Audio Upload Functionality: End-to-End Guide for Security Testers
https://medium.com/meetcyber/audio-upload-functionality-end-to-end-guide-for-security-testers-701ab79bbeeb?source=rss------bug_bounty-5
Audio upload functionalities are increasingly common in modern applications, especially in platforms offering support ticketing, voicemail…Continue reading on MeetCyber » (https://medium.com/meetcyber/audio-upload-functionality-end-to-end-guide-for-security-testers-701ab79bbeeb?source=rss------bug_bounty-5)
https://medium.com/meetcyber/audio-upload-functionality-end-to-end-guide-for-security-testers-701ab79bbeeb?source=rss------bug_bounty-5
Audio upload functionalities are increasingly common in modern applications, especially in platforms offering support ticketing, voicemail…Continue reading on MeetCyber » (https://medium.com/meetcyber/audio-upload-functionality-end-to-end-guide-for-security-testers-701ab79bbeeb?source=rss------bug_bounty-5)
Access Bank Account Information via Response Manipulation
https://brbr0s.medium.com/access-bank-account-information-via-response-manipulation-b373c9e4b536?source=rss------bug_bounty-5
https://brbr0s.medium.com/access-bank-account-information-via-response-manipulation-b373c9e4b536?source=rss------bug_bounty-5
Hi mates, I’m Mahmoud — aka brbr0s — . I’m a bug hunter who’s always trying to learn more and get better at what I do. I’m mainly focused…Continue reading on Medium » (https://brbr0s.medium.com/access-bank-account-information-via-response-manipulation-b373c9e4b536?source=rss------bug_bounty-5)
Human in the Loop for AI Pentesting Co-Pilot
https://www.reddit.com/r/redteamsec/comments/1mk4amn/human_in_the_loop_for_ai_pentesting_copilot/
<!-- SC_OFF -->Hi all, we took lots of feedback from our original post on here with our AI Pentesting copilot. We have now added a feature that can be toggled so our AI Pentester can run in a "user approve" mode. This allows users to feel more comfortable with the software as this requires user approval before executing commands on target. You can also switch it back to agentic mode and it will go back to being autonomous. As we had previously, you can still give it tasks which will be put in a queue to increase thoroughness. Cheers. www.vulnetic.ai (http://www.vulnetic.ai/) We are looking to build out a more permanent beta testing group for early features, so if you are interested, it is a free way to use the product. Email us at [contact@vulnetic.ai (mailto:contact@vulnetic.ai)](mailto:contact@vulnetic.ai (mailto:contact@vulnetic.ai)) if you want to be a beta tester. <!-- SC_ON --> submitted by /u/Pitiful_Table_1870 (https://www.reddit.com/user/Pitiful_Table_1870)
[link] (http://www.vulnetic.ai/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mk4amn/human_in_the_loop_for_ai_pentesting_copilot/)
https://www.reddit.com/r/redteamsec/comments/1mk4amn/human_in_the_loop_for_ai_pentesting_copilot/
<!-- SC_OFF -->Hi all, we took lots of feedback from our original post on here with our AI Pentesting copilot. We have now added a feature that can be toggled so our AI Pentester can run in a "user approve" mode. This allows users to feel more comfortable with the software as this requires user approval before executing commands on target. You can also switch it back to agentic mode and it will go back to being autonomous. As we had previously, you can still give it tasks which will be put in a queue to increase thoroughness. Cheers. www.vulnetic.ai (http://www.vulnetic.ai/) We are looking to build out a more permanent beta testing group for early features, so if you are interested, it is a free way to use the product. Email us at [contact@vulnetic.ai (mailto:contact@vulnetic.ai)](mailto:contact@vulnetic.ai (mailto:contact@vulnetic.ai)) if you want to be a beta tester. <!-- SC_ON --> submitted by /u/Pitiful_Table_1870 (https://www.reddit.com/user/Pitiful_Table_1870)
[link] (http://www.vulnetic.ai/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mk4amn/human_in_the_loop_for_ai_pentesting_copilot/)
Bug Hunting Like No One’s Thought Of: Quantum Tactics, AI Evolution, and Security Concepts From…
We set out to build a better bug bounty scanner. What we accidentally discovered felt like hacking the fabric of reality.Continue reading on Medium »
Read more...
We set out to build a better bug bounty scanner. What we accidentally discovered felt like hacking the fabric of reality.Continue reading on Medium »
Read more...
Medium
🧠 Bug Hunting Like No One’s Thought Of: Quantum Tactics, AI Evolution, and Security Concepts From the Edge
We set out to build a better bug bounty scanner. What we accidentally discovered felt like hacking the fabric of reality.
Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards
Sometimes privacy issues don’t come from zero-days or fancy payloads — they come from features doing more than they should. This time, the…Continue reading on Medium »
Read more...
Sometimes privacy issues don’t come from zero-days or fancy payloads — they come from features doing more than they should. This time, the…Continue reading on Medium »
Read more...
Medium
Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards
Sometimes privacy issues don’t come from zero-days or fancy payloads — they come from features doing more than they should. This time, the…
ZERO-DAY CVE-2025–24893 “XWiki Platform — Remote Code Execution” POC
XWiki is a free and open source wiki software platform written in Java with a design emphasis on extensibility.Continue reading on Medium »
Read more...
XWiki is a free and open source wiki software platform written in Java with a design emphasis on extensibility.Continue reading on Medium »
Read more...
Medium
ZERO-DAY CVE-2025–24893 “XWiki Platform — Remote Code Execution” POC
XWiki is a free and open source wiki software platform written in Java with a design emphasis on extensibility.
Monitor HTTP Response Headers Like a Pro: Introducing Header Change Notifier for Burp Suite
A must-have tool for every security researcher, penetration tester, or bug bounty hunter who cares about security headers and…Continue reading on Medium »
Read more...
A must-have tool for every security researcher, penetration tester, or bug bounty hunter who cares about security headers and…Continue reading on Medium »
Read more...
Medium
Monitor HTTP Response Headers Like a Pro: Introducing Header Change Notifier for Burp Suite
A must-have tool for every security researcher, penetration tester, or bug bounty hunter who cares about security headers and…
Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards
https://medium.com/@regan_temudo/unauthorized-disclosure-of-private-emails-via-wakatime-private-leaderboards-197361b80476?source=rss------bug_bounty-5
https://medium.com/@regan_temudo/unauthorized-disclosure-of-private-emails-via-wakatime-private-leaderboards-197361b80476?source=rss------bug_bounty-5
Sometimes privacy issues don’t come from zero-days or fancy payloads — they come from features doing more than they should. This time, the…Continue reading on Medium » (https://medium.com/@regan_temudo/unauthorized-disclosure-of-private-emails-via-wakatime-private-leaderboards-197361b80476?source=rss------bug_bounty-5)
ZERO-DAY CVE-2025–24893 “XWiki Platform — Remote Code Execution” POC
https://medium.com/@hariharanhex00/zero-day-cve-2025-24893-xwiki-platform-remote-code-execution-poc-00bd2ca3a93d?source=rss------bug_bounty-5
https://medium.com/@hariharanhex00/zero-day-cve-2025-24893-xwiki-platform-remote-code-execution-poc-00bd2ca3a93d?source=rss------bug_bounty-5
XWiki is a free and open source wiki software platform written in Java with a design emphasis on extensibility.Continue reading on Medium » (https://medium.com/@hariharanhex00/zero-day-cve-2025-24893-xwiki-platform-remote-code-execution-poc-00bd2ca3a93d?source=rss------bug_bounty-5)
Monitor HTTP Response Headers Like a Pro: Introducing Header Change Notifier for Burp Suite
https://medium.com/@mohamednfe78/monitor-http-response-headers-like-a-pro-introducing-header-change-notifier-for-burp-suite-b1494028b4db?source=rss------bug_bounty-5
A must-have tool for every security researcher, penetration tester, or bug bounty hunter who cares about security headers and…Continue reading on Medium » (https://medium.com/@mohamednfe78/monitor-http-response-headers-like-a-pro-introducing-header-change-notifier-for-burp-suite-b1494028b4db?source=rss------bug_bounty-5)
https://medium.com/@mohamednfe78/monitor-http-response-headers-like-a-pro-introducing-header-change-notifier-for-burp-suite-b1494028b4db?source=rss------bug_bounty-5
A must-have tool for every security researcher, penetration tester, or bug bounty hunter who cares about security headers and…Continue reading on Medium » (https://medium.com/@mohamednfe78/monitor-http-response-headers-like-a-pro-introducing-header-change-notifier-for-burp-suite-b1494028b4db?source=rss------bug_bounty-5)
OpenAIがgpt-ossセキュリティハッカソンを開催(2025年8月8日公開)
2025年8月6日、OpenAIは、前日にリリースしたgpt-oss-20bを対象とするセキュリティハッカソン「Red‑Teaming Challenge」をKaggleプラットフォーム上で開始した。Continue reading on Medium »
Read more...
2025年8月6日、OpenAIは、前日にリリースしたgpt-oss-20bを対象とするセキュリティハッカソン「Red‑Teaming Challenge」をKaggleプラットフォーム上で開始した。Continue reading on Medium »
Read more...
Medium
OpenAIがgpt-ossセキュリティハッカソンを開催(2025年8月8日公開)
2025年8月6日、OpenAIは、前日にリリースしたgpt-oss-20bを対象とするセキュリティハッカソン「Red‑Teaming Challenge」をKaggleプラットフォーム上で開始した。
OpenAIがgpt-ossセキュリティハッカソンを開催(2025年8月8日公開)
https://medium.com/@esasahara/openai%E3%81%8Cgpt-oss%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E3%83%8F%E3%83%83%E3%82%AB%E3%82%BD%E3%83%B3%E3%82%92%E9%96%8B%E5%82%AC-2025%E5%B9%B48%E6%9C%888%E6%97%A5%E5%85%AC%E9%96%8B-d2d429c6fa25?source=rss------bug_bounty-5
2025年8月6日、OpenAIは、前日にリリースしたgpt-oss-20bを対象とするセキュリティハッカソン「Red‑Teaming Challenge」をKaggleプラットフォーム上で開始した。Continue reading on Medium » (https://medium.com/@esasahara/openai%E3%81%8Cgpt-oss%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E3%83%8F%E3%83%83%E3%82%AB%E3%82%BD%E3%83%B3%E3%82%92%E9%96%8B%E5%82%AC-2025%E5%B9%B48%E6%9C%888%E6%97%A5%E5%85%AC%E9%96%8B-d2d429c6fa25?source=rss------bug_bounty-5)
https://medium.com/@esasahara/openai%E3%81%8Cgpt-oss%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E3%83%8F%E3%83%83%E3%82%AB%E3%82%BD%E3%83%B3%E3%82%92%E9%96%8B%E5%82%AC-2025%E5%B9%B48%E6%9C%888%E6%97%A5%E5%85%AC%E9%96%8B-d2d429c6fa25?source=rss------bug_bounty-5
2025年8月6日、OpenAIは、前日にリリースしたgpt-oss-20bを対象とするセキュリティハッカソン「Red‑Teaming Challenge」をKaggleプラットフォーム上で開始した。Continue reading on Medium » (https://medium.com/@esasahara/openai%E3%81%8Cgpt-oss%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E3%83%8F%E3%83%83%E3%82%AB%E3%82%BD%E3%83%B3%E3%82%92%E9%96%8B%E5%82%AC-2025%E5%B9%B48%E6%9C%888%E6%97%A5%E5%85%AC%E9%96%8B-d2d429c6fa25?source=rss------bug_bounty-5)
Bug Bounty Journey — Valid Report Part 9
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…Continue reading on Medium »
Read more...
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…Continue reading on Medium »
Read more...
Medium
Bug Bounty Journey — Valid Report Part 9
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…
Server-Side Request Forgery (SSRF — OWASP A10): Guía para Hacking y Bug Bounty
Descubre cómo el SSRF permite a un atacante acceder a la red interna, leer metadatos de la nube y escalar privilegios.Continue reading on Medium »
Read more...
Descubre cómo el SSRF permite a un atacante acceder a la red interna, leer metadatos de la nube y escalar privilegios.Continue reading on Medium »
Read more...
Medium
Server-Side Request Forgery (SSRF — OWASP A10): Guía para Hacking y Bug Bounty
Descubre cómo el SSRF permite a un atacante acceder a la red interna, leer metadatos de la nube y escalar privilegios.
Human in the loop for AI Pentesting Co-Pilot
https://www.reddit.com/r/Pentesting/comments/1mk4a0z/human_in_the_loop_for_ai_pentesting_copilot/
<!-- SC_OFF -->Hi all, we took lots of feedback from our original post on here with our AI Pentesting copilot. We have now added a feature that can be toggled so our AI Pentester can run in a "user approve" mode. This allows users to feel more comfortable with the software as this requires user approval before executing commands on target. You can also switch it back to agentic mode and it will go back to being autonomous. As we had previously, you can still give it tasks which will be put in a queue to increase thoroughness. Cheers. www.vulnetic.ai (http://www.vulnetic.ai/) We are looking to build out a more permanent beta testing group for early features, so if you are interested, it is a free way to use the product. Email us at [contact@vulnetic.ai (mailto:contact@vulnetic.ai)](mailto:contact@vulnetic.ai (mailto:contact@vulnetic.ai)) if you want to be a beta tester. <!-- SC_ON --> submitted by /u/Pitiful_Table_1870 (https://www.reddit.com/user/Pitiful_Table_1870)
[link] (https://www.reddit.com/r/Pentesting/comments/1mk4a0z/human_in_the_loop_for_ai_pentesting_copilot/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mk4a0z/human_in_the_loop_for_ai_pentesting_copilot/)
https://www.reddit.com/r/Pentesting/comments/1mk4a0z/human_in_the_loop_for_ai_pentesting_copilot/
<!-- SC_OFF -->Hi all, we took lots of feedback from our original post on here with our AI Pentesting copilot. We have now added a feature that can be toggled so our AI Pentester can run in a "user approve" mode. This allows users to feel more comfortable with the software as this requires user approval before executing commands on target. You can also switch it back to agentic mode and it will go back to being autonomous. As we had previously, you can still give it tasks which will be put in a queue to increase thoroughness. Cheers. www.vulnetic.ai (http://www.vulnetic.ai/) We are looking to build out a more permanent beta testing group for early features, so if you are interested, it is a free way to use the product. Email us at [contact@vulnetic.ai (mailto:contact@vulnetic.ai)](mailto:contact@vulnetic.ai (mailto:contact@vulnetic.ai)) if you want to be a beta tester. <!-- SC_ON --> submitted by /u/Pitiful_Table_1870 (https://www.reddit.com/user/Pitiful_Table_1870)
[link] (https://www.reddit.com/r/Pentesting/comments/1mk4a0z/human_in_the_loop_for_ai_pentesting_copilot/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mk4a0z/human_in_the_loop_for_ai_pentesting_copilot/)