g3n3r4l9
-
Disclosed ․ Online (reddit.com)
Directory that aggregates bug-bounty researcher profiles from HackerOne, Bugcrowd, GitHub, and more. (reddit.com)
-
Have I Been Squatted? (haveibeensquatted.com)
Fast typosquatting-discovery tool that maps look-alike domains and offers defence guidance. (haveibeensquatted.com)
-
On the 10th Anniversary of the Snowden Revelations (electrospaces.net)
Updated retrospective on key NSA leaks and their continuing impact (updated 7 Apr 2025). (electrospaces.net)
-
Incident Response in AWS: Scoping Strategies (medium.com)
Fresh Medium post (6 days ago) showing how to pivot on CloudTrail artefacts for rapid scoping. (medium.com)
-
Covert Web-to-App Tracking via Localhost on Android (localmess.github.io)
Research revealing Meta & Yandex apps quietly listening on fixed local ports for tracking. (localmess.github.io)
-
Roundcube ≤ 1.6.10 Post-Auth RCE (CVE-2025-49113) (fearsoff.org)
Deep dive into a PHP deserialization flaw that yields full remote code-execution. (fearsoff.org)
-
Analyzing IPv4 Trades with gnuplot (ipv4a-5539ad.gitlab.io)
Demo project exploring IPv4 supply-and-demand trends during the IPv6 transition. (ipv4a-5539ad.gitlab.io)
-
The Ultimate Guide to JWT Vulnerabilities & Attacks (pentesterlab.com)
Hands-on PentesterLab guide to exploiting and defending JWT flaws. (pentesterlab.com)
-
AI bugSWAT in Tokyo & 2025 Hacker Roadshow (bughunters.google.com)
Google Bug Hunters’ inside look at their live AI hacking event and top findings. (x.com)
X1
-
James Woolley shares what attackers did when handed an exposed VNC box. (x.com)
y0utube1
-
Practical OPSEC tips for reporters working in hostile environments. (youtube.com)
g1thub2
-
frida-script-gen (github.com)
CLI that scans Android APKs for root/SSL-pinning checks and auto-generates Frida bypass hooks. (github.com)
-
assetnote/surf (github.com)
Go tool that filters massive host lists to surface cloud-based SSRF candidates for escalation. (github.com)