Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
AppEnumGuard v1.2
https://kitploit.com/en/posts/github-kolbicz-appenumguard-v12

CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1
httrack v3.49.24
https://kitploit.com/en/posts/github-xroche-httrack-34924

Offline website copier that recursively downloads HTML, images, and files to create a browsable local mirror, with support for resuming and updating existing mirrored sites.
promptfoo v0.122.1
https://kitploit.com/en/posts/github-promptfoo-promptfoo-01221

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
semgrep v1.175.0
https://kitploit.com/en/posts/github-semgrep-semgrep-v11750

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
That “Random Token” Is a Serialized Object — and It’s RCE

What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium » (https://saleemyousaf.medium.com/a-bug-bounty-is-not-a-control-you-buy-it-is-a-queue-you-have-to-staff-4bc2b76b6387?source=rss------bug_bounty-5)
RDP-Guard

Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and whitelist support.
Read more...
One Restaurant Account. 23,000+ Order IDs. One Very Big MQTT Problem

While testing a partner-facing live order dashboard, I found that a valid low-privilege restaurant account could connect to the…Continue reading on Medium »
Read more...
The Best Claude Code Setup for Bug Bounty Hunting

Turn Claude Code into a powerful bug bounty hunting assistant with MCP, custom skills, agents, tools and automated security workflows.Continue reading on Medium »
Read more...
Cache Memory CTF | Penetration Testing & Exploitation Explained

Cache memory vulnerabilities are a fascinating area of cybersecurity because they sit at the intersection of application security…Continue reading on Medium »
Read more...
Sign Out Everywhere Bypass: How I Found a Session Revocation Vulnerability in OAuth & Password…

Bismillāh ir-Raḥmān ir-Raḥīm.Continue reading on Medium »
Read more...
How an OAuth 2.0 Redirect URI Bypass Led to Account Takeover and an $8,000 Bounty

Single Sign-On (SSO) integrations are designed to streamline authentication, but subtle oversights in how callback parameters are…Continue reading on Medium »
Read more...