⤷ Title: The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
Daily CyberSecurity
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
Koi Security unmasks DarkSpectre, a Chinese threat group that used 300+ browser extensions to spy on 8.8M users and steal corporate meeting data.
⤷ Title: Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #Ananda Dhakal #CVE_2025_61922 #e_commerce security #paypal #PII Leak #PrestaShop #PS Checkout #Session Hijacking #Web Vulnerability #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #Ananda Dhakal #CVE_2025_61922 #e_commerce security #paypal #PII Leak #PrestaShop #PS Checkout #Session Hijacking #Web Vulnerability #Zero_Click
Daily CyberSecurity
Zero-Click Hijack: The PrestaShop Checkout Flaw That Turns Emails Into Full Account Access, PoC Publishes
PrestaShop patches a 9.1 critical flaw (CVE-2025-61922) in the Checkout module. Attackers can hijack accounts via email. PoC available.
⤷ Title: QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_59384 #CVE_2025_59387 #cybersecurity #Data Protection #Mac Security #MARS #NAS #Path Traversal #Qfiling #QNAP #security #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_59384 #CVE_2025_59387 #cybersecurity #Data Protection #Mac Security #MARS #NAS #Path Traversal #Qfiling #QNAP #security #sql injection
Daily CyberSecurity
QNAP Patches High-Severity SQL Injection and Path Traversal Flaws
QNAP patches high-severity flaws (CVSS 8.1) in Qfiling and MARS that allow data theft and code injection. Secure your NAS by updating to the latest versions!
⤷ Title: How Our Agent Extracted a System Prompt Using Base64
════════════════════════
𐀪 Author: Daniel Knight
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:56:05 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #llm #cybersecurity #prompt_injection_attack
════════════════════════
𐀪 Author: Daniel Knight
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:56:05 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #llm #cybersecurity #prompt_injection_attack
Medium
How Our Agent Extracted a System Prompt Using Base64
Daniel Knight, CEO at Vulnetic
⤷ Title: The Great Disappearing Act -TryHackMe Writeup
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:10:25 GMT
════════════════════════
⌗ Tags: #writeup #tryhackme #thegreatdisappearingac #ctf_walkthrough #tryhackme_walkthrough
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:10:25 GMT
════════════════════════
⌗ Tags: #writeup #tryhackme #thegreatdisappearingac #ctf_walkthrough #tryhackme_walkthrough
Medium
The Great Disappearing Act -TryHackMe Writeup
Hard-rated THM Room Writeup
⤷ Title: HTB Labs : Spookifier | Web Exploitation Write-up
════════════════════════
𐀪 Author: Alexander Sapo
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 01:44:43 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #ssti_vulnerability #owasp_top_10 #ctf_writeup #web_hacking
════════════════════════
𐀪 Author: Alexander Sapo
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 01:44:43 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #ssti_vulnerability #owasp_top_10 #ctf_writeup #web_hacking
Medium
HTB Labs : Spookifier | Web Exploitation
Category: Web
⤷ Title: CPTS — HackTheBox: Password Attacks — Attacking Active Directory and NTDS.dit
════════════════════════
𐀪 Author: Daniel Hruska
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 20:10:22 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox_walkthrough #hackthebox
════════════════════════
𐀪 Author: Daniel Hruska
════════════════════════
ⴵ Time: Fri, 02 Jan 2026 20:10:22 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox_walkthrough #hackthebox
⤷ Title: DbgNexum: Shellcode injection using the Windows Debugging API
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:32:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:32:19 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
Penetration Testing Tools
DbgNexum: Shellcode injection using the Windows Debugging API
DbgNexum is a 2026 PoC that uses Hardware Breakpoints and File Mapping to inject shellcode without standard APIs, making it invisible to most EDRs.
⤷ Title: The End of Offline: Microsoft Silently Kills Phone Activation After 24 Years
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:28:15 +0000
════════════════════════
⌗ Tags: #Windows #Air_Gapped Security #Ben Kleinberg #Microsoft #Microsoft Account #Office Activation #Offline Setup #Phone Activation #Windows 10 #Windows 11 #Windows 7
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:28:15 +0000
════════════════════════
⌗ Tags: #Windows #Air_Gapped Security #Ben Kleinberg #Microsoft #Microsoft Account #Office Activation #Offline Setup #Phone Activation #Windows 10 #Windows 11 #Windows 7
Penetration Testing Tools
The End of Offline: Microsoft Silently Kills Phone Activation After 24 Years
Microsoft has definitively abandoned phone-based activation for Windows and Office. Although the company still references this method in
⤷ Title: Hack or Honeypot? ShinyHunters Claims Victory While Resecurity Claims a Masterful Trap
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:26:28 +0000
════════════════════════
⌗ Tags: #Data Leak #Cyber Espionage #data breach #HoneyPot #InfoSec 2026 #LAPSUS$ #Mattermost #Resecurity #Scattered Spider #ShinyHunters #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:26:28 +0000
════════════════════════
⌗ Tags: #Data Leak #Cyber Espionage #data breach #HoneyPot #InfoSec 2026 #LAPSUS$ #Mattermost #Resecurity #Scattered Spider #ShinyHunters #threat intelligence
Penetration Testing Tools
Hack or Honeypot? ShinyHunters Claims Victory While Resecurity Claims a Masterful Trap
The hacking group known as ShinyHunters has claimed responsibility for breaching the infrastructure of Resecurity and exfiltrating internal
⤷ Title: The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:25:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #DoNot Group #InfoSec 2026 #MSBuild #Pakistan Defense #Patchwork APT #Python RAT #QiAnXin #Spyder Malware #StreamSpy #WebSocket C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:25:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #DoNot Group #InfoSec 2026 #MSBuild #Pakistan Defense #Patchwork APT #Python RAT #QiAnXin #Spyder Malware #StreamSpy #WebSocket C2
Penetration Testing Tools
The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
The hacking group known as Patchwork—also referred to as Dropping Elephant and Maha Grass—has once again come under
⤷ Title: The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:23:01 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Malware #Corporate Espionage #DarkSpectre #GhostPoster #InfoSec 2026 #Koi Security #ShadyPanda #Steganography #Zoom Stealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:23:01 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Malware #Corporate Espionage #DarkSpectre #GhostPoster #InfoSec 2026 #Koi Security #ShadyPanda #Steganography #Zoom Stealer
Penetration Testing Tools
The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
A hacking group operating under the name DarkSpectre has, for seven years, systematically infected the computers of users
⤷ Title: The Adaptive Spy: Transparent Tribe’s New RAT Outsmarts Antivirus to Target India
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:21:48 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Evasion #APT36 #Cyber Espionage #CYFIRMA #India #InfoSec 2026 #malware #phishing #RAT #Transparent Tribe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:21:48 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Evasion #APT36 #Cyber Espionage #CYFIRMA #India #InfoSec 2026 #malware #phishing #RAT #Transparent Tribe
Penetration Testing Tools
The Adaptive Spy: Transparent Tribe’s New RAT Outsmarts Antivirus to Target India
The hacking group known as Transparent Tribe has launched a new wave of cyber-espionage operations targeting government bodies,
⤷ Title: The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:20:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Theft #DevOps Security #Github #InfoSec 2026 #JavaScript #malware #npm #Shai_Hulud #supply chain attack #Trust Wallet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:20:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Theft #DevOps Security #Github #InfoSec 2026 #JavaScript #malware #npm #Shai_Hulud #supply chain attack #Trust Wallet
Penetration Testing Tools
The Worm in the Code: How the Shai-Hulud npm Attack Hijacked Trust Wallet
A large-scale supply chain compromise known as Shai-Hulud has been linked to the recent theft of approximately USD
⤷ Title: Terminal Rebellion: The brow6el Project Brings the Full Web to Your Command Line
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:17:56 +0000
════════════════════════
⌗ Tags: #Technology #AI_Free #brow6el #Chromium #Codeberg #Command Line #Linux #open source #privacy #Sixel Graphics #Terminal Browser #Vim Keybindings
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:17:56 +0000
════════════════════════
⌗ Tags: #Technology #AI_Free #brow6el #Chromium #Codeberg #Command Line #Linux #open source #privacy #Sixel Graphics #Terminal Browser #Vim Keybindings
Penetration Testing Tools
Terminal Rebellion: The brow6el Project Brings the Full Web to Your Command Line
When it seems that modern browsers have exhausted their capacity to surprise, someone comes along and returns the
⤷ Title: The Physical Firewall: How Hong Kong’s “Money Safe” Uses Face-to-Face Checks to Kill Digital Fraud
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:14:18 +0000
════════════════════════
⌗ Tags: #Information Security #Bank Fraud #cybersecurity #Digital Banking #Eddie Yue #Face_to_Face Verification #Financial Security #HKMA #Hong Kong #Money Safe #Scam Prevention
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:14:18 +0000
════════════════════════
⌗ Tags: #Information Security #Bank Fraud #cybersecurity #Digital Banking #Eddie Yue #Face_to_Face Verification #Financial Security #HKMA #Hong Kong #Money Safe #Scam Prevention
Penetration Testing Tools
The Physical Firewall: How Hong Kong’s "Money Safe" Uses Face-to-Face Checks to Kill Digital Fraud
Hong Kong banks have devised a radical way to undercut fraudsters: a portion of funds can be placed
⤷ Title: Deep Space Leak: 200GB of ESA and Airbus Code Put Up for Sale by Hacker “888”
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:12:59 +0000
════════════════════════
⌗ Tags: #Data Leak #888 #Airbus Defence #Bitbucket #BreachForums #CI/CD Security #Cyber Espionage #data breach #European Space Agency #InfoSec 2026 #JUICE Mission
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:12:59 +0000
════════════════════════
⌗ Tags: #Data Leak #888 #Airbus Defence #Bitbucket #BreachForums #CI/CD Security #Cyber Espionage #data breach #European Space Agency #InfoSec 2026 #JUICE Mission
Penetration Testing Tools
Deep Space Leak: 200GB of ESA and Airbus Code Put Up for Sale by Hacker "888"
An advertisement has surfaced on the BreachForums forum offering a large data archive for sale. According to the
⤷ Title: The Christmas Blitz: Coordinated Attack Spikes to 2.5M Requests via Adobe ColdFusion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:09:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2023_26359 #CVE_2023_38205 #cyberattack #GreyNoise #InfoSec 2026 #JNDI injection #Shellshock
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:09:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Adobe ColdFusion #Christmas 2025 #CTG Server Limited #CVE_2023_26359 #CVE_2023_38205 #cyberattack #GreyNoise #InfoSec 2026 #JNDI injection #Shellshock
Penetration Testing Tools
The Christmas Blitz: Coordinated Attack Spikes to 2.5M Requests via Adobe ColdFusion
In the midst of the Christmas holidays, researchers at Greynoise detected a large-scale cyberattack targeting vulnerable Adobe ColdFusion
⤷ Title: The AI-Found Zero-Day: Critical CVE-2025-54322 Leaves 70,000 XSpeeder Devices Exposed
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:08:40 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_54322 #Edge Computing #Industrial Security #pwn.ai #Python eval() #RCE #Root Exploit #SD_WAN #SXZOS #XSpeeder #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:08:40 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_54322 #Edge Computing #Industrial Security #pwn.ai #Python eval() #RCE #Root Exploit #SD_WAN #SXZOS #XSpeeder #zero_day
Penetration Testing Tools
The AI-Found Zero-Day: Critical CVE-2025-54322 Leaves 70,000 XSpeeder Devices Exposed
A critical vulnerability has been discovered in XSpeeder devices that could allow unauthenticated remote execution of arbitrary code.
⤷ Title: GlassWorm’s macOS Gambit: The Invisible Worm Draining Developer Wallets via Open VSX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:05:20 +0000
════════════════════════
⌗ Tags: #Malware #Crypto_Stealer #GlassWorm #Koi Security #macOS Security #Open VSX #Prettier Pro #Solana C2 #supply chain attack #Vibe_Coding #VS Code #ZOMBI RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:05:20 +0000
════════════════════════
⌗ Tags: #Malware #Crypto_Stealer #GlassWorm #Koi Security #macOS Security #Open VSX #Prettier Pro #Solana C2 #supply chain attack #Vibe_Coding #VS Code #ZOMBI RAT
Penetration Testing Tools
GlassWorm’s macOS Gambit: The Invisible Worm Draining Developer Wallets via Open VSX
A new wave of malicious extensions has been uncovered in the Open VSX extension marketplace, which is used
⤷ Title: Sherlock Exposes You In Seconds: The OSINT Weapon!!
════════════════════════
𐀪 Author: cybrNK
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 02:27:17 GMT
════════════════════════
⌗ Tags: #aws #cybersecurity #osint_investigation #osint #hacking
════════════════════════
𐀪 Author: cybrNK
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 02:27:17 GMT
════════════════════════
⌗ Tags: #aws #cybersecurity #osint_investigation #osint #hacking
Medium
Sherlock Exposes You In Seconds: The OSINT Weapon!!
Sherlock is a focused, high‑impact OSINT tool that lets you pivot from a single username to a broad, cross‑platform picture of someone’s…