⤷ Title: TryHackMe — Ra: Writeup
════════════════════════
𐀪 Author: Taher Borgi
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 23:44:22 GMT
════════════════════════
⌗ Tags: #active_directory #cybersecurity #ethical_hacking #penetration_testing #tryhackme
════════════════════════
𐀪 Author: Taher Borgi
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 23:44:22 GMT
════════════════════════
⌗ Tags: #active_directory #cybersecurity #ethical_hacking #penetration_testing #tryhackme
Medium
TryHackMe — Ra: Writeup
Room: Ra Difficulty: Hard Infrastructure: Active Directory / Windows Server 2019 Made by: @4nqr34z and @theart42
⤷ Title: Building Secure APIs at Scale: A Practical Guide to SSO, MFA, and RBAC
════════════════════════
𐀪 Author: Vaishnavius Apply
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 23:28:13 GMT
════════════════════════
⌗ Tags: #microservices #oauth #software_engineering #backend_development #api_security
════════════════════════
𐀪 Author: Vaishnavius Apply
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 23:28:13 GMT
════════════════════════
⌗ Tags: #microservices #oauth #software_engineering #backend_development #api_security
Medium
Building Secure APIs at Scale: A Practical Guide to SSO, MFA, and RBAC
Learn how to design scalable and secure APIs using SSO, MFA, JWT, and RBAC in real-world distributed systems.
⤷ Title: The High-Stakes Return of 0xFFF: ‘notnullOSX’ Stealer Targets macOS Crypto Whales
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:30:33 +0000
════════════════════════
⌗ Tags: #Malware #0xFFF #alh1mik #ClickFix #Crypto Stealer #cyber_espionage #DeFi Security #Go malware #Hardware Wallet #macOS Malware #Moonlock Lab #notnullOSX
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:30:33 +0000
════════════════════════
⌗ Tags: #Malware #0xFFF #alh1mik #ClickFix #Crypto Stealer #cyber_espionage #DeFi Security #Go malware #Hardware Wallet #macOS Malware #Moonlock Lab #notnullOSX
Daily CyberSecurity
The High-Stakes Return of 0xFFF: 'notnullOSX' Stealer Targets macOS Crypto Whales
Moonlock Lab reveals notnullOSX, a predatory macOS stealer targeting crypto users with $10k+ holdings. See how it uses ClickFix to hijack wallet apps.
⤷ Title: The Billion-Dollar Invite: How UNC1069’s Fake Meetings Hijack Crypto Fortunes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:14:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlueNoroff #Cryptocurrency Security #cyber_espionage #macOS Malware #North Korea APT #phishing #Session Hijacking #social engineering #UNC1069 #Web3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:14:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlueNoroff #Cryptocurrency Security #cyber_espionage #macOS Malware #North Korea APT #phishing #Session Hijacking #social engineering #UNC1069 #Web3
Daily CyberSecurity
The Billion-Dollar Invite: How UNC1069’s Fake Meetings Hijack Crypto Fortunes
North Korean group UNC1069 (BlueNoroff) targets Web3 with fake Zoom/Teams links. 164 domains blocked. Secure your crypto assets and browser extensions now!
⤷ Title: Industrial Key Leak: Critical 9.3 CVSS Flaws Expose Mitsubishi’s GENESIS64 and ICONICS Suite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:46:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Disclosure #CVE_2025_14815 #CVE_2025_14816 #GENESIS64 #ICONICS Suite #ICS #Industrial Security #infosec #Mitsubishi Electric #SCADA #sql server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:46:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Disclosure #CVE_2025_14815 #CVE_2025_14816 #GENESIS64 #ICONICS Suite #ICS #Industrial Security #infosec #Mitsubishi Electric #SCADA #sql server
Daily CyberSecurity
Industrial Key Leak: Critical 9.3 CVSS Flaws Expose Mitsubishi’s GENESIS64 and ICONICS Suite
Mitsubishi Electric warns of 9.3 CVSS flaws in GENESIS64 & ICONICS. Attackers can leak SQL credentials to destroy or tamper with industrial data. Patch now!
⤷ Title: Critical SSRF Flaw Discovered in Axios – CVE-2025-62718 (CVSS 9.3)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:35:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2025_62718 #data exfiltration #Hostname Normalization #infosec #NO_PROXY #Node.js Security #ssrf #vulnerability management #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:35:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2025_62718 #data exfiltration #Hostname Normalization #infosec #NO_PROXY #Node.js Security #ssrf #vulnerability management #web development
Daily CyberSecurity
Critical SSRF Flaw Discovered in Axios - CVE-2025-62718 (CVSS 9.3)
Axios CVE-2025-62718 allows a critical NO_PROXY bypass via hostname normalization errors. Protect your internal network from SSRF—patch or normalize today!
⤷ Title: ⚙️ 11. — Method-based Access Control Can Be Circumvented
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:15:07 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #portswigger #bug_bounty
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:15:07 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #portswigger #bug_bounty
Medium
⚙️ 11. — Method-based Access Control Can Be Circumvented
⚙️ 11. — Method-based Access Control Can Be Circumvented Difficulty: 🟡 Practitioner Goal: 🔍 Log in as administrator:admin → promote carlos via the admin panel → capture POST …
⤷ Title: ⚙️ 10. — URL-based Access Control Can Be Circumvented — X -Original-URL
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:13:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #bug_bounty #portswigger
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:13:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #bug_bounty #portswigger
Medium
⚙️ 10. — URL-based Access Control Can Be Circumvented — X -Original-URL
⚙️ 10. — URL-based Access Control Can Be Circumvented — X -Original-URL Difficulty: 🟡 Practitioner Goal: 🔍 Confirm that GET /admin is blocked by a front-end system — the plain …
⤷ Title: This AI Can Find Bugs Faster Than Humans So Why Can’t We Use It
════════════════════════
𐀪 Author: Anuja Gadde
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:45:22 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #hacking #technology #cybersecurity #data_science
════════════════════════
𐀪 Author: Anuja Gadde
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:45:22 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #hacking #technology #cybersecurity #data_science
Medium
This AI Can Find Bugs Faster Than Humans So Why Can’t We Use It
A few days ago, I came across a report about a new AI system from Anthropic that isn’t being released to the public.
⤷ Title: CAPen Review: A Well Rounded Web Security Exam That Keeps You on Your Toes
════════════════════════
𐀪 Author: Crowx01
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:01:05 GMT
════════════════════════
⌗ Tags: #web_application_security #the_secops_group #penetration_testing #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Crowx01
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:01:05 GMT
════════════════════════
⌗ Tags: #web_application_security #the_secops_group #penetration_testing #ethical_hacking #cybersecurity
Medium
CAPen Review: A Well Rounded Web Security Exam That Keeps You on Your Toes
My honest take on the Certified AppSec Pentester exam the highs, the hard questions, and what to prepare for.
⤷ Title: Server-side Template Injection in a Sandboxed Environment
════════════════════════
𐀪 Author: Ⓥ
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:51:19 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #portswigger #penetration_testing
════════════════════════
𐀪 Author: Ⓥ
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 01:51:19 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #portswigger #penetration_testing
Medium
Server-side Template Injection in a Sandboxed Environment
This lab demonstrates a server-side template injection vulnerability in a poorly sandboxed Freemarker template engine. We will exploit the…
⤷ Title: The Proxifier Trap: The “Fileless” Marathon Stealing Your Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:15:18 +0000
════════════════════════
⌗ Tags: #Malware #ClipBanker #Cryptocurrency Theft #Fileless Malware #GitHub Malware #infosec #kaspersky #powershell #Proxifier #SEO Poisoning #Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:15:18 +0000
════════════════════════
⌗ Tags: #Malware #ClipBanker #Cryptocurrency Theft #Fileless Malware #GitHub Malware #infosec #kaspersky #powershell #Proxifier #SEO Poisoning #Trojan
Daily CyberSecurity
The Proxifier Trap: The "Fileless" Marathon Stealing Your Crypto
Kaspersky reveals a fileless Trojan campaign targeting Proxifier searches. Learn how this "ClipBanker" hijacks crypto wallets via search engine poisoning.
⤷ Title: Payroll Pirates in the North: Microsoft Unmasks ‘Storm-2755’ and the Theft of Canadian Salaries
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:11:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM Attack #Canada Cyber Threat #cybersecurity #HR Security #MFA Bypass #Microsoft DART #Payroll Fraud #phishing #SEO Poisoning #Storm_2755 #Workday Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:11:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM Attack #Canada Cyber Threat #cybersecurity #HR Security #MFA Bypass #Microsoft DART #Payroll Fraud #phishing #SEO Poisoning #Storm_2755 #Workday Security
Daily CyberSecurity
Payroll Pirates in the North: Microsoft Unmasks 'Storm-2755' and the Theft of Canadian Salaries
Microsoft DART uncovers Storm-2755, a "payroll pirate" using AiTM traps and SEO poisoning to steal salaries. Protect your organization from this MFA bypass.
⤷ Title: Inside Canis C2: The ‘Wide Open’ Surveillance Engine Targeting Every Major OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 03:00:53 +0000
════════════════════════
⌗ Tags: #Malware #AI_assisted development #AiTM #Android APK #Canis C2 #cyber_espionage #Hunt.io #iOS Malware #malware #Paidy #phishing #surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 03:00:53 +0000
════════════════════════
⌗ Tags: #Malware #AI_assisted development #AiTM #Android APK #Canis C2 #cyber_espionage #Hunt.io #iOS Malware #malware #Paidy #phishing #surveillance
Daily CyberSecurity
Inside Canis C2: The 'Wide Open' Surveillance Engine Targeting Every Major OS
Hunt.io discovers Canis C2, an AI-assisted surveillance framework targeting all major OSs. An exposed API revealed payloads and source code. Read more here.
⤷ Title: VPN Security Alert: Synology Patches Flaws in SSL VPN Client
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:00:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2021_47960 #CVE_2021_47961 #Data Disclosure #infosec #Patch Alert #Remote Work Security #SSL VPN Client #Synology #Traffic Interception #VPN security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:00:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2021_47960 #CVE_2021_47961 #Data Disclosure #infosec #Patch Alert #Remote Work Security #SSL VPN Client #Synology #Traffic Interception #VPN security
Daily CyberSecurity
VPN Security Alert: Synology Patches Flaws in SSL VPN Client
Synology urges SSL VPN Client users to update to v1.4.5-0684. Fixes critical 8.1 CVSS flaw allowing PIN theft and traffic interception. Secure your data now!
⤷ Title: XSS Cross-Site Scripting Zero Se Hero: Browser Ko Apna Weapon Banao! (Hinglish Mein)
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:36:01 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #xss_attack #web_security #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:36:01 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #xss_attack #web_security #bug_bounty #ethical_hacking
Medium
XSS Cross-Site Scripting Zero Se Hero: Browser Ko Apna Weapon Banao! (Hinglish Mein)
Series: Bug Bounty Zero se Hero 🦸 | Article #14 By HackerMD | 20 min read
⤷ Title: Business Logic Bugs — The Highest Paying (But Most Missed)
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:25:10 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #linux #security #hacking
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:25:10 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #linux #security #hacking
Medium
💰 Business Logic Bugs — The Highest Paying (But Most Missed)
✍️ Introduction
⤷ Title: When OAuth Bypasses Email Restrictions — A Simple Signup Logic Flaw
════════════════════════
𐀪 Author: StrangeRwhite
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 03:52:49 GMT
════════════════════════
⌗ Tags: #infosec #security #bug_bounty_writeup #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: StrangeRwhite
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 03:52:49 GMT
════════════════════════
⌗ Tags: #infosec #security #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Medium
When OAuth Bypasses Email Restrictions — A Simple Signup Logic Flaw
Hey everyone! It’s been a while… hope you didn’t forget me 😄
⤷ Title: Offenso Hackers Academy
════════════════════════
𐀪 Author: Mohammed Farhanoff
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:34:21 GMT
════════════════════════
⌗ Tags: #kerala #cybersecurity #offenso_hackers_academy #hacking #ethical_hacking
════════════════════════
𐀪 Author: Mohammed Farhanoff
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:34:21 GMT
════════════════════════
⌗ Tags: #kerala #cybersecurity #offenso_hackers_academy #hacking #ethical_hacking
Medium
Offenso Hackers Academy
Offenso Hackers Academy offers the best ethical hacking course in Kerala, with training centers in Kochi, Calicut and Trivandrum. Learn…
⤷ Title: Polkadot’s DOT hit by hack triggering unauthorized minting on Ethereum
════════════════════════
𐀪 Author: Coin Headlines
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:11:31 GMT
════════════════════════
⌗ Tags: #polkadot_news #hacking #cryptocurrency_news #cryptocurrency
════════════════════════
𐀪 Author: Coin Headlines
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:11:31 GMT
════════════════════════
⌗ Tags: #polkadot_news #hacking #cryptocurrency_news #cryptocurrency
Medium
Polkadot’s DOT hit by hack triggering unauthorized minting on Ethereum
Polkadot’s native $DOT token has faced a hack that led to a large volume of unauthorized minting on the Ethereum network.
⤷ Title: DHCP Inside Out: The Complete Guide to Dynamic Host Configuration Protocol
════════════════════════
𐀪 Author: Sumit Sah
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:16:01 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #dhcp #networking #network_security
════════════════════════
𐀪 Author: Sumit Sah
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 04:16:01 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #dhcp #networking #network_security
Medium
DHCP Inside Out: The Complete Guide to Dynamic Host Configuration Protocol
Imagine booting up your laptop in a coffee shop, hotel, or enterprise office. Within seconds, you’re online — no manual IP configuration…