⤷ Title: The Right Methodology for Hacking Anything
════════════════════════
𐀪 Author: Cybernight
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:21:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #penetration_testing #hacking #ai
════════════════════════
𐀪 Author: Cybernight
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:21:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #penetration_testing #hacking #ai
Medium
The Right Methodology for Hacking Anything
Almost every hacker has been there at some point — staring at a target and wondering, “Am I even good enough?” That doubt is normal…
⤷ Title: Securing API Servers (Week 4)
════════════════════════
𐀪 Author: Stella Obatoye
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 21:04:24 GMT
════════════════════════
⌗ Tags: #api_security #cors #application_security #cybersecurity #api_server
════════════════════════
𐀪 Author: Stella Obatoye
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 21:04:24 GMT
════════════════════════
⌗ Tags: #api_security #cors #application_security #cybersecurity #api_server
Medium
Securing API Servers (Week 4)
In Week 4, I took the Securing API Servers course on APISEC University.
⤷ Title: Breaking vm2 Isolation in n8n via Exposed Global Helpers (CVE-2025–68697)
════════════════════════
𐀪 Author: Berk Dedekargınoğlu
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:56:36 GMT
════════════════════════
⌗ Tags: #red_team #vulnerability #cybersecurity #information_security #application_security
════════════════════════
𐀪 Author: Berk Dedekargınoğlu
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:56:36 GMT
════════════════════════
⌗ Tags: #red_team #vulnerability #cybersecurity #information_security #application_security
Medium
Breaking vm2 Isolation in n8n via Exposed Global Helpers (CVE-2025–68697)
Introduction
⤷ Title: The Worm That Eats the Supply Chain: Deconstructing Shai-Hulud
════════════════════════
𐀪 Author: The GlassBox Security
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:56:21 GMT
════════════════════════
⌗ Tags: #application_security #supply_chain #shai_hulud #supply_chain_security #open_source
════════════════════════
𐀪 Author: The GlassBox Security
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:56:21 GMT
════════════════════════
⌗ Tags: #application_security #supply_chain #shai_hulud #supply_chain_security #open_source
Medium
The Worm That Eats the Supply Chain: Deconstructing Shai-Hulud
How a self-replicating NPM malware conquered the ecosystem — and why your CI/CD pipeline is the next victim.
⤷ Title: Sandbox Escape and Remote Code Execution in n8n Python Code Node (CVE-2025–68668)
════════════════════════
𐀪 Author: Berk Dedekargınoğlu
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:08:53 GMT
════════════════════════
⌗ Tags: #information_security #red_team #cybersecurity #vulnerability #application_security
════════════════════════
𐀪 Author: Berk Dedekargınoğlu
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:08:53 GMT
════════════════════════
⌗ Tags: #information_security #red_team #cybersecurity #vulnerability #application_security
Medium
Sandbox Escape and Remote Code Execution in n8n Python Code Node (CVE-2025–68668)
Introduction
⤷ Title: Infrared, Reflections, and Wires: Reading the Signs of Hidden Surveillance
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 21:06:00 GMT
════════════════════════
⌗ Tags: #infrared #surveillance #privacy #opsec #hacking
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 21:06:00 GMT
════════════════════════
⌗ Tags: #infrared #surveillance #privacy #opsec #hacking
Medium
Infrared, Reflections, and Wires: Reading the Signs of Hidden Surveillance
Spaces are never neutral. They contain histories, intentions, unseen observation. Walls, furniture, fixtures — they record and transmit…
⤷ Title: Cracking Passwords with John the Ripper: A Beginner’s Guide
════════════════════════
𐀪 Author: Madhu Sudhan
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:47:12 GMT
════════════════════════
⌗ Tags: #hacking #cracking #password_cracking #cybersecurity #john_the_ripper
════════════════════════
𐀪 Author: Madhu Sudhan
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 20:47:12 GMT
════════════════════════
⌗ Tags: #hacking #cracking #password_cracking #cybersecurity #john_the_ripper
Medium
Cracking Passwords with John the Ripper: A Beginner’s Guide
A step-by-step walkthrough for ethical hacking students.
⤷ Title: What You’ll Learn After Gaining Your 1'st Hacking Certifcate? | Certificated Hacker’s Roadmap #1
════════════════════════
𐀪 Author: NnFace
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 23:33:13 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #ethical_hacking #certification #ceh_certification
════════════════════════
𐀪 Author: NnFace
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 23:33:13 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #ethical_hacking #certification #ceh_certification
Medium
What You’ll Learn After Gaining Your 1'st Hacking Certifcate? | Certificated Hacker’s Roadmap #1
Greetings, Beautifull Hackers. There was a pretty long time brake, wasn’t it? Here I am to share one question that I’ve answered and it’s…
⤷ Title: Windows Malware Development Roadmap
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 23:00:29 GMT
════════════════════════
⌗ Tags: #malware #pentesting #red_team #cybersecurity #hacking
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 23:00:29 GMT
════════════════════════
⌗ Tags: #malware #pentesting #red_team #cybersecurity #hacking
Medium
Windows Malware Development Roadmap
Welcome to this Medium article! Unlike my previous posts that dive into specific malware development techniques, this one focuses on a…
⤷ Title: Chaos is the Name of this Congress
════════════════════════
𐀪 Author: A. J. Wyzinski
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 22:35:07 GMT
════════════════════════
⌗ Tags: #technology #ai #claude #society #hacking
════════════════════════
𐀪 Author: A. J. Wyzinski
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 22:35:07 GMT
════════════════════════
⌗ Tags: #technology #ai #claude #society #hacking
Medium
Chaos is the Name of this Congress
And it is probably one of the sanest meetings on tech around
⤷ Title: APPRENEZ LE NMAP: Exécutez des Scans Stratégiques avec Scripts et Automatisation
════════════════════════
𐀪 Author: Diego Rodrigues
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 21:58:41 GMT
════════════════════════
⌗ Tags: #virus #nmap #hacking #kali_linux #metasploit
════════════════════════
𐀪 Author: Diego Rodrigues
════════════════════════
ⴵ Time: Sun, 04 Jan 2026 21:58:41 GMT
════════════════════════
⌗ Tags: #virus #nmap #hacking #kali_linux #metasploit
Medium
APPRENEZ LE NMAP: Exécutez des Scans Stratégiques avec Scripts et Automatisation
#BestSeller #Amazon #France #Lesmeilleuresventes #Top10 en Certification en informatique et Internet
⤷ Title: Researcher Wipes White Supremacist Dating Sites, Leaks Data on okstupid.lol
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 01:36:49 +0000
════════════════════════
⌗ Tags: #Hacking News #Security #CCC #Cybersecurity #DDoSecrets #europe #Germany #HACKTIVISM #Martha Root #OkCupid #OkStupid #Vulnerability #WhiteChild #WhiteDate #WhiteDeal
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 01:36:49 +0000
════════════════════════
⌗ Tags: #Hacking News #Security #CCC #Cybersecurity #DDoSecrets #europe #Germany #HACKTIVISM #Martha Root #OkCupid #OkStupid #Vulnerability #WhiteChild #WhiteDate #WhiteDeal
Hackread
Researcher Wipes White Supremacist Dating Sites, Leaks Data on okstupid.lol
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:44:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@adonisjs/bodyparser #AdonisJS #Arbitrary File Write #CVE_2026_21440 #Cyber Security #File Upload Vulnerability #Node.js #Patch Alert #Path Traversal #rce #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:44:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@adonisjs/bodyparser #AdonisJS #Arbitrary File Write #CVE_2026_21440 #Cyber Security #File Upload Vulnerability #Node.js #Patch Alert #Path Traversal #rce #web development
Daily CyberSecurity
CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
CVE-2026-21440: A critical 9.2 flaw in AdonisJS file uploads allows attackers to overwrite system files and gain RCE. Update to v10.1.2 immediately!
⤷ Title: “Sliver” in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:40:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Bangladesh #Bangladesh Airforce #c0baltstrik3d #CVE_2025_55182 #cyber_espionage #Edge Security #Fast Reverse Proxy #FortiWeb #FRP #Pakistan #React2Shell #Sliver C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:40:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Bangladesh #Bangladesh Airforce #c0baltstrik3d #CVE_2025_55182 #cyber_espionage #Edge Security #Fast Reverse Proxy #FortiWeb #FRP #Pakistan #React2Shell #Sliver C2
Daily CyberSecurity
"Sliver" in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
Threat actor uses React2Shell to deploy Sliver C2 on FortiWeb devices, using a Bangladesh Airforce decoy to target govt and financial sectors.
⤷ Title: The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:32:07 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Cybercrime #Discord #Discord Injection #Infostealer #Obfuscation #Pyarmor #Python Malware #Session Hijacking #Telegram #Unit 42 #VVS Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:32:07 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Cybercrime #Discord #Discord Injection #Infostealer #Obfuscation #Pyarmor #Python Malware #Session Hijacking #Telegram #Unit 42 #VVS Stealer
Daily CyberSecurity
The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
Unit 42 unmasks VVS Stealer, a Python-based threat using Pyarmor obfuscation to bypass AV, hijack Discord sessions, and steal browser credentials.
⤷ Title: CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:28:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2025_66848 #firmware update #JD Cloud #Joylink API #NAS #rce #Remote Code Execution #root access #router security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:28:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2025_66848 #firmware update #JD Cloud #Joylink API #NAS #rce #Remote Code Execution #root access #router security
Daily CyberSecurity
CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
JD Cloud alerts users to CVE-2025-66848, a 9.8 critical flaw allowing remote attackers to bypass auth and gain root access on NAS routers.
⤷ Title: Transparent Tribe Weaponizes “JLPT” Tests in New Cyber-Espionage Campaign Against India
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:22:18 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT36 #cyber_espionage #Cyfirma #Fileless Malware #India #JLPT #LNK malware #MSHTA #Pakistan_linked #rat #Remote Access Trojan #Transparent Tribe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:22:18 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT36 #cyber_espionage #Cyfirma #Fileless Malware #India #JLPT #LNK malware #MSHTA #Pakistan_linked #rat #Remote Access Trojan #Transparent Tribe
Daily CyberSecurity
Transparent Tribe Weaponizes "JLPT" Tests in New Cyber-Espionage Campaign Against India
CYFIRMA unmasks APT36's latest campaign: a fake JLPT exam lure using fileless LNK malware to evade antivirus and spy on Indian government targets.
⤷ Title: New WordPress Phishing Scam Steals Credit Cards via Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #3_D Secure bypass #Anurag #credit card theft #cyber fraud #DMARC #Domain Renewal Scam #Exfiltration #OTP Harvesting #phishing #soyfix[.]com #Telegram bot #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #3_D Secure bypass #Anurag #credit card theft #cyber fraud #DMARC #Domain Renewal Scam #Exfiltration #OTP Harvesting #phishing #soyfix[.]com #Telegram bot #wordpress
Daily CyberSecurity
New WordPress Phishing Scam Steals Credit Cards via Telegram
Researcher Anurag uncovers a WordPress phishing campaign that steals credit cards and 3-D Secure OTPs, exfiltrating data directly via Telegram bots.
⤷ Title: Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:11:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Christmas Eve Alert #CVE_2025_59887 #CVE_2025_59888 #DLL hijacking #Eaton #infosec #Power Management #rce #Remote Code Execution #Unquoted Search Path #UPS Companion #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:11:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Christmas Eve Alert #CVE_2025_59887 #CVE_2025_59888 #DLL hijacking #Eaton #infosec #Power Management #rce #Remote Code Execution #Unquoted Search Path #UPS Companion #Vulnerability
Daily CyberSecurity
Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
Eaton warns of critical 8.6 severity flaws in UPS Companion software (CVE-2025-59887 & 59888). Upgrade to v3.0 now to prevent hijacking!
⤷ Title: The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
Daily CyberSecurity
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
Koi Security unmasks DarkSpectre, a Chinese threat group that used 300+ browser extensions to spy on 8.8M users and steal corporate meeting data.
⤷ Title: Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #Ananda Dhakal #CVE_2025_61922 #e_commerce security #paypal #PII Leak #PrestaShop #PS Checkout #Session Hijacking #Web Vulnerability #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #Ananda Dhakal #CVE_2025_61922 #e_commerce security #paypal #PII Leak #PrestaShop #PS Checkout #Session Hijacking #Web Vulnerability #Zero_Click
Daily CyberSecurity
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
PrestaShop patches a 9.1 critical flaw (CVE-2025-61922) in the Checkout module. Attackers can hijack accounts via email. PoC available.