⤷ Title: Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 11:58:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 11:58:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
Daily CyberSecurity
New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
Microsoft uncovers EvilToken, an AI-powered PhaaS toolkit using Dynamic Device Code Generation to bypass MFA and breach high-value accounts. Patch now!
⤷ Title: New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:15:19 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Crypto theft #cybersecurity #grpc #Infostealer #MaaS #Malware_as_a_Service #Netskope #Node.js Malware #powershell #tor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:15:19 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Crypto theft #cybersecurity #grpc #Infostealer #MaaS #Malware_as_a_Service #Netskope #Node.js Malware #powershell #tor
Daily CyberSecurity
New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users
Netskope uncovers a Node.js-based ClickFix campaign using gRPC over Tor for stealthy crypto theft. A leaked file exposed their entire MaaS backend.
⤷ Title: ️ The 2026 Web3 Security Roadmap
════════════════════════
𐀪 Author: Tabrez Mukadam
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:12 GMT
════════════════════════
⌗ Tags: #blockchain #ethereum #web3 #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Tabrez Mukadam
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:12 GMT
════════════════════════
⌗ Tags: #blockchain #ethereum #web3 #bug_bounty #cybersecurity
Medium
🗺️ The 2026 Web3 Security Roadmap: How to Stop Chasing XSS and Start Auditing Smart Contracts
How to Stop Chasing XSS and Start Auditing Smart Contracts
⤷ Title: Learning About Post-message Vulnerabilities
════════════════════════
𐀪 Author: Raunak Gupta Aka Biscuit
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:51:06 GMT
════════════════════════
⌗ Tags: #javascript #programming #cybersecurity #ethical_hacking #bug_bounty
════════════════════════
𐀪 Author: Raunak Gupta Aka Biscuit
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:51:06 GMT
════════════════════════
⌗ Tags: #javascript #programming #cybersecurity #ethical_hacking #bug_bounty
Medium
Learning About Post-message Vulnerabilities
Note: I’m writing this as personal learning notes, not a generic article please keep that in mind. Also, I used AI for rephrasing and…
⤷ Title: NoSQL Injection: How I Turned ?search= Into an Admin Oracle
════════════════════════
𐀪 Author: Thomas Youssef
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:28:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #penetration_testing #bug_bounty #info_sec_writeups #cybersecurity
════════════════════════
𐀪 Author: Thomas Youssef
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:28:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #penetration_testing #bug_bounty #info_sec_writeups #cybersecurity
Medium
NoSQL Injection: How I Turned ?search= Into an Admin Oracle
Hello friend, I’m Thomas Youssef — and this one is a little different from my usual access control writeups. No role swapping. No token…
⤷ Title: How I found a $5,000 Command Injection via an RSS validator
════════════════════════
𐀪 Author: Yazeed Bilal
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:05:53 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bug_bounty_tips #bugs
════════════════════════
𐀪 Author: Yazeed Bilal
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:05:53 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty #bug_bounty_tips #bugs
Medium
RSS Feed Validator to RCE 🤯
Hello everyone,
⤷ Title: Empline (THM) Tryhackme WriteUp With Answer
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:32:12 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #privilege_escalation #hacking #cybersecurity
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:32:12 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf_writeup #privilege_escalation #hacking #cybersecurity
Medium
Empline (THM) Tryhackme WriteUp With Answer
Description : Are you good enough to apply for this job?
⤷ Title: Ethical Hacking vs Criminal Hacking: What’s the Difference?
════════════════════════
𐀪 Author: ASRBD | Cybersecurity Bangladesh
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:25:49 GMT
════════════════════════
⌗ Tags: #hacking #cyber_awareness #asrbd
════════════════════════
𐀪 Author: ASRBD | Cybersecurity Bangladesh
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:25:49 GMT
════════════════════════
⌗ Tags: #hacking #cyber_awareness #asrbd
Medium
Ethical Hacking vs Criminal Hacking: What’s the Difference?
When people hear the word “hacker,” they often imagine a criminal sitting in a dark room breaking into systems.
⤷ Title: Shady Oaks Financial (JWT) Bugforge.io
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:54:08 GMT
════════════════════════
⌗ Tags: #hacking #jwt #jwt_token #ctf #jwt_authentication
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:54:08 GMT
════════════════════════
⌗ Tags: #hacking #jwt #jwt_token #ctf #jwt_authentication
Medium
Shady Oaks Financial (JWT) Bugforge.io
Thanks for following along!
⤷ Title: Come iniziare con il Penetration Testing nel 2025: una roadmap pratica
════════════════════════
𐀪 Author: Caniocampa
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:01:36 GMT
════════════════════════
⌗ Tags: #offensive_security #cybersecurity #hacking
════════════════════════
𐀪 Author: Caniocampa
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:01:36 GMT
════════════════════════
⌗ Tags: #offensive_security #cybersecurity #hacking
Medium
Come iniziare con il Penetration Testing nel 2025: una roadmap pratica
Il penetration testing non si impara leggendo libri.
⤷ Title: PortSwigger Lab: Information disclosure in version control history
════════════════════════
𐀪 Author: Nikhil Bhandari
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #appsec #portswigger_lab #portswigger #cybersecurity
════════════════════════
𐀪 Author: Nikhil Bhandari
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #appsec #portswigger_lab #portswigger #cybersecurity
Medium
PortSwigger Lab: Information disclosure in version control history
Hello everyone! Nikhil Bhandari here. Today, I’ll be sharing a step-by-step guide on how to solve the PortSwigger Lab: Authentication…
⤷ Title: METATRON — Open-Source AI Penetration Testing Assistant Bringing Local LLM Analysis to Linux
════════════════════════
𐀪 Author: Cybervolt
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:14:36 GMT
════════════════════════
⌗ Tags: #penetration_testing #artificial_intelligence #cybersecurity #red_team #ethical_hacking
════════════════════════
𐀪 Author: Cybervolt
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:14:36 GMT
════════════════════════
⌗ Tags: #penetration_testing #artificial_intelligence #cybersecurity #red_team #ethical_hacking
Medium
METATRON — Open-Source AI Penetration Testing Assistant Bringing Local LLM Analysis to Linux
As AI continues to reshape cybersecurity, a new class of tools is emerging — private, offline, and intelligent. One of the most…
⤷ Title: TryHackMe — One Piece — Ctf
════════════════════════
𐀪 Author: Avshivapriyan
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:58:52 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #ctf_writeup #cybersecurity #ctf #tryhackme
════════════════════════
𐀪 Author: Avshivapriyan
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:58:52 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #ctf_writeup #cybersecurity #ctf #tryhackme
Medium
TryHackMe — One Piece — Ctf
Port scan
⤷ Title: Tryhackme: Linux Fundamentals
════════════════════════
𐀪 Author: Ikhlasdansantai
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:46:10 GMT
════════════════════════
⌗ Tags: #tryhackme #terminal #cybersecurity #kitty #linux
════════════════════════
𐀪 Author: Ikhlasdansantai
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 07:46:10 GMT
════════════════════════
⌗ Tags: #tryhackme #terminal #cybersecurity #kitty #linux
Medium
Tryhackme: Linux Fundamentals
What I’ve learned
⤷ Title: File Upload Vulnerability /Privilege escalations on Twiki(playmode)
════════════════════════
𐀪 Author: Goldsploit
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:31:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking
════════════════════════
𐀪 Author: Goldsploit
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:31:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking
Medium
File Upload Vulnerability /Privilege escalations on Twiki(playmode)
Accessed the webpage on port 80, clicked on TWiki went through other links,but let’s click on get started
⤷ Title: The “Seal of Approval” Trap: How Hackers are Hijacking GitHub and Jira Notifications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 09:15:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cisco Talos #Credential Harvesting #cybersecurity #GitHub Phishing #infosec #Jira Abuse #PaaP #Platform_as_a_Proxy #SaaS Security #social engineering #SPF Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 09:15:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cisco Talos #Credential Harvesting #cybersecurity #GitHub Phishing #infosec #Jira Abuse #PaaP #Platform_as_a_Proxy #SaaS Security #social engineering #SPF Bypass
Daily CyberSecurity
The "Seal of Approval" Trap: How Hackers are Hijacking GitHub and Jira Notifications
Cisco Talos exposes "Platform-as-a-Proxy" (PaaP). Hackers are abusing GitHub and Jira's trusted mail servers to bypass SPF/DKIM and deliver phishing lures.
⤷ Title: Referer-Based Access Control — The Last Access Control Lab Before I Move On to Authentication
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #hackerone #cybersecurity #bug_bounty #web_development
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #hackerone #cybersecurity #bug_bounty #web_development
Medium
Referer-Based Access Control — The Last Access Control Lab Before I Move On to Authentication
13 labs deep. This is how the access control series ends — and what is coming next.
⤷ Title: Lab 12: Multi-Step Process With No Access Control on One Step — How I Promoted Myself to Admin
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 09:31:30 GMT
════════════════════════
⌗ Tags: #website #bug_bounty #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 09:31:30 GMT
════════════════════════
⌗ Tags: #website #bug_bounty #cybersecurity #ethical_hacking
Medium
Lab 12: Multi-Step Process With No Access Control on One Step — How I Promoted Myself to Admin
A common mistake developers make is securing the first step of a process and forgetting the rest. Here is how that one oversight becomes a…
⤷ Title: How Good Are AI Agents at Finding Web Vulnerabilities (Part 2)
════════════════════════
𐀪 Author: Tuomo Makkonen
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 10:39:16 GMT
════════════════════════
⌗ Tags: #agentic_ai #artificial_intelligence #application_security #cybersecurity #ai
════════════════════════
𐀪 Author: Tuomo Makkonen
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 10:39:16 GMT
════════════════════════
⌗ Tags: #agentic_ai #artificial_intelligence #application_security #cybersecurity #ai
Medium
How Good Are AI Agents at Finding Web Vulnerabilities (Part 2)
We gave AI agents the source code and their detection rate tripled, but they still can’t chain vulnerabilities together, agree on severity…
⤷ Title: Trilab — Complete Domain Compromise via Kerberos and ADCS Misconfiguration
════════════════════════
𐀪 Author: GauthamV
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 10:44:21 GMT
════════════════════════
⌗ Tags: #penetration_testing #active_directory #red_teaming #hacking
════════════════════════
𐀪 Author: GauthamV
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 10:44:21 GMT
════════════════════════
⌗ Tags: #penetration_testing #active_directory #red_teaming #hacking
Medium
Trilab — Complete Domain Compromise via Kerberos and ADCS Misconfiguration
Objective / Scope