⤷ Title: CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:44:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@adonisjs/bodyparser #AdonisJS #Arbitrary File Write #CVE_2026_21440 #Cyber Security #File Upload Vulnerability #Node.js #Patch Alert #Path Traversal #rce #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:44:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@adonisjs/bodyparser #AdonisJS #Arbitrary File Write #CVE_2026_21440 #Cyber Security #File Upload Vulnerability #Node.js #Patch Alert #Path Traversal #rce #web development
Daily CyberSecurity
CVE-2026-21440: New AdonisJS 9.2 Critical Flaw Allows Arbitrary File Writes and RCE
CVE-2026-21440: A critical 9.2 flaw in AdonisJS file uploads allows attackers to overwrite system files and gain RCE. Update to v10.1.2 immediately!
⤷ Title: “Sliver” in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:40:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Bangladesh #Bangladesh Airforce #c0baltstrik3d #CVE_2025_55182 #cyber_espionage #Edge Security #Fast Reverse Proxy #FortiWeb #FRP #Pakistan #React2Shell #Sliver C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:40:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Bangladesh #Bangladesh Airforce #c0baltstrik3d #CVE_2025_55182 #cyber_espionage #Edge Security #Fast Reverse Proxy #FortiWeb #FRP #Pakistan #React2Shell #Sliver C2
Daily CyberSecurity
"Sliver" in the Stack: Exposed Logs Reveal Targeted FortiWeb Exploitation Campaign
Threat actor uses React2Shell to deploy Sliver C2 on FortiWeb devices, using a Bangladesh Airforce decoy to target govt and financial sectors.
⤷ Title: The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:32:07 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Cybercrime #Discord #Discord Injection #Infostealer #Obfuscation #Pyarmor #Python Malware #Session Hijacking #Telegram #Unit 42 #VVS Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:32:07 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Cybercrime #Discord #Discord Injection #Infostealer #Obfuscation #Pyarmor #Python Malware #Session Hijacking #Telegram #Unit 42 #VVS Stealer
Daily CyberSecurity
The Invisible Predator: How VVS Stealer Abuses Pyarmor to Ghost Discord Accounts
Unit 42 unmasks VVS Stealer, a Python-based threat using Pyarmor obfuscation to bypass AV, hijack Discord sessions, and steal browser credentials.
⤷ Title: CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:28:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2025_66848 #firmware update #JD Cloud #Joylink API #NAS #rce #Remote Code Execution #root access #router security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:28:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Command Injection #CVE_2025_66848 #firmware update #JD Cloud #Joylink API #NAS #rce #Remote Code Execution #root access #router security
Daily CyberSecurity
CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access
JD Cloud alerts users to CVE-2025-66848, a 9.8 critical flaw allowing remote attackers to bypass auth and gain root access on NAS routers.
⤷ Title: Transparent Tribe Weaponizes “JLPT” Tests in New Cyber-Espionage Campaign Against India
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:22:18 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT36 #cyber_espionage #Cyfirma #Fileless Malware #India #JLPT #LNK malware #MSHTA #Pakistan_linked #rat #Remote Access Trojan #Transparent Tribe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:22:18 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT36 #cyber_espionage #Cyfirma #Fileless Malware #India #JLPT #LNK malware #MSHTA #Pakistan_linked #rat #Remote Access Trojan #Transparent Tribe
Daily CyberSecurity
Transparent Tribe Weaponizes "JLPT" Tests in New Cyber-Espionage Campaign Against India
CYFIRMA unmasks APT36's latest campaign: a fake JLPT exam lure using fileless LNK malware to evade antivirus and spy on Indian government targets.
⤷ Title: New WordPress Phishing Scam Steals Credit Cards via Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #3_D Secure bypass #Anurag #credit card theft #cyber fraud #DMARC #Domain Renewal Scam #Exfiltration #OTP Harvesting #phishing #soyfix[.]com #Telegram bot #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:17:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #3_D Secure bypass #Anurag #credit card theft #cyber fraud #DMARC #Domain Renewal Scam #Exfiltration #OTP Harvesting #phishing #soyfix[.]com #Telegram bot #wordpress
Daily CyberSecurity
New WordPress Phishing Scam Steals Credit Cards via Telegram
Researcher Anurag uncovers a WordPress phishing campaign that steals credit cards and 3-D Secure OTPs, exfiltrating data directly via Telegram bots.
⤷ Title: Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:11:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Christmas Eve Alert #CVE_2025_59887 #CVE_2025_59888 #DLL hijacking #Eaton #infosec #Power Management #rce #Remote Code Execution #Unquoted Search Path #UPS Companion #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:11:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Christmas Eve Alert #CVE_2025_59887 #CVE_2025_59888 #DLL hijacking #Eaton #infosec #Power Management #rce #Remote Code Execution #Unquoted Search Path #UPS Companion #Vulnerability
Daily CyberSecurity
Eaton UPS Software Flaws Expose Systems to High-Risk Code Execution
Eaton warns of critical 8.6 severity flaws in UPS Companion software (CVE-2025-59887 & 59888). Upgrade to v3.0 now to prevent hijacking!
⤷ Title: The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
Daily CyberSecurity
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
Koi Security unmasks DarkSpectre, a Chinese threat group that used 300+ browser extensions to spy on 8.8M users and steal corporate meeting data.
⤷ Title: Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #Ananda Dhakal #CVE_2025_61922 #e_commerce security #paypal #PII Leak #PrestaShop #PS Checkout #Session Hijacking #Web Vulnerability #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #Ananda Dhakal #CVE_2025_61922 #e_commerce security #paypal #PII Leak #PrestaShop #PS Checkout #Session Hijacking #Web Vulnerability #Zero_Click
Daily CyberSecurity
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
PrestaShop patches a 9.1 critical flaw (CVE-2025-61922) in the Checkout module. Attackers can hijack accounts via email. PoC available.
⤷ Title: QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_59384 #CVE_2025_59387 #cybersecurity #Data Protection #Mac Security #MARS #NAS #Path Traversal #Qfiling #QNAP #security #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_59384 #CVE_2025_59387 #cybersecurity #Data Protection #Mac Security #MARS #NAS #Path Traversal #Qfiling #QNAP #security #sql injection
Daily CyberSecurity
QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
QNAP patches high-severity flaws (CVSS 8.1) in Qfiling and MARS that allow data theft and code injection. Secure your NAS by updating to the latest versions!
⤷ Title: How Our Agent Extracted a System Prompt Using Base64
════════════════════════
𐀪 Author: Daniel Knight
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:56:05 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #llm #cybersecurity #prompt_injection_attack
════════════════════════
𐀪 Author: Daniel Knight
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:56:05 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #llm #cybersecurity #prompt_injection_attack
Medium
How Our Agent Extracted a System Prompt Using Base64
Daniel Knight, CEO at Vulnetic
⤷ Title: The Great Disappearing Act -TryHackMe Writeup
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:10:25 GMT
════════════════════════
⌗ Tags: #writeup #tryhackme #thegreatdisappearingac #ctf_walkthrough #tryhackme_walkthrough
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:10:25 GMT
════════════════════════
⌗ Tags: #writeup #tryhackme #thegreatdisappearingac #ctf_walkthrough #tryhackme_walkthrough
Medium
The Great Disappearing Act -TryHackMe Writeup
Hard-rated THM Room Writeup
⤷ Title: HTB Labs : Spookifier | Web Exploitation Write-up
════════════════════════
𐀪 Author: Alexander Sapo
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 01:44:43 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #ssti_vulnerability #owasp_top_10 #ctf_writeup #web_hacking
════════════════════════
𐀪 Author: Alexander Sapo
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 01:44:43 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #ssti_vulnerability #owasp_top_10 #ctf_writeup #web_hacking
Medium
HTB Labs : Spookifier | Web Exploitation
Category: Web
⤷ Title: CPTS — HackTheBox: Password Attacks — Attacking Active Directory and NTDS.dit
════════════════════════
𐀪 Author: Daniel Hruska
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 20:10:22 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox_walkthrough #hackthebox
════════════════════════
𐀪 Author: Daniel Hruska
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 20:10:22 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox_walkthrough #hackthebox
⤷ Title: DbgNexum: Shellcode injection using the Windows Debugging API
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:32:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:32:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
Penetration Testing Tools
DbgNexum: Shellcode injection using the Windows Debugging API
DbgNexum is a 2026 PoC that uses Hardware Breakpoints and File Mapping to inject shellcode without standard APIs, making it invisible to most EDRs.
⤷ Title: The End of Offline: Microsoft Silently Kills Phone Activation After 24 Years
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:28:15 +0000
════════════════════════
⌗ Tags: #Windows #Air_Gapped Security #Ben Kleinberg #Microsoft #Microsoft Account #Office Activation #Offline Setup #Phone Activation #Windows 10 #Windows 11 #Windows 7
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:28:15 +0000
════════════════════════
⌗ Tags: #Windows #Air_Gapped Security #Ben Kleinberg #Microsoft #Microsoft Account #Office Activation #Offline Setup #Phone Activation #Windows 10 #Windows 11 #Windows 7
Penetration Testing Tools
The End of Offline: Microsoft Silently Kills Phone Activation After 24 Years
Microsoft has definitively abandoned phone-based activation for Windows and Office. Although the company still references this method in
⤷ Title: Hack or Honeypot? ShinyHunters Claims Victory While Resecurity Claims a Masterful Trap
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:26:28 +0000
════════════════════════
⌗ Tags: #Data Leak #Cyber Espionage #data breach #HoneyPot #InfoSec 2026 #LAPSUS$ #Mattermost #Resecurity #Scattered Spider #ShinyHunters #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:26:28 +0000
════════════════════════
⌗ Tags: #Data Leak #Cyber Espionage #data breach #HoneyPot #InfoSec 2026 #LAPSUS$ #Mattermost #Resecurity #Scattered Spider #ShinyHunters #threat intelligence
Penetration Testing Tools
Hack or Honeypot? ShinyHunters Claims Victory While Resecurity Claims a Masterful Trap
The hacking group known as ShinyHunters has claimed responsibility for breaching the infrastructure of Resecurity and exfiltrating internal
⤷ Title: The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:25:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #DoNot Group #InfoSec 2026 #MSBuild #Pakistan Defense #Patchwork APT #Python RAT #QiAnXin #Spyder Malware #StreamSpy #WebSocket C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:25:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #DoNot Group #InfoSec 2026 #MSBuild #Pakistan Defense #Patchwork APT #Python RAT #QiAnXin #Spyder Malware #StreamSpy #WebSocket C2
Penetration Testing Tools
The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
The hacking group known as Patchwork—also referred to as Dropping Elephant and Maha Grass—has once again come under
⤷ Title: The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:23:01 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Malware #Corporate Espionage #DarkSpectre #GhostPoster #InfoSec 2026 #Koi Security #ShadyPanda #Steganography #Zoom Stealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:23:01 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Malware #Corporate Espionage #DarkSpectre #GhostPoster #InfoSec 2026 #Koi Security #ShadyPanda #Steganography #Zoom Stealer
Penetration Testing Tools
The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
A hacking group operating under the name DarkSpectre has, for seven years, systematically infected the computers of users
⤷ Title: The Adaptive Spy: Transparent Tribe’s New RAT Outsmarts Antivirus to Target India
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:21:48 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Evasion #APT36 #Cyber Espionage #CYFIRMA #India #InfoSec 2026 #malware #phishing #RAT #Transparent Tribe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:21:48 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Evasion #APT36 #Cyber Espionage #CYFIRMA #India #InfoSec 2026 #malware #phishing #RAT #Transparent Tribe
Penetration Testing Tools
The Adaptive Spy: Transparent Tribe’s New RAT Outsmarts Antivirus to Target India
The hacking group known as Transparent Tribe has launched a new wave of cyber-espionage operations targeting government bodies,
⤷ Title: The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:20:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Theft #DevOps Security #Github #InfoSec 2026 #JavaScript #malware #npm #Shai_Hulud #supply chain attack #Trust Wallet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:20:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Theft #DevOps Security #Github #InfoSec 2026 #JavaScript #malware #npm #Shai_Hulud #supply chain attack #Trust Wallet
Penetration Testing Tools
The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet
A large-scale supply chain compromise known as Shai-Hulud has been linked to the recent theft of approximately USD