⤷ Title: AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services Abuse #Android RAT #Banking Trojan #Bitdefender #Cybercrime #Hugging Face #mobile security #Polymorphic Malware #Premium Club #TrustBastion
Daily CyberSecurity
AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data
⤷ Title: CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:05:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Management #CVE_2026_25137 #Database Vulnerability #ERP Security #Immutability #Linux Security #Master Password #NixOS #Odoo #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:05:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Management #CVE_2026_25137 #Database Vulnerability #ERP Security #Immutability #Linux Security #Master Password #NixOS #Odoo #Patch Alert
Daily CyberSecurity
CVE-2026-25137: Critical Odoo on NixOS Flaw Exposes Databases
Critical Odoo on NixOS flaw (CVE-2026-25137) leaves databases exposed due to configuration immutability. Restarts wipe the master password.
⤷ Title: Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:38 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Cheat Driver #BYOVD #CVE_2025_61155 #Education Security #FortiGuard Labs #Hotta Killer #Interlock #Malware Analysis #NodeSnake #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:38 +0000
════════════════════════
⌗ Tags: #Malware #Anti_Cheat Driver #BYOVD #CVE_2025_61155 #Education Security #FortiGuard Labs #Hotta Killer #Interlock #Malware Analysis #NodeSnake #ransomware
Daily CyberSecurity
Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
Interlock ransomware exploits a zero-day in gaming anti-cheat drivers to blind defenses. "Hotta Killer" tool targets education sector. Read the analysis.
⤷ Title: John the Ripper: Complete Guide to Cracking for Bug Bounty and Auditing
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #penetration_testing #cybersecurity #technology
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #penetration_testing #cybersecurity #technology
Medium
John the Ripper: Complete Guide to Cracking for Bug Bounty and Auditing
Master John the Ripper: installation, essential commands, and advanced strategies for password audits and bug bounty hunting.
⤷ Title: Day 10: Intro to Python Part 3 — Functions + Booleans (Cybersecurity Python)
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
Medium
Day 10: Intro to Python Part 3 — Functions + Booleans (Cybersecurity Python)
Today I moved into Python Part 3, and this was honestly one of the days that made Python feel more “real” to me. I learned about functions…
⤷ Title: Day 9: Python Part 2 — Variables and Methods (Cybersecurity Python)
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
════════════════════════
𐀪 Author: Mohammad-AL-Momani
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 01:35:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #money #cybersecurity
Medium
Day 9: Python Part 2 — Variables and Methods (Cybersecurity Python)
Today I continued my Python cybersecurity journey, and this part was about variables and some basic string methods. I’m still learning, so…
⤷ Title: From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:28:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EEPROM dumping #fault injection #firmware extraction #glitching #hardware hacking #I2C #open source hardware #PCB design #PwnPad #PwnPad hardware hacking #side_channel attacks #SPI #TwelveSec #UART
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:28:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EEPROM dumping #fault injection #firmware extraction #glitching #hardware hacking #I2C #open source hardware #PCB design #PwnPad #PwnPad hardware hacking #side_channel attacks #SPI #TwelveSec #UART
Penetration Testing Tools
From UART to Glitching: Master Hardware Hacking with PwnPad’s Modular Learning Lab
PwnPad by TwelveSec is an open-source hardware hacking platform. Master UART, SPI, firmware extraction, and fault injection with built-in modular challenges.
⤷ Title: The “Async” Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:22:10 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AsyncClient.exe #AsyncRAT #C2 Infrastructure #Censys #Remote Access Trojan #SSL/TLS certificates #Tech News 2026 #Threat Hunting #VenomRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:22:10 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AsyncClient.exe #AsyncRAT #C2 Infrastructure #Censys #Remote Access Trojan #SSL/TLS certificates #Tech News 2026 #Threat Hunting #VenomRAT
Penetration Testing Tools
The "Async" Surge: January 2026 Telemetry Reveals a Global Explosion in AsyncRAT Command Nodes
A pronounced escalation in the activity of infrastructure tethered to the AsyncRAT remote access trojan has been meticulously
⤷ Title: The “VISTA” Vigilante: South Korea Deploys High-Speed AI to Crush Crypto “Pump and Dump” Scams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:20:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Surveillance #Crypto Fraud #Financial Regulation #Financial Supervisory Service (FSS) #high_frequency trading #Korea Exchange (KRX) #pump and dump #South Korea #stock manipulation #VISTA platform
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:20:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Surveillance #Crypto Fraud #Financial Regulation #Financial Supervisory Service (FSS) #high_frequency trading #Korea Exchange (KRX) #pump and dump #South Korea #stock manipulation #VISTA platform
Penetration Testing Tools
The "VISTA" Vigilante: South Korea Deploys High-Speed AI to Crush Crypto "Pump and Dump" Scams
Authorities in South Korea and the nation’s preeminent financial institutions have intensified the integration of artificial intelligence to
⤷ Title: The “Update” Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:17:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #Chrysalis backdoor #Don Ho #Lotus Blossom #malware #Notepad++ #supply chain attack #Supply Chain Security #update hijack #Violet Typhoon #WinGUp #Zirconium
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:17:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #Chrysalis backdoor #Don Ho #Lotus Blossom #malware #Notepad++ #supply chain attack #Supply Chain Security #update hijack #Violet Typhoon #WinGUp #Zirconium
Penetration Testing Tools
The "Update" Trap: How State-Sponsored Hackers Hijacked Notepad++ Infrastructure for 6 Months
For nearly half a year, the ubiquitous text editor Notepad++ inadvertently disseminated malicious payloads rather than legitimate refinements.
⤷ Title: Sabotaged Strings: The “Malicious” Vandalism Behind Tor Browser’s Emergency 15.0.5 Patch
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:14:58 +0000
════════════════════════
⌗ Tags: #Technology #Android Security #localization attack #NoScript #OpenSSL 3.5.5 #software vandalism #Supply Chain Security #Tech News #Tor Browser 15.0.5 #Tor Project #Vietnamese translation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:14:58 +0000
════════════════════════
⌗ Tags: #Technology #Android Security #localization attack #NoScript #OpenSSL 3.5.5 #software vandalism #Supply Chain Security #Tech News #Tor Browser 15.0.5 #Tor Project #Vietnamese translation
Penetration Testing Tools
Sabotaged Strings: The "Malicious" Vandalism Behind Tor Browser’s Emergency 15.0.5 Patch
The architects of Tor Browser have inaugurated a nascent iteration, Tor Browser 15.0.5. This unscheduled refinement was catalyzed
⤷ Title: Native Sysmon Arrives in the Latest Windows 11 Insider Build 26300
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:08:19 +0000
════════════════════════
⌗ Tags: #Windows #Build 26300.7733 #Dev Channel #forensic analysis #KB5074178 #Microsoft Sysinternals #Sysmon #Tech News #Threat Detection #Windows 11 #Windows 26H2 #Windows Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:08:19 +0000
════════════════════════
⌗ Tags: #Windows #Build 26300.7733 #Dev Channel #forensic analysis #KB5074178 #Microsoft Sysinternals #Sysmon #Tech News #Threat Detection #Windows 11 #Windows 26H2 #Windows Insider
Daily CyberSecurity
Native Sysmon Arrives in the Latest Windows 11 Insider Build 26300
Microsoft integrates native Sysmon into Windows 11 Build 26300.7733 (KB5074178). Track process creation and network links with this built-in forensic "dashcam."
⤷ Title: Breaking the AI Silo: How Google’s New “Import AI Chats” Feature Ends Context Lock-In
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:00:35 +0000
════════════════════════
⌗ Tags: #Technology #AI chat history #AI data portability #ChatGPT #Claude #context lock_in #Data Migration #Gemini Beta features #Google Gemini #Import AI Chats #Tech News 2026
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:00:35 +0000
════════════════════════
⌗ Tags: #Technology #AI chat history #AI data portability #ChatGPT #Claude #context lock_in #Data Migration #Gemini Beta features #Google Gemini #Import AI Chats #Tech News 2026
Daily CyberSecurity
Breaking the AI Silo: How Google’s New "Import AI Chats" Feature Ends Context Lock-In
Google Gemini is testing an "Import AI Chats" tool to let users migrate histories from ChatGPT and Claude. Say goodbye to starting over with every new AI.
⤷ Title: The Vanishing Taskbar: Windows 11’s Optional KB5074105 Update Rescues Users from “Explorer” Hell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:56:01 +0000
════════════════════════
⌗ Tags: #Windows #24H2 #25H2 #desktop icons #KB5074105 #laptop camera bug #optional update #taskbar bug #Tech News #Windows 11 #Windows Explorer crash
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:56:01 +0000
════════════════════════
⌗ Tags: #Windows #24H2 #25H2 #desktop icons #KB5074105 #laptop camera bug #optional update #taskbar bug #Tech News #Windows 11 #Windows Explorer crash
Daily CyberSecurity
The Vanishing Taskbar: Windows 11’s Optional KB5074105 Update Rescues Users from “Explorer” Hell
On January 29, Microsoft disseminated the preview update KB5074105 for Windows 11 versions 24H2 and 25H2. While this release encompasses a vast array of remedial fixes and functional refinements, …
⤷ Title: Silent Intrusion: “Metro4Shell” Exploited in the Wild Since December
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:27:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11953 #DevSecOps #Exploitation in the Wild #Metro Development Server #Metro4Shell #React Native #VulnCheck #vulnerability management #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:27:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11953 #DevSecOps #Exploitation in the Wild #Metro Development Server #Metro4Shell #React Native #VulnCheck #vulnerability management #zero_day
Daily CyberSecurity
Silent Intrusion: “Metro4Shell” Exploited in the Wild Since December
A new report from VulnCheck reveals that CVE-2025-11953, a critical flaw in the Metro development server dubbed “Metro4Shell,” was being actively weaponized in the wild as early as lat…
⤷ Title: Urgent Django Update: Patches 3 Critical SQL Injections & DoS Risks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:19:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Backend Development #CVE_2026_1207 #CVE_2026_1287 #Django #dos #FilteredRelation #PostGIS #Python #software update #sql injection #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:19:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Backend Development #CVE_2026_1207 #CVE_2026_1287 #Django #dos #FilteredRelation #PostGIS #Python #software update #sql injection #Web Security
Daily CyberSecurity
Urgent Django Update: Patches 3 Critical SQL Injections & DoS Risks
Django patches 3 critical SQL injection flaws & DoS risks in versions 6.0.2, 5.2.11, & 4.2.28. Update immediately to secure your database.
⤷ Title: React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:12:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptomining #CVE_2025_55182 #DevSecOps #GreyNoise #Patch Alert #React #React Server Components #Remote Code Execution #reverse shell #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:12:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptomining #CVE_2025_55182 #DevSecOps #GreyNoise #Patch Alert #React #React Server Components #Remote Code Execution #reverse shell #Web Security
Daily CyberSecurity
React Under Siege: Two IPs Drive 56% of Critical CVE-2025-55182 Attacks
Critical React flaw CVE-2025-55182 (CVSS 10.0) under mass exploitation. Two IPs drive 56% of attacks deploying miners & shells. Upgrade to v19.0.1+ now.
⤷ Title: Chrome 144 Security Alert: V8 & Libvpx Flaws Expose Systems to Hacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:05:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Update #CVE_2026_1861 #CVE_2026_1862 #google chrome #Heap Buffer Overflow #libvpx #Patch Alert #Type Confusion #V8 JavaScript engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:05:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Update #CVE_2026_1861 #CVE_2026_1862 #google chrome #Heap Buffer Overflow #libvpx #Patch Alert #Type Confusion #V8 JavaScript engine
Daily CyberSecurity
Chrome 144 Security Alert: V8 & Libvpx Flaws Expose Systems to Hacks
Google Chrome patches high-severity V8 (CVE-2026-1862) and libvpx (CVE-2026-1861) flaws. Update to version 144.0.7559.132 immediately.
⤷ Title: When Encryption Replaced Authorization — and the IDOR Didn’t Go Away
════════════════════════
𐀪 Author: Xp10it
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #web_security #bug_bounty #software_engineering
════════════════════════
𐀪 Author: Xp10it
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:46:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #web_security #bug_bounty #software_engineering
Medium
When Encryption Replaced Authorization — and the IDOR Didn’t Go Away
A real-world example of why cryptography cannot substitute object-level authorization.
⤷ Title: The Hidden Danger in XML: A Deep Dive into XXE Injection for Modern Pentesters
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:32:54 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #web_development #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:32:54 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #web_development #bug_bounty_writeup #bug_bounty_tips
Medium
The Hidden Danger in XML: A Deep Dive into XXE Injection for Modern Pentesters
If you have spent any time testing APIs, legacy enterprise systems, or authentication workflows, you have probably seen XML quietly sitting…
⤷ Title: How to Analyze a Suspicious URL Without Clicking It
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:06:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #phishing #hacking #bug_bounty
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 02:06:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #phishing #hacking #bug_bounty
Medium
How to Analyze a Suspicious URL Without Clicking It
Because curiosity is good. Clicking random links is not. 😅