en
Feedback
Bug bounty Tips

Bug bounty Tips

Open in Telegram

πŸ›‘οΈ Cybersecurity enthusiast | πŸ’» Helping secure the digital world | 🌐 Web App Tester | πŸ•΅οΈβ€β™‚οΈ OSINT Specialist Admin: @laazy_hack3r

Show more
6 832
Subscribers
+1424 hours
+1097 days
+43130 days
Attracting Subscribers
September '26
September '26
+103
in 0 channels
August '26
+484
in 0 channels
Get PRO
July '26
+463
in 0 channels
Get PRO
June '26
+419
in 0 channels
Get PRO
May '26
+588
in 0 channels
Get PRO
April '26
+543
in 0 channels
Get PRO
March '26
+358
in 0 channels
Get PRO
February '26
+318
in 0 channels
Get PRO
January '26
+360
in 0 channels
Get PRO
December '25
+411
in 1 channels
Get PRO
November '25
+464
in 0 channels
Get PRO
October '25
+152
in 0 channels
Get PRO
September '25
+74
in 0 channels
Get PRO
August '25
+213
in 1 channels
Get PRO
July '25
+41
in 0 channels
Get PRO
June '25
+15
in 0 channels
Get PRO
May '25
+27
in 0 channels
Get PRO
April '25
+43
in 0 channels
Get PRO
March '25
+41
in 0 channels
Get PRO
February '25
+45
in 0 channels
Get PRO
January '25
+88
in 1 channels
Get PRO
December '24
+73
in 2 channels
Get PRO
November '24
+234
in 2 channels
Get PRO
October '24
+372
in 2 channels
Get PRO
September '24
+307
in 2 channels
Get PRO
August '24
+414
in 2 channels
Get PRO
July '24
+131
in 1 channels
Get PRO
June '24
+84
in 0 channels
Get PRO
May '24
+196
in 2 channels
Get PRO
April '24
+117
in 0 channels
Get PRO
March '24
+41
in 0 channels
Get PRO
February '24
+76
in 0 channels
Get PRO
January '24
+47
in 0 channels
Get PRO
December '23
+13
in 0 channels
Get PRO
November '23
+79
in 0 channels
Get PRO
October '23
+282
in 0 channels
Date
Subscriber Growth
Mentions
Channels
07 September+5
06 September+15
05 September+11
04 September+17
03 September+16
02 September+15
01 September+24
Channel Posts
#MLSecOps #Tech_book "Practical AI Security: A Hands-on Guide to Attacking, Defending, and Securing Modern AI Systems", 2026. // Break AI Systems. Then Secure Them. If you’re a security practitioner learning to operate in AI environments, or an ML engineer who needs to understand what adversaries actually do, Practical AI Security gives you the technical foundation the field demands

2
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Aug 15 - Sep 05, 2026) 0⃣ nDPI 6.0 (Aug 2026) 1⃣ Attackers used BGP to spoof the Virtualizor update server and the Softaculous website 2⃣ Sleepwalker Malware 3⃣ Sangoma Switchvox Exploit 4⃣ Fronics Deploy Abuse 5⃣ Escaping Google Cloud Application Integration Sandbox: Straight into Borg 6⃣ VMware threat emulation techniques // A reproducible catalogue of 86 atomic actions against vCenter, ESXi, SDDC Manager, and the wider VCF ecosystem 7⃣ Log4J FilteredObjectInputStream Vulnerability // Research 8⃣ FTP Banners The New Dead Drop Resolver Delivering Novel RATs 9⃣ Android Car Malware πŸ”Ÿ AliExpress WebAudio fingerprinting
214
3
#DFIR #Whitepaper #Blue_Team_Techniques "Detection Engineering 2026: 100 Priority Use Cases, Alert Detections & Correlation Rules", 2026. // The whitepaper authored by cybersecurity leader Izzmier Izzuddin represents one of the industry's most comprehensive defensive playbooks. Updated explicitly for MITRE ATT&CK v19, it separates traditional defense evasion into Stealth and Defense Impairment, providing production-grade detection logic, analyst triage workflows, and structured correlation frameworks
188
4
#Infosec_Standards NIST IR 8611: "m-NGAC Transcending Traditional Database Security Models", Aug. 2026. // This paper examines the limitations of conventional database access control practices and introduces mNGAC (embedded Next Generation Access Control), a novel system that embeds the ANSI/INCITS NGAC standard directly within the database. By enforcing access control at the level of individual column data right in the database, m-NGAC offers a significant advancement over traditional methods and ensures data security, regardless of the querying tool, including SQL editors
166
5
#Research #Threat_Modelling #WebApp_Security "Beyond the Trust Boundary: A Critical Reassessment of the FIDO2 Threat Model", Sep. 2026. // In this work, the FIDO2 threat model is critically reassessed, and it is shown that several commonly assumed security properties do not hold under realistic deployment conditions. The threat model is extended beyond the cryptographic layer to examine eight attack vectors across the FIDO2 stack: malicious browser extensions, platform-handler malware, passive sniffing, virtual device drivers, CTAP2-specific malware, USB/hardware implants, malicious USB hubs/docks/extenders, and NFC relay attacks
129
6
#AIOps #Threat_Research GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok https://www.manifold.security/blog/ai-coding-agents-git-hijack // Git Hijack for AI Agents. Eight findings across seven agents. Four remain unpatched at publication..
124
7
#tools #Kernel_Security #Sec_code_review "PrimSynth: An Agentic Approach to Discover, Validate, and Synthesize Exploit Primitives for Linux Kernel Vulnerabilities", Sep. 2026. // PrimSynth - multi-agent framework for Linux kernel vulnerability, covering the full path from CVE query to primitive extraction and exploit code synthesis
124
8
#AIOps "Zero-Knowledge Predicate Proofs Between AI Agents: A Measured, Cross-Protocol Gateway and the Source-Integrity Gap", Aug. 2026. ]-> Reference implementation
111
9
#Research #Threat_Research #Blue_Team_Techniques "The Exclusion Ratchet: False-Positive Suppression Accumulates and Persists in Detection Rule Repositories", Aug. 2026. ]-> https://zenodo.org/records/22107282 // When a rule produces too many false alarms an analyst adds an exclusion, and the rule thereafter declines to alert in that circumstance. Each such decision is locally reasonable; what becomes of them collectively is not known..
116
10
#AppSec #MLSecOps Breaking Claude Code Opus 5 Auto Mode https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode // Auto Mode in Claude Code's safety classifier does not prevent targeted code execution attacks, which can hijack agents via malicious websites, highlighting the need for OS isolation and strict process controls beyond simple safety gating
109
11
#Analytics #Whitepaper "SANS 2026 Security Awareness & Culture Report: Embedding a Strong Security Culture", 2026. // The SANS Security Awareness & Culture Report is the field's only annual benchmark built by practitioners, for practitioners. Now in its 11th year, the report maps where programs stand, what risks are rising, and what the data says about how to respond - giving security awareness professionals the benchmarks, maturity roadmap, and career intelligence to move their programs and their roles forward
109
12
#AppSec Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit ]-> https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject
110
13
#Threat_Research #WebApp_Security Attack of The Extensions https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence // Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft
111
14
#tools #Offensive_security CrystalPotato - Windows privilege escalation tool https://github.com/ricardojoserf/CrystalPotato // CrystalPotato is a static Windows privilege escalation tool that exploits DCOM OXID Resolver and named pipe impersonation to elevate from SeImpersonatePrivilege to SYSTEM, supporting command execution, reverse shells, and local account creation
113
15
#tools #AIOps "ClawSentry: A Progressive Multi-Tier Security Monitor for Safeguarding Autonomous LLM Agents", Aug. 2026. ]-> https://github.com/Elroyper/ClawSentry // ClawSentry is the reference implementation of the Agent Harness Protocol (AHP), a framework-independent interface for mediating AI-agent actions at runtime
119
16
#tools #Offensive_security "KeyTAR: Practical Keystroke Timing Attacks and Input Reconstruction", 2026. ]-> https://zenodo.org/records/17254163 ]-> https://github.com/UNITES-Lab/keylogging // The attack consists of two main components: - Keystroke Extraction: Collects inter-keystroke timings through microarchitectural side-channel techniques - Keystroke Inference: Uses the extracted timings to infer the original typed input
127
17
#Malware_analysis 1⃣ Dissecting the JWR phishing framework https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework 2⃣ Akira Hits Safe Mode: Ransomware Rebooting Around EDR https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr 3⃣ Expired Malicious Domains Bring New Threats to Life https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows 4⃣ Malicious Rust Crate arrayref Runs a Build-Time Payload https://safedep.io/arrayref-proc-macro1-rust-build-time-malware 5⃣ The invisible passenger in your car https://securelist.com/android-head-unit-malware/121106
173
18
#Tech_book #WebApp_Security "Rust Web Programming, Third Edition: A hands-on guide to Rust for modern web development, with microservices and nanoservices", 2026. // A comprehensive guide to developing, packaging, and deploying Rust web applications - with new coverage on async Rust, WebAssembly, nanoservices, and more
188
19
Bug Bounty Hunting: How to Start Finding Real Vulnerabilities (and Get Paid): https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/bug-bounty-hunting-how-to-start-finding-real-vulnerabilities-and-get-paid-2068d19c964f?source=rss------bug_bounty-5
1 020
20
Bug Bounty Hunting: How to Start Finding Real Vulnerabilities (and Get Paid): https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/bug-bounty-hunting-how-to-start-finding-real-vulnerabilities-and-get-paid-2068d19c964f?source=rss------bug_bounty-5
993
Bug bounty Tips - Statistics & analytics of Telegram channel @bugbounty_tech