⤷ Title: “Coruna” Exploit Kit: Mass iOS Attacks Pivot from Crypto Scams to Iran-Themed Lures
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:50:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Coruna #Cryptocurrency Drainer #cyber_espionage #Google Threat Intelligence #iOS Exploit Kit #iPhone security #Plasmagrid #threat intelligence #Validin #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:50:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Coruna #Cryptocurrency Drainer #cyber_espionage #Google Threat Intelligence #iOS Exploit Kit #iPhone security #Plasmagrid #threat intelligence #Validin #Vulnerability
Daily CyberSecurity
"Coruna" Exploit Kit: Mass iOS Attacks Pivot from Crypto Scams to Iran-Themed Lures
Validin reveals how the Coruna iOS exploit kit evolved from targeted surveillance to mass crypto-draining and geopolitical watering hole attacks.
⤷ Title: Fake CleanMyMac Site Unleashes SHub Stealer to Drain macOS Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:45:06 +0000
════════════════════════
⌗ Tags: #Malware #CleanMyMac Phishing #ClickFix #Cryptocurrency Theft #cybersecurity #infosec #MAC Malware #macOS security #SHub Stealer #social engineering #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:45:06 +0000
════════════════════════
⌗ Tags: #Malware #CleanMyMac Phishing #ClickFix #Cryptocurrency Theft #cybersecurity #infosec #MAC Malware #macOS security #SHub Stealer #social engineering #threat intelligence
Daily CyberSecurity
Fake CleanMyMac Site Unleashes SHub Stealer to Drain macOS Crypto Wallets
A fake CleanMyMac website is using ClickFix tactics to trick macOS users into installing SHub Stealer, a potent malware targeting passwords and crypto.
⤷ Title: Critical 9.8 CVSS Flaws Expose SICK Lector Scanners to Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:41:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2330 #CVE_2026_2331 #cybersecurity #ICS security #industrial automation #Manufacturing Security #OT Security #Patch Alert #SICK Lector #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:41:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2330 #CVE_2026_2331 #cybersecurity #ICS security #industrial automation #Manufacturing Security #OT Security #Patch Alert #SICK Lector #Vulnerability
Daily CyberSecurity
Critical 9.8 CVSS Flaws Expose SICK Lector Scanners to Hijacking
SICK PSIRT warns of critical vulnerabilities (CVE-2026-2330, CVE-2026-2331) in Lector85x and Lector83x scanners allowing full device takeover. Update now.
⤷ Title: Malicious “Hex Visualizer” Chrome Extension Targeting imToken Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:37:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Extension Phishing #Crypto Wallet Drainer #Cryptocurrency Security #Homoglyph Attack #ImToken Chromophore #infosec #Malware Analysis #Seed Phrase Theft #Socket Threat Research #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:37:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Extension Phishing #Crypto Wallet Drainer #Cryptocurrency Security #Homoglyph Attack #ImToken Chromophore #infosec #Malware Analysis #Seed Phrase Theft #Socket Threat Research #Web3 security
Daily CyberSecurity
Malicious "Hex Visualizer" Chrome Extension Targeting imToken Users
Socket researchers uncover "ImToken Chromophore," a malicious Chrome extension using fake branding and homoglyphs to steal crypto wallet seed phrases.
⤷ Title: Critical 9.3 CVSS Flaw in Gogs Turns Repositories into Malware Delivery Vectors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:32:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Repository Overwrite #CVE_2026_25921 #cybersecurity #Gogs #infosec #Large File Storage #LFS #Path Collision #supply chain attack #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:32:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Repository Overwrite #CVE_2026_25921 #cybersecurity #Gogs #infosec #Large File Storage #LFS #Path Collision #supply chain attack #Vulnerability
Daily CyberSecurity
Critical 9.3 CVSS Flaw in Gogs Turns Repositories into Malware Delivery Vectors
A critical 9.3 CVSS flaw (CVE-2026-25921) in Gogs' LFS handling allows attackers to silently overwrite repository files, risking severe supply-chain attacks.
⤷ Title: Agencies Issue Urgent Warning on INC Ransom Healthcare Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:22:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ACSC #CERT Tonga #cybersecurity #Double Extortion #healthcare security #INC Ransom #infosec #NCSC New Zealand #ransomware #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:22:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ACSC #CERT Tonga #cybersecurity #Double Extortion #healthcare security #INC Ransom #infosec #NCSC New Zealand #ransomware #threat intelligence
Daily CyberSecurity
Agencies Issue Urgent Warning on INC Ransom Healthcare Attacks
A joint advisory warns of INC Ransom's devastating pivot to the Pacific. Discover how this RaaS group uses double extortion to target healthcare sectors.
⤷ Title: Critical Request Smuggling & Cache Flaws Discovered in Cloudflare’s Pingora
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:18:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cache Poisoning #Cloudflare Pingora #CVE_2026_2833 #CVE_2026_2835 #CVE_2026_2836 #cybersecurity #http_request_smuggling #infosec #Patch Alert #Rust Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:18:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cache Poisoning #Cloudflare Pingora #CVE_2026_2833 #CVE_2026_2835 #CVE_2026_2836 #cybersecurity #http_request_smuggling #infosec #Patch Alert #Rust Security
Daily CyberSecurity
Critical Request Smuggling & Cache Flaws Discovered in Cloudflare's Pingora
Discover three critical flaws (including CVE-2026-2835) in Cloudflare's Pingora Rust framework causing request smuggling and cache poisoning. Update now.
⤷ Title: The Spy in Your Sidebar: Fake AI Browser Extensions Steal Data from 900,000 Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:11:44 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Web Store #Chromium Security #cyber_espionage #cybersecurity #data exfiltration #infosec #Malicious AI Extensions #Microsoft Defender #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:11:44 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Web Store #Chromium Security #cyber_espionage #cybersecurity #data exfiltration #infosec #Malicious AI Extensions #Microsoft Defender #threat intelligence
Daily CyberSecurity
The Spy in Your Sidebar: Fake AI Browser Extensions Steal Data from 900,000 Users
Microsoft Defender uncovers a massive campaign of malicious Chromium extensions impersonating AI tools to steal data from 900,000 users. Audit browsers now.
⤷ Title: The ‘Contagious Interview’ Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:07:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #infosec #Kill Switch #LinkedIn Phishing #Malware Analysis #North Korean malware #social engineering #threat intelligence #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:07:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #infosec #Kill Switch #LinkedIn Phishing #Malware Analysis #North Korean malware #social engineering #threat intelligence #Web3 security
Daily CyberSecurity
The 'Contagious Interview' Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
A fake LinkedIn recruiter and a poisoned GitHub repo: See how a CEO uncovered the North Korean "Contagious Interview" malware targeting Web3 developers.
⤷ Title: Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:02:53 +0000
════════════════════════
⌗ Tags: #Malware #Bincrypter #ClipXDaemon #Cryptocurrency Hijacker #cybersecurity #Cyble Research #infosec #Linux Malware #Process Masquerading #threat intelligence #X11 Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:02:53 +0000
════════════════════════
⌗ Tags: #Malware #Bincrypter #ClipXDaemon #Cryptocurrency Hijacker #cybersecurity #Cyble Research #infosec #Linux Malware #Process Masquerading #threat intelligence #X11 Security
Daily CyberSecurity
Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
Cyble Research unmasks ClipXDaemon, a C2-less Linux malware that silently hijacks cryptocurrency wallet addresses in X11 clipboard environments.
⤷ Title: Guía de XXE Injection: Fundamentos, Payloads y Estrategias de Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #cybersecurity #web_security #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #cybersecurity #web_security #hacking
Medium
Guía de XXE Injection: Fundamentos, Payloads y Estrategias de Bug Bounty
Aprende qué es XXE, cómo detectarlo y los mejores payloads para lectura de archivos, SSRF y ataques OOB en auditorías de seguridad.
⤷ Title: THM: Windows Privilege Escalation
════════════════════════
𐀪 Author: Murad Salem
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 23:32:07 GMT
════════════════════════
⌗ Tags: #tryhackme #privilege_escalation #cybersecurity #penetration_testing #windows
════════════════════════
𐀪 Author: Murad Salem
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 23:32:07 GMT
════════════════════════
⌗ Tags: #tryhackme #privilege_escalation #cybersecurity #penetration_testing #windows
Medium
THM: Windows Privilege Escalation
A write-up for Windows Privilege Escalation room
⤷ Title: TryHackMe Write-Up: AD Basic Enumeration
════════════════════════
𐀪 Author: Senoputraaa
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 23:13:56 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme_writeup #active_directory #cybersecurity
════════════════════════
𐀪 Author: Senoputraaa
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 23:13:56 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme_writeup #active_directory #cybersecurity
Medium
TryHackMe Write-Up: AD Basic Enumeration
Pendahuluan
⤷ Title: TryHack3M — Bricks Heist
════════════════════════
𐀪 Author: inbd4unix
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:05:01 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #tryhackme_writeup
════════════════════════
𐀪 Author: inbd4unix
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:05:01 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #tryhackme_writeup
Medium
TryHack3M — Bricks Heist
Technical Walkthrough
⤷ Title: sams walkthrough (proving groung-windows)
════════════════════════
𐀪 Author: cyber_public_school
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:28:49 GMT
════════════════════════
⌗ Tags: #cve #cybersecurity #information_security #oscp #ethical_hacking
════════════════════════
𐀪 Author: cyber_public_school
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:28:49 GMT
════════════════════════
⌗ Tags: #cve #cybersecurity #information_security #oscp #ethical_hacking
Medium
🔥 sams walkthrough (proving groung-windows)
By cyber_public_school | Cyber Security Researcher
⤷ Title: Under Active Attack: Critical 9.8 CVSS Tutor LMS Pro Flaw Exploited in the Wild for Full Site Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:40:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_0953 #cybersecurity #exploited in the wild #infosec #Patch Alert #Social Login Flaw #Tutor LMS Pro #Vulnerability #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:40:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_0953 #cybersecurity #exploited in the wild #infosec #Patch Alert #Social Login Flaw #Tutor LMS Pro #Vulnerability #wordpress security
Daily CyberSecurity
Under Active Attack: Critical 9.8 CVSS Tutor LMS Pro Flaw Exploited in the Wild for Full Site Takeover
A critical 9.8 CVSS authentication bypass (CVE-2026-0953) in Tutor LMS Pro is being actively exploited in the wild. Update to version 3.9.6 immediately.
⤷ Title: Home Network Alert: TP-Link Patches RCE Vulnerability in Archer AXE75 Routers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:33:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer AXE75 #Command Injection #CVE_2025_15568 #cybersecurity #infosec #Patch Alert #rce #router security #TP_Link #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:33:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer AXE75 #Command Injection #CVE_2025_15568 #cybersecurity #infosec #Patch Alert #rce #router security #TP_Link #Vulnerability
Daily CyberSecurity
Home Network Alert: TP-Link Patches RCE Vulnerability in Archer AXE75 Routers
A critical 8.5 CVSS command injection flaw (CVE-2025-15568) in TP-Link Archer AXE75 routers allows complete root-level network takeover. Patch immediately.
⤷ Title: Kubernetes Security Alert: “Ingress-Nginx” Injection Flaw Risks Cluster-Wide Secret Exposure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:23:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #container security #CVE_2026_3288 #Data Leakage #infosec #ingress_nginx #Kubernetes Security #nginx #Patch Alert #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:23:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #container security #CVE_2026_3288 #Data Leakage #infosec #ingress_nginx #Kubernetes Security #nginx #Patch Alert #Vulnerability
Daily CyberSecurity
Kubernetes Security Alert: "Ingress-Nginx" Injection Flaw Risks Cluster-Wide Secret Exposure
A high 8.8 CVSS flaw (CVE-2026-3288) in ingress-nginx allows arbitrary code execution and massive Kubernetes secret leakage. Patch immediately.
⤷ Title: CVE-2026-0866: Malformed ZIP Headers Allow Malware to Slip Past EDR Scanners
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:15:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Antivirus Evasion #CVE_2026_0866 #cybersecurity #EDR Bypass #False Negatives #infosec #Malware Analysis #Shadow Archives #threat intelligence #ZIP Metadata
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:15:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Antivirus Evasion #CVE_2026_0866 #cybersecurity #EDR Bypass #False Negatives #infosec #Malware Analysis #Shadow Archives #threat intelligence #ZIP Metadata
Daily CyberSecurity
CVE-2026-0866: Malformed ZIP Headers Allow Malware to Slip Past EDR Scanners
Discover how attackers use shadow archives (CVE-2026-0866) to bypass AV and EDR by malforming ZIP metadata, keeping malware hidden but executable.
⤷ Title: A Practical Web Pentesting CTF Challenge — Step-by-Step Walkthrough
════════════════════════
𐀪 Author: cryptoshant
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:47:30 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #hacking #ctf #bug_bounty
════════════════════════
𐀪 Author: cryptoshant
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:47:30 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #hacking #ctf #bug_bounty
Medium
A Practical Web Pentesting CTF Challenge — Step-by-Step Walkthrough
Hello everyone, I hope you are doing well and having a wonderful day. Today in this writeup I am going to give you an comprehensive…
⤷ Title: Log Analysis with SIEM (THM) Tryhackme WriteUp
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:37:17 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #tryhackme #siem #log_analysis
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 02:37:17 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #tryhackme #siem #log_analysis
Medium
Log Analysis with SIEM (THM) Tryhackme WriteUp
Description : Learn how SIEM solutions can be used to detect and analyse malicious behaviour.