Abhishek meena·Sep 13Top 43 AI Security Skills, MCP Servers & GitHub Repos Every Bug Hunter NeedsThe AI-security corner of GitHub is moving too fast for its own good.
Ashar Mahmood·4d ago€1500 | 2FA Bypass: How We Bypassed the 2nd Factor Without Ever Passing ItHello! I’m Ashar Mahmood, a 23 year old cybersecurity researcher who keeps coming back to one thing: broken authentication. There is…A response icon2
Rohith S·Sep 15💰 How I Earned My First $5,000 Bug Bounty by Finding a Critical Authorization FlawBy Rohith SA response icon1
Pratik Dabhi·3d agoOne Redirect Was Enough: Bypassing a Strict SSRF Filter to Breach the Internal NetworkHello there,A response icon2
Abhishek meena·Sep 3Is Manual Bug Bounty Hunting Still Worth It in 2026?Everyone keeps asking this question. Nobody gives an honest answer. So here are the real numbers.A response icon5
Raj Namdev·Just now52 Request Smuggling Reports. Two Rules Decide the Payout.30-Second Version: On August 5, PortSwigger published “CRLF-Powered Desync Attacks,” which turns plain HTTP header injection into full…
Joko Purwanto·Just nowInsecure Authorization on *** Android — mobile applicationAssalamualaikum wr.wb.
h1ddn·2h agoHow I Went from Zero Experience to Finding Valid Bugs on HackerOneAbout Me: I hunt under the handle I1ce on HackerOne.
CypherNova1337·2h agoThe Bug Bounty Blindspot: Why Crowdsourced Triage Leaves You More Exposed (and Costs You More) Than…Corporate security leaders love the crowdsourced bug bounty pitch. The sales team from a major platform steps into your boardroom with a…
Md. Mehedi hasan Babu·2h agoBug Bounty শুরু করার আগে যা বুঝতে হবেআপনি একটা bug bounty program-এ target পেলেন। Scope দেখলেন। একটা domain, কিছু subdomain, একটা web app।