Security Researches, Exploit, New Updates & more
Hey friends! Nitin here, and today we’re finding our FIRST real bug 🎉
Background
Subdomain Takeover is often described as one of the easiest vulnerabilities to find in Bug Bounty programs. Even today, hunters continue to…
An introduction to prompt injection!
Cybercriminals use malware to steal data, disrupt operations, and gain unauthorized access to systems. To effectively defend against these…
If you’re brand new to AI-assisted bug bounty and every guide you’ve opened assumes you already know what “MCP” or “skills” or “agentic”…
Most university students will never know if a cybercriminal briefly had access to their records. That’s what makes incidents like the…
A recent research paper, “AI Agents Enable Adaptive Computer Worms”, offers a fascinating and somewhat unsettling glimpse into how…
Learn how to recover complete access to a self-hosted n8n Docker deployment when password reset emails fail.
Damn Vulnerable Web Application
Technical skills alone will not save you. Here is the exact mindset that separates elite security professionals from automated tool…
Building a simple attack lab to understand how Fail2Ban detects and blocks repeated SSH login attempts.
Request headers are not metadata. They are inputs, and inputs can be manipulated.
Top 10 Leadership and Management links of the week, curated by Corix Partners Founder and CEO JC Gaillard, focusing on cyber security of…
Learn how AI agents work, the risks of indirect prompt injection, and the best security practices for 2026.
A real-world case study on WAF evasion techniques and stored cross-site scripting vulnerabilities
Not everything broken is a vulnerability. Here’s how to know the difference.
And the Patterns That Prevent Them
What is DNS over HTTPS (DoH)? Every time you type a website address (like medium.com) into your browser, your computer uses a Domain Name…
Subscribe to my self hosted blog to get future posts that may not appear on medium anymore: