⤷ Title: What Is API Security and Why Should Everyday People Care? (Non-tech user friendly)
════════════════════════
𐀪 Author: Charmaine Mangorima
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 23:17:40 GMT
════════════════════════
⌗ Tags: #api_security #api
════════════════════════
𐀪 Author: Charmaine Mangorima
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 23:17:40 GMT
════════════════════════
⌗ Tags: #api_security #api
Medium
What Is API Security and Why Should Everyday People Care? (Non-tech user friendly)
Introduction
You have probably heard the term “API” before, maybe when using apps like Spotify, Instagram or online banking among others…
You have probably heard the term “API” before, maybe when using apps like Spotify, Instagram or online banking among others…
⤷ Title: Interesting Bug Bounty Findings I found in Android Application
════════════════════════
𐀪 Author: m_kamal
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:52:01 GMT
════════════════════════
⌗ Tags: #android_pentesting #hacking #bug_bounty #android
════════════════════════
𐀪 Author: m_kamal
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:52:01 GMT
════════════════════════
⌗ Tags: #android_pentesting #hacking #bug_bounty #android
Medium
Interesting Bug Bounty Findings I found in Android Application
Hi, I’m Mohamed Kamal, Offensive Security Engineer and bug bounty hunter
⤷ Title: The Most Used Tool in Bug Hunting — And How to Master It Like a Pro
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:12 GMT
════════════════════════
⌗ Tags: #tech #cybersecurity #technology #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:12 GMT
════════════════════════
⌗ Tags: #tech #cybersecurity #technology #bug_bounty #penetration_testing
Medium
The Most Used Tool in Bug Hunting — And How to Master It Like a Pro
Stop learning 50 tools — master the one that actually finds real money bugs.
⤷ Title: OWASP API9: Cómo Explotar Shadow y Zombie APIs (Improper Inventory Management)
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:02:16 GMT
════════════════════════
⌗ Tags: #hacking #technology #bug_bounty #cybersecurity #api
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:02:16 GMT
════════════════════════
⌗ Tags: #hacking #technology #bug_bounty #cybersecurity #api
Medium
OWASP API9: Cómo Explotar Shadow y Zombie APIs (Improper Inventory Management)
Descubre cómo la falla API9 (Improper Inventory Management) expone APIs Zombie y Shadow para un Bypass de seguridad crítico.
⤷ Title: When “Cancel Order” Becomes “Access Granted” — Blind SQL Injection
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:45:35 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #hacking #sql_injection #web_penetration_testing
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:45:35 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #hacking #sql_injection #web_penetration_testing
Medium
When “Cancel Order” Becomes “Access Granted” — Blind SQL Injection
⚡Quick Overview
⤷ Title: DoS และ DDoS คืออะไร ทำไมถึงต้องรู้ไว้ก่อนจะสายเกินไป
════════════════════════
𐀪 Author: Pongsatorn Waiyaworn
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:58:01 GMT
════════════════════════
⌗ Tags: #dos_ddos_attack_defense #dos_vs_ddos #backend #hacking #security
════════════════════════
𐀪 Author: Pongsatorn Waiyaworn
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:58:01 GMT
════════════════════════
⌗ Tags: #dos_ddos_attack_defense #dos_vs_ddos #backend #hacking #security
Medium
DoS และ DDoS คืออะไร ทำไมถึงต้องรู้ไว้ก่อนจะสายเกินไป
เมื่อไม่นานมานี้ ผมมีโอกาสได้เข้าฟังกิจกรรมที่บริษัทด้านไอทีแห่งหนึ่งเข้ามาแนะนำตัวเอง ว่าทำอะไร รับคนแบบไหน มีโปรเจกต์อะไรน่าสนใจบ้าง…
⤷ Title: Great AI Tools For Pentesters & OSINT Investigators
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:24 GMT
════════════════════════
⌗ Tags: #ai #ai_tools #artificial_intelligence #hacking #cybersecurity
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:24 GMT
════════════════════════
⌗ Tags: #ai #ai_tools #artificial_intelligence #hacking #cybersecurity
Medium
Great AI Tools For Pentesters & OSINT Investigators
20+AI Tools for Effective Pentesting and OSINT Research
⤷ Title: THM — Tech_Supp0rt: 1
════════════════════════
𐀪 Author: 0xEnzoSantana
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:16:09 GMT
════════════════════════
⌗ Tags: #capture_the_flag #ethical_hacking #tryhackme_writeup #cybersecurity #tryhackme
════════════════════════
𐀪 Author: 0xEnzoSantana
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:16:09 GMT
════════════════════════
⌗ Tags: #capture_the_flag #ethical_hacking #tryhackme_writeup #cybersecurity #tryhackme
Medium
THM — Tech_Supp0rt: 1
Link: https://tryhackme.com/room/techsupp0rt1
⤷ Title: Black Hat GEO in the LLM Era: Policy, Ethics, and the Fight for Information Integrity
════════════════════════
𐀪 Author: Geolyze
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:27 GMT
════════════════════════
⌗ Tags: #llm #ai #ethical_hacking
════════════════════════
𐀪 Author: Geolyze
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:27 GMT
════════════════════════
⌗ Tags: #llm #ai #ethical_hacking
Medium
Black Hat GEO in the LLM Era: Policy, Ethics, and the Fight for Information Integrity
In the early stages of search, ranking algorithms were easily manipulated through tactics such as hidden text, link farms, and keyword…
⤷ Title: What Is API Security and Why Should WE Care?
════════════════════════
𐀪 Author: Hafsah Ashraf
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:51:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #api_security
════════════════════════
𐀪 Author: Hafsah Ashraf
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:51:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #api_security
Medium
What Is API Security and Why Should WE Care?
A few months ago, a friend told me about something strange that happened while she was checking her bank account on her phone. The page…
⤷ Title: Understanding Broken Object Level Authorization (BOLA): What It Is, How It Happens, and How to…
════════════════════════
𐀪 Author: Charmaine Mangorima
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 23:54:38 GMT
════════════════════════
⌗ Tags: #api_security #api #owasp_api_security_top_10
════════════════════════
𐀪 Author: Charmaine Mangorima
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 23:54:38 GMT
════════════════════════
⌗ Tags: #api_security #api #owasp_api_security_top_10
Medium
Understanding Broken Object Level Authorization (BOLA): What It Is, How It Happens, and How to…
Introduction
APIs (Application Programming Interfaces) power almost every app you use today, from social media and banking to fitness…
APIs (Application Programming Interfaces) power almost every app you use today, from social media and banking to fitness…
⤷ Title: Farewell, Tabs: Google’s Experimental Disco Browser Generates Web Apps with AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:50:22 +0000
════════════════════════
⌗ Tags: #Technology #AI Browser #artificial intelligence #Chromium #Disco #Gemini 3 #GenTab #google #Google Labs #PWA #Web Browsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:50:22 +0000
════════════════════════
⌗ Tags: #Technology #AI Browser #artificial intelligence #Chromium #Disco #Gemini 3 #GenTab #google #Google Labs #PWA #Web Browsing
Daily CyberSecurity
Farewell, Tabs: Google's Experimental Disco Browser Generates Web Apps with AI
Google Labs unveils Disco, an experimental AI browser powered by Gemini 3. It features GenTab, which can generate interactive Progressive Web Apps (PWAs) from web content.
⤷ Title: React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:38:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_55184 #dos #Infinite Loop #React Server Components #security vulnerability #Source Code Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:38:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_55184 #dos #Infinite Loop #React Server Components #security vulnerability #Source Code Disclosure
Daily CyberSecurity
React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure
New flaws found in React Server Components risk a Server-Crashing DoS (CVSS 7.5) via infinite loop and Source Code Disclosure (CVE-2025-55183). Update to v19.0.3/19.1.4/19.2.3 immediately.
⤷ Title: Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:28:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fineract #Authorization Bypass #Core Banking #CVE_2025_58137 #Financial services #IDOR #Weak Password Policy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:28:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fineract #Authorization Bypass #Core Banking #CVE_2025_58137 #Financial services #IDOR #Weak Password Policy
Daily CyberSecurity
Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access
A flaw in Apache Fineract risks Authorization Bypass via IDOR (CVE-2025-58137) in its self-service API, potentially exposing customer data. Also fixed: Weak Password Policy and Unmasked Server Keys. Update to v1.13.0.
⤷ Title: New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:10:55 +0000
════════════════════════
⌗ Tags: #Malware #01flip #APAC #Cross_Platform #CVE_2019_11580 #LockBit #ransomware #Rust #Sliver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:10:55 +0000
════════════════════════
⌗ Tags: #Malware #01flip #APAC #Cross_Platform #CVE_2019_11580 #LockBit #ransomware #Rust #Sliver
Daily CyberSecurity
New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
New 01flip ransomware (written in Rust) targets APAC critical infra across Windows/Linux. The attackers use Sliver for C2 and older exploits for access. A curious "lockbit" ignore list was found in the code.
⤷ Title: CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
Daily CyberSecurity
CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
CISA added a critical XXE flaw (CVE-2025-58360) in OSGeo GeoServer to the KEV Catalog. The actively exploited bug allows attackers to read arbitrary files and perform SSRF on internal networks. Patch immediately.
⤷ Title: Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:57:10 +0000
════════════════════════
⌗ Tags: #Malware #Builder Leak #Cybercrime #EDR Bypass #Kernel Rootkit #Modular Backdoor #ValleyRAT #Windows 11 #Winos
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:57:10 +0000
════════════════════════
⌗ Tags: #Malware #Builder Leak #Cybercrime #EDR Bypass #Kernel Rootkit #Modular Backdoor #ValleyRAT #Windows 11 #Winos
Daily CyberSecurity
Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge
A sophisticated cyber weapon previously linked to targeted espionage has gone rogue, flooding the threat landscape after its creation tools were leaked to the public. A new report from Check Point…
⤷ Title: Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:32:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Datadog Labs #Microsoft 365 #Okta #phishing #Salary Review #Session Token Hijack #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:32:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Datadog Labs #Microsoft 365 #Okta #phishing #Salary Review #Session Token Hijack #SSO Bypass
Daily CyberSecurity
Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures
A sophisticated phishing campaign uses salary review lures to target M365/Okta SSO. Attackers proxy the login page to preserve customization and hijack critical session tokens via dynamic redirection.
⤷ Title: CVE-2025-64188 (CVSS 9.8): Critical “Soledad” Theme Flaw Lets Subscribers Take Over WordPress Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:22:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:22:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
CVE-2025-64188 (CVSS 9.8): Critical "Soledad" Theme Flaw Lets Subscribers Take Over WordPress Sites
A Critical (CVSS 9.8) flaw in Soledad WordPress Theme allows Subscribers to escalate privileges and gain full site takeover by exploiting an exposed AJAX action. Update to v8.6.9.1 immediately.
⤷ Title: DiCaprio Movie Torrent Lures Users: Agent Tesla Deployed via Malicious LNK and Subtitle File Code Hiding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:15:04 +0000
════════════════════════
⌗ Tags: #Malware #Agent Tesla #Cybercrime #living_off_the_land #LNK Exploit #LotL #Movie Torrent #powershell #Subtitle File
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:15:04 +0000
════════════════════════
⌗ Tags: #Malware #Agent Tesla #Cybercrime #living_off_the_land #LNK Exploit #LotL #Movie Torrent #powershell #Subtitle File
Daily CyberSecurity
DiCaprio Movie Torrent Lures Users: Agent Tesla Deployed via Malicious LNK and Subtitle File Code Hiding
A movie torrent scam uses a DiCaprio film lure to infect PCs with Agent Tesla RAT. The attack chain uses LNK files and malicious code hidden in a subtitle file to achieve fileless execution via LotL tools.
⤷ Title: GOLD BLADE APT Hits Canadian Firms with BYOVD EDR Killer and Ransomware Delivered Via Fake Resumes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:52:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Canada #corporate espionage #EDR Killer #GOLD BLADE #QWCrypt Ransomware #Recruitment Lure #RedCurl #RedWolf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:52:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Canada #corporate espionage #EDR Killer #GOLD BLADE #QWCrypt Ransomware #Recruitment Lure #RedCurl #RedWolf
Daily CyberSecurity
GOLD BLADE APT Hits Canadian Firms with BYOVD EDR Killer and Ransomware Delivered Via Fake Resumes
GOLD BLADE (RedCurl) targets Canadian firms (80% of attacks) with espionage and QWCrypt ransomware. The group uses fake resumes and a BYOVD EDR killer (Zemana driver) to disable security controls.