⤷ Title: The NPM Token That Stayed Alive for Two Years
════════════════════════
𐀪 Author: Arshad Kazmi
════════════════════════
ⴵ Time: Fri, 30 May 2025 15:29:14 GMT
════════════════════════
⌗ Tags: #hackerone_report #bug_bounty #npm_token #dockerhub #exposed_credential
════════════════════════
𐀪 Author: Arshad Kazmi
════════════════════════
ⴵ Time: Fri, 30 May 2025 15:29:14 GMT
════════════════════════
⌗ Tags: #hackerone_report #bug_bounty #npm_token #dockerhub #exposed_credential
Medium
The NPM Token That Stayed Alive for Two Years
About two years ago, while testing an early, unreleased version of iScan.today, I picked up something odd during a routine scan.
⤷ Title: Blind Eagle (APT-C-36): Financially Motivated Cybercrime Meets Open-Access Infrastructure in LATAM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:44:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #APT_C_36 #AsyncRAT #Blind Eagle #Colombia #Cybercrime #Exposed C2 #Latin America #phishing #rat #Remcos #Remote Access Trojan #Trustwave #VBS Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:44:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #APT_C_36 #AsyncRAT #Blind Eagle #Colombia #Cybercrime #Exposed C2 #Latin America #phishing #rat #Remcos #Remote Access Trojan #Trustwave #VBS Malware
Daily CyberSecurity
Blind Eagle (APT-C-36): Financially Motivated Cybercrime Meets Open-Access Infrastructure in LATAM
Trustwave exposes Blind Eagle (APT-C-36) leveraging exposed infrastructure and VBS malware in phishing campaigns, targeting Colombian banks with blatant disregard for concealment.
⤷ Title: Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:14:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Infrastructure #cyberattack #cybersecurity #Exposed Devices #ICS #industrial control systems #Operation Sindoor #OT Security #Power Grid #Vulnerability #zoomeye
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:14:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Infrastructure #cyberattack #cybersecurity #Exposed Devices #ICS #industrial control systems #Operation Sindoor #OT Security #Power Grid #Vulnerability #zoomeye
Daily CyberSecurity
Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure?
Over 143,000 ICS devices in the power sector are publicly exposed to the internet, facing high/critical vulnerabilities. Urgent action is needed to secure global energy infrastructure.
⤷ Title: Penetration Testing Exposed: A Day in the Life of a Professional Hacker (For Good)
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 15:23:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #exposed #professional_hackers #penetration_testing
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 15:23:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #exposed #professional_hackers #penetration_testing
Medium
Penetration Testing Exposed: A Day in the Life of a Professional Hacker (For Good)
Breaking Into Offices, Bypassing Security, and Getting Paid to Do It—All With Permission
⤷ Title: Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:05:45 +0000
════════════════════════
⌗ Tags: #Malware #Akamai #botnet #cryptomining #cybersecurity #Docker malware #exposed APIs #malware evolution #Remote Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:05:45 +0000
════════════════════════
⌗ Tags: #Malware #Akamai #botnet #cryptomining #cybersecurity #Docker malware #exposed APIs #malware evolution #Remote Access
Daily CyberSecurity
Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs
A new malware strain is targeting exposed Docker APIs, evolving from a cryptominer into a stealthy botnet that blocks ports to "own" a victim's system for exclusive use.
⤷ Title: 48,000 Cisco Firewalls Remain Exposed to Active Zero-Day Attacks, Shadowserver Finds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 02 Oct 2025 03:07:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #Cisco ASA #Exposed Devices #Firepower #NCSC #network security #RCE #Shadowserver #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 02 Oct 2025 03:07:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #Cisco ASA #Exposed Devices #Firepower #NCSC #network security #RCE #Shadowserver #zero_day
Penetration Testing Tools
48,000 Cisco Firewalls Remain Exposed to Active Zero-Day Attacks, Shadowserver Finds
A Shadowserver scan found over 48,000 Cisco ASA/FTD firewalls remain unpatched against two critical zero-day RCE/Unauthorized Access flaws, despite CISA’s emergency directive.
⤷ Title: MuddyWater’s Latest Malware Suite Exposed: A Global Espionage Campaign
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 11:28:01 GMT
════════════════════════
⌗ Tags: #campaign #cybersecurity #malware #exposed #hacking
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 11:28:01 GMT
════════════════════════
⌗ Tags: #campaign #cybersecurity #malware #exposed #hacking
Medium
MuddyWater’s Latest Malware Suite Exposed: A Global Espionage Campaign
Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent…
⤷ Title: The Shai-Hulud Attack: Exposing Weak Links in Modern Software Supply Chains
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Fri, 14 Nov 2025 15:17:18 GMT
════════════════════════
⌗ Tags: #attack #software #cybersecurity #hacking #exposed
════════════════════════
𐀪 Author: Himanshu Bhatt
════════════════════════
ⴵ Time: Fri, 14 Nov 2025 15:17:18 GMT
════════════════════════
⌗ Tags: #attack #software #cybersecurity #hacking #exposed
Medium
The Shai-Hulud Attack: Exposing Weak Links in Modern Software Supply Chains
The recent “Shai-Hulud” worm that hit the NPM ecosystem shows just how fragile our software supply chains really are. This malware — named…
⤷ Title: CyberHeroes THM Writeup
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:31:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cyberheros_thm #exposed_javascript #broken_authentication #tryhackme
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 14:31:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #cyberheros_thm #exposed_javascript #broken_authentication #tryhackme
Medium
CyberHeroes THM Writeup
Understanding Broken Authentication Through Exposed JavaScript Logic
⤷ Title: 240,000 OpenClaw AI Instances Exposed to the Public Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 04:18:02 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #AI security #Clawdbot #cloud server security #Cybersecurity 2026 #Data Privacy #exposed instances #Information Leakage #Moltbot #OpenClaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 04:18:02 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Agents #AI security #Clawdbot #cloud server security #Cybersecurity 2026 #Data Privacy #exposed instances #Information Leakage #Moltbot #OpenClaw
Daily CyberSecurity
240,000 OpenClaw AI Instances Exposed to the Public Web
240,000 OpenClaw AI instances are currently exposed to the public internet. Learn how to secure your personal assistant before it becomes a portal for hackers.
⤷ Title: OWASP Top 10 #5 — Security Misconfiguration ⚙️
════════════════════════
𐀪 Author: Kanishkakhandelwal
════════════════════════
ⴵ Time: Wed, 13 May 2026 10:48:14 GMT
════════════════════════
⌗ Tags: #vapt #exposed #bug_bounty #owasp_top_10 #security_misconfiguration
════════════════════════
𐀪 Author: Kanishkakhandelwal
════════════════════════
ⴵ Time: Wed, 13 May 2026 10:48:14 GMT
════════════════════════
⌗ Tags: #vapt #exposed #bug_bounty #owasp_top_10 #security_misconfiguration
Medium
OWASP Top 10 #5 — Security Misconfiguration ⚙️
The Vulnerability That Happens When Systems Are Left Carelessly Exposed
⤷ Title: Bug Bounty — Bypassing Access Controls: How a Single Boolean Flag Exposed KYC Government IDs
════════════════════════
𐀪 Author: Kenjisubagja
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 08:16:01 GMT
════════════════════════
⌗ Tags: #exposed_kyc #bug_bounty_hunter #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Kenjisubagja
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 08:16:01 GMT
════════════════════════
⌗ Tags: #exposed_kyc #bug_bounty_hunter #bug_bounty #bug_bounty_writeup
Medium
Bug Bounty — Bypassing Access Controls: How a Single Boolean Flag Exposed KYC Government IDs
Hello, hackers! In this writeup, I want to share a high-severity vulnerability I discovered during a recent bug bounty hunt. The…
⤷ Title: An Exposed API Key Cost Me $4,000. Here Is Exactly What to Do To Avoid It.
════════════════════════
𐀪 Author: Belkin Marketing Team
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 10:01:43 GMT
════════════════════════
⌗ Tags: #hacking #exposed_api_key #iaros_belkin #api_key #credential_containment
════════════════════════
𐀪 Author: Belkin Marketing Team
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 10:01:43 GMT
════════════════════════
⌗ Tags: #hacking #exposed_api_key #iaros_belkin #api_key #credential_containment
Medium
An Exposed API Key Cost Me $4,000. Here Is Exactly What to Do To Avoid It.
The Four-Layer Credential Containment Model, the axios supply chain attack that hit 100 million downloads in under three hours, and the…