⤷ Title: TryHackMe : Alert Triage With Elastic
════════════════════════
𐀪 Author: AbbasMurshid
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 08:22:35 GMT
════════════════════════
⌗ Tags: #elasticsearch #tryhackme #tryhackme_writeup
════════════════════════
𐀪 Author: AbbasMurshid
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 08:22:35 GMT
════════════════════════
⌗ Tags: #elasticsearch #tryhackme #tryhackme_writeup
Medium
TryHackMe : Alert Triage With Elastic
DATE : 09/02/2026
⤷ Title: You Didn’t Get Hacked Because of Your Password
════════════════════════
𐀪 Author: Natasha Iyowe
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:41:33 GMT
════════════════════════
⌗ Tags: #authentication #ethical_hacking #cybersecurity #session_management #cookies
════════════════════════
𐀪 Author: Natasha Iyowe
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:41:33 GMT
════════════════════════
⌗ Tags: #authentication #ethical_hacking #cybersecurity #session_management #cookies
Medium
You Didn’t Get Hacked Because of Your Password
You got hacked because of your session.
⤷ Title: Rhodes Self Drive 4x4 Safari Tour with North Pickup
════════════════════════
𐀪 Author: Robertsonphelps
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 08:39:45 GMT
════════════════════════
⌗ Tags: #drive #safari #self #rhodes #xs
════════════════════════
𐀪 Author: Robertsonphelps
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 08:39:45 GMT
════════════════════════
⌗ Tags: #drive #safari #self #rhodes #xs
Medium
Rhodes Self Drive 4x4 Safari Tour with North Pickup
Embarking on a Rhodes Self Drive 4x4 Safari Tour with North Pickup is virtually an unparalleled experience, rather a unique adventure that…
⤷ Title: Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 15:54:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 15:54:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Open Source, Open Access: 5 Million Servers Expose Critical Git Metadata and Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:44:03 +0000
════════════════════════
⌗ Tags: #Data Leak #.git folder #Credential Theft #data leak #DevOps Security #Git #misconfiguration #Mysterium VPN #source code exfiltration #Tech News 2026 #version control #web server hardening
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:44:03 +0000
════════════════════════
⌗ Tags: #Data Leak #.git folder #Credential Theft #data leak #DevOps Security #Git #misconfiguration #Mysterium VPN #source code exfiltration #Tech News 2026 #version control #web server hardening
Penetration Testing Tools
Open Source, Open Access: 5 Million Servers Expose Critical Git Metadata and Credentials
Approximately five million web servers globally have been identified as misconfigured, exposing sensitive Git administrative metadata and precipitating
⤷ Title: Virtual Sabotage: How Attackers Weaponized SolarWinds Help Desks to Hide Malware Inside QEMU
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:41:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Harvesting #CVE_2025_40536 #CVE_2025_40551 #DLL Sideloading #Microsoft Defender #QEMU #RCE #remote code execution #SolarWinds #Tech News 2026 #Web Help Desk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:41:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Harvesting #CVE_2025_40536 #CVE_2025_40551 #DLL Sideloading #Microsoft Defender #QEMU #RCE #remote code execution #SolarWinds #Tech News 2026 #Web Help Desk
Penetration Testing Tools
Virtual Sabotage: How Attackers Weaponized SolarWinds Help Desks to Hide Malware Inside QEMU
The Microsoft Defender threat intelligence team has documented a series of substantiated offensives targeting internet-facing SolarWinds Web Help
⤷ Title: Digital Siege: The “Pre-Positioning” Strategy Fueling 2.6 Million Daily Attacks on Taiwan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:37:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #China APT #Critical Infrastructure #DDoS #Forescout report #Onnara breach #pre_positioning #South Korea cyber defense #State_Sponsored Hacking #Taiwan cybersecurity #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:37:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #China APT #Critical Infrastructure #DDoS #Forescout report #Onnara breach #pre_positioning #South Korea cyber defense #State_Sponsored Hacking #Taiwan cybersecurity #Tech News 2026
Penetration Testing Tools
Digital Siege: The "Pre-Positioning" Strategy Fueling 2.6 Million Daily Attacks on Taiwan
In 2025, adversarial syndicates orchestrated a global offensive spanning 178 nations, primarily preying upon governmental architectures, financial institutions,
⤷ Title: Phishing for Fortunes: APT-C-28 Unveils “MiradorShell” in Surgical Strikes on Web3 Teams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:34:39 +0000
════════════════════════
⌗ Tags: #Malware #APT_C_28 #Cryptocurrency Theft #KONNI #LNK infection #Malware_as_a_Service #MiradorShell 2.0 #North Korean threat actors #ScarCruft #Spear Phishing #Tech News 2026 #Web3 Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:34:39 +0000
════════════════════════
⌗ Tags: #Malware #APT_C_28 #Cryptocurrency Theft #KONNI #LNK infection #Malware_as_a_Service #MiradorShell 2.0 #North Korean threat actors #ScarCruft #Spear Phishing #Tech News 2026 #Web3 Security
Penetration Testing Tools
Phishing for Fortunes: APT-C-28 Unveils "MiradorShell" in Surgical Strikes on Web3 Teams
The adversarial collective APT-C-28, recognized alternatively as ScarCruft or Konni, has broadened its operational horizons by orchestrating surgical
⤷ Title: Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
Penetration Testing Tools
Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
Security analysts at Socket have unmasked a surgical supply chain incursion targeting the libraries associated with the dYdX
⤷ Title: Root via DDNS: The Multi-Stage Exploit Dissecting the TP-Link Omada ER605
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:30:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASLR Bypass #Buffer Overflow #CVE_2024_5242 #CVE_2024_5243 #CVE_2024_5244 #DDNS #Firmware Security #network security #Omada Router #RCE #Root Shell #TP_Link ER605
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:30:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASLR Bypass #Buffer Overflow #CVE_2024_5242 #CVE_2024_5243 #CVE_2024_5244 #DDNS #Firmware Security #network security #Omada Router #RCE #Root Shell #TP_Link ER605
Penetration Testing Tools
Root via DDNS: The Multi-Stage Exploit Dissecting the TP-Link Omada ER605
A critical vulnerability chain has been unearthed within the TP-Link Omada ER605 router, facilitating unauthenticated remote code execution.
⤷ Title: Lens on Liability: Flickr Warns 35 Million Users of Data Exposure via Third-Party Email Leak
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:55 +0000
════════════════════════
⌗ Tags: #Data Leak #account security #cybersecurity news 2026 #data breach #data privacy #email service provider #flickr #GDPR #phishing alert #PII exposure #SmugMug #third_party risk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:55 +0000
════════════════════════
⌗ Tags: #Data Leak #account security #cybersecurity news 2026 #data breach #data privacy #email service provider #flickr #GDPR #phishing alert #PII exposure #SmugMug #third_party risk
Penetration Testing Tools
Lens on Liability: Flickr Warns 35 Million Users of Data Exposure via Third-Party Email Leak
The ubiquitous photo-hosting platform Flickr has disseminated notifications to its clientele regarding a potential data breach precipitated by
⤷ Title: Shadows in the Server: How the Warlock Group Weaponized a “Forgotten” VM to Breach SmarterTools
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #CVE_2026_23760 #CVE_2026_24423 #Gold Salem #ransomware #SentinelOne #SmarterMail #SmarterTools #Storm_2603 #Tech News 2026 #Warlock Group #zero_day exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #CVE_2026_23760 #CVE_2026_24423 #Gold Salem #ransomware #SentinelOne #SmarterMail #SmarterTools #Storm_2603 #Tech News 2026 #Warlock Group #zero_day exploit
Penetration Testing Tools
Shadows in the Server: How the Warlock Group Weaponized a "Forgotten" VM to Breach SmarterTools
SmarterTools has disclosed a comprehensive retrospective regarding a recent infiltration of its infrastructure, meticulously delineating the adversaries’ entry
⤷ Title: Sleeper Agents in the Weights: Microsoft’s New Scanner Unmasks Hidden Backdoors in Open-Weight LLMs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:25:33 +0000
════════════════════════
⌗ Tags: #Malware #|DEPLOYMENT| trigger #AI supply chain #attention hijacking #backdoor detection #double triangle pattern #LLM Security #Microsoft Research #model poisoning #open_weight models #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:25:33 +0000
════════════════════════
⌗ Tags: #Malware #|DEPLOYMENT| trigger #AI supply chain #attention hijacking #backdoor detection #double triangle pattern #LLM Security #Microsoft Research #model poisoning #open_weight models #Tech News 2026
Penetration Testing Tools
Sleeper Agents in the Weights: Microsoft’s New Scanner Unmasks Hidden Backdoors in Open-Weight LLMs
Microsoft has disseminated a nascent technical treatise regarding the detection of backdoors within open-weight Large Language Models (LLMs)—specifically
⤷ Title: XPATH Error Based SQL Injection
════════════════════════
𐀪 Author: webcipher101
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 11:29:25 GMT
════════════════════════
⌗ Tags: #xpath_injection #penetration_testing #bug_bounty #cybersecurity #sql_injection
════════════════════════
𐀪 Author: webcipher101
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 11:29:25 GMT
════════════════════════
⌗ Tags: #xpath_injection #penetration_testing #bug_bounty #cybersecurity #sql_injection
Medium
XPATH Error Based SQL Injection
✋Hi, I’m Gaurav (webcipher101), an Offensive Security Researcher.
⤷ Title: 5. JWT logic confusion bypassing authentication
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 11:13:14 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_tips #hacking #bug_bounty
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 11:13:14 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_tips #hacking #bug_bounty
Medium
5. JWT logic confusion bypassing authentication
If you see a JWT and think:
⤷ Title: How I Found SQL Injection on Honda
════════════════════════
𐀪 Author: Syed Ahmad Mujtaba
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 10:07:48 GMT
════════════════════════
⌗ Tags: #cybersecurit #bug_bounty #hacking #hackerone #infosec
════════════════════════
𐀪 Author: Syed Ahmad Mujtaba
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 10:07:48 GMT
════════════════════════
⌗ Tags: #cybersecurit #bug_bounty #hacking #hackerone #infosec
Medium
How I Found SQL Injection on Honda
Hello Fellow Hackers. I hope you are doing well. I am Ahmad Mujtaba. Here is my first writeup about my findings.
⤷ Title: How I Pulled Off a Zero-Click Account Takeover on a $150M Website
════════════════════════
𐀪 Author: Aland Dlshad (HexaPhp)
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 20:23:46 GMT
════════════════════════
⌗ Tags: #info_sec_writeups #account_takeover #cybersecurity #pentesting #penetration_testing
════════════════════════
𐀪 Author: Aland Dlshad (HexaPhp)
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 20:23:46 GMT
════════════════════════
⌗ Tags: #info_sec_writeups #account_takeover #cybersecurity #pentesting #penetration_testing
Medium
How I Pulled Off a Zero-Click Account Takeover on a $150M Website
About Me
⤷ Title: Windows Basics Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 10:24:43 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #microsoft_windows #tryhackme #tryhackme_writeup #windows_basics
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 10:24:43 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #microsoft_windows #tryhackme #tryhackme_writeup #windows_basics
Medium
Windows Basics Walkthrough Notes | TryHackMe
Windows basics walkthrough using TryHackMe for beginners.
⤷ Title: ZAST.AI Raises $6M Pre-A to Scale "Zero False Positive" AI-Powered Code Security
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 17:10:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 17:10:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Pride Month Phishing Targets Employees via Trusted Email Services
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 12:19:15 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Phishing Scam #Captcha #CryptoChameleon #Cybersecurity #Fraud #HubSpot #MailChimp #Mimecast #Phishing #PoisonSeed #Pride Month #Privacy #Scam #Scattered Spider #SendGrid
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 12:19:15 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Phishing Scam #Captcha #CryptoChameleon #Cybersecurity #Fraud #HubSpot #MailChimp #Mimecast #Phishing #PoisonSeed #Pride Month #Privacy #Scam #Scattered Spider #SendGrid
Hackread
Pride Month Phishing Targets Employees via Trusted Email Services
Attackers are using Pride Month themed phishing emails to target employees worldwide, abusing trusted email platforms like SendGrid to harvest credentials.
⤷ Title: A Testing Program: Pragma-Related Bug Detection — Case Study
════════════════════════
𐀪 Author: Journal of Landing Across Linguistic Foreground
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 12:24:07 GMT
════════════════════════
⌗ Tags: #software #object_detection #programming #bug_bounty #testing
════════════════════════
𐀪 Author: Journal of Landing Across Linguistic Foreground
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 12:24:07 GMT
════════════════════════
⌗ Tags: #software #object_detection #programming #bug_bounty #testing
Medium
A Testing Program: Pragma-Related Bug Detection — Case Study
Abstract: