Deception False Security: Users receive notifications stating "Security Update Installed," but the underlying binaries dated March 18, 2026 remain vulnerable. This erodes trust in the Android ecosystem and leaves users exposed to known exploits. Regulatory Violation: This practice likely violates consumer protection laws in Mexico, Brazil, and the EU, as it constitutes a material misrepresentation of product security. <!-- SC_ON --> submitted by /u/Acceptable-County443 (https://www.reddit.com/user/Acceptable-County443)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/)
[link] (https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/) [comments] (https://www.reddit.com/r/Pentesting/comments/1uwxt60/analysis_of_spreadtrum_longcheer_chipsets/)
What should every beginner include in a penetration testing report?
https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/
<!-- SC_OFF -->A penetration test is not complete when the vulnerability is found. The real value comes from explaining the risk clearly enough for the client to fix it. A beginner report should include: Scope and methodology Affected asset Clear vulnerability description Evidence and reproduction steps Risk severity Business impact Remediation guidance Retest status Which section do beginners usually underestimate the most: evidence, impact, or remediation? <!-- SC_ON --> submitted by /u/redfoxsecurity (https://www.reddit.com/user/redfoxsecurity)
[link] (https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/)
https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/
<!-- SC_OFF -->A penetration test is not complete when the vulnerability is found. The real value comes from explaining the risk clearly enough for the client to fix it. A beginner report should include: Scope and methodology Affected asset Clear vulnerability description Evidence and reproduction steps Risk severity Business impact Remediation guidance Retest status Which section do beginners usually underestimate the most: evidence, impact, or remediation? <!-- SC_ON --> submitted by /u/redfoxsecurity (https://www.reddit.com/user/redfoxsecurity)
[link] (https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ux17jp/what_should_every_beginner_include_in_a/)
Built an OWASP LLM Top 10 vulnerable lab platform for learning AI security (Open Source)
https://www.reddit.com/r/Pentesting/comments/1ux3c56/built_an_owasp_llm_top_10_vulnerable_lab_platform/
submitted by /u/DistributionAlive465 (https://www.reddit.com/user/DistributionAlive465)
[link] (https://www.reddit.com/r/Pentesting/comments/1ux3c56/built_an_owasp_llm_top_10_vulnerable_lab_platform/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ux3c56/built_an_owasp_llm_top_10_vulnerable_lab_platform/)
https://www.reddit.com/r/Pentesting/comments/1ux3c56/built_an_owasp_llm_top_10_vulnerable_lab_platform/
submitted by /u/DistributionAlive465 (https://www.reddit.com/user/DistributionAlive465)
[link] (https://www.reddit.com/r/Pentesting/comments/1ux3c56/built_an_owasp_llm_top_10_vulnerable_lab_platform/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ux3c56/built_an_owasp_llm_top_10_vulnerable_lab_platform/)
When -1 Becomes a Heap Write: A libtiff TIFFReadAndRealloc() Vulnerability
How an ordinary stream read failure reached pointer arithmetic and caused confirmed heap memory corruptionContinue reading on Medium »
Read more...
How an ordinary stream read failure reached pointer arithmetic and caused confirmed heap memory corruptionContinue reading on Medium »
Read more...
Medium
When -1 Becomes a Heap Write: A libtiff TIFFReadAndRealloc() Vulnerability
How an ordinary stream read failure reached pointer arithmetic and caused confirmed heap memory corruption
One postMessage Was Enough to Break a Trust Boundary (CSRF)
Most bug bounty discoveries don’t begin with an advanced exploit. No SQL Injection. No authentication bypass. No complex exploit chain…Continue reading on Medium »
Read more...
Most bug bounty discoveries don’t begin with an advanced exploit. No SQL Injection. No authentication bypass. No complex exploit chain…Continue reading on Medium »
Read more...
Medium
One postMessage Was Enough to Break a Trust Boundary (CSRF)
Most bug bounty discoveries don’t begin with an advanced exploit.
No SQL Injection.
No authentication bypass.
No complex exploit chain…
No SQL Injection.
No authentication bypass.
No complex exploit chain…
When Your Own Automated Scanners Start Lying to You
In cybersecurity, we are taught to trust our tools. We unleash powerful crawlers like Katana or automated scanners inside Burp Suite, grab…Continue reading on Medium »
Read more...
In cybersecurity, we are taught to trust our tools. We unleash powerful crawlers like Katana or automated scanners inside Burp Suite, grab…Continue reading on Medium »
Read more...
Medium
When Your Own Automated Scanners Start Lying to You
In cybersecurity, we are taught to trust our tools. We unleash powerful crawlers like Katana or automated scanners inside Burp Suite, grab…
Agentic AI CyberSecurity Arsenal | 33 FREE Local AI Tools for Cyber Defense
Exploring CyberSentinel AI: A Fully Local AI Security Platform for Modern Security TeamsContinue reading on Medium »
Read more...
Exploring CyberSentinel AI: A Fully Local AI Security Platform for Modern Security TeamsContinue reading on Medium »
Read more...
Medium
Agentic AI CyberSecurity Arsenal | 33 FREE Local AI Tools for Cyber Defense 🔥
Exploring CyberSentinel AI: A Fully Local AI Security Platform for Modern Security Teams
Smali By bithowl: Chapter 2 Why Every Android Hacker Needs Smali
(“The Code You See Isn’t Always the Code That Runs”)Continue reading on Medium »
Read more...
(“The Code You See Isn’t Always the Code That Runs”)Continue reading on Medium »
Read more...
Medium
Smali By bithowl: Chapter 2 Why Every Android Hacker Needs Smali
(“The Code You See Isn’t Always the Code That Runs”)
When -1 Becomes a Heap Write: A libtiff TIFFReadAndRealloc() Vulnerability
https://medium.com/@aleens09/when-1-becomes-a-heap-write-a-libtiff-tiffreadandrealloc-vulnerability-b7e241e7731e?source=rss------bug_bounty-5
https://medium.com/@aleens09/when-1-becomes-a-heap-write-a-libtiff-tiffreadandrealloc-vulnerability-b7e241e7731e?source=rss------bug_bounty-5
How an ordinary stream read failure reached pointer arithmetic and caused confirmed heap memory corruptionContinue reading on Medium » (https://medium.com/@aleens09/when-1-becomes-a-heap-write-a-libtiff-tiffreadandrealloc-vulnerability-b7e241e7731e?source=rss------bug_bounty-5)
One postMessage Was Enough to Break a Trust Boundary (CSRF)
https://medium.com/@RootXSec/one-postmessage-was-enough-to-break-a-trust-boundary-csrf-8adeb40315ac?source=rss------bug_bounty-5
https://medium.com/@RootXSec/one-postmessage-was-enough-to-break-a-trust-boundary-csrf-8adeb40315ac?source=rss------bug_bounty-5
Most bug bounty discoveries don’t begin with an advanced exploit.
No SQL Injection.
No authentication bypass.
No complex exploit chain…Continue reading on Medium » (https://medium.com/@RootXSec/one-postmessage-was-enough-to-break-a-trust-boundary-csrf-8adeb40315ac?source=rss------bug_bounty-5)
No SQL Injection.
No authentication bypass.
No complex exploit chain…Continue reading on Medium » (https://medium.com/@RootXSec/one-postmessage-was-enough-to-break-a-trust-boundary-csrf-8adeb40315ac?source=rss------bug_bounty-5)
When Your Own Automated Scanners Start Lying to You
https://medium.com/@psaibtech/when-your-own-automated-scanners-start-lying-to-you-4fe29424981d?source=rss------bug_bounty-5
https://medium.com/@psaibtech/when-your-own-automated-scanners-start-lying-to-you-4fe29424981d?source=rss------bug_bounty-5
In cybersecurity, we are taught to trust our tools. We unleash powerful crawlers like Katana or automated scanners inside Burp Suite, grab…Continue reading on Medium » (https://medium.com/@psaibtech/when-your-own-automated-scanners-start-lying-to-you-4fe29424981d?source=rss------bug_bounty-5)
Agentic AI CyberSecurity Arsenal | 33 FREE Local AI Tools for Cyber Defense
https://medium.com/@pentesterclubpvtltd/agentic-ai-cybersecurity-arsenal-33-free-local-ai-tools-for-cyber-defense-32b2627d9949?source=rss------bug_bounty-5
https://medium.com/@pentesterclubpvtltd/agentic-ai-cybersecurity-arsenal-33-free-local-ai-tools-for-cyber-defense-32b2627d9949?source=rss------bug_bounty-5
Exploring CyberSentinel AI: A Fully Local AI Security Platform for Modern Security TeamsContinue reading on Medium » (https://medium.com/@pentesterclubpvtltd/agentic-ai-cybersecurity-arsenal-33-free-local-ai-tools-for-cyber-defense-32b2627d9949?source=rss------bug_bounty-5)
Smali By bithowl: Chapter 2 Why Every Android Hacker Needs Smali
https://medium.com/@bithowl/smali-by-bithowl-chapter-2-why-every-android-hacker-needs-smali-1d89d42f1b7c?source=rss------bug_bounty-5
https://medium.com/@bithowl/smali-by-bithowl-chapter-2-why-every-android-hacker-needs-smali-1d89d42f1b7c?source=rss------bug_bounty-5