home.social

#bugbountytips — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bugbountytips, aggregated by home.social.

  1. $148,337 #BugBounty paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full #RCE in Google Cloud production (CVE-2026-2031)
    #CloudSecurity #BugBountyTips
    👇
    brutecat.com/articles/google-c

  2. $148,337 #BugBounty paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full #RCE in Google Cloud production (CVE-2026-2031)
    #CloudSecurity #BugBountyTips
    👇
    brutecat.com/articles/google-c

  3. $148,337 #BugBounty paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full #RCE in Google Cloud production (CVE-2026-2031)
    #CloudSecurity #BugBountyTips
    👇
    brutecat.com/articles/google-c

  4. $148,337 #BugBounty paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full #RCE in Google Cloud production (CVE-2026-2031)
    #CloudSecurity #BugBountyTips
    👇
    brutecat.com/articles/google-c

  5. $148,337 #BugBounty paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full #RCE in Google Cloud production (CVE-2026-2031)
    #CloudSecurity #BugBountyTips
    👇
    brutecat.com/articles/google-c

  6. DOM XSS isn’t always in the HTML.

    Sometimes your input never appears in the Source because JavaScript is building the page.
    Source → Sink → Execution in real-world DOM flows.

    medium.com/@marduk.i.am/url-ba

    #infosec #cybersecurity #bugbountytips #websecurity #OWASP

  7. DOM XSS isn’t always in the HTML.

    Sometimes your input never appears in the Source because JavaScript is building the page.
    Source → Sink → Execution in real-world DOM flows.

    medium.com/@marduk.i.am/url-ba

    #infosec #cybersecurity #bugbountytips #websecurity #OWASP

  8. #Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
    #BugBountyTips
    👇

    hacktron.ai/blog/hacking-googl

  9. #Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
    #BugBountyTips
    👇

    hacktron.ai/blog/hacking-googl

  10. #Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
    #BugBountyTips
    👇

    hacktron.ai/blog/hacking-googl

  11. #Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
    #BugBountyTips
    👇

    hacktron.ai/blog/hacking-googl

  12. #Antgravity - an AI code editor from Google that has access to your entire codebase and terminal had a Remote Code Execution (#RCE) vulnerability - a great find and write-up by @HacktronAI earning them $10k #BugBounty!
    #BugBountyTips
    👇

    hacktron.ai/blog/hacking-googl

  13. The Best AI for Ethical Hacking In 2025, most programmers use LLMs to help them write code faster , which got me thinking , which LLM is the best to “ break ”  code . The LLMs which will be co...

    #bug-bounty-tips #bug-bounty #ai #cybersecurity #bug-bounty-writeup

    Origin | Interest | Match
  14. The payload contains '|/???/\b**\h,' which is meant to confuse WAF rules. Unusual characters are a common evasion tactic.

    image by: win3zz

    #cybersec #BugBountytips #infosec

  15. The payload contains '|/???/\b**\h,' which is meant to confuse WAF rules. Unusual characters are a common evasion tactic.

    image by: win3zz

    #cybersec #BugBountytips #infosec

  16. The payload contains '|/???/\b**\h,' which is meant to confuse WAF rules. Unusual characters are a common evasion tactic.

    image by: win3zz

    #cybersec #BugBountytips #infosec

  17. this is your reminder that if you're using Burp for web app testing, you should be using an extension that lets you use variables in your outgoing requests. variables functionality gives you a single place to update credential, token, and identifier values which improves productivity and reduces false positives. there are a few extensions that provide this functionality and I recommend my extension, Burp Variables, which is purpose-built for it: github.com/0xceba/burp_variabl

    #burp #burpsuite #burp_suite #pentesting #pentest #bugbounty #bugbountytips #hacking

  18. this is your reminder that if you're using Burp for web app testing, you should be using an extension that lets you use variables in your outgoing requests. variables functionality gives you a single place to update credential, token, and identifier values which improves productivity and reduces false positives. there are a few extensions that provide this functionality and I recommend my extension, Burp Variables, which is purpose-built for it: github.com/0xceba/burp_variabl

    #burp #burpsuite #burp_suite #pentesting #pentest #bugbounty #bugbountytips #hacking

  19.  Introducing KeyChecker – a CLI to fingerprint SSH private keys & map them to Git hosting accounts.

    We have been talking about this in our classes for a long while, finally automation is present now.

      Blog: https://cyfinoid.com/automating-a-known-weakness-introducing-keychecker/
     PyPI: https://pypi.org/project/keychecker/

    #bugbountytips #ssh #git #github #infosec #postexploitation

  20.  Introducing KeyChecker – a CLI to fingerprint SSH private keys & map them to Git hosting accounts.

    We have been talking about this in our classes for a long while, finally automation is present now.

      Blog: https://cyfinoid.com/automating-a-known-weakness-introducing-keychecker/
     PyPI: https://pypi.org/project/keychecker/

    #bugbountytips #ssh #git #github #infosec #postexploitation

  21.  Introducing KeyChecker – a CLI to fingerprint SSH private keys & map them to Git hosting accounts.

    We have been talking about this in our classes for a long while, finally automation is present now.

      Blog: https://cyfinoid.com/automating-a-known-weakness-introducing-keychecker/
     PyPI: https://pypi.org/project/keychecker/

    #bugbountytips #ssh #git #github #infosec #postexploitation

  22.  Introducing KeyChecker – a CLI to fingerprint SSH private keys & map them to Git hosting accounts.

    We have been talking about this in our classes for a long while, finally automation is present now.

      Blog: https://cyfinoid.com/automating-a-known-weakness-introducing-keychecker/
     PyPI: https://pypi.org/project/keychecker/

    #bugbountytips #ssh #git #github #infosec #postexploitation

  23.  Introducing KeyChecker – a CLI to fingerprint SSH private keys & map them to Git hosting accounts.

    We have been talking about this in our classes for a long while, finally automation is present now.

      Blog: https://cyfinoid.com/automating-a-known-weakness-introducing-keychecker/
     PyPI: https://pypi.org/project/keychecker/

    #bugbountytips #ssh #git #github #infosec #postexploitation

  24. Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
    #doyensec #security #internship #bugbounty

  25. Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
    #doyensec #security #internship #bugbounty

  26. Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
    #doyensec #security #internship #bugbounty

  27. Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
    #doyensec #security #internship #bugbounty

  28. Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
    #doyensec #security #internship #bugbounty