⤷ Title: Why Your Employees Are Your Biggest Security Risk (And How Hackers Know It)
════════════════════════
𐀪 Author: Dhanush N
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 14:25:52 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #employees #social_engineering #ethical_hacking
════════════════════════
𐀪 Author: Dhanush N
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 14:25:52 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #employees #social_engineering #ethical_hacking
Medium
Why Your Employees Are Your Biggest Security Risk (And How Hackers Know It)
Dark art of social engineering: where a simple “urgent” email can cost your company millions
⤷ Title: My first test: Firewall & Network Troubleshooting
════════════════════════
𐀪 Author: Oluwadamilare Adeosun
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:54:21 GMT
════════════════════════
⌗ Tags: #writing #infosec #cybersecurity #technology #medium
════════════════════════
𐀪 Author: Oluwadamilare Adeosun
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:54:21 GMT
════════════════════════
⌗ Tags: #writing #infosec #cybersecurity #technology #medium
Medium
My first test: Firewall & Network Troubleshooting
I thought that everything will be smooth after deploying the lab, then i decided to do a mini exercise but i found out that there are…
⤷ Title: Your Security Scanner Misses 97% of AI-Generated Backdoors
════════════════════════
𐀪 Author: AhmedAbdelmenem
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:50:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #technology #supply_chain_security #ai_security
════════════════════════
𐀪 Author: AhmedAbdelmenem
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:50:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #technology #supply_chain_security #ai_security
Medium
Your Security Scanner Misses 97% of AI-Generated Backdoors
Research shows even specialized detection tools fail — and every sprint ships vulnerable code to production
⤷ Title: From Abstract to Acumen — Anatomy of a Modern BEC Attack
════════════════════════
𐀪 Author: Cyb3rhawk
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:22:36 GMT
════════════════════════
⌗ Tags: #threat_hunting #infosec #blue_team #cbse #microsoft_365
════════════════════════
𐀪 Author: Cyb3rhawk
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:22:36 GMT
════════════════════════
⌗ Tags: #threat_hunting #infosec #blue_team #cbse #microsoft_365
Medium
From Abstract to Acumen — Anatomy of a Modern BEC Attack
During a recent threat hunt, I investigated a BEC campaign that moved from a standard credential phish to OAuth persistence using a…
⤷ Title: Documenting My Journey Into Penetration Testing
════════════════════════
𐀪 Author: Written by k41r0s3
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:40:49 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Written by k41r0s3
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:40:49 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing
Medium
Documenting My Journey Into Penetration Testing
It all started with a question I couldn’t answer: “What do you actually want to be?” Fresh out of university, I had projects spanning cloud
⤷ Title: When Frontend Assumptions Break: Observing Server-Side Command Execution in React & Next.js
════════════════════════
𐀪 Author: Shikhar Sinha
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:18:12 GMT
════════════════════════
⌗ Tags: #ethical_hacking #nodejs #react #nextjs #penetration_testing
════════════════════════
𐀪 Author: Shikhar Sinha
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:18:12 GMT
════════════════════════
⌗ Tags: #ethical_hacking #nodejs #react #nextjs #penetration_testing
Medium
When Frontend Assumptions Break: Observing Server-Side Command Execution in React & Next.js
⚠️[CVE-2025–55182]⚠️
⤷ Title: OWASP Top 10 2025: IAAA Failures — TryHackMe Walkthrough
════════════════════════
𐀪 Author: farshad moradi shahrbabak
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:29:39 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #ctf #cybersecurity #owasp
════════════════════════
𐀪 Author: farshad moradi shahrbabak
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 15:29:39 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #ctf #cybersecurity #owasp
Medium
OWASP Top 10 2025: IAAA Failures — TryHackMe Walkthrough
You can learn in depth about the OWASP Top 10 and the OWASP Top 10 (2025) through this article: In a World Full of Vulnerabilities, OWASP…
⤷ Title: Web Challenge: Bypassing Login with a Hidden Dev Header
════════════════════════
𐀪 Author: vulnhunter
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 14:23:04 GMT
════════════════════════
⌗ Tags: #social_media #ctf #ethical_hacking #cybersecurity #web_development
════════════════════════
𐀪 Author: vulnhunter
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 14:23:04 GMT
════════════════════════
⌗ Tags: #social_media #ctf #ethical_hacking #cybersecurity #web_development
Medium
Web Challenge: Bypassing Login with a Hidden Dev Header
When solving web challenges in CTFs, sometimes the vulnerability isn’t complex crypto or heavy exploitation — it’s developer mistakes left…
⤷ Title: Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:05:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:05:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 21:09:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 21:09:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:55:38 +0000
════════════════════════
⌗ Tags: #Security #0day #Amazon #APT44 #AWS #Curly COMrades #Cyber Attack #Cyber Crime #Cybersecurity #GRU #Malware #Russia #Sandworm #Seashell Blizzard #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:55:38 +0000
════════════════════════
⌗ Tags: #Security #0day #Amazon #APT44 #AWS #Curly COMrades #Cyber Attack #Cyber Crime #Cybersecurity #GRU #Malware #Russia #Sandworm #Seashell Blizzard #Vulnerability
Hackread
Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: You Are Awesome PDF! (SSRF VM Challenge)
════════════════════════
𐀪 Author: Josh Beck
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:44:53 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Josh Beck
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:44:53 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #bug_bounty
Medium
You Are Awesome PDF! (SSRF VM Challenge)
Lab Objective:
⤷ Title: ️♂️ The Dark Web Knew Before the Company Did: Finding a Bug Using Leaked Chatter
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:39:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #bug_bounty_tips #infosec #bug_bounty
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:39:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #bug_bounty_tips #infosec #bug_bounty
Medium
🕵️♂️🌑 The Dark Web Knew Before the Company Did: Finding a Bug Using Leaked Chatter
Free Link 🎈
⤷ Title: Raccoons and the Importance of Logging…In Our Applications!
════════════════════════
𐀪 Author: Jen Cracchiola
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:40:27 GMT
════════════════════════
⌗ Tags: #application_development #software_development #application_security #software_engineering #owasp
════════════════════════
𐀪 Author: Jen Cracchiola
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:40:27 GMT
════════════════════════
⌗ Tags: #application_development #software_development #application_security #software_engineering #owasp
Medium
Raccoons and the Importance of Logging…In Our Applications!
I wrote an article titled “Vulnerability Highlight: Beavers, Insufficient Logging and Monitoring,” and we learned about Insufficient…
⤷ Title: Business logic vulnerabilities (İş mantığı zafiyetleri)
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:44:56 GMT
════════════════════════
⌗ Tags: #pentesting #web3 #hacking #portswigger #web_penetration_testing
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:44:56 GMT
════════════════════════
⌗ Tags: #pentesting #web3 #hacking #portswigger #web_penetration_testing
Medium
Business logic vulnerabilities (İş mantığı zafiyetleri)
Bu bölümde, iş mantığı zafiyetleri kavramını tanıtacağız ve bu zafiyetlerin, kullanıcı davranışları hakkında yapılan hatalı varsayımlar…
⤷ Title: Lab: User ID controlled by request parameter, with unpredictable user IDs
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:12:14 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #ctf #portswigger #ctf_writeup #hacking
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:12:14 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #ctf #portswigger #ctf_writeup #hacking
Medium
Lab: User ID controlled by request parameter, with unpredictable user IDs
Bu labda, kullanıcı hesap sayfasında yatay yetki yükseltme zafiyeti bulunuyor ancak kullanıcılar GUID değerleriyle tanımlanıyor. Amaç…
⤷ Title: CVE‑2025‑66516: Critical XXE in Apache Tika (PDF Uploads at Risk)
════════════════════════
𐀪 Author: vinod
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:15:26 GMT
════════════════════════
⌗ Tags: #devops #security #cyber #infosec #cve
════════════════════════
𐀪 Author: vinod
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:15:26 GMT
════════════════════════
⌗ Tags: #devops #security #cyber #infosec #cve
Medium
CVE‑2025‑66516: Critical XXE in Apache Tika (PDF Uploads at Risk)
CVE‑2025‑66516 is a maximum‑severity XXE vulnerability in Apache Tika that lets attackers weaponize PDFs with malicious XFA content to…
⤷ Title: PortSwigger Lab Write‑Up: Automating Gift Card Redemption via Checkout Workflow Exploit
════════════════════════
𐀪 Author: Anas Elsaba
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:16:53 GMT
════════════════════════
⌗ Tags: #portswigger #web_penetration_testing #cybersecurity #python #penetration_testing
════════════════════════
𐀪 Author: Anas Elsaba
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:16:53 GMT
════════════════════════
⌗ Tags: #portswigger #web_penetration_testing #cybersecurity #python #penetration_testing
Medium
🔐 PortSwigger Lab Write‑Up: Automating Gift Card Redemption via Checkout Workflow Exploit
Honestly, I was too lazy to make a detailed write‑up this time, so I’m just sharing the script I used.
⤷ Title: Advent of Cyber 2025 Day 16 | TryHackMe | Forensics — Registry Furensics | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:45:27 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #tryhackme #tryhackme_walkthrough #tryhackme_writeup
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:45:27 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #tryhackme #tryhackme_walkthrough #tryhackme_writeup
Medium
Advent of Cyber 2025 Day 16 | TryHackMe | Forensics — Registry Furensics | WriteUp
Learn what the Windows Registry is and how to investigate it
⤷ Title: Advent of Cyber 2025|Day 16| Web Forensics — Registry Furensics TryhackMe
════════════════════════
𐀪 Author: Md Amjad
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:39:44 GMT
════════════════════════
⌗ Tags: #webforensics_registry #advent_of_cyber_2025 #tryhackme #16days
════════════════════════
𐀪 Author: Md Amjad
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 16:39:44 GMT
════════════════════════
⌗ Tags: #webforensics_registry #advent_of_cyber_2025 #tryhackme #16days
Medium
Advent of Cyber 2025|Day 16| Web Forensics — Registry Furensics TryhackMe
Learn what the Windows Registry is and how to investigate it.
⤷ Title: LFI to RCE via Log Poisoning: A Hands-On Exploit Guide
════════════════════════
𐀪 Author: Raj Prasad Kuiri
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 19:41:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #cybersecurity #information_security #security
════════════════════════
𐀪 Author: Raj Prasad Kuiri
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 19:41:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #cybersecurity #information_security #security
Medium
LFI to RCE via Log Poisoning: A Hands-On Exploit Guide
Hey everyone, in this blog, we will see how to identify RCE via LFI using manual and automated approaches. So let’s begin