I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium »
Read more...
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium »
Read more...
Medium
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.
How I Found a $4,750 Security Flaw by Accident
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium »
Read more...
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium »
Read more...
Medium
How I Found a $4,750 Security Flaw by Accident
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium »
Read more...
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium »
Read more...
Medium
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…
Anyone here done HIPAA-compliant pentesting? What are your go-to tools and challenges?
https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/
<!-- SC_OFF -->Hey folks, I’m working on a project involving HIPAA-compliant penetration testing for a healthcare provider, and I’m curious to learn from others who’ve been through it. What tools or platforms have you found effective for HIPAA-focused environments? Do you usually go with manual or automated approaches (or a mix)? How do you typically handle things like risk reporting, PHI data handling, and compliance documentation? Also, how often do you recommend running tests for continuous compliance (beyond the once-a-year minimum)? Would love to hear your experiences, best practices, or even war stories from the field. Thanks in advance! <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/)
https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/
<!-- SC_OFF -->Hey folks, I’m working on a project involving HIPAA-compliant penetration testing for a healthcare provider, and I’m curious to learn from others who’ve been through it. What tools or platforms have you found effective for HIPAA-focused environments? Do you usually go with manual or automated approaches (or a mix)? How do you typically handle things like risk reporting, PHI data handling, and compliance documentation? Also, how often do you recommend running tests for continuous compliance (beyond the once-a-year minimum)? Would love to hear your experiences, best practices, or even war stories from the field. Thanks in advance! <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/)
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and…
https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5
https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…Continue reading on Medium » (https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5)
Open Redirect on Logout Page — When Shopping Got Too Redirected
https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5
https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5
“I came to shop, not to teleport!”
– Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium » (https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5)
– Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium » (https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5)
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
https://kkonann.medium.com/i-found-a-major-privacy-leak-in-a-popular-social-app-just-because-a-friend-said-check-this-out-cd7edd798e32?source=rss------bug_bounty-5
https://kkonann.medium.com/i-found-a-major-privacy-leak-in-a-popular-social-app-just-because-a-friend-said-check-this-out-cd7edd798e32?source=rss------bug_bounty-5
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium » (https://kkonann.medium.com/i-found-a-major-privacy-leak-in-a-popular-social-app-just-because-a-friend-said-check-this-out-cd7edd798e32?source=rss------bug_bounty-5)
How I Found a $4,750 Security Flaw by Accident
https://medium.com/@ibtissamhammadi1/how-i-found-a-4-750-security-flaw-by-accident-6acb32eaede5?source=rss------bug_bounty-5
https://medium.com/@ibtissamhammadi1/how-i-found-a-4-750-security-flaw-by-accident-6acb32eaede5?source=rss------bug_bounty-5
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/how-i-found-a-4-750-security-flaw-by-accident-6acb32eaede5?source=rss------bug_bounty-5)
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
https://medium.com/@thedhruvsingh/microsoft-raises-zero-day-quest-prize-pool-to-5-million-to-tackle-ai-and-cloud-vulnerabilities-9425c7e6553d?source=rss------bug_bounty-5
https://medium.com/@thedhruvsingh/microsoft-raises-zero-day-quest-prize-pool-to-5-million-to-tackle-ai-and-cloud-vulnerabilities-9425c7e6553d?source=rss------bug_bounty-5
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium » (https://medium.com/@thedhruvsingh/microsoft-raises-zero-day-quest-prize-pool-to-5-million-to-tackle-ai-and-cloud-vulnerabilities-9425c7e6553d?source=rss------bug_bounty-5)
Jangan dikit-dikit “Bypass”. Gak semua yang “Aneh” itu vulnerability
Udah yakin ini “bypass” tapi ternyata ditolak? mungkin ini salah kamu!Continue reading on Medium »
Read more...
Udah yakin ini “bypass” tapi ternyata ditolak? mungkin ini salah kamu!Continue reading on Medium »
Read more...
Medium
Jangan dikit-dikit “Bypass”. Gak semua yang “Aneh” itu vulnerability
Udah yakin ini “bypass” tapi ternyata ditolak? mungkin ini salah kamu!
Starting Bug Bounty — Documenting My Journey
Hey guys. I’m starting bug bounty.Continue reading on Medium »
Read more...
Hey guys. I’m starting bug bounty.Continue reading on Medium »
Read more...
Medium
Starting Bug Bounty — Documenting My Journey
Hey guys. I’m starting bug bounty.