BUG BOUNTY TOOLS & Courses
Статистика- Последний пост
- 26 февр.
- Последнее чтение
- 13 авг.
- Постов за неделю
- 0
- Всего постов
- 21
- Тип
- открытый
- Язык
- английский
- В каталоге с
- 13 авг.
- 1/24сутки в ленте
- —
- 1/48двое суток
- —
- 1/72трое суток
- —
Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.
Посты
GraphQL Pentesting for Bug Bounty Hunters: From Endpoint Discovery to High-Impact Exploits…! https://medium.com/@mpjani294/graphql-pentesting-for-bug-bounty-hunters-from-endpoint-discovery-to-high-impact-exploits-821f64a953b5
When Audits Fail Part 2: From Pre-Auth SSRF to RCE in TRUfusion Enterprise https://www.rcesecurity.com/2026/02/when-audits-fail-from-pre-auth-ssrf-to-rce-in-trufusion-enterprise/
RCE in Google's AI code editor Antigravity - $10000 Bounty https://www.hacktron.ai/blog/hacking-google-antigravity
Electron Research in Desktop apps [Part 1] https://blog.securelayer7.net/electron-app-security-risks/
Cyber Resilience Act: Navigating speed and security with AI-coding https://www.sonarsource.com/blog/cra-navigating-speed-and-security-with-ai-coding/
Java 23: Embrace the new era of code comments https://www.sonarsource.com/blog/java-23-embrace-the-new-era-of-code-comments/
Intigriti Bug Bytes #228 - September 2025 🚀 https://www.intigriti.com/researchers/blog/bug-bytes/intigriti-bug-bytes-228-september-2025
What's the top bug in your language? Find out in The State of Code: Languages report https://www.sonarsource.com/blog/the-state-of-code-languages/
Jumping the line: How MCP servers can attack you before you ever use them https://blog.trailofbits.com/2025/04/21/jumping-the-line-how-mcp-servers-can-attack-you-before-you-ever-use-them/?hss_channel=lcp-912286
The No BS Bug Bounty & Web Hacking Roadmap https://www.youtube.com/watch?v=AMQq06WUMVk
Escalating Impact: Full Account Takeover in Microsoft via XSS in Login Flow https://melotover.medium.com/escalating-impact-full-account-takeover-in-microsoft-via-xss-in-login-flow-f160fa79b008
Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida https://sensepost.com/blog/2025/intercepting-https-communication-in-flutter-going-full-hardcore-mode-with-frida/
YesWeHack Hunter Interviews – #14 g4mb4: “My favourite bug was an IDOR at a $1 billion company” https://www.youtube.com/watch?v=hF0j4UTe8kE
They Used Tools I Used Logic 0-Click Account Takeover Without Breaking a Sweat https://medium.com/@loayahmed686/they-used-tools-i-used-logic-0-click-account-takeover-without-breaking-a-sweat-fd57c078dc82
без подписи
Bug Bounty from Scratch
TruffleHog's Burp Suite Extension: A Techical Deep Dive https://trufflesecurity.com/blog/introducing-trufflehog-s-burp-suite-extension-a-techical-deep-dive 10x to @ValyaRoller
XXE: A complete guide to exploiting advanced XXE vulnerabilities https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-advanced-xxe-vulnerabilities
CVE-2025-1094: PostgreSQL SQL Injection Vulnerability - ARMO https://www.armosec.io/blog/cve-2025-1094-postgresql-sql-injection-vulnerability/
Reversing Samsung’s H-Arx Hypervisor Framework - Part 1 https://dayzerosec.com/blog/2025/03/08/reversing-samsungs-h-arx-hypervisor-part-1.html