thebugbountyhunter | Unsorted

Telegram-канал thebugbountyhunter - The Bug Bounty Hunter

43962

Happy hunting! thebugbountyhunter.com hello@thebugbountyhunter.com

Subscribe to a channel

The Bug Bounty Hunter

Apple Developer Stored XSS — $5,000 Bounty | Writeup 2025

ZombieHack/apple-developer-stored-xss-5-000-bounty-writeup-2025-cc34a030a5bf" rel="nofollow">https://medium.com/@ZombieHack/apple-developer-stored-xss-5-000-bounty-writeup-2025-cc34a030a5bf

Читать полностью…

The Bug Bounty Hunter

Sonar launches integration program to unify code governance across the SDLC

https://www.sonarsource.com/blog/sonar-launches-integration-program/

Читать полностью…

The Bug Bounty Hunter

An Evening with Claude (Code) - SpecterOps

https://specterops.io/blog/2025/11/21/an-evening-with-claude-code/

Читать полностью…

The Bug Bounty Hunter

Constant-time support lands in LLVM: Protecting cryptographic code at the compiler level

https://blog.trailofbits.com/2025/11/25/constant-time-support-lands-in-llvm-protecting-cryptographic-code-at-the-compiler-level/

Читать полностью…

The Bug Bounty Hunter

Understanding signal-to-noise for vulnerability management success

https://www.intigriti.com/blog/business-insights/understanding-signal-to-noise-for-vulnerability-management-success

Читать полностью…

The Bug Bounty Hunter

Sonar honored in Fast Company

https://www.sonarsource.com/blog/sonar-honored-in-fast-company-next-big-things-in-tech/

Читать полностью…

The Bug Bounty Hunter

From Token to Takeover: Exploiting Weak HS256 Secrets (POC)

1998satheesh/from-token-to-takeover-exploiting-weak-hs256-secrets-poc-c53afb9a75a0" rel="nofollow">https://medium.com/@1998satheesh/from-token-to-takeover-exploiting-weak-hs256-secrets-poc-c53afb9a75a0

Читать полностью…

The Bug Bounty Hunter

Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

http://security.googleblog.com/2025/11/android-quick-share-support-for-airdrop-security.html

Читать полностью…

The Bug Bounty Hunter

SupaPwn: Hacking Our Way into Lovable

https://www.hacktron.ai/blog/supapwn

Читать полностью…

The Bug Bounty Hunter

We found cryptography bugs in the elliptic library using Wycheproof

https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/

Читать полностью…

The Bug Bounty Hunter

Securing GitHub Actions With SonarQube: Real-World Examples

https://www.sonarsource.com/blog/securing-github-actions-with-sonarqube-real-world-examples/

Читать полностью…

The Bug Bounty Hunter

Level up your Solidity LLM tooling with Slither-MCP

https://blog.trailofbits.com/2025/11/15/level-up-your-solidity-llm-tooling-with-slither-mcp/

Читать полностью…

The Bug Bounty Hunter

Release v3.5.0 · projectdiscovery/nuclei

https://github.com/projectdiscovery/nuclei/releases/tag/v3.5.0

Читать полностью…

The Bug Bounty Hunter

How we avoided side-channels in our new post-quantum Go cryptography libraries

https://blog.trailofbits.com/2025/11/14/how-we-avoided-side-channels-in-our-new-post-quantum-go-cryptography-libraries/

Читать полностью…

The Bug Bounty Hunter

SonarQube Named a Leader and Fast Mover in GigaOm

https://www.sonarsource.com/blog/sonarqube-named-leader-in-gigaom-application-security-testing/

Читать полностью…

The Bug Bounty Hunter

How to Research & Reverse Web Vulnerabilities 101 — ProjectDiscovery Blog

https://projectdiscovery.io/blog/how-to-research-web-vulnerabilities

Читать полностью…

The Bug Bounty Hunter

November CTF Challenge: Exploiting JWT vulnerabilities to achieve RCE

https://www.intigriti.com/researchers/blog/hacking-tools/november-ctf-challenge-exploiting-jwt-vulnerabilities

Читать полностью…

The Bug Bounty Hunter

🔥 Intigriti Challenge 1125 — JWT Confusion to SSTI → RCE (My Fastest CTF Solve Ever)

https://savi0r.medium.com/intigriti-challenge-1125-jwt-confusion-to-ssti-rce-my-fastest-ctf-solve-ever-43d43df4182c

Читать полностью…

The Bug Bounty Hunter

Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)

https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/

Читать полностью…

The Bug Bounty Hunter

Announcing SonarSweep: Improving training data quality for coding LLMs

https://www.sonarsource.com/blog/announcing-sonarsweep-improving-training-data-quality-for-coding-llms/

Читать полностью…

The Bug Bounty Hunter

Intigriti Bug Bytes #230 - November 2025 🚀

https://www.intigriti.com/researchers/blog/bug-bytes/intigriti-bug-bytes-230-november-2025

Читать полностью…

The Bug Bounty Hunter

Securing GitHub Actions With SonarQube: Real-World Examples

https://www.sonarsource.com/blog/securing-github-actions-with-sonarqube-real-world-examples/

Читать полностью…

The Bug Bounty Hunter

Black Friday and Cyber Monday price distortion identification

https://www.intigriti.com/blog/business-insights/black-friday-and-cyber-monday-price-distortion-identification

Читать полностью…

The Bug Bounty Hunter

Securing GitHub Actions With SonarQube: Real-World Examples

https://www.sonarsource.com/blog/securing-github-actions-with-sonarqube-real-world-examples/

Читать полностью…

The Bug Bounty Hunter

Intigriti wins ‘Security Innovation of the Year’ at the 2025 UK IT Industry Awards

https://www.intigriti.com/blog/awards/intigriti-wins-security-innovation-of-the-year-at-the-2025-uk-it-industry-awards

Читать полностью…

The Bug Bounty Hunter

Flutter SSL Bypass: How to Intercept HTTPS Traffic When all other Frida Scripts Fail
https://m4kr0x.medium.com/flutter-tls-bypass-how-to-intercept-https-traffic-when-all-other-frida-scripts-fail-bd3d04489088

Читать полностью…

The Bug Bounty Hunter

When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446)

https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/

Читать полностью…

The Bug Bounty Hunter

Hacking with Burp AI in the Chesspocalypse: API expert Corey Ball showcases how Burp AI can support pentesters.

https://portswigger.net/blog/hacking-with-burp-ai-in-the-chesspocalypse-api-expert-corey-ball-showcases-how-burp-ai-can-support-pentesters

Читать полностью…

The Bug Bounty Hunter

Injection for an athlete

https://swarm.ptsecurity.com/injection-for-an-athlete/

Читать полностью…

The Bug Bounty Hunter

Rust in Android: move fast and fix things

http://security.googleblog.com/2025/11/rust-in-android-move-fast-fix-things.html

Читать полностью…
Subscribe to a channel