My First Accepted Bug!Continue reading on Medium » (https://saurabh-jain.medium.com/recon-to-responsible-disclosure-ee3d308a3b69?source=rss------bug_bounty-5)
Cloudflare Tunnel — Origin Exposure Weaponized
https://p4n7h3rx.medium.com/cloudflare-tunnel-origin-exposure-weaponized-6ae5b1f09bb2?source=rss------bug_bounty-5
https://p4n7h3rx.medium.com/cloudflare-tunnel-origin-exposure-weaponized-6ae5b1f09bb2?source=rss------bug_bounty-5
🔎 IntroductionContinue reading on Medium » (https://p4n7h3rx.medium.com/cloudflare-tunnel-origin-exposure-weaponized-6ae5b1f09bb2?source=rss------bug_bounty-5)
The Little CV + CSRF That Broke an Account
https://0onoproblem.medium.com/the-little-cv-csrf-that-broke-an-account-3c0abbc08597?source=rss------bug_bounty-5
https://0onoproblem.medium.com/the-little-cv-csrf-that-broke-an-account-3c0abbc08597?source=rss------bug_bounty-5
السَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ. اللَّهُمَّ صَلِّ عَلَى مُحَمَّدٍ وَعَلَى آلِ مُحَمَّدٍ، كَمَا صَلَّيْتَ عَلَى…Continue reading on Medium » (https://0onoproblem.medium.com/the-little-cv-csrf-that-broke-an-account-3c0abbc08597?source=rss------bug_bounty-5)
How I Discovered CVE-2025–0133 – Reflected XSS with Shodan Recon
Hello Hackers,Continue reading on Medium »
Read more...
Hello Hackers,Continue reading on Medium »
Read more...
Medium
How I Discovered CVE-2025–0133 – Reflected XSS with Shodan Recon
Hello Hackers,
Bug Bounty Time Travel — Hacking the Past to Predict the Future
⏳ IntroductionContinue reading on Medium »
Read more...
⏳ IntroductionContinue reading on Medium »
Read more...
Medium
Bug Bounty Time Travel — Hacking the Past to Predict the Future
⏳ Introduction
IoT Security - Threat modeling with MITRE ATTACK
https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/
<!-- SC_OFF -->hi folks, Just started in IoT security and want to point out this site for threat modeling and threat analysis for IoT embedded devices - MITRE EMB3D™ (https://emb3d.mitre.org/) Hope this will be new standard for IoT, cause its really comprehensive and detailed analysis from MITRE team. If anyone is included in CS of embeded devices dont skip this one! public webinar available - https://www.youtube.com/watch?v=umld2nY6uas&ab_channel=MITREEMB3D Tnx MITRE! <!-- SC_ON --> submitted by /u/Expensive-One-939 (https://www.reddit.com/user/Expensive-One-939)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/)
https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/
<!-- SC_OFF -->hi folks, Just started in IoT security and want to point out this site for threat modeling and threat analysis for IoT embedded devices - MITRE EMB3D™ (https://emb3d.mitre.org/) Hope this will be new standard for IoT, cause its really comprehensive and detailed analysis from MITRE team. If anyone is included in CS of embeded devices dont skip this one! public webinar available - https://www.youtube.com/watch?v=umld2nY6uas&ab_channel=MITREEMB3D Tnx MITRE! <!-- SC_ON --> submitted by /u/Expensive-One-939 (https://www.reddit.com/user/Expensive-One-939)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5kb0e/iot_security_threat_modeling_with_mitre_attack/)
What topics are you pursuing in pentesting right now?
https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/
<!-- SC_OFF -->As a pentester I'm digging into AI (although I'm tired of this word and hype, but can't miss it) and clouds - both look interesting, and I noticed that a lot of penetration tester vacancies now require them by default. What are you pursuing and why? <!-- SC_ON --> submitted by /u/No_Engine4575 (https://www.reddit.com/user/No_Engine4575)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/)
https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/
<!-- SC_OFF -->As a pentester I'm digging into AI (although I'm tired of this word and hype, but can't miss it) and clouds - both look interesting, and I noticed that a lot of penetration tester vacancies now require them by default. What are you pursuing and why? <!-- SC_ON --> submitted by /u/No_Engine4575 (https://www.reddit.com/user/No_Engine4575)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5nb9s/what_topics_are_you_pursuing_in_pentesting_right/)
From Zero to My First Critical XSS Finding
A Step-by-Step Guide from Recon to ExploitationContinue reading on Medium »
Read more...
A Step-by-Step Guide from Recon to ExploitationContinue reading on Medium »
Read more...
Medium
From Zero to My First Critical XSS Finding
A Step-by-Step Guide from Recon to Exploitation
Trusting 3rd Party Libraries: A Growing Cybersecurity Risk
In today’s technology world, using 3rd party libraries, frameworks and open-source code has become a common practice for developers. These…Continue reading on Medium »
Read more...
In today’s technology world, using 3rd party libraries, frameworks and open-source code has become a common practice for developers. These…Continue reading on Medium »
Read more...
Medium
Trusting 3rd Party Libraries: A Growing Cybersecurity Risk
In today’s technology world, using 3rd party libraries, frameworks and open-source code has become a common practice for developers. These…
Bypassing Subscription Restrictions: A Business Logic Vulnerability in a Video Streaming App
Discover how attackers exploit business logic vulnerabilities to stream paid content for free.Continue reading on Medium »
Read more...
Discover how attackers exploit business logic vulnerabilities to stream paid content for free.Continue reading on Medium »
Read more...
Medium
🎬 Bypassing Subscription Restrictions: A Business Logic Vulnerability in a Video Streaming App 🔐
Discover how attackers exploit business logic vulnerabilities to stream paid content for free.
“Day 26: The Logic Bomb — How I Hacked 0.1% of a Million-User Platform in 10 Minutes”
Exploiting a Flawed State Machine in Password ResetContinue reading on InfoSec Write-ups »
Read more...
Exploiting a Flawed State Machine in Password ResetContinue reading on InfoSec Write-ups »
Read more...
Medium
“Day 25: The Logic Bomb — How I Hacked 0.1% of a Million-User Platform in 10 Minutes”
Exploiting a Flawed State Machine in Password Reset
How I Discovered CVE-2025–0133 – Reflected XSS with Shodan Recon
https://zuksh.medium.com/how-i-discovered-cve-2025-0133-reflected-xss-with-shodan-recon-33297703bfc0?source=rss------bug_bounty-5
https://zuksh.medium.com/how-i-discovered-cve-2025-0133-reflected-xss-with-shodan-recon-33297703bfc0?source=rss------bug_bounty-5
Hello Hackers,Continue reading on Medium » (https://zuksh.medium.com/how-i-discovered-cve-2025-0133-reflected-xss-with-shodan-recon-33297703bfc0?source=rss------bug_bounty-5)
A Critical Zero-Day in Atlassian Jira Service Management Cloud: Password Reset Account Takeover
0-Day ATO By Reset PasswordContinue reading on Medium »
Read more...
0-Day ATO By Reset PasswordContinue reading on Medium »
Read more...
Medium
A Critical Zero-Day in Atlassian Jira Service Management Cloud: Password Reset Account Takeover
0-Day ATO By Reset Password
From image Upload to Workspace Takeover: Deconstructing a Critical Stored XSS Attack
A seemingly harmless feature — file uploading — became the entry point for a complete workspace takeover in a recent vulnerability found…Continue reading on Medium »
Read more...
A seemingly harmless feature — file uploading — became the entry point for a complete workspace takeover in a recent vulnerability found…Continue reading on Medium »
Read more...
Medium
From image Upload to Workspace Takeover: Deconstructing a Critical Stored XSS Attack
A seemingly harmless feature — file uploading — became the entry point for a complete workspace takeover in a recent vulnerability found…