⤷ Title: Tryhackme AD: Basic Enumeration Write-Up
════════════════════════
𐀪 Author: Harmonax
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 20:52:56 GMT
════════════════════════
⌗ Tags: #active_directory #red_team #microsoft #pentesting #tryhackme
════════════════════════
𐀪 Author: Harmonax
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 20:52:56 GMT
════════════════════════
⌗ Tags: #active_directory #red_team #microsoft #pentesting #tryhackme
Medium
Tryhackme AD: Basic Enumeration Write-Up
Enumerasi Active Directory (AD) adalah langkah krusial awal dalam melakukan penetration testing pada jaringan enterprise Microsoft Windows…
⤷ Title: Cal AI, New Owner of MyFitnessPal, Hit by Alleged Breach of 3 Million Users
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:58:59 +0000
════════════════════════
⌗ Tags: #Data Breaches #AI #BreachForums #Cal AI #Cyber Attack #Cybersecurity #data breach #Fitness #MyFitnessPal #Vibecodelegend
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:58:59 +0000
════════════════════════
⌗ Tags: #Data Breaches #AI #BreachForums #Cal AI #Cyber Attack #Cybersecurity #data breach #Fitness #MyFitnessPal #Vibecodelegend
Hackread
Cal AI, New Owner of MyFitnessPal, Hit by Alleged Breach of 3 Million Users
Cal AI faces data breach claims after hackers post alleged data of 3 million users, including emails, health details, and subscriptions.
⤷ Title: Lab: Reflected XSS into HTML context with most tags and attributes blocked
════════════════════════
𐀪 Author: mayhack
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:23:24 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #xss_attack #hacking #bug_bounty
════════════════════════
𐀪 Author: mayhack
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:23:24 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #xss_attack #hacking #bug_bounty
Medium
Lab: Reflected XSS into HTML context with most tags and attributes blocked
Challenge Overview
⤷ Title: The Global Advanced Persistent Threat (APT) Landscape: Strategic Evolution, Taxonomic Mapping, and…
════════════════════════
𐀪 Author: Mr_MalMan
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:41:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #war #apt #malware
════════════════════════
𐀪 Author: Mr_MalMan
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:41:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #war #apt #malware
Medium
The Global Advanced Persistent Threat (APT) Landscape: Strategic Evolution, Taxonomic Mapping, and…
The global cyber threat landscape has reached a critical inflection point, fundamentally altered by the unprecedented velocity of threat…
⤷ Title: Layered Polymorphic String Encryption
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:32:31 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #malware #red_team #cybersecurity
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:32:31 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #malware #red_team #cybersecurity
Medium
Layered Polymorphic String Encryption
Welcome to this new Medium post! Today, we are talking about a smart way to hide important text inside your implants that I just saw in the…
⤷ Title: From Zero to Domain Admin: Compromising Active Directory in Attacktive Directory (TryHackMe)
════════════════════════
𐀪 Author: razzee
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:38:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme #ethical_hacking #active_directory #cybersecurity
════════════════════════
𐀪 Author: razzee
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:38:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme #ethical_hacking #active_directory #cybersecurity
Medium
From Zero to Domain Admin: Compromising Active Directory in Attacktive Directory (TryHackMe)
Active Directory environments are one of the most common targets during internal network penetration testing. Misconfigurations in…
⤷ Title: HTB Arctic: Remote Command Execution to JuicyPotato Privesc
════════════════════════
𐀪 Author: Onurcan Genç
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:31:06 GMT
════════════════════════
⌗ Tags: #privilege_escalation #cybersecurity #penetration_testing #hackthebox #capture_the_flag
════════════════════════
𐀪 Author: Onurcan Genç
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:31:06 GMT
════════════════════════
⌗ Tags: #privilege_escalation #cybersecurity #penetration_testing #hackthebox #capture_the_flag
Medium
HTB Arctic: Remote Command Execution to JuicyPotato Privesc
Conduct a full port scan via nmap:
⤷ Title: Advanced XPath Injection Guide (Authentication Bypass → Data Exfiltration → Blind Extraction)
════════════════════════
𐀪 Author: Raman Gautam | rghx
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:20:05 GMT
════════════════════════
⌗ Tags: #web_development #xpath #cybersecurity #security #penetration_testing
════════════════════════
𐀪 Author: Raman Gautam | rghx
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:20:05 GMT
════════════════════════
⌗ Tags: #web_development #xpath #cybersecurity #security #penetration_testing
Medium
Advanced XPath Injection Guide (Authentication Bypass → Data Exfiltration → Blind Extraction)
👋 Hi everyone! I’m back again with another deep dive into web application security.
⤷ Title: I Switched Sides: What It’s Like Investigating an Attack Instead of Running One
════════════════════════
𐀪 Author: Robert Perez
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:16:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #penetration_testing #blue_team #splunk
════════════════════════
𐀪 Author: Robert Perez
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:16:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #penetration_testing #blue_team #splunk
Medium
I Switched Sides: What It’s Like Investigating an Attack Instead of Running One
Most of my labs so far have been offensive. I’ve brute-forced logins, exploited web applications, replaced binaries in writable…
⤷ Title: Abusing AD-DACL: GenericWrite
════════════════════════
𐀪 Author: Youssef Said Thabet
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:14:15 GMT
════════════════════════
⌗ Tags: #active_directory_attack #active_directory #dacl #penetration_testing
════════════════════════
𐀪 Author: Youssef Said Thabet
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:14:15 GMT
════════════════════════
⌗ Tags: #active_directory_attack #active_directory #dacl #penetration_testing
Medium
Abusing AD-DACL: GenericWrite
The GenericWrite permission in Active Directory allows a user to modify all writable attributes of an object, except for properties that…
⤷ Title: TryHackMe Writeup: Active Directory Basic Enumeration (Jr-Pentester AD v01)
════════════════════════
𐀪 Author: Nazwass
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:52:37 GMT
════════════════════════
⌗ Tags: #tryhackme #enumeration #tryhackme_writeup #cybersecurity #tryhackme_walkthrough
════════════════════════
𐀪 Author: Nazwass
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:52:37 GMT
════════════════════════
⌗ Tags: #tryhackme #enumeration #tryhackme_writeup #cybersecurity #tryhackme_walkthrough
Medium
TryHackMe Writeup: Active Directory Basic Enumeration (Jr-Pentester AD v01)
Task 1
⤷ Title: Lab: SQL injection UNION attack, retrieving data from other tables
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:59:12 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #sql_injection #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:59:12 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #sql_injection #ethical_hacking #cybersecurity
Medium
Lab: SQL injection UNION attack, retrieving data from other tables
Bu yazıda PortSwigger Web Security Academy’nin “SQL injection UNION attack, retrieving data from other tables” adlı labını nasıl çözdüğümü…
⤷ Title: Maximum 10.0 CVSS Flaws in OneUptime Allow Full Account Takeovers and RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:41:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_30956 #CVE_2026_30957 #cybersecurity #infosec #OneUptime #Playwright #rce #Remote Code Execution #Tenant Isolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:41:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_30956 #CVE_2026_30957 #cybersecurity #infosec #OneUptime #Playwright #rce #Remote Code Execution #Tenant Isolation
Daily CyberSecurity
Maximum 10.0 CVSS Flaws in OneUptime Allow Full Account Takeovers and RCE
Two critical 10.0 CVSS flaws (CVE-2026-30956, CVE-2026-30957) in OneUptime allow full account takeovers and Server-Side RCE. Update to 10.0.21 immediately.
⤷ Title: Malicious npm Package “pino-sdk-v2” Caught Harvesting Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DevSecOps #Discord Webhook Exfiltration #infosec #Malware Analysis #Node.js Security #npm Supply Chain Attack #pino_sdk_v2 #SafeDep #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DevSecOps #Discord Webhook Exfiltration #infosec #Malware Analysis #Node.js Security #npm Supply Chain Attack #pino_sdk_v2 #SafeDep #Typosquatting
Daily CyberSecurity
Malicious npm Package "pino-sdk-v2" Caught Harvesting Secrets
SafeDep uncovers pino-sdk-v2, a malicious npm package impersonating the pino logger to silently steal .env secrets and exfiltrate them via Discord.
⤷ Title: APT-C-23 Weaponized Israel’s ‘Red Alert’ App for Mobile Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:33:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Android Malware #APT_C_23 #Arid Viper #cybersecurity #infosec #Mobile Espionage #Red Alert Trojan #threat intelligence #Trojanized App
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:33:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Android Malware #APT_C_23 #Arid Viper #cybersecurity #infosec #Mobile Espionage #Red Alert Trojan #threat intelligence #Trojanized App
Daily CyberSecurity
APT-C-23 Weaponized Israel's 'Red Alert' App for Mobile Espionage
Acronis TRU uncovers a trojanized Red Alert rocket warning app targeting Israelis. Linked to APT-C-23, this Android malware steals data while alerting users.
⤷ Title: Microsoft Exposes How Hackers Use Generative Models as a Force Multiplier
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:26:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Memory Poisoning #Cyber Security #Generative AI #infosec #Malicious AI #Microsoft Threat Intelligence #North Korean APT #Prompt injection #social engineering #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:26:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Memory Poisoning #Cyber Security #Generative AI #infosec #Malicious AI #Microsoft Threat Intelligence #North Korean APT #Prompt injection #social engineering #threat intelligence
Daily CyberSecurity
Microsoft Exposes How Hackers Use Generative Models as a Force Multiplier
Microsoft Threat Intelligence reveals how cybercriminals and North Korean APTs are weaponizing generative AI to scale attacks and poison AI assistants.
⤷ Title: The Vibe-Coding Trap: Fake Claude Code Installers Unleash Amatera Malware via Search Ads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:21:33 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Malware #Claude Code #CLI Security #cybersecurity #DevSecOps #info_stealer #infosec #InstallFix #Malvertising #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:21:33 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Malware #Claude Code #CLI Security #cybersecurity #DevSecOps #info_stealer #infosec #InstallFix #Malvertising #threat intelligence
Daily CyberSecurity
The Vibe-Coding Trap: Fake Claude Code Installers Unleash Amatera Malware via Search Ads
Hackers are targeting AI developers with a fake Claude Code "InstallFix" malvertising campaign, using malicious terminal commands to drop Amatera malware.
⤷ Title: Zscaler Uncovers 8,000+ Domains and APT Backdoors Exploiting Middle East Tensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:18:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Geopolitical Threats #infosec #LOTUSLITE Backdoor #Middle East Cyber Threats #Mustang Panda #phishing scams #StealC malware #threat intelligence #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:18:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Geopolitical Threats #infosec #LOTUSLITE Backdoor #Middle East Cyber Threats #Mustang Panda #phishing scams #StealC malware #threat intelligence #Zscaler ThreatLabz
Daily CyberSecurity
Zscaler Uncovers 8,000+ Domains and APT Backdoors Exploiting Middle East Tensions
Zscaler ThreatLabz reveals a surge in Middle East conflict-themed cyberattacks, uncovering 8,000+ malicious domains, LOTUSLITE backdoors, and scams.
⤷ Title: North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:12:27 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cybersecurity #DEV#POPPER #eSentire TRU #GitHub Malware #infosec #North Korean APT #OmniStealer #Remote Access Trojan #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:12:27 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cybersecurity #DEV#POPPER #eSentire TRU #GitHub Malware #infosec #North Korean APT #OmniStealer #Remote Access Trojan #supply chain attack
Daily CyberSecurity
North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
eSentire exposes DEV#POPPER, a North Korean RAT hiding in GitHub repos. It uses blockchain to deploy OmniStealer, targeting crypto and dev secrets.
⤷ Title: CL-UNK-1068: The Stealthy Chinese Threat Actor Haunting Asian Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:08:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese APT #CL_UNK_1068 #cyber_espionage #cybersecurity #data exfiltration #GodZilla Web Shell #infosec #LOLBins #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:08:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese APT #CL_UNK_1068 #cyber_espionage #cybersecurity #data exfiltration #GodZilla Web Shell #infosec #LOLBins #threat intelligence #Unit 42
Daily CyberSecurity
CL-UNK-1068: The Stealthy Chinese Threat Actor Haunting Asian Infrastructure
Unit 42 uncovers CL-UNK-1068, a Chinese APT targeting Asian critical infrastructure using stealthy web shells, LOLBINs, and screen-printed exfiltration.
⤷ Title: Critical RCE Vulnerabilities Uncovered in Janitza and Weidmueller Energy Meters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:02:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_41709 #cybersecurity #Energy Meters #firmware update #ICS security #Janitza #rce #SCADA #Weidmueller
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:02:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_41709 #cybersecurity #Energy Meters #firmware update #ICS security #Janitza #rce #SCADA #Weidmueller
Daily CyberSecurity
Critical RCE Vulnerabilities Uncovered in Janitza and Weidmueller Energy Meters
Critical flaws (CVE-2025-41709) in Janitza and Weidmueller energy meters allow remote code execution and full system takeover. Update to firmware 3.14 now.