How a Simple API Misconfiguration Leaked PII of 100,000+ Users
A Quick Word on MeContinue reading on Medium »
Read more...
A Quick Word on MeContinue reading on Medium »
Read more...
Medium
How a Simple API Misconfiguration Leaked PII of 100,000+ Users
A Quick Word on Me
How I Found an SSRF Vulnerability in Istio and Got Credited in the Official Release Notes
Aser Ahmed · August 8, 2026Continue reading on Medium »
Read more...
Aser Ahmed · August 8, 2026Continue reading on Medium »
Read more...
Medium
How I Found an SSRF Vulnerability in Istio and Got Credited in the Official Release Notes
Aser Ahmed · August 8, 2026
One Invitation, Three Vulnerabilities: Breaking RBAC Across Two Applications
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
One Invitation, Three Vulnerabilities: Breaking RBAC Across Two Applications
Introduction
When the Marketing Page Became the Threat Model: Forging “Verified Reviews” on PriceRunner
How a simple business-logic flaw turned a company’s own trust promise into a security test.Continue reading on Medium »
Read more...
How a simple business-logic flaw turned a company’s own trust promise into a security test.Continue reading on Medium »
Read more...
Medium
When the Marketing Page Became the Threat Model: Forging “Verified Reviews” on PriceRunner
How a simple business-logic flaw turned a company’s own trust promise into a security test.
Smali By bithowl: Chapter 6 Smali Naming System
(“The Secret Code Every Android Reverse Engineer Must Learn”)Continue reading on Medium »
Read more...
(“The Secret Code Every Android Reverse Engineer Must Learn”)Continue reading on Medium »
Read more...
Medium
Smali By bithowl: Chapter 6 Smali Naming System
(“The Secret Code Every Android Reverse Engineer Must Learn”)
Exploiting CSRF in GraphQL APIs: Achieving Unauthorized CRUD Operations ( $$$ Bounty )
Hello Community👋, I’m Divyank Sitapara, an Application Security Researcher and Bug Bounty Hunter. This is my 3rd write-up, where I’ll…Continue reading on Medium »
Read more...
Hello Community👋, I’m Divyank Sitapara, an Application Security Researcher and Bug Bounty Hunter. This is my 3rd write-up, where I’ll…Continue reading on Medium »
Read more...
Medium
Exploiting CSRF in GraphQL APIs: Achieving Unauthorized CRUD Operations ( $$$ Bounty )
Hello Community👋, I’m Divyank Sitapara, an Application Security Researcher and Bug Bounty Hunter. This is my 3rd write-up, where I’ll…
Finding SSRF In Modern Web Apps
You think Modern Web Apps are like Labs out there. C’mon. That’s not how Modern Web Apps work. The beginners that say that they know the…Continue reading on Medium »
Read more...
You think Modern Web Apps are like Labs out there. C’mon. That’s not how Modern Web Apps work. The beginners that say that they know the…Continue reading on Medium »
Read more...
Medium
Finding SSRF In Modern Web Apps
You think Modern Web Apps are like Labs out there. C’mon. That’s not how Modern Web Apps work. The beginners that say that they know the…
Shodan for Bug Bounty: Finding Exposed Assets Before Anyone Else Does
بِسْمِ ٱللَّٰهِ ٱلرَّحْمَٰنِ ٱلرَّحِيمِContinue reading on OSINT Team »
Read more...
بِسْمِ ٱللَّٰهِ ٱلرَّحْمَٰنِ ٱلرَّحِيمِContinue reading on OSINT Team »
Read more...
Medium
Shodan for Bug Bounty: Finding Exposed Assets Before Anyone Else Does
بِسْمِ ٱللَّٰهِ ٱلرَّحْمَٰنِ ٱلرَّحِيمِ
How a Simple API Misconfiguration Leaked PII of 100,000+ Users
https://medium.com/@sagar_kirola-G35638/how-a-simple-api-misconfiguration-leaked-pii-of-100-000-users-326a1a29bf44?source=rss------bug_bounty-5
https://medium.com/@sagar_kirola-G35638/how-a-simple-api-misconfiguration-leaked-pii-of-100-000-users-326a1a29bf44?source=rss------bug_bounty-5
A Quick Word on MeContinue reading on Medium » (https://medium.com/@sagar_kirola-G35638/how-a-simple-api-misconfiguration-leaked-pii-of-100-000-users-326a1a29bf44?source=rss------bug_bounty-5)
How I Found an SSRF Vulnerability in Istio and Got Credited in the Official Release Notes
https://medium.com/@0xanubiis/how-i-found-an-ssrf-vulnerability-in-istio-and-got-credited-in-the-official-release-notes-e4d6f21c9707?source=rss------bug_bounty-5
https://medium.com/@0xanubiis/how-i-found-an-ssrf-vulnerability-in-istio-and-got-credited-in-the-official-release-notes-e4d6f21c9707?source=rss------bug_bounty-5
Aser Ahmed · August 8, 2026Continue reading on Medium » (https://medium.com/@0xanubiis/how-i-found-an-ssrf-vulnerability-in-istio-and-got-credited-in-the-official-release-notes-e4d6f21c9707?source=rss------bug_bounty-5)
One Invitation, Three Vulnerabilities: Breaking RBAC Across Two Applications
https://medium.com/@omaralgbry1/one-invitation-three-vulnerabilities-breaking-rbac-across-two-applications-f66508af3e83?source=rss------bug_bounty-5
https://medium.com/@omaralgbry1/one-invitation-three-vulnerabilities-breaking-rbac-across-two-applications-f66508af3e83?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@omaralgbry1/one-invitation-three-vulnerabilities-breaking-rbac-across-two-applications-f66508af3e83?source=rss------bug_bounty-5)
Sol in the shade: benchmarking Opus 4.6 and GPT-5.6 Sol for finding zero-days
I pointed Opus 4.6 and GPT-5.6 Sol at a big, hardened open source project and told them to hunt for zero-days.Continue reading on Medium »
Read more...
I pointed Opus 4.6 and GPT-5.6 Sol at a big, hardened open source project and told them to hunt for zero-days.Continue reading on Medium »
Read more...
Medium
Sol in the shade: benchmarking Opus 4.6 and GPT-5.6 Sol for finding zero-days
I pointed Opus 4.6 and GPT-5.6 Sol at a big, hardened open source project and told them to hunt for zero-days. Opus 4.6 out-counted GPT-5.6…
From Zero to 100+ Reports: My Bug Bounty Journey So Far
I started bug bounty hunting two years ago knowing absolutely nothing. No formal training, no course just YouTube. I didn’t grind through…Continue reading on Medium »
Read more...
I started bug bounty hunting two years ago knowing absolutely nothing. No formal training, no course just YouTube. I didn’t grind through…Continue reading on Medium »
Read more...
Medium
From Zero to 100+ Reports: My Bug Bounty Journey So Far
I started bug bounty hunting two years ago knowing absolutely nothing. No formal training, no course just YouTube. I didn’t grind through…
Check-Then-Act: The Timing Bug Hiding in Every Money Endpoint
What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
Medium
Check-Then-Act: The Timing Bug Hiding in Every Money Endpoint
What’s up everyone! Nitin here 👋
Sol in the shade: benchmarking Opus 4.6 and GPT-5.6 Sol for finding zero-days
https://xdead4f.medium.com/sol-in-the-shade-benchmarking-opus-4-6-and-gpt-5-6-sol-for-finding-zero-days-a5eaf594d1ab?source=rss------bug_bounty-5
https://xdead4f.medium.com/sol-in-the-shade-benchmarking-opus-4-6-and-gpt-5-6-sol-for-finding-zero-days-a5eaf594d1ab?source=rss------bug_bounty-5