g3n3r4l15
-
Tiny XSS Payloads (tinyxss.terjanq.me)
A curated list of tiny, minimalistic XSS payloads for testing and evasion.
-
Top CVE Trends & Expert Vulnerability Insights | cvemon (cvemon.intruder.io)
Real-time CVE trends and insights from vulnerability intelligence experts.
-
Postman is logging all your secrets and environment variables (anonymousdata.medium.com)
Postman may be exposing sensitive variables to logging systems.
-
Authentication Bypass to RCE in Versa Concerto (0-Day) (projectdiscovery.io)
Full technical breakdown of a 0-day RCE in Versa Concerto.
-
Clipjacking: Hacked by copying text (blog.jaisal.dev)
A creative attack method leveraging clipboard copy-paste behavior.
-
Stored XSS in My Flow To RCE in Opera Browser 2 (medium.com)
Exploiting stored XSS to achieve RCE in Opera's My Flow feature.
-
Finding and Exploiting 20-year-old bugs in Web Browsers (docs.google.com)
Slides covering long-lived browser vulnerabilities and exploitation strategies.
-
Have I Been Pwned 2.0 is Now Live! (troyhunt.com)
Major updates to Troy Hunt’s breach notification platform.
-
Pressing Buttons with Popups (on Twitch, LinkedIn and more) (jorianwoltjer.com)
Abuse of popups to trigger unauthorized user actions.
-
Kusto-Mice: Optimizing Kusto joins (parsiya.net)
Performance tips for better join operations in Kusto Query Language.
-
Go Cryptography Security Audit (go.dev)
Detailed report on Go language’s cryptographic libraries and audit findings.
-
The Single-Packet Shovel: Desync Tunnelling (assured.se)
Exploring HTTP request desync for covert tunneling techniques.
-
Integrating secure design principles with modern cloud-native tools.
-
Don’t Call That “Protected” Method: vBulletin RCE (karmainsecurity.com)
How a logic flaw in vBulletin led to full RCE.
-
Reverse Engineering iOS Shortcuts Deeplinks (blog.alexbeals.com)
Analysis of iOS Shortcuts deep linking for exploitation or automation.
X2
-
The Fake Ledger That Stole Everything | IOC (@intell_on_chain)
A gripping thread on a fake hardware wallet that led to total crypto loss.
-
OffensiveCon25 videos now up! (@offensive_con)
Full archive of OffensiveCon 2025 talks now available.
y0utube1
-
Entertaining and educational talk on exploiting cloud document features.
g1thub7
-
urbanadventurer/urlcrazy (github.com)
Tool for generating typo variants of domain names to detect phishing.
-
c1phy/sqltimer (github.com)
A lightweight and fast scanner for time-based SQL injection detection.
-
NightBloodz/CVE-2025-4123 (github.com)
PoC for XSS and SSRF leading to data exfiltration in Grafana.
-
kapellos/LNKSmuggler (github.com)
Tool to embed data in .lnk files and wrap them into ZIPs for evasion.
-
curated-intel/Attribution-to-IP (github.com)
Collection of methods for IP ownership and attribution analysis.
-
sw33tLie/uff (github.com)
A supercharged version of ffuf for fuzzing web directories and APIs.
-
cybrly/badsuccessor (github.com)
An experimental project with unclear purpose – watch this one evolve.