Hey everyone, let’s talk about another CSRF lab from PortSwigger.net.Continue reading on Medium » (https://smartpicks4u.medium.com/samesite-strict-no-problem-bypassing-it-with-a-client-side-redirect-45dbb439addb?source=rss------bug_bounty-5)
GitHub Dorking: The Complete 2026 Hunter’s Guide to Finding Exposed Secrets
https://medium.com/@thenewdate24/github-dorking-the-complete-2026-hunters-guide-to-finding-exposed-secrets-9a72331ed5bb?source=rss------bug_bounty-5
https://medium.com/@thenewdate24/github-dorking-the-complete-2026-hunters-guide-to-finding-exposed-secrets-9a72331ed5bb?source=rss------bug_bounty-5
Every day, developers accidentally push secrets to public GitHub repositories. API keys. Database passwords. AWS credentials. Private…Continue reading on Medium » (https://medium.com/@thenewdate24/github-dorking-the-complete-2026-hunters-guide-to-finding-exposed-secrets-9a72331ed5bb?source=rss------bug_bounty-5)
SSRF → Cloud Compromise — From Internal Access to Credentials
https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/ssrf-cloud-compromise-from-internal-access-to-credentials-e1b9835edf37?source=rss------bug_bounty-5
https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/ssrf-cloud-compromise-from-internal-access-to-credentials-e1b9835edf37?source=rss------bug_bounty-5
✍️ IntroductionContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french » (https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/ssrf-cloud-compromise-from-internal-access-to-credentials-e1b9835edf37?source=rss------bug_bounty-5)
Stored DoS via Missing Parameter
بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ ─────────────Continue reading on Medium »
Read more...
بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ ─────────────Continue reading on Medium »
Read more...
Medium
Stored DoS via Missing Parameter
بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ ─────────────
Stored DoS via Missing Parameter
https://medium.com/@mostafaabogoda8/stored-dos-via-missing-parameter-4e0394f211d4?source=rss------bug_bounty-5
https://medium.com/@mostafaabogoda8/stored-dos-via-missing-parameter-4e0394f211d4?source=rss------bug_bounty-5
بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ ─────────────Continue reading on Medium » (https://medium.com/@mostafaabogoda8/stored-dos-via-missing-parameter-4e0394f211d4?source=rss------bug_bounty-5)
Adventures at Black Hat Asia 2026: Windows Shellcoding Training and MSRC Researcher Celebration
It’s been a crazy week at Black Hat Asia 2026 in Singapore.Continue reading on InfoSec Write-ups »
Read more...
It’s been a crazy week at Black Hat Asia 2026 in Singapore.Continue reading on InfoSec Write-ups »
Read more...
Medium
Adventures at Black Hat Asia 2026: Windows Shellcoding Training and MSRC Researcher Celebration
It’s been a crazy week at Black Hat Asia 2026 in Singapore.
From Fake Flag to Full RCE — Clankers Market Writeup
Clankers Market | b01lers CTF Solved by: S0n1c_404Continue reading on Medium »
Read more...
Clankers Market | b01lers CTF Solved by: S0n1c_404Continue reading on Medium »
Read more...
Medium
🚀 From Fake Flag to Full RCE — Clankers Market Writeup
Clankers Market | b01lers CTF Solved by: S0n1c_404
Environment Cross-Trust: Leveraging Staging APIs to “Buy” for $0.00
Many bug hunters are afraid to delve into the scope of famous companies, thinking it’s the most complex system they’ve ever seen. Based on…Continue reading on Medium »
Read more...
Many bug hunters are afraid to delve into the scope of famous companies, thinking it’s the most complex system they’ve ever seen. Based on…Continue reading on Medium »
Read more...
Medium
Environment Cross-Trust: Leveraging Staging APIs to “Buy” for $0.00
Many bug hunters are afraid to delve into the scope of famous companies, thinking it’s the most complex system they’ve ever seen. Based on…
How I Earned €200 in 10 Minutes by Exploiting a Race Condition on a Job Application Portal
A simple business logic bypass using Burp Suite’s parallel sending feature — no complex exploit, no fancy tooling. Just timing.Continue reading on Medium »
Read more...
A simple business logic bypass using Burp Suite’s parallel sending feature — no complex exploit, no fancy tooling. Just timing.Continue reading on Medium »
Read more...
Medium
How I Earned €200 in 10 Minutes by Exploiting a Race Condition on a Job Application Portal
A simple business logic bypass using Burp Suite’s parallel sending feature — no complex exploit, no fancy tooling. Just timing.
Easiest $100 on Hackerone | Null Byte Broke Authentication
Welcome again!Continue reading on OSINT Team »
Read more...
Welcome again!Continue reading on OSINT Team »
Read more...
Medium
Easiest $100 on Hackerone | Null Byte Broke Authentication
Welcome again!
WebVersePro Labs — Challenge: Herbalist Remedies Writeup (NoSQL Injection)
OBJECTIVE: Bypass the authentication mechanism of a MongoDB-backed web application by exploiting a NoSQL Injection (NoSQLi) vulnerability…Continue reading on Medium »
Read more...
OBJECTIVE: Bypass the authentication mechanism of a MongoDB-backed web application by exploiting a NoSQL Injection (NoSQLi) vulnerability…Continue reading on Medium »
Read more...
Medium
WebVersePro Labs — Challenge: Herbalist Remedies Writeup (NoSQL Injection)
OBJECTIVE: Bypass the authentication mechanism of a MongoDB-backed web application by exploiting a NoSQL Injection (NoSQLi) vulnerability…
SSRF Master Guide: Exploitation and Mitigation Strategies
Learn how to identify and exploit SSRF vulnerabilities in cloud-native environments, from metadata services to filter bypass.Continue reading on Medium »
Read more...
Learn how to identify and exploit SSRF vulnerabilities in cloud-native environments, from metadata services to filter bypass.Continue reading on Medium »
Read more...
Medium
SSRF Master Guide: Exploitation and Mitigation Strategies
Learn how to identify and exploit SSRF vulnerabilities in cloud-native environments, from metadata services to filter bypass.
Lab: HTTP request smuggling, confirming a CL.TE vulnerability via differential responses
Before diving into the lab, there are some important concepts we need to understand first: what Content-Length and Transfer-Encoding are…Continue reading on Medium »
Read more...
Before diving into the lab, there are some important concepts we need to understand first: what Content-Length and Transfer-Encoding are…Continue reading on Medium »
Read more...
Medium
Lab: HTTP request smuggling, confirming a CL.TE vulnerability via differential responses
Before diving into the lab, there are some important concepts we need to understand first: what Content-Length and Transfer-Encoding are…
How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Cloud Blog
https://www.reddit.com/r/redteamsec/comments/1stmdjy/how_unc6692_employed_social_engineering_to_deploy/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/) [comments] (https://www.reddit.com/r/redteamsec/comments/1stmdjy/how_unc6692_employed_social_engineering_to_deploy/)
https://www.reddit.com/r/redteamsec/comments/1stmdjy/how_unc6692_employed_social_engineering_to_deploy/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/) [comments] (https://www.reddit.com/r/redteamsec/comments/1stmdjy/how_unc6692_employed_social_engineering_to_deploy/)