IDORs & BACs are still the most reported vulnerabilities 🔝
Explore our free lab to understand how this vulnerability works, guided by @hacksplained 👇
https://t.co/tmGpZoDYGa
$10,000 Google Bug Bounty: AppSheet RCE
BugTraceAI found deserialization RCE in AppSheet automation. Malicious .NET payload → PowerShell execution on Google's backend.
🔗 https://t.co/XiBqxr8dLi
---
More writeups like this? 👇
🔗 Want to perfect?👉https://t.co/pJWHoCMDix
APIs are only as secure as the code behind them.
This write-up breaks down how SQL Injection still shows up in API endpoints, how attackers identify it, and what developers should do to stop it.
📖 https://t.co/EzELwxzBzJ
Join the team 👉 https://t.co/cADA5DUdp5
I am just completed the @THNCAbyNCSA Cybersecurity program!
Another step toward becoming a Security Researcher.
Now it's time to put the knowledge into practice through labs, web security, and bug bounty. 🚀
#Cybersecurity#THNCA#BugBounty#SecurityResearch
Most bug hunters stop at X-Forwarded-Host and wonder why their cache poisoning reports get $500.
Someone spent 6 months studying CDN architectures.
Here's what separates $500 reports from $10,000+ critical findings:
🧵👇
CLAUDE HAS A SERIOUS PRIVACY PROBLEM RIGHT NOW, A HUGE NUMBER OF SHARED CONVERSATIONS ARE PUBLICLY INDEXED ON GOOGLE FOR ANYONE TO FIND
when you use claude's share feature it makes a public link. it turns out those links got indexed by search engines, so "share with anyone who has the link" actually became "anyone can find this by searching"
and people are pulling up genuinely alarming stuff:
> api keys, credentials and crypto wallets
> personal resumes with real names, addresses and phone numbers
> a lawyer working through a potential ethics violation
> an engineers internal company project details
> what appear to be peoples social security numbers
> and a crazy number of deeply personal chats people never imagined another human would read
anthropic never added a noindex tag to those shared pages, so search engines were free to crawl and list them
one line of code would have prevented the whole thing
this already happened to chatgpt about a year ago, same exact issue, but openai patched it fast
if you have EVER hit share on a claude chat, assume it could be public
go to settings > privacy > your data > shared chats > manage
delete anything you dont want the whole internet to see, especially anything personal or financial
FROM INTERNET
1)How a Simple Profile Setting Revealed Sensitive Credentials in a Bug Bounty Program
https://t.co/8iQSYE5ATG
2)Reverse Engineering APIs with Chrome DevTools: A Bug Bounty Practical Guide
https://t.co/0C1yMicf8V
3)How I Earned $10,000 From Microsoft (From Just 2 Bugs Out of 30+)
https://t.co/L43Z3tSqd5
4)An AI Agent Hacked Hugging Face. Here’s Exactly How It Happened — Step by Step
https://t.co/82SdaagDpe
5)How I found Critical Vulnerability In Government PSU that exposes Employee Very Sensitive Details through AI Chatbot
https://t.co/4L0IAfXoH9
6)SSRF with Blacklist-Based Input Filter:Write-up
https://t.co/ntGXlNOftU
7)Bruno Vulnlab write-up
https://t.co/uOe7xMDsZI
8)100 Cybersecurity Resources That Actually Matter
https://t.co/b2m5yiztZH
9)🚨 Critical Media Takeover: How a Base64-Encoded QA Secret Compromised Production 📸
https://t.co/bhTMMDsLio
10)When Security by Obscurity Blinds the WAF: From Client-Side Encryption to Critical SQL Injection — Part 1
https://t.co/cqAD8C7Jo8
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity