⤷ Title: Abusing AD-DACL: AddSelf
════════════════════════
𐀪 Author: Youssef Said Thabet
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:16:49 GMT
════════════════════════
⌗ Tags: #active_directory #red_teaming #active_directory_attack #active_directory_security #penetration_testing
════════════════════════
𐀪 Author: Youssef Said Thabet
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:16:49 GMT
════════════════════════
⌗ Tags: #active_directory #red_teaming #active_directory_attack #active_directory_security #penetration_testing
Medium
Abusing AD-DACL: AddSelf
The AddSelf permission in Active Directory allows users to add themselves to the target security group. Because of security group…
⤷ Title: Break it — TryHackMe Writeup
════════════════════════
𐀪 Author: Riad Moudjahed
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:58:05 GMT
════════════════════════
⌗ Tags: #cryptography #decryption #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Riad Moudjahed
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:58:05 GMT
════════════════════════
⌗ Tags: #cryptography #decryption #cybersecurity #tryhackme
Medium
Break it — TryHackMe Writeup
Task 1: Bases
⤷ Title: Exploiting an SSRF Vulnerability to Retrieve the Server Hostname-Hackviser Lab
════════════════════════
𐀪 Author: Manohar T H
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:27:02 GMT
════════════════════════
⌗ Tags: #ssrf_vulnerability #ssrf #labs #ssrf_walkthrough #hackviser
════════════════════════
𐀪 Author: Manohar T H
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:27:02 GMT
════════════════════════
⌗ Tags: #ssrf_vulnerability #ssrf #labs #ssrf_walkthrough #hackviser
Medium
Exploiting an SSRF Vulnerability to Retrieve the Server Hostname-Hackviser Lab
Server-Side Request Forgery (SSRF) is a common and dangerous web vulnerability that allows an attacker to make the server perform…
⤷ Title: The ‘Must-Patch’ Release: WordPress 6.9.2 Scrambles to Fix 10 Critical Flaws from XSS to SSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 03:58:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CMS Security #cybersecurity #infosec #Patch Alert #Path Traversal #ssrf #vulnerability management #WordPress 6.9.2 #wordpress security #XSS Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 03:58:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CMS Security #cybersecurity #infosec #Patch Alert #Path Traversal #ssrf #vulnerability management #WordPress 6.9.2 #wordpress security #XSS Vulnerability
Daily CyberSecurity
The 'Must-Patch' Release: WordPress 6.9.2 Scrambles to Fix 10 Critical Flaws from XSS to SSRF
Urgent: WordPress 6.9.2 patches 10 critical security flaws, including XSS, SSRF, and path traversal. Update your site immediately to prevent exploitation.
⤷ Title: High-Severity SQL Injection in Ally WordPress Plugin Threatens 400K Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 03:03:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Ally Plugin #CVE_2026_2413 #database security #infosec #Patch Alert #sql injection #Time_Based SQLi #Vulnerability #Wordfence #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 03:03:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Ally Plugin #CVE_2026_2413 #database security #infosec #Patch Alert #sql injection #Time_Based SQLi #Vulnerability #Wordfence #wordpress security
Daily CyberSecurity
High-Severity SQL Injection in Ally WordPress Plugin Threatens 400K Sites
A critical SQL injection flaw (CVE-2026-2413) in the Ally WordPress plugin exposes 400K+ sites to database theft. Update to version 4.1.0 immediately.
⤷ Title: The Default Danger: Maximum 10.0 CVSS Vulnerability Leaves Honeywell IQ4x Controllers Wide Open
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BMS Security #building management system #CVE_2026_3611 #CVSS 10.0 #cybersecurity #Honeywell IQ4x #ICS security #infosec #unauthenticated access #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BMS Security #building management system #CVE_2026_3611 #CVSS 10.0 #cybersecurity #Honeywell IQ4x #ICS security #infosec #unauthenticated access #Vulnerability
Daily CyberSecurity
The Default Danger: Maximum 10.0 CVSS Vulnerability Leaves Honeywell IQ4x Controllers Wide Open
A critical 10.0 CVSS flaw (CVE-2026-3611) in Honeywell IQ4x BMS controllers leaves web HMIs exposed without authentication. Secure your systems immediately.
⤷ Title: Industrial Alert: Critical Stored XSS Vulnerability Discovered in Siemens SIMATIC S7-1500
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:05:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2025_40943 #ICS security #Industrial Automation Security #Manufacturing Security #Patch Alert #SCADA Security #Siemens SIMATIC #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 02:05:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2025_40943 #ICS security #Industrial Automation Security #Manufacturing Security #Patch Alert #SCADA Security #Siemens SIMATIC #Vulnerability #XSS
Daily CyberSecurity
Industrial Alert: Critical Stored XSS Vulnerability Discovered in Siemens SIMATIC S7-1500
A critical 9.6 CVSS XSS vulnerability (CVE-2025-40943) in Siemens SIMATIC S7-1500 CPUs allows attackers to inject malicious code via trace files.
⤷ Title: Microsoft Patch Tuesday March 2026: 93 Vulnerabilities Addressed, Including Two Zero-Days
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:48:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET Vulnerability #CVE_2026_21262 #CVE_2026_26127 #cybersecurity #infosec #Microsoft Patch Tuesday #Patch Alert #sql server #vulnerability management #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 01:48:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET Vulnerability #CVE_2026_21262 #CVE_2026_26127 #cybersecurity #infosec #Microsoft Patch Tuesday #Patch Alert #sql server #vulnerability management #zero_day
Daily CyberSecurity
Microsoft Patch Tuesday March 2026: 93 Vulnerabilities Addressed, Including Two Zero-Days
Microsoft's March 2026 Patch Tuesday addresses 93 vulnerabilities, including two public zero-days affecting SQL Server and .NET. Patch your systems now.
⤷ Title: PostMessage Misconfiguration + AI Prompt Injection + Sandbox Escape = XSS & Data Exfiltration
════════════════════════
𐀪 Author: SJ_Source_Sink
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:40:29 GMT
════════════════════════
⌗ Tags: #penetration_testing #prompt_injection_attack #bug_bounty #genai #bug_bounty_tips
════════════════════════
𐀪 Author: SJ_Source_Sink
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:40:29 GMT
════════════════════════
⌗ Tags: #penetration_testing #prompt_injection_attack #bug_bounty #genai #bug_bounty_tips
Medium
PostMessage Misconfiguration + AI Prompt Injection + Sandbox Escape = XSS & Data Exfiltration
When three individually medium-severity issues chain together to compromise an AI assistant platform.
⤷ Title: ️Turning Directory Data into Domain Access
════════════════════════
𐀪 Author: Jabaribrown
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:40:16 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #hacking #ctf #bug_bounty
════════════════════════
𐀪 Author: Jabaribrown
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:40:16 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #hacking #ctf #bug_bounty
Medium
💻🕷️Turning Directory Data into Domain Access
Continuing my mastery of the AD journey.
⤷ Title: XSS Bypass to Zero Click Account Takeover in AI Chatbot
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:37:08 GMT
════════════════════════
⌗ Tags: #report #bug_bounty #llm #cybersecurity #xss_attack
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:37:08 GMT
════════════════════════
⌗ Tags: #report #bug_bounty #llm #cybersecurity #xss_attack
Medium
XSS Bypass to Zero Click Account Takeover in AI Chatbot
Hi everyone, in this article, I’ll walk through a recent penetration test I conducted against a custom-built AI chatbot. As usual, we’ll…
⤷ Title: Citrix Bleed: How a Single Bug Leaked Corporate Secrets (CVE-2023–4966)
════════════════════════
𐀪 Author: Krishna Kumar
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:36:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #cybersecurity #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Krishna Kumar
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:36:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hacking #cybersecurity #bug_bounty_tips #bug_bounty
Medium
🩸 Citrix Bleed: How a Single Bug Leaked Corporate Secrets (CVE-2023–4966)
TL;DR — The Juicy Bits
⤷ Title: Zomato Privacy Flaw: How the ‘Friend Recommendations’ Feature Enables Location Stalking
════════════════════════
𐀪 Author: Jatin Banga
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:35:50 GMT
════════════════════════
⌗ Tags: #osint #cybersecurity #bug_bounty #bug_bounty_writeup #privacy
════════════════════════
𐀪 Author: Jatin Banga
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:35:50 GMT
════════════════════════
⌗ Tags: #osint #cybersecurity #bug_bounty #bug_bounty_writeup #privacy
Medium
Zomato Privacy Flaw: How the ‘Friend Recommendations’ Feature Enables Location Stalking
TL;DR: Zomato’s “Friend Recommendations” API allows unilateral contact syncing. By uploading a phone number, bad actors can extract a…
⤷ Title: I Found a Bug That Exposed Private Instagram Posts to Anyone.
════════════════════════
𐀪 Author: Jatin Banga
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:22:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #privacy #cybersecurity #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Jatin Banga
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:22:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #privacy #cybersecurity #penetration_testing #bug_bounty
Medium
I Found a Bug That Exposed Private Instagram Posts to Anyone.
In October 2025, I discovered a server-side vulnerability in Instagram that allowed completely unauthenticated access to private account…
⤷ Title: Chaining the Boredom: How a Quiet Weekday Led to a Full Database Heist
════════════════════════
𐀪 Author: k3rnelpan1c
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:18:40 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #bug_bounty #cybersecurity #tryhackme
════════════════════════
𐀪 Author: k3rnelpan1c
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:18:40 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #bug_bounty #cybersecurity #tryhackme
Medium
Chaining the Boredom: How a Quiet Weekday Led to a Full Database Heist
A ValenFind Walkthrough: Why “low” vulnerabilities are the key to Red Team success.
⤷ Title: Hackviser — Cryptanalysis walkthrough
════════════════════════
𐀪 Author: Mukilan Baskaran
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:17:45 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #security #ethical_hacking
════════════════════════
𐀪 Author: Mukilan Baskaran
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:17:45 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #security #ethical_hacking
Medium
Hackviser — Cryptanalysis walkthrough
CTF — Based
⤷ Title: HTTP Parameter Pollution (HPP)
════════════════════════
𐀪 Author: Lost_hacker
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:56:51 GMT
════════════════════════
⌗ Tags: #http_parameter_pollution #bugbounty_writeup #bug_bounty #parameter_pollution #hacking
════════════════════════
𐀪 Author: Lost_hacker
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:56:51 GMT
════════════════════════
⌗ Tags: #http_parameter_pollution #bugbounty_writeup #bug_bounty #parameter_pollution #hacking
Medium
HTTP Parameter Pollution (HPP)
1. Topic Overview — What, Why, Where, How, Which
⤷ Title: PostMessage Misconfiguration + AI Prompt Injection + Sandbox Escape = XSS & Data Exfiltration
════════════════════════
𐀪 Author: SJ_Source_Sink
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:40:27 GMT
════════════════════════
⌗ Tags: #penetration_testing #prompt_injection_attack #bug_bounty #genai #bug_bounty_tips
════════════════════════
𐀪 Author: SJ_Source_Sink
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:40:27 GMT
════════════════════════
⌗ Tags: #penetration_testing #prompt_injection_attack #bug_bounty #genai #bug_bounty_tips
Medium
PostMessage Misconfiguration + AI Prompt Injection + Sandbox Escape = XSS & Data Exfiltration
When three individually medium-severity issues chain together to compromise an AI assistant platform.
⤷ Title: XSS Bypass to Zero Click Account Takeover in AI Chatbot
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:37:07 GMT
════════════════════════
⌗ Tags: #report #bug_bounty #llm #cybersecurity #xss_attack
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:37:07 GMT
════════════════════════
⌗ Tags: #report #bug_bounty #llm #cybersecurity #xss_attack
Medium
XSS Bypass to Zero Click Account Takeover in AI Chatbot
Hi everyone, in this article, I’ll walk through a recent penetration test I conducted against a custom-built AI chatbot. As usual, we’ll…
⤷ Title: Chaining the Boredom: How a Quiet Weekday Led to a Full Database Heist
════════════════════════
𐀪 Author: k3rnelpan1c
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:18:38 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #bug_bounty #cybersecurity #tryhackme
════════════════════════
𐀪 Author: k3rnelpan1c
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 04:18:38 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #bug_bounty #cybersecurity #tryhackme
Medium
Chaining the Boredom: How a Quiet Weekday Led to a Full Database Heist
A ValenFind Walkthrough: Why “low” vulnerabilities are the key to Red Team success.
⤷ Title: Zero Trust for Oracle Fusion Cloud (ERP and HCM): SSO, MFA, and Conditional Access That Works in…
════════════════════════
𐀪 Author: Khader Nawaz khan
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 03:53:15 GMT
════════════════════════
⌗ Tags: #application_security #oracle #oracle_security #oracle_cloud
════════════════════════
𐀪 Author: Khader Nawaz khan
════════════════════════
ⴵ Time: Wed, 11 Mar 2026 03:53:15 GMT
════════════════════════
⌗ Tags: #application_security #oracle #oracle_security #oracle_cloud
Medium
Zero Trust for Oracle Fusion Cloud (ERP and HCM): SSO, MFA, and Conditional Access That Works in the Real World
A security practitioner guide to harden Fusion Cloud access using strong federation, risk based MFA, device and network controls, and a…