⤷ Title: Web Uygulamalarında Veri Giriş Güvenliği: HTML Injection ve XSS Analizi
════════════════════════
𐀪 Author: Adar Aydinoglu
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:27:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #bug_bounty
════════════════════════
𐀪 Author: Adar Aydinoglu
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:27:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #bug_bounty
Medium
Web Uygulamalarında Veri Giriş Güvenliği: HTML Injection ve XSS Analizi
Web uygulamalarında kullanıcıdan alınan verinin nasıl işlendiği kritik bir konudur. Gerekli kontroller yapılmazsa, bu veriler üzerinden…
⤷ Title: Secured by STM, huh?
════════════════════════
𐀪 Author: Isaac Privett
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:07:18 GMT
════════════════════════
⌗ Tags: #hacking #artificial_intelligence #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Isaac Privett
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:07:18 GMT
════════════════════════
⌗ Tags: #hacking #artificial_intelligence #penetration_testing #cybersecurity
Medium
Secured by STM, huh?
Sometimes things line up in a way that feels almost… suspiciously perfect.
⤷ Title: OWASP Top 10 (2025) — Tryhackme (FR)
════════════════════════
𐀪 Author: Khalil
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 21:37:42 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #owasp_top_10_2025 #tryhackme #tryhackme_writeup #hacking
════════════════════════
𐀪 Author: Khalil
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 21:37:42 GMT
════════════════════════
⌗ Tags: #owasp_top_10 #owasp_top_10_2025 #tryhackme #tryhackme_writeup #hacking
Medium
OWASP Top 10 (2025) — Tryhackme (FR)
Introduction :
⤷ Title: Vulnerability Data Enrichment for CVE Records: 258 CNAs on the Enrichment Recognition List for…
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:44:53 GMT
════════════════════════
⌗ Tags: #information_security #information_technology #cybersecurity #vulnerability #infosec
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:44:53 GMT
════════════════════════
⌗ Tags: #information_security #information_technology #cybersecurity #vulnerability #infosec
Medium
Vulnerability Data Enrichment for CVE Records: 258 CNAs on the Enrichment Recognition List for…
The “CNA Enrichment Recognition List” for April 6, 2026, is now available with 258 CNAs listed. Published monthly on the CVE website, the…
⤷ Title: How I Built NullScore: Combining CVSS, EPSS, KEV, and PoC Into One Vulnerability Risk Score
════════════════════════
𐀪 Author: Sam0t
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:21:58 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #cybersecurity #security #ai
════════════════════════
𐀪 Author: Sam0t
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:21:58 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #cybersecurity #security #ai
Medium
How I Built NullScore: Combining CVSS, EPSS, KEV, and PoC Into One Vulnerability Risk Score
The problem with how most people prioritize CVEs
⤷ Title: Cloud Security and SaaS Supply Chain Attacks
════════════════════════
𐀪 Author: Joshua Moses
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:06:01 GMT
════════════════════════
⌗ Tags: #technology #business #money #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Joshua Moses
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:06:01 GMT
════════════════════════
⌗ Tags: #technology #business #money #penetration_testing #cybersecurity
Medium
Cloud Security and SaaS Supply Chain Attacks
By Joshua Moses
⤷ Title: TryHackMe — TakeOver CTF Writeup
════════════════════════
𐀪 Author: Aryan Vij
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 21:09:49 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Aryan Vij
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 21:09:49 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme #cybersecurity
Medium
TryHackMe — TakeOver CTF Writeup
Platform: TryHackMe | Difficulty: Easy | Category: Web / Subdomain Enumeration
⤷ Title: Your Android App’s API Keys Are Not Safe - Here’s What to Do Instead
════════════════════════
𐀪 Author: Bhagirath Devmurari
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:55:30 GMT
════════════════════════
⌗ Tags: #kotlin #android_app_development #cybersecurity #api_security #mobile_app_security
════════════════════════
𐀪 Author: Bhagirath Devmurari
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 22:55:30 GMT
════════════════════════
⌗ Tags: #kotlin #android_app_development #cybersecurity #api_security #mobile_app_security
Medium
Your Android App’s API Keys Are Not Safe - Here’s What to Do Instead
Hardcoding API keys in your Android app is like leaving your front door unlocked. In this guide, you’ll learn certificate pinning, runtime…
⤷ Title: The Ministry of Silly Walks Presents: Walking the PEB
════════════════════════
𐀪 Author: Tom O'Neill
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 00:14:22 GMT
════════════════════════
⌗ Tags: #malware #hacking #red_team #cybersecurity
════════════════════════
𐀪 Author: Tom O'Neill
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 00:14:22 GMT
════════════════════════
⌗ Tags: #malware #hacking #red_team #cybersecurity
Medium
The Ministry of Silly Walks Presents: Walking the PEB
Walking the PEB for Windows Process Injection
⤷ Title: Stuxnet: The Virus That Sabotaged Iran’s Nuclear Program and the Future of Cyberwarfare
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #technology #cyberattack #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #technology #cyberattack #hacking
Medium
Stuxnet: The Virus That Sabotaged Iran’s Nuclear Program and the Future of Cyberwarfare
Technical Analysis of Stuxnet: How Four Zero-Day Vulnerabilities Managed to Sabotage Critical Infrastructure in Natanz.
⤷ Title: HackTheBox — Pirate: Pre2k, gMSA, RBCD, WriteSPN, and the Road to Domain Admin
════════════════════════
𐀪 Author: T0NY_8
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 23:08:43 GMT
════════════════════════
⌗ Tags: #hard #hackthebox_writeup #walktrough #active_directory #pirates
════════════════════════
𐀪 Author: T0NY_8
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 23:08:43 GMT
════════════════════════
⌗ Tags: #hard #hackthebox_writeup #walktrough #active_directory #pirates
Medium
HackTheBox — Pirate: Pre2k, gMSA, RBCD, WriteSPN, and the Road to Domain Admin
Difficulty: Hard | OS: Windows | Category: Active Directory Tags: pre2k · gMSA · RBCD · PetitPotam · S4U2Proxy · Ligolo-ng · ntlmrelayx ·…
⤷ Title: APT28 Hijacks Home Routers to Steal Corporate Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:20:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #APT28 #CVE_2023_50224 #cybersecurity #DNS hijacking #Fancy Bear #GRU #MikroTik #NCSC #OAuth Theft #router security #TP_Link
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:20:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #APT28 #CVE_2023_50224 #cybersecurity #DNS hijacking #Fancy Bear #GRU #MikroTik #NCSC #OAuth Theft #router security #TP_Link
Daily CyberSecurity
APT28 Hijacks Home Routers to Steal Corporate Credentials
NCSC unmasks APT28’s "digital funnel" using router DNS hijacking to steal OAuth tokens and passwords. Protect your remote workforce—patch your routers now.
⤷ Title: Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:14:54 +0000
════════════════════════
⌗ Tags: #Malware #Chrome Bypass #ClickFix #crypto drainer #cybersecurity #infosec #MaaS #Malware Analysis #Tonkeeper #UAC Elevation #Venom Stealer #Wallet Cracking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:14:54 +0000
════════════════════════
⌗ Tags: #Malware #Chrome Bypass #ClickFix #crypto drainer #cybersecurity #infosec #MaaS #Malware Analysis #Tonkeeper #UAC Elevation #Venom Stealer #Wallet Cracking
Daily CyberSecurity
Venom Stealer Bypasses Chrome and "Auto-Cracks" Tonkeeper Wallets
Venom Stealer is a new C++ MaaS targeting crypto wallets like Tonkeeper. It features silent UAC elevation and Chrome encryption bypass. Learn how to defend.
⤷ Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Daily CyberSecurity
The 1,700-Package Blitz: North Korea’s "Contagious Interview" Infiltrates Every Major Dev Registry
North Korea’s "Contagious Interview" campaign expands to 1,700+ malicious packages across npm, PyPI, and more. Learn how to protect your dev environment.
⤷ Title: Malicious VeloraDEX SDK Compromises Developer Machines via npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:58:56 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #C2 #Credential Theft #cybersecurity #infosec #macOS Malware #Malware Analysis #Node.js #npm #StepSecurity #supply chain attack #zsh.profiler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:58:56 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #C2 #Credential Theft #cybersecurity #infosec #macOS Malware #Malware Analysis #Node.js #npm #StepSecurity #supply chain attack #zsh.profiler
Daily CyberSecurity
Malicious VeloraDEX SDK Compromises Developer Machines via npm
A malicious update to @velora-dex/sdk (v9.4.1) drops a stealthy macOS backdoor on import. Learn how to detect the zsh.profiler infection and rotate secrets.
⤷ Title: From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:01:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #china #cyber_espionage #EU #infosec #Middle East #MSBuild #NATO #OAuth Abuse #PlugX #Proofpoint #Spearphishing #TA416
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:01:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #china #cyber_espionage #EU #infosec #Middle East #MSBuild #NATO #OAuth Abuse #PlugX #Proofpoint #Spearphishing #TA416
Daily CyberSecurity
From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
Proofpoint uncovers TA416's pivot to EU, NATO, and Middle East diplomacy. Learn how this state-linked actor uses updated PlugX and Cloudflare lures in 2026.
⤷ Title: My Bug Bounty Journey #7: When Hidden URLs Aren’t Secure
════════════════════════
𐀪 Author: awchjimmy
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:13:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development
════════════════════════
𐀪 Author: awchjimmy
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:13:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development
Medium
My Bug Bounty Journey #7: When Hidden URLs Aren’t Secure
Background
⤷ Title: From Low Bug to $1000 Bounty — The Privilege Escalation Playbook Every Hacker Should Know
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #privilege_escalation #infosec_write_ups #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #privilege_escalation #infosec_write_ups #bug_bounty #cybersecurity
Medium
🔥 From Low Bug to $1000 Bounty — The Privilege Escalation Playbook Every Hacker Should Know
💻 How a simple IDOR turned into full admin access (and what most hunters completely miss) 🚨
⤷ Title: I Found a “Hidden” API Bug That Could Have Paid $2,000+ — And Most Hackers Would Miss It
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:56 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #infosec_write_ups #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:56 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #infosec_write_ups #bug_bounty_writeup #bug_bounty
Medium
🔥 I Found a “Hidden” API Bug That Could Have Paid $2,000+ — And Most Hackers Would Miss It 💰
💻 This invisible vulnerability exposed user data… and turned into a high-paying bug bounty 🚨
⤷ Title: Monthly Threat Actor Group Intelligence Report, March 2026
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:11:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_intelligence #cyberattack #infosec #hacking
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:11:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_intelligence #cyberattack #infosec #hacking
Medium
Monthly Threat Actor Group Intelligence Report, March 2026
This is a summary of the activities of hacking groups (Threat Actor Group) analyzed based on data and information collected by the NSHC…
⤷ Title: The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:29:45 +0000
════════════════════════
⌗ Tags: #Technology #@BotFather #AI Agents #AI orchestration #Automation #Bot_to_Bot #Multi_Agent Systems #OpenClaw #Tech News 2026 #Telegram #Telegram Bots
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:29:45 +0000
════════════════════════
⌗ Tags: #Technology #@BotFather #AI Agents #AI orchestration #Automation #Bot_to_Bot #Multi_Agent Systems #OpenClaw #Tech News 2026 #Telegram #Telegram Bots
Daily CyberSecurity
The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows
In its most recent iteration, the instant messaging platform Telegram has granted bots the faculty of inter-bot accessibility, thereby enabling autonomous dialogue between automated entities—a cap…