Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How a Simple API Misconfiguration Leaked PII of 100,000+ Users

A Quick Word on MeContinue reading on Medium »
Read more...
How I Found an SSRF Vulnerability in Istio and Got Credited in the Official Release Notes

Aser Ahmed · August 8, 2026Continue reading on Medium »
Read more...
One Invitation, Three Vulnerabilities: Breaking RBAC Across Two Applications

IntroductionContinue reading on Medium »
Read more...
When the Marketing Page Became the Threat Model: Forging “Verified Reviews” on PriceRunner

How a simple business-logic flaw turned a company’s own trust promise into a security test.Continue reading on Medium »
Read more...
Smali By bithowl: Chapter 6 Smali Naming System

(“The Secret Code Every Android Reverse Engineer Must Learn”)Continue reading on Medium »
Read more...
Exploiting CSRF in GraphQL APIs: Achieving Unauthorized CRUD Operations ( $$$ Bounty )

Hello Community👋, I’m Divyank Sitapara, an Application Security Researcher and Bug Bounty Hunter. This is my 3rd write-up, where I’ll…Continue reading on Medium »
Read more...
Finding SSRF In Modern Web Apps

You think Modern Web Apps are like Labs out there. C’mon. That’s not how Modern Web Apps work. The beginners that say that they know the…Continue reading on Medium »
Read more...
Shodan for Bug Bounty: Finding Exposed Assets Before Anyone Else Does

بِسْمِ ٱللَّٰهِ ٱلرَّحْمَٰنِ ٱلرَّحِيمِContinue reading on OSINT Team »
Read more...
Sol in the shade: benchmarking Opus 4.6 and GPT-5.6 Sol for finding zero-days

I pointed Opus 4.6 and GPT-5.6 Sol at a big, hardened open source project and told them to hunt for zero-days.Continue reading on Medium »
Read more...
From Zero to 100+ Reports: My Bug Bounty Journey So Far

I started bug bounty hunting two years ago knowing absolutely nothing. No formal training, no course just YouTube. I didn’t grind through…Continue reading on Medium »
Read more...
Check-Then-Act: The Timing Bug Hiding in Every Money Endpoint

What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...