Sabitlenmiş Tweet
oxflask
227 posts


الحمدلله بهذي الايام الفضيلة ،
تم تسجيل ثاني CVE لي
CVE-2026-42558
Attack Chain مكون من اربع ثغرات
في نظام Xibo CMS
Full writeup:
@0xrixet/how-i-found-an-attack-chain-and-got-cve-2026-42558-485e716605da" target="_blank" rel="nofollow noopener">medium.com/@0xrixet/how-i…
شرحت الهجوم كامل بالرايت اب وكيف قدرت اهرب من الساند بوكس المعزول واسرق بيانات الادمن
قراءة ممتعه 🙏🏻
العربية

Update Unifi OS guys 🚨 CVE-2026-34909
This one is special.
I received my highest bounty so far: $30,500 for a Critical CVSS 10.0 vulnerability in UniFi OS Servers.
الثغرة حرجة ,الـ write-up راح ننزله قريبًا على @CatchifySA
بإذن الله 🔥
Advisory: community.ui.com/releases/Secur…


الحمد لله، كانت حصيلة الشهر الماضي مليئة بالتحديات والإنجازات
• ثغرة بمستوى خطورة عالي (High).
• ثغرة بمستوى متوسط (Medium).
• ثغرة بمستوى منخفض (Low)
• (Informational)
فخور بالمساهمة في تعزيز الأمن الرقمي، والقادم أفضل بإذن الله
#BugBounty

العربية
oxflask retweetledi

Today, May 1st 2026, I received confirmation from @hackthebox_eu that I've successfully passed the HTB Certified Web Exploitation Expert (CWEE) exam with a perfect score of 100/100.
As a bug bounty hunter, the web exploitation skills were already there. What this path really added was depth in whitebox testing, source code review, and application debugging.
Capturing all the flags is not enough to pass. You need to invest real effort into the report. I wrote mine as if it was being delivered to a real client, every vulnerability detailed with clear description, impact, reproduction steps, evidence, and actionable remediation.
#CWEE #HackTheBox #HTB

English


Quick Shots In One Day at @Hacker0x01 (:"
Privilege Escalation :
1 . After removing the user, I found that the JWT can still be used for up to 2 days after the user has been revoked
2 . Unprotected .JSON Endpoint allowed me to Access Earning History and Pending payments



English














