Hi friends,
Greetings from the hive!
So, I got sick two times in a row, all in the last two weeks. Luckily, a doctor's visit, medicine, and much rest got me back on my feet.
Now, I’m still recovering, but the difference is night and day.
For the future, I want to work towards getting sick less and reduce the duration of when I do. If you have any tips, let me know!
Let's take this week by swarm:
🐝 The Bee's Knees
How and why TrustedSec’s Targeted Operations team uses Obsidian for their knowledge management strategy. An in-depth look into their vault, setup, and workflow. MORE
Strategies to combat the allure of the endless project and cultivate the art of finishing - each completed work, no matter how small, is a step towards becoming someone who not only starts with enthusiasm, but finishes with satisfaction. MORE
Jack Dorsey created Twitter and Square. This is his talk from Startup School 2013, sharing books, a song, and a note-taking method that’s crucial for his success. MORE | TRANSCRIPT
LiveOverflow gave a talk on Android hacking at the University of Nevada, Las Vegas during DEF CON and Black Hat. During which he shares a "trick" to get into Android hacking and reverse engineering, which can be adapted to other topics. MORE
Andrej Karpathy, a founding member of OpenAI and former Tesla Autopilot leader, discusses the evolution of self-driving cars, Tesla’s Optimus humanoid robot, the bottlenecks of AI development today, and more. MORE
Upgrade Yourself →
You're getting the free version. Members get more — including exclusive & bonus content, access to an online community of smart and driven hackers, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Do you have a product or service to promote? Find out more about advertising in Hive Five.
Table of Contents
📰 Updates
🍯 My work
Check out the newly launched Hive Five shop. Also, let me know if you have any design ideas.
✅ Changelog
LazyGit v0.44.0 is a simple terminal UI for git commands. Changes include: Per-repo config files and Easily view diff across a range of commits. MORE
Dalfox is a powerful open-source tool for automating XSS (Cross-Site Scripting) scanning and utilities. This release, v2.9.3, includes numerous improvements and version bumps. MORE
Param Miner 1.5 updates library to let users disable cache-busters during attacks. MORE
OffSec announced an update to the OSCP exam and introduced a new certification called the OSCP+, which has confused many. Tib3rius discusses the announcement and changes to the exam. MORE
SpaceX plans to launch uncrewed Starships to Mars in 2 years to test landing reliability, and if successful, will send the first crewed flights in 4 years. MORE
💼 Work
💰 Career
The Lean Canvas, a business model design tool by Ash Maurya, is now available for use in the Obsidian app. This ready-to-use template allows entrepreneurs to quickly map out their business ideas and strategies. MORE
🚀 Productivity
How to Supercharge Your Writing With AI Tools. an expert workshop on how they use ChatGPT, Claude, AI-powered word processor Lex, and the prompt builder that they launched, Spiral. MORE
The "Do it now!" mantra can instill a sense of urgency, motivating one to tackle tasks immediately instead of procrastinating. This approach may enhance productivity and prevent tasks from being put off indefinitely. MORE
Actionable steps to stop procrastinating. Symptoms include reading but not taking action, endless research, and perfecting your business plan. MORE
A morning routine that has made Sahil millions and will turn mornings into a powerful launchpad for productivity and success. Get ahead of 99% of people. MORE
Learn three powerful techniques: Freelining, Freetalking, and Freewriting to capture ideas and get thoughts onto a page. MORE
🌎 Community
🎉 Celebrate
The DEF CON Youth Challenge saw nearly a hundred kids participate across three age ranges. Love it! MORE
In this h1-702 vlog, NahamSec became HackerOne's latest Most Valuable Hacker. Congrats! MORE
After 5.5 years at Intigriti, it's time for a new chapter for Quikke. He has decided to focus on a more offensive/technical path in cybersecurity. Exciting! MORE
⚡️ Timeline
Orange Tsai has revamped his website, where he shares his thoughts and experiences. MORE
Corgi and her husband discovered during the pandemic that their jobs allowed them to be nomadic, so they began exploring the United States in their little camper, towed by a Jeep Gladiator, visiting National Parks whenever they could. MORE
Over the last decade, Daniel has managed servers for prominent businesses, including Pieter Levels, and met many helpful people, inspiring him to create a community dedicated to server-related issues. MORE
Ron spent a few years bug bounty hunting, a year as an app sec engineer, and now running a pen test company in NZ. He's also building a scanner on the side, and says that trying new stuff is fun. MORE
Frans Rosen was informed that his minority equity in Detectify was given up due to decisions by the current management, and he no longer has any affiliation with them. MORE
💛 Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
freddyb | Frederik Braun | Dad in Berlin | Computer person at @MozillaSecurity | co-founder of @fluxfingers | he/him.
zer0pwn | Dominik Penner | Senior Security Consultant, formerly NCC Group.
@fortelabs | Tiago Forte | The Second Brain Guy | Learn how to build one for yourself.
@bendtheory | bend theory | Techno Entomologist | Web App Pen Tester | OSCP.
🍄 Level up
📰 Read
Researchers examine the modern ransomware ecosystem, highlighting its evolution and the complex network of actors involved. They present novel techniques to identify ransomware payments with low false positives. MORE
A critical vulnerability in Spring Cloud Skipper allows for the deserialization of arbitrary objects, posing a remote code execution risk. MORE
Where money goes, crime follows. The rapid growth of Web3 has opened up new avenues for criminal activity, particularly in the realm of decentralized finance (DeFi), where heists are larger and more frequent than in traditional finance. MORE
Mathew on Why Login Security Sucks, including that it has to satisfy a wide range of experts, from normal users to national security professionals. Making it a challenging domain with varied requirements. MORE
0xold details how they transformed their black box testing into semi-white box testing, allowing them to uncover a $15k remote code execution vulnerability through monitoring debug mode. MORE
💡 Tips
A poster on Hacker News asks where to find domain experts for one-on-one tutoring, with the more specific the topic, the better. The top answer is graduate students (and sometimes even undergrads). MORE
This cheat sheet contains payloads for bypassing URL validation, useful for attacks like server-side request forgery, CORS misconfigurations, and open redirection. MORE
In macOS 13 or later, you can use Photos to isolate the subject of a photo from the photo background and then share it in other documents and apps. MORE
Japan, once known for its high costs, can now be traveled for just $1,000 over two weeks, as this video showcases. MORE
🧠 Wisdom
The Instinctive Drowning Response – so named by Francesco A. Pia, Ph.D., is what people do to avoid actual or perceived suffocation in the water. And it does not look like most people expect. MORE
An essay on why you should quit your job, particularly a good job, and encourage productive leisure. MORE
"Perhaps this is why our society has been so stagnant and uncreative in some ways for the past 50 years. We chose the path of comfort, certainty, measurable progress, and indeterminate hedging of bets. In our cowardice, we turned away from the uncertain leaps of faith of collective struggle after fatal ends that would have demanded us to truly live."
Sahil has maintained a running list of favored life hacks over the past several years, carefully testing each one before adding it to the list. MORE
d0nut's advice to new bug bounty hunters when they start: "If you're new to bug bounty, you should not learn recon." MORE
17 Naval Life Rules, including "Be present above all else.", "Desire is suffering.", "99 percent of all effort is wasted.", and more. MORE
📚 Resources
AWS S3 buckets are a popular storage service, but improper implementation can lead to security vulnerabilities. This guide provides a comprehensive overview of hacking misconfigured AWS S3 buckets. MORE
A look at the Information Laundromat website analysis tool. The Alliance For Securing Democracy created a free OSINT tool to examine the content and metadata of websites. MORE
Frank found that OpenAI is shockingly good at reverse-engineering minified code. MORE
How to detect, find, and mitigate Dependency Confusion attacks. MORE
The project aims to provide a series of vulnerable LLM CTF challenges that can be run locally, enabling users to learn AI security without sign-ups or cloud fees. MORE
💭 Quote
"The best way to predict the future is to create it."
🛠 Explore
🧰 Tools
Get $200 to try DigitalOcean — the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
This tool allows you to check if your AdBlock solution is blocking enough hosts. With a simple UI and easy UX, you can check how much you have blocked. MORE
XlsNinja is a versatile web application vulnerability scanner that can detect issues like Local File Inclusion, Open Redirects, SQL Injection, and Cross-Site Scripting. MORE
NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data for given IP addresses using various online services. MORE
ShellGPT is a command-line productivity tool powered by AI large language models (LLM). This command-line tool offers a streamlined generation of shell commands, code snippets, documentation, eliminating the need for external resources (like Google search). MORE
Synacksync is a project that syncs the API endpoints for missions, patches, and upcoming projects on the Synack platform to a Google calendar, with some light sanitization to mitigate sensitive client data. MORE
🎥 Watch
Caido is a web security auditing toolkit built in Rust (think Burp). The video showcases Caido's workflows and demonstrates how to script a WAF bypass using the tool. MORE
Planes have unlocked doors for practical reasons, not security risks, as commonly believed. The video dispels misconceptions and provides expert insights on this topic. MORE
An advanced tutorial on the proper usage of OpenAI's Structured Output. MORE
On June 16, Ross Edgley embarked on a 510km (317 mile) non-stop swim down the Yukon River (Canada) in water temperatures as low as 8°C (46.4°F). MORE
Guy made an electronic bumper sticker to broadcast one's music listening in real-time. MORE
🎵 Listen
SNAP, better known as food stamps, were replaced with EBT cards in the 1990s. Enterprising criminals found ways to drain funds meant for low-income families. MORE
In this episode, Justin and his wife Mariah discuss the bug bounty lifestyle, including its impact on travel, household responsibilities, and shared goals. MORE
David Heinemeier Hansson (DHH), creator of Rails and co-founder of Basecamp, discusses his strong opinions on software development, including his views on today's excessive complexity and AI. MORE
Life Hacks From The King of Introverts, Nick Gray, + 7 Business Ideas. MORE
🌐 Technology
The ai-digest project is a command-line tool that aggregates a codebase into a single Markdown file, ignoring common build artifacts and configuration files. This streamlines the process of sharing code with AI-powered tools like Claude Projects or custom ChatGPTs. MORE
A full-stack application that enables you to turn any document, resource, or piece of content into context that any LLM can use as references during chatting. MORE
A straightforward NixOS setup for a home lab and personal computers. MORE
Kolors Virtual Try-On is a Hugging Face Space that allows users to virtually try on different color options for various clothing items. MORE
The 2023 Python Developers Survey revealed that a remarkable number of Python developers contributed to open-source projects last year, a new metric for the survey. MORE
👀 Interesting
An engaging platform to instantly generate anagram sentences in multiple languages, providing a quick and free creative outlet. MORE
what3words is an easy way to identify precise locations. Every 10-foot square has been given a unique combination of three words.. MORE
Why A.I. Isn’t Going to Make Art. To create a novel or a painting, an artist makes choices that are fundamentally alien to artificial intelligence. MORE
Becca took 999 photos with the new $1,100 Pixel 9 Pro XL to see how its camera holds up in the real world. MORE
Find out why you keep making the same mistakes, and learn how embracing shame helps break the cycle. MORE
Until next week, take care of yourself and each other,
Bee 🐝
Share Hive Five →
Share this newsletter with your friends, colleagues, and BFFs.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.


