⤷ Title: Discovering PPL Protection in Windows Processes
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:27:19 GMT
════════════════════════
⌗ Tags: #malware #hackthebox #tryhackme #hacking #cybersecurity
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 23:27:19 GMT
════════════════════════
⌗ Tags: #malware #hackthebox #tryhackme #hacking #cybersecurity
Medium
Discovering PPL Protection in Windows Processes
Welcome to my latest post! Today, we’re exploring the classic method for identifying the Protected Process Light (PPL) status of a specific…
⤷ Title: From INTERPOL to Hollywood: How Real Cybercrime Differs from TV Hacking
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 22:42:43 GMT
════════════════════════
⌗ Tags: #hollywood #cybersecurity #script_consultant #hacking #hollywood_movies
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 22:42:43 GMT
════════════════════════
⌗ Tags: #hollywood #cybersecurity #script_consultant #hacking #hollywood_movies
Medium
From INTERPOL to Hollywood: How Real Cybercrime Differs from TV Hacking
Let me tell you about the first time a Hollywood producer called me. I was sitting in my office, surrounded by too many monitors, not…
⤷ Title: [Writeup] Proving Grounds: Prison (Linux)
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
Medium
📝 [Writeup] Proving Grounds: Prison (Linux)
From Prison Break to Jenkins Break: Tunnelling for Root
⤷ Title: Rooted via Wi-Fi 7: TP-Link Patches Command Injection in Archer BE230
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:50:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer BE230 #Command Injection #CVE_2026_0630 #CVE_2026_22229 #Cyber Security #firmware update #Home Network Security #router security #TP_Link #Wi_Fi 7
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:50:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer BE230 #Command Injection #CVE_2026_0630 #CVE_2026_22229 #Cyber Security #firmware update #Home Network Security #router security #TP_Link #Wi_Fi 7
Daily CyberSecurity
Rooted via Wi-Fi 7: TP-Link Patches Command Injection in Archer BE230
TP-Link discloses command injection flaws in Archer BE230 routers (CVE-2026-0630). Authenticated attackers can gain root access. Update firmware now.
⤷ Title: CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:45:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADM #Arbitrary File Write #ASUSTOR #Critical Vulnerability #CVE_2026_24936 #Data Integrity #NAS security #Patch Alert #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:45:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADM #Arbitrary File Write #ASUSTOR #Critical Vulnerability #CVE_2026_24936 #Data Integrity #NAS security #Patch Alert #ransomware
Daily CyberSecurity
CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover
Critical ASUSTOR ADM flaw CVE-2026-24936 (CVSS 9.5) allows remote file overwrite. Unauthenticated attackers can seize NAS control. Update to v5.1.2 now.
⤷ Title: “IT Support” Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Corporate Security #Extortion #identity theft #Mandiant #MFA Bypass #ShinyHunters #social engineering #UNC6661 #UNC6671 #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Corporate Security #Extortion #identity theft #Mandiant #MFA Bypass #ShinyHunters #social engineering #UNC6661 #UNC6671 #Vishing
Daily CyberSecurity
"IT Support" Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
Mandiant warns of vishing rings like ShinyHunters impersonating IT support to bypass MFA and steal corporate cloud data. Verify your callers.
⤷ Title: Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:36:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2026_23947 #CVE_2026_25141 #Developer Tools #JavaScript Security #OpenAPI #Orval #Supply Chain Security #TypeScript #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:36:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2026_23947 #CVE_2026_25141 #Developer Tools #JavaScript Security #OpenAPI #Orval #Supply Chain Security #TypeScript #web development
Daily CyberSecurity
Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
Critical Orval flaw CVE-2026-25141 (CVSS 9.3) allows code injection via OpenAPI comments. 2.8M+ downloads affected. Update to v7.21.0 now.
⤷ Title: Digital Ghost: “PhantomVAI” Malware Revives Decade-Old RunPE Tricks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
Daily CyberSecurity
Digital Ghost: "PhantomVAI" Malware Revives Decade-Old RunPE Tricks
New "PhantomVAI" malware recycles old Hackforums "RunPE" code to bypass modern EDR. Campaigns use task scheduler masquerading to deliver infostealers.
⤷ Title: Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:27:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CLI Vulnerability #container security #CVE_2025_67601 #DevOps #Kubernetes #Man in the Middle #Patch Alert #Rancher #SUSE #tls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:27:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CLI Vulnerability #container security #CVE_2025_67601 #DevOps #Kubernetes #Man in the Middle #Patch Alert #Rancher #SUSE #tls
Daily CyberSecurity
Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials
High-severity Rancher CLI flaw (CVE-2025-67601) exposes credentials via MitM attacks when using --skip-verify. Update or use -cacert immediately.
⤷ Title: Invisible Intruder: “ShadowHS” Malware Weaponizes Hackshell on Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
Daily CyberSecurity
Invisible Intruder: "ShadowHS" Malware Weaponizes Hackshell on Linux
Cyble uncovers "ShadowHS," a fileless Linux malware weaponizing hackshell. It uses GSocket tunneling to evade firewalls and kill rival bots.
⤷ Title: TAMECAT Exposed: APT42’s Fileless Backdoor Targets Defense Chiefs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #cyber_espionage #Fileless Threat #IRGC #Israel National Digital Agency #PowerShell Malware #Pulsedive #social engineering #TAMECAT #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #cyber_espionage #Fileless Threat #IRGC #Israel National Digital Agency #PowerShell Malware #Pulsedive #social engineering #TAMECAT #Telegram C2
Daily CyberSecurity
TAMECAT Exposed: APT42's Fileless Backdoor Targets Defense Chiefs
APT42 targets defense officials with "TAMECAT," a modular PowerShell backdoor. The malware uses social engineering and Telegram C2 to steal secrets.
⤷ Title: AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
Daily CyberSecurity
AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
⤷ Title: CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:05:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Management #CVE_2026_25137 #Database Vulnerability #ERP Security #Immutability #Linux Security #Master Password #NixOS #Odoo #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:05:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Management #CVE_2026_25137 #Database Vulnerability #ERP Security #Immutability #Linux Security #Master Password #NixOS #Odoo #Patch Alert
Daily CyberSecurity
CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
Critical Odoo on NixOS flaw (CVE-2026-25137) leaves databases exposed due to configuration immutability. Restarts wipe the master password.
⤷ Title: Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:38 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Cheat Driver #BYOVD #CVE_2025_61155 #Education Security #FortiGuard Labs #Hotta Killer #Interlock #Malware Analysis #NodeSnake #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:38 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Cheat Driver #BYOVD #CVE_2025_61155 #Education Security #FortiGuard Labs #Hotta Killer #Interlock #Malware Analysis #NodeSnake #ransomware
Daily CyberSecurity
Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
Interlock ransomware exploits a zero-day in gaming anti-cheat drivers to blind defenses. "Hotta Killer" tool targets education sector. Read the analysis.
⤷ Title: John the Ripper: Complete Guide to Cracking for Bug Bounty and Auditing
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #penetration_testing #cybersecurity #technology
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #penetration_testing #cybersecurity #technology
Medium
John the Ripper: Complete Guide to Cracking for Bug Bounty and Auditing
Master John the Ripper: installation, essential commands, and advanced strategies for password audits and bug bounty hunting.
⤷ Title: Day 10: Intro to Python Part 3 — Functions + Booleans (Cybersecurity Python)
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
Medium
Day 10: Intro to Python Part 3 — Functions + Booleans (Cybersecurity Python)
Today I moved into Python Part 3, and this was honestly one of the days that made Python feel more “real” to me. I learned about functions…
⤷ Title: Day 9: Python Part 2 — Variables and Methods (Cybersecurity Python)
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
Medium
Day 9: Python Part 2 — Variables and Methods (Cybersecurity Python)
Today I continued my Python cybersecurity journey, and this part was about variables and some basic string methods. I’m still learning, so…
⤷ Title: From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:28:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EEPROM dumping #fault injection #firmware extraction #glitching #hardware hacking #I2C #open source hardware #PCB design #PwnPad #PwnPad hardware hacking #side_channel attacks #SPI #TwelveSec #UART
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:28:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EEPROM dumping #fault injection #firmware extraction #glitching #hardware hacking #I2C #open source hardware #PCB design #PwnPad #PwnPad hardware hacking #side_channel attacks #SPI #TwelveSec #UART
Penetration Testing Tools
From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
PwnPad by TwelveSec is an open-source hardware hacking platform. Master UART, SPI, firmware extraction, and fault injection with built-in modular challenges.
⤷ Title: The “Async” Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:22:10 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AsyncClient.exe #AsyncRAT #C2 Infrastructure #Censys #Remote Access Trojan #SSL/TLS certificates #Tech News 2026 #Threat Hunting #VenomRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:22:10 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AsyncClient.exe #AsyncRAT #C2 Infrastructure #Censys #Remote Access Trojan #SSL/TLS certificates #Tech News 2026 #Threat Hunting #VenomRAT
Penetration Testing Tools
The "Async" Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
A pronounced escalation in the activity of infrastructure tethered to the AsyncRAT remote access trojan has been meticulously
⤷ Title: The “VISTA” Vigilante: South Korea Deploys High-Speed AI to Crush Crypto “Pump and Dump” Scams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:20:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Surveillance #Crypto Fraud #Financial Regulation #Financial Supervisory Service (FSS) #high_frequency trading #Korea Exchange (KRX) #pump and dump #South Korea #stock manipulation #VISTA platform
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:20:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Surveillance #Crypto Fraud #Financial Regulation #Financial Supervisory Service (FSS) #high_frequency trading #Korea Exchange (KRX) #pump and dump #South Korea #stock manipulation #VISTA platform
Penetration Testing Tools
The "VISTA" Vigilante: South Korea Deploys High-Speed AI to Crush Crypto "Pump and Dump" Scams
Authorities in South Korea and the nation’s preeminent financial institutions have intensified the integration of artificial intelligence to
⤷ Title: The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:17:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #Chrysalis backdoor #Don Ho #Lotus Blossom #malware #Notepad++ #supply chain attack #Supply Chain Security #update hijack #Violet Typhoon #WinGUp #Zirconium
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:17:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #Chrysalis backdoor #Don Ho #Lotus Blossom #malware #Notepad++ #supply chain attack #Supply Chain Security #update hijack #Violet Typhoon #WinGUp #Zirconium
Penetration Testing Tools
The "Update" Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
For nearly half a year, the ubiquitous text editor Notepad++ inadvertently disseminated malicious payloads rather than legitimate refinements.