Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium » (https://medium.com/@yasser_/when-an-invitation-isnt-really-an-invitation-a-real-world-bug-finding-5d1469a877f0?source=rss------bug_bounty-5)
When an Invitation Isn’t Really an Invitation , A real world bug Finding

One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium »
Read more...
Dark-Moon v1.4.0

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
Read more...
DOM XSS Deep Dive: Sources, Sinks, and Backwards Tracing

Hello, I am Nitin.Continue reading on Medium »
Read more...
How Did I Find a Subdomain Takeover in a HackerOne Program?

How a forgotten DNS record led me to an unclaimed Heroku applicationContinue reading on Medium »
Read more...
LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting

Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium »
Read more...
The Victim Paid. The Attacker Used Their Subscription.

Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
The AI Bug Bounty Delusion: Why LLMs and Scanners Won’t Make You a Hacker

If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…Continue reading on Medium »
Read more...
opencti v7.260907.0

Open Cyber Threat Intelligence Platform
Read more...
Shuffle v2.3.0-rc1
https://kitploit.com/en/posts/github-shuffle-shuffle-v230-rc1

Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and hybrid resource sharing for SOC teams.
Dark-Moon v1.4.0
https://kitploit.com/en/posts/github-ascit31-dark-moon-v140

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
I Wasn’t Hunting an Email Bug. I Just Changed One Word.

Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Advanced Vulnerabilities Part 2: Cross-Chain, Signatures & Upgradeable Pitfalls

Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min readContinue reading on Medium »
Read more...
How I Could Have Shut Down Every Restaurant in Europe With One Click

I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.Continue reading on Medium »
Read more...