Setting up Burp Suite, MCP, and AI skills to speed up bug huntingContinue reading on Medium » (https://medium.com/@octaviam/ai-bug-hunting-101-from-setup-to-your-first-scan-5ce6c958879b?source=rss------bug_bounty-5)
Exploiting Race Condition to Break Idempotency & Corrupt Data Integrity
Hello hackers! I’m back with another writeup. This time, I want to share a recent finding from a HackerOne program (jobs.target.com).Continue reading on Medium »
Read more...
Hello hackers! I’m back with another writeup. This time, I want to share a recent finding from a HackerOne program (jobs.target.com).Continue reading on Medium »
Read more...
Medium
Exploiting Race Condition to Break Idempotency & Corrupt Data Integrity
Hello hackers! I’m back with another writeup. This time, I want to share a recent finding from a HackerOne program (jobs.target.com).
Pondering Paths — Linux Luminarium Part 2
Part 1 is already available on my profile. Check my profile if you haven’t read it yet.Continue reading on Medium »
Read more...
Part 1 is already available on my profile. Check my profile if you haven’t read it yet.Continue reading on Medium »
Read more...
Medium
Pondering Paths — Linux Luminarium Part 2
Part 1 is already available on my profile. Check my profile if you haven’t read it yet.
How to Extract Information from Websites: Automated OSINT Techniques and Tools
A Complete Guide to Web Scraping, OSINT, and Data Extraction Using Automated ToolsContinue reading on OSINT Team »
Read more...
A Complete Guide to Web Scraping, OSINT, and Data Extraction Using Automated ToolsContinue reading on OSINT Team »
Read more...
Medium
How to Extract Information from Websites: Automated OSINT Techniques and Tools
A Complete Guide to Web Scraping, OSINT, and Data Extraction Using Automated Tools
Sentora
https://kitploit.com/en/tools/github/d3vhex/sentora
An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.
https://kitploit.com/en/tools/github/d3vhex/sentora
An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.
hayduk
https://kitploit.com/en/tools/github/jolovicdev/hayduk
Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign workflows, Hail Mary, sessions, report export, and team mode.
https://kitploit.com/en/tools/github/jolovicdev/hayduk
Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign workflows, Hail Mary, sessions, report export, and team mode.
RDP-Guard
https://kitploit.com/en/tools/gitlab/siberanka/rdp-guard
Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and whitelist support.
https://kitploit.com/en/tools/gitlab/siberanka/rdp-guard
Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and whitelist support.
aegis-latent-core
https://kitploit.com/en/tools/github/juanlunaia/aegis-latent-core
AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions, signed durable evidence, and fail-closed error paths. Self-hosted; no certification or SLO claim.
https://kitploit.com/en/tools/github/juanlunaia/aegis-latent-core
AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions, signed durable evidence, and fail-closed error paths. Self-hosted; no certification or SLO claim.
Findomain v11.0.0-beta.1
https://kitploit.com/en/posts/github-findomain-findomain-1100-beta1
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
https://kitploit.com/en/posts/github-findomain-findomain-1100-beta1
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
pentx-vapt-skill
https://kitploit.com/en/tools/github/yashas-13/pentx-vapt-skill
Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC
https://kitploit.com/en/tools/github/yashas-13/pentx-vapt-skill
Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC
nvidia-gpu-security-poc
https://kitploit.com/en/tools/github/abhinavagarwal07/nvidia-gpu-security-poc
PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via NVML, and an unprivileged Xid 31 copy-engine MMU fault via a peer-access teardown race.
https://kitploit.com/en/tools/github/abhinavagarwal07/nvidia-gpu-security-poc
PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via NVML, and an unprivileged Xid 31 copy-engine MMU fault via a peer-access teardown race.
Tata Nexarc’s OTP Leak: How an “Encrypted” API Response Handed Out Full Admin Access
Title: Tata Nexarc’s OTP Leak: How a “Encrypted” API Response Handed Out Full Admin AccessContinue reading on Medium »
Read more...
Title: Tata Nexarc’s OTP Leak: How a “Encrypted” API Response Handed Out Full Admin AccessContinue reading on Medium »
Read more...
Medium
Tata Nexarc’s OTP Leak: How an “Encrypted” API Response Handed Out Full Admin Access
Title: Tata Nexarc’s OTP Leak: How a “Encrypted” API Response Handed Out Full Admin Access
FuzzingBrain-Bench
A sealed benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java). Each challenge is an answer-free Docker image with in-image grading — no patch, Poc or answer key ships.
Read more...
A sealed benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java). Each challenge is an answer-free Docker image with in-image grading — no patch, Poc or answer key ships.
Read more...
Understanding Confidentiality, Integrity, and Availability in Information Security.
Lets begin…Continue reading on Medium »
Read more...
Lets begin…Continue reading on Medium »
Read more...
Medium
CIA TRIAD SECURITY MODEL
Lets begin…
PortSwigger Lab: Unprotected Admin Functionality — Solution
Before diving directly into the lab, let’s first understand the basics of Access Control.Continue reading on Medium »
Read more...
Before diving directly into the lab, let’s first understand the basics of Access Control.Continue reading on Medium »
Read more...
Medium
PortSwigger Lab: Unprotected Admin Functionality — Solution
Before diving directly into the lab, let’s first understand the basics of Access Control.
One Key, Two Meanings: JWT Algorithm Confusion in OopsSec Store
A public key you were meant to trust becomes the secret that betrays youContinue reading on Medium »
Read more...
A public key you were meant to trust becomes the secret that betrays youContinue reading on Medium »
Read more...
Medium
One Key, Two Meanings: JWT Algorithm Confusion in OopsSec Store
A public key you were meant to trust becomes the secret that betrays you
Hello Hackers — Linux Luminarium Part 1
https://medium.com/@may.hack/linux-luminarium-hello-hackers-461253e396a7?source=rss------bug_bounty-5
https://medium.com/@may.hack/linux-luminarium-hello-hackers-461253e396a7?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@may.hack/linux-luminarium-hello-hackers-461253e396a7?source=rss------bug_bounty-5)