A bug bounty is not a control you buy, it is a queue you have to staff
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium »
Read more...
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium »
Read more...
Medium
A bug bounty is not a control you buy, it is a queue you have to staff
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…
Account Takeover via Parameter Confusion in Login Authentication
One day, while testing an application, I came across a relatively simple login flow.Continue reading on Medium »
Read more...
One day, while testing an application, I came across a relatively simple login flow.Continue reading on Medium »
Read more...
Medium
Account Takeover via Parameter Confusion in Login Authentication
One day, while testing an application, I came across a relatively simple login flow.
cottage v0.7.0
https://kitploit.com/en/posts/github-sayanarijit-cottage-v070
A modern git based age-encrypted secrets manager for teams.
https://kitploit.com/en/posts/github-sayanarijit-cottage-v070
A modern git based age-encrypted secrets manager for teams.
cdncheck v1.2.50
https://kitploit.com/en/posts/github-projectdiscovery-cdncheck-v1250
A utility to detect various technology for a given IP address.
https://kitploit.com/en/posts/github-projectdiscovery-cdncheck-v1250
A utility to detect various technology for a given IP address.
cli v1.1307.0
https://kitploit.com/en/posts/github-snyk-cli-v113070
Snyk CLI scans and monitors your projects for security vulnerabilities.
https://kitploit.com/en/posts/github-snyk-cli-v113070
Snyk CLI scans and monitors your projects for security vulnerabilities.
Nest v2026.08.24
https://kitploit.com/en/posts/github-owasp-nest-20260824
Your gateway to OWASP. Discover, engage, and help shape the future!
https://kitploit.com/en/posts/github-owasp-nest-20260824
Your gateway to OWASP. Discover, engage, and help shape the future!
apex v2.4.0-canary.d5c18874
https://kitploit.com/en/posts/github-pensarai-apex-v240-canaryd5c18874
AI-powered offensive security testing using autonomous agents, directly in your terminal.
https://kitploit.com/en/posts/github-pensarai-apex-v240-canaryd5c18874
AI-powered offensive security testing using autonomous agents, directly in your terminal.
cloudprober v0.14.5
https://kitploit.com/en/posts/github-cloudprober-cloudprober-v0145
An active monitoring software to detect failures before your customers do.
https://kitploit.com/en/posts/github-cloudprober-cloudprober-v0145
An active monitoring software to detect failures before your customers do.
DakshSCRA v0.38-beta
https://kitploit.com/en/posts/github-coffeeandsecurity-dakshscra-v038-beta
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.
https://kitploit.com/en/posts/github-coffeeandsecurity-dakshscra-v038-beta
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and suppression baselines.
AppEnumGuard v1.2
https://kitploit.com/en/posts/github-kolbicz-appenumguard-v12
CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1
https://kitploit.com/en/posts/github-kolbicz-appenumguard-v12
CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1
httrack v3.49.24
https://kitploit.com/en/posts/github-xroche-httrack-34924
Offline website copier that recursively downloads HTML, images, and files to create a browsable local mirror, with support for resuming and updating existing mirrored sites.
https://kitploit.com/en/posts/github-xroche-httrack-34924
Offline website copier that recursively downloads HTML, images, and files to create a browsable local mirror, with support for resuming and updating existing mirrored sites.
promptfoo v0.122.1
https://kitploit.com/en/posts/github-promptfoo-promptfoo-01221
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
https://kitploit.com/en/posts/github-promptfoo-promptfoo-01221
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
semgrep v1.175.0
https://kitploit.com/en/posts/github-semgrep-semgrep-v11750
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
https://kitploit.com/en/posts/github-semgrep-semgrep-v11750
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
That “Random Token” Is a Serialized Object — and It’s RCE
What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
Medium
That “Random Token” Is a Serialized Object — and It’s RCE
What’s up everyone! Nitin here 👋
Crack the Gate 1 — picoCTF Write-up | Authentication Bypass via Hidden HTTP Header
https://medium.com/@affanhaxor/crack-the-gate-1-picoctf-write-up-authentication-bypass-via-hidden-http-header-e8554ec55b01?source=rss------bug_bounty-5
https://medium.com/@affanhaxor/crack-the-gate-1-picoctf-write-up-authentication-bypass-via-hidden-http-header-e8554ec55b01?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@affanhaxor/crack-the-gate-1-picoctf-write-up-authentication-bypass-via-hidden-http-header-e8554ec55b01?source=rss------bug_bounty-5)
The Bug Bounty Hunter’s Guide to Prototype Pollution
https://meetcyber.net/beginners-guide-to-understanding-client-prototype-pollution-65d9b2e7d1d8?source=rss------bug_bounty-5
https://meetcyber.net/beginners-guide-to-understanding-client-prototype-pollution-65d9b2e7d1d8?source=rss------bug_bounty-5
Finding and Breaking .Js prototype for the devs to fix.Continue reading on MeetCyber » (https://meetcyber.net/beginners-guide-to-understanding-client-prototype-pollution-65d9b2e7d1d8?source=rss------bug_bounty-5)