Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Web Uygulamalarında Veri Giriş Güvenliği: HTML Injection ve XSS Analizi

Web uygulamalarında kullanıcıdan alınan verinin nasıl işlendiği kritik bir konudur. Gerekli kontroller yapılmazsa, bu veriler üzerinden…Continue reading on Medium »
Read more...
Web Uygulamalarında Veri Giriş Güvenliği: HTML Injection ve XSS Analizi
https://medium.com/@adaraydinoglu/html-injection-ve-xss-temelden-ger%C3%A7ek-senaryolara-42af09d17e1a?source=rss------bug_bounty-5

Web uygulamalarında kullanıcıdan alınan verinin nasıl işlendiği kritik bir konudur. Gerekli kontroller yapılmazsa, bu veriler üzerinden…Continue reading on Medium » (https://medium.com/@adaraydinoglu/html-injection-ve-xss-temelden-ger%C3%A7ek-senaryolara-42af09d17e1a?source=rss------bug_bounty-5)
I Found a “Hidden” API Bug That Could Have Paid $2,000+ — And Most Hackers Would Miss It

💻 This invisible vulnerability exposed user data… and turned into a high-paying bug bounty 🚨Continue reading on OSINT Team »
Read more...
From Low Bug to $1000 Bounty — The Privilege Escalation Playbook Every Hacker Should Know

💻 How a simple IDOR turned into full admin access (and what most hunters completely miss) 🚨Continue reading on OSINT Team »
Read more...
💻 This invisible vulnerability exposed user data… and turned into a high-paying bug bounty 🚨Continue reading on OSINT Team » (https://osintteam.blog/i-found-a-hidden-api-bug-that-could-have-paid-2-000-and-most-hackers-would-miss-it-99c641560e17?source=rss------bug_bounty-5)
💻 How a simple IDOR turned into full admin access (and what most hunters completely miss) 🚨Continue reading on OSINT Team » (https://osintteam.blog/from-low-bug-to-1000-bounty-the-privilege-escalation-playbook-every-hacker-should-know-35fad04ff112?source=rss------bug_bounty-5)
My Bug Bounty Journey #7: When Hidden URLs Aren’t Secure

BackgroundContinue reading on Medium »
Read more...
ClickFix Hits macOS via AI Tools: Real Attack Analyzed
https://www.reddit.com/r/redteamsec/comments/1sew24m/clickfix_hits_macos_via_ai_tools_real_attack/

<!-- SC_OFF --> The ClickFix technique has evolved. Attackers now mimic and abuse legitimate AI platforms like Claude Code and Grok, exploiting the trust employees place in these tools to bypass traditional security controls entirely. macOS is no longer a low-risk environment. Engineering, product, and executive teams are disproportionately Mac users with privileged access, making them high-value targets. <!-- SC_ON --> submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/macos-clickfix-amos-attack/?utm_source=reddit) [comments] (https://www.reddit.com/r/redteamsec/comments/1sew24m/clickfix_hits_macos_via_ai_tools_real_attack/)
The Race to Ship AI Tools Left Security Behind. Part 1: Sandbox Escape
https://www.reddit.com/r/redteamsec/comments/1sf54ak/the_race_to_ship_ai_tools_left_security_behind/

<!-- SC_OFF -->AI coding tools are being shipped fast. In too many cases, basic security is not keeping up. In our latest research, we found the same sandbox trust-boundary failure pattern across tools from Anthropic, Google, and OpenAI. Anthropic fixed and engaged quickly (CVE-2026-25725). Google did not ship a fix by disclosure. OpenAI closed the report as informational and did not address the core architectural issue. That gap in response says a lot about vendor security posture. <!-- SC_ON --> submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/the-race-to-ship-ai-tools-left-security-behind-part-1-sandbox-escape/) [comments] (https://www.reddit.com/r/redteamsec/comments/1sf54ak/the_race_to_ship_ai_tools_left_security_behind/)
BSCP Exam
https://www.reddit.com/r/Pentesting/comments/1sepeo1/bscp_exam/

<!-- SC_OFF -->Hey, I’m currently preparing for the Burp Suite Certified Practitioner (BSCP) mainly using PortSwigger Web Security Academy labs + notes, and doing a bit of bug bounty on the side. Quick questions: • ⁠Is the exam similar to the labs or harder? • ⁠What topics show up the most? • ⁠Any tips for final revision + time management? Would really appreciate any advice or mistakes to avoid 🙏 <!-- SC_ON --> submitted by /u/Worried_Self_3508 (https://www.reddit.com/user/Worried_Self_3508)
[link] (https://www.reddit.com/r/Pentesting/comments/1sepeo1/bscp_exam/) [comments] (https://www.reddit.com/r/Pentesting/comments/1sepeo1/bscp_exam/)
Need Remote internship
https://www.reddit.com/r/Pentesting/comments/1sezwyw/need_remote_internship/

<!-- SC_OFF -->Hello, I'm currently looking for a Remote internship. I don't care if it's paid or not; what really matters to me is gaining experience. <!-- SC_ON --> submitted by /u/Static_Motion1 (https://www.reddit.com/user/Static_Motion1)
[link] (https://www.reddit.com/r/Pentesting/comments/1sezwyw/need_remote_internship/) [comments] (https://www.reddit.com/r/Pentesting/comments/1sezwyw/need_remote_internship/)