Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Local Privilege Escalation in Pardus Software Center via APT Option Injection | CVE-2026–14459
https://medium.com/@dasokkk/local-privilege-escalation-in-pardus-software-center-via-apt-option-injection-cve-2026-14459-569ad65a2250?source=rss------bug_bounty-5

A member of the pardus-software group — with no sudo rights and no password — can inject APT options into a privileged helper and execute…Continue reading on Medium » (https://medium.com/@dasokkk/local-privilege-escalation-in-pardus-software-center-via-apt-option-injection-cve-2026-14459-569ad65a2250?source=rss------bug_bounty-5)
Hijacking a Live Shopping Stream From a Plain Customer Account

The admin button is hidden, but the API never asked who you wereContinue reading on Medium »
Read more...
What we see: A plaintext exposure of apiKey, authDomain, projectId, storageBucket, messagingSenderId, and appId for a project named…Continue reading on Medium » (https://medium.com/@cryptdefender26/-19b3bae889bc?source=rss------bug_bounty-5)
Never Underestimate This “Boring” Vulnerability in Bug Bounties — 2FA Madness Writeup (Hacking Hub)

If you participate in bug bounty programs and only hunt for “fancy” bugs — like RCE or SQL Injection — or simply run automated scripts or…Continue reading on Medium »
Read more...
OS Command Injection Guide: Exploitation, WAF Bypass & PoC

Learn advanced techniques for OS command injection, WAF evasion, impact chaining, and writing secure bug bounty PoC reports.Continue reading on Medium »
Read more...
How I Found an Account Takeover (ATO) in Swisscom

Password Reset Token Reuse → Account TakeoverContinue reading on Medium »
Read more...
They Gave Me $1,000 After I Found Their Entire Student Database Exposed!

A writeup about HTTP method override leading to massive PII exposure by Anukar.Continue reading on Medium »
Read more...
The Festival Phantom: How I Found a Ghost in Germany’s Anubis Logistics During Durga Puja

A stored XSS in tracking notifications, a €200 bounty, and the bug that almost made me miss my mother’s bhog offeringContinue reading on Medium »
Read more...
How I Discovered a Critical Data Leak Starting with a Small Clue

INTRODUCTIONContinue reading on Medium »
Read more...
SameSite Strict Bypass via Client-Side Redirect — Testing with Sonnet 4.6 (Medium Effort)

Discover how client-side redirects can undermine SameSite=Strict and reintroduce CSRF risk.Continue reading on OSINT Team »
Read more...