⤷ Title: [Writeup] Proving Grounds: Prison (Linux)
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
════════════════════════
𐀪 Author: Ekemini Bassey
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 17:55:00 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #jenkins_security #tunneling #sql_injection #privilege_escalation
Medium
📝 [Writeup] Proving Grounds: Prison (Linux)
From Prison Break to Jenkins Break: Tunnelling for Root
⤷ Title: Rooted via Wi-Fi 7: TP-Link Patches Command Injection in Archer BE230
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:50:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer BE230 #Command Injection #CVE_2026_0630 #CVE_2026_22229 #Cyber Security #firmware update #Home Network Security #router security #TP_Link #Wi_Fi 7
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:50:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer BE230 #Command Injection #CVE_2026_0630 #CVE_2026_22229 #Cyber Security #firmware update #Home Network Security #router security #TP_Link #Wi_Fi 7
Daily CyberSecurity
Rooted via Wi-Fi 7: TP-Link Patches Command Injection in Archer BE230
TP-Link discloses command injection flaws in Archer BE230 routers (CVE-2026-0630). Authenticated attackers can gain root access. Update firmware now.
⤷ Title: CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:45:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADM #Arbitrary File Write #ASUSTOR #Critical Vulnerability #CVE_2026_24936 #Data Integrity #NAS security #Patch Alert #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:45:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADM #Arbitrary File Write #ASUSTOR #Critical Vulnerability #CVE_2026_24936 #Data Integrity #NAS security #Patch Alert #ransomware
Daily CyberSecurity
CVE-2026-24936: Critical ASUSTOR Flaw (CVSS 9.5) Allows Remote System Takeover
Critical ASUSTOR ADM flaw CVE-2026-24936 (CVSS 9.5) allows remote file overwrite. Unauthenticated attackers can seize NAS control. Update to v5.1.2 now.
⤷ Title: “IT Support” Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Corporate Security #Extortion #identity theft #Mandiant #MFA Bypass #ShinyHunters #social engineering #UNC6661 #UNC6671 #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Corporate Security #Extortion #identity theft #Mandiant #MFA Bypass #ShinyHunters #social engineering #UNC6661 #UNC6671 #Vishing
Daily CyberSecurity
"IT Support" Imposters: ShinyHunters Vishing Rings Bypass MFA to Steal Data
Mandiant warns of vishing rings like ShinyHunters impersonating IT support to bypass MFA and steal corporate cloud data. Verify your callers.
⤷ Title: Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:36:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2026_23947 #CVE_2026_25141 #Developer Tools #JavaScript Security #OpenAPI #Orval #Supply Chain Security #TypeScript #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:36:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2026_23947 #CVE_2026_25141 #Developer Tools #JavaScript Security #OpenAPI #Orval #Supply Chain Security #TypeScript #web development
Daily CyberSecurity
Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
Critical Orval flaw CVE-2026-25141 (CVSS 9.3) allows code injection via OpenAPI comments. 2.8M+ downloads affected. Update to v7.21.0 now.
⤷ Title: Digital Ghost: “PhantomVAI” Malware Revives Decade-Old RunPE Tricks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:31:03 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Crime #Infostealer #Intrinsec #Legacy Malware #Malware Analysis #Mandark #PhantomVAI #Process Hollowing #RunPE #Task Scheduler Masquerading
Daily CyberSecurity
Digital Ghost: "PhantomVAI" Malware Revives Decade-Old RunPE Tricks
New "PhantomVAI" malware recycles old Hackforums "RunPE" code to bypass modern EDR. Campaigns use task scheduler masquerading to deliver infostealers.
⤷ Title: Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:27:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CLI Vulnerability #container security #CVE_2025_67601 #DevOps #Kubernetes #Man in the Middle #Patch Alert #Rancher #SUSE #tls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:27:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CLI Vulnerability #container security #CVE_2025_67601 #DevOps #Kubernetes #Man in the Middle #Patch Alert #Rancher #SUSE #tls
Daily CyberSecurity
Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials
High-severity Rancher CLI flaw (CVE-2025-67601) exposes credentials via MitM attacks when using --skip-verify. Update or use -cacert immediately.
⤷ Title: Invisible Intruder: “ShadowHS” Malware Weaponizes Hackshell on Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:22:02 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #Cyble Research #Fileless attack #GSocket #Hackshell #Linux Malware #Memory injection #post_exploitation #ShadowHS #threat intelligence
Daily CyberSecurity
Invisible Intruder: "ShadowHS" Malware Weaponizes Hackshell on Linux
Cyble uncovers "ShadowHS," a fileless Linux malware weaponizing hackshell. It uses GSocket tunneling to evade firewalls and kill rival bots.
⤷ Title: TAMECAT Exposed: APT42’s Fileless Backdoor Targets Defense Chiefs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #cyber_espionage #Fileless Threat #IRGC #Israel National Digital Agency #PowerShell Malware #Pulsedive #social engineering #TAMECAT #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #cyber_espionage #Fileless Threat #IRGC #Israel National Digital Agency #PowerShell Malware #Pulsedive #social engineering #TAMECAT #Telegram C2
Daily CyberSecurity
TAMECAT Exposed: APT42's Fileless Backdoor Targets Defense Chiefs
APT42 targets defense officials with "TAMECAT," a modular PowerShell backdoor. The malware uses social engineering and Telegram C2 to steal secrets.
⤷ Title: AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
Daily CyberSecurity
AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
⤷ Title: CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:05:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Management #CVE_2026_25137 #Database Vulnerability #ERP Security #Immutability #Linux Security #Master Password #NixOS #Odoo #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:05:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Management #CVE_2026_25137 #Database Vulnerability #ERP Security #Immutability #Linux Security #Master Password #NixOS #Odoo #Patch Alert
Daily CyberSecurity
CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
Critical Odoo on NixOS flaw (CVE-2026-25137) leaves databases exposed due to configuration immutability. Restarts wipe the master password.
⤷ Title: Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:38 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Cheat Driver #BYOVD #CVE_2025_61155 #Education Security #FortiGuard Labs #Hotta Killer #Interlock #Malware Analysis #NodeSnake #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:38 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Cheat Driver #BYOVD #CVE_2025_61155 #Education Security #FortiGuard Labs #Hotta Killer #Interlock #Malware Analysis #NodeSnake #ransomware
Daily CyberSecurity
Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
Interlock ransomware exploits a zero-day in gaming anti-cheat drivers to blind defenses. "Hotta Killer" tool targets education sector. Read the analysis.
⤷ Title: John the Ripper: Complete Guide to Cracking for Bug Bounty and Auditing
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #penetration_testing #cybersecurity #technology
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #penetration_testing #cybersecurity #technology
Medium
John the Ripper: Complete Guide to Cracking for Bug Bounty and Auditing
Master John the Ripper: installation, essential commands, and advanced strategies for password audits and bug bounty hunting.
⤷ Title: Day 10: Intro to Python Part 3 — Functions + Booleans (Cybersecurity Python)
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
Medium
Day 10: Intro to Python Part 3 — Functions + Booleans (Cybersecurity Python)
Today I moved into Python Part 3, and this was honestly one of the days that made Python feel more “real” to me. I learned about functions…
⤷ Title: Day 9: Python Part 2 — Variables and Methods (Cybersecurity Python)
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
Medium
Day 9: Python Part 2 — Variables and Methods (Cybersecurity Python)
Today I continued my Python cybersecurity journey, and this part was about variables and some basic string methods. I’m still learning, so…
⤷ Title: From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:28:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EEPROM dumping #fault injection #firmware extraction #glitching #hardware hacking #I2C #open source hardware #PCB design #PwnPad #PwnPad hardware hacking #side_channel attacks #SPI #TwelveSec #UART
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:28:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EEPROM dumping #fault injection #firmware extraction #glitching #hardware hacking #I2C #open source hardware #PCB design #PwnPad #PwnPad hardware hacking #side_channel attacks #SPI #TwelveSec #UART
Penetration Testing Tools
From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
PwnPad by TwelveSec is an open-source hardware hacking platform. Master UART, SPI, firmware extraction, and fault injection with built-in modular challenges.
⤷ Title: The “Async” Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:22:10 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AsyncClient.exe #AsyncRAT #C2 Infrastructure #Censys #Remote Access Trojan #SSL/TLS certificates #Tech News 2026 #Threat Hunting #VenomRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:22:10 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AsyncClient.exe #AsyncRAT #C2 Infrastructure #Censys #Remote Access Trojan #SSL/TLS certificates #Tech News 2026 #Threat Hunting #VenomRAT
Penetration Testing Tools
The "Async" Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
A pronounced escalation in the activity of infrastructure tethered to the AsyncRAT remote access trojan has been meticulously
⤷ Title: The “VISTA” Vigilante: South Korea Deploys High-Speed AI to Crush Crypto “Pump and Dump” Scams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:20:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Surveillance #Crypto Fraud #Financial Regulation #Financial Supervisory Service (FSS) #high_frequency trading #Korea Exchange (KRX) #pump and dump #South Korea #stock manipulation #VISTA platform
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:20:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Surveillance #Crypto Fraud #Financial Regulation #Financial Supervisory Service (FSS) #high_frequency trading #Korea Exchange (KRX) #pump and dump #South Korea #stock manipulation #VISTA platform
Penetration Testing Tools
The "VISTA" Vigilante: South Korea Deploys High-Speed AI to Crush Crypto "Pump and Dump" Scams
Authorities in South Korea and the nation’s preeminent financial institutions have intensified the integration of artificial intelligence to
⤷ Title: The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:17:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #Chrysalis backdoor #Don Ho #Lotus Blossom #malware #Notepad++ #supply chain attack #Supply Chain Security #update hijack #Violet Typhoon #WinGUp #Zirconium
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:17:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #Chrysalis backdoor #Don Ho #Lotus Blossom #malware #Notepad++ #supply chain attack #Supply Chain Security #update hijack #Violet Typhoon #WinGUp #Zirconium
Penetration Testing Tools
The "Update" Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
For nearly half a year, the ubiquitous text editor Notepad++ inadvertently disseminated malicious payloads rather than legitimate refinements.
⤷ Title: Sabotaged Strings: The “Malicious” Vandalism Behind Tor Browser’s Emergency 15.0.5 Patch
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:14:58 +0000
════════════════════════
⌗ Tags: #Technology #Android Security #localization attack #NoScript #OpenSSL 3.5.5 #software vandalism #Supply Chain Security #Tech News #Tor Browser 15.0.5 #Tor Project #Vietnamese translation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:14:58 +0000
════════════════════════
⌗ Tags: #Technology #Android Security #localization attack #NoScript #OpenSSL 3.5.5 #software vandalism #Supply Chain Security #Tech News #Tor Browser 15.0.5 #Tor Project #Vietnamese translation
Penetration Testing Tools
Sabotaged Strings: The "Malicious" Vandalism Behind Tor Browser’s Emergency 15.0.5 Patch
The architects of Tor Browser have inaugurated a nascent iteration, Tor Browser 15.0.5. This unscheduled refinement was catalyzed
⤷ Title: Native Sysmon Arrives in the Latest Windows 11 Insider Build 26300
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:08:19 +0000
════════════════════════
⌗ Tags: #Windows #Build 26300.7733 #Dev Channel #forensic analysis #KB5074178 #Microsoft Sysinternals #Sysmon #Tech News #Threat Detection #Windows 11 #Windows 26H2 #Windows Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:08:19 +0000
════════════════════════
⌗ Tags: #Windows #Build 26300.7733 #Dev Channel #forensic analysis #KB5074178 #Microsoft Sysinternals #Sysmon #Tech News #Threat Detection #Windows 11 #Windows 26H2 #Windows Insider
Daily CyberSecurity
Native Sysmon Arrives in the Latest Windows 11 Insider Build 26300
Microsoft integrates native Sysmon into Windows 11 Build 26300.7733 (KB5074178). Track process creation and network links with this built-in forensic "dashcam."