⤷ Title: A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
════════════════════════
𐀪 Author: McCaulay Hudson
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:21:07 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: McCaulay Hudson
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:21:07 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
A long, long time ago, in a land free of binary exploit mitigations, when Unix still roamed the Earth, there lived a pre-authentication Telnetd vulnerability.
In fact, this vulnerability was born so long ago (way back in 1994) that it may even be older than…
In fact, this vulnerability was born so long ago (way back in 1994) that it may even be older than…
⤷ Title: The Developer Called Me: How an IDOR Leaked 403 Users and Led to Account Takeover
════════════════════════
𐀪 Author: Gaurang Jethva
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:24:20 GMT
════════════════════════
⌗ Tags: #bug_bounty #information_security #cybersecurity #software_development #hacking
════════════════════════
𐀪 Author: Gaurang Jethva
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:24:20 GMT
════════════════════════
⌗ Tags: #bug_bounty #information_security #cybersecurity #software_development #hacking
Medium
The Developer Called Me: How an IDOR Leaked 403 Users and Led to Account Takeover
Short story
⤷ Title: Client security, runtime tampering, and why SPKI and TLS do not prove trusted execution
════════════════════════
𐀪 Author: Mark Solo
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:36:57 GMT
════════════════════════
⌗ Tags: #application_security #information_security #mobile_app_architecture #ssl_pinning #cybersecurity
════════════════════════
𐀪 Author: Mark Solo
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 20:36:57 GMT
════════════════════════
⌗ Tags: #application_security #information_security #mobile_app_architecture #ssl_pinning #cybersecurity
Medium
Client security, runtime tampering, and why SPKI and TLS do not prove trusted execution
SPKI pinning and TLS can prove that a mobile app reached the correct backend over a protected channel. They cannot prove that the client…
⤷ Title: DAST on Any Infrastructure: Open Source Dynamic Scanning with a Reproducible Test Environment
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:09:00 GMT
════════════════════════
⌗ Tags: #application_security
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:09:00 GMT
════════════════════════
⌗ Tags: #application_security
Medium
DAST on Any Infrastructure: Open Source Dynamic Scanning with a Reproducible Test Environment
The pipeline from post one catches a lot. SAST finds insecure code patterns before they ship. Dependency scanning finds vulnerable…
⤷ Title: Writing Semgrep Rules That Actually Matter
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:07:57 GMT
════════════════════════
⌗ Tags: #information_security #application_security
════════════════════════
𐀪 Author: Marshall Humble
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:07:57 GMT
════════════════════════
⌗ Tags: #information_security #application_security
Medium
Writing Semgrep Rules That Actually Matter
Community Semgrep rulesets are a good starting point. The OWASP Top 10 pack, the secrets detection rules, the language-specific security…
⤷ Title: Spotting a Malicious Workday Sign‑In: A Practical Breakdown
════════════════════════
𐀪 Author: Vonte Sewell
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:53:00 GMT
════════════════════════
⌗ Tags: #hacking #microsoft #cybersecurity #security #cloud_computing
════════════════════════
𐀪 Author: Vonte Sewell
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:53:00 GMT
════════════════════════
⌗ Tags: #hacking #microsoft #cybersecurity #security #cloud_computing
Medium
Spotting a Malicious Workday Sign‑In: A Practical Breakdown
A would-be credential stuffing thwarted
⤷ Title: The Spy Who Checked Into Paradise
════════════════════════
𐀪 Author: O. J. Okpabi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:32:19 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #hacking #true_crime #technology
════════════════════════
𐀪 Author: O. J. Okpabi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:32:19 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #hacking #true_crime #technology
Medium
The Spy Who Checked Into Paradise
How The FBI Caught A Russian Hacker Sleeping On A Thai Beach
⤷ Title: Assessment Methodologies: Enumeration CTF 1 (2026)
════════════════════════
𐀪 Author: Vanshaj Kumar
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:08:33 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #ejpt #penetration_testing #ethical_hacking
════════════════════════
𐀪 Author: Vanshaj Kumar
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 19:08:33 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #ejpt #penetration_testing #ethical_hacking
Medium
Assessment Methodologies: Enumeration CTF 1 (2026)
Hey everyone.
⤷ Title: Protecting Your Node.js API with Rate Limiting
════════════════════════
𐀪 Author: Okwudili onyido
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 18:59:11 GMT
════════════════════════
⌗ Tags: #api_security #programming #nodejs #mongodb #web_development
════════════════════════
𐀪 Author: Okwudili onyido
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 18:59:11 GMT
════════════════════════
⌗ Tags: #api_security #programming #nodejs #mongodb #web_development
Medium
Protecting Your Node.js API with Rate Limiting
How to prevent brute-force attacks and server overload using scalable middleware.
⤷ Title: How I Earned $76,000 From a Single Program on Bugcrowd
════════════════════════
𐀪 Author: Sharik Khan
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:46:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #hackerone #bug_bounty #bugcrowd
════════════════════════
𐀪 Author: Sharik Khan
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:46:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #offensive_security #hackerone #bug_bounty #bugcrowd
Medium
How I Earned $76,000 From a Single Program on Bugcrowd
Consistency and patience are not soft skills in bug bounty. They are the strategy.
⤷ Title: Hacking SmartCard Only AD Environments
════════════════════════
𐀪 Author: Zumi Yumi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:38:53 GMT
════════════════════════
⌗ Tags: #hacking #red_teaming #phishing #smart_cards #active_directory
════════════════════════
𐀪 Author: Zumi Yumi
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:38:53 GMT
════════════════════════
⌗ Tags: #hacking #red_teaming #phishing #smart_cards #active_directory
Medium
Hacking SmartCard Only AD Environments
Recently I have been involved heavily into researching PKI PIV secured Smart Cards, which has led to my discovery of a “new” TTP I will be…
⤷ Title: Voyage writeup — TryHackMe
════════════════════════
𐀪 Author: 0xH1S
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:33:56 GMT
════════════════════════
⌗ Tags: #ctf #hacking #tryhackme_walkthrough #tryhackme #ctf_writeup
════════════════════════
𐀪 Author: 0xH1S
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:33:56 GMT
════════════════════════
⌗ Tags: #ctf #hacking #tryhackme_walkthrough #tryhackme #ctf_writeup
Medium
Voyage writeup — TryHackMe
Writeup of the "Voyage" machine of tryhackme
⤷ Title: Abusing a vulnerable driver BYOVD to gain arbitrary kernel R/W and bypass PPL protection
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:30:22 GMT
════════════════════════
⌗ Tags: #hacking #malware #cybersecurity #hackthebox #pentesting
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:30:22 GMT
════════════════════════
⌗ Tags: #hacking #malware #cybersecurity #hackthebox #pentesting
Medium
Abusing a vulnerable driver BYOVD to gain arbitrary kernel R/W and bypass PPL protection
Welcome to this new Medium post. In this one, we will explore a powerful technique used in offensive security that allows us to bypass…
⤷ Title: Active Directory for Pentesters — Part 2: Active Directory Enumeration
════════════════════════
𐀪 Author: Azzam Mohammed (WHHacker)
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:01:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #windows #ethical_hacking #penetration_testing #active_directory
════════════════════════
𐀪 Author: Azzam Mohammed (WHHacker)
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:01:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #windows #ethical_hacking #penetration_testing #active_directory
Medium
Active Directory for Pentesters — Part 2: Active Directory Enumeration
In the previous article, we explored the fundamental concepts of Active Directory, including domains, domain controllers, forests, trees…
⤷ Title: I Spent 15 Years in Cybersecurity. Here’s Why AI Is Finally Changing Penetration Testing for Real.
════════════════════════
𐀪 Author: Viktor
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:24:15 GMT
════════════════════════
⌗ Tags: #ai #vibe_coding #security #ai_agent #penetration_testing
════════════════════════
𐀪 Author: Viktor
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:24:15 GMT
════════════════════════
⌗ Tags: #ai #vibe_coding #security #ai_agent #penetration_testing
Medium
I Spent 15 Years in Cybersecurity. Here’s Why AI Is Finally Changing Penetration Testing for Real.
Let me start with an honest confession: I was skeptical about AI in security for a long time.
⤷ Title: I Was Told to Try to Break a “Proprietary AI.” It Took Five Minutes.
════════════════════════
𐀪 Author: Leah Manoni
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:02:40 GMT
════════════════════════
⌗ Tags: #ai_in_business #llm_applications #artificial_intelligence #ai_agent #penetration_testing
════════════════════════
𐀪 Author: Leah Manoni
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 21:02:40 GMT
════════════════════════
⌗ Tags: #ai_in_business #llm_applications #artificial_intelligence #ai_agent #penetration_testing
Medium
I Was Told to Try to Break a “Proprietary AI.” It Took Five Minutes.
What a real-world penetration test taught me about what businesses misunderstand about AI and why
⤷ Title: The Ultimate Guide to HTTPS Decryption in Wireshark: Master Secrets, Key Logs & SNI Explained (With…
════════════════════════
𐀪 Author: Mohamed Mostafa Sayed Saber Ali
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:59:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #networking #cryptography #encryption #ethical_hacking
════════════════════════
𐀪 Author: Mohamed Mostafa Sayed Saber Ali
════════════════════════
ⴵ Time: Thu, 19 Mar 2026 22:59:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #networking #cryptography #encryption #ethical_hacking
Medium
The Ultimate Guide to HTTPS Decryption in Wireshark: Master Secrets, Key Logs & SNI Explained (With Real Examples)
Everything you need to know about decrypting HTTPS traffic: from theory to hands-on with real key log files and PCAP analysis
⤷ Title: Hacking the “Republic of Valdoria”: Chaining IDOR, Cryptography Cracking, and JWT Bypass in a…
════════════════════════
𐀪 Author: 0xPedrop
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:43:42 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #ethical_hacking #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: 0xPedrop
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:43:42 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #ethical_hacking #penetration_testing #cybersecurity
Medium
Hacking the “Republic of Valdoria”: Chaining IDOR, Cryptography Cracking, and JWT Bypass in a Technical Assessment
The offensive security ecosystem teaches us a golden rule: the weakest link is almost never a complex zero-day vulnerability, but rather…
⤷ Title: SANS 542 and GWAPT..Worth?
════════════════════════
𐀪 Author: 0ber1n
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:47:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #web_application_security #gwapt #san
════════════════════════
𐀪 Author: 0ber1n
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:47:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #web_application_security #gwapt #san
Medium
SANS 542 and GWAPT..Worth?
The GIAC Worth Scale (Thanks Gemini)
⤷ Title: The War Did Not Create This Problem. It Just Turned On the Lights.
════════════════════════
𐀪 Author: Michael Reichstein
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:09:22 GMT
════════════════════════
⌗ Tags: #critical_infrastructure #information_technology #operational_technology #cybersecurity #hacking
════════════════════════
𐀪 Author: Michael Reichstein
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:09:22 GMT
════════════════════════
⌗ Tags: #critical_infrastructure #information_technology #operational_technology #cybersecurity #hacking
Medium
The War Did Not Create This Problem. It Just Turned On the Lights.
OT security in 2026; why your physical world is running on cybersecurity assumptions from a decade ago, and why that matters right now.
⤷ Title: CrimeWare + IA
════════════════════════
𐀪 Author: Adrian Romanov
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #ai #hacking #true_crime #agentic_ai #inteligencia_artificial
════════════════════════
𐀪 Author: Adrian Romanov
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #ai #hacking #true_crime #agentic_ai #inteligencia_artificial
Medium
CrimeWare + IA
Cuando la inteligencia artificial se convierte en el mejor socio del crimen digital.