⤷ Title: [Rabbit Store] — JWT Manipulation, SSRF, SSTI Leading to RCE and Root Access via a Vulnerable…
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:51:31 GMT
════════════════════════
⌗ Tags: #rce #ssrf #privilege_escalation #ssti #jwt_token
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 21:51:31 GMT
════════════════════════
⌗ Tags: #rce #ssrf #privilege_escalation #ssti #jwt_token
Medium
[Rabbit Store] — JWT Manipulation, SSRF, SSTI Leading to RCE and Root Access via a Vulnerable Erlang Distribution on RabbitMQ
From SSRF and SSTI to Erlang cookie theft and root compromise.
⤷ Title: Blind SQL Injection: A Hands-On Lab Walkthrough
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:32:59 GMT
════════════════════════
⌗ Tags: #hacker #hacking_tutorial #hacking
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:32:59 GMT
════════════════════════
⌗ Tags: #hacker #hacking_tutorial #hacking
Medium
Blind SQL Injection: A Hands-On Lab Walkthrough
In a standard SQL injection, the database often spits out helpful error messages or direct data. But what happens when the application is…
⤷ Title: Welcome to my space :)
════════════════════════
𐀪 Author: Hobin Rood
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:18:00 GMT
════════════════════════
⌗ Tags: #osint #freelancing #hacking #osint_investigation #education
════════════════════════
𐀪 Author: Hobin Rood
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:18:00 GMT
════════════════════════
⌗ Tags: #osint #freelancing #hacking #osint_investigation #education
Medium
Welcome to my space :)
Welcome to the Network (the name I have still yet to decide).
⤷ Title: Beyond the Noise: Why I Built VedicRecon (and Why Reconnaissance Needs to Change)
════════════════════════
𐀪 Author: Vedic_error
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:11:49 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #cybersecurity #ethical_hacking #generative_ai_tools
════════════════════════
𐀪 Author: Vedic_error
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 23:11:49 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #cybersecurity #ethical_hacking #generative_ai_tools
Medium
Beyond the Noise: Why I Built VedicRecon (and Why Reconnaissance Needs to Change)
⚠️All testing described below was performed in a fully isolated lab environment for educational and defensive research purposes only. No…
⤷ Title: Phishing Simulator
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:16:16 GMT
════════════════════════
⌗ Tags: #ethical_hacking #python_web_developer #html5_development #phishing_awareness
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 18 Jan 2026 22:16:16 GMT
════════════════════════
⌗ Tags: #ethical_hacking #python_web_developer #html5_development #phishing_awareness
Medium
Phishing Simulator
This is for educational purposes only! Do not use unless authorized.
⤷ Title: Fake Malwarebytes Campaign Exploits DLL Sideloading to Drop Infostealers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:46:26 +0000
════════════════════════
⌗ Tags: #Malware #BrowserStealer #CoreMessaging.dll #Cyber Security #DLL Sideloading #Infostealer #Joseliyo Sánchez #Malware Analysis #Malwarebytes #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:46:26 +0000
════════════════════════
⌗ Tags: #Malware #BrowserStealer #CoreMessaging.dll #Cyber Security #DLL Sideloading #Infostealer #Joseliyo Sánchez #Malware Analysis #Malwarebytes #social engineering
Daily CyberSecurity
Fake Malwarebytes Campaign Exploits DLL Sideloading to Drop Infostealers
New malware campaign impersonates Malwarebytes installers. Hackers use DLL sideloading to deploy infostealers targeting crypto & MFA. Verify downloads now.
⤷ Title: CVE-2026-0695: High-Severity XSS Flaw Patched in ConnectWise PSA 2026.1
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise PSA #CVE_2026_0695 #CVE_2026_0696 #Cyber Security #MSP Security #Patch Alert #Session Hijacking #Stored XSS #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise PSA #CVE_2026_0695 #CVE_2026_0696 #Cyber Security #MSP Security #Patch Alert #Session Hijacking #Stored XSS #Web Security
Daily CyberSecurity
CVE-2026-0695: High-Severity XSS Flaw Patched in ConnectWise PSA 2026.1
ConnectWise has released a crucial security update for its Professional Services Automation (PSA) platform, addressing two significant vulnerabilities that could allow attackers to weaponize munda…
⤷ Title: DragonForce: The Rise of a New “Ransomware Cartel” Built on LockBit and Conti DNA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:42:44 +0000
════════════════════════
⌗ Tags: #Malware #BlackLock #Conti #Cyber Cartel #decryptor #DragonForce #infosec #LockBit 3.0 #Malware Analysis #RansomBay #ransomware #S2W
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:42:44 +0000
════════════════════════
⌗ Tags: #Malware #BlackLock #Conti #Cyber Cartel #decryptor #DragonForce #infosec #LockBit 3.0 #Malware Analysis #RansomBay #ransomware #S2W
Daily CyberSecurity
DragonForce: The Rise of a New “Ransomware Cartel” Built on LockBit and Conti DNA
A comprehensive new analysis by security researchers at S2W details the inner workings of the DragonForce Ransomware Group, revealing a threat actor that is not only deploying sophisticated malwar…
⤷ Title: Fake Productivity Tools: 5 Malicious Chrome Extensions Hijack Enterprise Sessions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:37:04 +0000
════════════════════════
⌗ Tags: #Malware #Chrome extensions #Cookie Injection #DataByCloud #Enterprise Security #infosec #malware #NetSuite #Session Hijacking #Socket Threat Research #Workday
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:37:04 +0000
════════════════════════
⌗ Tags: #Malware #Chrome extensions #Cookie Injection #DataByCloud #Enterprise Security #infosec #malware #NetSuite #Session Hijacking #Socket Threat Research #Workday
Daily CyberSecurity
Fake Productivity Tools: 5 Malicious Chrome Extensions Hijack Enterprise Sessions
A new and sophisticated campaign targeting enterprise environments has been uncovered by Socket’s Threat Research Team. Five malicious Google Chrome extensions, masquerading as productivity …
⤷ Title: Sitting Ducks and Scammy Notifications: Inside a Global Malvertising Operation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:32:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Fraud #Android security #Cyber Crime #Cyber Hygiene #DNS hijacking #DNS Vulnerability #Infoblox #Malvertising #Push Notification Scam #Sitting Ducks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:32:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Fraud #Android security #Cyber Crime #Cyber Hygiene #DNS hijacking #DNS Vulnerability #Infoblox #Malvertising #Push Notification Scam #Sitting Ducks
Daily CyberSecurity
Sitting Ducks and Scammy Notifications: Inside a Global Malvertising Operation
Researchers at Infoblox have peeled back the curtain on a massive, deceptive push notification network, revealing how poor DNS hygiene and “Sitting Ducks” vulnerabilities are fueling a…
⤷ Title: Unpatched RCE: Livewire Filemanager Upload Flaw (CVE-2025-14894) Exposes Laravel Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:27:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14894 #File Upload Vulnerability #Laravel #Livewire Filemanager #PHP Security #Remote Code Execution #Unpatched Vulnerability #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:27:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14894 #File Upload Vulnerability #Laravel #Livewire Filemanager #PHP Security #Remote Code Execution #Unpatched Vulnerability #Web Security
Daily CyberSecurity
Unpatched RCE: Livewire Filemanager Upload Flaw (CVE-2025-14894) Exposes Laravel Apps
A critical new security flaw has been unearthed in Livewire Filemanager, a popular tool used within the Laravel PHP framework, potentially leaving web applications wide open to unauthenticated rem…
⤷ Title: KnownSec Data Leak Exposes State-Aligned Cyber Espionage Pipeline
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:22:49 +0000
════════════════════════
⌗ Tags: #Data Leak #APT #China MPS #cyber_espionage #data leak #DomainTools #GhostX #infosec #KnownSec #Passive Radar #Un_Mail #zoomeye
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:22:49 +0000
════════════════════════
⌗ Tags: #Data Leak #APT #China MPS #cyber_espionage #data leak #DomainTools #GhostX #infosec #KnownSec #Passive Radar #Un_Mail #zoomeye
Daily CyberSecurity
KnownSec Data Leak Exposes State-Aligned Cyber Espionage Pipeline
A massive data leak from KnownSec, a prominent Beijing-based cybersecurity firm, has exposed the inner workings of a sophisticated, state-aligned cyber espionage apparatus. The leaked documents, i…
⤷ Title: Bluetooth “Heartbleed” and DoS Flaws Found in Xiaomi Redmi Buds, No Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:19:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audio Security #Bluetooth security #CERT/CC #CVE_2025_13328 #CVE_2025_13834 #Denial of Service #Heartbleed #Privacy Leak #Redmi Buds #Xiaomi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:19:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audio Security #Bluetooth security #CERT/CC #CVE_2025_13328 #CVE_2025_13834 #Denial of Service #Heartbleed #Privacy Leak #Redmi Buds #Xiaomi
Daily CyberSecurity
Bluetooth “Heartbleed” and DoS Flaws Found in Xiaomi Redmi Buds, No Patch
A pair of critical vulnerabilities has been discovered in Xiaomi’s popular Redmi Buds series, exposing users to privacy leaks and persistent denial-of-service (DoS) attacks. According to a new vul…
⤷ Title: Invisible Intruder: Fileless Remcos RAT Hides in Shipping Emails
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2017_11882 #Cyber Security #Fileless Malware #FortiGuard Labs #Malware Analysis #phishing #Process Hollowing #Remcos RAT #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:15:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2017_11882 #Cyber Security #Fileless Malware #FortiGuard Labs #Malware Analysis #phishing #Process Hollowing #Remcos RAT #steganography
Daily CyberSecurity
Invisible Intruder: Fileless Remcos RAT Hides in Shipping Emails
A sophisticated new phishing campaign has been detected in the wild, leveraging a fileless variant of the notorious Remcos RAT (Remote Access Trojan) to evade detection and seize control of victim…
⤷ Title: Critical Deno Flaws Risk Secrets (CVE-2026-22863) & Execution (CVE-2026-22864)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:14:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #cryptography #CVE_2026_22863 #CVE_2026_22864 #Deno #JavaScript Security #Node.js Compatibility #Patch Alert #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:14:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #cryptography #CVE_2026_22863 #CVE_2026_22864 #Deno #JavaScript Security #Node.js Compatibility #Patch Alert #Windows Security
Daily CyberSecurity
Critical Deno Flaws Risk Secrets (CVE-2026-22863) & Execution (CVE-2026-22864)
Deno, CVE-2026-22863, CVE-2026-22864, JavaScript Security, Cryptography, Command Injection, Windows Security, Node.js Compatibility, Patch Alert
⤷ Title: New “LOTUSLITE” Backdoor Targets U.S. Government in Suspected Mustang Panda Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:11:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Acronis TRU #APT #DLL Sideloading #Espionage #LOTUSLITE #Malware Analysis #Mustang Panda #spear_phishing #US government
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:11:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Acronis TRU #APT #DLL Sideloading #Espionage #LOTUSLITE #Malware Analysis #Mustang Panda #spear_phishing #US government
Daily CyberSecurity
New “LOTUSLITE” Backdoor Targets U.S. Government in Suspected Mustang Panda Campaign
A new espionage campaign targeting U.S. government entities has been uncovered, utilizing a custom backdoor dubbed LOTUSLITE. Researchers from the Acronis Threat Research Unit (TRU) have linked th…
⤷ Title: Critical ABB Alert: OPTIMAX Flaw Allows Full System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB #Ability OPTIMAX #Authentication Bypass #Azure AD #Critical Infrastructure #CVE_2025_14510 #CVSS 9.2 #ICS #Industrial Security #SCADA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB #Ability OPTIMAX #Authentication Bypass #Azure AD #Critical Infrastructure #CVE_2025_14510 #CVSS 9.2 #ICS #Industrial Security #SCADA
Daily CyberSecurity
Critical ABB Alert: OPTIMAX Flaw Allows Full System Takeover
Critical: ABB OPTIMAX flaw CVE-2025-14510 (CVSS 9.2) allows auth bypass via Azure AD. Attackers can shut down systems. Patch or disable SSO now.
⤷ Title: The Fake “RedLine”: Imposter Malware Hijacks Crypto Wallets on Discord
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:05:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Clipboard Hijacker #CloudSEK #Cryptocurrency Theft #Discord Security #Python Malware #Redline stealer #RedLineCyber #social engineering #Wallet drainer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:05:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Clipboard Hijacker #CloudSEK #Cryptocurrency Theft #Discord Security #Python Malware #Redline stealer #RedLineCyber #social engineering #Wallet drainer
Daily CyberSecurity
The Fake "RedLine": Imposter Malware Hijacks Crypto Wallets on Discord
CloudSEK exposes "RedLineCyber," an impostor hijacking crypto clipboards on Discord. This stealthy malware drains wallets without a C2 server.
⤷ Title: Decades-Old Flaw & New Heap Corruption: Critical glibc Bugs Revealed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:01:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASLR Bypass #CVE_2026_0861 #CVE_2026_0915 #glibc #GNU C Library #heap corruption #infosec #integer overflow #Linux Security #Memory Leak
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 00:01:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASLR Bypass #CVE_2026_0861 #CVE_2026_0915 #glibc #GNU C Library #heap corruption #infosec #integer overflow #Linux Security #Memory Leak
Daily CyberSecurity
Decades-Old Flaw & New Heap Corruption: Critical glibc Bugs Revealed
The maintainers of the GNU C Library (glibc), the core library that underpins the vast majority of Linux-based systems, have disclosed details on two security vulnerabilities ranging from high-sev…
⤷ Title: Mastering Input Handling in PHP: A Deep Dive into ‘Sanitize’ vs ‘Validate’
════════════════════════
𐀪 Author: Ann R.
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 01:36:19 GMT
════════════════════════
⌗ Tags: #input_sanitization #input_validation #sql_injection #php #prepared_statements
════════════════════════
𐀪 Author: Ann R.
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 01:36:19 GMT
════════════════════════
⌗ Tags: #input_sanitization #input_validation #sql_injection #php #prepared_statements
Medium
Mastering Input Handling in PHP: A Deep Dive into ‘Sanitize’ vs ‘Validate’
How Proper Input Validation and Sanitization Can Secure Your PHP Applications
⤷ Title: The Silent Listener: WhisperPair Exploit Turns Flagship Headphones into Spy Tools
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 04:00:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bluetooth Security #cybersecurity #Find My Device #Google Fast Pair #Google Pixel Buds #InfoSec 2026 #JBL #KU Leuven #privacy #Sony #WhisperPair
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 04:00:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bluetooth Security #cybersecurity #Find My Device #Google Fast Pair #Google Pixel Buds #InfoSec 2026 #JBL #KU Leuven #privacy #Sony #WhisperPair
Penetration Testing Tools
The Silent Listener: WhisperPair Exploit Turns Flagship Headphones into Spy Tools
Envision strolling through a thoroughfare, enveloped in the melodies of your headphones, utterly oblivious to the specter of