⤷ Title: Beyond Authentication — Exploiting a Nasty IDOR in Profile Update Functionality
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:57:05 GMT
════════════════════════
⌗ Tags: #programming #infosec #bug_bounty #cybersecurity #technology
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:57:05 GMT
════════════════════════
⌗ Tags: #programming #infosec #bug_bounty #cybersecurity #technology
Medium
Beyond Authentication — Exploiting a Nasty IDOR in Profile Update Functionality
It wasn’t a complex SQL injection or a tricky deserialization flaw. It was a failure to ask one simple question: “Are you really…
⤷ Title: Highest Paying Cyber Security Jobs In 2025
════════════════════════
𐀪 Author: Muhammad Haider Tallal
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:55:14 GMT
════════════════════════
⌗ Tags: #careers #infosec #cybersecurity #ciso #cloud_security
════════════════════════
𐀪 Author: Muhammad Haider Tallal
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:55:14 GMT
════════════════════════
⌗ Tags: #careers #infosec #cybersecurity #ciso #cloud_security
Medium
Highest Paying Cyber Security Jobs In 2025
How the top 5% break into premium roles
⤷ Title: TRYHACKME AOC 2025 Phishing — Phishmas Greetings Writeup
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:19:33 GMT
════════════════════════
⌗ Tags: #aoc2025 #tryhackme_writeup #tryhackme_walkthrough #phishing #tryhackme
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:19:33 GMT
════════════════════════
⌗ Tags: #aoc2025 #tryhackme_writeup #tryhackme_walkthrough #phishing #tryhackme
Medium
TRYHACKME AOC 2025 Phishing — Phishmas Greetings Writeup
Learn how to spot phishing emails from Malhare’s Eggsploit Bunnies sent to TBFC users.
⤷ Title: TryHackMe — Block Writeup
════════════════════════
𐀪 Author: Edward Nathanael
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:16:11 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #cybersecurity
════════════════════════
𐀪 Author: Edward Nathanael
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:16:11 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #cybersecurity
Medium
TryHackMe — Block Writeup
writeup for the TryHackMe room BLOCK
⤷ Title: React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:49:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #crypto mining #CVE_2025_55182 #Espionage #GTIG #rce #React Server Components #React2Shell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:49:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #crypto mining #CVE_2025_55182 #Espionage #GTIG #rce #React Server Components #React2Shell #zero_day
Daily CyberSecurity
React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
A critical RCE (CVSS 10.0) in React Server Components (CVE-2025-55182) is under widespread exploitation by China-nexus groups deploying MINOCAT and HISONIC backdoors, plus XMRig miners.
⤷ Title: Beyond Authentication — Exploiting a Nasty IDOR in Profile Update Functionality
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:57:06 GMT
════════════════════════
⌗ Tags: #programming #infosec #bug_bounty #cybersecurity #technology
════════════════════════
𐀪 Author: Munna✨
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:57:06 GMT
════════════════════════
⌗ Tags: #programming #infosec #bug_bounty #cybersecurity #technology
Medium
Beyond Authentication — Exploiting a Nasty IDOR in Profile Update Functionality
It wasn’t a complex SQL injection or a tricky deserialization flaw. It was a failure to ask one simple question: “Are you really…
⤷ Title: From Recon to RCE: Hunting React2Shell (CVE-2025–55182) for Bug Bounties
════════════════════════
𐀪 Author: coffinxp
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:53:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bug_bounty #technology #react
════════════════════════
𐀪 Author: coffinxp
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 07:53:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bug_bounty #technology #react
Medium
From Recon to RCE: Hunting React2Shell (CVE-2025–55182) for Bug Bounties
A step-by-step walkthrough covering discovery, validation and real-world exploitation in React and Next.js applications
⤷ Title: Bug Bounty from Zero: A Realistic Beginner’s Guide
════════════════════════
𐀪 Author: Shruthilaya
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:44:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #information_security #bug_bounty_tips #beginners_guide
════════════════════════
𐀪 Author: Shruthilaya
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:44:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #information_security #bug_bounty_tips #beginners_guide
Medium
Bug Bounty from Zero: A Realistic Beginner’s Guide
Most people want to start bug bounty because it sounds exciting. All those hacking, bounties, recognition. But most people also quit within…
⤷ Title: SOC Prime and the Sigma Standard
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:24:59 GMT
════════════════════════
⌗ Tags: #cyber_defense #cybersecurity #cybercrime #sigma_rules #hacking
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:24:59 GMT
════════════════════════
⌗ Tags: #cyber_defense #cybersecurity #cybercrime #sigma_rules #hacking
Medium
SOC Prime and the Sigma Standard
SOC Prime and the Sigma Standard The Era of Pre-Standardization For the better part of the early 21st century, the cybersecurity industry — specifically within Security Operations Centers (SOCs) …
⤷ Title: Whoami ?
════════════════════════
𐀪 Author: DrXpl0iT
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:01:20 GMT
════════════════════════
⌗ Tags: #hacking #introduction #cybersecurity #who_am_i #ethical_hacking
════════════════════════
𐀪 Author: DrXpl0iT
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:01:20 GMT
════════════════════════
⌗ Tags: #hacking #introduction #cybersecurity #who_am_i #ethical_hacking
Medium
Whoami ?
Whoami ? — AN INTRODUCTION
⤷ Title: Authentication vs Authorization: One Story You’ll Never Forget
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:48:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #authentication #infosec #authorization
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:48:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #authentication #infosec #authorization
Medium
Authentication vs Authorization: One Story You’ll Never Forget
The Problem Everyone Has 😅
⤷ Title: Year-End Bumper Sale: OSCP + OSEP Training Only
════════════════════════
𐀪 Author: Manisha Chaudhary
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:41:38 GMT
════════════════════════
⌗ Tags: #cyber #cybersecurity #cyber_security_awareness #sales #penetration_testing
════════════════════════
𐀪 Author: Manisha Chaudhary
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:41:38 GMT
════════════════════════
⌗ Tags: #cyber #cybersecurity #cyber_security_awareness #sales #penetration_testing
Medium
Year-End Bumper Sale: OSCP + OSEP Training Only
Get ready to take your cybersecurity career to the next level with Craw Security’s exclusive offer allows you to enroll in the Year-End…
⤷ Title: Try Hack Me- Blaster Walkthrough
════════════════════════
𐀪 Author: Herrfuhrer
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:23:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_walkthrough #tryhackme #penetration_testing #tryhackme_writeup
════════════════════════
𐀪 Author: Herrfuhrer
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:23:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_walkthrough #tryhackme #penetration_testing #tryhackme_writeup
Medium
Try Hack Me- Blaster Walkthrough
Let’s do it!!!
⤷ Title: TryHackMe: Startup Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:43:23 GMT
════════════════════════
⌗ Tags: #information_security #tryhackme #pentesting #cybersecurity
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 09:43:23 GMT
════════════════════════
⌗ Tags: #information_security #tryhackme #pentesting #cybersecurity
Medium
TryHackMe: Startup Writeup
This is an easy-difficulty ranked box, it involves us uploading a reverse shell via FTP anonymous login and escalating privileges by…
⤷ Title: OWASP API Security Top 10–2 | TryHackMe Walkthrough
════════════════════════
𐀪 Author: Yogesh Mishra
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:22:09 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #tryhackme_writeup #owasp_top_10 #owasp
════════════════════════
𐀪 Author: Yogesh Mishra
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 08:22:09 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #tryhackme_writeup #owasp_top_10 #owasp
Medium
OWASP API Security Top 10–2 | TryHackMe Walkthrough
Task 1 | Quick Recap
⤷ Title: LazyHook: New Framework Uses Hardware Breakpoints to Bypass EDR Stealthily
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:39:52 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #cybersecurity #EDR evasion #Hardware Breakpoint #Hooking #LazyHook #Stealth #System Call Interception #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:39:52 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #cybersecurity #EDR evasion #Hardware Breakpoint #Hooking #LazyHook #Stealth #System Call Interception #Windows Security
Penetration Testing Tools
LazyHook: New Framework Uses Hardware Breakpoints to Bypass EDR Stealthily
LazyHook is a new open-source framework using hardware breakpoints and SEH to intercept system calls and execute code stealthily, bypassing memory integrity and EDR checks.
⤷ Title: Next-Gen Malware: EtherRAT Uses Ethereum Smart Contract for Stealth C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:38:12 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #C2 #CVE_2025_55182 #cybersecurity #Ethereum #EtherRAT #Node.js #React2Shell #Remote Access Trojan #Smart Contract #Sysdig
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:38:12 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #C2 #CVE_2025_55182 #cybersecurity #Ethereum #EtherRAT #Node.js #React2Shell #Remote Access Trojan #Smart Contract #Sysdig
Penetration Testing Tools
Next-Gen Malware: EtherRAT Uses Ethereum Smart Contract for Stealth C2
The emergence of a new malicious tool within the React2Shell attack chain has become a notable development amid
⤷ Title: Fileless Evasion: Multi-Stage Campaign Deploys NetSupport RAT via Obfuscated HTA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:36:59 +0000
════════════════════════
⌗ Tags: #Malware #Corporate Attack #cybersecurity #Fileless Malware #HTA #JavaScript #NetSupport RAT #PowerShell #Remote Access Trojan #Securonix
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:36:59 +0000
════════════════════════
⌗ Tags: #Malware #Corporate Attack #cybersecurity #Fileless Malware #HTA #JavaScript #NetSupport RAT #PowerShell #Remote Access Trojan #Securonix
Penetration Testing Tools
Fileless Evasion: Multi-Stage Campaign Deploys NetSupport RAT via Obfuscated HTA
Researchers at Securonix have uncovered a multi-layered malware campaign designed to surreptitiously deploy the NetSupport RAT remote access
⤷ Title: Unpatched .NET RCE Flaw Lets Attackers Write Files via SOAP—Microsoft Blames Developers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #.NET #Arbitrary File Write #Black Hat Europe #cybersecurity #Microsoft #Piotr Bazydło #RCE #SOAP #SoapHttpClientProtocol #WSDL
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #.NET #Arbitrary File Write #Black Hat Europe #cybersecurity #Microsoft #Piotr Bazydło #RCE #SOAP #SoapHttpClientProtocol #WSDL
Penetration Testing Tools
Unpatched .NET RCE Flaw Lets Attackers Write Files via SOAP—Microsoft Blames Developers
Security researchers have disclosed a .NET vulnerability that could affect a wide range of enterprise products and lead
⤷ Title: 700+ Instances Hacked: Gogs Zero-Day CVE-2025-8110 Under Active Exploitation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:32:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_8110 #cybersecurity #Git Service #Gogs #RCE #remote code execution #Supershell #Symbolic Link #Wiz #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:32:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_8110 #cybersecurity #Git Service #Gogs #RCE #remote code execution #Supershell #Symbolic Link #Wiz #zero_day
Penetration Testing Tools
700+ Instances Hacked: Gogs Zero-Day CVE-2025-8110 Under Active Exploitation
Attackers are actively exploiting a newly discovered zero-day vulnerability in Gogs—a widely used self-hosted Git service—for which no
⤷ Title: DeadLock Ransomware Uses BYOVD to Kill EDR and Erase Backups Stealthily
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:31:13 +0000
════════════════════════
⌗ Tags: #Malware #Baidu Driver #BYOVD #Cisco Talos #CVE_2024_51324 #cybersecurity #DeadLock Ransomware #EDR Kill #Ransomware_as_a_Service #Session Messenger
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:31:13 +0000
════════════════════════
⌗ Tags: #Malware #Baidu Driver #BYOVD #Cisco Talos #CVE_2024_51324 #cybersecurity #DeadLock Ransomware #EDR Kill #Ransomware_as_a_Service #Session Messenger
Penetration Testing Tools
DeadLock Ransomware Uses BYOVD to Kill EDR and Erase Backups Stealthily
Cisco Talos has uncovered a new DeadLock ransomware campaign in which attackers exploit a vulnerable Baidu Antivirus driver