⤷ Title: Day 7 : XSS
════════════════════════
𐀪 Author: Cybersecurity with Jojo
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 21:39:46 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #tryhackme_walkthrough #xss_attack #tryhackme_writeup #cybersecurity
════════════════════════
𐀪 Author: Cybersecurity with Jojo
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 21:39:46 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #tryhackme_walkthrough #xss_attack #tryhackme_writeup #cybersecurity
Medium
Day 7 : XSS
Cross-Site Scripting (XSS) is a vulnerability that compromises the interaction a user has with a vulnerable web application. It allows an…
⤷ Title: How to make our Password stronger?
════════════════════════
𐀪 Author: Junhong Park
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 23:58:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ethical_hacking #information_security #practice
════════════════════════
𐀪 Author: Junhong Park
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 23:58:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ethical_hacking #information_security #practice
Medium
How to make our Password stronger?
Password cracking is something we encounter more often than we realize, and it may have already affected you without your knowledge.
⤷ Title: What API Developers Need to Know About PCI DSS and Financial API Security
════════════════════════
𐀪 Author: Chihurumnanya Ruth Godwin
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 23:38:54 GMT
════════════════════════
⌗ Tags: #fintech_cybersecurity #pci_dss #information_security #api_security #compliance
════════════════════════
𐀪 Author: Chihurumnanya Ruth Godwin
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 23:38:54 GMT
════════════════════════
⌗ Tags: #fintech_cybersecurity #pci_dss #information_security #api_security #compliance
Medium
What API Developers Need to Know About PCI DSS and Financial API Security
When users submit payment information, they trust systems they will never see. Behind every transaction is an API carrying sensitive data…
⤷ Title: Why API Gateways Are Critical for Securing Public APIs
════════════════════════
𐀪 Author: Esther Kenneth
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 22:42:55 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #api_gateway #api_development #api
════════════════════════
𐀪 Author: Esther Kenneth
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 22:42:55 GMT
════════════════════════
⌗ Tags: #api_security #cybersecurity #api_gateway #api_development #api
Medium
Why API Gateways Are Critical for Securing Public APIs
Public APIs power modern applications, from mobile banking and fintech platforms to SaaS products and third-party integrations. But…
⤷ Title: My Journey Learning API Security
════════════════════════
𐀪 Author: Cristina Manjarrez
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 22:14:55 GMT
════════════════════════
⌗ Tags: #api_security #qa #cybersecurity #software_testing #owasp_api_security_top_10
════════════════════════
𐀪 Author: Cristina Manjarrez
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 22:14:55 GMT
════════════════════════
⌗ Tags: #api_security #qa #cybersecurity #software_testing #owasp_api_security_top_10
Medium
My Journey Learning API Security
API security has been a truly eye-opening experience. APIs are a fundamental part of modern applications — arguably one of the most…
⤷ Title: JS Recon to Uncover Hidden Web Vulnerabilities in Minutes — And How You Can Too
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:09:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #tech #bug_bounty #cybersecurity #technology
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:09:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #tech #bug_bounty #cybersecurity #technology
Medium
JS Recon to Uncover Hidden Web Vulnerabilities in Minutes — And How You Can Too
A Practical Guide to Finding Real-World Bugs Hidden Inside JavaScript Files
⤷ Title: OSCP Exam Secrets — Avoiding Rabbit Holes and Staying on Track (Part 4)
════════════════════════
𐀪 Author: Got Root?
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:15:32 GMT
════════════════════════
⌗ Tags: #infosec #information_security #cybersecurity #information_technology #hacking
════════════════════════
𐀪 Author: Got Root?
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:15:32 GMT
════════════════════════
⌗ Tags: #infosec #information_security #cybersecurity #information_technology #hacking
Medium
OSCP Exam Secrets — Avoiding Rabbit Holes and Staying on Track (Part 4)
Part 4 reveals how smart breaks, structured reporting, and a final checklist can protect you from OSCP rabbit holes.
⤷ Title: Best Hacking Tools for 2026: From Linux to DragonOS
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:04:49 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #ethical_hacking #dragon_os #hacking_tools
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:04:49 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #ethical_hacking #dragon_os #hacking_tools
Medium
Best Hacking Tools for 2026: From Linux to DragonOS
Forget the Fancy Hacks. Your Toolkit is Your Foundation.
⤷ Title: The Walking Dead of Active Directory
════════════════════════
𐀪 Author: Nikos Vourdas (nickvourd)
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:26:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_teaming #penetration_testing #red_team #active_directory
════════════════════════
𐀪 Author: Nikos Vourdas (nickvourd)
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:26:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_teaming #penetration_testing #red_team #active_directory
Medium
The Walking Dead of Active Directory
Hello folks, @nickvourd is calling! Just your friendly neighborhood APT! The story shared in this post is inspired by a real-world…
⤷ Title: The Skeleton Key in your Pocket: Mastering The iCopy-XS (Part 2 of 5)
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:10:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #gadgets #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Nicholas Mullenski
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:10:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #gadgets #cybersecurity #ethical_hacking
Medium
The Skeleton Key in your Pocket: Mastering The iCopy-XS (Part 2 of 5)
THE MAGIC TRICK (VELOCITY & DICTIONARY ATTACKS)🔓 THE EXPECTATION VS. REALITY
⤷ Title: BYPASSING STATIC ANALYSIS
════════════════════════
𐀪 Author: Cybernight
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:07:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #security_research #threat_detection #malware_analysis
════════════════════════
𐀪 Author: Cybernight
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 01:07:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #security_research #threat_detection #malware_analysis
Medium
BYPASSING STATIC ANALYSIS
BEFORE
⤷ Title: CTF Galaxy Dash Access JWT Private Key
════════════════════════
𐀪 Author: Mr3Moe
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 03:38:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #jwt #ctf #web_security #ctf_writeup
════════════════════════
𐀪 Author: Mr3Moe
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 03:38:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #jwt #ctf #web_security #ctf_writeup
Medium
CTF Galaxy Dash Access JWT Private Key
Galaxy Dash recently rolled out new features to their application, and with that came a fresh security challenge. In this weekly lab, the…
⤷ Title: I Got Tired of Rebuilding DAST in Every Repo
════════════════════════
𐀪 Author: Rio Wiraldhani
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 02:20:56 GMT
════════════════════════
⌗ Tags: #application_security #open_source #devops #cloud_security #github_actions
════════════════════════
𐀪 Author: Rio Wiraldhani
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 02:20:56 GMT
════════════════════════
⌗ Tags: #application_security #open_source #devops #cloud_security #github_actions
Medium
I Got Tired of Rebuilding DAST in Every Repo
So I built a reusable GitHub Actions workflow for ZAP, Nuclei, and OPA
⤷ Title: XSS Made Simple: How It Works, Why It’s Dangerous, and How Hackers Use JavaScript
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Researcher
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 03:40:41 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #pentesting #xss_attack #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Researcher
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 03:40:41 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #pentesting #xss_attack #cybersecurity #bug_bounty_tips
Medium
XSS Made Simple: How It Works, Why It’s Dangerous, and How Hackers Use JavaScript
“Wait… how can a website attack me from inside itself?”
⤷ Title: Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 10:34:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 10:34:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:46:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Asian Cyber Threat #BadIIS #Cisco Talos #cyber_espionage #GotoHTTP #IIS Security #Linux Malware #SEO Fraud #UAT_8099 #WEBJACK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:46:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Asian Cyber Threat #BadIIS #Cisco Talos #cyber_espionage #GotoHTTP #IIS Security #Linux Malware #SEO Fraud #UAT_8099 #WEBJACK
Daily CyberSecurity
IIS Under Siege: UAT-8099 Deploys Region-Locked "BadIIS" & Linux Variants
Cisco Talos warns of UAT-8099 targeting Asian IIS servers with region-locked BadIIS malware. New variants now attack Linux systems.
⤷ Title: The “Fix” is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:42:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AuthCodeFix #Azure CLI #Conditional Access #ConsentFix #MFA Bypass #Microsoft Entra ID #NVISO #OAuth Abuse #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:42:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AuthCodeFix #Azure CLI #Conditional Access #ConsentFix #MFA Bypass #Microsoft Entra ID #NVISO #OAuth Abuse #phishing #social engineering
Daily CyberSecurity
The "Fix" is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI
"ConsentFix" phishing tricks users into pasting OAuth codes from Azure CLI, bypassing MFA and Conditional Access. Detect this "fix" scam now.
⤷ Title: Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
Daily CyberSecurity
Signed & Stolen: "Phantom Stealer" Hijacks Java App via Fake DHL Invoice
Attackers use fake DHL invoices to sideload Phantom Stealer v3.5.0 via a signed Java utility. Malware hides in AddInProcess32.exe. Watch out.
⤷ Title: New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:32:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT IRAN #Critical Infrastructure #Cyber Warfare #ICS security #IEC 61850 #IRGC #Lab52 #OT Security #Power Grid Attacks #SCADA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:32:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT IRAN #Critical Infrastructure #Cyber Warfare #ICS security #IEC 61850 #IRGC #Lab52 #OT Security #Power Grid Attacks #SCADA
Daily CyberSecurity
New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web
New "APT IRAN" framework targets energy grids & military networks. Lab52 links the tool to the IRGC. See the threat to critical infrastructure.
⤷ Title: Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Asterisk #CVE_2025_64328 #EncystPHP #FortiGuard Labs #FreePBX #INJ3CTOR3 #Malware Analysis #persistence #VoIP Security #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Asterisk #CVE_2025_64328 #EncystPHP #FortiGuard Labs #FreePBX #INJ3CTOR3 #Malware Analysis #persistence #VoIP Security #Web Shell
Daily CyberSecurity
Silent Intruder: "EncystPHP" Web Shell Burrows into FreePBX Systems
INJ3CTOR3 hackers target FreePBX with EncystPHP web shell via CVE-2025-64328. Malware uses cron jobs for persistence. Patch immediately.
⤷ Title: “Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audit Logs #Cloud Security #data exfiltration #Email Security #Exfil Out&Look #Insider Threat #Microsoft 365 #Outlook Web Access #OWA #Varonis Threat Labs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audit Logs #Cloud Security #data exfiltration #Email Security #Exfil Out&Look #Insider Threat #Microsoft 365 #Outlook Web Access #OWA #Varonis Threat Labs
Daily CyberSecurity
"Exfil Out&Look" Flaw Lets Spies Steal Emails via OWA Undetected
New "Exfil Out&Look" attack uses OWA add-ins to steal emails without leaving logs. Microsoft has no immediate fix for this blind spot.