⤷ Title: XSS Made Simple: How It Works, Why It’s Dangerous, and How Hackers Use JavaScript
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Researcher
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 03:40:41 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #pentesting #xss_attack #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Researcher
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 03:40:41 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #pentesting #xss_attack #cybersecurity #bug_bounty_tips
Medium
XSS Made Simple: How It Works, Why It’s Dangerous, and How Hackers Use JavaScript
“Wait… how can a website attack me from inside itself?”
⤷ Title: Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 10:34:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 10:34:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:46:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Asian Cyber Threat #BadIIS #Cisco Talos #cyber_espionage #GotoHTTP #IIS Security #Linux Malware #SEO Fraud #UAT_8099 #WEBJACK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:46:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Asian Cyber Threat #BadIIS #Cisco Talos #cyber_espionage #GotoHTTP #IIS Security #Linux Malware #SEO Fraud #UAT_8099 #WEBJACK
Daily CyberSecurity
IIS Under Siege: UAT-8099 Deploys Region-Locked "BadIIS" & Linux Variants
Cisco Talos warns of UAT-8099 targeting Asian IIS servers with region-locked BadIIS malware. New variants now attack Linux systems.
⤷ Title: The “Fix” is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:42:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AuthCodeFix #Azure CLI #Conditional Access #ConsentFix #MFA Bypass #Microsoft Entra ID #NVISO #OAuth Abuse #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:42:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AuthCodeFix #Azure CLI #Conditional Access #ConsentFix #MFA Bypass #Microsoft Entra ID #NVISO #OAuth Abuse #phishing #social engineering
Daily CyberSecurity
The "Fix" is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI
"ConsentFix" phishing tricks users into pasting OAuth codes from Azure CLI, bypassing MFA and Conditional Access. Detect this "fix" scam now.
⤷ Title: Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:36:35 +0000
════════════════════════
⌗ Tags: #Malware #AddInProcess32.exe #DHL Phishing #DLL Sideloading #info_stealer #Java security #jdeps.exe #Malware Analysis #Manoj Kshirsagar #Phantom Stealer #Process Hollowing
Daily CyberSecurity
Signed & Stolen: "Phantom Stealer" Hijacks Java App via Fake DHL Invoice
Attackers use fake DHL invoices to sideload Phantom Stealer v3.5.0 via a signed Java utility. Malware hides in AddInProcess32.exe. Watch out.
⤷ Title: New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:32:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT IRAN #Critical Infrastructure #Cyber Warfare #ICS security #IEC 61850 #IRGC #Lab52 #OT Security #Power Grid Attacks #SCADA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:32:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT IRAN #Critical Infrastructure #Cyber Warfare #ICS security #IEC 61850 #IRGC #Lab52 #OT Security #Power Grid Attacks #SCADA
Daily CyberSecurity
New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web
New "APT IRAN" framework targets energy grids & military networks. Lab52 links the tool to the IRGC. See the threat to critical infrastructure.
⤷ Title: Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Asterisk #CVE_2025_64328 #EncystPHP #FortiGuard Labs #FreePBX #INJ3CTOR3 #Malware Analysis #persistence #VoIP Security #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Asterisk #CVE_2025_64328 #EncystPHP #FortiGuard Labs #FreePBX #INJ3CTOR3 #Malware Analysis #persistence #VoIP Security #Web Shell
Daily CyberSecurity
Silent Intruder: "EncystPHP" Web Shell Burrows into FreePBX Systems
INJ3CTOR3 hackers target FreePBX with EncystPHP web shell via CVE-2025-64328. Malware uses cron jobs for persistence. Patch immediately.
⤷ Title: “Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audit Logs #Cloud Security #data exfiltration #Email Security #Exfil Out&Look #Insider Threat #Microsoft 365 #Outlook Web Access #OWA #Varonis Threat Labs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Audit Logs #Cloud Security #data exfiltration #Email Security #Exfil Out&Look #Insider Threat #Microsoft 365 #Outlook Web Access #OWA #Varonis Threat Labs
Daily CyberSecurity
"Exfil Out&Look" Flaw Lets Spies Steal Emails via OWA Undetected
New "Exfil Out&Look" attack uses OWA add-ins to steal emails without leaving logs. Microsoft has no immediate fix for this blind spot.
⤷ Title: Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:11:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Fileless Malware #IAB #initial access broker #Malware Analysis #Null Byte Injection #Proofpoint #ransomware #Registry Persistence #TA584 #Tsundere Bot
Daily CyberSecurity
Hidden in Plain Sight: TA584 Deploys "Tsundere Bot" & Invisible Registry Keys
TA584 triples activity with new "Tsundere Bot" malware. Attackers use invisible Registry keys to hide persistence. Read the Proofpoint analysis.
⤷ Title: Wrapped in Stealth: Python RAT Hides Inside ELF Binary to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:05:00 +0000
════════════════════════
⌗ Tags: #Malware #Adaptive Beaconing #anti_forensics #Cross_Platform Malware #Cyber Security #ELF Binary #K7 Labs #Malware Analysis #PyInstaller #Python Malware #rat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:05:00 +0000
════════════════════════
⌗ Tags: #Malware #Adaptive Beaconing #anti_forensics #Cross_Platform Malware #Cyber Security #ELF Binary #K7 Labs #Malware Analysis #PyInstaller #Python Malware #rat
Daily CyberSecurity
Wrapped in Stealth: Python RAT Hides Inside ELF Binary to Evade Detection
K7 Labs uncovers a stealthy Python-based RAT disguised as an ELF binary. Features adaptive beaconing and anti-forensics to stay hidden. Read the analysis.
⤷ Title: AI-Coded Malware: Vietnamese “Huna” Actor Targets Job Seekers with PureRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:00:55 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cybercrime #Huna #Job Scam #Malware Analysis #phishing #PureRAT #social engineering #Threat Hunter Team #Vietnam Hacker
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 00:00:55 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cybercrime #Huna #Job Scam #Malware Analysis #phishing #PureRAT #social engineering #Threat Hunter Team #Vietnam Hacker
Daily CyberSecurity
AI-Coded Malware: Vietnamese "Huna" Actor Targets Job Seekers with PureRAT
New AI-generated malware campaign targets job seekers. Vietnamese actor "Huna" uses fake job offers to deliver PureRAT via Dropbox.
⤷ Title: Vibe Coding: Balancing Speed and Security
════════════════════════
𐀪 Author: Sherman Davis
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:09:46 GMT
════════════════════════
⌗ Tags: #ai #software_development #cybersecurity #vibe_coding #application_security
════════════════════════
𐀪 Author: Sherman Davis
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:09:46 GMT
════════════════════════
⌗ Tags: #ai #software_development #cybersecurity #vibe_coding #application_security
Medium
Vibe Coding: Balancing Speed and Security
The demand for developers to produce more applications at an unprecedented speed has made many shift to vibe coding. What is vibe coding…
⤷ Title: 25 Best Hacking Movies For Cybersecurity Enthusiasts [2026 List]
════════════════════════
𐀪 Author: Alex Cole
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:18:37 GMT
════════════════════════
⌗ Tags: #coding #college #students #assignmentdude #hacking
════════════════════════
𐀪 Author: Alex Cole
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:18:37 GMT
════════════════════════
⌗ Tags: #coding #college #students #assignmentdude #hacking
Medium
25 Best Hacking Movies For Cybersecurity Enthusiasts [2026 List]
It’s 2 a.m. in my dorm room, and I’m three energy drinks deep into debugging a network security lab. My roommate walks in, sees my terminal…
⤷ Title: Zero Trust in Cybersecurity Sounds So Cool, but the Failure Rate Is Around 75%!
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:28:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #cyberattack #zero_trust #cybercrime
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:28:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #cyberattack #zero_trust #cybercrime
Medium
Zero Trust in Cybersecurity Sounds So Cool, but the Failure Rate Is Around 75%!
The Seduction of Perfection
⤷ Title: Uchiha Seruapk
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:25:22 GMT
════════════════════════
⌗ Tags: #games #uchihaapk #apkpure #apk_mod #hacking
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:25:22 GMT
════════════════════════
⌗ Tags: #games #uchihaapk #apkpure #apk_mod #hacking
Medium
Uchiha Seruapk
Nếu bạn đang tìm một ứng dụng hỗ trợ đơn giản, không rườm rà nhưng vẫn mang lại hiệu quả sử dụng ổn định, Uchiha Seruapk là lựa chọn đáng…
⤷ Title: Agent vs. Agent: How I Used CHACK to Audit OpenClaw and Uncover 10 Critical Flaws
════════════════════════
𐀪 Author: MaanVader
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:18:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai_security #information_technology #ai #infosec
════════════════════════
𐀪 Author: MaanVader
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:18:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai_security #information_technology #ai #infosec
Medium
Agent vs. Agent: How I Used CHACK to Audit OpenClaw and Uncover 10 Critical Flaws
Introduction:
⤷ Title: Operation Slither
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:11:49 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_writeup #tryhackme_walkthrough #ctf_writeup #operation_slither
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 04:11:49 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_writeup #tryhackme_walkthrough #ctf_writeup #operation_slither
Medium
Operation Slither
Follow the leads and find who’s behind this operation.
⤷ Title: Protecting Social Media Accounts from Unauthorised Access
════════════════════════
𐀪 Author: Elizabeth (Libby)
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:04:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybersecurity_awareness #social_media #ethical_hacking
════════════════════════
𐀪 Author: Elizabeth (Libby)
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:04:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybersecurity_awareness #social_media #ethical_hacking
Medium
Protecting Social Media Accounts from Unauthorised Access
Recent studies show that 70% of recruiters check social media profiles during the hiring process. For example, John lost a job offer after…
⤷ Title: Why Your Twitter Data Pipeline Probably Sucks (And How to Actually Fix It)
════════════════════════
𐀪 Author: Afjgku
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:21:25 GMT
════════════════════════
⌗ Tags: #api #twitter #saas #xs
════════════════════════
𐀪 Author: Afjgku
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 05:21:25 GMT
════════════════════════
⌗ Tags: #api #twitter #saas #xs
Medium
Why Your Twitter Data Pipeline Probably Sucks (And How to Actually Fix It)
Part 1: The Problem Nobody Talks About
⤷ Title: eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 11:17:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 11:17:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Notepad++ Hijacked: State-Sponsored Actors Poisoned Updates for Months
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 07:55:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Chinese hackers #cybersecurity #malware #notepad++ #Open Source Security #Patch Alert #state_sponsored #supply chain attack #Update Hijack #WinGUp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Feb 2026 07:55:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Chinese hackers #cybersecurity #malware #notepad++ #Open Source Security #Patch Alert #state_sponsored #supply chain attack #Update Hijack #WinGUp
Daily CyberSecurity
Notepad++ Hijacked: State-Sponsored Actors Poisoned Updates for Months
Notepad++ confirms update infrastructure was compromised by state-sponsored actors targeting specific users. Update to version 8.8.9 immediately.