⤷ Title: Triple Threat Patched: Zimbra 10.1.16 Fixes XSS, XXE & LDAP Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:33:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Collaboration Suite #CSRF #Email Security #LDAP injection #Patch Alert #security update #XSS #xxe #Zimbra #Zimbra 10.1.16
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:33:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Collaboration Suite #CSRF #Email Security #LDAP injection #Patch Alert #security update #XSS #xxe #Zimbra #Zimbra 10.1.16
Daily CyberSecurity
Triple Threat Patched: Zimbra 10.1.16 Fixes XSS, XXE & LDAP Injection
Zimbra 10.1.16 patches critical XSS, XXE, and LDAP injection flaws. Update immediately to secure your email collaboration suite and restore PDF previews.
⤷ Title: Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:28:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23760 #CVE_2026_24423 #Email Security #living_off_the_land #Patch Alert #ReliaQuest #SmarterMail #Storm_2603 #Velociraptor #Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:28:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23760 #CVE_2026_24423 #Email Security #living_off_the_land #Patch Alert #ReliaQuest #SmarterMail #Storm_2603 #Velociraptor #Warlock Ransomware
Daily CyberSecurity
Email Under Siege: Storm-2603 Exploits SmarterMail to Deploy Warlock Ransomware
Storm-2603 exploits SmarterMail vulnerability CVE-2026-23760 to deploy Warlock ransomware. Upgrade to Build 9511 immediately to prevent system compromise.
⤷ Title: Dream Job or Nightmare? Lazarus Group Hunts Crypto Devs with “Graphalgo” Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:22:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Crypto Malware #Fake Recruiter #Graphalgo #javascript #Lazarus Group #North Korea #npm Security #Python #ReversingLabs #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:22:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Crypto Malware #Fake Recruiter #Graphalgo #javascript #Lazarus Group #North Korea #npm Security #Python #ReversingLabs #supply chain attack
Daily CyberSecurity
Dream Job or Nightmare? Lazarus Group Hunts Crypto Devs with "Graphalgo" Malware
Lazarus Group targets crypto developers with fake job offers in new "Graphalgo" campaign. Malicious npm packages deliver multi-stage malware. Stay alert.
⤷ Title: The Human Hack: LummaStealer Returns with Deceptive “ClickFix” Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:18:53 +0000
════════════════════════
⌗ Tags: #Malware #Bitdefender #CAPTCHA Fraud #CastleLoader #ClickFix #Cybercrime #Infostealer #LummaStealer #Malware_as_a_Service #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:18:53 +0000
════════════════════════
⌗ Tags: #Malware #Bitdefender #CAPTCHA Fraud #CastleLoader #ClickFix #Cybercrime #Infostealer #LummaStealer #Malware_as_a_Service #phishing #social engineering
Daily CyberSecurity
The Human Hack: LummaStealer Returns with Deceptive "ClickFix" Attacks
LummaStealer is back, evading takedowns with "ClickFix" tactics. Bitdefender reveals how fake CAPTCHAs trick users into running malware. Stay alert.
⤷ Title: Back to the Future: SSHStalker Botnet Revives 2009 Tactics to Hijack Linux Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:13:36 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Cybercrime #ddos #Flare Research #IRC Malware #Legacy Linux #Linux Botnet #SSH Brute_Force #SSHStalker #Tsunami Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:13:36 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Cybercrime #ddos #Flare Research #IRC Malware #Legacy Linux #Linux Botnet #SSH Brute_Force #SSHStalker #Tsunami Malware
Daily CyberSecurity
Back to the Future: SSHStalker Botnet Revives 2009 Tactics to Hijack Linux Servers
New SSHStalker botnet uses vintage IRC tactics & automated SSH brute-forcing to compromise Linux servers. Flare research reveals a "zombie army" in the making.
⤷ Title: Trojan Horse in the Server Room: Muddled Libra’s Rogue VM Strategy Exposed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:06:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Crime #Incident Response #Muddled Libra #Rogue VM #Scattered Spider #Snowflake #social engineering #UNC3944 #Unit 42 #VMware vSphere
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:06:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Crime #Incident Response #Muddled Libra #Rogue VM #Scattered Spider #Snowflake #social engineering #UNC3944 #Unit 42 #VMware vSphere
Daily CyberSecurity
Trojan Horse in the Server Room: Muddled Libra's Rogue VM Strategy Exposed
Unit 42 reveals Muddled Libra (Scattered Spider) uses rogue VMs in vSphere to persist. Learn how they bypass defenses without malware. Read more.
⤷ Title: Top 10 Recon Mistakes That Make Hackers Miss Easy Bugs
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 01:23:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #hacking #programming #ai
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 01:23:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #hacking #programming #ai
Medium
Top 10 Recon Mistakes That Make Hackers Miss Easy Bugs
Hi Vipul from The Hacker’s Log here 👋 Alright, let’s talk about money left on the table. 💸
⤷ Title: Breaking Role Barriers: Exploiting Broken Access Control in CriticalOps — HTB Walkthrough
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 01:23:15 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #hackthebox #owasp_top_10 #ctf
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 01:23:15 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #hackthebox #owasp_top_10 #ctf
Medium
Breaking Role Barriers: Exploiting Broken Access Control in CriticalOps — HTB Walkthrough
How a simple role manipulation led to full admin access in the HTB OWASP Top 10 2025 track
⤷ Title: Anonymous Auto Tor Proxy IP Changer
════════════════════════
𐀪 Author: Mr Robot Hackteam
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:01:31 GMT
════════════════════════
⌗ Tags: #proxy #cybersecurity #hacking #bug_bounty #hacks
════════════════════════
𐀪 Author: Mr Robot Hackteam
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:01:31 GMT
════════════════════════
⌗ Tags: #proxy #cybersecurity #hacking #bug_bounty #hacks
Medium
Anonymous Auto Tor Proxy IP Changer
Hello, you can use Tor IP to remain anonymous, and since the IP address is automatically changed, tracking becomes impossible, which makes…
⤷ Title: Arp-Scan para Pentesting: Escaneo de Red y Bypass de Firewalls
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #pentesting #hacking #bug_bounty #technology #cybersecurity
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #pentesting #hacking #bug_bounty #technology #cybersecurity
Medium
Arp-Scan para Pentesting: Escaneo de Red y Bypass de Firewalls
Domina arp-scan para descubrir hosts invisibles, realizar fingerprinting de hardware y evadir la segmentación de red en auditorías.
⤷ Title: The “Open Window” in the SSO Fortress: How I Accessed Internal GraphQL Schemas Without Login (And…
════════════════════════
𐀪 Author: Zer0Figure
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 02:57:09 GMT
════════════════════════
⌗ Tags: #security #bug_bounty_tips #cybersecurity #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Zer0Figure
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 02:57:09 GMT
════════════════════════
⌗ Tags: #security #bug_bounty_tips #cybersecurity #bug_bounty #bug_bounty_writeup
Medium
The “Open Window” in the SSO Fortress: How I Accessed Internal GraphQL Schemas Without Login (And Why It Was N/A)
I found a direct line into the backend of a Fortune 500 company’s private code infrastructure. No passwords, no tokens — just one forgotten…
⤷ Title: Fixing Custom Segmented Control
════════════════════════
𐀪 Author: Jerry PM
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 02:51:45 GMT
════════════════════════
⌗ Tags: #swift #ios #iphone #bug_bounty #swiftui
════════════════════════
𐀪 Author: Jerry PM
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 02:51:45 GMT
════════════════════════
⌗ Tags: #swift #ios #iphone #bug_bounty #swiftui
Medium
Fixing Custom Segmented Control
A Real Bug Story from Production Code: When Your Border Disappears Behind Parent View
⤷ Title: File Berubah Tanpa Izin? Wazuh FIM Tahu Siapa Pelakunya
════════════════════════
𐀪 Author: Kuray
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 02:56:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #siem #cyber_security_awareness #wazuh
════════════════════════
𐀪 Author: Kuray
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 02:56:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #siem #cyber_security_awareness #wazuh
Medium
File Berubah Tanpa Izin? Wazuh FIM Tahu Siapa Pelakunya
Di dunia keamanan siber, mengetahui “apa yang berubah” itu penting. Tapi mengetahui “siapa yang mengubahnya” itulah yang membedakan…
⤷ Title: Inside Job: Abandoned Outlook Add-in “AgreeTo” Steals 4,000 Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 03:27:26 +0000
════════════════════════
⌗ Tags: #Malware #Add_in Security #AgreeTo #Cloud Security #Credential Harvest #KOI Security #Microsoft Outlook #Office 365 #phishing #supply chain attack #Vercel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 03:27:26 +0000
════════════════════════
⌗ Tags: #Malware #Add_in Security #AgreeTo #Cloud Security #Credential Harvest #KOI Security #Microsoft Outlook #Office 365 #phishing #supply chain attack #Vercel
Daily CyberSecurity
Inside Job: Abandoned Outlook Add-in "AgreeTo" Steals 4,000 Credentials
Malicious Outlook add-in "AgreeTo" steals 4,000+ credentials. Attackers hijacked the abandoned tool in the official store. Uninstall immediately.
⤷ Title: $1000 Bounty for Chaining 2 IDOR’s & WAF Bypass to Expose Full Event Database
════════════════════════
𐀪 Author: Ahmed Ghadban
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:21:02 GMT
════════════════════════
⌗ Tags: #cloud_security #bug_bounty_writeup #cybersecurity #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: Ahmed Ghadban
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:21:02 GMT
════════════════════════
⌗ Tags: #cloud_security #bug_bounty_writeup #cybersecurity #bug_bounty #bug_bounty_tips
Medium
$1000 Bounty for Chaining 2 IDOR’s & WAF Bypass to Expose Full Event Database
Bounty: $1,000 | Severity: High
⤷ Title: From API Keys to Dependency Confusion: Scaling JavaScript Analysis with 0xJS and 0xDepCheck
════════════════════════
𐀪 Author: 0xPedrop
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 04:59:57 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #bug_bounty #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: 0xPedrop
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 04:59:57 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #bug_bounty #bug_bounty_writeup #bug_bounty_tips
Medium
From API Keys to Dependency Confusion: Scaling JavaScript Analysis with 0xJS and 0xDepCheck
Learn how to find vulnerabilities easily
👍1
⤷ Title: Stop. Your AI Agent Is Overprivileged.
════════════════════════
𐀪 Author: Arun Kumar (AK)
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:48:38 GMT
════════════════════════
⌗ Tags: #application_security #llm_security #agentic_ai #ai_security #owasp_top_10
════════════════════════
𐀪 Author: Arun Kumar (AK)
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:48:38 GMT
════════════════════════
⌗ Tags: #application_security #llm_security #agentic_ai #ai_security #owasp_top_10
Medium
Stop. Your AI Agent Is Overprivileged.
A practical security guide for teams shipping AI agents to production
⤷ Title: Web Application Security: Hands-On Practice (Chapter 11 from The Web Application Hacker’s Handbook)
════════════════════════
𐀪 Author: Aditya Kumar
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:45:23 GMT
════════════════════════
⌗ Tags: #web_application_security #hacking #cybersecurity #chapter_11 #testing
════════════════════════
𐀪 Author: Aditya Kumar
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:45:23 GMT
════════════════════════
⌗ Tags: #web_application_security #hacking #cybersecurity #chapter_11 #testing
Medium
Web Application Security: Hands-On Practice (Chapter 11 from The Web Application Hacker’s Handbook)
Note: This write-up reflects my learning and hands-on practice based on the book The Web Application Hacker’s Handbook: Discovering and…
⤷ Title: Linux Privilege enumeration
════════════════════════
𐀪 Author: Dev kaushik
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:36:29 GMT
════════════════════════
⌗ Tags: #hacking #ethical_hacking #linux #computers #exploit
════════════════════════
𐀪 Author: Dev kaushik
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 05:36:29 GMT
════════════════════════
⌗ Tags: #hacking #ethical_hacking #linux #computers #exploit
Medium
Linux Privilege enumeration
Meaning of Linux Privilege enumeration is that we had already exploit the machine and now we have gained the access of the normal user and…
⤷ Title: Architectural Asymmetry in Authentication: Part 1 — Summary
════════════════════════
𐀪 Author: Anton Minin Baranovskii
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 04:23:07 GMT
════════════════════════
⌗ Tags: #passwordless #authentication #infosec #cybersecurity #passkey
════════════════════════
𐀪 Author: Anton Minin Baranovskii
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 04:23:07 GMT
════════════════════════
⌗ Tags: #passwordless #authentication #infosec #cybersecurity #passkey
Medium
Architectural Asymmetry in Authentication: Part 1 — Summary
Most authentication systems still follow an identity-first model.
⤷ Title: CVE-2025–49144分析:Notepad++ Privilege Escalation 與防禦策略
════════════════════════
𐀪 Author: segalee
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 04:01:11 GMT
════════════════════════
⌗ Tags: #blue_team #privilege_escalation #cve #cybersecurity #infosec
════════════════════════
𐀪 Author: segalee
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 04:01:11 GMT
════════════════════════
⌗ Tags: #blue_team #privilege_escalation #cve #cybersecurity #infosec
Medium
CVE-2025–49144分析:Notepad++ Privilege 與防禦策略
漏洞摘要 Notepad++ 是一款免費且開源的原始碼編輯器,在文書人員以及工程師中廣泛被使用,其安裝程式被發現存在 本機提權 (Local Privilege Escalation, LPE) 漏洞。