⤷ Title: Chaining Public Endpoints Into Data Exposure: A Case Study in Unauthenticated PII Leakage
════════════════════════
𐀪 Author: Inside_m
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:58:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_engineering #web_security #api_security #data_privacy
════════════════════════
𐀪 Author: Inside_m
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:58:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_engineering #web_security #api_security #data_privacy
Medium
Chaining Public Endpoints Into Data Exposure: A Case Study in Unauthenticated PII Leakage
Not every impactful security issue starts with a sophisticated exploit. Sometimes it starts with a design pattern that looks harmless until…
⤷ Title: When Does an API Become a Security Vulnerability?
════════════════════════
𐀪 Author: @dsfglobal
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:22:34 GMT
════════════════════════
⌗ Tags: #api #api_security #api_testing
════════════════════════
𐀪 Author: @dsfglobal
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:22:34 GMT
════════════════════════
⌗ Tags: #api #api_security #api_testing
Medium
When Does an API Become a Security Vulnerability?
We use dozens of APIs every day without even realizing it. Whether we are ordering food, checking our bank accounts, or booking a hotel…
⤷ Title: Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 20:10:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 20:10:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 19:40:54 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 19:40:54 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:43:57 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #APT28 #Cyber Attack #Cybersecurity #Fancy Bear #Forest Blizzard #Hotels #Microsoft #Microsoft 365 #Phishing #ReliaQuest #Scam #WIFI
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:43:57 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #APT28 #Cyber Attack #Cybersecurity #Fancy Bear #Forest Blizzard #Hotels #Microsoft #Microsoft 365 #Phishing #ReliaQuest #Scam #WIFI
Hackread
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
⤷ Title: Critical GitLab RCE Vulnerability Exposed in Oj JSON Parser
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:00:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #Gitlab #Jupyter Notebook #Oj Parser #remote code execution #vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:00:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #Gitlab #Jupyter Notebook #Oj Parser #remote code execution #vulnerability
Information Security News
Critical GitLab RCE Vulnerability Exposed in Oj JSON Parser
Unmasking the Concealed Remote Code Execution Flaw A critical remote code execution (RCE) flaw in self-hosted GitLab installations lay concealed for nearly six weeks. Although GitLab patched the u…
⤷ Title: Iranian Hackers Modify PLC Logic in US Infrastructure Attacks
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:09:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA Advisory #Critical Infrastructure #ICS Security #Iranian hackers #PLC Hacking
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:09:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA Advisory #Critical Infrastructure #ICS Security #Iranian hackers #PLC Hacking
Information Security News
Iranian Hackers Modify PLC Logic in US Infrastructure Attacks
Covert Sabotage of Critical Infrastructure Iranian threat actors have developed sophisticated techniques to covertly manipulate programmable logic controllers (PLCs), ensuring that human operators…
⤷ Title: CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:26:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arista #CVE_2026_16812 #CVE_2026_17191 #CVE_2026_17192 #exploited in the wild #os command injection #ssrf #VCO #VeloCloud #VeloCloud Orchestrator
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:26:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arista #CVE_2026_16812 #CVE_2026_17191 #CVE_2026_17192 #exploited in the wild #os command injection #ssrf #VCO #VeloCloud #VeloCloud Orchestrator
Daily CyberSecurity
CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild
TL;DR: Arista confirmed that CVE-2026-16812, a VeloCloud command injection flaw, is under active attack. The bug scores a maximum CVSS 10.0 and needs no credentials. Arista also patched two relate…
⤷ Title: VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:50:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #active directory #Operation STANDOFF #proxy botnet #Raccoon Stealer #Russian_speaking threat group #Telegram account farm #VMRay
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:50:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #active directory #Operation STANDOFF #proxy botnet #Raccoon Stealer #Russian_speaking threat group #Telegram account farm #VMRay
Daily CyberSecurity
VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub
At a glance Actor or group Unnamed Russian-speaking crew tracked as Operation STANDOFF; self-branded “GG Influence” and “ggstandoff” Activity type Pay-per-install malware, …
⤷ Title: Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:01:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BirdTroy #DriveTroy #Gomir #HttpTroy #Kimsuky #Linux Backdoor #North Korea #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:01:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BirdTroy #DriveTroy #Gomir #HttpTroy #Kimsuky #Linux Backdoor #North Korea #supply chain attack
Daily CyberSecurity
Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants
At a glance Actor or group Kimsuky, a North Korea-linked group also tracked as Springtail, Thallium and APT43 Activity type Espionage, supply-chain pivoting, credential theft, Linux backdoor deplo…
⤷ Title: How a Hidden GraphQL Endpoint Led Me to a Critical SQL Injection Worth €2,500
════════════════════════
𐀪 Author: 0xSADAT
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:58:18 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #infosec #bug_bounty #info_sec_writeups #cybersecurity
════════════════════════
𐀪 Author: 0xSADAT
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:58:18 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #infosec #bug_bounty #info_sec_writeups #cybersecurity
Medium
How a Hidden GraphQL Endpoint Led Me to a Critical SQL Injection Worth €2,500
A simple directory fuzzing session uncovered a hidden GraphQL endpoint. A harmless-looking search bar eventually turned into a confirmed…
⤷ Title: TryHeartMe THM write-up
════════════════════════
𐀪 Author: Creepus
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #labs #writeup #solved #hacking #tryhackme
════════════════════════
𐀪 Author: Creepus
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #labs #writeup #solved #hacking #tryhackme
Medium
TryHeartMe THM write-up
Introduction
⤷ Title: Volatility — Memory Forensics
════════════════════════
𐀪 Author: SAFAL GAUTAM
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:32:12 GMT
════════════════════════
⌗ Tags: #memory_forensics #hacking #cybersecurity #tools
════════════════════════
𐀪 Author: SAFAL GAUTAM
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:32:12 GMT
════════════════════════
⌗ Tags: #memory_forensics #hacking #cybersecurity #tools
Medium
Volatility — Memory Forensics
Volatility 2 and 3 have some genuinely frustrating setup quirks that aren’t documented clearly anywhere. Here’s everything worth knowing.
⤷ Title: TryHackMe: Passive Reconnaissance
════════════════════════
𐀪 Author: Chimeremeze
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:27:57 GMT
════════════════════════
⌗ Tags: #tryhackme #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Chimeremeze
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:27:57 GMT
════════════════════════
⌗ Tags: #tryhackme #penetration_testing #cybersecurity
Medium
TryHackMe: Passive Reconnaissance
Introduction
⤷ Title: TryHackMe — Metasploit Meterpreter
════════════════════════
𐀪 Author: Ufuk Yaman
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:52:31 GMT
════════════════════════
⌗ Tags: #tryhackme #windows #metasploit #pentesting #exploitation
════════════════════════
𐀪 Author: Ufuk Yaman
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:52:31 GMT
════════════════════════
⌗ Tags: #tryhackme #windows #metasploit #pentesting #exploitation
Medium
TryHackMe — Metasploit Meterpreter
Bu oda, Metasploit Framework’ün en güçlü bileşenlerinden biri olan Meterpreter’ın işlevselliğini, mimarisini ve kullanım yöntemlerini…
⤷ Title: TryHackMe The Brochure Day 0 Challenge
════════════════════════
𐀪 Author: Benedict
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:07:03 GMT
════════════════════════
⌗ Tags: #osint_investigation #tryhackme #osint
════════════════════════
𐀪 Author: Benedict
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 14:07:03 GMT
════════════════════════
⌗ Tags: #osint_investigation #tryhackme #osint
Medium
TryHackMe The Brochure Day 0 Challenge
This is a write-up of my thought process when solving the TryHackMe The Brochure challenge.
⤷ Title: YACS — Ethical Hacking & Cybersecurity Course in Kerala
════════════════════════
𐀪 Author: Eldho Yacs
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:33:40 GMT
════════════════════════
⌗ Tags: #ethical_hacking
════════════════════════
𐀪 Author: Eldho Yacs
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:33:40 GMT
════════════════════════
⌗ Tags: #ethical_hacking
Medium
YACS — Ethical Hacking & Cybersecurity Course in Kerala
Looking for the best ethical hacking course in Kerala or a hands-on cybersecurity course in Kerala? Welcome to YACS (Yet Another Cyber…
⤷ Title: Introduction
════════════════════════
𐀪 Author: Shreya Upadhyay
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:25:05 GMT
════════════════════════
⌗ Tags: #students #cybersecurity #content_creation #technology #ethical_hacking
════════════════════════
𐀪 Author: Shreya Upadhyay
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:25:05 GMT
════════════════════════
⌗ Tags: #students #cybersecurity #content_creation #technology #ethical_hacking
Medium
Introduction
Hii , My name is Shreya a student , currently pursuing my Bachelor’s degree and from today on I am starting my journey here and will…
⤷ Title: Database developments DON’Ts
════════════════════════
𐀪 Author: Zahir Mohideen
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:46:51 GMT
════════════════════════
⌗ Tags: #explain_plan #sql #best_practices #sql_injection #database_development
════════════════════════
𐀪 Author: Zahir Mohideen
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:46:51 GMT
════════════════════════
⌗ Tags: #explain_plan #sql #best_practices #sql_injection #database_development
Medium
Database developments DON’Ts
This is my first blog. Based on your feedback , I will be updating this blog , post new blogs .Thanks for looking into this .
⤷ Title: Reading the patch instead of the code: SQL Injection in GLPI (CVE-2026–53629)
════════════════════════
𐀪 Author: Paulo Werneck (5kr1pt)
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:52:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #sql_injection #vulnerability_research #cve
════════════════════════
𐀪 Author: Paulo Werneck (5kr1pt)
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:52:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #sql_injection #vulnerability_research #cve
Medium
Reading the patch instead of the code: SQL Injection in GLPI (CVE-2026–53629)
On March 3, 2026, GLPI shipped a fix for a SQL injection in the history filters, CVE-2026–29047. Five lines added across two files…