DefectDojo โ€“ Setup, Workflow and Real Usage

I was looking for something to keep findings, scan results, and reports in one place instead of dumping everything into a notebook. For pure bug bounty work, I still think a normal notes app such as O

0ut3r Space
OAuth account takeover doesn't need leaked tokens. No state param = CSRF to forced account linking. Loose redirect_uri matching = code theft via open redirect chains. Implicit flow puts tokens in browser history and Referer headers. PKCE bypass when not enforced server-side. SSRF via OpenID dynamic client registration. Six patterns, all with labs. https://www.kayssel.com/newsletter/issue-43/ #OAuth #BugBounty #Pentesting #websecurity #Offsec #InfoSec
OAuth 2.0: Six Ways the Authorization Flow Breaks

Missing state CSRF, redirect_uri hijacking, open redirect code theft, implicit flow token leakage, PKCE bypass, and SSRF via OpenID dynamic client registration

Kayssel

Kali Linux 2026.1 is out โ€” the first release of the year.

What's new:
- 2026 theme refresh โ€” boot, installer, login, wallpapers
- BackTrack mode in kali-undercover (BackTrack turns 20!)
- 8 new tools: AdaptixC2, MetasploitMCP, XSStrike, WPProbe, GEF & more
- Kernel bumped to 6.18
- NetHunter fixes + QCACLD-3.0 injection patch

โš ๏ธ SDR tools (GNU Radio ecosystem) are broken this release.

https://www.opensourcefeed.org/kali-linux-2026-1-release/

#KaliLinux #Linux #FOSS #PenTesting #NetHunter

If you are interested in hacking, privacy, or the real-world events shaping todayโ€™s connected systems, these cybersecurity documentaries are worth watching ๐Ÿ˜Ž๐Ÿ‘‡

Find high-res pdf ebooks with all my cybersecurity related infographics at https://study-notes.org

#cybersecurity #hacking #infosec #ethicalhacker #pentesting

Build Resilient Systems with Zero Trust Architecture

Seasia helps organisations implement zero trust architecture with robust penetration testing services to eliminate security gaps. Enhance your Zero Trust security posture and protect critical systems with continuous validation and monitoring.
๐Ÿ”— https://www.seasiainfotech.com/penetration-testing-services

#ZeroTrust #CyberDefense #PenTesting #CloudSecurity #SecurityArchitecture #DigitalSecurity

From pentesting tips to cloud defense, todayโ€™s curated cyber playlist has it all. ๐ŸŽฅ https://www.youtube.com/playlist?list=PLXqx05yil_mdK9Q5RBtPutDXfADoEJHhC
#PenTesting #AppSec #CyberSecurity #ThreatIntelligence #IncidentResponse
260326 rootshell.online

YouTube

Da werde ich wohl ein Update durchfรผhren ๐Ÿ˜œ

#KaliLinux 2026.1 bringt neue Tools mit und erstrahlt in neuer oder Retro-Optik | Security https://www.heise.de/news/Kali-Linux-2026-1-bringt-neue-Tools-mit-und-erstrahlt-in-neuer-oder-Retro-Optik-11223739.html #Linux  #PenTest #PenTesting #PenetrationTesting

Kali Linux 2026.1 bringt neue Tools mit und erstrahlt in neuer oder Retro-Optik

Die Linux-Distribution fรผr Sicherheitsforscher Kali Linux 2026.1 ist erschienen. Sie bringt neue Tools mit und zollt Tribut fรผr den Vorgรคnger BackTrack Linux.

heise online

RE: https://chaos.social/@alexglow/116290732583697250

Going #live with @alexglow in about two hours! In #DayGlow Episode 9, we will be #hacking on Pocket #PenTesting Platforms, including the #DevKitty #CutieCat, the #FlipperZero, the #M5Stack #Cardputer, and the #LILYGO T-embed. Alex Lynd from DevKitty will also be giving away a free CutieCat to one lucky winner! Join the chaos at 3pm Eastern! ๐Ÿค˜๐Ÿฌ๐Ÿค˜

https://www.youtube.com/watch?v=M9a5mjuKl4c

#DayGlowShow #MakersOfMastodon #HackThePlanet

๐—”๐˜„๐—ฒ๐˜€๐—ผ๐—บ๐—ฒ ๐—น๐—ถ๐˜€๐˜ ๐—ณ๐—ผ๐—ฟ ๐—›๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—ง๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด. Training your hacking skills safely and legally.

Repo: https://github.com/Smithech/awesome-hacking-training

Open to contributions ๐Ÿค

#hacking #pentesting #awesome

Kali Linux 2026.1 released

Kali Linux has been released in version 2026.1. The summary of the changelog since the 2025.

SecBurg - InfoSec Blog