Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
There is a kind of security decision that looks like buying a control and is actually taking on an operational commitment. A bug bounty…Continue reading on Medium » (https://saleemyousaf.medium.com/a-bug-bounty-is-not-a-control-you-buy-it-is-a-queue-you-have-to-staff-4bc2b76b6387?source=rss------bug_bounty-5)
RDP-Guard

Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and whitelist support.
Read more...
One Restaurant Account. 23,000+ Order IDs. One Very Big MQTT Problem

While testing a partner-facing live order dashboard, I found that a valid low-privilege restaurant account could connect to the…Continue reading on Medium »
Read more...
The Best Claude Code Setup for Bug Bounty Hunting

Turn Claude Code into a powerful bug bounty hunting assistant with MCP, custom skills, agents, tools and automated security workflows.Continue reading on Medium »
Read more...
Cache Memory CTF | Penetration Testing & Exploitation Explained

Cache memory vulnerabilities are a fascinating area of cybersecurity because they sit at the intersection of application security…Continue reading on Medium »
Read more...
Sign Out Everywhere Bypass: How I Found a Session Revocation Vulnerability in OAuth & Password…

Bismillāh ir-Raḥmān ir-Raḥīm.Continue reading on Medium »
Read more...
How an OAuth 2.0 Redirect URI Bypass Led to Account Takeover and an $8,000 Bounty

Single Sign-On (SSO) integrations are designed to streamline authentication, but subtle oversights in how callback parameters are…Continue reading on Medium »
Read more...
Findomain v11.0.0-beta.1

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
Read more...
PortSwigger Lab: User role controlled by request parameter

Platform: PortSwigger Web Security AcademyContinue reading on Medium »
Read more...
AI Bug Hunting 101: From Setup to Your First Scan

Setting up Burp Suite, MCP, and AI skills to speed up bug huntingContinue reading on Medium »
Read more...