⤷ Title: Hackers Using AI to Target Siemens PLCs in Critical US Sectors
════════════════════════
𐀪 Author: Eduard Kovacs
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:02:02 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #ICS/OT #AI #Featured #ICS #PLC #Siemens
════════════════════════
𐀪 Author: Eduard Kovacs
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:02:02 +0000
════════════════════════
⌗ Tags: #Artificial Intelligence #ICS/OT #AI #Featured #ICS #PLC #Siemens
SecurityWeek
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.
⤷ Title: Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 11:34:34 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 11:34:34 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Exchange SE CU1 Delay: Microsoft Prioritizes Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:23:54 +0000
════════════════════════
⌗ Tags: #Microsoft #Artificial intelligence #cybersecurity #Exchange Server #Tech News
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:23:54 +0000
════════════════════════
⌗ Tags: #Microsoft #Artificial intelligence #cybersecurity #Exchange Server #Tech News
Information Security News
Exchange SE CU1 Delay: Microsoft Prioritizes Security
Microsoft finds itself unable to release the inaugural cumulative update for Exchange Server Subscription Edition according to its original schedule. Initially anticipated by the close of the firs…
⤷ Title: Typosquatting Attack Strikes RubyGems and npm
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:23:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #npm #RubyGems #StubMaker #Typosquatting
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:23:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #npm #RubyGems #StubMaker #Typosquatting
Information Security News
Typosquatting Attack Strikes RubyGems and npm
Malicious actors brazenly targeted developers utilizing counterfeit packages deployed simultaneously across two highly prominent repositories. Cybercriminals stealthily introduced 16 malicious lib…
⤷ Title: Cisco Talos Discovers JWR Phishing Framework
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:01:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CiscoTalos #cybersecurity #infosec #JWR #PhaaS #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:01:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CiscoTalos #cybersecurity #infosec #JWR #PhaaS #phishing
Daily CyberSecurity
Cisco Talos Discovers JWR Phishing Framework
At a glance Actor or group: Suspected Chinese-speaking cybercriminals. Activity type: Phishing-as-a-Service (PhaaS). Targets or victims: Shoppers using Shopify, PayPal, Apple, and Klarna. Scale: W…
⤷ Title: Evooo1Bot Linux Botnet Employs SOCKS Relays and DDoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:17:35 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evooo1Bot #FortiGuard #Linux Botnet #malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:17:35 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Evooo1Bot #FortiGuard #Linux Botnet #malware
Daily CyberSecurity
Evooo1Bot Linux Botnet Employs SOCKS Relays and DDoS
At a glance Malware family: Evooo1Bot Threat actor: Unknown Target or victims: Internet-facing devices, routers, firewalls, and IP cameras globally Delivery vector: Exploitation of known CVEs and …
⤷ Title: HunterX v7.0.0 — Less Noise. More Verified Findings.
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:00:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty #ai #machine_learning
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:00:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty #ai #machine_learning
Medium
🐺 HunterX v7.0.0 — Less Noise. More Verified Findings.
A few months ago, HunterX was an idea.
⤷ Title: CVE-2026 — 75855 : Path Traversal in ArcadeDB - Arbitrary File Write and Delete via Database Names
════════════════════════
𐀪 Author: Pervin Zahidli
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:32:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #cve #vulnerability #path_traversal
════════════════════════
𐀪 Author: Pervin Zahidli
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:32:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #cve #vulnerability #path_traversal
Medium
CVE-2026 — 75855 : Path Traversal in ArcadeDB - Arbitrary File Write and Delete via Database Names
ArcadeDB is a multi-model database engine with an HTTP server API. Like most database servers, it lets an admin create and drop databases…
⤷ Title: KQL & Threat Hunting in Cloud Workloads
════════════════════════
𐀪 Author: Ashutosh Yadav
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:46:42 GMT
════════════════════════
⌗ Tags: #kql #hacking #threat_hunting #cybersecurity #cloud_computing
════════════════════════
𐀪 Author: Ashutosh Yadav
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:46:42 GMT
════════════════════════
⌗ Tags: #kql #hacking #threat_hunting #cybersecurity #cloud_computing
Medium
KQL & Threat Hunting in Cloud Workloads
Unearthing Persistence, Token Abuse, and Anomalous Service Principals in Entra ID
⤷ Title: The Hacker Didn’t Break In… He logged in
════════════════════════
𐀪 Author: Devarshi Acharya
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:51:35 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #technology #cybercrime #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Devarshi Acharya
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:51:35 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #technology #cybercrime #penetration_testing #cybersecurity
Medium
The Hacker Didn’t Break In… He logged in
A company once believed its systems were secure.
⤷ Title: Cyber Security Engineer Course: A Practical Guide for Beginners
════════════════════════
𐀪 Author: Google Red Teaming
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:55:00 GMT
════════════════════════
⌗ Tags: #cyber_attack_courses #penetration_testing #cybersecurity_for_beginne #pentesting #cybersecurity_engineer
════════════════════════
𐀪 Author: Google Red Teaming
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:55:00 GMT
════════════════════════
⌗ Tags: #cyber_attack_courses #penetration_testing #cybersecurity_for_beginne #pentesting #cybersecurity_engineer
Medium
Cyber Security Engineer Course: A Practical Guide for Beginners
Cybersecurity has become a critical priority for organizations of every size. As businesses move their applications, infrastructure, and…
⤷ Title: Penetration Testing, Red Teaming, and Purple Teaming: A Practical Guide for Security Leaders
════════════════════════
𐀪 Author: Lakshita Gulliya
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:10:56 GMT
════════════════════════
⌗ Tags: #enterprise_security #penetration_testing #cyber_security_awareness #mitre_attack #threat_detection
════════════════════════
𐀪 Author: Lakshita Gulliya
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:10:56 GMT
════════════════════════
⌗ Tags: #enterprise_security #penetration_testing #cyber_security_awareness #mitre_attack #threat_detection
Medium
Penetration Testing, Red Teaming, and Purple Teaming: A Practical Guide for Security Leaders
Most companies find out the hard way that a security test they paid for didn’t answer the question they actually needed answered. They…
⤷ Title: TryHackMe |Agent Design
════════════════════════
𐀪 Author: Qaevix
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:34:01 GMT
════════════════════════
⌗ Tags: #ai #technology #cybersecurity #information_security #tryhackme
════════════════════════
𐀪 Author: Qaevix
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:34:01 GMT
════════════════════════
⌗ Tags: #ai #technology #cybersecurity #information_security #tryhackme
Medium
TryHackMe |Agent Design
https://tryhackme.com/room/agentdesign
⤷ Title: The Return of the Yeti — TryhackmeWrite-up
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:54:48 GMT
════════════════════════
⌗ Tags: #wireshark #decryption #encryption #tryhackme
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:54:48 GMT
════════════════════════
⌗ Tags: #wireshark #decryption #encryption #tryhackme
Medium
The Return of the Yeti — TryhackmeWrite-up
Solution:
⤷ Title: How a Cyber Security Diploma Course Can Support Your Career Goals
════════════════════════
𐀪 Author: cybersecuritycourse
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:41:48 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity_training #cybersecurity #ethical_hacking #education
════════════════════════
𐀪 Author: cybersecuritycourse
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 07:41:48 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity_training #cybersecurity #ethical_hacking #education
Medium
How a Cyber Security Diploma Course Can Support Your Career Goals
Cybersecurity has become one of the most important areas of the modern technology industry. Businesses, government organizations, banks…
⤷ Title: Vegeta Walkthrough | Proving Ground Machine | Oscp Prep
════════════════════════
𐀪 Author: Cybersecurity writeup's
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 05:58:10 GMT
════════════════════════
⌗ Tags: #ethical_hacking #oscp #cybersecurity #linux #pentesting
════════════════════════
𐀪 Author: Cybersecurity writeup's
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 05:58:10 GMT
════════════════════════
⌗ Tags: #ethical_hacking #oscp #cybersecurity #linux #pentesting
Medium
Vegeta Walkthrough | Proving Ground Machine | Oscp Prep
Lab Description
⤷ Title: SQL Injection to RCE: Understanding the Attack Chain
════════════════════════
𐀪 Author: Vibecyberv
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:03:54 GMT
════════════════════════
⌗ Tags: #rce #cybersecurity #attack #vapt #sql_injection
════════════════════════
𐀪 Author: Vibecyberv
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:03:54 GMT
════════════════════════
⌗ Tags: #rce #cybersecurity #attack #vapt #sql_injection
Medium
SQL Injection to RCE: Understanding the Attack Chain
In 2017, Equifax lost the personal data of 147 million people. In 2008, Heartland Payment Systems leaked over 130 million card numbers…
⤷ Title: Hunting Open Redirects: My Practical Methodology for Web Application Testing
════════════════════════
𐀪 Author: chalampalem Neeraja
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:30:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #bug_bounty_tips #happyhunting #vapt
════════════════════════
𐀪 Author: chalampalem Neeraja
════════════════════════
ⴵ Time: Thu, 20 Aug 2026 06:30:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #cybersecurity #bug_bounty_tips #happyhunting #vapt
Medium
Hunting Open Redirects: My Practical Methodology for Web Application Testing
Introduction
👏2
Forwarded from Bug Bounty Diary
✎ Extract & Download All JavaScript Files for Recon
For modern web apps, scraping
My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
For modern web apps, scraping
<script> tags or relying on Burp's Site Map often isn't enough. Why? Because applications may dynamically load JavaScript from CDNs, cross-origin domains, specific routes (Lazy Loading), or after user interactions.My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from
.HAR file using unhar (I'll talk about it in the next post.)#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
❤1
Forwarded from Bug Bounty Diary
✎ Unhar - Extract, Unminify, Beautify Javascript files from .Har file
In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a
unhar turns a raw
In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis
● Installation
● Usage
• Repository: Github
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a
.HAR file for further local analysis. Now, let’s take it a step further with unhar and process that HAR files. unhar turns a raw
.HAR file into a structured set of web assets for local analysis. It extracts unique JavaScript and HTML resources while preserving the original URL structure, fetches available source maps, beautifies/unminifies JavaScript, and extracts inline scripts from HTML pages.In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis
● Installation
git clone https://github.com/Spix0r/unhar
cd unhar
● Usage
# custom output directory
python3 unhar.py site.har --output folder
# skip source map fetching
python3 unhar.py site.har --no-srcmap
# skip beautify
python3 unhar.py site.har --no-beautify
• Repository: Github
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary