Security Breached_
Bug bounty POCs, ethical hacking writeups and cybersecurity tutorials.
Purple Teaming: What Not to Do in OT & IoT Testing to Avoid Halting the Factory or Sinking the Oil Rig
Testing operational and IoT systems is no easy feat, especially when the stakes involve halting a factory or sinking an oil rig. Every one of us who has embarked on the journey to …
From Staging to Full Admin Control In Prod: A Breakdown of Critical Authentication Flaws
In this blog, I explore a real-world case of an Admin Panel Takeover caused by broken authentication and insecure configurations. By exploiting a misconfigured JWT token from a sta…
AI Hijack: How I Took Control of an AI Assistant
A simple API key leak led to the complete takeover of an AI assistant in production. Allowing to change AI's Instructions.
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…
Bug Bounty Blueprint: A Beginner's Guide
This guide is for beginners to dive into Bug Bounty Hunting. It provides foundational skills, tips, tools, and resources for Bug Bounty Hunters.
How I Manipulated My Rank on the Bugcrowd Platform
In recent years, Bug Bounties have gained significant popularity as a growing number of companies rely on crowdsourcing platforms to identify vulnerabilities within their systems. …
Hacking 100k+ Loyalty Programs for Fun and Profit!
This blog post is about how a hacker could have Hacked 100k+ Loyalty Programs to get free points & redeem them for free stuff or coupons.
Hacking Subscription Plans for free service.
The blog post describes how I was able to bypass subscription plans to get access to paid services for free.






