nextjs.pdf vulnerabilities check list
Mind the Web: The Security of Web Use Agents
How I Found the Worst ASP.NET Vulnerability — A $10K Bug (CVE-2025-55315)
Introduction Earlier this year, I earned a $10,000 bounty from Microsoft after discovering a critical HTTP request smuggling vulnerability in ASP.NET Core’s Kestrel server (CVE-2025-55315). The vulnerability garnered significant media attention after Microsoft assigned it a CVSS score of 9.9, the highest severity rating ever assigned to an ASP.NET Core vulnerability. This post walks through […]
Flutter SSL Bypass: How to Intercept HTTPS Traffic When all other Frida Scripts Fail
Flutter SSL Bypass: How to Intercept HTTPS Traffic When all other Frida Scripts Fail بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيم Hello Folks In this article, I’ll …
GitHub - sbaresearch/whatsapp-census
Contribute to sbaresearch/whatsapp-census development by creating an account on GitHub.
Unicode surrogates conversion to (simplified) replacement characters
A case for question-mark smuggle: using Unicode surrogates to bypass input validation with replacement character fallback.
JS for Bug Bounties 2.0 Extreme Edition 2024
JS for Bug Bounties 2.0 Extreme Edition 2024 Hi everyone, I am Aditya Shende aka Kongsec from India. A Bounty Hunter , Biker , Researcher and Trainer . As I am training people in Bug Bounty from last …
Pentesting Firebase
Pentesting Firebase Rəqəmsal oğrulara salam olsun. Pentest üçün mobile app göndərirlər, atırsan JADX ilə statik olaraq analiz etməyə. Şesi nəsə tapmaq üçün “secret_key” …
OWA Pentest Guide
⚠ Важно: Все материалы предоставлены исключительно в образовательных целях.
Common OAuth Vulnerabilities · Doyensec's Blog
Common OAuth Vulnerabilities
Account hijacking using "dirty dancing" in sign-in OAuth-flows - Labs Detectify
Combining response-type switching, invalid state and redirect-uri quirks using OAuth, with third-party javascript-inclusions has multiple vulnerable scenarios where authorization codes or tokens could leak to an attacker. This could be used in attacks for single-click account takeovers. Frans Rosén, Security Advisor at Detectify goes through three different scenarios found in the wild below.
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
!exploitable Episode Two - Enter the Matrix · Doyensec's Blog
!exploitable Episode Two - Enter the Matrix
Scream at It Until It Escalates — XSS to ATO via Server Size Errors Gadgets
Jewelbug: Chinese APT Group Widens Reach to Russia
Russian IT company among group’s latest targets. Attackers may have been attempting to target company’s customers in Russia with software supply chain attack.
Notable email phishing techniques in 2025 | Securelist
Common email phishing tactics in 2025 include PDF attachments with QR codes, password-protected PDF documents, calendar phishing, and advanced websites that validate email addresses.
Mem3nt0 mori – The Hacking Team is back!
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
Ukrainian organizations still heavily targeted by Russian attacks
Attackers are gaining access using a custom, Sandworm-linked webshell and are making heavy use of Living-off-the-Land tactics to maintain persistent access.
Prompt injection to RCE in AI agents
We bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms.
RCE in "json" mode of JsonPlusSerializer
# Summary
Prior to `langgraph-checkpoint` version `3.0` , LangGraph’s `JsonPlusSerializer` (used as the default serialization protocol for all checkpointing) contains a remote code execution (RC...
How to test NextJS applications
Learn how to assess Next.js apps for SSRF, XSS, CSTI, SSTI, CSRF, cache issues, and data leaks. Practical tips, checks, and tools for bug bounty and pentesting.
Klazify - Additional Documentation.
Secrets Ninja
GUI tool for testing API keys and secrets for bug bounty hunting.
Tor anonymity
Google Cloud Account Takeover via URL Parsing Confusion
Google Cloud Account Takeover via URL Parsing Confusion TL;DR This article walks through a unique OAuth account takeover vulnerability I had recently discovered affecting several Google services. It …
The War Against Spam: A report from the front line.pdf
“EchoSpoofing” — A Massive Phishing Campaign Exploiting Proofpoint’s Email Protection to Dispatch Millions of Perfectly Spoofed Emails
Cache smuggling: When a picture isn’t a thousand words
We recently observed an innovative campaign using the ClickFix attack tactic for cache smuggling. Here's what you need to know.
Tabshell Microsoft exchange
Tabshell
Confucius Espionage: From Stealer to Backdoor | FortiGuard Labs
FortiGuard Labs has uncovered a shift in the tactics of threat actor Confucius, from stealers to Python backdoors, highlighting advanced techniques used in South Asian cyber espionage. Read more.…
