Project Page Here: https://humble-raptor-f30.notion.site/TOTP-Classroom-Activity-15a4c8e5237680429670e050f958c68e?source=copy_linkContinue reading on Medium » (https://medium.com/@josh.beck2006/cybersecurity-lab-authenticator-apps-how-they-work-and-what-students-need-to-know-for-security-ee30277b5495?source=rss------bug_bounty-5)
How I Discover what Developers Forgot to Secure(Bug Bounty)
Some of the most impactful vulnerabilities are not complex, they exist because of simple mistakes. Hidden files and endpoints are often…Continue reading on Medium »
Read more...
Some of the most impactful vulnerabilities are not complex, they exist because of simple mistakes. Hidden files and endpoints are often…Continue reading on Medium »
Read more...
Medium
How I Discover what Developers Forgot to Secure(Bug Bounty)
Some of the most impactful vulnerabilities are not complex, they exist because of simple mistakes. Hidden files and endpoints are often…
Wordpress Hacking
All You Need To Know . Learning With Live Targets !Continue reading on Medium »
Read more...
All You Need To Know . Learning With Live Targets !Continue reading on Medium »
Read more...
Medium
Wordpress Hacking
All You Need To Know . Learning With Live Targets !
How I Discover what Developers Forgot to Secure(Bug Bounty)
https://medium.com/@thenewdate24/how-i-discover-what-developers-forgot-to-secure-bug-bounty-cce0468031aa?source=rss------bug_bounty-5
https://medium.com/@thenewdate24/how-i-discover-what-developers-forgot-to-secure-bug-bounty-cce0468031aa?source=rss------bug_bounty-5
Some of the most impactful vulnerabilities are not complex, they exist because of simple mistakes. Hidden files and endpoints are often…Continue reading on Medium » (https://medium.com/@thenewdate24/how-i-discover-what-developers-forgot-to-secure-bug-bounty-cce0468031aa?source=rss------bug_bounty-5)
All You Need To Know . Learning With Live Targets !Continue reading on Medium » (https://d0natel00.medium.com/wordpress-hacking-599bf729e738?source=rss------bug_bounty-5)
Hey Everyone!Continue reading on Medium » (https://medium.com/@Muhammad_Wageh/500-in-just-a-single-idor-b13e9df22f4a?source=rss------bug_bounty-5)
How I Chained Mass Assignment and CSV Injection to Exfiltrate Corporate Data
IntroductionContinue reading on System Weakness »
Read more...
IntroductionContinue reading on System Weakness »
Read more...
Medium
How I Chained Mass Assignment and CSV Injection to Exfiltrate Corporate Data
Introduction
Authentication Bypass & Username Enumeration in AdminPanel (Jason2605)
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Medium
🔐 Authentication Bypass & Username Enumeration in AdminPanel (Jason2605)
🔐 Authentication Bypass & Username Enumeration in AdminPanel (Jason2605) 📌 Introduction During security testing of the AdminPanel project by Jason2605, multiple vulnerabilities were identified …
Blind SQL Injection in Yahoo!
In 2014, Stefano Vettorazzi discovered a significant vulnerability in Boolean-based blind SQL.affecting the Yahoo! Sports draft endpoint.Continue reading on Medium »
Read more...
In 2014, Stefano Vettorazzi discovered a significant vulnerability in Boolean-based blind SQL.affecting the Yahoo! Sports draft endpoint.Continue reading on Medium »
Read more...
Medium
Blind SQL Injection in Yahoo!
In 2014, Stefano Vettorazzi discovered a significant vulnerability in Boolean-based blind SQL.affecting the Yahoo! Sports draft endpoint.
Deterministic Network Halt: How a Nil Pointer in BSC Geth Can Stop a Blockchain
Introduction In the high-stakes world of blockchain security, the spotlight usually falls on clever DeFi flash loan exploits or complex…Continue reading on Block Magnates »
Read more...
Introduction In the high-stakes world of blockchain security, the spotlight usually falls on clever DeFi flash loan exploits or complex…Continue reading on Block Magnates »
Read more...
Medium
Deterministic Network Halt: How a Nil Pointer in BSC Geth Can Stop a Blockchain
Introduction
In the high-stakes world of blockchain security, the spotlight usually falls on clever DeFi flash loan exploits or complex…
In the high-stakes world of blockchain security, the spotlight usually falls on clever DeFi flash loan exploits or complex…
Resolute | HackTheBox | OSCP Preparation
Firstly, we start off by setting our environment variable $target to the machine’s IP so as we don’t have to manually type its IPContinue reading on Medium »
Read more...
Firstly, we start off by setting our environment variable $target to the machine’s IP so as we don’t have to manually type its IPContinue reading on Medium »
Read more...
Medium
Resolute | HackTheBox | OSCP Preparation
Firstly, we start off by setting our environment variable $target to the machine’s IP so as we don’t have to manually type its IP
Hacking NASA Without a Login: How One Clojure Function Gave Me Root Access
You get used to looking at a lot of source code when bug hunting. Most of the time it’s a grind, but every once in a while, you spot…Continue reading on Medium »
Read more...
You get used to looking at a lot of source code when bug hunting. Most of the time it’s a grind, but every once in a while, you spot…Continue reading on Medium »
Read more...
Medium
Hacking NASA Without a Login: How One Clojure Function Gave Me Root Access
You get used to looking at a lot of source code when bug hunting. Most of the time it’s a grind, but every once in a while, you spot…
(ab)using windows toast notification for fun and user manipulation
https://www.reddit.com/r/redteamsec/comments/1rys5zy/abusing_windows_toast_notification_for_fun_and/
<!-- SC_OFF -->During some free time I ended up doing some research on something I never really thought about before: using Windows toast notifications for user manipulation. I ended up writing a BOF and a blog post about it, hope it's useful. Blog post: https://brmk.me/2026/03/18/toast-my-way.html BOF: https://github.com/brmkit/toastnotify-bof <!-- SC_ON --> submitted by /u/brmkit (https://www.reddit.com/user/brmkit)
[link] (https://brmk.me/2026/03/18/toast-my-way.html) [comments] (https://www.reddit.com/r/redteamsec/comments/1rys5zy/abusing_windows_toast_notification_for_fun_and/)
https://www.reddit.com/r/redteamsec/comments/1rys5zy/abusing_windows_toast_notification_for_fun_and/
<!-- SC_OFF -->During some free time I ended up doing some research on something I never really thought about before: using Windows toast notifications for user manipulation. I ended up writing a BOF and a blog post about it, hope it's useful. Blog post: https://brmk.me/2026/03/18/toast-my-way.html BOF: https://github.com/brmkit/toastnotify-bof <!-- SC_ON --> submitted by /u/brmkit (https://www.reddit.com/user/brmkit)
[link] (https://brmk.me/2026/03/18/toast-my-way.html) [comments] (https://www.reddit.com/r/redteamsec/comments/1rys5zy/abusing_windows_toast_notification_for_fun_and/)
AI agent hacked McKinsey's chatbot and gained full read-write access in just two hours
https://www.reddit.com/r/redteamsec/comments/1ryummv/ai_agent_hacked_mckinseys_chatbot_and_gained_full/
<!-- SC_OFF -->A new report from The Register reveals that an autonomous AI agent built by security startup CodeWall successfully hacked into the internal AI platform Lilli used by McKinsey in just two hours. Operating entirely without human input the offensive AI discovered exposed endpoints and a severe SQL injection vulnerability granting it full read and write access to millions of highly confidential chat messages strategy documents and system prompts. <!-- SC_ON --> submitted by /u/EchoOfOppenheimer (https://www.reddit.com/user/EchoOfOppenheimer)
[link] (https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_hacked/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ryummv/ai_agent_hacked_mckinseys_chatbot_and_gained_full/)
https://www.reddit.com/r/redteamsec/comments/1ryummv/ai_agent_hacked_mckinseys_chatbot_and_gained_full/
<!-- SC_OFF -->A new report from The Register reveals that an autonomous AI agent built by security startup CodeWall successfully hacked into the internal AI platform Lilli used by McKinsey in just two hours. Operating entirely without human input the offensive AI discovered exposed endpoints and a severe SQL injection vulnerability granting it full read and write access to millions of highly confidential chat messages strategy documents and system prompts. <!-- SC_ON --> submitted by /u/EchoOfOppenheimer (https://www.reddit.com/user/EchoOfOppenheimer)
[link] (https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_hacked/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ryummv/ai_agent_hacked_mckinseys_chatbot_and_gained_full/)