⤷ Title: Race Conditions Tryhackme — (Challenge Web App)
════════════════════════
𐀪 Author: Panglimaizza
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 18:45:51 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_writeup #cybersecurity #ctf_writeup #penetration_testing
════════════════════════
𐀪 Author: Panglimaizza
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 18:45:51 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_writeup #cybersecurity #ctf_writeup #penetration_testing
Medium
Race Conditions Tryhackme — (Challenge Web App)
Introduction
⤷ Title: What Is Phishing & How It Steals Your Data
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 19:40:21 GMT
════════════════════════
⌗ Tags: #cyberattack #phishing #ethical_hacking #technology #data_science
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 19:40:21 GMT
════════════════════════
⌗ Tags: #cyberattack #phishing #ethical_hacking #technology #data_science
Medium
What Is Phishing & How It Steals Your Data
It does not Hack Your Software it Hacks Your Trust
⤷ Title: Proving Grounds: Prison (Linux) Full Walkthrough
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
Medium
📝 [Writeup] Proving Grounds: Prison (Linux)
From Prison Break to Jenkins Break: Tunnelling for Root
⤷ Title: Vulnerability Analysis: Reflected XSS via React Bypass and CSP Whitelist Gadget
════════════════════════
𐀪 Author: lightofmoon
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 21:43:43 GMT
════════════════════════
⌗ Tags: #hacking #html #penetration_testing #web_development #web_penetration_testing
════════════════════════
𐀪 Author: lightofmoon
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 21:43:43 GMT
════════════════════════
⌗ Tags: #hacking #html #penetration_testing #web_development #web_penetration_testing
Medium
Vulnerability Analysis: Reflected XSS via React Bypass and CSP Whitelist Gadget
Executive Summary
⤷ Title: TryHackMe (THM) Further Nmap Walkthrough + Answers
════════════════════════
𐀪 Author: Mann Diwani
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 21:29:31 GMT
════════════════════════
⌗ Tags: #port_scanning #nmap #tryhackme #network_mapping_tools #tryhackme_walkthrough
════════════════════════
𐀪 Author: Mann Diwani
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 21:29:31 GMT
════════════════════════
⌗ Tags: #port_scanning #nmap #tryhackme #network_mapping_tools #tryhackme_walkthrough
⤷ Title: What Learning API Security Taught Me About Building Systems for the Real World
════════════════════════
𐀪 Author: Chihurumnanya Ruth Godwin
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 21:04:59 GMT
════════════════════════
⌗ Tags: #learning #cyber_security_awareness #api_security #information_technology #technology
════════════════════════
𐀪 Author: Chihurumnanya Ruth Godwin
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 21:04:59 GMT
════════════════════════
⌗ Tags: #learning #cyber_security_awareness #api_security #information_technology #technology
Medium
What Learning API Security Taught Me About Building Systems for the Real World
When I first began learning about API security, my understanding was narrow and overly optimistic. I believed that once an endpoint…
⤷ Title: How to Use Python to Detect SQL Injection
════════════════════════
𐀪 Author: Ilkay Adil
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 13:16:07 GMT
════════════════════════
⌗ Tags: #sql_server #sql #sql_injection #python_programming #python
════════════════════════
𐀪 Author: Ilkay Adil
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 13:16:07 GMT
════════════════════════
⌗ Tags: #sql_server #sql #sql_injection #python_programming #python
Medium
How to Use Python to Detect SQL Injection (Beginner-Friendly Guide)
SQL Injection is one of the oldest — and still one of the most dangerous — vulnerabilities in web applications. The good news is that you…
⤷ Title: Jobert Abma — A Determined Black Man & A $50,000 Bounty — Chains, Coke & Doubles
════════════════════════
𐀪 Author: Justas_b_2
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:39:39 GMT
════════════════════════
⌗ Tags: #ethical_hacking #hacker #hackerone #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Justas_b_2
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:39:39 GMT
════════════════════════
⌗ Tags: #ethical_hacking #hacker #hackerone #cybersecurity #bug_bounty
Medium
Jobert Abma — A Determined Black Man & A $50,000 Bounty — Chains, Coke & Doubles
Against all odds, this is the inspiring true story of one African American man who triumphed over grueling work conditions, a fabricated…
⤷ Title: The Invisible Flaw: A Write-Up on Business Logic & Access Control
════════════════════════
𐀪 Author: lightofmoon
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 22:13:44 GMT
════════════════════════
⌗ Tags: #web_development #bug_bounty #logic #money #web_penetration_testing
════════════════════════
𐀪 Author: lightofmoon
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 22:13:44 GMT
════════════════════════
⌗ Tags: #web_development #bug_bounty #logic #money #web_penetration_testing
Medium
The Invisible Flaw: A Write-Up on Business Logic & Access Control
1. The Challenge Analysis (Barbarossa CTF)
⤷ Title: What If SSO Logged You In Without Checking Your Password?
════════════════════════
𐀪 Author: Sujaykumar
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:40:57 GMT
════════════════════════
⌗ Tags: #sso_authentication #identity_management #application_security #cybersecurity #enterprise_security
════════════════════════
𐀪 Author: Sujaykumar
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:40:57 GMT
════════════════════════
⌗ Tags: #sso_authentication #identity_management #application_security #cybersecurity #enterprise_security
Medium
What If SSO Logged You In Without Checking Your Password?
What If Your SSO Never Checked the Password?
⤷ Title: When Trust Backfires: Inside the Sophisticated Supply-Chain Hack of Notepad++
════════════════════════
𐀪 Author: Aaron
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:37:13 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #programming #hacking #information_technology
════════════════════════
𐀪 Author: Aaron
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:37:13 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #programming #hacking #information_technology
Medium
When Trust Backfires: Inside the Sophisticated Supply-Chain Hack of Notepad++
How advanced attackers weaponized a beloved developer tool using elite tradecraft and a clever abuse of security software
⤷ Title: Discovering PPL Protection in Windows Processes
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:27:19 GMT
════════════════════════
⌗ Tags: #malware #hackthebox #tryhackme #hacking #cybersecurity
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:27:19 GMT
════════════════════════
⌗ Tags: #malware #hackthebox #tryhackme #hacking #cybersecurity
Medium
Discovering PPL Protection in Windows Processes
Welcome to my latest post! Today, we’re exploring the classic method for identifying the Protected Process Light (PPL) status of a specific…
⤷ Title: From INTERPOL to Hollywood: How Real Cybercrime Differs from TV Hacking
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 22:42:43 GMT
════════════════════════
⌗ Tags: #hollywood #cybersecurity #script_consultant #hacking #hollywood_movies
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 22:42:43 GMT
════════════════════════
⌗ Tags: #hollywood #cybersecurity #script_consultant #hacking #hollywood_movies
Medium
From INTERPOL to Hollywood: How Real Cybercrime Differs from TV Hacking
Let me tell you about the first time a Hollywood producer called me. I was sitting in my office, surrounded by too many monitors, not…
⤷ Title: [Writeup] Proving Grounds: Prison (Linux)
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
Medium
📝 [Writeup] Proving Grounds: Prison (Linux)
From Prison Break to Jenkins Break: Tunnelling for Root
⤷ Title: Rooted via Wi-Fi 7: TP-Link Patches Command Injection in Archer BE230
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:50:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer BE230 #Command Injection #CVE_2026_0630 #CVE_2026_22229 #Cyber Security #firmware update #Home Network Security #router security #TP_Link #Wi_Fi 7
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:50:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer BE230 #Command Injection #CVE_2026_0630 #CVE_2026_22229 #Cyber Security #firmware update #Home Network Security #router security #TP_Link #Wi_Fi 7
Daily CyberSecurity
Rooted via Wi-Fi 7: TP-Link Patches Command Injection in Archer BE230
TP-Link discloses command injection flaws in Archer BE230 routers (CVE-2026-0630). Authenticated attackers can gain root access. Update firmware now.
⤷ Title: CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:45:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADM #Arbitrary File Write #ASUSTOR #Critical Vulnerability #CVE_2026_24936 #Data Integrity #NAS security #Patch Alert #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:45:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADM #Arbitrary File Write #ASUSTOR #Critical Vulnerability #CVE_2026_24936 #Data Integrity #NAS security #Patch Alert #ransomware
Daily CyberSecurity
CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover
Critical ASUSTOR ADM flaw CVE-2026-24936 (CVSS 9.5) allows remote file overwrite. Unauthenticated attackers can seize NAS control. Update to v5.1.2 now.
⤷ Title: “IT Support” Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Corporate Security #Extortion #identity theft #Mandiant #MFA Bypass #ShinyHunters #social engineering #UNC6661 #UNC6671 #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Corporate Security #Extortion #identity theft #Mandiant #MFA Bypass #ShinyHunters #social engineering #UNC6661 #UNC6671 #Vishing
Daily CyberSecurity
"IT Support" Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
Mandiant warns of vishing rings like ShinyHunters impersonating IT support to bypass MFA and steal corporate cloud data. Verify your callers.
⤷ Title: Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:36:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2026_23947 #CVE_2026_25141 #Developer Tools #JavaScript Security #OpenAPI #Orval #Supply Chain Security #TypeScript #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:36:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2026_23947 #CVE_2026_25141 #Developer Tools #JavaScript Security #OpenAPI #Orval #Supply Chain Security #TypeScript #web development
Daily CyberSecurity
Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
Critical Orval flaw CVE-2026-25141 (CVSS 9.3) allows code injection via OpenAPI comments. 2.8M+ downloads affected. Update to v7.21.0 now.
⤷ Title: Digital Ghost: “PhantomVAI” Malware Revives Decade-Old RunPE Tricks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
Daily CyberSecurity
Digital Ghost: "PhantomVAI" Malware Revives Decade-Old RunPE Tricks
New "PhantomVAI" malware recycles old Hackforums "RunPE" code to bypass modern EDR. Campaigns use task scheduler masquerading to deliver infostealers.
⤷ Title: Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:27:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CLI Vulnerability #container security #CVE_2025_67601 #DevOps #Kubernetes #Man in the Middle #Patch Alert #Rancher #SUSE #tls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:27:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CLI Vulnerability #container security #CVE_2025_67601 #DevOps #Kubernetes #Man in the Middle #Patch Alert #Rancher #SUSE #tls
Daily CyberSecurity
Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials
High-severity Rancher CLI flaw (CVE-2025-67601) exposes credentials via MitM attacks when using --skip-verify. Update or use -cacert immediately.
⤷ Title: Invisible Intruder: “ShadowHS” Malware Weaponizes Hackshell on Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
Daily CyberSecurity
Invisible Intruder: "ShadowHS" Malware Weaponizes Hackshell on Linux
Cyble uncovers "ShadowHS," a fileless Linux malware weaponizing hackshell. It uses GSocket tunneling to evade firewalls and kill rival bots.