⤷ Title: Malicious VeloraDEX SDK Compromises Developer Machines via npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:58:56 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #C2 #Credential Theft #cybersecurity #infosec #macOS Malware #Malware Analysis #Node.js #npm #StepSecurity #supply chain attack #zsh.profiler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:58:56 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #C2 #Credential Theft #cybersecurity #infosec #macOS Malware #Malware Analysis #Node.js #npm #StepSecurity #supply chain attack #zsh.profiler
Daily CyberSecurity
Malicious VeloraDEX SDK Compromises Developer Machines via npm
A malicious update to @velora-dex/sdk (v9.4.1) drops a stealthy macOS backdoor on import. Learn how to detect the zsh.profiler infection and rotate secrets.
⤷ Title: From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:01:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #china #cyber_espionage #EU #infosec #Middle East #MSBuild #NATO #OAuth Abuse #PlugX #Proofpoint #Spearphishing #TA416
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:01:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #china #cyber_espionage #EU #infosec #Middle East #MSBuild #NATO #OAuth Abuse #PlugX #Proofpoint #Spearphishing #TA416
Daily CyberSecurity
From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
Proofpoint uncovers TA416's pivot to EU, NATO, and Middle East diplomacy. Learn how this state-linked actor uses updated PlugX and Cloudflare lures in 2026.
⤷ Title: My Bug Bounty Journey #7: When Hidden URLs Aren’t Secure
════════════════════════
𐀪 Author: awchjimmy
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:13:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development
════════════════════════
𐀪 Author: awchjimmy
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:13:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development
Medium
My Bug Bounty Journey #7: When Hidden URLs Aren’t Secure
Background
⤷ Title: From Low Bug to $1000 Bounty — The Privilege Escalation Playbook Every Hacker Should Know
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #privilege_escalation #infosec_write_ups #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #privilege_escalation #infosec_write_ups #bug_bounty #cybersecurity
Medium
🔥 From Low Bug to $1000 Bounty — The Privilege Escalation Playbook Every Hacker Should Know
💻 How a simple IDOR turned into full admin access (and what most hunters completely miss) 🚨
⤷ Title: I Found a “Hidden” API Bug That Could Have Paid $2,000+ — And Most Hackers Would Miss It
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:56 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #infosec_write_ups #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 01:23:56 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #infosec_write_ups #bug_bounty_writeup #bug_bounty
Medium
🔥 I Found a “Hidden” API Bug That Could Have Paid $2,000+ — And Most Hackers Would Miss It 💰
💻 This invisible vulnerability exposed user data… and turned into a high-paying bug bounty 🚨
⤷ Title: Monthly Threat Actor Group Intelligence Report, March 2026
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:11:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_intelligence #cyberattack #infosec #hacking
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:11:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_intelligence #cyberattack #infosec #hacking
Medium
Monthly Threat Actor Group Intelligence Report, March 2026
This is a summary of the activities of hacking groups (Threat Actor Group) analyzed based on data and information collected by the NSHC…
⤷ Title: The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:29:45 +0000
════════════════════════
⌗ Tags: #Technology #@BotFather #AI Agents #AI orchestration #Automation #Bot_to_Bot #Multi_Agent Systems #OpenClaw #Tech News 2026 #Telegram #Telegram Bots
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:29:45 +0000
════════════════════════
⌗ Tags: #Technology #@BotFather #AI Agents #AI orchestration #Automation #Bot_to_Bot #Multi_Agent Systems #OpenClaw #Tech News 2026 #Telegram #Telegram Bots
Daily CyberSecurity
The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows
In its most recent iteration, the instant messaging platform Telegram has granted bots the faculty of inter-bot accessibility, thereby enabling autonomous dialogue between automated entities—a cap…
⤷ Title: The “Entertainment Only” Paradox: Why Microsoft’s Copilot Legal Terms Just Ignited a Viral Controversy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:27:03 +0000
════════════════════════
⌗ Tags: #Technology #AI Ethics #AI Marketing #AI Output #Consumer Confidence #Copyright Liability #Legal Liability #Microsoft Bing #Microsoft Copilot #Microsoft faces backlash over Copilot terms labeling the AI as "entertainment only." Discover why this legacy clause contradicts its 2026 marketing narrative. #Tech News 2026 #Terms of Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:27:03 +0000
════════════════════════
⌗ Tags: #Technology #AI Ethics #AI Marketing #AI Output #Consumer Confidence #Copyright Liability #Legal Liability #Microsoft Bing #Microsoft Copilot #Microsoft faces backlash over Copilot terms labeling the AI as "entertainment only." Discover why this legacy clause contradicts its 2026 marketing narrative. #Tech News 2026 #Terms of Service
Daily CyberSecurity
The "Entertainment Only" Paradox: Why Microsoft’s Copilot Legal Terms Just Ignited a Viral Controversy
Microsoft faces backlash over Copilot terms labeling the AI as "entertainment only." Discover why this legacy clause contradicts its 2026 marketing narrative.
⤷ Title: The Cloud-Only Safety Net: Microsoft to Bypass Local Recycle Bins in Major OneDrive Overhaul
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:23:45 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Sync #data recovery #Files On_Demand #IT Administration #macOS #Microsoft 365 #OneDrive #Recycle Bin #Tech News 2026 #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:23:45 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Sync #data recovery #Files On_Demand #IT Administration #macOS #Microsoft 365 #OneDrive #Recycle Bin #Tech News 2026 #Windows 11
Daily CyberSecurity
The Cloud-Only Safety Net: Microsoft to Bypass Local Recycle Bins in Major OneDrive Overhaul
Starting May 2026, OneDrive cloud deletions will no longer land in your local Recycle Bin. Learn how this mandatory update changes file recovery forever.
⤷ Title: AI Against AI: Anthropic Unveils “Project Glasswing” to Stop the Next Great Cyber War
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:16:20 +0000
════════════════════════
⌗ Tags: #Technology #AI Defense #Anthropic #AWS #Claude Mythos Preview #Cybersecurity 2026 #google #Microsoft #nvidia #Project Glasswing #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:16:20 +0000
════════════════════════
⌗ Tags: #Technology #AI Defense #Anthropic #AWS #Claude Mythos Preview #Cybersecurity 2026 #google #Microsoft #nvidia #Project Glasswing #threat intelligence
Daily CyberSecurity
AI Against AI: Anthropic Unveils "Project Glasswing" to Stop the Next Great Cyber War
Anthropic launches Project Glasswing, using the unreleased "Claude Mythos" model to find thousands of zero-days and defend global infrastructure from AI threats.
⤷ Title: Alert: Social Engineering Campaign Targets Open Source Developers via Slack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:01:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #Linux Foundation #macOS Malware #malware #phishing #Root Certificate #Slack #social engineering #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:01:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #Linux Foundation #macOS Malware #malware #phishing #Root Certificate #Slack #social engineering #Windows Security
Daily CyberSecurity
Alert: Social Engineering Campaign Targets Open Source Developers via Slack
Attackers are impersonating Linux leaders on Slack to drop malware via fake Google Workspace links. Protect your dev environment—verify before acting!
⤷ Title: OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES_CFB_128 #CVE_2026_31789 #CVE_2026_31790 #cybersecurity #infosec #Memory Leak #openssl #Patch Tuesday #RSA #security advisory #Vulnerability Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:40:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES_CFB_128 #CVE_2026_31789 #CVE_2026_31790 #cybersecurity #infosec #Memory Leak #openssl #Patch Tuesday #RSA #security advisory #Vulnerability Research
Daily CyberSecurity
OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed
OpenSSL's April 2026 advisory reveals 7 flaws, including a moderate RSA memory leak (CVE-2026-31790). Learn if your version is affected and how to patch.
⤷ Title: GitHub Notification Phishing: How Attackers Abuse Legit Platforms
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:57:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #phishing #programming #hacking #github
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:57:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #phishing #programming #hacking #github
Medium
GitHub Notification Phishing: How Attackers Abuse Legit Platforms
You Got an Email From GitHub. You Clicked It. That’s All It Took.
⤷ Title: TCS HackQuest Season 10 Experience
════════════════════════
𐀪 Author: Chittibabubavisetti
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:03:04 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #ctf #cybersecurity #hackquest
════════════════════════
𐀪 Author: Chittibabubavisetti
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:03:04 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #ctf #cybersecurity #hackquest
Medium
TCS HackQuest Season 10 Experience
What is TCS HackQuest?
TCS HackQuest is a national-level cyber security competition conducted by Tata Consultancy Services (TCS). It aims…
TCS HackQuest is a national-level cyber security competition conducted by Tata Consultancy Services (TCS). It aims…
⤷ Title: JOTNAR— Autonomous AI-Powered Penetration Testing Framework
════════════════════════
𐀪 Author: Aks
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:19:44 GMT
════════════════════════
⌗ Tags: #penetration_testing #jotnar #gemini_cli #ai #agentic_ai_framework
════════════════════════
𐀪 Author: Aks
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:19:44 GMT
════════════════════════
⌗ Tags: #penetration_testing #jotnar #gemini_cli #ai #agentic_ai_framework
Medium
JOTNAR— Autonomous AI-Powered Penetration Testing Framework
One script. Full control. JOTNAR turns Gemini CLI into an autonomous pentesting partner.
⤷ Title: The Importance of Security: How VAPT by TrustLayerLabs Protects Modern Businesses
════════════════════════
𐀪 Author: Trustlayerlabs
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:36:21 GMT
════════════════════════
⌗ Tags: #owasp #ethical_hacking #api_security #vapt #cybersecurity
════════════════════════
𐀪 Author: Trustlayerlabs
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 03:36:21 GMT
════════════════════════
⌗ Tags: #owasp #ethical_hacking #api_security #vapt #cybersecurity
Medium
The Importance of Security: How VAPT by TrustLayerLabs Protects Modern Businesses 🔐
In today’s digital ecosystem, applications, APIs, and cloud platforms process massive amounts of sensitive information. From user…
⤷ Title: Red Team: DOM based XSS on DVWA
════════════════════════
𐀪 Author: Haritsar
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:31:01 GMT
════════════════════════
⌗ Tags: #dvwa_dom_based_xss #dvwa #xs #dom_xss
════════════════════════
𐀪 Author: Haritsar
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:31:01 GMT
════════════════════════
⌗ Tags: #dvwa_dom_based_xss #dvwa #xs #dom_xss
Medium
Red Team: DOM based XSS on DVWA
Introduction DOM-Based XSS
⤷ Title: Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:53:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:53:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:31:30 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #Dropbox Abuse #Kimsuky #LNK #Malware Analysis #powershell #Python backdoor #Task Scheduler #threat intelligence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:31:30 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #cyber_espionage #Dropbox Abuse #Kimsuky #LNK #Malware Analysis #powershell #Python backdoor #Task Scheduler #threat intelligence #VBScript
Daily CyberSecurity
The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
ASEC uncovers Kimsuky’s evolved LNK-to-Python chain abusing Dropbox for stealthy persistence. Learn how to detect this complex multi-stage backdoor.
⤷ Title: Critical Alert: Iranian-Affiliated Actors Target U.S. Infrastructure via Industrial Control Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:21:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA #Critical Infrastructure #CyberAv3ngers #fbi #HMI #ICS security #industrial cybersecurity #Iranian APT #OT Security #PLC Security #Rockwell Automation #SCADA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:21:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA #Critical Infrastructure #CyberAv3ngers #fbi #HMI #ICS security #industrial cybersecurity #Iranian APT #OT Security #PLC Security #Rockwell Automation #SCADA
Daily CyberSecurity
Critical Alert: Iranian-Affiliated Actors Target U.S. Infrastructure via Industrial Control Systems
FBI and CISA warn of Iranian APTs hijacking internet-facing PLCs to disrupt U.S. energy and water systems. Learn the 2026 TTPs and how to defend your OT.
⤷ Title: I Found a User Password in a Chat Log File Just by Changing a Number in a URL — This is How Hackers…
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:38:40 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #hacking #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 06:38:40 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #hacking #bug_bounty #ethical_hacking
Medium
I Found a User Password in a Chat Log File Just by Changing a Number in a URL — This is How Hackers…
My Journey So Far