Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
ApplicationInspector v1.10.1

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
Read more...
The Bug Bounty Hunter’s Guide to Prototype Pollution

Finding and Breaking .Js prototype for the devs to fix.Continue reading on MeetCyber »
Read more...
Unauthenticated Full User Directory PII Dump — 103K+ Records Exposed

IntroductionContinue reading on Medium »
Read more...
sandbox-runtime v0.0.74

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.
Read more...
droidground v1.0.14

A flexible playground for Android CTF challenges.
Read more...
keyhog v0.5.86

Open-source secret scanner in Rust
Read more...
A bug bounty is not a control you buy, it is a queue you have to staff

There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium »
Read more...
Account Takeover via Parameter Confusion in Login Authentication

One day, while testing an application, I came across a relatively simple login flow.Continue reading on Medium »
Read more...
cottage v0.7.0
https://kitploit.com/en/posts/github-sayanarijit-cottage-v070

A modern git based age-encrypted secrets manager for teams.
cdncheck v1.2.50
https://kitploit.com/en/posts/github-projectdiscovery-cdncheck-v1250

A utility to detect various technology for a given IP address.
cli v1.1307.0
https://kitploit.com/en/posts/github-snyk-cli-v113070

Snyk CLI scans and monitors your projects for security vulnerabilities.
Nest v2026.08.24
https://kitploit.com/en/posts/github-owasp-nest-20260824

Your gateway to OWASP. Discover, engage, and help shape the future!
apex v2.4.0-canary.d5c18874
https://kitploit.com/en/posts/github-pensarai-apex-v240-canaryd5c18874

AI-powered offensive security testing using autonomous agents, directly in your terminal.
cloudprober v0.14.5
https://kitploit.com/en/posts/github-cloudprober-cloudprober-v0145

An active monitoring software to detect failures before your customers do.
DakshSCRA v0.38-beta
https://kitploit.com/en/posts/github-coffeeandsecurity-dakshscra-v038-beta

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.
AppEnumGuard v1.2
https://kitploit.com/en/posts/github-kolbicz-appenumguard-v12

CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1
httrack v3.49.24
https://kitploit.com/en/posts/github-xroche-httrack-34924

Offline website copier that recursively downloads HTML, images, and files to create a browsable local mirror, with support for resuming and updating existing mirrored sites.
promptfoo v0.122.1
https://kitploit.com/en/posts/github-promptfoo-promptfoo-01221

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
semgrep v1.175.0
https://kitploit.com/en/posts/github-semgrep-semgrep-v11750

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
That “Random Token” Is a Serialized Object — and It’s RCE

What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...