The Ghost Vulnerabilities — How “Fixed Bugs” Come Back From the Dead
👻 IntroductionContinue reading on Medium »
Read more...
👻 IntroductionContinue reading on Medium »
Read more...
Medium
The Ghost Vulnerabilities — How “Fixed Bugs” Come Back From the Dead
👻 Introduction
Not All Vulnerabilities Require Highly Technical Exploits | Security Misconfiguration
A Story of Security MisconfigurationContinue reading on Medium »
Read more...
A Story of Security MisconfigurationContinue reading on Medium »
Read more...
Medium
Not All Vulnerabilities Require Highly Technical Exploits | Security Misconfiguration
A Story of Security Misconfiguration
Critical but very easy Unauthorized Data Disclosure via HTTP Method Manipulation: A Lesson in API…
https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…Continue reading on Medium » (https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5)
https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…Continue reading on Medium » (https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5)
Understanding the OWASP Top 10: The Simplest Guide for Web Security
https://medium.com/@cybersenpai/understanding-the-owasp-top-10-the-simplest-guide-for-web-security-8986530582d6?source=rss------bug_bounty-5
https://medium.com/@cybersenpai/understanding-the-owasp-top-10-the-simplest-guide-for-web-security-8986530582d6?source=rss------bug_bounty-5
The OWASP Top 10 is a globally recognized list of the most critical web application security risks, published by the Open Web Application…Continue reading on Medium » (https://medium.com/@cybersenpai/understanding-the-owasp-top-10-the-simplest-guide-for-web-security-8986530582d6?source=rss------bug_bounty-5)
Recon to Responsible Disclosure
https://saurabh-jain.medium.com/recon-to-responsible-disclosure-ee3d308a3b69?source=rss------bug_bounty-5
https://saurabh-jain.medium.com/recon-to-responsible-disclosure-ee3d308a3b69?source=rss------bug_bounty-5
My First Accepted Bug!Continue reading on Medium » (https://saurabh-jain.medium.com/recon-to-responsible-disclosure-ee3d308a3b69?source=rss------bug_bounty-5)
Cloudflare Tunnel — Origin Exposure Weaponized
https://p4n7h3rx.medium.com/cloudflare-tunnel-origin-exposure-weaponized-6ae5b1f09bb2?source=rss------bug_bounty-5
https://p4n7h3rx.medium.com/cloudflare-tunnel-origin-exposure-weaponized-6ae5b1f09bb2?source=rss------bug_bounty-5
🔎 IntroductionContinue reading on Medium » (https://p4n7h3rx.medium.com/cloudflare-tunnel-origin-exposure-weaponized-6ae5b1f09bb2?source=rss------bug_bounty-5)
The Little CV + CSRF That Broke an Account
https://0onoproblem.medium.com/the-little-cv-csrf-that-broke-an-account-3c0abbc08597?source=rss------bug_bounty-5
https://0onoproblem.medium.com/the-little-cv-csrf-that-broke-an-account-3c0abbc08597?source=rss------bug_bounty-5
السَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ. اللَّهُمَّ صَلِّ عَلَى مُحَمَّدٍ وَعَلَى آلِ مُحَمَّدٍ، كَمَا صَلَّيْتَ عَلَى…Continue reading on Medium » (https://0onoproblem.medium.com/the-little-cv-csrf-that-broke-an-account-3c0abbc08597?source=rss------bug_bounty-5)
How I Discovered CVE-2025–0133 – Reflected XSS with Shodan Recon
Hello Hackers,Continue reading on Medium »
Read more...
Hello Hackers,Continue reading on Medium »
Read more...
Medium
How I Discovered CVE-2025–0133 – Reflected XSS with Shodan Recon
Hello Hackers,
Bug Bounty Time Travel — Hacking the Past to Predict the Future
⏳ IntroductionContinue reading on Medium »
Read more...
⏳ IntroductionContinue reading on Medium »
Read more...
Medium
Bug Bounty Time Travel — Hacking the Past to Predict the Future
⏳ Introduction
IoT Security - Threat modeling with MITRE ATTACK
https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/
<!-- SC_OFF -->hi folks, Just started in IoT security and want to point out this site for threat modeling and threat analysis for IoT embedded devices - MITRE EMB3D™ (https://emb3d.mitre.org/) Hope this will be new standard for IoT, cause its really comprehensive and detailed analysis from MITRE team. If anyone is included in CS of embeded devices dont skip this one! public webinar available - https://www.youtube.com/watch?v=umld2nY6uas&ab_channel=MITREEMB3D Tnx MITRE! <!-- SC_ON --> submitted by /u/Expensive-One-939 (https://www.reddit.com/user/Expensive-One-939)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/)
https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/
<!-- SC_OFF -->hi folks, Just started in IoT security and want to point out this site for threat modeling and threat analysis for IoT embedded devices - MITRE EMB3D™ (https://emb3d.mitre.org/) Hope this will be new standard for IoT, cause its really comprehensive and detailed analysis from MITRE team. If anyone is included in CS of embeded devices dont skip this one! public webinar available - https://www.youtube.com/watch?v=umld2nY6uas&ab_channel=MITREEMB3D Tnx MITRE! <!-- SC_ON --> submitted by /u/Expensive-One-939 (https://www.reddit.com/user/Expensive-One-939)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/)
What topics are you pursuing in pentesting right now?
https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/
<!-- SC_OFF -->As a pentester I'm digging into AI (although I'm tired of this word and hype, but can't miss it) and clouds - both look interesting, and I noticed that a lot of penetration tester vacancies now require them by default. What are you pursuing and why? <!-- SC_ON --> submitted by /u/No_Engine4575 (https://www.reddit.com/user/No_Engine4575)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/)
https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/
<!-- SC_OFF -->As a pentester I'm digging into AI (although I'm tired of this word and hype, but can't miss it) and clouds - both look interesting, and I noticed that a lot of penetration tester vacancies now require them by default. What are you pursuing and why? <!-- SC_ON --> submitted by /u/No_Engine4575 (https://www.reddit.com/user/No_Engine4575)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/)
From Zero to My First Critical XSS Finding
A Step-by-Step Guide from Recon to ExploitationContinue reading on Medium »
Read more...
A Step-by-Step Guide from Recon to ExploitationContinue reading on Medium »
Read more...
Medium
From Zero to My First Critical XSS Finding
A Step-by-Step Guide from Recon to Exploitation
Trusting 3rd Party Libraries: A Growing Cybersecurity Risk
In today’s technology world, using 3rd party libraries, frameworks and open-source code has become a common practice for developers. These…Continue reading on Medium »
Read more...
In today’s technology world, using 3rd party libraries, frameworks and open-source code has become a common practice for developers. These…Continue reading on Medium »
Read more...
Medium
Trusting 3rd Party Libraries: A Growing Cybersecurity Risk
In today’s technology world, using 3rd party libraries, frameworks and open-source code has become a common practice for developers. These…