My server was asking Amazon for sensitive credentials, and it was all because of a PDF button.Continue reading on Medium » (https://medium.com/@codii/from-a-simple-certificate-to-a-critical-cloud-flaw-a-bug-bounty-journey-1e613efc42fc?source=rss------bug_bounty-5)
From a Simple Certificate to a Critical Cloud Flaw: A Bug Bounty Journey
My server was asking Amazon for sensitive credentials, and it was all because of a PDF button.Continue reading on Medium »
Read more...
My server was asking Amazon for sensitive credentials, and it was all because of a PDF button.Continue reading on Medium »
Read more...
Medium
From a Simple Certificate to a Critical Cloud Flaw: A Bug Bounty Journey
My server was asking Amazon for sensitive credentials, and it was all because of a PDF button.
Write-Up — Publicly Exposed MySQL on an “Inactive” Subdomain (KAIAWEB-216)
During a scoped bug-bounty engagement I discovered a MySQL/MariaDB service publicly reachable on shop.kaia.io (IP 147.93.79.55) that…Continue reading on Medium »
Read more...
During a scoped bug-bounty engagement I discovered a MySQL/MariaDB service publicly reachable on shop.kaia.io (IP 147.93.79.55) that…Continue reading on Medium »
Read more...
Medium
Write-Up — Publicly Exposed MySQL on an “Inactive” Subdomain (KAIAWEB-216)
During a scoped bug-bounty engagement I discovered a MySQL/MariaDB service publicly reachable on shop.kaia.io (IP 147.93.79.55) that…
How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path
Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.Continue reading on Medium »
Read more...
Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.Continue reading on Medium »
Read more...
Medium
How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path
Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.
Why Most Bug Bounty Findings Come From Thinking, Not Tools
A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst »
Read more...
A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst »
Read more...
Medium
Why Most Bug Bounty Findings Come From Thinking, Not Tools
A practitioner’s guide to sustainable web security testing
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium »
Read more...
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium »
Read more...
Medium
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…
Broken Access Control: low-privilege user dapat Menghapus Lampiran Slip Gaji Melalui Endpoint…
PendahuluanContinue reading on Medium »
Read more...
PendahuluanContinue reading on Medium »
Read more...
Medium
Broken Access Control: low-privilege user dapat Menghapus file/attachment Lampiran Melalui…
Broken Access Control: low-privilege user dapat Menghapus file/attachment Lampiran Melalui Endpoint Tersembunyi Pendahuluan Beberapa bulan lalu saya menemukan kerentanan Broken Access Control (IDOR) …
Hidden Admin Tools → Full Exploitation Chains
How JavaScript-Exposed Admin Features Turn Into Real-World Critical VulnerabilitiesContinue reading on OSINT Team »
Read more...
How JavaScript-Exposed Admin Features Turn Into Real-World Critical VulnerabilitiesContinue reading on OSINT Team »
Read more...
Medium
Hidden Admin Tools → Full Exploitation Chains
How JavaScript-Exposed Admin Features Turn Into Real-World Critical Vulnerabilities
The Password Alchemist: How a Simple Parameter Swap Led to Full Account Takeover
Because sometimes the “Forgot Password?” feature forgets who’s asking.Continue reading on OSINT Team »
Read more...
Because sometimes the “Forgot Password?” feature forgets who’s asking.Continue reading on OSINT Team »
Read more...
Medium
The Password Alchemist: How a Simple Parameter Swap Led to Full Account Takeover
Because sometimes the “Forgot Password?” feature forgets who’s asking.
Ink Dragon's Relay Network and Stealthy Offensive Operation
https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/)
https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/)
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182)
Continue reading on OSINT Team »
Read more...
Continue reading on OSINT Team »
Read more...
Medium
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182)
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182) Introduction In the rapidly evolving landscape of web development, React has established itself as a …
How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path
https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5
https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5
Most impactful vulnerabilities are not found by scanning tools or exploit templates.
They are found by questioning assumptions.Continue reading on Medium » (https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5)
They are found by questioning assumptions.Continue reading on Medium » (https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5)
Why Most Bug Bounty Findings Come From Thinking, Not Tools
https://medium.com/write-a-catalyst/why-most-bug-bounty-findings-come-from-thinking-not-tools-2899347e6890?source=rss------bug_bounty-5
https://medium.com/write-a-catalyst/why-most-bug-bounty-findings-come-from-thinking-not-tools-2899347e6890?source=rss------bug_bounty-5
A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst » (https://medium.com/write-a-catalyst/why-most-bug-bounty-findings-come-from-thinking-not-tools-2899347e6890?source=rss------bug_bounty-5)
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset
https://medium.com/@Cyber-AppSec/why-ai-driven-vibe-hacking-demands-a-new-devsecops-mindset-790c0383ca38?source=rss------bug_bounty-5
https://medium.com/@Cyber-AppSec/why-ai-driven-vibe-hacking-demands-a-new-devsecops-mindset-790c0383ca38?source=rss------bug_bounty-5
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium » (https://medium.com/@Cyber-AppSec/why-ai-driven-vibe-hacking-demands-a-new-devsecops-mindset-790c0383ca38?source=rss------bug_bounty-5)
How 4 Months of Sleepless Nights Led Me to My First NASA Letter of Recognition
by Ninad GowdaContinue reading on Medium »
Read more...
by Ninad GowdaContinue reading on Medium »
Read more...
Medium
How 4 Months of Sleepless Nights Led Me to My First NASA Letter of Recognition
by Ninad Gowda