⤷ Title: Lab: Reflected XSS into HTML context with nothing encoded
════════════════════════
𐀪 Author: Mylescorey
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 20:28:02 GMT
════════════════════════
⌗ Tags: #burpsuite #bug_bounty #xss_attack
════════════════════════
𐀪 Author: Mylescorey
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 20:28:02 GMT
════════════════════════
⌗ Tags: #burpsuite #bug_bounty #xss_attack
Medium
Lab: Reflected XSS into HTML context with nothing encoded
After opening the lab, I put the basic alert payload into the search bar and after putting search we got the alert function that lets us…
⤷ Title: Inter Process Communication with RPC
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:52:51 GMT
════════════════════════
⌗ Tags: #malware #hacking #cybersecurity #tryhackme #pentesting
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:52:51 GMT
════════════════════════
⌗ Tags: #malware #hacking #cybersecurity #tryhackme #pentesting
Medium
Inter Process Communication with RPC
Welcome to this new Medium post! In this one we’re gonna mess around with something pretty cool: RPC (Remote Procedure Call), basically the…
⤷ Title: For 11 Minutes, the Internet Trusted a Lie — and No Firewall Noticed
════════════════════════
𐀪 Author: Liam
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:17:19 GMT
════════════════════════
⌗ Tags: #technology #ai_security #cybersecurity #artificial_intelligence #hacking
════════════════════════
𐀪 Author: Liam
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:17:19 GMT
════════════════════════
⌗ Tags: #technology #ai_security #cybersecurity #artificial_intelligence #hacking
Medium
For 11 Minutes, the Internet Trusted a Lie — and No Firewall Noticed
A story about why “secure” networks still fail, and why most defenses are pointed in the wrong direction.
⤷ Title: The Hacking Tool Chronicles: Dirb
════════════════════════
𐀪 Author: z3r0trust
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:08:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_hacking #hacking #osint #ethical_hacking
════════════════════════
𐀪 Author: z3r0trust
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:08:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_hacking #hacking #osint #ethical_hacking
Medium
The Hacking Tool Chronicles: Dirb
A series of articles focused on freely available hacking tools, in this edition we look at the web recon tool Dirb.
⤷ Title: ওয়েব অ্যাপ্লিকেশন পেনটেস্টিংয়ে রিকন টুলসের ব্যবহার: একটি পূর্ণাঙ্গ গাইড
════════════════════════
𐀪 Author: SecurityMindPro
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:36:41 GMT
════════════════════════
⌗ Tags: #web_testing #penetration_testing #webapplicationpentest
════════════════════════
𐀪 Author: SecurityMindPro
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:36:41 GMT
════════════════════════
⌗ Tags: #web_testing #penetration_testing #webapplicationpentest
Medium
ওয়েব অ্যাপ্লিকেশন পেনটেস্টিংয়ে রিকন টুলসের ব্যবহার: একটি পূর্ণাঙ্গ গাইড
সাইবার সিকিউরিটি এবং পেনিট্রেশন টেস্টিংয়ের জগতে একটি বহুল প্রচলিত কথা আছে — “আপনি যা দেখতে পাচ্ছেন না, তা আপনি হ্যাক করতে পারবেন না।” এই…
⤷ Title: “Relevant” ctf | TryHackMe| Complete detailed walkthrough| (Token Impersonation, PrintSpoofer.exe,
════════════════════════
𐀪 Author: Nishchay Manhas
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:27:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #ctf_writeup #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Nishchay Manhas
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:27:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #ctf_writeup #tryhackme #cybersecurity
Medium
“Relevant” ctf | TryHackMe| Complete detailed walkthrough| (Token Impersonation, PrintSpoofer.exe,
A step-by-step TryHackMe walkthrough covering enumeration, token impersonation, and Windows privilege escalation using PrintSpoofer.exe
⤷ Title: Breaking and Finding Vulnerabilities: My Cybersecurity Capstone Project
════════════════════════
𐀪 Author: Maria Sagwa
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 20:20:47 GMT
════════════════════════
⌗ Tags: #parocyber #cybersecurity #smbclient #ethical_hacking #sql_injection
════════════════════════
𐀪 Author: Maria Sagwa
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 20:20:47 GMT
════════════════════════
⌗ Tags: #parocyber #cybersecurity #smbclient #ethical_hacking #sql_injection
Medium
🔐 Breaking and Finding Vulnerabilities: My Cybersecurity Capstone Project
Cybersecurity is best learned by doing, not just reading. This capstone project challenged me to step into the mindset of an attacker while…
⤷ Title: [Rabbit Store] — JWT Manipulation, SSRF, SSTI Leading to RCE and Root Access via a Vulnerable…
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:51:31 GMT
════════════════════════
⌗ Tags: #rce #ssrf #privilege_escalation #ssti #jwt_token
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:51:31 GMT
════════════════════════
⌗ Tags: #rce #ssrf #privilege_escalation #ssti #jwt_token
Medium
[Rabbit Store] — JWT Manipulation, SSRF, SSTI Leading to RCE and Root Access via a Vulnerable Erlang Distribution on RabbitMQ
From SSRF and SSTI to Erlang cookie theft and root compromise.
⤷ Title: Blind SQL Injection: A Hands-On Lab Walkthrough
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:32:59 GMT
════════════════════════
⌗ Tags: #hacker #hacking_tutorial #hacking
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:32:59 GMT
════════════════════════
⌗ Tags: #hacker #hacking_tutorial #hacking
Medium
Blind SQL Injection: A Hands-On Lab Walkthrough
In a standard SQL injection, the database often spits out helpful error messages or direct data. But what happens when the application is…
⤷ Title: Welcome to my space :)
════════════════════════
𐀪 Author: Hobin Rood
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:18:00 GMT
════════════════════════
⌗ Tags: #osint #freelancing #hacking #osint_investigation #education
════════════════════════
𐀪 Author: Hobin Rood
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:18:00 GMT
════════════════════════
⌗ Tags: #osint #freelancing #hacking #osint_investigation #education
Medium
Welcome to my space :)
Welcome to the Network (the name I have still yet to decide).
⤷ Title: Beyond the Noise: Why I Built VedicRecon (and Why Reconnaissance Needs to Change)
════════════════════════
𐀪 Author: Vedic_error
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:11:49 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #cybersecurity #ethical_hacking #generative_ai_tools
════════════════════════
𐀪 Author: Vedic_error
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:11:49 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #cybersecurity #ethical_hacking #generative_ai_tools
Medium
Beyond the Noise: Why I Built VedicRecon (and Why Reconnaissance Needs to Change)
⚠️All testing described below was performed in a fully isolated lab environment for educational and defensive research purposes only. No…
⤷ Title: Phishing Simulator
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:16:16 GMT
════════════════════════
⌗ Tags: #ethical_hacking #python_web_developer #html5_development #phishing_awareness
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:16:16 GMT
════════════════════════
⌗ Tags: #ethical_hacking #python_web_developer #html5_development #phishing_awareness
Medium
Phishing Simulator
This is for educational purposes only! Do not use unless authorized.
⤷ Title: Fake Malwarebytes Campaign Exploits DLL Sideloading to Drop Infostealers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:46:26 +0000
════════════════════════
⌗ Tags: #Malware #BrowserStealer #CoreMessaging.dll #Cyber Security #DLL Sideloading #Infostealer #Joseliyo Sánchez #Malware Analysis #Malwarebytes #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:46:26 +0000
════════════════════════
⌗ Tags: #Malware #BrowserStealer #CoreMessaging.dll #Cyber Security #DLL Sideloading #Infostealer #Joseliyo Sánchez #Malware Analysis #Malwarebytes #social engineering
Daily CyberSecurity
Fake Malwarebytes Campaign Exploits DLL Sideloading to Drop Infostealers
New malware campaign impersonates Malwarebytes installers. Hackers use DLL sideloading to deploy infostealers targeting crypto & MFA. Verify downloads now.
⤷ Title: CVE-2026-0695: High-Severity XSS Flaw Patched in ConnectWise PSA 2026.1
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise PSA #CVE_2026_0695 #CVE_2026_0696 #Cyber Security #MSP Security #Patch Alert #Session Hijacking #Stored XSS #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise PSA #CVE_2026_0695 #CVE_2026_0696 #Cyber Security #MSP Security #Patch Alert #Session Hijacking #Stored XSS #Web Security
Daily CyberSecurity
CVE-2026-0695: High-Severity XSS Flaw Patched in ConnectWise PSA 2026.1
ConnectWise has released a crucial security update for its Professional Services Automation (PSA) platform, addressing two significant vulnerabilities that could allow attackers to weaponize munda…
⤷ Title: DragonForce: The Rise of a New “Ransomware Cartel” Built on LockBit and Conti DNA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:42:44 +0000
════════════════════════
⌗ Tags: #Malware #BlackLock #Conti #Cyber Cartel #decryptor #DragonForce #infosec #LockBit 3.0 #Malware Analysis #RansomBay #ransomware #S2W
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:42:44 +0000
════════════════════════
⌗ Tags: #Malware #BlackLock #Conti #Cyber Cartel #decryptor #DragonForce #infosec #LockBit 3.0 #Malware Analysis #RansomBay #ransomware #S2W
Daily CyberSecurity
DragonForce: The Rise of a New “Ransomware Cartel” Built on LockBit and Conti DNA
A comprehensive new analysis by security researchers at S2W details the inner workings of the DragonForce Ransomware Group, revealing a threat actor that is not only deploying sophisticated malwar…
⤷ Title: Fake Productivity Tools: 5 Malicious Chrome Extensions Hijack Enterprise Sessions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:37:04 +0000
════════════════════════
⌗ Tags: #Malware #Chrome extensions #Cookie Injection #DataByCloud #Enterprise Security #infosec #malware #NetSuite #Session Hijacking #Socket Threat Research #Workday
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:37:04 +0000
════════════════════════
⌗ Tags: #Malware #Chrome extensions #Cookie Injection #DataByCloud #Enterprise Security #infosec #malware #NetSuite #Session Hijacking #Socket Threat Research #Workday
Daily CyberSecurity
Fake Productivity Tools: 5 Malicious Chrome Extensions Hijack Enterprise Sessions
A new and sophisticated campaign targeting enterprise environments has been uncovered by Socket’s Threat Research Team. Five malicious Google Chrome extensions, masquerading as productivity …
⤷ Title: Sitting Ducks and Scammy Notifications: Inside a Global Malvertising Operation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:32:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Fraud #Android security #Cyber Crime #Cyber Hygiene #DNS hijacking #DNS Vulnerability #Infoblox #Malvertising #Push Notification Scam #Sitting Ducks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:32:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Fraud #Android security #Cyber Crime #Cyber Hygiene #DNS hijacking #DNS Vulnerability #Infoblox #Malvertising #Push Notification Scam #Sitting Ducks
Daily CyberSecurity
Sitting Ducks and Scammy Notifications: Inside a Global Malvertising Operation
Researchers at Infoblox have peeled back the curtain on a massive, deceptive push notification network, revealing how poor DNS hygiene and “Sitting Ducks” vulnerabilities are fueling a…
⤷ Title: Unpatched RCE: Livewire Filemanager Upload Flaw (CVE-2025-14894) Exposes Laravel Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:27:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14894 #File Upload Vulnerability #Laravel #Livewire Filemanager #PHP Security #Remote Code Execution #Unpatched Vulnerability #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:27:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14894 #File Upload Vulnerability #Laravel #Livewire Filemanager #PHP Security #Remote Code Execution #Unpatched Vulnerability #Web Security
Daily CyberSecurity
Unpatched RCE: Livewire Filemanager Upload Flaw (CVE-2025-14894) Exposes Laravel Apps
A critical new security flaw has been unearthed in Livewire Filemanager, a popular tool used within the Laravel PHP framework, potentially leaving web applications wide open to unauthenticated rem…
⤷ Title: KnownSec Data Leak Exposes State-Aligned Cyber Espionage Pipeline
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:22:49 +0000
════════════════════════
⌗ Tags: #Data Leak #APT #China MPS #cyber_espionage #data leak #DomainTools #GhostX #infosec #KnownSec #Passive Radar #Un_Mail #zoomeye
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:22:49 +0000
════════════════════════
⌗ Tags: #Data Leak #APT #China MPS #cyber_espionage #data leak #DomainTools #GhostX #infosec #KnownSec #Passive Radar #Un_Mail #zoomeye
Daily CyberSecurity
KnownSec Data Leak Exposes State-Aligned Cyber Espionage Pipeline
A massive data leak from KnownSec, a prominent Beijing-based cybersecurity firm, has exposed the inner workings of a sophisticated, state-aligned cyber espionage apparatus. The leaked documents, i…
⤷ Title: Bluetooth “Heartbleed” and DoS Flaws Found in Xiaomi Redmi Buds, No Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:19:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audio Security #Bluetooth security #CERT/CC #CVE_2025_13328 #CVE_2025_13834 #Denial of Service #Heartbleed #Privacy Leak #Redmi Buds #Xiaomi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:19:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audio Security #Bluetooth security #CERT/CC #CVE_2025_13328 #CVE_2025_13834 #Denial of Service #Heartbleed #Privacy Leak #Redmi Buds #Xiaomi
Daily CyberSecurity
Bluetooth “Heartbleed” and DoS Flaws Found in Xiaomi Redmi Buds, No Patch
A pair of critical vulnerabilities has been discovered in Xiaomi’s popular Redmi Buds series, exposing users to privacy leaks and persistent denial-of-service (DoS) attacks. According to a new vul…
⤷ Title: Invisible Intruder: Fileless Remcos RAT Hides in Shipping Emails
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2017_11882 #Cyber Security #Fileless Malware #FortiGuard Labs #Malware Analysis #phishing #Process Hollowing #Remcos RAT #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2017_11882 #Cyber Security #Fileless Malware #FortiGuard Labs #Malware Analysis #phishing #Process Hollowing #Remcos RAT #steganography
Daily CyberSecurity
Invisible Intruder: Fileless Remcos RAT Hides in Shipping Emails
A sophisticated new phishing campaign has been detected in the wild, leveraging a fileless variant of the notorious Remcos RAT (Remote Access Trojan) to evade detection and seize control of victim…