ASAbdulaziz Saadinblog.abdulaziz-d.com·9h ago · 10 min readThe $1000 Ticket IDOR: One Number Exposed National IDs and Government Staff PIISeverity: HighBounty: ~$949Program: Private Bug BountyPlatform: Bugbounty.sa This finding started with a very simple endpoint: GET /api/tickets-management/portal/history-by-ticket/<ticket_id> The end00
SSunnyincybersecurity-learning.hashnode.dev·12h ago · 14 min readTryHackMe Pickle Rick Beginner-Friendly Learning GuideIntroduction I recently completed the Pickle Rick room on TryHackMe as part of my ongoing cybersecurity learning journey. Pickle Rick is a beginner-friendly CTF-style room based on a fun Rick and Mort00
HFHussain Fakhruddininsultanbyte.com·15h ago · 8 min readMENA phone numbers in production: E.164, validation and OTP routingA phone-number field looks harmless until it reaches production. Then a Dubai user pastes 050 123 4567, a Saudi customer enters a Riyadh landline without +966, and a Qatari mobile arrives with a leadi10
李李弘基inkd-agentic.hashnode.dev·4h ago · 13 min readAI Daily Digest — August 19, 2026: OpenAI Pauses RL Training, NVIDIA $105B Ohio, Stripe Buys OpenRouter for $7BOpenAI pauses its frontier RL training and turns on token-level monitoring — safety as a release valve OpenAI said on Tuesday it had paused reinforcement-learning runs on its largest frontier models a00
KDKajal Dhanjalinkajalbuilds.hashnode.dev·16h ago · 12 min readAnatomy of an identity compromiseWhy nothing fired When a detection misses, the first instinct is to blame the rule. Wrong threshold, wrong table, wrong logic. Sometimes that is exactly right. But there is a class of intrusion where 00
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·10h ago · 4 min readWeb App Recon (Part-3)Finding Hidden Content and Functionality When assessing a web application's security, its visible structure alone isn't enough. Content and functionality that aren't linked from anywhere within the ap00
YPYogeshwar Peelainexploitnotes.hashnode.dev·10h ago · 8 min readTryHackMe : Athena WriteupOverview Athena is an easy-rated TryHackMe box that chains a leaked internal path (found via an anonymous SMB share) into a command injection vulnerability in a "router panel" ping tool, followed by a00
OIOghenemaro Ikelegbeincybersage.hashnode.dev·1d ago · 3 min readDetecting Synthetic Identity FraudSome of the most damaging financial fraud out there isn't committed by criminals stealing your identity. It's committed by criminals building an identity from scratch, one that never belonged to anyon00
YPYogeshwar Peelainexploitnotes.hashnode.dev·17h ago · 4 min readTryHackMe: Corridor - WriteupOverview Corridor is an easy TryHackMe box built around a single Flask/Werkzeug web app. The homepage presents an image of a corridor with thirteen clickable doors, each linking to a URL that is an MD00
ASAbdulaziz Saadinblog.abdulaziz-d.com·1d ago · 12 min readFrom Editor to Owner: One Writable Field Was Enough to Take Over an OrganizationSeverity: HighBounty: ~$315Platform: Standoff365 This one came down to a single field that should never have been writable by an editor: Firm[user_id] The application had a clear permission model. An10