⤷ Title: Instagram’s “17 Million User Data Leak” Was Just Scraped Records from 2022
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:24:14 +0000
════════════════════════
⌗ Tags: #Leaks #Security #BreachForums #Cybersecurity #data breach #Instagram #LeakBase #LEAKS #Malwarebytes #Meta #Privacy
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:24:14 +0000
════════════════════════
⌗ Tags: #Leaks #Security #BreachForums #Cybersecurity #data breach #Instagram #LeakBase #LEAKS #Malwarebytes #Meta #Privacy
Hackread
Instagram’s “17 Million User Data Leak” Was Just Scraped Records from 2022
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
❤1
⤷ Title: Beyond IDOR: Discovering a Stored XSS in a Vulnerable Web Platform
════════════════════════
𐀪 Author: mv999exe
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:11:49 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty_writeup #bug_bounty #pentesting
════════════════════════
𐀪 Author: mv999exe
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:11:49 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty_writeup #bug_bounty #pentesting
Medium
Beyond IDOR: Discovering a Stored XSS in a Vulnerable Web Platform
Security Note: Responsible Disclosure Policy
⤷ Title: 30 Days of Red Team: Day 15 — Credential Harvesting
════════════════════════
𐀪 Author: Maxwell Cross
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:43:18 GMT
════════════════════════
⌗ Tags: #ethical_hacking #infosec #red_teaming #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Maxwell Cross
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:43:18 GMT
════════════════════════
⌗ Tags: #ethical_hacking #infosec #red_teaming #cybersecurity #penetration_testing
Medium
30 Days of Red Team: Day 15 — Credential Harvesting
From LSASS to SAM: Mastering the Art of Dumping Hashes and Secrets
⤷ Title: Professional Ethical Hacking & Digital Investigation Services.
════════════════════════
𐀪 Author: Private-hackers.com
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:55:15 GMT
════════════════════════
⌗ Tags: #digital_investigation #hireprofessionalhacker #ethical_hacking #account_recovery #cybersecurity
════════════════════════
𐀪 Author: Private-hackers.com
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 22:55:15 GMT
════════════════════════
⌗ Tags: #digital_investigation #hireprofessionalhacker #ethical_hacking #account_recovery #cybersecurity
Medium
Professional Ethical Hacking & Digital Investigation Services.
Private-Hackers.com provides confidential, legal, and ethical hacking services to help individuals recover hacked accounts, investigate…
⤷ Title: The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 01:46:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts 2 #CVE_2025_68493 #Denial of Service #Java security #ssrf #XWork #XXE Injection #ZAST.AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 01:46:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts 2 #CVE_2025_68493 #Denial of Service #Java security #ssrf #XWork #XXE Injection #ZAST.AI
Daily CyberSecurity
The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data
A new flaw has appeared in the foundation of one of the web’s most popular Java frameworks. Security researchers at ZAST.AI have uncovered an “Important” severity vulnerability i…
⤷ Title: CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:32:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Spark #Apache Uniffle #Big Data Security #CVE_2025_68637 #Hadoop MapReduce #mitm attack #network_security #SSL Verification
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:32:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Spark #Apache Uniffle #Big Data Security #CVE_2025_68637 #Hadoop MapReduce #mitm attack #network_security #SSL Verification
Daily CyberSecurity
CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping
A high-severity vulnerability has been unearthed in Apache Uniffle, the remote shuffle service that powers data movement for massive distributed computing engines. Tracked as CVE-2025-68637, the f…
⤷ Title: “Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:28:23 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Astaroth #Banking Trojan #Boto Cor_de_Rosa #Malware Analysis #Python Worm #social engineering #WhatsApp Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:28:23 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Astaroth #Banking Trojan #Boto Cor_de_Rosa #Malware Analysis #Python Worm #social engineering #WhatsApp Security
Daily CyberSecurity
“Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign
The notorious Brazilian banking malware Astaroth has evolved again, this time turning one of the world’s most popular messaging platforms into a weapon. In a new campaign dubbed “Boto …
⤷ Title: Pig Butchering-as-a-Service: How “Penguin” Industrialized Global Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:22:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Scams #Cybercrime Economy #Fraud Intelligence #Infoblox #PBaaS #Penguin (Threat Actor) #Pig Butchering #UWORK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:22:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Scams #Cybercrime Economy #Fraud Intelligence #Infoblox #PBaaS #Penguin (Threat Actor) #Pig Butchering #UWORK
Daily CyberSecurity
Pig Butchering-as-a-Service: How “Penguin” Industrialized Global Fraud
The world of “pig butchering” scams has evolved from chaotic boiler rooms into a streamlined, automated service economy. A new report from Infoblox reveals how the “Pig Butcherin…
⤷ Title: CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:22:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2026_22184 #Data Compression #Open Source Security #Remote Code Execution #untgz #vulnerability management #zlib
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:22:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2026_22184 #Data Compression #Open Source Security #Remote Code Execution #untgz #vulnerability management #zlib
Daily CyberSecurity
CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow
A critical vulnerability has been discovered in zlib, the lossless data-compression engine used on “virtually any computer hardware and operating system.” Tracked as CVE-2026-22184, th…
⤷ Title: RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:17:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT (Advanced Persistent Threat) #CloudSEK #Malware Analysis #Middle East Cyberattacks #MuddyWater #Rust malware #RustyWater #Spearphishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:17:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT (Advanced Persistent Threat) #CloudSEK #Malware Analysis #Middle East Cyberattacks #MuddyWater #Rust malware #RustyWater #Spearphishing
Daily CyberSecurity
RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants
The notorious MuddyWater APT group has overhauled its arsenal, ditching its traditional scripting tools for a sophisticated new weapon built to evade detection. In a new report released by CloudSE…
⤷ Title: Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:12:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT Polska #CVE_2025_66049 #End of Life (EOL) #IoT Vulnerability #IP Camera Security #RTSP #Surveillance Privacy #Vivotek
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:12:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT Polska #CVE_2025_66049 #End of Life (EOL) #IoT Vulnerability #IP Camera Security #RTSP #Surveillance Privacy #Vivotek
Daily CyberSecurity
Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All
Owners of legacy Vivotek IP7137 surveillance cameras have been dealt a harsh reality check: their devices are riddled with critical security holes, and no patch is coming to save them. CERT Polska…
⤷ Title: China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:07:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Bulbature #Cisco Talos #Critical Infrastructure #cyber_espionage #ORB (Operational Relay Box) #Telecommunications Security #UAT_7290
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:07:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Bulbature #Cisco Talos #Critical Infrastructure #cyber_espionage #ORB (Operational Relay Box) #Telecommunications Security #UAT_7290
Daily CyberSecurity
China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe
Cisco Talos has pulled the curtain back on UAT-7290, a threat actor operating out of the China-nexus since at least 2022. Specializing in stealth and persistence, this group has been systematicall…
⤷ Title: Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:02:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14338 #CVE_2025_66005 #D_Bus Security #InputPlumber #Linux Gaming #privilege escalation #SteamOS #SUSE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:02:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14338 #CVE_2025_66005 #D_Bus Security #InputPlumber #Linux Gaming #privilege escalation #SteamOS #SUSE
Daily CyberSecurity
Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking
A utility designed to enhance the Linux gaming experience has been found to harbor critical security vulnerabilities that could allow local attackers to hijack sessions or crash systems. The SUSE …
⤷ Title: VulnBank — FahemSec Web Challenge
════════════════════════
𐀪 Author: محمد بن إبراهيم
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:17:39 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bug_bounty #ctf #hacking
════════════════════════
𐀪 Author: محمد بن إبراهيم
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:17:39 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bug_bounty #ctf #hacking
Medium
VulnBank — FahemSec Web Challenge
بسم الله الرحمن الرحيم
⤷ Title: Threat Modeling Guide: STRIDE, Data Flow Diagrams, Risk Ranking & Mitigations
════════════════════════
𐀪 Author: QuarkAndCode
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:38:37 GMT
════════════════════════
⌗ Tags: #strideframework #application_security #data_flow_diagram #devsecops #threat_modeling
════════════════════════
𐀪 Author: QuarkAndCode
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 00:38:37 GMT
════════════════════════
⌗ Tags: #strideframework #application_security #data_flow_diagram #devsecops #threat_modeling
Medium
Threat Modeling Guide: STRIDE, Data Flow Diagrams, Risk Ranking & Mitigations
Master threat modeling: map data flows, apply STRIDE, rank risks, pick mitigations, and integrate security into DevSecOps for every…
⤷ Title: Defense-in-Depth for AI Agents: Why Input Security Isn’t Enough
════════════════════════
𐀪 Author: David Anderson
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 23:47:30 GMT
════════════════════════
⌗ Tags: #llm #artificial_intelligence #cybersecurity #application_security #ai
════════════════════════
𐀪 Author: David Anderson
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 23:47:30 GMT
════════════════════════
⌗ Tags: #llm #artificial_intelligence #cybersecurity #application_security #ai
Medium
Defense-in-Depth for AI Agents: Why Input Security Isn’t Enough
Defense-in-depth for AI agents requires securing both input and output layers.
⤷ Title: ☕ Master CISSP Domain 4: 40 Coffee Shot Questions (Part 2 of 2)
════════════════════════
𐀪 Author: Pushpak Sharma
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 01:30:14 GMT
════════════════════════
⌗ Tags: #cissp #cybersecurity #infosec #arp_layer #isc2
════════════════════════
𐀪 Author: Pushpak Sharma
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 01:30:14 GMT
════════════════════════
⌗ Tags: #cissp #cybersecurity #infosec #arp_layer #isc2
Medium
☕ Master CISSP Domain 4: 40 Coffee Shot Questions (Part 2 of 2)
Network Security Practice Questions 21-40 with Explanations & Fun Visuals
⤷ Title: The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 03:47:57 +0000
════════════════════════
⌗ Tags: #Data Leak #2FA #Account Hijacking #API Leak #Cybersecurity 2026 #dark web #Data Breach #Instagram #Malwarebytes #Meta #phishing #Solonik
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 03:47:57 +0000
════════════════════════
⌗ Tags: #Data Leak #2FA #Account Hijacking #API Leak #Cybersecurity 2026 #dark web #Data Breach #Instagram #Malwarebytes #Meta #phishing #Solonik
Daily CyberSecurity
The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web
A monumental data breach has compromised approximately 17.5 million Instagram users, resulting in the exfiltration of sensitive personal information that is now proliferating across the dark web. …
⤷ Title: WAFs Wide Open: Critical OWASP CRS Flaw Bypasses Filters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 03:16:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Coraza #Cross_Site Scripting (XSS) #modsecurity #OWASP CRS #Rule 922110 #WAF Bypass #web application security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 03:16:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Coraza #Cross_Site Scripting (XSS) #modsecurity #OWASP CRS #Rule 922110 #WAF Bypass #web application security
Daily CyberSecurity
WAFs Wide Open: Critical OWASP CRS Flaw Bypasses Filters
A foundational pillar of web application security has cracked. The OWASP Core Rule Set (CRS) team has disclosed a critical security bypass vulnerability that renders one of its key defenses ineffe…
⤷ Title: Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:32:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_61686 #React Router #Remix Framework #Server_Side Rendering (SSR) #Session Hijacking #Web Security #XSS (Cross_Site Scripting)
Daily CyberSecurity
Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
Developers relying on the popular React Router library are being urged to patch their applications immediately following the disclosure of multiple high-severity vulnerabilities. The flaws, rangin…
⤷ Title: The Soviet Ghost: How Carding Markets Survive on Legacy Domains
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:04:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.su Domain #bulletproof hosting #carding #Credit Card Fraud #Cybercrime Economy #Dark Web Markets #Team Cymru #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 02:04:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.su Domain #bulletproof hosting #carding #Credit Card Fraud #Cybercrime Economy #Dark Web Markets #Team Cymru #threat intelligence
Daily CyberSecurity
The Soviet Ghost: How Carding Markets Survive on Legacy Domains
A new analysis by Team Cymru researchers has shed light on the physical and digital infrastructure powering this underground economy, revealing a network heavily reliant on “bulletproof̶…