StegoRSA — picoCTF Writeup (Steganography + RSA Deep Dive)
Challenge DescriptionContinue reading on Medium »
Read more...
Challenge DescriptionContinue reading on Medium »
Read more...
Medium
StegoRSA — picoCTF Writeup (Steganography + RSA Deep Dive)
Challenge Description
How I Found Internal Products Exposed via API
While testing a web application during my internship, I came across an interesting API endpoint:Continue reading on Medium »
Read more...
While testing a web application during my internship, I came across an interesting API endpoint:Continue reading on Medium »
Read more...
Medium
How I Found Internal Products Exposed via API
While testing a web application during my internship, I came across an interesting API endpoint:
The Year 2038 Problem: The Next “Y2K” Waiting to Happen?
https://medium.com/@shubhamvartak01/the-year-2038-problem-the-next-y2k-waiting-to-happen-2ba3fdc72ea5?source=rss------bug_bounty-5
https://medium.com/@shubhamvartak01/the-year-2038-problem-the-next-y2k-waiting-to-happen-2ba3fdc72ea5?source=rss------bug_bounty-5
Hey there 👋
You’ve probably heard about the famous Y2K bug, right? The one that made the world panic as the year 2000 approached.Continue reading on Medium » (https://medium.com/@shubhamvartak01/the-year-2038-problem-the-next-y2k-waiting-to-happen-2ba3fdc72ea5?source=rss------bug_bounty-5)
You’ve probably heard about the famous Y2K bug, right? The one that made the world panic as the year 2000 approached.Continue reading on Medium » (https://medium.com/@shubhamvartak01/the-year-2038-problem-the-next-y2k-waiting-to-happen-2ba3fdc72ea5?source=rss------bug_bounty-5)
Axios npm compromise—Recreation & PoC write-up
https://medium.com/@akshatshirsat77/axios-npm-compromise-recreation-poc-write-up-302ee17e659b?source=rss------bug_bounty-5
https://medium.com/@akshatshirsat77/axios-npm-compromise-recreation-poc-write-up-302ee17e659b?source=rss------bug_bounty-5
Intro — Recently there was an incident involving Axios where a malicious version got pushed to npm. It wasn’t really a bug in Axios code…Continue reading on Medium » (https://medium.com/@akshatshirsat77/axios-npm-compromise-recreation-poc-write-up-302ee17e659b?source=rss------bug_bounty-5)
️Unmasking the Battlefield: Understanding the Professional Hacker Mindset
जय श्री राम 🚩 ,HackersContinue reading on Medium »
Read more...
जय श्री राम 🚩 ,HackersContinue reading on Medium »
Read more...
Medium
🛡️Unmasking the Battlefield: Understanding the Professional Hacker Mindset
जय श्री राम 🚩 ,Hackers
Reverse Engineering a WhatsApp 0-Click Vulnerability: A Deep Dive into CVE-2025–43300
Based on “Reverse Engineering a WhatsApp 0-Click Vulnerability” by Billy EllisContinue reading on InfoSec Write-ups »
Read more...
Based on “Reverse Engineering a WhatsApp 0-Click Vulnerability” by Billy EllisContinue reading on InfoSec Write-ups »
Read more...
Medium
Reverse Engineering a WhatsApp 0-Click Vulnerability: A Deep Dive into CVE-2025–43300
Based on “Reverse Engineering a WhatsApp 0-Click Vulnerability” by Billy Ellis
An AI Grader Was Tricked Into Giving a Perfect Score Here’s How Prompt Injection Works
A real-world vulnerability class discovered in a production AI application — reproduced in a controlled lab to show developers exactly…Continue reading on Medium »
Read more...
A real-world vulnerability class discovered in a production AI application — reproduced in a controlled lab to show developers exactly…Continue reading on Medium »
Read more...
Medium
An AI Grader Was Tricked Into Giving a Perfect Score Here’s How Prompt Injection Works
A real-world vulnerability class discovered in a production AI application — reproduced in a controlled lab to show developers exactly what…
Reverse Engineering a WhatsApp 0-Click Vulnerability: A Deep Dive into CVE-2025–43300
https://infosecwriteups.com/reverse-engineering-a-whatsapp-0-click-vulnerability-a-deep-dive-into-cve-2025-43300-d8d425644fe9?source=rss------bug_bounty-5
https://infosecwriteups.com/reverse-engineering-a-whatsapp-0-click-vulnerability-a-deep-dive-into-cve-2025-43300-d8d425644fe9?source=rss------bug_bounty-5
Based on “Reverse Engineering a WhatsApp 0-Click Vulnerability” by Billy EllisContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/reverse-engineering-a-whatsapp-0-click-vulnerability-a-deep-dive-into-cve-2025-43300-d8d425644fe9?source=rss------bug_bounty-5)
An AI Grader Was Tricked Into Giving a Perfect Score Here’s How Prompt Injection Works
https://blackhawkk.medium.com/an-ai-grader-was-tricked-into-giving-a-perfect-score-heres-how-prompt-injection-works-613df9411584?source=rss------bug_bounty-5
https://blackhawkk.medium.com/an-ai-grader-was-tricked-into-giving-a-perfect-score-heres-how-prompt-injection-works-613df9411584?source=rss------bug_bounty-5
A real-world vulnerability class discovered in a production AI application — reproduced in a controlled lab to show developers exactly…Continue reading on Medium » (https://blackhawkk.medium.com/an-ai-grader-was-tricked-into-giving-a-perfect-score-heres-how-prompt-injection-works-613df9411584?source=rss------bug_bounty-5)
Exploiting Certificates for Lateral Movement
Pass-the-Certificate is a highly effective post-exploitation technique that leverages X.509 certificates instead of traditional passwords…Continue reading on Medium »
Read more...
Pass-the-Certificate is a highly effective post-exploitation technique that leverages X.509 certificates instead of traditional passwords…Continue reading on Medium »
Read more...
Medium
Exploiting Certificates for Lateral Movement
Pass-the-Certificate is a highly effective post-exploitation technique that leverages X.509 certificates instead of traditional passwords…
AmassAdvanced Recon Mastery: Attack Surface Ko Poora Expose Karo! (Hinglish Mein)
Series: Bug Bounty Zero se Hero 🦸 | Article #7 By HackerMD | 18 min readContinue reading on Medium »
Read more...
Series: Bug Bounty Zero se Hero 🦸 | Article #7 By HackerMD | 18 min readContinue reading on Medium »
Read more...
Medium
AmassAdvanced Recon Mastery: Attack Surface Ko Poora Expose Karo! (Hinglish Mein)
Series: Bug Bounty Zero se Hero 🦸 | Article #7 By HackerMD | 18 min read
How I Found a Critical SAML Authentication Bypasson a Major Automotive Company's Dealer Portal
INTRODUCTION:Continue reading on Medium »
Read more...
INTRODUCTION:Continue reading on Medium »
Read more...
Medium
How I Found a Critical SAML Authentication Bypasson a Major Automotive Company's Dealer Portal
INTRODUCTION:
Advanced IDOR Guide: How to Find and Exploit Broken Access Control in Modern APIs
Stop looking for id=1. Start hunting the authorization mistakes developers don’t see.Continue reading on Medium »
Read more...
Stop looking for id=1. Start hunting the authorization mistakes developers don’t see.Continue reading on Medium »
Read more...
Medium
Advanced IDOR Guide: How to Find and Exploit Broken Access Control in Modern APIs
Stop looking for id=1. Start hunting the authorization mistakes developers don’t see.
Exploiting Certificates for Lateral Movement
https://medium.com/@pentesterclubpvtltd/exploiting-certificates-for-lateral-movement-a2e5c4b0e155?source=rss------bug_bounty-5
https://medium.com/@pentesterclubpvtltd/exploiting-certificates-for-lateral-movement-a2e5c4b0e155?source=rss------bug_bounty-5