How I use httpx to identify live hosts, collect valuable HTTP information, and streamline my bug bounty reconnaissance with practical…Continue reading on MeetCyber » (https://meetcyber.net/httpx-explained-with-practical-examples-70dd6b9aa743?source=rss------bug_bounty-5)
The OAuth2 Secret That Was Never Supposed to Leave the Server — But Did
https://medium.com/@rs67iran/the-oauth2-secret-that-was-never-supposed-to-leave-the-server-but-did-4d4862194323?source=rss------bug_bounty-5
https://medium.com/@rs67iran/the-oauth2-secret-that-was-never-supposed-to-leave-the-server-but-did-4d4862194323?source=rss------bug_bounty-5
There’s a specific kind of quiet that happens when you’re scrolling through a minified JavaScript bundle and a string catches your eye…Continue reading on Medium » (https://medium.com/@rs67iran/the-oauth2-secret-that-was-never-supposed-to-leave-the-server-but-did-4d4862194323?source=rss------bug_bounty-5)
I Found a Fully Misconfigured S3 Bucket Exposing Private Images and Lead Complete Takeover
https://medium.com/@tanjimul_islam/i-found-a-fully-misconfigured-s3-bucket-exposing-private-images-and-lead-complete-takeover-8e24320e612a?source=rss------bug_bounty-5
https://medium.com/@tanjimul_islam/i-found-a-fully-misconfigured-s3-bucket-exposing-private-images-and-lead-complete-takeover-8e24320e612a?source=rss------bug_bounty-5
By Md Tanjimul Islam Sifat (TI Sifat) Cybersecurity Researcher | Bug Bounty Hunter | Founder of SftSec TimContinue reading on Medium » (https://medium.com/@tanjimul_islam/i-found-a-fully-misconfigured-s3-bucket-exposing-private-images-and-lead-complete-takeover-8e24320e612a?source=rss------bug_bounty-5)
ziti v2.0.4
Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces VPNs, secures IoT, and connects multi-cloud environments without open ports.
Read more...
Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces VPNs, secures IoT, and connects multi-cloud environments without open ports.
Read more...
8 Months of Learning, 4 Months of Hunting, 0 Bugs — Here’s What Actually Went Wrong
The stuck-at-zero year is common, documented, and mostly misdiagnosed. The evidence points at where you hunt — not how well.Continue reading on Medium »
Read more...
The stuck-at-zero year is common, documented, and mostly misdiagnosed. The evidence points at where you hunt — not how well.Continue reading on Medium »
Read more...
Medium
8 Months of Learning, 4 Months of Hunting, 0 Bugs — Here’s What Actually Went Wrong
The stuck-at-zero year is common, documented, and mostly misdiagnosed. The evidence points at where you hunt — not how well.
The Bugs AI Still Can’t Find: What Will Make You a Valuable Bug Hunter in 2026
Every few months someone posts a screenshot of an AI tool finding an XSS in thirty seconds, and the bug bounty community has a small panic…Continue reading on Medium »
Read more...
Every few months someone posts a screenshot of an AI tool finding an XSS in thirty seconds, and the bug bounty community has a small panic…Continue reading on Medium »
Read more...
Medium
The Bugs AI Still Can’t Find: What Will Make You a Valuable Bug Hunter in 2026
Every few months someone posts a screenshot of an AI tool finding an XSS in thirty seconds, and the bug bounty community has a small panic…
systeminformer v4.0.26241.138
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management. Portable and free.
Read more...
Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management. Portable and free.
Read more...
Smali By bithowl: Chapter 8 Methods and Fields
(“The Memory and Machinery Inside Every Android Class”)Continue reading on Medium »
Read more...
(“The Memory and Machinery Inside Every Android Class”)Continue reading on Medium »
Read more...
Medium
Smali By bithowl: Chapter 8 Methods and Fields
(“The Memory and Machinery Inside Every Android Class”)
8 Months of Learning, 4 Months of Hunting, 0 Bugs — Here’s What Actually Went Wrong
https://medium.com/@rajnamdev/8-months-of-learning-4-months-of-hunting-0-bugs-heres-what-actually-went-wrong-898628c62438?source=rss------bug_bounty-5
https://medium.com/@rajnamdev/8-months-of-learning-4-months-of-hunting-0-bugs-heres-what-actually-went-wrong-898628c62438?source=rss------bug_bounty-5
The stuck-at-zero year is common, documented, and mostly misdiagnosed. The evidence points at where you hunt — not how well.Continue reading on Medium » (https://medium.com/@rajnamdev/8-months-of-learning-4-months-of-hunting-0-bugs-heres-what-actually-went-wrong-898628c62438?source=rss------bug_bounty-5)
New CTF: Format of Doom - Pentester vs AI Challenge 2
https://www.reddit.com/r/redteamsec/comments/1vxwg9u/new_ctf_format_of_doom_pentester_vs_ai_challenge_2/
<!-- SC_OFF -->Hi all! My company Escape just released a new CTF called Format of Doom (https://pentester-vs-ai-game.com/) which I thought you might be interested in trying. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge. This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature. Give it a try and let me know what you think! The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard. Happy playing : ) <!-- SC_ON --> submitted by /u/PriorPuzzleheaded880 (https://www.reddit.com/user/PriorPuzzleheaded880)
[link] (https://pentester-vs-ai-game.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1vxwg9u/new_ctf_format_of_doom_pentester_vs_ai_challenge_2/)
https://www.reddit.com/r/redteamsec/comments/1vxwg9u/new_ctf_format_of_doom_pentester_vs_ai_challenge_2/
<!-- SC_OFF -->Hi all! My company Escape just released a new CTF called Format of Doom (https://pentester-vs-ai-game.com/) which I thought you might be interested in trying. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge. This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature. Give it a try and let me know what you think! The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard. Happy playing : ) <!-- SC_ON --> submitted by /u/PriorPuzzleheaded880 (https://www.reddit.com/user/PriorPuzzleheaded880)
[link] (https://pentester-vs-ai-game.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1vxwg9u/new_ctf_format_of_doom_pentester_vs_ai_challenge_2/)
SpecterOps Kubernetes for Red Teamers lab on KVM/libvirt
https://www.reddit.com/r/redteamsec/comments/1vxyowc/specterops_kubernetes_for_red_teamers_lab_on/
<!-- SC_OFF -->Had a look through SpecterOps' Kubernetes for Red Teamers course and ended up patching the lab to run on KVM/libvirt instead of VirtualBox. Dropping it here in case anyone else on Linux wants the same setup. <!-- SC_ON --> submitted by /u/blahmemeblah (https://www.reddit.com/user/blahmemeblah)
[link] (https://github.com/GregDurys/specterops-k8s-red-teamers-libvirt-patch) [comments] (https://www.reddit.com/r/redteamsec/comments/1vxyowc/specterops_kubernetes_for_red_teamers_lab_on/)
https://www.reddit.com/r/redteamsec/comments/1vxyowc/specterops_kubernetes_for_red_teamers_lab_on/
<!-- SC_OFF -->Had a look through SpecterOps' Kubernetes for Red Teamers course and ended up patching the lab to run on KVM/libvirt instead of VirtualBox. Dropping it here in case anyone else on Linux wants the same setup. <!-- SC_ON --> submitted by /u/blahmemeblah (https://www.reddit.com/user/blahmemeblah)
[link] (https://github.com/GregDurys/specterops-k8s-red-teamers-libvirt-patch) [comments] (https://www.reddit.com/r/redteamsec/comments/1vxyowc/specterops_kubernetes_for_red_teamers_lab_on/)
AI safety & security redteaming
https://www.reddit.com/r/redteamsec/comments/1vy5qjm/ai_safety_security_redteaming/
<!-- SC_OFF -->Most redteaming solutions for AI applications are focused on pure security aspects but application owners are putting behavior safeguards and want to validate those besides the security safeguards. The cyber professionals want to test not just the AI stack but any of the exposed API layers. These were some of the common pieces of feedback I heard to help design a solution from the ground up for these needs. We just announced a major release of our OSS repo at https://github.com/NuGuardAI/nuguard Supports wide-range of languages: JS/TS, Python, C#, Golang, K8s/cloud manifest files. 10+ agentic frameworks, data stores, guardrails, etc. Looking forward to your reviews and feedback. Give us a star if you like the toolkit. <!-- SC_ON --> submitted by /u/3Pointers (https://www.reddit.com/user/3Pointers)
[link] (https://github.com/NuGuardAI/nuguard) [comments] (https://www.reddit.com/r/redteamsec/comments/1vy5qjm/ai_safety_security_redteaming/)
https://www.reddit.com/r/redteamsec/comments/1vy5qjm/ai_safety_security_redteaming/
<!-- SC_OFF -->Most redteaming solutions for AI applications are focused on pure security aspects but application owners are putting behavior safeguards and want to validate those besides the security safeguards. The cyber professionals want to test not just the AI stack but any of the exposed API layers. These were some of the common pieces of feedback I heard to help design a solution from the ground up for these needs. We just announced a major release of our OSS repo at https://github.com/NuGuardAI/nuguard Supports wide-range of languages: JS/TS, Python, C#, Golang, K8s/cloud manifest files. 10+ agentic frameworks, data stores, guardrails, etc. Looking forward to your reviews and feedback. Give us a star if you like the toolkit. <!-- SC_ON --> submitted by /u/3Pointers (https://www.reddit.com/user/3Pointers)
[link] (https://github.com/NuGuardAI/nuguard) [comments] (https://www.reddit.com/r/redteamsec/comments/1vy5qjm/ai_safety_security_redteaming/)
I made a Cyberpunk 2077-inspired theme for Adaptix C2
https://www.reddit.com/r/redteamsec/comments/1vy83iu/i_made_a_cyberpunk_2077inspired_theme_for_adaptix/
<!-- SC_OFF -->I’ve been playing around with Adaptix C2 and decided its interface needed a bit more neon. So I made a Cyberpunk 2077-inspired theme for it. It includes custom themes for both the main UI and console. The basic setup only requires importing two JSON files. I also added instructions for applying a custom background if you want the full look. <!-- SC_ON --> submitted by /u/alfabuster (https://www.reddit.com/user/alfabuster)
[link] (https://github.com/alfabuster/Adaptix-C2-Cyberpunk-Theme) [comments] (https://www.reddit.com/r/redteamsec/comments/1vy83iu/i_made_a_cyberpunk_2077inspired_theme_for_adaptix/)
https://www.reddit.com/r/redteamsec/comments/1vy83iu/i_made_a_cyberpunk_2077inspired_theme_for_adaptix/
<!-- SC_OFF -->I’ve been playing around with Adaptix C2 and decided its interface needed a bit more neon. So I made a Cyberpunk 2077-inspired theme for it. It includes custom themes for both the main UI and console. The basic setup only requires importing two JSON files. I also added instructions for applying a custom background if you want the full look. <!-- SC_ON --> submitted by /u/alfabuster (https://www.reddit.com/user/alfabuster)
[link] (https://github.com/alfabuster/Adaptix-C2-Cyberpunk-Theme) [comments] (https://www.reddit.com/r/redteamsec/comments/1vy83iu/i_made_a_cyberpunk_2077inspired_theme_for_adaptix/)
Unauthenticated remote uninstall in my own EDR agent, and the four other auth bugs that turned out to be the same bug
https://www.reddit.com/r/redteamsec/comments/1vy9rwy/unauthenticated_remote_uninstall_in_my_own_edr/
submitted by /u/RevolutionaryPie4948 (https://www.reddit.com/user/RevolutionaryPie4948)
[link] (https://d3vhex.github.io/2026-08-25-unauthenticated-remote-uninstall/) [comments] (https://www.reddit.com/r/redteamsec/comments/1vy9rwy/unauthenticated_remote_uninstall_in_my_own_edr/)
https://www.reddit.com/r/redteamsec/comments/1vy9rwy/unauthenticated_remote_uninstall_in_my_own_edr/
submitted by /u/RevolutionaryPie4948 (https://www.reddit.com/user/RevolutionaryPie4948)
[link] (https://d3vhex.github.io/2026-08-25-unauthenticated-remote-uninstall/) [comments] (https://www.reddit.com/r/redteamsec/comments/1vy9rwy/unauthenticated_remote_uninstall_in_my_own_edr/)