⤷ Title: New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:19:40 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #apk0day #banking malware #FvncBot #H.264 #HVNC #mBank #WebSocket C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:19:40 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #apk0day #banking malware #FvncBot #H.264 #HVNC #mBank #WebSocket C2
Daily CyberSecurity
New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming
A unique Android banking trojan, FvncBot, targets mBank (Poland) customers. It uses HVNC and H.264 to stream screens and performs web-inject attacks via FCM/WebSocket C2.
⤷ Title: Web Security Academy: Websockets— Manipulating WebSocket messages to exploit vulnerabilities
════════════════════════
𐀪 Author: Octavian I.
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:19:08 GMT
════════════════════════
⌗ Tags: #tutorial #websocket #web_security #cybersecurity #hacking
════════════════════════
𐀪 Author: Octavian I.
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:19:08 GMT
════════════════════════
⌗ Tags: #tutorial #websocket #web_security #cybersecurity #hacking
Medium
Web Security Academy: Websockets— Manipulating WebSocket messages to exploit vulnerabilities
A simple case of WebSocket message manipulation
⤷ Title: Exploiting WebSocket Information Disclosure to Achieve Account Deletion (IDOR)
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 01:38:29 GMT
════════════════════════
⌗ Tags: #web_development #idor #hacking #bug_bounty #websocket
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 01:38:29 GMT
════════════════════════
⌗ Tags: #web_development #idor #hacking #bug_bounty #websocket
Medium
Exploiting WebSocket Information Disclosure to Achieve Account Deletion (IDOR)
🔍 Quick Overview
⤷ Title: WebSocket Misconfiguration Leading to DOM Manipulation and Denial of Service in a Web Chat…
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 04:21:37 GMT
════════════════════════
⌗ Tags: #websocket #bug_bounty #hacking #penetration_testing #web_development
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 04:21:37 GMT
════════════════════════
⌗ Tags: #websocket #bug_bounty #hacking #penetration_testing #web_development
Medium
WebSocket Misconfiguration Leading to DOM Manipulation and Denial of Service in a Web Chat…
✅ Quick Overview (Polished Version)
⤷ Title: The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:25:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #DoNot Group #InfoSec 2026 #MSBuild #Pakistan Defense #Patchwork APT #Python RAT #QiAnXin #Spyder Malware #StreamSpy #WebSocket C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:25:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #DoNot Group #InfoSec 2026 #MSBuild #Pakistan Defense #Patchwork APT #Python RAT #QiAnXin #Spyder Malware #StreamSpy #WebSocket C2
Penetration Testing Tools
The StreamSpy Breach: Patchwork’s Stealthy New Trojan Targets Pakistan Defense
The hacking group known as Patchwork—also referred to as Dropping Elephant and Maha Grass—has once again come under
⤷ Title: WebSocket Penetration Testing: How to Test for WebSocket Hijacking, IDOR, Injection & More
════════════════════════
𐀪 Author: Assassin
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 15:50:37 GMT
════════════════════════
⌗ Tags: #burpsuite_extension #penetration_testing #bug_bounty #cybersecurity #websocket
════════════════════════
𐀪 Author: Assassin
════════════════════════
ⴵ Time: Thu, 12 Feb 2026 15:50:37 GMT
════════════════════════
⌗ Tags: #burpsuite_extension #penetration_testing #bug_bounty #cybersecurity #websocket
Medium
WebSocket Penetration Testing: How to Test for WebSocket Hijacking, IDOR, Injection & More
Understanding WebSocket security, common attack vectors, and a purpose-built toolkit to test them.
⤷ Title: Total Dominion: The CVSS 10.0 Flaw in Nanobot Allowing Hackers to Hijack Your WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:55:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Assistant #Critical Vulnerability #CVE_2026_2577 #CVSS 10.0 #Nanobot #QR code theft #session takeover #Tech News 2026 #Tenable #WebSocket hijacking #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:55:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Assistant #Critical Vulnerability #CVE_2026_2577 #CVSS 10.0 #Nanobot #QR code theft #session takeover #Tech News 2026 #Tenable #WebSocket hijacking #WhatsApp
Penetration Testing Tools
Total Dominion: The CVSS 10.0 Flaw in Nanobot Allowing Hackers to Hijack Your WhatsApp
Security researchers from Tenable have unearthed a critical vulnerability, designated CVE-2026-2577, within the prominent AI assistant Nanobot, a
⤷ Title: Phantom Protocol (Razzify) .
════════════════════════
𐀪 Author: mayhack
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 20:44:50 GMT
════════════════════════
⌗ Tags: #razzify #hacking #websocket #ctf #cybersecurity
════════════════════════
𐀪 Author: mayhack
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 20:44:50 GMT
════════════════════════
⌗ Tags: #razzify #hacking #websocket #ctf #cybersecurity
Medium
Phantom Protocol (Razzify) .
Challenge Overview
⤷ Title: Critical CISA Advisory Unmasks Severe Flaws in EV2GO Charging Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 28 Feb 2026 03:50:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA advisory #Critical Infrastructure #CVE_2026_24731 #EV Charging Security #EV2GO #ICS #ICSA_26_057_04 #industrial control systems #infosec #OCPP #WebSocket Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 28 Feb 2026 03:50:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA advisory #Critical Infrastructure #CVE_2026_24731 #EV Charging Security #EV2GO #ICS #ICSA_26_057_04 #industrial control systems #infosec #OCPP #WebSocket Vulnerability
Daily CyberSecurity
Critical CISA Advisory Unmasks Severe Flaws in EV2GO Charging Networks
CISA issues an urgent ICS advisory (ICSA-26-057-04) for the EV2GO charging platform. Critical 9.4 severity flaws allow for session hijacking and station impersonation.
⤷ Title: EV Charging Grid Alert: Critical Flaws Exposed in Everon OCPP Backends
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 00:22:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_26288 #cybersecurity #EV Charging Security #Everon #infosec #OCPP #Session Hijacking #Smart Grid #threat intelligence #WebSocket Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 00:22:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_26288 #cybersecurity #EV Charging Security #Everon #infosec #OCPP #Session Hijacking #Smart Grid #threat intelligence #WebSocket Vulnerability
Daily CyberSecurity
EV Charging Grid Alert: Critical Flaws Exposed in Everon OCPP Backends
Critical authentication flaws (CVE-2026-26288) in Everon's OCPP backend allowed hackers to hijack EV chargers, forcing a complete platform shutdown.
⤷ Title: PortSwigger: WebSockets Labs
════════════════════════
𐀪 Author: Abdelhamid Elbouz
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 09:08:01 GMT
════════════════════════
⌗ Tags: #hacking #penetration_testing #cybersecurity #portswigger #websocket
════════════════════════
𐀪 Author: Abdelhamid Elbouz
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 09:08:01 GMT
════════════════════════
⌗ Tags: #hacking #penetration_testing #cybersecurity #portswigger #websocket
Medium
PortSwigger: WebSockets Labs
Lab: Manipulating WebSocket messages to exploit vulnerabilities
⤷ Title: Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
Daily CyberSecurity
Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
Unauthenticated RCE in marimo (CVE-2026-39987) exploited in the wild in record time. Attackers gained root access in under 10 hours. Patch to v0.23.0 now!
⤷ Title: No Patch Available: The CVSS 10 Flaw Turning AVideo into an Attacker’s Playground
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 12:40:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #AVideo #CVSS 10 #cybersecurity #infosec #JavaScript Injection #rce #WebSocket Vulnerability #YPTSocket #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 12:40:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #AVideo #CVSS 10 #cybersecurity #infosec #JavaScript Injection #rce #WebSocket Vulnerability #YPTSocket #zero_day
Daily CyberSecurity
No Patch Available: The CVSS 10 Flaw Turning AVideo into an Attacker’s Playground
AVideo’s YPTSocket plugin faces a critical CVSS 10 vulnerability. Unauthenticated attackers can hijack every active session at once. No patch is available.
⤷ Title: Critical 9.8 CVSS RCE Hijacks Pipecat Voice Agents
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 08:06:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_62373 #cybersecurity #Deserialization #infosec #LiveKit #Patch Alert #Pickle #Pipecat #Python #rce #Voice AI #WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Apr 2026 08:06:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_62373 #cybersecurity #Deserialization #infosec #LiveKit #Patch Alert #Pickle #Pipecat #Python #rce #Voice AI #WebSocket Security
Daily CyberSecurity
Critical 9.8 CVSS RCE Hijacks Pipecat Voice Agents
Critical 9.8 CVSS RCE in Pipecat (CVE-2025-62373)! Unsafe pickle deserialization allows remote code execution. Patch to v0.0.94 immediately to secure agents.
⤷ Title: 9.6 Severity: Critical “Cline” AI Agent Flaw Allows Stealthy RCE via Your Browser
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:20:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cline AI #CVE_2026_44211 #DevSecOps #infosec #Localhost Vulnerability #npm Security #rce #Remote Code Execution #Web Security #WebSocket Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:20:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cline AI #CVE_2026_44211 #DevSecOps #infosec #Localhost Vulnerability #npm Security #rce #Remote Code Execution #Web Security #WebSocket Hijacking
Daily CyberSecurity
9.6 Severity: Critical "Cline" AI Agent Flaw Allows Stealthy RCE via Your Browser
Critical Alert: CVE-2026-44211 (CVSS 9.6) in Cline AI allows malicious sites to hijack your terminal and steal data via WebSockets. Update your CLI tools now.
⤷ Title: CVE-2026-44578 Next.js SSRF Vulnerability
════════════════════════
𐀪 Author: Nisal Renuja Palliyaguru
════════════════════════
ⴵ Time: Sat, 16 May 2026 04:09:14 GMT
════════════════════════
⌗ Tags: #nextjs #ssrf #vulnerability #websocket
════════════════════════
𐀪 Author: Nisal Renuja Palliyaguru
════════════════════════
ⴵ Time: Sat, 16 May 2026 04:09:14 GMT
════════════════════════
⌗ Tags: #nextjs #ssrf #vulnerability #websocket
Medium
CVE-2026-44578 Next.js SSRF Vulnerability
A high severity Server Side Request Forgery (SSRF) vulnerability has been disclosed in Next.js one of the most widely used React frameworks…
⤷ Title: Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 06:56:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cloud Metadata Exploit #CVE_2026_44578 #CWE_918 #Next.js #Security Patch 2026 #Self_Hosted Node.js #Server_Side Request Forgery #SSRF #Vercel #WebSocket Upgrade
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 06:56:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cloud Metadata Exploit #CVE_2026_44578 #CWE_918 #Next.js #Security Patch 2026 #Self_Hosted Node.js #Server_Side Request Forgery #SSRF #Vercel #WebSocket Upgrade
Penetration Testing Tools
Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints
The development framework Next.js has remediated a critical security vulnerability, designated as CVE-2026-44578, which afflicts applications deployed on
⤷ Title: The Zero-Detection Shadow: Unit 42 Exposes Advanced Gremlin Stealer Hijacking Live Browser WebSockets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:42:37 +0000
════════════════════════
⌗ Tags: #Malware #.NET Resource Obfuscation #Chromium Identity Theft #Code Virtualization Bytecode #Cookie Protection Bypass #Cryptojacking Clipboard Hijacker #Gremlin Stealer Malware #Unit 42 Palo Alto Networks #WebSocket Session Hijacking #XOR Encoded Payload #Zero Detection C2 Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:42:37 +0000
════════════════════════
⌗ Tags: #Malware #.NET Resource Obfuscation #Chromium Identity Theft #Code Virtualization Bytecode #Cookie Protection Bypass #Cryptojacking Clipboard Hijacker #Gremlin Stealer Malware #Unit 42 Palo Alto Networks #WebSocket Session Hijacking #XOR Encoded Payload #Zero Detection C2 Infrastructure
Information Security News
The Zero-Detection Shadow: Unit 42 Exposes Advanced Gremlin Stealer Hijacking Live Browser WebSockets - Information Security News
The exfiltration of administrative credentials and volatile session tokens increasingly manifests not as a rudimentary brute-force incursion, but as a meticulously obfuscated mechanism engineered to maintain absolute silence until the definitive moment of…
⤷ Title: Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 02:00:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_6734 #CVE_2026_9697 #nodejs #npm #SOCKS5 #TLS Bypass #undici #WebSocket
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 02:00:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_6734 #CVE_2026_9697 #nodejs #npm #SOCKS5 #TLS Bypass #undici #WebSocket
Daily CyberSecurity
Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
Four undici vulnerabilities (CVE-2026-6734, CVE-2026-9697) affect the Node.js HTTP client, which sees 133M weekly downloads. Update undici now.
⤷ Title: Critical Event-Driven Ansible Flaw Leaks Stored Credentials
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Ansible Automation Platform #Credential Disclosure #CVE_2026_11807 #Event_Driven Ansible #Missing Authorization #red hat #websocket API
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Ansible Automation Platform #Credential Disclosure #CVE_2026_11807 #Event_Driven Ansible #Missing Authorization #red hat #websocket API
Daily CyberSecurity
Critical Event-Driven Ansible Flaw Leaks Stored Credentials
A missing authorization flaw in Event-Driven Ansible (CVE-2026-11807, CVSS 9.6) leaks credentials like OAuth tokens, vault passwords, and SSH keys.