⤷ Title: XSS, CSRF, and SSRF: Understanding Three Commonly Confused Web Vulnerabilities
════════════════════════
𐀪 Author: Moez Ben-Azzouz
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 02:23:31 GMT
════════════════════════
⌗ Tags: #ssrf #xss_attack #csrf #penetration_testing #web_application_security
════════════════════════
𐀪 Author: Moez Ben-Azzouz
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 02:23:31 GMT
════════════════════════
⌗ Tags: #ssrf #xss_attack #csrf #penetration_testing #web_application_security
Medium
XSS, CSRF, and SSRF: Understanding Three Commonly Confused Web Vulnerabilities
If you are new to web application security, you have probably encountered the acronyms XSS, CSRF, and SSRF. These three vulnerability…
⤷ Title: Malware Analysis — Egg-xecutable
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 03:51:45 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme_walkthrough #tryhackme #ctf #ctf_writeup
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 03:51:45 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme_walkthrough #tryhackme #ctf #ctf_writeup
Medium
Malware Analysis — Egg-xecutable
Discover some common tooling for malware analysis within a sandbox environment.
⤷ Title: Trust Writeup (Web) — WannaGame CTF 2025
════════════════════════
𐀪 Author: Ahmed Reda (minyawy)
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 02:37:20 GMT
════════════════════════
⌗ Tags: #ctf #minyawy #wannagame #web_ctf_writeup #rce
════════════════════════
𐀪 Author: Ahmed Reda (minyawy)
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 02:37:20 GMT
════════════════════════
⌗ Tags: #ctf #minyawy #wannagame #web_ctf_writeup #rce
Medium
Trust Writeup (Web) — WannaGame CTF 2025
Hi, this is a simple writeup for a web challenge in WannaGame CTF 2025, I found it interesting to share it🤏
⤷ Title: Singularity: Advanced Linux Kernel Rootkit Uses ftrace to Bypass EDR and eBPF
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:39:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #eBPF #EDR Bypass #ftrace #Linux Kernel #Offensive Security #privilege escalation #Process Hiding #rootkit #Singularity #Stealth
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:39:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #eBPF #EDR Bypass #ftrace #Linux Kernel #Offensive Security #privilege escalation #Process Hiding #rootkit #Singularity #Stealth
Penetration Testing Tools
Singularity: Advanced Linux Kernel Rootkit Uses ftrace to Bypass EDR and eBPF
Singularity is an advanced Linux Kernel 6.x rootkit that uses ftrace hooking to provide comprehensive stealth, including process/file hiding and eBPF/EDR detection evasion.
⤷ Title: NVIDIA CUDA 13.1: ‘CUDA Tile’ Abstraction Simplifies High-Level GPU Programming
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:32:05 +0000
════════════════════════
⌗ Tags: #Technology #Abstraction #AI Workloads #CUDA 13.1 #CUDA Tile #cuTile #GPU Programming #Nvidia #SIMT #Tensor Cores
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:32:05 +0000
════════════════════════
⌗ Tags: #Technology #Abstraction #AI Workloads #CUDA 13.1 #CUDA Tile #cuTile #GPU Programming #Nvidia #SIMT #Tensor Cores
Penetration Testing Tools
NVIDIA CUDA 13.1: 'CUDA Tile' Abstraction Simplifies High-Level GPU Programming
NVIDIA has announced the most significant update to the CUDA platform since its inception in 2006. With CUDA
⤷ Title: Alpine Linux 3.23 Released: Adopts 6.18 LTS Kernel & Unveils APK 3.0 Package Manager
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:31:10 +0000
════════════════════════
⌗ Tags: #Linux #Alpine Linux #APK 3.0.0 #Containers #Linux 3.23 #Linux 6.18 #LTS Kernel #Minimalist OS #musl libc #Package Manager
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:31:10 +0000
════════════════════════
⌗ Tags: #Linux #Alpine Linux #APK 3.0.0 #Containers #Linux 3.23 #Linux 6.18 #LTS Kernel #Minimalist OS #musl libc #Package Manager
Penetration Testing Tools
Alpine Linux 3.23 Released: Adopts 6.18 LTS Kernel & Unveils APK 3.0 Package Manager
The latest cycle of updates within the Linux distribution ecosystem closes the year with a notable milestone: Alpine
⤷ Title: Zero-Click Threat: New Attacks Turn AI Browsers into Google Drive Wipers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:27:00 +0000
════════════════════════
⌗ Tags: #Malware #AI browser #data loss #Google Drive Wiper #HashJack #OAuth Security #Perplexity Comet #Prompt Injection #Zero_Click Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:27:00 +0000
════════════════════════
⌗ Tags: #Malware #AI browser #data loss #Google Drive Wiper #HashJack #OAuth Security #Perplexity Comet #Prompt Injection #Zero_Click Attack
Penetration Testing Tools
Zero-Click Threat: New Attacks Turn AI Browsers into Google Drive Wipers
Researchers at Striker STAR Labs have detailed a new attack against agent-based browsers that can turn an ordinary
⤷ Title: Phishing Kits Steal Cards, Bind to Apple Pay/Google Wallet via Fake Stores
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:22:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Apple Pay #Card Binding #Fake Stores #Google Wallet #Mobile Wallet Fraud #phishing #SecAlliance #Smishing #T_Mobile Scam
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:22:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Apple Pay #Card Binding #Fake Stores #Google Wallet #Mobile Wallet Fraud #phishing #SecAlliance #Smishing #T_Mobile Scam
Penetration Testing Tools
Phishing Kits Steal Cards, Bind to Apple Pay/Google Wallet via Fake Stores
Chinese phishing groups that inundate users with endless SMS alerts about a “delivery problem” or an “unpaid fine”
⤷ Title: GhostFrame: Stealthy Iframe Phishing Toolkit Fuels 1 Million+ Covert Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:20:00 +0000
════════════════════════
⌗ Tags: #Malware #Barracuda #Covert Attack #cybercrime #GhostFrame #Iframe Attack #Phishing Toolkit #Social Engineering #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:20:00 +0000
════════════════════════
⌗ Tags: #Malware #Barracuda #Covert Attack #cybercrime #GhostFrame #Iframe Attack #Phishing Toolkit #Social Engineering #web security
Penetration Testing Tools
GhostFrame: Stealthy Iframe Phishing Toolkit Fuels 1 Million+ Covert Attacks
The new malicious distribution tool GhostFrame has spread with remarkable speed throughout the cybercriminal ecosystem, becoming the source
⤷ Title: China APTs Exploiting React Server RCE (CVE-2025-55182) Hours After Disclosure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:18:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #AWS MadPot #China APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #Patch Now #RCE #React2Shell #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:18:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #AWS MadPot #China APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #Patch Now #RCE #React2Shell #Supply Chain
Penetration Testing Tools
China APTs Exploiting React Server RCE (CVE-2025-55182) Hours After Disclosure
Two China-linked hacking groups began exploiting a critical vulnerability in React Server Components just hours after it became
⤷ Title: Cloudflare Outage 2.0: Faulty React Patch Configuration Disrupts Major Websites
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:17:01 +0000
════════════════════════
⌗ Tags: #Technology #Cloudflare #Configuration Error #Internet Centralization #LinkedIn #Outage #React Server Components #WAF #Zoom
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:17:01 +0000
════════════════════════
⌗ Tags: #Technology #Cloudflare #Configuration Error #Internet Centralization #LinkedIn #Outage #React Server Components #WAF #Zoom
Penetration Testing Tools
Cloudflare Outage 2.0: Faulty React Patch Configuration Disrupts Major Websites
Cloudflare’s services suffered yet another disruption on Friday morning, rendering LinkedIn, Zoom, Downdetector, and a number of other
⤷ Title: Developer Alert: Fake VS Code Extension Deploys OctoRAT via Multi-Stage Anivia Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:08:51 +0000
════════════════════════
⌗ Tags: #Malware #Anivia Loader #Credential Theft #Developer Security #OctoRAT #Prettier_vscode_plus #supply chain attack #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:08:51 +0000
════════════════════════
⌗ Tags: #Malware #Anivia Loader #Credential Theft #Developer Security #OctoRAT #Prettier_vscode_plus #supply chain attack #VS Code
Penetration Testing Tools
Developer Alert: Fake VS Code Extension Deploys OctoRAT via Multi-Stage Anivia Loader
At the end of November, a team of bug hunters uncovered an infection chain that began with a
⤷ Title: FreeBSD 15.0 Arrives: New 4-Year Lifecycle, pkgbase Updates, and Massive ZFS/Jail Upgrades
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:01:31 +0000
════════════════════════
⌗ Tags: #Linux #BSD #FreeBSD 15.0 #Jails #Lifetime Policy #Linux Drivers #operating system #pkgbase #Reproducible Builds #Unix #ZFS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:01:31 +0000
════════════════════════
⌗ Tags: #Linux #BSD #FreeBSD 15.0 #Jails #Lifetime Policy #Linux Drivers #operating system #pkgbase #Reproducible Builds #Unix #ZFS
Penetration Testing Tools
FreeBSD 15.0 Arrives: New 4-Year Lifecycle, pkgbase Updates, and Massive ZFS/Jail Upgrades
Nearly two years after the debut of the 14.0 branch, the FreeBSD project has unveiled a major new
⤷ Title: IDOR & Parameter Tampering Vulnerability — How a Simple URL Change Exposed Hidden Content
════════════════════════
𐀪 Author: Sabuj Kumar Modak
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:49:56 GMT
════════════════════════
⌗ Tags: #bugs #penetration_testing #vapt #idor_vulnerability #bug_bounty
════════════════════════
𐀪 Author: Sabuj Kumar Modak
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:49:56 GMT
════════════════════════
⌗ Tags: #bugs #penetration_testing #vapt #idor_vulnerability #bug_bounty
Medium
IDOR & Parameter Tampering Vulnerability — How a Simple URL Change Exposed Hidden Content
A few days ago, while testing a web platform of a company (let’s call it example.com), I discovered a classic yet dangerous vulnerability…
⤷ Title: How I Discovered a Price Manipulation Bug While Buying a Simple Product
════════════════════════
𐀪 Author: Sabuj Kumar Modak
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:57:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability #web_vapt #cybersecurity #idor_vulnerability
════════════════════════
𐀪 Author: Sabuj Kumar Modak
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:57:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability #web_vapt #cybersecurity #idor_vulnerability
Medium
How I Discovered a Price Manipulation Bug While Buying a Simple Product
A few days ago, I was trying to purchase a product from a website. Everything looked normal during checkout, but something caught my…
⤷ Title: The Hidden Cost of DIY Application Security: When to Call Security Consultants
════════════════════════
𐀪 Author: KomodoSec.com
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:49:10 GMT
════════════════════════
⌗ Tags: #application_security #app_security
════════════════════════
𐀪 Author: KomodoSec.com
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:49:10 GMT
════════════════════════
⌗ Tags: #application_security #app_security
Medium
The Hidden Cost of DIY Application Security: When to Call Security Consultants
As modern businesses rely heavily on web, mobile, and cloud applications, securing these systems has become a top priority. Yet many…
⤷ Title: Hacking AI: How I Crafted RCE on a Vibe-Coding LLM Using Prompt Engineering
════════════════════════
𐀪 Author: ipsbruno3
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:23:05 GMT
════════════════════════
⌗ Tags: #llm #chatgpt #internet #pentesting #hacking
════════════════════════
𐀪 Author: ipsbruno3
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:23:05 GMT
════════════════════════
⌗ Tags: #llm #chatgpt #internet #pentesting #hacking
Medium
🚨 Hacking AI: How I Crafted RCE on a Vibe-Coding LLM Using Prompt Engineering
⚠️ A real-world, authorized pentest on a big tech “vibe coding” AI platform (codename Falcon), with all vulnerabilities disclosed and fixed
⤷ Title: React2Shell Detection Script.
════════════════════════
𐀪 Author: Adrian Romanov
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:05:57 GMT
════════════════════════
⌗ Tags: #hacking #threat_detection #react2shell #pentesting #ai
════════════════════════
𐀪 Author: Adrian Romanov
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:05:57 GMT
════════════════════════
⌗ Tags: #hacking #threat_detection #react2shell #pentesting #ai
Medium
React2Shell Detection Script.
# React2Shell (CVE-2025–55182): La Vulnerabilidad Critica que Debes Conocer.
⤷ Title: How to Get Free Windows Activation Using the KMS Exploit.
════════════════════════
𐀪 Author: TheCyberNirvana
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:51:35 GMT
════════════════════════
⌗ Tags: #hacking #windows #malware #cybersecurity
════════════════════════
𐀪 Author: TheCyberNirvana
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:51:35 GMT
════════════════════════
⌗ Tags: #hacking #windows #malware #cybersecurity
Medium
How to Get Free Windows Activation Using the KMS Exploit.
Hello readers , I am Nirvana , and today I will explain the KMS (Key Management Service). You may find this especially interesting because…
⤷ Title: Tải Hack Haunted Dorm (Vô Hạn Tiền, Tiếng Việt) v1.8.1
════════════════════════
𐀪 Author: Bandisharecx
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:28:08 GMT
════════════════════════
⌗ Tags: #hacking #bandishare #games
════════════════════════
𐀪 Author: Bandisharecx
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:28:08 GMT
════════════════════════
⌗ Tags: #hacking #bandishare #games
Medium
Tải Hack Haunted Dorm (Vô Hạn Tiền, Tiếng Việt) v1.8.1
Haunted Dorm là một tựa game chiến thuật — sinh tồn độc đáo, nơi người chơi vào vai sinh viên phải trốn tránh khỏi những linh hồn ma quái…
⤷ Title: Exploiting EternalBlue (MS17–010) — Walkthrough
════════════════════════
𐀪 Author: B3TA-BLOCKER
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:41:01 GMT
════════════════════════
⌗ Tags: #eternalblue_exploit #eternalblue #penetration_testing #red_teaming #cybersecurity
════════════════════════
𐀪 Author: B3TA-BLOCKER
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 05:41:01 GMT
════════════════════════
⌗ Tags: #eternalblue_exploit #eternalblue #penetration_testing #red_teaming #cybersecurity
Medium
Exploiting EternalBlue (MS17–010) — Walkthrough
Lab Setup: