Open to everyone · No gatekeeping

Security Community

Share knowledge — post CVE discussions, tool reviews, career advice, and anything cyber.

Join the community to share your knowledge

Sign in to post security news, CVE discussions, tool reviews, and more.

Sign in to post
?

Anonymous

2 hours ago

CVE Discussion

Log4Shell is still being exploited in 2024 — honeypot data

Saw three attempts on our honeypot today targeting Log4j. Make sure you are patched. The payloads are getting more sophisticated — rotating JNDI endpoints and using DNS-over-HTTPS to bypass egress filters. Don't assume you're safe just because it's an old CVE.

8 comments
S

SecurityTamil

5 hours ago

Tutorial

Free resources to learn pentesting in Tamil

List of Tamil YouTube channels and resources for learning ethical hacking. Covers web app pentesting, network scanning, and bug bounty basics. Great for beginners who are more comfortable learning in Tamil. Drop your favourites in the comments!

15 comments
C

CVEBot

1 day ago

Security News

CISA added 3 new CVEs to KEV today — check if your stack is affected

Three new actively exploited vulnerabilities added. Check if your stack is affected. Two are in Cisco IOS XE and one targets a popular VPN appliance. Federal agencies have a 3-week deadline; the rest of us should treat it as urgent.

12 comments
P

PentestPro

2 days ago

Tool Review

Honest review: Burp Suite Pro vs OWASP ZAP in 2024

Been using both for 6 months on real engagements. Burp Suite Pro wins for manual testing workflow and extensions ecosystem, but ZAP has caught up significantly for automated scanning. If you're on a budget, ZAP is genuinely viable now. Full comparison in comments.

23 comments
H

HireRight_Sec

3 days ago

Career Advice

How to negotiate your first SOC analyst salary in India

Tier-1 SOC roles in India range from ₹4–8 LPA but vary wildly by company. Certifications like CompTIA Security+ and CEH help justify the upper end. Know your SIEM, know your incident response playbooks, and never accept the first offer. Here's what to say.

31 comments
B

BugHunterX

4 days ago

Tutorial

Writeup: Stored XSS via SVG upload in a major bug bounty program

Found a stored XSS by embedding a script in an SVG file and uploading it as a profile picture. The platform rendered SVG files inline without sanitization. Here's the full attack chain, the report, and the $750 bounty they paid. Learn from this pattern.

19 comments