Bug bounty Tips
Kanalga Telegramβda oβtish
π‘οΈ Cybersecurity enthusiast | π» Helping secure the digital world | π Web App Tester | π΅οΈββοΈ OSINT Specialist Admin: @laazy_hack3r
Ko'proq ko'rsatish5 784
Obunachilar
+1024 soatlar
+887 kunlar
+41930 kunlar
Postlar arxiv
5 783
β€· Title: MITM lab + tryhackme DetectionβββBlue vs Red
ββββββββββββββββββββββββ
πͺ Author: Khalil
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Feb 2026 21:48:58 GMT
ββββββββββββββββββββββββ
β Tags: #tryhackme #ethical_hacking #man_in_the_middle_attack #ctf #wireshark
5 783
β€· Title: Privilege Escalation: Hijacking an Organization via Billing Notifications
ββββββββββββββββββββββββ
πͺ Author: Mohamed Fathy
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Feb 2026 20:16:09 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #penetration_testing #business_logic #security #idor_vulnerability
5 783
β€· Title: Why Moltbook is Dangerous: Critical Zero-days Found in My Audit (Full Report)
ββββββββββββββββββββββββ
πͺ Author: Saad Khalid
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Feb 2026 21:20:44 GMT
ββββββββββββββββββββββββ
β Tags: #vulnerability #penetration_testing #cybersecurity #moltbook #ai
5 783
β€· Title: Understanding the Evolution of Darkweb Markets Over Time
ββββββββββββββββββββββββ
πͺ Author: Tor BBB
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Feb 2026 21:24:30 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #osint #cybersecurity #darkweb
5 783
β€· Title: Hacking Networking Services Home Lab
ββββββββββββββββββββββββ
πͺ Author: Mainekhacker
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Feb 2026 21:01:00 GMT
ββββββββββββββββββββββββ
β Tags: #smb #protocol #cybersecurity #hacking #networking
5 783
Repost from Daily Writeups
β€· Title: Advanced Curl Guide for Bug Hunting: Reconnaissance and Exploitation Techniques
ββββββββββββββββββββββββ
πͺ Author: JPablo13
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 07 Feb 2026 00:01:01 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #hacking #technology #cybersecurity #bug_bounty
5 783
Repost from Daily Writeups
β€· Title: Bug Bounty Recon for Everyone
ββββββββββββββββββββββββ
πͺ Author: Batuhan AydΔ±n
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 07 Feb 2026 01:59:42 GMT
ββββββββββββββββββββββββ
β Tags: #hacking #recon #beginner #ethical_hacking #bug_bounty
5 783
Repost from Daily Writeups
β€· Title: Web Fuzzing: A Practical Testing Methodology
ββββββββββββββββββββββββ
πͺ Author: Israel ArΓ‘oz Severiche
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 07 Feb 2026 02:00:13 GMT
ββββββββββββββββββββββββ
β Tags: #web_security #ethical_hacking #hacking #cybersecurity #bug_bounty
5 783
Repost from Daily Writeups
β€· Title: OpenClaw and NetSec for the Uninitiated
ββββββββββββββββββββββββ
πͺ Author: Jade Seeker
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 06 Feb 2026 23:43:04 GMT
ββββββββββββββββββββββββ
β Tags: #cyber_security_awareness #ai #penetration_testing #cybersecurity #security
5 783
#tools
#Cloud_Security
1β£ Weaponizing Whitelists:
An Azure Blob Storage Mythic C2 Profile
https://specterops.io/blog/2026/01/30/weaponizing-whitelists-an-azure-blob-storage-mythic-c2-profile
]-> Azure Blob Storage C2 Profile
// The article explores how enterprise firewalls' broad Azure Blob Storage exceptions can be exploited for covert C2, introducing Mythic's "azureBlob" profile that uses container-scoped SAS tokens and blob operations for stealthy C2
2β£ Moltworker: a self-hosted personal AI agent, minus the minis
https://blog.cloudflare.com/moltworker-self-hosted-ai-agent
// Moltworker enables deploying scalable, secure AI applications on Cloudflareβs platform using Workers, Sandboxes, R2, and Browser Rendering, demonstrated through Slack integrations and open-sourced for global deployment
5 783
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events for the week (Jan.24-31, 2026)
1β£ Critical eScan Supply Chain Compromise
// Anti-virus vendor eScan was compromised, and its update servers were used to install malware on some customer systems
2β£ Fake Clawdbot VS Code Extension Installs ScreenConnect RAT
// The news about Clawdbot (now Moltbot) is used to distribute malware, in particular malicious VS Code extensions
3β£ OpenSSL Updates
// OpenSSL released its monthly updates, fixing a potential RCE
4β£ DoS Vulnerabilities in React Server Components
// Another folowup fix for the severe React vulnerability from last year, but now only fixing a DoS condition
5β£ CVE-2026-21509 - MS Office 0-Day
// Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability
6β£ StackRox 4.8.8 Kubernetes Security Platform + OpenAEV 2.0.14 Adversarial Exposure Validation Platform
// New releases have been released
7β£ GnuPG 2.5.17
// This version fixes a critical security bug in versions 2.5.13 to 2.5.16
8β£ Hacking Clawdbot and Eating Lobster Souls
// Part 2
9β£ Operation Bizarre Bazaar
// First Attributed LLMjacking Campaign with Commercial Marketplace Monetization
1β£0β£ Silent Brothers: Ollama Hosts Form Anonymous AI Network Beyond Platform Guardrails
]-> Analytical review (Jan.17-24, 2026)
5 783
#Malware_analysis
1β£ SonicWall Breach Enabled Ransomware Attack
https://www.ctrlaltnod.com/news/sonicwall-breach-enabled-ransomware-attack-on-74-us-banks
2β£ RedKitten: AI-accelerated Campaign
https://harfanglab.io/insidethelab/redkitten-ai-accelerated-campaign-targeting-iranian-protests
3β£ Pulsar RAT: When Malware Talks Back
https://www.pointwild.com/threat-intelligence/when-malware-talks-back
5 783
#MLSecOps
"Llama-3.1-FoundationAI-SecurityLLM-Reasoning-8B Technical Report", Jan 2026.
]-> Foundation-Sec-8B-Reasoning, the first open-source native reasoning model for cybersecurity
5 783
#Tech_book
#Malware_analysis
#Blue_Team_Techniques
"Phishing RunBook/PlayBook", 2025
// Phishing playbook guides SOC teams in detecting, analyzing, and responding to phishing threats.
- SOC phishing detection and response guide
- Defines roles, triage, and investigation steps
- Focuses on email, credential, and social engineering threats
- Ensures quick containment and awareness
- Promotes continuous improvement and prevention
5 783
#Research
#IoD_Security
"A Large-Scale Evaluation Suite of Security, Resilience, and Trust for LLM-based UAV Agents over 6G Networks", 2026.
]-> Repo
// Large-scale benchmark for evaluating security, resilience, and trust of LLM-based UAV agents under realistic adversarial conditions in 6G-enabled networks, featuring layered attack taxonomies and CWE-aligned evaluation
5 783
#Malware_analysis
#Threat_Research
1β£ GOGITTER, GITSHELLPAD, and GOSHELL Analysis
https://www.zscaler.com/blogs/security-research/apt-attacks-target-indian-government-using-gogitter-gitshellpad-and-goshell
2β£ Blackmoon malware + SyncFuture TSM tool
https://www.esentire.com/blog/weaponized-in-china-deployed-in-india-the-syncfuture-espionage-targeted-campaign
3β£ Inside a Multi-Stage Windows Malware Campaign
https://www.fortinet.com/blog/threat-research/inside-a-multi-stage-windows-malware-campaign
4β£ MacSync Stealer Returns:
SEO Poisoning and Fake GitHub Repositories
https://daylight.ai/blog/macsync-stealer-returns-seo-poisoning
5β£ PURELOGS Infostealer Analysis
https://www.swisspost-cybersecurity.ch/news/purelogs-infostealer-analysis-dont-judge-a-png-by-its-header
5 783
#Analytics
#Research
"Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies", Jan 2026.
// We define frontier AI auditing as rigorous third-party verification of frontier AI developers' safety and security claims, and evaluation of their systems and practices against relevant standards, based on deep, secure access to non-public information
5 783
#Analytics
#Threat_Research
An analytical review of the main cybersecurity events for the week (Jan.17-24, 2026)
1β£ CVE-2026-24061: Telnetd RCE as Root
// This script exploits the CVE-2026-24061 vulnerability in Telnet servers using a malformed USER environment variable
2β£ Top Agentic AI Security Threats in 2026
// The agentic AI era has arrived. The question is not whether your organization will face agentic threats in 2026. The question is whether you will be ready
3β£ ISC BIND DoS vulnerability in Drone ID Records
// CVE-2025-13878
4β£ Pwn2Own Automotive 2026
// Day One Two Three Results
5β£ Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts
// The vulnerabilities allow for unauth bypass of SSO login authentication via crafted SAML messages when the FortiCloud SSO feature is enabled on affected Devices
6β£ SmarterTools SmarterMail WT-2026-0001 Auth Bypass
// This issue was patched in ver.9511, released on Jan 15, 2026. If you have not already upgraded, do so immediately. This vulnerability is already being actively exploited!
7β£ Wireshark 4.6.3 and 4.4.13 Released
// Release notes + download page
8β£ Bandit v.1.9.3
// Tool to find common security issues in Python code
]-> Analytical review (Jan.10-17, 2026)
5 783
#MLSecOps
#Offensive_security
"Reasoning Hijacking: Subverting LLM Classification via Decision-Criteria Injection", 2026.
]-> Criteria Attack Dataset
// Current LLM safety research predominantly focuses on mitigating Goal Hijacking, preventing attackers from redirecting a model's high-level objective. In this paper, we argue that this perspective is incomplete and highlight a critical vulnerability in Reasoning Alignment. We propose a new adversarial paradigm: Reasoning Hijacking and instantiate it with Criteria Attack, which subverts model judgments by injecting spurious decision criteria without altering the high-level task goal
5 783
#AIOps
#MLSecOps
#Threat_Research
"Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale", 2026.
// The rise of AI agent frameworks has introduced agent skills, modular packages containing instructions and executable code that dynamically extend agent capabilities. While this architecture enables powerful customization, skills execute with implicit trust and minimal vetting, creating a significant yet uncharacterized attack surface
Endi mavjud! Telegram Tadqiqoti 2025 β yilning asosiy insaytlari 
