⤷ Title: Unmasking Gbyte: How One Hacker Exposed the Masters of 2FA-Bypassing Stalkerware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 08:26:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA Bypass #Data Breach 2026 #Gbyte Technology #Google Password Leak #iCloud Hack #Maia Arson Crimew #MSafely #Shenzhen #SpyX #stalkerware #Xiunde Cheng
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 08:26:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA Bypass #Data Breach 2026 #Gbyte Technology #Google Password Leak #iCloud Hack #Maia Arson Crimew #MSafely #Shenzhen #SpyX #stalkerware #Xiunde Cheng
Penetration Testing Tools
Unmasking Gbyte: How One Hacker Exposed the Masters of 2FA-Bypassing Stalkerware
Investigative journalist Maia Arson Crimew disclosed in a recent blog post that in February 2024, she received a
⤷ Title: 2FA Bypass via Session Fixation — High Vulnerability in Vero 300$
════════════════════════
𐀪 Author: Hasan Khan
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 18:35:14 GMT
════════════════════════
⌗ Tags: #idor_vulnerability #bug_bounty_tips #2fa_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Hasan Khan
════════════════════════
ⴵ Time: Sun, 01 Feb 2026 18:35:14 GMT
════════════════════════
⌗ Tags: #idor_vulnerability #bug_bounty_tips #2fa_bypass #bug_bounty_writeup
Medium
2FA Bypass via Session Fixation — High Vulnerability in Vero 300$
📌 Introduction
⤷ Title: The “Go Client” Trap: Why Your RustDesk ID is Currently Under Automated Botnet Siege
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:03:24 +0000
════════════════════════
⌗ Tags: #Malware #2FA #botnet attack #cybersecurity alert 2026 #Go Client #IT security tips #Remote Access Malware #remote desktop security #RustDesk #self_hosting RustDesk #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 04:03:24 +0000
════════════════════════
⌗ Tags: #Malware #2FA #botnet attack #cybersecurity alert 2026 #Go Client #IT security tips #Remote Access Malware #remote desktop security #RustDesk #self_hosting RustDesk #social engineering
Daily CyberSecurity
The "Go Client" Trap: Why Your RustDesk ID is Currently Under Automated Botnet Siege
A massive botnet is targeting RustDesk users with fake "Go Client" connection requests. Learn how to lock down your ID and prevent unauthorized remote takeovers.
⤷ Title: 2FA Bypass via OTP Reuse Across Multiple Authentication Flows
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
════════════════════════
𐀪 Author: rootxJeet
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 06:45:31 GMT
════════════════════════
⌗ Tags: #otp_bypass #cybersecurity #2fa_bypass #bug_bounty #authentication
Medium
2FA Bypass via OTP Reuse Across Multiple Authentication Flows
Hello everyone, I’m Jeet. I used to hunt bugs regularly, but due to some personal reasons I couldn’t stay consistent for a while. Now I’m…
⤷ Title: Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:36:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #CVE_2025_64111 #CVE_2025_64175 #CVE_2026_24135 #Git Service #Gogs #Patch Alert #Path Traversal #Remote Code Execution #Self_Hosted
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:36:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #CVE_2025_64111 #CVE_2025_64175 #CVE_2026_24135 #Git Service #Gogs #Patch Alert #Path Traversal #Remote Code Execution #Self_Hosted
Daily CyberSecurity
Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass
Critical Gogs flaws (CVE-2025-64111) allow RCE & 2FA bypass. Attackers can execute commands via .git config. Update to v0.13.4 immediately.
⤷ Title: 2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 11 Feb 2026 17:12:28 GMT
════════════════════════
⌗ Tags: #improper_authentication #2fa_bypass #bug_bounty_tips #otp_bypass #bug_bounty_writeup
Medium
2FA bypass after fix via manually injecting “isVerifyAuth” cookie in local storage
Hello Hackers 👋
⤷ Title: Total Mobile Dominion: The “ZeroDayRAT” Spyware Turning iPhones and Androids into Open Books
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 03:32:23 +0000
════════════════════════
⌗ Tags: #Malware #2FA Bypass #Android malware #iOS spyware #iVerify #mobile EDR #Mobile Spyware #Smishing #Tech News 2026 #Telegram malware #ZeroDayRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 03:32:23 +0000
════════════════════════
⌗ Tags: #Malware #2FA Bypass #Android malware #iOS spyware #iVerify #mobile EDR #Mobile Spyware #Smishing #Tech News 2026 #Telegram malware #ZeroDayRAT
Penetration Testing Tools
Total Mobile Dominion: The "ZeroDayRAT" Spyware Turning iPhones and Androids into Open Books
Security analysts at iVerify have unearthed a nascent mobile espionage platform dubbed ZeroDayRAT within public Telegram channels. The
⤷ Title: “CL Suite” Deception: Malicious Chrome Extension Steals 2FA Secrets and Meta Business Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #2FA Theft #Account Takeover #CL Suite #Cyber Security #Facebook Business #Instagram Business #Malicious Chrome Extension #Meta Business Suite #Socket Threat Research #TOTP Seeds
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #2FA Theft #Account Takeover #CL Suite #Cyber Security #Facebook Business #Instagram Business #Malicious Chrome Extension #Meta Business Suite #Socket Threat Research #TOTP Seeds
Daily CyberSecurity
"CL Suite" Deception: Malicious Chrome Extension Steals 2FA Secrets and Meta Business Data
"CL Suite" Chrome extension steals Meta Business 2FA seeds & data. Attackers bypass security even after uninstall. Reset 2FA immediately.
⤷ Title: Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 12:53:20 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Phishing Scam #Security #2FA #Cybersecurity #Europol #Fraud #MFA #Phishing #Scam #Tycoon 2FA
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 12:53:20 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Phishing Scam #Security #2FA #Cybersecurity #Europol #Fraud #MFA #Phishing #Scam #Tycoon 2FA
Hackread
Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA
Follow us on all social media platforms @Hackread
⤷ Title: How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt
════════════════════════
𐀪 Author: Lokesh Soni
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 09:01:09 GMT
════════════════════════
⌗ Tags: #2fa #ethicle_hacking #web_security_testing #hacking #2fa_bypass
════════════════════════
𐀪 Author: Lokesh Soni
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 09:01:09 GMT
════════════════════════
⌗ Tags: #2fa #ethicle_hacking #web_security_testing #hacking #2fa_bypass
Medium
How I Bypassed OTP Rate Limits and Earned $303 in a Bug Bounty Hunt
hello gyussssss
⤷ Title: Inside the Master Panel: How an Unprotected Server Exposed a Massive X Hijacking Operation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:47:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA #BOTNET #Breakglass Intelligence #credential stuffing #cybersecurity #data breach #Infosec #Turkish Hackers #twitter #X
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 09:47:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA #BOTNET #Breakglass Intelligence #credential stuffing #cybersecurity #data breach #Infosec #Turkish Hackers #twitter #X
Penetration Testing Tools
Inside the Master Panel: How an Unprotected Server Exposed a Massive X Hijacking Operation
An exposed administrative console, accessible without even the most rudimentary password, has transformed a clandestine operation into a
⤷ Title: Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 04:00:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA bypass #Aggravated Identity Theft #Cryptocurrency Theft #Cybercrime #Department of Justice #Dundee #fbi #Scotland #SIM Swapping #SMS phishing #Tyler Robert Buchanan #Wire Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 04:00:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA bypass #Aggravated Identity Theft #Cryptocurrency Theft #Cybercrime #Department of Justice #Dundee #fbi #Scotland #SIM Swapping #SMS phishing #Tyler Robert Buchanan #Wire Fraud
Daily CyberSecurity
Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign
Tyler Buchanan pleads guilty in US court for an $8M cyber heist. Discover how SMS phishing and SIM swapping bypassed 2FA to drain corporate & crypto assets.
⤷ Title: Sentry’s 9.1 CVSS SSO Flaw Lets Attackers “Link” Their Way Into Your Account
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 12:45:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA #Account Takeover #CVE_2026_42354 #CVSS 9.1 #cybersecurity #Identity Linking #infosec #SAML SSO #Self_Hosted Sentry #sentry #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 12:45:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA #Account Takeover #CVE_2026_42354 #CVSS 9.1 #cybersecurity #Identity Linking #infosec #SAML SSO #Self_Hosted Sentry #sentry #SSO Bypass
Daily CyberSecurity
Sentry’s 9.1 CVSS SSO Flaw Lets Attackers "Link" Their Way Into Your Account
Sentry reveals a critical 9.1 CVSS flaw (CVE-2026-42354) in SAML SSO. Multi-org instances are at risk of account takeover via identity linking. Patch now!
⤷ Title: New “Pheno” Malware Hijacks Microsoft Phone Link to Steal SMS and OTPs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 06:22:26 +0000
════════════════════════
⌗ Tags: #Malware #2FA bypass #Cisco Talos #CloudZ RAT #cybersecurity #infosec #Microsoft Phone Link #mobile security #OTP Theft #Pheno Plugin #SMS interception #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 06:22:26 +0000
════════════════════════
⌗ Tags: #Malware #2FA bypass #Cisco Talos #CloudZ RAT #cybersecurity #infosec #Microsoft Phone Link #mobile security #OTP Theft #Pheno Plugin #SMS interception #Windows malware
Daily CyberSecurity
New "Pheno" Malware Hijacks Microsoft Phone Link to Steal SMS and OTPs
Cisco Talos exposes Pheno, a malware plugin that hijacks Microsoft Phone Link to steal SMS and 2FA codes without touching your phone. Secure your PC today!
⤷ Title: How I Bypassed 2FA by Mutating My Profile Phone Number in Graphql Request
════════════════════════
𐀪 Author: Mohamed Elmorsy
════════════════════════
ⴵ Time: Tue, 19 May 2026 16:30:03 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #hacking #2fa_bypass
════════════════════════
𐀪 Author: Mohamed Elmorsy
════════════════════════
ⴵ Time: Tue, 19 May 2026 16:30:03 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #bug_bounty #hacking #2fa_bypass
Medium
How I Bypassed 2FA by Mutating My Profile Phone Number in Graphql Request
How a simple phone number update in Graphql request compeletly bypassed 2fa protection and gave full account control.
⤷ Title: UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 09:04:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA phishing #CERT Polska #Ghostwriter #Gmail phishing campaign #Storm_0257 #UNC1151 #UNC1151 Gmail phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 09:04:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2FA phishing #CERT Polska #Ghostwriter #Gmail phishing campaign #Storm_0257 #UNC1151 #UNC1151 Gmail phishing
Daily CyberSecurity
UNC1151 'Ghostwriter' Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
The UNC1151 Gmail phishing campaign by Ghostwriter steals passwords and 2FA codes from Polish targets via fake Google login pages. Stay alert.
⤷ Title: 2FA Bypass via Switching Between Email OTP and TOTP During Authentication
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 20:29:33 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #otp_bypass #2fa_bypass #2fa_authentication
════════════════════════
𐀪 Author: Mahmoud Magdy
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 20:29:33 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #otp_bypass #2fa_bypass #2fa_authentication
Medium
2FA Bypass via Switching Between Email OTP and TOTP During Authentication
Hello Hackers 👋