MAMehmood Aliincrackingstation.hashnode.dev·1d ago · 1 min readTryHackMe CC: Pen Testing - Full Walkthrough (2026)Note: I originally published this guide on my blog…00
PRPass Revelatorinpassrevelator.hashnode.dev·5d ago · 4 min readHow Law Enforcement Uses AI & Cybersecurity Software Pass Revelator to Reunite Stolen DevicesCase study on how a French municipal police department addresses the challenge of password-protected recovered laptops. Official handover of Pass Revelator to the Municipal Police — Photo credit: Pasc00
ABAlejandro Bañoinblog.cain.tech·Sep 21 · 14 min readBusiness Logic Flaws: When the bug is the behaviorIntroduction Most security vulnerabilities exist because the code does something it shouldn't: it trusts unsanitized input, exposes internal state, or fails to enforce access controls. Business logic 00
ASAbdulaziz Saadinblog.abdulaziz-d.com·Sep 19 · 10 min readFrom Establishment IDOR to Account Takeover: Changing One Number Was EnoughSeverity: HighBounty: ~$1145Program: Private Bug BountyPlatform: Bugbounty.sa Some account takeovers start with stolen passwords, leaked tokens, or complicated OAuth chains. This one started with chan00
DEDavid Essienindavid-essien.hashnode.dev·Sep 19 · 6 min readOne Missing Parameter Cost Me Six Hours (PortSwigger Lab)I spent six hours trying to upgrade a non-admin user to admin, convinced I was missing some clever bypass. The gap turned out to be one field in a request body I'd already looked at twice. This is a P12M
AFAeon Flex / Splicer Scorninchaincoder.hashnode.dev·Sep 17 · 7 min readTool Poisoning on MCP Servers: The Attack Vector Nobody's PatchingThe MCP (Model Context Protocol) ecosystem grew from a specification into production infrastructure faster than most teams can spell "threat model." And that speed left a gap: the layer where an agent01C
AFAeon Flex / Splicer Scorninchaincoder.hashnode.dev·Sep 17 · 8 min readRansomware Operators Are Using AI Coding Agents NowA ransomware crew used Cursor to write exploit code for ESXi hypervisors this month. Not a hypothetical. Not a tabletop exercise. The Aurora group integrated AI coding agents into active operations an00
Mmehveteroinmehvetero.com·Sep 15 · 6 min readThe Hacker Who Lost $7.73M to a Bot — rsETH Safe Module ExploitOn September 15, 2026, someone found a bug in a custom router module attached to a Gnosis Safe holding over $7.73 million in Aave-wrapped rsETH. They built the exploit, submitted it to the mempool — a01M
KKernelzerainkernelzera.hashnode.dev·Sep 6 · 9 min readMalware Write-up: Analyzing a PDF-Disguised Multi-Stage .NET LoaderDisclaimer: This post describes malware analysis in an isolated lab. Do not run samples on a daily-use machine. Hashes and IOCs are shared for research and defense. Introduction I am an IT profession00
CGCristiano Gabrieliincrisdigital.hashnode.dev·Sep 7 · 15 min readBackend Exploits in ICS Systems — and Why Enclaves Matter More Than Ever Introduction There are moments in engineering where physics whispers a truth that software keeps forgetting. A diode does not negotiate. A photodiode does not improvise. They do not “trust” the signal00