Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Authentication Failures — The #7 Vulnerability on the Web

When the system that’s supposed to verify who you are — fails completely.Continue reading on Medium »
Read more...
raptor v3.1.0
https://kitploit.com/en/posts/github-gadievron-raptor-v310

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit generation, and patch writing for offensive and defensive operations.
mvt v2026.9.7
https://kitploit.com/en/posts/github-mvt-project-mvt-v202697

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private indicators of compromise.
syswarden
https://kitploit.com/en/tools/github/duggytuxy/syswarden

SysWarden is a host-local security orchestrator combining authoritative nftables policy, HIDS/HIPS telemetry, bounded threat intelligence, out-of-band WAAP log analysis, authenticated high availability and a native terminal dashboard.
DarkTortilla-RAT-Telegram-Exfiltration-Payload-Extraction-Analysis
https://kitploit.com/en/tools/github/kaandemir993/darktortilla-rat-telegram-exfiltration-payload-extraction-analysis

Reverse engineering analysis of DarkTortilla RAT, a sophisticated malware that steals credit card data, decrypts browser passwords, and exfiltrates via Telegram, SMTP, and FTP.
wraith
https://kitploit.com/en/tools/github/arcanum-sec/wraith

WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educators. For authorized security testing, research & education only.
When the system that’s supposed to verify who you are — fails completely.Continue reading on Medium » (https://medium.com/@vedanthore/authentication-failures-the-7-vulnerability-on-the-web-ba57a1ad2024?source=rss------bug_bounty-5)
One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium » (https://medium.com/@yasser_/when-an-invitation-isnt-really-an-invitation-a-real-world-bug-finding-5d1469a877f0?source=rss------bug_bounty-5)
When an Invitation Isn’t Really an Invitation , A real world bug Finding

One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium »
Read more...
Dark-Moon v1.4.0

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
Read more...
DOM XSS Deep Dive: Sources, Sinks, and Backwards Tracing

Hello, I am Nitin.Continue reading on Medium »
Read more...
How Did I Find a Subdomain Takeover in a HackerOne Program?

How a forgotten DNS record led me to an unclaimed Heroku applicationContinue reading on Medium »
Read more...
LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting

Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium »
Read more...