How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path
Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.Continue reading on Medium »
Read more...
Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.Continue reading on Medium »
Read more...
Medium
How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path
Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.
Why Most Bug Bounty Findings Come From Thinking, Not Tools
A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst »
Read more...
A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst »
Read more...
Medium
Why Most Bug Bounty Findings Come From Thinking, Not Tools
A practitioner’s guide to sustainable web security testing
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium »
Read more...
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium »
Read more...
Medium
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…
Broken Access Control: low-privilege user dapat Menghapus Lampiran Slip Gaji Melalui Endpoint…
PendahuluanContinue reading on Medium »
Read more...
PendahuluanContinue reading on Medium »
Read more...
Medium
Broken Access Control: low-privilege user dapat Menghapus file/attachment Lampiran Melalui…
Broken Access Control: low-privilege user dapat Menghapus file/attachment Lampiran Melalui Endpoint Tersembunyi Pendahuluan Beberapa bulan lalu saya menemukan kerentanan Broken Access Control (IDOR) …
Hidden Admin Tools → Full Exploitation Chains
How JavaScript-Exposed Admin Features Turn Into Real-World Critical VulnerabilitiesContinue reading on OSINT Team »
Read more...
How JavaScript-Exposed Admin Features Turn Into Real-World Critical VulnerabilitiesContinue reading on OSINT Team »
Read more...
Medium
Hidden Admin Tools → Full Exploitation Chains
How JavaScript-Exposed Admin Features Turn Into Real-World Critical Vulnerabilities
The Password Alchemist: How a Simple Parameter Swap Led to Full Account Takeover
Because sometimes the “Forgot Password?” feature forgets who’s asking.Continue reading on OSINT Team »
Read more...
Because sometimes the “Forgot Password?” feature forgets who’s asking.Continue reading on OSINT Team »
Read more...
Medium
The Password Alchemist: How a Simple Parameter Swap Led to Full Account Takeover
Because sometimes the “Forgot Password?” feature forgets who’s asking.
Ink Dragon's Relay Network and Stealthy Offensive Operation
https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/)
https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ppmtm7/ink_dragons_relay_network_and_stealthy_offensive/)
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182)
Continue reading on OSINT Team »
Read more...
Continue reading on OSINT Team »
Read more...
Medium
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182)
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182) Introduction In the rapidly evolving landscape of web development, React has established itself as a …
How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path
https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5
https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5
Most impactful vulnerabilities are not found by scanning tools or exploit templates.
They are found by questioning assumptions.Continue reading on Medium » (https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5)
They are found by questioning assumptions.Continue reading on Medium » (https://medium.com/@Rawi1X/how-i-found-a-zero-click-flaw-by-questioning-a-safe-rendering-path-b104c29a3e8e?source=rss------bug_bounty-5)
Why Most Bug Bounty Findings Come From Thinking, Not Tools
https://medium.com/write-a-catalyst/why-most-bug-bounty-findings-come-from-thinking-not-tools-2899347e6890?source=rss------bug_bounty-5
https://medium.com/write-a-catalyst/why-most-bug-bounty-findings-come-from-thinking-not-tools-2899347e6890?source=rss------bug_bounty-5
A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst » (https://medium.com/write-a-catalyst/why-most-bug-bounty-findings-come-from-thinking-not-tools-2899347e6890?source=rss------bug_bounty-5)
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset
https://medium.com/@Cyber-AppSec/why-ai-driven-vibe-hacking-demands-a-new-devsecops-mindset-790c0383ca38?source=rss------bug_bounty-5
https://medium.com/@Cyber-AppSec/why-ai-driven-vibe-hacking-demands-a-new-devsecops-mindset-790c0383ca38?source=rss------bug_bounty-5
AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium » (https://medium.com/@Cyber-AppSec/why-ai-driven-vibe-hacking-demands-a-new-devsecops-mindset-790c0383ca38?source=rss------bug_bounty-5)
How 4 Months of Sleepless Nights Led Me to My First NASA Letter of Recognition
by Ninad GowdaContinue reading on Medium »
Read more...
by Ninad GowdaContinue reading on Medium »
Read more...
Medium
How 4 Months of Sleepless Nights Led Me to My First NASA Letter of Recognition
by Ninad Gowda
Don’t Just Patch; Predict: How I Used Dark Web Chatter to Find a Vulnerability Before It Was…
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Don’t Just Patch; Predict: How I Used Dark Web Chatter to Find a Vulnerability Before It Was Exploited 🔮💻
Free Link 🎈
From Brute-Force to Bounty: My $200 and Double XSS Win on Acronis
In the world of cybersecurity, bug bounty programs stand as a crucial bridge between organizations and security researchers. These programs incentivize ethical hackers to identify and report vulnerabilities, ultimately making the digital world safer. I’m excited to share my recent experience participating in the HackerOne bug bounty program and uncovering not one, but two Cross-Site Scripting (XSS) vulnerabilities on Acronis platforms.Report 1: XSS in Acronis Login Callback URL My first discovery centered around the login callback URL for Acronis, specifically https://learn.acronis.com/portal/. During the login process, the redirectUrl parameter, designed to redirect users back to their intended destination, was not properly secured. This oversight paved the way for a classic XSS attack. Simply crafting a malicious URL and enticing a user to click it was enough to trigger the vulnerability. For example, a URL like this could be used: https://learn.acronis.com/portal/?redirectUrl=javascript:alert(document.domain) Here is my original disclosure report URL if you want it: https://hackerone.com/reports/2611305 For This I was rewarded $100 for this: My AcronisReport 2: Double Parameter Trouble! During further testing on the Acronis learn platform, I decided to brute-force variations of the redirectUrl parameter. This led to the discovery of a second, similar parameter: redirect_url. Unfortunately, this parameter was also vulnerable to the same XSS flaw. Vulnerability: XSS (on both redirecturl and redirecturl) Here is my original disclosure report URL if you want it: https://hackerone.com/reports/2653342ConclusionThese three XSS findings emphasize secure coding, especially with user inputs and redirects. The discovery of the redirect_Url parameter through brute-forcing shows how important it is to go beyond basic testing and explore parameter variations. Acronis' quick response demonstrates their security commitment. Bug bounty programs are vital for collaborative security improvement and uncovering these kinds of nuanced vulnerabilities. Stay tuned for more cybersecurity insights! From Brute-Force to Bounty: My $200 and Double XSS Win on Acronis was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
In the world of cybersecurity, bug bounty programs stand as a crucial bridge between organizations and security researchers. These programs incentivize ethical hackers to identify and report vulnerabilities, ultimately making the digital world safer. I’m excited to share my recent experience participating in the HackerOne bug bounty program and uncovering not one, but two Cross-Site Scripting (XSS) vulnerabilities on Acronis platforms.Report 1: XSS in Acronis Login Callback URL My first discovery centered around the login callback URL for Acronis, specifically https://learn.acronis.com/portal/. During the login process, the redirectUrl parameter, designed to redirect users back to their intended destination, was not properly secured. This oversight paved the way for a classic XSS attack. Simply crafting a malicious URL and enticing a user to click it was enough to trigger the vulnerability. For example, a URL like this could be used: https://learn.acronis.com/portal/?redirectUrl=javascript:alert(document.domain) Here is my original disclosure report URL if you want it: https://hackerone.com/reports/2611305 For This I was rewarded $100 for this: My AcronisReport 2: Double Parameter Trouble! During further testing on the Acronis learn platform, I decided to brute-force variations of the redirectUrl parameter. This led to the discovery of a second, similar parameter: redirect_url. Unfortunately, this parameter was also vulnerable to the same XSS flaw. Vulnerability: XSS (on both redirecturl and redirecturl) Here is my original disclosure report URL if you want it: https://hackerone.com/reports/2653342ConclusionThese three XSS findings emphasize secure coding, especially with user inputs and redirects. The discovery of the redirect_Url parameter through brute-forcing shows how important it is to go beyond basic testing and explore parameter variations. Acronis' quick response demonstrates their security commitment. Bug bounty programs are vital for collaborative security improvement and uncovering these kinds of nuanced vulnerabilities. Stay tuned for more cybersecurity insights! From Brute-Force to Bounty: My $200 and Double XSS Win on Acronis was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Acronis
Management portal
Advanced all-in-one learning platform for education and research focusing on rapid authoring, interactive & active learning and limitless expansibility. Create exceptional learner experience with practical multimedia blocks, coding exercises, adaptive quizzes…
You’re Fuzzing All Wrong: FFUF & Virtual Host Fuzzing
📖FREE LINK HERE . A hands-on story of how FFUF virtual host fuzzing exposed hidden infrastructure, internal APIs, and four flags.Continue reading on InfoSec Write-ups »
Read more...
📖FREE LINK HERE . A hands-on story of how FFUF virtual host fuzzing exposed hidden infrastructure, internal APIs, and four flags.Continue reading on InfoSec Write-ups »
Read more...
Medium
You’re Fuzzing All Wrong: FFUF & Virtual Host Fuzzing
📖FREE LINK HERE . A hands-on story of how FFUF virtual host fuzzing exposed hidden infrastructure, internal APIs, and four flags.