⤷ Title: How a Capital Letter Bypasses Fortinet 2FA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 03:09:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #2FA Bypass #Active Directory #CVE_2020_12812 #cyber attack #Cybersecurity 2025 #FortiGate #Fortinet #FortiOS #LDAP #MFA #SSL VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 03:09:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #2FA Bypass #Active Directory #CVE_2020_12812 #cyber attack #Cybersecurity 2025 #FortiGate #Fortinet #FortiOS #LDAP #MFA #SSL VPN
Penetration Testing Tools
How a Capital Letter Bypasses Fortinet 2FA
Fortinet has warned administrators that real-world attacks are once again exploiting the vulnerability FG-IR-19-283 (CVE-2020-12812), first disclosed in
⤷ Title: The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 03:47:57 +0000
════════════════════════
⌗ Tags: #Data Leak #2FA #Account Hijacking #API Leak #Cybersecurity 2026 #dark web #Data Breach #Instagram #Malwarebytes #Meta #phishing #Solonik
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 03:47:57 +0000
════════════════════════
⌗ Tags: #Data Leak #2FA #Account Hijacking #API Leak #Cybersecurity 2026 #dark web #Data Breach #Instagram #Malwarebytes #Meta #phishing #Solonik
Daily CyberSecurity
The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web
A monumental data breach has compromised approximately 17.5 million Instagram users, resulting in the exfiltration of sensitive personal information that is now proliferating across the dark web. …
⤷ Title: Bypassing Two-Factor Authentication via Password Reset Functionality
════════════════════════
𐀪 Author: WHO AM I ?
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 00:40:35 GMT
════════════════════════
⌗ Tags: #2fa #penetration_testing #bug_bounty #cybersecurity #broken_access_control
════════════════════════
𐀪 Author: WHO AM I ?
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 00:40:35 GMT
════════════════════════
⌗ Tags: #2fa #penetration_testing #bug_bounty #cybersecurity #broken_access_control
Medium
Bypassing Two-Factor Authentication via Password Reset Functionality
⤷ Title: Hacked Despite 2FA: My LinkedIn Hack Lessons
════════════════════════
𐀪 Author: Ebube Nwankwo
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 21:34:48 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #2fa_bypass #tech #linkedin
════════════════════════
𐀪 Author: Ebube Nwankwo
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 21:34:48 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #2fa_bypass #tech #linkedin
Medium
Hacked Despite 2FA: My LinkedIn Hack Lessons
I used to wonder how people's accounts get hacked, even with 2FA turned on.
⤷ Title: Unmasking Gbyte: How One Hacker Exposed the Masters of 2FA-Bypassing Stalkerware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 08:26:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA Bypass #Data Breach 2026 #Gbyte Technology #Google Password Leak #iCloud Hack #Maia Arson Crimew #MSafely #Shenzhen #SpyX #stalkerware #Xiunde Cheng
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 08:26:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA Bypass #Data Breach 2026 #Gbyte Technology #Google Password Leak #iCloud Hack #Maia Arson Crimew #MSafely #Shenzhen #SpyX #stalkerware #Xiunde Cheng
Penetration Testing Tools
Unmasking Gbyte: How One Hacker Exposed the Masters of 2FA-Bypassing Stalkerware
Investigative journalist Maia Arson Crimew disclosed in a recent blog post that in February 2024, she received a
⤷ Title: 2FA Bypass via Session Fixation — High Vulnerability in Vero 300$
════════════════════════
𐀪 Author: Hasan Khan
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 18:35:14 GMT
════════════════════════
⌗ Tags: #idor_vulnerability #bug_bounty_tips #2fa_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Hasan Khan
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 18:35:14 GMT
════════════════════════
⌗ Tags: #idor_vulnerability #bug_bounty_tips #2fa_bypass #bug_bounty_writeup
Medium
2FA Bypass via Session Fixation — High Vulnerability in Vero 300$
📌 Introduction
⤷ Title: The “Go Client” Trap: Why Your RustDesk ID is Currently Under Automated Botnet Siege
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:03:24 +0000
════════════════════════
⌗ Tags: #Malware #2FA #botnet attack #cybersecurity alert 2026 #Go Client #IT security tips #Remote Access Malware #remote desktop security #RustDesk #self_hosting RustDesk #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:03:24 +0000
════════════════════════
⌗ Tags: #Malware #2FA #botnet attack #cybersecurity alert 2026 #Go Client #IT security tips #Remote Access Malware #remote desktop security #RustDesk #self_hosting RustDesk #social engineering
Daily CyberSecurity
The "Go Client" Trap: Why Your RustDesk ID is Currently Under Automated Botnet Siege
A massive botnet is targeting RustDesk users with fake "Go Client" connection requests. Learn how to lock down your ID and prevent unauthorized remote takeovers.
⤷ Title: 2FA Bypass via OTP Reuse Across Multiple Authentication Flows
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
Medium
2FA Bypass via OTP Reuse Across Multiple Authentication Flows
Hello everyone, I’m Jeet. I used to hunt bugs regularly, but due to some personal reasons I couldn’t stay consistent for a while. Now I’m…
⤷ Title: Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:36:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #CVE_2025_64111 #CVE_2025_64175 #CVE_2026_24135 #Git Service #Gogs #Patch Alert #Path Traversal #Remote Code Execution #Self_Hosted
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:36:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #CVE_2025_64111 #CVE_2025_64175 #CVE_2026_24135 #Git Service #Gogs #Patch Alert #Path Traversal #Remote Code Execution #Self_Hosted
Daily CyberSecurity
Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass
Critical Gogs flaws (CVE-2025-64111) allow RCE & 2FA bypass. Attackers can execute commands via .git config. Update to v0.13.4 immediately.
⤷ Title: 2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
Medium
2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
Hello Hackers 👋
⤷ Title: Total Mobile Dominion: The “ZeroDayRAT” Spyware Turning iPhones and Androids into Open Books
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 03:32:23 +0000
════════════════════════
⌗ Tags: #Malware #2FA Bypass #Android malware #iOS spyware #iVerify #mobile EDR #Mobile Spyware #Smishing #Tech News 2026 #Telegram malware #ZeroDayRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 03:32:23 +0000
════════════════════════
⌗ Tags: #Malware #2FA Bypass #Android malware #iOS spyware #iVerify #mobile EDR #Mobile Spyware #Smishing #Tech News 2026 #Telegram malware #ZeroDayRAT
Penetration Testing Tools
Total Mobile Dominion: The "ZeroDayRAT" Spyware Turning iPhones and Androids into Open Books
Security analysts at iVerify have unearthed a nascent mobile espionage platform dubbed ZeroDayRAT within public Telegram channels. The
⤷ Title: “CL Suite” Deception: Malicious Chrome Extension Steals 2FA Secrets and Meta Business Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #2FA Theft #Account Takeover #CL Suite #Cyber Security #Facebook Business #Instagram Business #Malicious Chrome Extension #Meta Business Suite #Socket Threat Research #TOTP Seeds
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #2FA Theft #Account Takeover #CL Suite #Cyber Security #Facebook Business #Instagram Business #Malicious Chrome Extension #Meta Business Suite #Socket Threat Research #TOTP Seeds
Daily CyberSecurity
"CL Suite" Deception: Malicious Chrome Extension Steals 2FA Secrets and Meta Business Data
"CL Suite" Chrome extension steals Meta Business 2FA seeds & data. Attackers bypass security even after uninstall. Reset 2FA immediately.
⤷ Title: Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 12:53:20 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Phishing Scam #Security #2FA #Cybersecurity #Europol #Fraud #MFA #Phishing #Scam #Tycoon 2FA
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 12:53:20 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Phishing Scam #Security #2FA #Cybersecurity #Europol #Fraud #MFA #Phishing #Scam #Tycoon 2FA
Hackread
Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA
Follow us on all social media platforms @Hackread
⤷ Title: How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt
════════════════════════
𐀪 Author: Lokesh Soni
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 09:01:09 GMT
════════════════════════
⌗ Tags: #2fa #ethicle_hacking #web_security_testing #hacking #2fa_bypass
════════════════════════
𐀪 Author: Lokesh Soni
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 09:01:09 GMT
════════════════════════
⌗ Tags: #2fa #ethicle_hacking #web_security_testing #hacking #2fa_bypass
Medium
How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt
hello gyussssss
⤷ Title: Inside the Master Panel: How an Unprotected Server Exposed a Massive X Hijacking Operation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:47:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA #BOTNET #Breakglass Intelligence #credential stuffing #cybersecurity #data breach #Infosec #Turkish Hackers #twitter #X
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:47:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA #BOTNET #Breakglass Intelligence #credential stuffing #cybersecurity #data breach #Infosec #Turkish Hackers #twitter #X
Penetration Testing Tools
Inside the Master Panel: How an Unprotected Server Exposed a Massive X Hijacking Operation
An exposed administrative console, accessible without even the most rudimentary password, has transformed a clandestine operation into a
⤷ Title: Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 04:00:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA bypass #Aggravated Identity Theft #Cryptocurrency Theft #Cybercrime #Department of Justice #Dundee #fbi #Scotland #SIM Swapping #SMS phishing #Tyler Robert Buchanan #Wire Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 04:00:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA bypass #Aggravated Identity Theft #Cryptocurrency Theft #Cybercrime #Department of Justice #Dundee #fbi #Scotland #SIM Swapping #SMS phishing #Tyler Robert Buchanan #Wire Fraud
Daily CyberSecurity
Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign
Tyler Buchanan pleads guilty in US court for an $8M cyber heist. Discover how SMS phishing and SIM swapping bypassed 2FA to drain corporate & crypto assets.
⤷ Title: Sentry’s 9.1 CVSS SSO Flaw Lets Attackers “Link” Their Way Into Your Account
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 12:45:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA #Account Takeover #CVE_2026_42354 #CVSS 9.1 #cybersecurity #Identity Linking #infosec #SAML SSO #Self_Hosted Sentry #sentry #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 12:45:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA #Account Takeover #CVE_2026_42354 #CVSS 9.1 #cybersecurity #Identity Linking #infosec #SAML SSO #Self_Hosted Sentry #sentry #SSO Bypass
Daily CyberSecurity
Sentry’s 9.1 CVSS SSO Flaw Lets Attackers "Link" Their Way Into Your Account
Sentry reveals a critical 9.1 CVSS flaw (CVE-2026-42354) in SAML SSO. Multi-org instances are at risk of account takeover via identity linking. Patch now!
⤷ Title: New “Pheno” Malware Hijacks Microsoft Phone Link to Steal SMS and OTPs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 06:22:26 +0000
════════════════════════
⌗ Tags: #Malware #2FA bypass #Cisco Talos #CloudZ RAT #cybersecurity #infosec #Microsoft Phone Link #mobile security #OTP Theft #Pheno Plugin #SMS interception #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 06:22:26 +0000
════════════════════════
⌗ Tags: #Malware #2FA bypass #Cisco Talos #CloudZ RAT #cybersecurity #infosec #Microsoft Phone Link #mobile security #OTP Theft #Pheno Plugin #SMS interception #Windows malware
Daily CyberSecurity
New "Pheno" Malware Hijacks Microsoft Phone Link to Steal SMS and OTPs
Cisco Talos exposes Pheno, a malware plugin that hijacks Microsoft Phone Link to steal SMS and 2FA codes without touching your phone. Secure your PC today!
⤷ Title: How I Bypassed 2FA by Mutating My Profile Phone Number in Graphql Request
════════════════════════
𐀪 Author: Mohamed Elmorsy
════════════════════════
ⴵ Time: Tue, 19 May 2026 16:30:03 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #hacking #2fa_bypass
════════════════════════
𐀪 Author: Mohamed Elmorsy
════════════════════════
ⴵ Time: Tue, 19 May 2026 16:30:03 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #hacking #2fa_bypass
Medium
How I Bypassed 2FA by Mutating My Profile Phone Number in Graphql Request
How a simple phone number update in Graphql request compeletly bypassed 2fa protection and gave full account control.
⤷ Title: UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 09:04:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA phishing #CERT Polska #Ghostwriter #Gmail phishing campaign #Storm_0257 #UNC1151 #UNC1151 Gmail phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 09:04:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA phishing #CERT Polska #Ghostwriter #Gmail phishing campaign #Storm_0257 #UNC1151 #UNC1151 Gmail phishing
Daily CyberSecurity
UNC1151 'Ghostwriter' Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
The UNC1151 Gmail phishing campaign by Ghostwriter steals passwords and 2FA codes from Polish targets via fake Google login pages. Stay alert.