и посмотреть медиа
Bugpoint - bug bounty отчеты
и посмотреть медиа
Канал с последними новостями о bug bounty: детали уязвимостей, impacts и bounties. Идеально для этичных хакеров и пентестеров.
Канал с последними новостями о bug bounty: детали уязвимостей, impacts и bounties. Идеально для этичных хакеров и пентестеров.
bot de IA para clonar texto a voz y voz en Telegram. Cree audio utilizando la red neuronal de forma rápida y fácil.
📣 Bugpoint собирает самые свежие обновления о раскрытых отчетах bug bounty программ. Здесь вы найдете подробные технические описания уязвимостей, их потенциальное влияние на системы и суммы выплаченных вознаграждений. Это ценный источник для специалистов по информационной безопасности, этичных хакеров и всех, кто интересуется кибербезопасностью.
🔍 Каждый пост разбирает реальные кейсы: от обнаружения багов до их фикса. Узнайте, как работают популярные bug bounty платформы, какие инструменты используют исследователи и какие награды можно получить. Канал помогает оставаться в курсе трендов в области vulnerability disclosure.
💰 От простых XSS до сложных RCE — все с примерами кода и рекомендациями. Полезно для обучения и профессионального роста в сфере bug hunting.
Unauthenticated Disclosure of Unpublished / Embargoed 🔹 Severity: Informational 🔹 Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program 🔹 Reported By: 0xPewPew 🔹 State: 🟢 Resolved 🔹 Disclosed: August 27, 2026 🐞 Source: Bugcrowd 👉 Read full report
Открыть канал и посмотреть медиаUnbound cross-peer HTTP Digest challenge state 🔹 Severity: Medium 🔹 Reported To: curl 🔹 Reported By: giant_anteater 🔹 State: ⚪️ Informative 🔹 Disclosed: August 27, 2026, 8:21am (UTC) 🐞 Source: HackerOne 👉 Read full report
Открыть канал и посмотреть медиаARG_CLEAR credential scrubbing wipes only UTF-8 copies on Windows Unicode builds 🔹 Severity: Low 🔹 Weakness: Information Disclosure 🔹 Reported To: curl 🔹 Reported By: giant_anteater 🔹 State: 🔴 N/A 🔹 Disclosed: August 27, 2026, 8:21am (UTC) 🐞 Source: HackerOne 👉 Read full report
Открыть канал и посмотреть медиаAdding phone number to profile By OTP brute forcing 🔹 Severity: Medium | 💰 100 USD 🔹 Weakness: Insecure Storage of Sensitive Information 🔹 Reported To: CoinMate.io 🔹 Reported By: ganesh_reddy 🔹 State: 🟢 Resolved 🔹 Disclosed: August 8, 2026, 9:11am (UTC) 🐞 Source: HackerOne A vulnerability was found that allowed an attacker to add any phone number to a user's profile by brute-forcing the one-time password (OTP) used for phone number verification. The steps involved intercepting the OTP verification request, using a brute-force attack to find the valid OTP, and then replaying the original request with the discovered OTP to complete the phone number addition. 👉 Read full report
Открыть канал и посмотреть медиаURL API: triple-slash parses path segment as hostname 🔹 Severity: Medium 🔹 Weakness: Use of Incorrectly-Resolved Name or Reference 🔹 Reported To: curl 🔹 Reported By: thinhlx 🔹 State: 🔴 N/A 🔹 Disclosed: August 7, 2026, 8:49pm (UTC) 🐞 Source: HackerOne 👉 Read full report
Открыть канал и посмотреть медиаSolo los usuarios registrados pueden compartir su opinión.
¡Sé el primero en compartir tu experiencia con este recurso!
Aviso de planes VPS de restock y ofertas especiales.☁️🔔
Un mundo de aplicaciones exclusivas, Giveaway, noticias de tecnología.
Señales de bomba enBinanceandKucoin. Bombas de gran escala sin preventa para 2x-10x beneficios.