⤷ Title: JUMPSEC Unmasks Iranian ‘Muddy Water’ Using Russian ‘CastleRAT’ Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 02:05:45 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #browser hijacking #CastleRAT #ChainShell #cyber_espionage #Ethereum C2 #HVNC #Iranian APT #JUMPSEC #Malware_as_a_Service #MFA Bypass #Muddy Water
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 02:05:45 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #browser hijacking #CastleRAT #ChainShell #cyber_espionage #Ethereum C2 #HVNC #Iranian APT #JUMPSEC #Malware_as_a_Service #MFA Bypass #Muddy Water
Daily CyberSecurity
JUMPSEC Unmasks Iranian 'Muddy Water' Using Russian 'CastleRAT' Malware
Iranian state actor Muddy Water adopts CastleRAT and ChainShell to hijack browsers and bypass MFA invisibly. A professional-grade shift in APT strategy.
⤷ Title: OpenStack Keystone Flaw Grants Access to Disabled LDAP Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:57:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Cloud Security #Dalmatian #Epoxy #Flamingo #Gazpacho #Identity Management #Keystone #LDAP #OpenStack #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:57:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Cloud Security #Dalmatian #Epoxy #Flamingo #Gazpacho #Identity Management #Keystone #LDAP #OpenStack #Patch Alert
Daily CyberSecurity
OpenStack Keystone Flaw Grants Access to Disabled LDAP Users
OpenStack Keystone vulnerability allows disabled LDAP users to authenticate. Logic flaw in attribute mapping affects releases up to 2026.1. Patch now!
⤷ Title: Urgent Patch Alert: SharePoint Spoofing Under Active Attack as Microsoft Releases April 2026 Updates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:42:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #April 2026 #CISA KEV #CVE_2026_32201 #infosec #Microsoft #Patch Tuesday #rce #Sharepoint #Windows Security #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:42:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #April 2026 #CISA KEV #CVE_2026_32201 #infosec #Microsoft #Patch Tuesday #rce #Sharepoint #Windows Security #zero_day
Daily CyberSecurity
Urgent Patch Alert: SharePoint Spoofing Under Active Attack as Microsoft Releases April 2026 Updates
Microsoft’s April 2026 Patch Tuesday fixes 163 flaws, including an exploited SharePoint spoofing bug (CVE-2026-32201). Patch by April 28 per CISA mandate.
⤷ Title: 108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #browser security #C2 Infrastructure #Chrome extensions #cybersecurity #Google OAuth #infosec #malware #Session Hijacking #Socket Research #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #browser security #C2 Infrastructure #Chrome extensions #cybersecurity #Google OAuth #infosec #malware #Session Hijacking #Socket Research #Telegram
Daily CyberSecurity
108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
Socket identifies 108 malicious Chrome extensions stealing Telegram sessions and Google IDs. 20,000 installs hit—audit your browser extensions immediately!
⤷ Title: TryHackMe: Offensive Security Intro Writeup
════════════════════════
𐀪 Author: Jonathan Sanfer
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:23:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #infosec #tryhackme #cybersecurity #technology
════════════════════════
𐀪 Author: Jonathan Sanfer
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:23:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #infosec #tryhackme #cybersecurity #technology
Medium
TryHackMe: Offensive Security Intro Writeup
Introduction
⤷ Title: FBI and Indonesian Authorities Dismantle Prolific “W3LL” Phishing Empire
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 04:25:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime Takedown #FBI Atlanta #Indonesian National Police #MaaS #Malware_as_a_Service #MFA Bypass #Phishing_as_a_Service #Session Hijacking #W3LL Phishing Kit #W3LLSTORE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 04:25:52 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime Takedown #FBI Atlanta #Indonesian National Police #MaaS #Malware_as_a_Service #MFA Bypass #Phishing_as_a_Service #Session Hijacking #W3LL Phishing Kit #W3LLSTORE
Daily CyberSecurity
FBI and Indonesian Authorities Dismantle Prolific "W3LL" Phishing Empire
The FBI and Indonesia dismantle W3LL, a $20M phishing kit that bypassed MFA and hijacked live sessions. Learn about the takedown of this MaaS powerhouse.
⤷ Title: Adobe Rushes Patches for Critical ColdFusion RCE and Security Bypasses
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:18:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe #ColdFusion #ColdFusion 2025 #CVE_2026_27304 #CVE_2026_27306 #cybersecurity #infosec #Patch Alert #Path Traversal #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:18:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe #ColdFusion #ColdFusion 2025 #CVE_2026_27304 #CVE_2026_27306 #cybersecurity #infosec #Patch Alert #Path Traversal #rce #Remote Code Execution
Daily CyberSecurity
Adobe Rushes Patches for Critical ColdFusion RCE and Security Bypasses
Adobe patches critical RCE and security bypass flaws in ColdFusion 2023 & 2025. Protect your enterprise servers from takeover—update to the latest version now.
⤷ Title: Critical 9.1 Flaws Hit Fortinet FortiSandbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:07:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_39808 #CVE_2026_39813 #cybersecurity #Fortinet #FortiSandbox #infosec #os command injection #Patch Alert #Path Traversal #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:07:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_39808 #CVE_2026_39813 #cybersecurity #Fortinet #FortiSandbox #infosec #os command injection #Patch Alert #Path Traversal #rce
Daily CyberSecurity
Critical 9.1 Flaws Hit Fortinet FortiSandbox
Fortinet issues a critical 9.1 CVSS alert for FortiSandbox. Unauthenticated auth bypass and command injection risks. Patch to 5.0.6 or 4.4.9 immediately.
⤷ Title: Injection Attacks — From User Input to Full System Control
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 04:47:32 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #linux #security #cybersecurity
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 04:47:32 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #linux #security #cybersecurity
Medium
💉 Injection Attacks — From User Input to Full System Control
✍️ Introduction
⤷ Title: ⚙️ 13. — Referer — Based Access Control
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:03:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #portswigger #bug_bounty
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:03:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #portswigger #bug_bounty
Medium
⚙️ 13. — Referer — Based Access Control
⚙️ 13. — Referer — Based Access Control Difficulty: 🟡 Practitioner Goal: 🔍 Log in as administrator:admin → promote carlos → capture GET /admin-roles?username=carlos&action=upgrade …
⤷ Title: ⚙️ 12. — Multi-step process with no access control on one step
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:03:11 GMT
════════════════════════
⌗ Tags: #portswigger #web_security #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:03:11 GMT
════════════════════════
⌗ Tags: #portswigger #web_security #bug_bounty #cybersecurity
Medium
⚙️ 12. — Multi-step process with no access control on one step
⚙️ 12. — Multi-step process with no access control on one step Difficulty: 🟡 Practitioner Goal: 🔍 Log in as administrator:admin → browse to /admin → promote carlos — observe the …
⤷ Title: AI Models & Data (THM) Tryhackme Walkthrough
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #artificial_intelligence #hacking #ai_security
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 03:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #artificial_intelligence #hacking #ai_security
Medium
AI Models & Data (THM) Tryhackme Walkthrough
Description : Explore how data is fundamental to AI security, and the models which power it.
⤷ Title: OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 10:00:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 10:00:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: The “Graphalgo” Evolution: How North Korea Built a Fake Florida LLC to Hack Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:24:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #github #Graphalgo #infosec #Job Scam #malware #North Korea #phishing #rat #ReversingLabs #social engineering #Typo_squatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:24:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #github #Graphalgo #infosec #Job Scam #malware #North Korea #phishing #rat #ReversingLabs #social engineering #Typo_squatting
Daily CyberSecurity
The "Graphalgo" Evolution: How North Korea Built a Fake Florida LLC to Hack Developers
North Korea’s "graphalgo" campaign uses fake job interviews and real Florida LLCs to infect developers. Learn how to spot this sophisticated state-sponsored trap.
⤷ Title: Automated Pen Testing Writing Custom Burp Extensions with Python and Jython
════════════════════════
𐀪 Author: Shreyash Mall
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 19:50:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #automation #python #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Shreyash Mall
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 19:50:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #automation #python #penetration_testing #bug_bounty
Medium
Automated Pen Testing: Writing Custom Burp Extensions with Python and Jython
If you do any serious bug bounty hunting or penetration testing, you already know the pain. You end up clicking through the exact same…
⤷ Title: Beyond Pentesting: Why Your 2026 Cybersecurity Training Must Include AI-Threat Hunting
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:25:20 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #ai #hacking
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:25:20 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #ai #hacking
Medium
Beyond Pentesting: Why Your 2026 Cybersecurity Training Must Include AI-Threat Hunting
The cybersecurity landscape has reached a tipping point. As we navigate through 2026, the traditional “cat and mouse” game between hackers…
⤷ Title: The CPUID/CPU-Z Hack Explained
════════════════════════
𐀪 Author: Solvenite
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:25:19 GMT
════════════════════════
⌗ Tags: #cyber_security_incident #security #cybersecurity #hacking #cpu
════════════════════════
𐀪 Author: Solvenite
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:25:19 GMT
════════════════════════
⌗ Tags: #cyber_security_incident #security #cybersecurity #hacking #cpu
Medium
The CPUID/CPU-Z Hack Explained
Security Incident · April 9–10, 2026 · cpuid.com · STX RAT
⤷ Title: Can AI Fully Automate Pentesting?
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:58:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #pentesting #artificial_intelligence #ethical_hacking
════════════════════════
𐀪 Author: Redfox Security
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:58:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #pentesting #artificial_intelligence #ethical_hacking
Medium
Can AI Fully Automate Pentesting?
Artificial intelligence(AI) is transforming nearly every industry, and cybersecurity is no exception. Over the last few years, AI-powered…
⤷ Title: Survival in the 20-Hour Window: Why the Mythos Storm Makes Traditional Scanning Insufficient in…
════════════════════════
𐀪 Author: Eldor Zufarov
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:52:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #ciso #infosec #mythos2026 #appsec
════════════════════════
𐀪 Author: Eldor Zufarov
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:52:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #ciso #infosec #mythos2026 #appsec
Medium
Survival in the 20-Hour Window: Why the Mythos Storm Makes Traditional Scanning Insufficient in Isolation
By Eldor Zufarov, Founder of Auditor Core
⤷ Title: Man-in-the-Middle: Intercepting Trust in Transit
════════════════════════
𐀪 Author: Cybersphere Official
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 05:01:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #network_security #mitm #web_security #infosec
════════════════════════
𐀪 Author: Cybersphere Official
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 05:01:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #network_security #mitm #web_security #infosec
Medium
Man-in-the-Middle: Intercepting Trust in Transit
Context
⤷ Title: The Hidden Playbook: 15 “Secrets” Every Penetration Tester Learns the Hard Way
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:41:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 06:41:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing
Medium
🔐 The Hidden Playbook: 15 “Secrets” Every Penetration Tester Learns the Hard Way
What if I told you that most real-world hacks don’t look anything like what you see in movies?