- Hive Five
- Posts
- π Hive Five 209 - New Space
π Hive Five 209 - New Space
How to Escalate XSS, Ghostty 1.1.0, Elevenlabs Scraps Job Titles, Obsidian Dynamic Tables and Collaborative Editing, World's First MIDI Shellcode, Optimize your WFH lighting.
Hi friends,
Greetings from the hive!
I'm changing up my AI tools, I swapped my Claude Pro subscription for Raycast AI.
Now, my AI assistant is only two keybindings away, instead of the 6+ actions it required before.
Also, the $11 ($20 - $9) in savings can now be spend on API credits.
In other news, I'm still enjoying Zen browser as my daily driver. I haven't mastered it yet, but looking forward in doing so.
Let's take this week by swarm!
π The Bee's Knees
AI supercharges bug bounty hunting by automating tedious tasks, allowing hunters to focus on strategy and creativity. Transform your game by unlocking new levels of vulnerability discovery and exploit generation. MORE
Learn how specially crafted artifacts can be used to attack Maven repository managers. This post describes PoC exploits that can lead to pre-auth remote code execution and poisoning of the local artifacts in Sonatype Nexus and JFrog Artifactory. MORE
Get FortiRekt, I Am The Super_Admin Now - Fortinet FortiOS Authentication Bypass CVE-2024-55591. MORE
3 ways to escalate your XSS bugs to the next level, using reflected XSS and self XSS. MORE
In 1958, NASA was founded, and just 11 years later, we put man on the moon. But progress stagnated until private ambition met government funding, ushering in the "New Space" era of innovation and exploration. MORE
Brought to you by β
Hack in Style
Gear up with unique hacker-inspired apparel.
Discover the Hive Five Shop, where tech meets style! Our curated collection features everything from quirky tees to stylish caps, designed for those who think outside the box.
Whether you're coding late at night or just want to express your hacker mindset, we have the perfect gear for you.
Plus, refer a friend to our newsletter and get 20% off your next purchase. Donβt miss out on this chance to elevate your wardrobe!
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Table of Contents
π° Updates
β Changelog
Ghostty 1.1.0 brings crucial bug fixes and quality-of-life improvements based on user feedback - a month's work across multiple contributors. Exciting updates streamline the experience for this powerful open-source tool. MORE
Waymore v4.9 fixes include resolving an error with external JavaScript files and ensuring status code filters handle 404 responses correctly. MORE
Obsidian is working on dynamic tables and collaborative editing. Get ready for a game-changing leap in productivity and teamwork. MORE
πΌ Work
π° Career
Elevenlabs boldly reshapes its org structure, abandoning traditional job titles. Now, teams like Operations and Go-to-Market define the work, empowering employees to collaborate and innovate beyond rigid roles. MORE
Learn how to craft the perfect resume to land your dream tech job. This video covers the 5 biggest mistakes to avoid and insider tips to tailor your resume for better results. MORE
Blueprint (Don't Die) is hiring a Director of Digital Product amongst other roles to join their team. MORE
The Art of Calling Out Room Dynamics. Discover how naming what's happening in the room can defuse tense meetings, improve team dynamics, and elevate your leadership skills. MORE
π Productivity
Theo's made a video about his move from Arc to Zen Browser. MORE
Smart Composer, an Obsidian plugin, streamlines your writing process by seamlessly incorporating your vault's content, eliminating the need for excessive context-setting in AI conversations. MORE
Homebrew's top priority is improving performance, and you can get quicker results by disabling auto-updates and upgrades, though at the cost of reliability and security. MORE
Productivity hack that boosts you from the bottom 10% to the top 10% overnight. Write down every decision on paper. MORE
CleanMyMac appears to be a game-changer. Effortlessly reclaims system/browser caches without tedious detective work. MORE
π Community
π Celebrate
With grit and determination, SinSinology overcame long hours, sacrifices, and challenges to get 1st place at the prestigious Pwn2Own 2025. MORE
4 NahamSec Discord members earned $30k through Netflix's bug bounty in just January, from live collaborative bug hunting sessions! MORE
Searchlight Cyber acquires Assetnote to enhance continuous threat exposure management. MORE
β‘οΈ Timeline
π Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
β’ @adrien_jeanneau | Hisxo | @yeswehack (aka Hisxo) - I love to break things (and I'm paid for that) - Bug Hunter.
β’ @jstnkndy | Justin Kennedy | Infosec professional & beverage snob. Vice President of Research Consulting @ Atredis Partners. Forever terrified of Kithicor.
β’ @albinowax | James Kettle | Director of Research at PortSwigger aka Burp Suite.
β’ @rootxharsh | Harsh Jaiswal | Research at @httpvoid0x2f @pdiscoveryio.
β’ @ustayready | Mike Felch (Stay Ready) | Red Teamer / Security Research | Prior: CrowdStrike / Current: BHIS | In Christβs grip | Pentesting since 1997 | Security Focus: Cloud.

π Level up
π° Read
RyotaK, security engineer at GMO Flatt Security, uncovered a GitHub bug that allows you to steal Git credentials. MORE
During x3ctf, Jorian discovered an unintended solution. It allows you to detect the result of a selector during CSS Injection, bypassing any CSP restricting external requests. MORE
How Google estimates the risk from prompt injection attacks on AI systems. MORE
Bypassing character blocklists with unicode overflows. MORE
Worldβs First MIDI Shellcode. Porta gained remote code execution via MIDI messages to trick the synth into playing Bad Apple on its LCD. MORE
π‘ Tips
Hate wasting time with 2FA? Install this CLI tool, configure it with your sites, then use Espanso to auto-fill OTPs with a simple :otp command - instant 2FA access without hassle! MORE
How to generate brown noise using Python, a solution that could help other sleep-deprived parents. MORE
Optimize your WFH lighting to reduce eye strain and improve productivity with simple, science-backed tips. Achieve a comfortable, glare-free workspace that energizes your workday. MORE
To effectively provide context for coding projects using LLMs, create a catall alias in your zshrc that concatenates all files in a directory with their filenames. Then, copy the output, check the token count, and use AI Studio for projects exceeding 150k tokens or Claude for those under that limit. MORE
Tons of actionable and practical SEO tips. Packed with proven tactics to boost your online visibility and drive insane traffic. MORE
π§ Wisdom
Professional translator Tom Gally shares a detailed workflow for using LLMs to streamline the translation process, offering a game-changing approach for linguistic experts. MORE
Insightful tips from 9 expert writers to help you overcome writer's block and write with power. MORE
Hackers share what keeps them going when they're struggling to find much success. MORE
π Resources
A collection of Turbo Intruder scripts, specifically ones which emulate the 4 main attack types in Burp Intruder (Sniper, Battering ram, Pitchfork, and Cluster bomb). MORE
Sub.rehab helps you find alternative platforms for Reddit communities restricted due to ongoing API protests, making it easier to connect with your favorite online spaces. MORE
The State of the Cybersecurity Market in 2024. An in-depth look at the cybersecurity market in 2024, focusing on AI's role, funding shifts, and investment trends shaping the industry. MORE
Aspiring developer takes on a thrilling challenge, building a NES emulator in Go to showcase their skills and prepare for an exciting summer internship at miHoYo. MORE
How-To: Linux Process Injection. Ever wondered how to inject code into a process on Linux? MORE
π Explore
Get $200 to try DigitalOcean β the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
π§° Tools
Tool for searching exploits from several exploit databases. Exploits are inserted at sqlite database(go-exploitdb) can be searched by command line interface. MORE
HExHTTP is a tool designed to perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors. MORE
Fast virtual host scanner that finds hidden vhosts and identifies which ones are only accessible through Host header manipulation. MORE
Virtual host scanner that combines subfinder, dnsx, httpx, and VhostFinder to discover and validate virtual hosts, with automatic path scanning for sensitive endpoints. MORE
π₯ Watch
Uncover a treasure trove of 11 free, no-code OSINT tools to level up your investigative skills. Dive into open-source intelligence without a single line of code. MORE
Discover the fascinating journey of Valerio Brussani, a seasoned penetration tester and Cobalt Core member, as he shares his path from software development to bug bounty success. MORE
Alethe Denis takes audiences on a journey of Epic Fails and Heist Tales: Red Teaming Toward Truly Tested Security. MORE
PMing with o1 pro, v0, and DeepSeek-R1. MORE
cRay Fernando, a former Apple engineer, gives an in-depth tutorial on DeepSeek AI and its local implementation. MORE
π΅ Listen
Basic marketing still outperforms everything: a simple 90-minute webinar turns 200 attendees into 20 buyers, even with just 2,500 subscribers. The framework is dead simple: 20 minutes on your story, 15 minutes on the solution, 20 minutes showing the transformation. MORE
Stanford professor Jeffrey Pfeffer shares powerful insights on building influence and accelerating your career β a must-listen for anyone seeking to maximize their impact. MORE
Wrote this newsletter listening to Baby J on the ones and twos. MORE
Justin and Joseph bring on Aaron Costello to discuss SaaS security and misconfigurations as a bug class. He also gives some in-depth examples from Salesforce, ServiceNow, and Power Pages. MORE
π Technology
Beehiiv's 2025 State of Email Newsletters reveals the latest data and industry trends to help you maximize your email strategy in the years ahead. MORE
DeepSeek FAQ. DeepSeek has completely upended peopleβs expectations for AI and competition with China. What is it, and why does it matter? MORE
Why hardcoding feature flags is a smart, cost-effective approach β database lookups on small tables are practically free, and caching data can boost performance. MORE
If you still remember when Sublime Text launched you were probably one of its users. It was an innovative code editor at the time, and still used by some in 2025. MORE
Programmatic handling of CORS-configuration errors with jub0bs/cors. MORE
π Interesting
I discovered this platform through Pieter Levels, who now manages all his knowledge bases and feature requests here.
As an experience engineer, I can confidently say that these two core flywheels are the foundation of a modern self-service customer experience and support system.
In the case of feature requests, closing the loop is the most important.
The Good Day Fort Collins newsletter seems like a standard local news roundup, but it's actually part of a network of AI-generated newsletters targeting small-town America with hidden political agendas. MORE
Seattle Safe Eats is a svelte-kit project that was designed to easily navigate food safety rating inspections for King County. MORE
Anthropic has an AI Policy for Application: "While we encourage people to use AI systems during their role to help them work faster and more effectively, please do not use AI assistants during the application process. [...]"
π Quote
"My delusion got me out of the hood, so at this point using logic is absurd."
Until next week, take care of yourself and each other,
Bee π
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.
π Learned something?
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five β
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee π
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.