ASAbdulaziz Saadinblog.abdulaziz-d.com·21h ago · 12 min readFrom Editor to Owner: One Writable Field Was Enough to Take Over an OrganizationSeverity: HighBounty: ~$315Platform: Standoff365 This one came down to a single field that should never have been writable by an editor: Firm[user_id] The application had a clear permission model. An10
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·3d ago · 8 min readClient-Side Web Security EssentialsModern web apps aren’t just “pages in a browser”—they’re interactive systems where the client (browser) and the server continuously exchange data and decisions. If you’re learning web application secu10
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·6d ago · 8 min readMy AI Agent Captured the Flag. Then the Platform Refused to Accept It. Today was a good day and a weird day, in that order. The good part: the autonomous pentest agent I've been building — I call it HALO — went from "runs a bunch of tools and hopes" to an actual web-reco00
ASAbdulaziz Saadinblog.abdulaziz-d.com·Aug 7 · 12 min readA $2,000 API Key: Unauthorized Access to Paid Medical TranscriptionSeverity: HighBounty: $2,000Retest Reward: $150Total Awarded: $2,150Program: Private ProgramPlatform: HackerOne This finding started with a familiar Android testing problem: What secrets were shipped00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 6 · 3 min readClaude Code Just Hijacked My Workflow… and My Screen Started Glowing I asked Claude Code to do one of the most boring tasks imaginable. “Find the music file I made.” That’s it. No penetration testing. No coding marathon. No AI agent swarm coordinating across containers02S
Mmehveteroinmehvetero.com·Aug 1 · 8 min readHow a Missing `assert!` Drained $3.44M From Typus Finance — and Why the Code Looked CorrectOn October 15, 2025, at 13:05 UTC, an attacker began draining Typus Finance's TLP liquidity pool on the Sui network. Thirty-four minutes later, the contracts were paused — but the pool was already emp00
ASAbdulaziz Saadinblog.abdulaziz-d.com·Jul 30 · 13 min readFrom Profile IDOR to Zero-Click Account Takeover: Changing One userid Parameter Was EnoughSeverity: CriticalBounty: $1,805Program: Private Bug BountyPlatform: Bugbounty.sa This started as a straightforward profile IDOR. An authenticated user could change a userid parameter and load another21N
Rrobertovg24inrobertovg.hashnode.dev·Jul 29 · 8 min readVerifiable BookmarkletsI just added a small new tool to the site: Verifiable Bookmarklets. Every bookmarklet it generates carries a SHA-256 fingerprint, so anyone can check that the javascript: link they received was really00
BB0dj0xinb0dj0x.hashnode.dev·Jul 27 · 6 min readHow to Start Bug Bounty Hunting in 2026: The Complete Beginner's GuideEverything you need to know to find your first vulnerability, get paid, and build a real reputation in cybersecurity — without breaking any laws. If you've typed "how to start bug bounty hunting" int10
Mmehveteroinmehvetero.com·Jul 27 · 7 min readThree Sui Exploits, One Disease — Why "The Math Looked Fine" Keeps Costing Hundreds of MillionsCetus lost $223M to a shift overflow. Aftermath lost $1.14M to a negative fee. Bucket Protocol ships a decimal scaling bug today. All three passed audits. All three have the same root cause. I've spe00