⤷ Title: Stop Guessing XSS Payloads
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 20:24:00 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #web_security #ethical_hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 20:24:00 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #web_security #ethical_hacking #cybersecurity #bug_bounty
Medium
Stop Guessing XSS Payloads
Identify Context in 3 Steps
⤷ Title: Water Bottle Tryhackme Writeup
════════════════════════
𐀪 Author: Jawstar
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:15:50 GMT
════════════════════════
⌗ Tags: #tryhackme #osint_challenge #bug_bounty #tryhackme_walkthrough #osint
════════════════════════
𐀪 Author: Jawstar
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:15:50 GMT
════════════════════════
⌗ Tags: #tryhackme #osint_challenge #bug_bounty #tryhackme_walkthrough #osint
Medium
Water Bottle Tryhackme Writeup
Author : Jawstar
⤷ Title: CVE-2026–23398: PoC — A NULL Pointer in ICMP Tag Validation, and Why “One Packet” Is Never the…
════════════════════════
𐀪 Author: KeyboardSamurai
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:09:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #exploit #poc #linux #hacking
════════════════════════
𐀪 Author: KeyboardSamurai
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:09:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #exploit #poc #linux #hacking
Medium
CVE-2026–23398: PoC — A NULL Pointer in ICMP Tag Validation, and Why “One Packet” Is Never the…
CVE-2026–23398 is a remote denial-of-service in the Linux kernel IPv4 ICMP path: amissing NULL check in icmp_tag_validation() allows a…
⤷ Title: Understanding Dark Web AI Scams and Emerging Online Risks
════════════════════════
𐀪 Author: Tor BBB
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:12:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #osint #darkweb
════════════════════════
𐀪 Author: Tor BBB
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:12:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #osint #darkweb
Medium
Understanding Dark Web AI Scams and Emerging Online Risks
Artificial intelligence is transforming the internet, but it is also introducing new forms of risk. One growing concern is the rise of dark…
⤷ Title: How I Became an Organization Owner via Invite Manipulation (Privilege
Escalation)
════════════════════════
𐀪 Author: Ahmed Mahmoud
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 20:43:49 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #privilege_escalation #cybersecurity #penetration_testing
Escalation)
════════════════════════
𐀪 Author: Ahmed Mahmoud
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 20:43:49 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #privilege_escalation #cybersecurity #penetration_testing
Medium
How I Became an Organization Owner via Invite Manipulation (Privilege
Escalation)
Escalation)
“سُبْحَانَكَ لا عِلْمَ لَنَا إِلَّا مَا عَلَّمْتَنَا إِنَّكَ أَنْتَ الْعَلِيمُ الْحَكِيمُ”
⤷ Title: Pentester Labs Recon 00 write up
════════════════════════
𐀪 Author: Robert Nyinge
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:31:38 GMT
════════════════════════
⌗ Tags: #pentester_labs #pentesting #recon #reconnaissance
════════════════════════
𐀪 Author: Robert Nyinge
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 19:31:38 GMT
════════════════════════
⌗ Tags: #pentester_labs #pentesting #recon #reconnaissance
Medium
Pentester Labs Recon 00 write up
Hello hackers, this is a write-up for the Recon series on Pentester Lab, Recon 00
⤷ Title: How I Discovered a Blind SQL Injection in a Private program
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:09:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #hackerone #hacking #bugcrowd
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:09:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup #hackerone #hacking #bugcrowd
Medium
How I Discovered a Blind SQL Injection in a Private program
Hi, I’m mrx_w_ (Adem Ziane Berroudja), a bug bounty hunter on Bugcrowd. You can find me on Twitter and LinkedIn under mrx_w_. In this…
⤷ Title: Tryhackme Write-up: Corp Website (Romance and Co) 2026
════════════════════════
𐀪 Author: Day0x0f
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 21:25:12 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #bug_bounty #privilege_escalation #web_app_pentesting #ctf_writeup
════════════════════════
𐀪 Author: Day0x0f
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 21:25:12 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #bug_bounty #privilege_escalation #web_app_pentesting #ctf_writeup
Medium
Tryhackme Write-up: Corp Website (Romance and Co) 2026
Challenge: Corp Website Category: Web Difficulty: Medium
⤷ Title: The Helpful Internal Adversary: How AI threatens your data
════════════════════════
𐀪 Author: Nigel Kennis
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:40:22 GMT
════════════════════════
⌗ Tags: #web_exploitation #account_takeover #penetration_testing #hacking #idor_vulnerability
════════════════════════
𐀪 Author: Nigel Kennis
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:40:22 GMT
════════════════════════
⌗ Tags: #web_exploitation #account_takeover #penetration_testing #hacking #idor_vulnerability
Medium
The Helpful Internal Adversary
How AI threatens your data
⤷ Title: Why TTX Should Be Your Worst Nightmare - WiCyS 2026 (Women in Cybersecurity) Annual Conference …
════════════════════════
𐀪 Author: Meera Tamboli
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:03:33 GMT
════════════════════════
⌗ Tags: #wicys #ai #cybersecurity #infosec #incident_response
════════════════════════
𐀪 Author: Meera Tamboli
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:03:33 GMT
════════════════════════
⌗ Tags: #wicys #ai #cybersecurity #infosec #incident_response
Medium
Why TTX Should Be Your Worst Nightmare - WiCyS 2026 (Women in Cybersecurity) Annual Conference …
After attending conferences, I like to take notes and share the talks that stood out to me. This one was from WiCyS 2026 (Women in…
⤷ Title: Remote | HackTheBox | Walthrough | OSCP Preparation
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 23:11:09 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #ethical_hacking #tech #hacking
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 23:11:09 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #ethical_hacking #tech #hacking
Medium
Remote | HackTheBox | Walthrough | OSCP Preparation
Start off by setting our target machine’s IP as an environment variable ($target): this saves us having to constantly input the IP.
⤷ Title: Part 7: The AI under the hood and building trust in it’s automation
════════════════════════
𐀪 Author: Aparna Ash Himmatramka
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 00:56:47 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #application_security #ai #security
════════════════════════
𐀪 Author: Aparna Ash Himmatramka
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 00:56:47 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #application_security #ai #security
Medium
Part 7: The AI under the hood and building trust in it’s automation
Part 7 out of 8 of the Assisted Continuous Assurance series — rethinking AppSec from first principles
⤷ Title: The Helpful Internal Adversary
════════════════════════
𐀪 Author: Nigel Kennis
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:40:22 GMT
════════════════════════
⌗ Tags: #web_exploitation #account_takeover #penetration_testing #hacking #idor_vulnerability
════════════════════════
𐀪 Author: Nigel Kennis
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 22:40:22 GMT
════════════════════════
⌗ Tags: #web_exploitation #account_takeover #penetration_testing #hacking #idor_vulnerability
Medium
The Helpful Internal Adversary
How AI threatens your data
⤷ Title: HackTheBox: Tenten — My First Taste of CTFs
════════════════════════
𐀪 Author: Divya
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 23:01:02 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #ethical_hacking #ctf #cybersecurity
════════════════════════
𐀪 Author: Divya
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 23:01:02 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #ethical_hacking #ctf #cybersecurity
Medium
HackTheBox: Tenten — My First Taste of CTFs
A beginner-friendly walkthrough of the Tenten machine, featuring WordPress enumeration, steganography, and privilege escalation
⤷ Title: Security Alert: GitLab Issues Patch for High-Severity Vulnerabilities Across CE and EE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:52:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #Code Integrity #CVE_2026_5173 #DevOps Security #gitlab #GitLab CE #GitLab EE #graphql #infosec #privilege escalation #security update #terraform
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:52:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #Code Integrity #CVE_2026_5173 #DevOps Security #gitlab #GitLab CE #GitLab EE #graphql #infosec #privilege escalation #security update #terraform
Daily CyberSecurity
Security Alert: GitLab Issues Patch for High-Severity Vulnerabilities Across CE and EE
GitLab releases critical patches (18.10.3+) for WebSocket flaws, Terraform DoS, and unauthorized privilege demotions. Update your self-managed instances!
⤷ Title: SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4112 #CVE_2026_4114 #CVE_2026_4116 #cybersecurity #infosec #MFA Bypass #privilege escalation #SMA 1000 #SonicWall #sql injection #TOTP #Unicode Encoding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4112 #CVE_2026_4114 #CVE_2026_4116 #cybersecurity #infosec #MFA Bypass #privilege escalation #SMA 1000 #SonicWall #sql injection #TOTP #Unicode Encoding
Daily CyberSecurity
SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses
SonicWall patches critical SMA 1000 flaws, including a 7.2 SQL injection for privilege escalation and Unicode-based MFA bypasses. Secure your VPN—update now!
⤷ Title: New Phishing Campaign Abuses GitHub to Target South Korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:01:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyberespionage #FortiGuard Labs #Github C2 #infosec #LNK malware #LotL #Mirae Asset 3.0 #phishing #powershell #south korea #VBScript #XenoRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:01:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyberespionage #FortiGuard Labs #Github C2 #infosec #LNK malware #LotL #Mirae Asset 3.0 #phishing #powershell #south korea #VBScript #XenoRAT
Daily CyberSecurity
New Phishing Campaign Abuses GitHub to Target South Korea
FortiGuard Labs unmasks a South Korean espionage wave abusing the GitHub API for C2 and using LNK files to stay invisible. Protect your network from LotL.
⤷ Title: The $86,000 Patch: Chrome 147 Crushes “Critical” WebML Memory Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 01:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome 147 #CVE_2026_5858 #CVE_2026_5859 #cybersecurity #Google Chrome Update #Heap Buffer Overflow #integer overflow #memory safety #V8 Engine #WebML
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 01:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome 147 #CVE_2026_5858 #CVE_2026_5859 #cybersecurity #Google Chrome Update #Heap Buffer Overflow #integer overflow #memory safety #V8 Engine #WebML
Daily CyberSecurity
The $86,000 Patch: Chrome 147 Crushes "Critical" WebML Memory Flaws
Google Chrome 147 is out with critical security fixes for WebML and V8. Protect your browser from overflows and memory leaks—update to version 147 now!
⤷ Title: CISA Warning: Critical Ivanti EPMM Code Injection Vulnerability Under Active Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 01:46:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #code_injection #CVE_2026_1340 #cybersecurity #infosec #Ivanti EPMM #Ivanti Security Update #Mobile Device Management #patch management #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 01:46:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #code_injection #CVE_2026_1340 #cybersecurity #infosec #Ivanti EPMM #Ivanti Security Update #Mobile Device Management #patch management #rce
Daily CyberSecurity
CISA Warning: Critical Ivanti EPMM Code Injection Vulnerability Under Active Attack
CISA adds critical Ivanti EPMM flaw (CVE-2026-1340) to KEV catalog. The 9.8 CVSS code injection allows unauthenticated RCE. Patch mandated by April 11!
⤷ Title: Storm: 2026’s Newest Infostealer Bypasses Chrome to Hijack Your MFA Sessions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 01:01:38 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #browser security #Chrome 127 #Credential Theft #cybersecurity #infosec #Infostealer #MaaS #MFA Bypass #Session Cookie Theft #Storm Malware #Varonis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 01:01:38 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #browser security #Chrome 127 #Credential Theft #cybersecurity #infosec #Infostealer #MaaS #MFA Bypass #Session Cookie Theft #Storm Malware #Varonis
Daily CyberSecurity
Storm: 2026’s Newest Infostealer Bypasses Chrome to Hijack Your MFA Sessions
Storm malware bypasses Chrome security by shipping encrypted files for server-side decryption. Learn how it steals session cookies to defeat MFA in 2026.
⤷ Title: My Bug Bounty Journey #8: How an Unintentional Mistake Led to a Floor Plan Leak
════════════════════════
𐀪 Author: awchjimmy
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:18:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #cybersecurity
════════════════════════
𐀪 Author: awchjimmy
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 02:18:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #cybersecurity
Medium
My Bug Bounty Journey #8: How an Unintentional Mistake Led to a Floor Plan Leak
The Story