telegram-bot-abuse/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/)
https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/
submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/adversary-telegram-bot-abuse/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kreidu/how_adversary_telegram_bots_help_to_reveal/)
More than 1,500 AI projects are now vulnerable to a silent exploit
https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/
<!-- SC_OFF -->According to the latest research by ARIMLABS[.]AI, a critical security vulnerability (CVE-2025-47241) has been discovered in the widely used Browser Use framework — a dependency leveraged by more than 1,500 AI projects. The issue enables zero-click agent hijacking, meaning an attacker can take control of an LLM-powered browsing agent simply by getting it to visit a malicious page — no user interaction required. This raises serious concerns about the current state of security in autonomous AI agents, especially those that interact with the web. What’s the community’s take on this? Is AI agent security getting the attention it deserves? (all links in the comments) <!-- SC_ON --> submitted by /u/0xm3k (https://www.reddit.com/user/0xm3k)
[link] (https://arimlabs.ai/news/the-hidden-dangers-of-browsing-ai-agents) [comments] (https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/)
https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/
<!-- SC_OFF -->According to the latest research by ARIMLABS[.]AI, a critical security vulnerability (CVE-2025-47241) has been discovered in the widely used Browser Use framework — a dependency leveraged by more than 1,500 AI projects. The issue enables zero-click agent hijacking, meaning an attacker can take control of an LLM-powered browsing agent simply by getting it to visit a malicious page — no user interaction required. This raises serious concerns about the current state of security in autonomous AI agents, especially those that interact with the web. What’s the community’s take on this? Is AI agent security getting the attention it deserves? (all links in the comments) <!-- SC_ON --> submitted by /u/0xm3k (https://www.reddit.com/user/0xm3k)
[link] (https://arimlabs.ai/news/the-hidden-dangers-of-browsing-ai-agents) [comments] (https://www.reddit.com/r/redteamsec/comments/1krhn92/more_than_1500_ai_projects_are_now_vulnerable_to/)
My First CVE: Privilege Escalation & Possible Account Takeover in Froxlor (CVE-2025–29773)
https://medium.com/@salaheddine_kalada/my-first-cve-privilege-escalation-possible-account-takeover-in-froxlor-cve-2025-29773-c111469d74b0?source=rss------bug_bounty-5
https://medium.com/@salaheddine_kalada/my-first-cve-privilege-escalation-possible-account-takeover-in-froxlor-cve-2025-29773-c111469d74b0?source=rss------bug_bounty-5
Vulnerability OverviewContinue reading on Medium » (https://medium.com/@salaheddine_kalada/my-first-cve-privilege-escalation-possible-account-takeover-in-froxlor-cve-2025-29773-c111469d74b0?source=rss------bug_bounty-5)
I Slipped an Item Into a Stranger’s Cart(Well, Almost)
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium »
Read more...
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium »
Read more...
Medium
I Slipped an Item Into a Stranger’s Cart(Well, Almost)
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.
I Slipped an Item Into a Stranger’s Cart(Well, Almost)
https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5
https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5
It started the same way most bug bounty journeys begin — with a bit of curiosity, a browser & a proxy, and way too much coffee.Continue reading on Medium » (https://medium.com/@nizarkadiri70/i-slipped-an-item-into-a-strangers-cart-well-almost-4f1f5397a64b?source=rss------bug_bounty-5)
$2,400 in 60 Minutes: Hacking a Management Backend by Tweaking a Single Response Packet
https://medium.com/@cadeeper/0x00-368daffa75f7?source=rss------bug_bounty-5
https://medium.com/@cadeeper/0x00-368daffa75f7?source=rss------bug_bounty-5
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.Continue reading on Medium » (https://medium.com/@cadeeper/0x00-368daffa75f7?source=rss------bug_bounty-5)
How I Earned my Second Bounty of €2000 by Discovering an Authorization Bypass Vulnerability in a…
https://medium.com/@sohelparashar/how-i-earned-my-second-bounty-of-2000-by-discovering-an-authorization-bypass-vulnerability-in-a-8b20570004d8?source=rss------bug_bounty-5
https://medium.com/@sohelparashar/how-i-earned-my-second-bounty-of-2000-by-discovering-an-authorization-bypass-vulnerability-in-a-8b20570004d8?source=rss------bug_bounty-5
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…Continue reading on Medium » (https://medium.com/@sohelparashar/how-i-earned-my-second-bounty-of-2000-by-discovering-an-authorization-bypass-vulnerability-in-a-8b20570004d8?source=rss------bug_bounty-5)
$2,400 in 60 Minutes: Hacking a Management Backend by Tweaking a Single Response Packet
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.Continue reading on Medium »
Read more...
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.Continue reading on Medium »
Read more...
Medium
$2,400 in 60 Minutes: Hacking a Management Backend by Tweaking a Single Response Packet
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.
How I Earned my Second Bounty of €2000 by Discovering an Authorization Bypass Vulnerability in a…
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…Continue reading on Medium »
Read more...
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…Continue reading on Medium »
Read more...
Medium
💰How I Earned my Second Bounty of €2000 by Discovering an Authorization Bypass Vulnerability in a Document Management Platform
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…