Active Directory Enumeration – ADWS
https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://ipurple.team/2025/08/12/active-directory-enumeration-adws/) [comments] (https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/)
https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://ipurple.team/2025/08/12/active-directory-enumeration-adws/) [comments] (https://www.reddit.com/r/redteamsec/comments/1moabdt/active_directory_enumeration_adws/)
ChromeAlone: A Chromium Browser Implant Framework
https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/
submitted by /u/bouncyhat (https://www.reddit.com/user/bouncyhat)
[link] (https://github.com/praetorian-inc/chromealone) [comments] (https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/)
https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/
submitted by /u/bouncyhat (https://www.reddit.com/user/bouncyhat)
[link] (https://github.com/praetorian-inc/chromealone) [comments] (https://www.reddit.com/r/redteamsec/comments/1moe2bq/chromealone_a_chromium_browser_implant_framework/)
Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/
submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/)
https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/
submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mof7y2/zero_click_one_ntlm_microsoft_security_patch/)
CARTE tips?
https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/
<!-- SC_OFF -->Hi everyone. I will be attending the CARTE exam soon. any tips or stuff I should know before doing the exam? I can't seem to find a lot of reviews on the internet about this certification. I did CARTP (not the exam) so I have those enumeration notes ready as well. I heard it's a messy environment on purpose so wondering how that will play out. How did you find the exam? How long did you take it to complete? Let me know :) Thanks! <!-- SC_ON --> submitted by /u/SilverAd2716 (https://www.reddit.com/user/SilverAd2716)
[link] (https://www.alteredsecurity.com/carte-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/)
https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/
<!-- SC_OFF -->Hi everyone. I will be attending the CARTE exam soon. any tips or stuff I should know before doing the exam? I can't seem to find a lot of reviews on the internet about this certification. I did CARTP (not the exam) so I have those enumeration notes ready as well. I heard it's a messy environment on purpose so wondering how that will play out. How did you find the exam? How long did you take it to complete? Let me know :) Thanks! <!-- SC_ON --> submitted by /u/SilverAd2716 (https://www.reddit.com/user/SilverAd2716)
[link] (https://www.alteredsecurity.com/carte-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/)
My 100 Hour Rule for Bug Bounty !
https://devprogramming.medium.com/my-100-hour-rule-for-bug-bounty-046f96fc7791?source=rss------bug_bounty-5
https://devprogramming.medium.com/my-100-hour-rule-for-bug-bounty-046f96fc7791?source=rss------bug_bounty-5
In this post, I share my 100-Hour Rule — how I structure every minute of hunting into focused phases, avoid the sunk cost trap, and boost…Continue reading on Medium » (https://devprogramming.medium.com/my-100-hour-rule-for-bug-bounty-046f96fc7791?source=rss------bug_bounty-5)
Google Cloud Partner API Credentials Found in Public Repo
https://enterlectury.medium.com/google-cloud-partner-api-credentials-found-in-public-repo-45517dc54213?source=rss------bug_bounty-5
https://enterlectury.medium.com/google-cloud-partner-api-credentials-found-in-public-repo-45517dc54213?source=rss------bug_bounty-5
Hey everyone,Continue reading on Medium » (https://enterlectury.medium.com/google-cloud-partner-api-credentials-found-in-public-repo-45517dc54213?source=rss------bug_bounty-5)
From Shodan to Securing Government Systems: BFLA + Stored XSS Write-Up
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been…Continue reading on Medium »
Read more...
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been…Continue reading on Medium »
Read more...
Medium
From Shodan to Securing Government Systems: BFLA + Stored XSS Write-Up
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been sanitized…
Understanding DOM-Based XSS in Acronis Promo Page: A Deep Dive
Exploring How to Detect and Exploit DOM-Based XSSContinue reading on T3CH »
Read more...
Exploring How to Detect and Exploit DOM-Based XSSContinue reading on T3CH »
Read more...
Medium
Understanding DOM-Based XSS in Acronis Promo Page: A Deep Dive
Exploring How to Detect and Exploit DOM-Based XSS
From Shodan to Securing Government Systems: BFLA + Stored XSS Write-Up
https://medium.com/@eclipsedmarauder/from-shodan-to-securing-government-systems-bfla-stored-xss-write-up-ab3bfd4e703d?source=rss------bug_bounty-5
https://medium.com/@eclipsedmarauder/from-shodan-to-securing-government-systems-bfla-stored-xss-write-up-ab3bfd4e703d?source=rss------bug_bounty-5
This is a real security assessment case study. All sensitive details (IPs, domains, ports, and full malicious payloads) have been…Continue reading on Medium » (https://medium.com/@eclipsedmarauder/from-shodan-to-securing-government-systems-bfla-stored-xss-write-up-ab3bfd4e703d?source=rss------bug_bounty-5)
Understanding DOM-Based XSS in Acronis Promo Page: A Deep Dive
https://medium.com/h7w/understanding-dom-based-xss-in-acronis-promo-page-a-deep-dive-568d2ee1284e?source=rss------bug_bounty-5
https://medium.com/h7w/understanding-dom-based-xss-in-acronis-promo-page-a-deep-dive-568d2ee1284e?source=rss------bug_bounty-5
Exploring How to Detect and Exploit DOM-Based XSSContinue reading on T3CH » (https://medium.com/h7w/understanding-dom-based-xss-in-acronis-promo-page-a-deep-dive-568d2ee1284e?source=rss------bug_bounty-5)
Password Reset Poisoning via Middleware: The Hidden Flaw That Can Lead to Account Takeover
How a single unchecked header can hand over your users’ accounts to attackers.Continue reading on InfoSec Write-ups »
Read more...
How a single unchecked header can hand over your users’ accounts to attackers.Continue reading on InfoSec Write-ups »
Read more...
Medium
Password Reset Poisoning via Middleware: The Hidden Flaw That Can Lead to Account Takeover
How a single unchecked header can hand over your users’ accounts to attackers.
Bug Bounty Nightmare: How A Vulnerability Disclosure Turned into Nightmare !
An eye-opening account of hacking into a company’s systems, exposing the steps, and dealing with the aftermath.Continue reading on Medium »
Read more...
An eye-opening account of hacking into a company’s systems, exposing the steps, and dealing with the aftermath.Continue reading on Medium »
Read more...
Medium
Bug Bounty Nightmare: How A Vulnerability Disclosure Turned into Nightmare !
An eye-opening account of hacking into a company’s systems, exposing the steps, and dealing with the aftermath.
The Wild Story of How a Website Bug Could Let Strangers Unlock Cars Anywhere
Researcher Finds Shocking Flaw That Could Let Anyone Hijack Your Car’s FeaturesContinue reading on Readers Club »
Read more...
Researcher Finds Shocking Flaw That Could Let Anyone Hijack Your Car’s FeaturesContinue reading on Readers Club »
Read more...
Medium
The Wild Story of How a Website Bug Could Let Strangers Unlock Cars Anywhere
Researcher Finds Shocking Flaw That Could Let Anyone Hijack Your Car’s Features