⤷ Title: CVE-2025-60262: Critical Misconfiguration in H3C Wireless Gear Hands Control to Hackers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:06:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_60262 #H3C #Network Infrastructure #privilege escalation #root access #vsftpd #Wireless Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:06:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_60262 #H3C #Network Infrastructure #privilege escalation #root access #vsftpd #Wireless Security
Daily CyberSecurity
CVE-2025-60262: Critical Misconfiguration in H3C Wireless Gear Hands Control to Hackers
A glaring configuration oversight in select H3C wireless controllers and access points has opened the door for remote attackers to seize root-level control of the devices. The vulnerability, track…
⤷ Title: Taiwan Faces 2.6 Million Cyberattacks Daily from China
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Critical Infrastructure #Cyber Warfare #Energy Sector Security #Hybrid Warfare #infosec #Mustang Panda #Taiwan NSB
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Critical Infrastructure #Cyber Warfare #Energy Sector Security #Hybrid Warfare #infosec #Mustang Panda #Taiwan NSB
Daily CyberSecurity
Taiwan Faces 2.6 Million Cyberattacks Daily from China
Recently, Taiwan’s National Security Bureau (NSB) has released a comprehensive report detailing a massive surge in state-sponsored cyber aggression. The analysis for the year 2025 paints a grim pi…
⤷ Title: Lo-Fi TryHackMe Write UP
════════════════════════
𐀪 Author: cat0x01
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:48:59 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #pentesting #hacking #cybersecurity
════════════════════════
𐀪 Author: cat0x01
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:48:59 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #pentesting #hacking #cybersecurity
Medium
Lo-Fi TryHackMe Write UP
We’re back with another TryHackMe challenge. called LO-FI
⤷ Title: TryHackMe: Willow Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 01:42:11 GMT
════════════════════════
⌗ Tags: #information_security #tryhackme #pentesting #cybersecurity
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 01:42:11 GMT
════════════════════════
⌗ Tags: #information_security #tryhackme #pentesting #cybersecurity
Medium
TryHackMe: Willow Writeup
This box is ranked medium on THM, it involves us mounting a file share to get access to RSA key pair integers, which we can use to recover…
⤷ Title: From Ghostcat to Root: A Comprehensive Walkthrough of the Thompson Lab
════════════════════════
𐀪 Author: Justin Jude Cabodil
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:43:32 GMT
════════════════════════
⌗ Tags: #tryhackme #ajp #linux
════════════════════════
𐀪 Author: Justin Jude Cabodil
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:43:32 GMT
════════════════════════
⌗ Tags: #tryhackme #ajp #linux
Medium
From Ghostcat to Root: A Comprehensive Walkthrough of the Thompson Lab
In the world of cybersecurity, “Boot2Root” machines serve as the ultimate playground for testing technical depth and creative lateral…
⤷ Title: CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:55:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2009_0556 #CVE_2025_37164 #HPE OneView #Infrastructure Security #KEV Catalog #Microsoft PowerPoint #vulnerability management #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:55:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2009_0556 #CVE_2025_37164 #HPE OneView #Infrastructure Security #KEV Catalog #Microsoft PowerPoint #vulnerability management #zero_day
Daily CyberSecurity
CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with two new entries that span nearly two decades of computing history. Th…
⤷ Title: Public Exploit Released: Critical n8n Flaw CVE-2026-21858 Exposes 100k Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:44:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #CVE_2026_21858 #Cyera #DevSecOps #n8n #Public Exploit #RCE (Remote Code Execution) #Workflow Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:44:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #CVE_2026_21858 #Cyera #DevSecOps #n8n #Public Exploit #RCE (Remote Code Execution) #Workflow Automation
Daily CyberSecurity
Public Exploit Released: Critical n8n Flaw CVE-2026-21858 Exposes 100k Servers
The “central nervous system” of automation for thousands of companies has a critical weakness. A new report from Cyera reveals a devastating vulnerability in n8n, the popular workflow …
⤷ Title: “VM Isolation is Not Absolute”: Researchers Unmask Sophisticated ESXi “Maestro” Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:03:02 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CVE_2025_22224 #Huntress #Malware Analysis #Virtualization Security #VM Escape #VMware ESXi #VSOCKpuppet #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:03:02 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CVE_2025_22224 #Huntress #Malware Analysis #Virtualization Security #VM Escape #VMware ESXi #VSOCKpuppet #zero_day
Daily CyberSecurity
“VM Isolation is Not Absolute”: Researchers Unmask Sophisticated ESXi “Maestro” Exploit
In a new report, the Huntress Tactical Response Team details a sophisticated intrusion discovered in December 2025 where threat actors successfully executed a “VM escape”—breaking out …
⤷ Title: GoBruteforcer Returns: How AI Code Snippets Fueled a 50,000-Server Botnet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:45:28 +0000
════════════════════════
⌗ Tags: #Malware #AI_Generated Code #botnet #brute force attack #Check Point Research #Crypto theft #GoBruteforcer #Linux Security #Malware Analysis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:45:28 +0000
════════════════════════
⌗ Tags: #Malware #AI_Generated Code #botnet #brute force attack #Check Point Research #Crypto theft #GoBruteforcer #Linux Security #Malware Analysis
Daily CyberSecurity
GoBruteforcer Returns: How AI Code Snippets Fueled a 50,000-Server Botnet
A sophisticated new variant of the GoBruteforcer botnet is on the loose, and it’s capitalizing on a thoroughly modern problem: the “mass reuse of AI-generated server deployment example…
⤷ Title: CVE-2025-67859: Critical Auth Bypass Discovered in Popular Linux Battery Utility
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:28:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67859 #Denial of Service (DoS) #Linux Security #Polkit #Power Management #privilege escalation #SUSE #TLP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:28:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67859 #Denial of Service (DoS) #Linux Security #Polkit #Power Management #privilege escalation #SUSE #TLP
Daily CyberSecurity
CVE-2025-67859: Critical Auth Bypass Discovered in Popular Linux Battery Utility
A critical security flaw has been unearthed in TLP, the widely used power management utility for Linux laptops, potentially allowing unauthorized users to bypass authentication checks and tamper w…
⤷ Title: CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:17:34 +0000
════════════════════════
⌗ Tags: #Malware #Active Directory Security #BYOVD (Bring Your Own Vulnerable Driver) #CrazyHunter #healthcare security #Malware Analysis #ransomware #SharpGPOAbuse #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:17:34 +0000
════════════════════════
⌗ Tags: #Malware #Active Directory Security #BYOVD (Bring Your Own Vulnerable Driver) #CrazyHunter #healthcare security #Malware Analysis #ransomware #SharpGPOAbuse #Trellix
Daily CyberSecurity
CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
A new, highly aggressive ransomware strain is cutting a swath through the healthcare sector, leaving hospitals and critical organizations scrambling to protect their data. Security researchers at …
⤷ Title: GitLab Patch: High-Severity XSS & AI Flaws Expose User Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:08:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Application Security #CVE_2025_9222 #DevSecOps #gitlab #GitLab Duo #software update #vulnerability management #XSS (Cross_Site Scripting)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:08:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Application Security #CVE_2025_9222 #DevSecOps #gitlab #GitLab Duo #software update #vulnerability management #XSS (Cross_Site Scripting)
Daily CyberSecurity
GitLab Patch: High-Severity XSS & AI Flaws Expose User Data
GitLab has issued a critical security release for its Community Edition (CE) and Enterprise Edition (EE) platforms, patching a raft of vulnerabilities that range from high-severity Cross-Site Scri…
⤷ Title: Recruiting Google Gemini’s Email Summarizer as a Phishing Aid
════════════════════════
𐀪 Author: Mike Sheward
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:23:09 GMT
════════════════════════
⌗ Tags: #llm #infosec #gemini #ai #bug_bounty
════════════════════════
𐀪 Author: Mike Sheward
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:23:09 GMT
════════════════════════
⌗ Tags: #llm #infosec #gemini #ai #bug_bounty
Medium
Recruiting Google Gemini’s Email Summarizer as a Phishing Aid
Note: I originally disclosed these findings to the Google AI Bug Bounty (or VRP program), but they rejected them as being a non-qualified…
⤷ Title: LangChain Serialization Vulnerabilities: When LLMs Generate Exploits
════════════════════════
𐀪 Author: David Anderson
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:25:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #artificial_intelligence #ai #application_security
════════════════════════
𐀪 Author: David Anderson
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:25:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #artificial_intelligence #ai #application_security
Medium
LangChain Serialization Vulnerabilities: When LLMs Generate Exploits
Two critical vulnerabilities were published December 23, 2025 affecting LangChain Python (CVE-2025–68664, CVSS 9.3) and JavaScript…
⤷ Title: Archa CTF 2026 — Mobile (Writeups)
════════════════════════
𐀪 Author: CynPhone
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:38:01 GMT
════════════════════════
⌗ Tags: #mobile_games #hacking #ctf_writeup #mobile_security #ctf
════════════════════════
𐀪 Author: CynPhone
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:38:01 GMT
════════════════════════
⌗ Tags: #mobile_games #hacking #ctf_writeup #mobile_security #ctf
Medium
Archa CTF 2026 — Mobile (Writeups)
สวัสดีครับ ‘โฟน’ นะครับ สำหรับWriteups ในครั้งนี้มาจากการแข่งขัน Archa CTF บอกได้เลยครับว่าโจทย์สนุกทุกข้อ💖…
⤷ Title: Why Spotify’s latest problem could change music forever
════════════════════════
𐀪 Author: Abstract Mind
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:28:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #hacking #security
════════════════════════
𐀪 Author: Abstract Mind
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:28:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #hacking #security
Medium
Why Spotify’s latest problem could change music forever
Pirate activist group and shadow library Anna’s Archive claims to have “backed up” the world’s largest music streamer
⤷ Title: Token Leakage in Password Reset Flows
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:15:12 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #pentesting #passwords #cybersecurity
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:15:12 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #pentesting #passwords #cybersecurity
Medium
Token Leakage in Password Reset Flows
A Simple, High‑Impact Bug Bounty Technique
⤷ Title: CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 10:22:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 10:22:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: The “Blind Sniper” Attack: Spamming Thousands of Users Without Knowing Their Email Addresses
════════════════════════
𐀪 Author: Zer0Figure
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 04:32:42 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #security #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: Zer0Figure
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 04:32:42 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #security #cybersecurity #bug_bounty_tips
Medium
The “Blind Sniper” Attack: Spamming Thousands of Users Without Knowing Their Email Addresses
Most email bombers need a target email. I found a way to turn a User ID into a weapon, spamming verified users and causing financial chaos…
⤷ Title: Ni8mare: Unauthenticated RCE in n8n (CVE-2026–21858)
════════════════════════
𐀪 Author: Praveen Malhan
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:56:54 GMT
════════════════════════
⌗ Tags: #application_security #open_source_security #ai_security #n8n #supply_chain_security
════════════════════════
𐀪 Author: Praveen Malhan
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:56:54 GMT
════════════════════════
⌗ Tags: #application_security #open_source_security #ai_security #n8n #supply_chain_security
Medium
Ni8mare: Unauthenticated RCE in n8n (CVE-2026–21858)
In early 2026, security researchers revealed a critical vulnerability in n8n, a popular automation platform, that allows attackers to…
⤷ Title: Active Directory: Fundamental kirish va arxitektura
════════════════════════
𐀪 Author: Mukhammadiyev
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 05:53:10 GMT
════════════════════════
⌗ Tags: #hacking #active_directory_security #active_directory_attack #corporate_security
════════════════════════
𐀪 Author: Mukhammadiyev
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 05:53:10 GMT
════════════════════════
⌗ Tags: #hacking #active_directory_security #active_directory_attack #corporate_security
Medium
Active Directory: Fundamental kirish va arxitektura
Active Directory nima va nima uchun u barcha breach’larning markazida?