⤷ Title: Abusing AD-DACL: GenericWrite
════════════════════════
𐀪 Author: Youssef Said Thabet
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:14:15 GMT
════════════════════════
⌗ Tags: #active_directory_attack #active_directory #dacl #penetration_testing
════════════════════════
𐀪 Author: Youssef Said Thabet
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:14:15 GMT
════════════════════════
⌗ Tags: #active_directory_attack #active_directory #dacl #penetration_testing
Medium
Abusing AD-DACL: GenericWrite
The GenericWrite permission in Active Directory allows a user to modify all writable attributes of an object, except for properties that…
⤷ Title: TryHackMe Writeup: Active Directory Basic Enumeration (Jr-Pentester AD v01)
════════════════════════
𐀪 Author: Nazwass
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:52:37 GMT
════════════════════════
⌗ Tags: #tryhackme #enumeration #tryhackme_writeup #cybersecurity #tryhackme_walkthrough
════════════════════════
𐀪 Author: Nazwass
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 21:52:37 GMT
════════════════════════
⌗ Tags: #tryhackme #enumeration #tryhackme_writeup #cybersecurity #tryhackme_walkthrough
Medium
TryHackMe Writeup: Active Directory Basic Enumeration (Jr-Pentester AD v01)
Task 1
⤷ Title: Lab: SQL injection UNION attack, retrieving data from other tables
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:59:12 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #sql_injection #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:59:12 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #sql_injection #ethical_hacking #cybersecurity
Medium
Lab: SQL injection UNION attack, retrieving data from other tables
Bu yazıda PortSwigger Web Security Academy’nin “SQL injection UNION attack, retrieving data from other tables” adlı labını nasıl çözdüğümü…
⤷ Title: Maximum 10.0 CVSS Flaws in OneUptime Allow Full Account Takeovers and RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:41:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_30956 #CVE_2026_30957 #cybersecurity #infosec #OneUptime #Playwright #rce #Remote Code Execution #Tenant Isolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:41:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_30956 #CVE_2026_30957 #cybersecurity #infosec #OneUptime #Playwright #rce #Remote Code Execution #Tenant Isolation
Daily CyberSecurity
Maximum 10.0 CVSS Flaws in OneUptime Allow Full Account Takeovers and RCE
Two critical 10.0 CVSS flaws (CVE-2026-30956, CVE-2026-30957) in OneUptime allow full account takeovers and Server-Side RCE. Update to 10.0.21 immediately.
⤷ Title: Malicious npm Package “pino-sdk-v2” Caught Harvesting Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DevSecOps #Discord Webhook Exfiltration #infosec #Malware Analysis #Node.js Security #npm Supply Chain Attack #pino_sdk_v2 #SafeDep #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DevSecOps #Discord Webhook Exfiltration #infosec #Malware Analysis #Node.js Security #npm Supply Chain Attack #pino_sdk_v2 #SafeDep #Typosquatting
Daily CyberSecurity
Malicious npm Package "pino-sdk-v2" Caught Harvesting Secrets
SafeDep uncovers pino-sdk-v2, a malicious npm package impersonating the pino logger to silently steal .env secrets and exfiltrate them via Discord.
⤷ Title: APT-C-23 Weaponized Israel’s ‘Red Alert’ App for Mobile Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:33:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Android Malware #APT_C_23 #Arid Viper #cybersecurity #infosec #Mobile Espionage #Red Alert Trojan #threat intelligence #Trojanized App
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:33:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Android Malware #APT_C_23 #Arid Viper #cybersecurity #infosec #Mobile Espionage #Red Alert Trojan #threat intelligence #Trojanized App
Daily CyberSecurity
APT-C-23 Weaponized Israel's 'Red Alert' App for Mobile Espionage
Acronis TRU uncovers a trojanized Red Alert rocket warning app targeting Israelis. Linked to APT-C-23, this Android malware steals data while alerting users.
⤷ Title: Microsoft Exposes How Hackers Use Generative Models as a Force Multiplier
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:26:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Memory Poisoning #Cyber Security #Generative AI #infosec #Malicious AI #Microsoft Threat Intelligence #North Korean APT #Prompt injection #social engineering #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:26:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Memory Poisoning #Cyber Security #Generative AI #infosec #Malicious AI #Microsoft Threat Intelligence #North Korean APT #Prompt injection #social engineering #threat intelligence
Daily CyberSecurity
Microsoft Exposes How Hackers Use Generative Models as a Force Multiplier
Microsoft Threat Intelligence reveals how cybercriminals and North Korean APTs are weaponizing generative AI to scale attacks and poison AI assistants.
⤷ Title: The Vibe-Coding Trap: Fake Claude Code Installers Unleash Amatera Malware via Search Ads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:21:33 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Malware #Claude Code #CLI Security #cybersecurity #DevSecOps #info_stealer #infosec #InstallFix #Malvertising #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:21:33 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Malware #Claude Code #CLI Security #cybersecurity #DevSecOps #info_stealer #infosec #InstallFix #Malvertising #threat intelligence
Daily CyberSecurity
The Vibe-Coding Trap: Fake Claude Code Installers Unleash Amatera Malware via Search Ads
Hackers are targeting AI developers with a fake Claude Code "InstallFix" malvertising campaign, using malicious terminal commands to drop Amatera malware.
⤷ Title: Zscaler Uncovers 8,000+ Domains and APT Backdoors Exploiting Middle East Tensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:18:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Geopolitical Threats #infosec #LOTUSLITE Backdoor #Middle East Cyber Threats #Mustang Panda #phishing scams #StealC malware #threat intelligence #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:18:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Geopolitical Threats #infosec #LOTUSLITE Backdoor #Middle East Cyber Threats #Mustang Panda #phishing scams #StealC malware #threat intelligence #Zscaler ThreatLabz
Daily CyberSecurity
Zscaler Uncovers 8,000+ Domains and APT Backdoors Exploiting Middle East Tensions
Zscaler ThreatLabz reveals a surge in Middle East conflict-themed cyberattacks, uncovering 8,000+ malicious domains, LOTUSLITE backdoors, and scams.
⤷ Title: North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:12:27 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cybersecurity #DEV#POPPER #eSentire TRU #GitHub Malware #infosec #North Korean APT #OmniStealer #Remote Access Trojan #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:12:27 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #cybersecurity #DEV#POPPER #eSentire TRU #GitHub Malware #infosec #North Korean APT #OmniStealer #Remote Access Trojan #supply chain attack
Daily CyberSecurity
North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
eSentire exposes DEV#POPPER, a North Korean RAT hiding in GitHub repos. It uses blockchain to deploy OmniStealer, targeting crypto and dev secrets.
⤷ Title: CL-UNK-1068: The Stealthy Chinese Threat Actor Haunting Asian Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:08:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese APT #CL_UNK_1068 #cyber_espionage #cybersecurity #data exfiltration #GodZilla Web Shell #infosec #LOLBins #threat intelligence #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:08:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese APT #CL_UNK_1068 #cyber_espionage #cybersecurity #data exfiltration #GodZilla Web Shell #infosec #LOLBins #threat intelligence #Unit 42
Daily CyberSecurity
CL-UNK-1068: The Stealthy Chinese Threat Actor Haunting Asian Infrastructure
Unit 42 uncovers CL-UNK-1068, a Chinese APT targeting Asian critical infrastructure using stealthy web shells, LOLBINs, and screen-printed exfiltration.
⤷ Title: Critical RCE Vulnerabilities Uncovered in Janitza and Weidmueller Energy Meters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:02:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_41709 #cybersecurity #Energy Meters #firmware update #ICS security #Janitza #rce #SCADA #Weidmueller
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:02:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_41709 #cybersecurity #Energy Meters #firmware update #ICS security #Janitza #rce #SCADA #Weidmueller
Daily CyberSecurity
Critical RCE Vulnerabilities Uncovered in Janitza and Weidmueller Energy Meters
Critical flaws (CVE-2025-41709) in Janitza and Weidmueller energy meters allow remote code execution and full system takeover. Update to firmware 3.14 now.
⤷ Title: XXE Injection Guide: Fundamentals, Payloads, and Bug Bounty Strategies
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #cybersecurity #penetration_testing #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #cybersecurity #penetration_testing #hacking
Medium
XXE Injection Guide: Fundamentals, Payloads, and Bug Bounty Strategies
Learn what XXE is, how to detect it, and the best payloads for file reading, SSRF, and OOB attacks in security audits.
⤷ Title: Information Gathering in Web Pentesting — Solving INE “Information Gathering CTF 1”
════════════════════════
𐀪 Author: Amitishacked
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:51:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #information_security #hacking #security
════════════════════════
𐀪 Author: Amitishacked
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 22:51:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #information_security #hacking #security
Medium
Information Gathering in Web Pentesting — Solving INE “Information Gathering CTF 1”
Before you attack, you observe. Before you exploit, you enumerate. This is how information gathering wins CTFs — and real engagements.”
⤷ Title: Full Agenda Now Available for “CVE/FIRST VulnCon 2026” on April 13–16, 2026!
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 23:14:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability #cyber_security_awareness #information_security #infosec
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 23:14:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability #cyber_security_awareness #information_security #infosec
Medium
Full Agenda Now Available for “CVE/FIRST VulnCon 2026” on April 13–16, 2026!
The CVE Program and FIRST will co-host VulnCon 2026 at the DoubleTree Resort by Hilton Hotel Paradise Valley — Scottsdale, in Scottsdale…
⤷ Title: The Danger of Over-Permissive File Shares
════════════════════════
𐀪 Author: Jabaribrown
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:57:03 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #hacking #penetration_testing #bug_bounty_writeup
════════════════════════
𐀪 Author: Jabaribrown
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 00:57:03 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #hacking #penetration_testing #bug_bounty_writeup
Medium
📁The Danger of Over-Permissive File Shares
Another box, another hack. This time we’re making our way through Hack The Box machine Escape. Let’s see where this one takes us.
⤷ Title: HackTheBox CCTV Walkthrough – SQL Injection to Root via motionEye Command Injection
════════════════════════
𐀪 Author: Ndkmakka
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 23:39:03 GMT
════════════════════════
⌗ Tags: #ethical_hacking #sql_injection #penetration_testing #hackthebox #cybersecurity
════════════════════════
𐀪 Author: Ndkmakka
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 23:39:03 GMT
════════════════════════
⌗ Tags: #ethical_hacking #sql_injection #penetration_testing #hackthebox #cybersecurity
Medium
HackTheBox CCTV Walkthrough – SQL Injection to Root via motionEye Command Injection
HackTheBox CCTV (SecureVision) – Complete Walkthrough
⤷ Title: You Don’t Need a Threat Hunting Lab — If You’re a SOC Analyst, Your Environment Is Already One
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:30:51 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking #threat_hunting #soc
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:30:51 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking #threat_hunting #soc
Medium
You Don’t Need a Threat Hunting Lab — If You’re a SOC Analyst, Your Environment Is Already One
A lot of SOC analysts want to learn threat hunting.
⤷ Title: When gets() Gets You in Trouble
════════════════════════
𐀪 Author: Systemic
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:56:13 GMT
════════════════════════
⌗ Tags: #application_security #hacking #cybersecurity #technology #programming
════════════════════════
𐀪 Author: Systemic
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:56:13 GMT
════════════════════════
⌗ Tags: #application_security #hacking #cybersecurity #technology #programming
Medium
When gets() Gets You in Trouble
In my previous article, I showed you how easy it is to hijack a human brain. This time, I’ll show you that your computers are just as…
⤷ Title: Building a SOC Detection Engineering Lab with Elastic, Mythic C2, and Attack Simulations
════════════════════════
𐀪 Author: Gregory Dawson
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:51:13 GMT
════════════════════════
⌗ Tags: #security_engineering #hacking #elasticsearch #information_security #blue_team
════════════════════════
𐀪 Author: Gregory Dawson
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:51:13 GMT
════════════════════════
⌗ Tags: #security_engineering #hacking #elasticsearch #information_security #blue_team
Medium
Building a SOC Detection Engineering Lab with Elastic, Mythic C2, and Attack Simulations
Modern security operations centers rely heavily on detection engineering — building systems that detect attacker behavior and generate…
⤷ Title: 2025 Military and Defense Industry Cyber Threat Landscape
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:13:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberattack #infosec #threat_intelligence #hacking
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:13:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberattack #infosec #threat_intelligence #hacking
Medium
2025 Military and Defense Industry Cyber Threat Landscape
This report analyzes cyber threat activities targeting the military and defense industry from January to December 2025.