Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Pondering Paths — Linux Luminarium Part 2

Part 1 is already available on my profile. Check my profile if you haven’t read it yet.Continue reading on Medium »
Read more...
How to Extract Information from Websites: Automated OSINT Techniques and Tools

A Complete Guide to Web Scraping, OSINT, and Data Extraction Using Automated ToolsContinue reading on OSINT Team »
Read more...
Sentora
https://kitploit.com/en/tools/github/d3vhex/sentora

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.
hayduk
https://kitploit.com/en/tools/github/jolovicdev/hayduk

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign workflows, Hail Mary, sessions, report export, and team mode.
RDP-Guard
https://kitploit.com/en/tools/gitlab/siberanka/rdp-guard

Monitors Windows Security logs for failed RDP attempts and automatically blocks abusive IPs via Windows Firewall, with configurable thresholds and whitelist support.
aegis-latent-core
https://kitploit.com/en/tools/github/juanlunaia/aegis-latent-core

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions, signed durable evidence, and fail-closed error paths. Self-hosted; no certification or SLO claim.
Findomain v11.0.0-beta.1
https://kitploit.com/en/posts/github-findomain-findomain-1100-beta1

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
pentx-vapt-skill
https://kitploit.com/en/tools/github/yashas-13/pentx-vapt-skill

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC
nvidia-gpu-security-poc
https://kitploit.com/en/tools/github/abhinavagarwal07/nvidia-gpu-security-poc

PoCs and evidence for two NVIDIA Linux GPU driver findings closed by the vendor as expected/intended behavior: cross-UID GPU process telemetry via NVML, and an unprivileged Xid 31 copy-engine MMU fault via a peer-access teardown race.
Tata Nexarc’s OTP Leak: How an “Encrypted” API Response Handed Out Full Admin Access

Title: Tata Nexarc’s OTP Leak: How a “Encrypted” API Response Handed Out Full Admin AccessContinue reading on Medium »
Read more...
FuzzingBrain-Bench

A sealed benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java). Each challenge is an answer-free Docker image with in-image grading — no patch, Poc or answer key ships.
Read more...
Understanding Confidentiality, Integrity, and Availability in Information Security.

Lets begin…Continue reading on Medium »
Read more...
PortSwigger Lab: Unprotected Admin Functionality — Solution

Before diving directly into the lab, let’s first understand the basics of Access Control.Continue reading on Medium »
Read more...
One Key, Two Meanings: JWT Algorithm Confusion in OopsSec Store

A public key you were meant to trust becomes the secret that betrays youContinue reading on Medium »
Read more...
Hello hackers! I’m back with another writeup. This time, I want to share a recent finding from a HackerOne program (jobs.target.com).Continue reading on Medium » (https://medium.com/@coolorangee3/exploiting-race-condition-to-break-idempotency-corrupt-data-integrity-160cbf0d2b71?source=rss------bug_bounty-5)