⤷ Title: GitLab Patch Alert: High-Severity Web IDE Flaw Exposes Private Repos
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 01:58:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_7659 #Denial of Service #DevOps Security #gitlab #graphql #Markdown Vulnerability #Patch Alert #Token Theft #Web IDE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 01:58:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_7659 #Denial of Service #DevOps Security #gitlab #graphql #Markdown Vulnerability #Patch Alert #Token Theft #Web IDE
Daily CyberSecurity
GitLab Patch Alert: High-Severity Web IDE Flaw Exposes Private Repos
GitLab fixes critical CVE-2025-7659 (CVSS 8.0). Unauthenticated attackers can steal tokens via Web IDE. Update to v18.8.4 now to secure your code.
⤷ Title: Under Siege: GTIG Report Exposes North Korean Spies & Russian Drone Hacks in Defense Sector
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:50:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT44 #cyber_espionage #Defense Industrial Base #Drone Security #Edge Device Security #Google Threat Intelligence #GTIG #Insider Threat #North Korean IT workers #SANDWORM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:50:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT44 #cyber_espionage #Defense Industrial Base #Drone Security #Edge Device Security #Google Threat Intelligence #GTIG #Insider Threat #North Korean IT workers #SANDWORM
Daily CyberSecurity
Under Siege: GTIG Report Exposes North Korean Spies & Russian Drone Hacks in Defense Sector
GTIG report: Defense Industrial Base faces "constant siege" from Russian drone hackers & North Korean IT insiders. Learn the new threats.
⤷ Title: “Fiber” Optic Failure: Predictable UUIDs Expose Go Web Framework to Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:48:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Backend Development #CSRF #CVE_2025_66630 #Fiber Framework #go #Golang #Patch Alert #Session Hijacking #UUID #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:48:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Backend Development #CSRF #CVE_2025_66630 #Fiber Framework #go #Golang #Patch Alert #Session Hijacking #UUID #Web Security
Daily CyberSecurity
"Fiber" Optic Failure: Predictable UUIDs Expose Go Web Framework to Hijacking
Critical Fiber framework vulnerability CVE-2025-66630 (CVSS 9.2) causes silent UUID failures, leading to session hijacking. Update to v2.52.11 now.
⤷ Title: Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #cyber_espionage #Defused #Fileless Malware #In_Memory Backdoor #initial access broker #Ivanti EPMM #Java Class Loader #Patch Alert
Daily CyberSecurity
Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM
New campaign targets Ivanti EPMM with dormant in-memory backdoors. Attackers use CVE-2026-1281 to plant "sleeper" agents. Restart servers immediately.
⤷ Title: Unmasking the Proxy: Silent Push “Traffic Origin” Exposes True Actor Locations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #geolocation #Insider Threats #IP Analysis #North Korean IT workers #residential proxies #Silent Push #threat intelligence #Traffic Origin #VPN Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:42:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #geolocation #Insider Threats #IP Analysis #North Korean IT workers #residential proxies #Silent Push #threat intelligence #Traffic Origin #VPN Detection
Daily CyberSecurity
Unmasking the Proxy: Silent Push "Traffic Origin" Exposes True Actor Locations
Silent Push's Traffic Origin technology strips away VPN masks to reveal the true location of threat actors. Detect North Korean & Russian proxies now.
⤷ Title: Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Taint Bypass #CVE_2026_25881 #JavaScript Security #Patch Alert #Prototype Pollution #Remote Code Execution #Sandbox Escape #SandboxJS #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Array Taint Bypass #CVE_2026_25881 #JavaScript Security #Patch Alert #Prototype Pollution #Remote Code Execution #Sandbox Escape #SandboxJS #Web Security
Daily CyberSecurity
Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
Critical SandboxJS flaw CVE-2026-25881 allows sandbox escape via prototype pollution. Malicious code can modify host logic & execute RCE. Update to v0.8.31.
⤷ Title: Fake CEO, Real Hack: North Korea Uses AI Deepfakes to Steal Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:32:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI Threat #CHROMEPUSH #Cryptocurrency Theft #DEEPBREATH #Deepfake Attack #macOS Malware #Mandiant #SILENCELIFT #social engineering #UNC1069
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:32:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI Threat #CHROMEPUSH #Cryptocurrency Theft #DEEPBREATH #Deepfake Attack #macOS Malware #Mandiant #SILENCELIFT #social engineering #UNC1069
Daily CyberSecurity
Fake CEO, Real Hack: North Korea Uses AI Deepfakes to Steal Crypto
North Korean hackers (UNC1069) use AI deepfakes & "ClickFix" tactics to deploy SILENCELIFT malware. Learn how they target crypto firms via Zoom.
⤷ Title: Factory Flaw: Critical WAGO Switch Vulnerabilities (CVSS 9.8) Allow Remote Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:27:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CERT@VDE #CVE_2026_22904 #CVE_2026_22906 #Hardcoded Encryption Key #ICS security #Industrial Managed Switch #OT Security #SCADA #WAGO 852 Series
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:27:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CERT@VDE #CVE_2026_22904 #CVE_2026_22906 #Hardcoded Encryption Key #ICS security #Industrial Managed Switch #OT Security #SCADA #WAGO 852 Series
Daily CyberSecurity
Factory Flaw: Critical WAGO Switch Vulnerabilities (CVSS 9.8) Allow Remote Takeover
Critical flaws in WAGO 852 switches (CVSS 9.8) allow remote takeover via hardcoded keys & buffer overflows. Update firmware 2.64 immediately.
⤷ Title: Hiding in the Cloud: GuLoader Malware Evolves to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:22:09 +0000
════════════════════════
⌗ Tags: #Malware #CloudEye #cybersecurity #Downloader #Google Drive Malware #GuLoader #infosec #Malware Analysis #Obfuscation #Polymorphic Code #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:22:09 +0000
════════════════════════
⌗ Tags: #Malware #CloudEye #cybersecurity #Downloader #Google Drive Malware #GuLoader #infosec #Malware Analysis #Obfuscation #Polymorphic Code #Zscaler ThreatLabz
Daily CyberSecurity
Hiding in the Cloud: GuLoader Malware Evolves to Evade Detection
Zscaler analyzes GuLoader's evolution. The malware uses Google Drive, polymorphic code, and exception-based obfuscation to evade detection.
⤷ Title: CVE-2026-23906: Authentication Bypass Flaw Hits Apache Druid Analytics Clusters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Anonymous Bind #Apache Druid #Authentication Bypass #big data #CVE_2026_23906 #database security #LDAP Authentication #Patch Alert #Real_Time Analytics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:17:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Anonymous Bind #Apache Druid #Authentication Bypass #big data #CVE_2026_23906 #database security #LDAP Authentication #Patch Alert #Real_Time Analytics
Daily CyberSecurity
CVE-2026-23906: Authentication Bypass Flaw Hits Apache Druid Analytics Clusters
Critical Apache Druid flaw (CVE-2026-23906) allows login with no password via LDAP anonymous binds. Update to v36.0.0 or disable anonymous binds now.
⤷ Title: 5 Benefits of Using Automation to Stay in Touch With Customers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:13:21 +0000
════════════════════════
⌗ Tags: #Technology
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:13:21 +0000
════════════════════════
⌗ Tags: #Technology
Daily CyberSecurity
5 Benefits of Using Automation to Stay in Touch With Customers
⤷ Title: Signed” Sealed, Delivered: Cybercriminals Abuse PayPal and Apple to Bypass Email Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:11:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #business email compromise #DKIM replay #DMARC #Email Security #INKY #Invoice Fraud #Kaseya #PayPal Scam #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:11:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #business email compromise #DKIM replay #DMARC #Email Security #INKY #Invoice Fraud #Kaseya #PayPal Scam #phishing #social engineering
Daily CyberSecurity
Signed" Sealed, Delivered: Cybercriminals Abuse PayPal and Apple to Bypass Email Security
Hackers abuse PayPal & Apple to send "perfect" phishing emails. Learn how DKIM Replay attacks bypass security filters & DMARC checks.
⤷ Title: Handshake Halt: GnuTLS 3.8.12 Fixes TLS 1.3 Crash & CPU Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:06:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Certificate Verification #CVE_2025_14831 #CVE_2026_1584 #Denial of Service #GnuTLS #network_security #Patch Alert #PSK Binder #SSL/TLS #TLS 1.3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:06:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Certificate Verification #CVE_2025_14831 #CVE_2026_1584 #Denial of Service #GnuTLS #network_security #Patch Alert #PSK Binder #SSL/TLS #TLS 1.3
Daily CyberSecurity
Handshake Halt: GnuTLS 3.8.12 Fixes TLS 1.3 Crash & CPU Exhaustion
GnuTLS v3.8.12 fixes high-severity DoS flaws (CVE-2026-1584). Malicious TLS 1.3 handshakes can crash servers. Update now to prevent outages.
⤷ Title: CVE-2026-24343: Apache HertzBeat Flaw Opens Door to Resource Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:00:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache HertzBeat #CVE_2026_24343 #Denial of Service #DevOps #Monitoring Tools #Observability #Patch Alert #Resource Exhaustion #Xpath injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 00:00:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache HertzBeat #CVE_2026_24343 #Denial of Service #DevOps #Monitoring Tools #Observability #Patch Alert #Resource Exhaustion #Xpath injection
Daily CyberSecurity
CVE-2026-24343: Apache HertzBeat Flaw Opens Door to Resource Exhaustion
Apache HertzBeat flaw CVE-2026-24343 allows DoS via XPath injection. Vulnerable versions 1.7.1-1.7.9. Update to v1.8.0 immediately.
⤷ Title: Firewall and IDS/IPS: Hard Lab — HackTheBox
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 01:25:17 GMT
════════════════════════
⌗ Tags: #hackthebox #nmap #hacking #penetration_testing
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 01:25:17 GMT
════════════════════════
⌗ Tags: #hackthebox #nmap #hacking #penetration_testing
Medium
Firewall and IDS/IPS: Hard Lab — HackTheBox
If you’re here, then you are on the last section of the Network Enumeration with Nmap module in HTB. Congratulations! You’re almost done…
⤷ Title: NOTICE: Date/Time Normalization Maintenance of Historical CVE Records to Occur February 16–25, 2026
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 23:53:27 GMT
════════════════════════
⌗ Tags: #infosec #vulnerability #cybersecurity #information_security #technology
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 23:53:27 GMT
════════════════════════
⌗ Tags: #infosec #vulnerability #cybersecurity #information_security #technology
Medium
NOTICE: Date/Time Normalization Maintenance of Historical CVE Records to Occur February 16–25, 2026
The CVE™ Program will normalize the formatting of date/time fields across historical CVE Records from February 16, 2026, through February…
⤷ Title: PicoCTF.org CTF Challenge Write Up
Category: Web Exploitation
════════════════════════
𐀪 Author: Damian Robert Moore
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 03:51:40 GMT
════════════════════════
⌗ Tags: #capture_the_flag #no_ai_here #web_exploitation #bug_bounty #picoctf
Category: Web Exploitation
════════════════════════
𐀪 Author: Damian Robert Moore
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 03:51:40 GMT
════════════════════════
⌗ Tags: #capture_the_flag #no_ai_here #web_exploitation #bug_bounty #picoctf
Medium
PicoCTF.org CTF Challenge Write Up Category: Web Exploitation
Challenge Name: <head-dump>
⤷ Title: Blind OS Command Injection with Out-of-Band DNS Interaction
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 03:17:23 GMT
════════════════════════
⌗ Tags: #command_injection #blind_os_injection #os_command_injection #bug_bounty #dns_data_exfiltration
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 03:17:23 GMT
════════════════════════
⌗ Tags: #command_injection #blind_os_injection #os_command_injection #bug_bounty #dns_data_exfiltration
Medium
Blind OS Command Injection with Out-of-Band DNS Interaction
Exploiting Blind OS Command Injection via Out-of-Band DNS.
⤷ Title: Logic Poisoning: How One Bad Review Broke Ratings
════════════════════════
𐀪 Author: Parth Narula
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 02:52:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web_application_security #bug_bounty_writeup #vulnerability
════════════════════════
𐀪 Author: Parth Narula
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 02:52:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web_application_security #bug_bounty_writeup #vulnerability
Medium
Logic Poisoning: How One Bad Review Broke Ratings
Hey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…
⤷ Title: How To Hack Part 3
════════════════════════
𐀪 Author: Red
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 02:11:00 GMT
════════════════════════
⌗ Tags: #education #cybersecurity #infosec #linux #hacking
════════════════════════
𐀪 Author: Red
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 02:11:00 GMT
════════════════════════
⌗ Tags: #education #cybersecurity #infosec #linux #hacking
Medium
How To Hack Part 3
Linux Capture The Flag Bandit Levels 7 to 11
⤷ Title: CSRF Vulnerability Analysis in DVWA (Low to Impossible)
════════════════════════
𐀪 Author: Narathama Firmansyah Putra
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 03:05:11 GMT
════════════════════════
⌗ Tags: #csrf_attack #web_penetration_testing #penetration_testing #dvwa #cybersecurity
════════════════════════
𐀪 Author: Narathama Firmansyah Putra
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 03:05:11 GMT
════════════════════════
⌗ Tags: #csrf_attack #web_penetration_testing #penetration_testing #dvwa #cybersecurity
Medium
CSRF Vulnerability Analysis in DVWA (Low to Impossible)
Introduction CSRF (Cross Site Request Forgery) adalah serangan yang memanfaatkan akun korban yang sedang login untuk menjalankan aksi tanpa…