⤷ Title: Part 2 — (CVE-2026–5429) AWS Kiro WebView XSS to Remote Code Execution
════════════════════════
𐀪 Author: Dhiraj
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 17:28:57 GMT
════════════════════════
⌗ Tags: #aws_kiro #rce_vulnerability #kiro #5429 #aws
════════════════════════
𐀪 Author: Dhiraj
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 17:28:57 GMT
════════════════════════
⌗ Tags: #aws_kiro #rce_vulnerability #kiro #5429 #aws
Medium
Part 2 — (CVE-2026–5429) AWS Kiro WebView XSS to Remote Code Execution
Trust the Plugin, Own the Developer — again. Kiro Agent WebView XSS via workspace led to RCE. Where unsanitized input during web page…
⤷ Title: Business Logic vulnerability
════════════════════════
𐀪 Author: Divine
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:21:41 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #web_security
════════════════════════
𐀪 Author: Divine
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:21:41 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_development #web_security
Medium
Business Logic vulnerability
Business Logic vulnerability Business logic are set of rules that dictate how an application behaves for example payment must be made before an order is confirmed. These rules are encoded in the …
⤷ Title: “THE HOSPITAL” write-up
════════════════════════
𐀪 Author: Cybersenseieh
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 20:25:35 GMT
════════════════════════
⌗ Tags: #web_exploitation #hacking #ctf_writeup #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Cybersenseieh
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 20:25:35 GMT
════════════════════════
⌗ Tags: #web_exploitation #hacking #ctf_writeup #ethical_hacking #cybersecurity
Medium
“THE HOSPITAL” write-up
This is a walk-through on the vault challenge titled “The hospital”; a web exploitation lab rated easy on the CTFroom platform. From the…
⤷ Title: Docker — A Nonsense Guide
════════════════════════
𐀪 Author: Ishant
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:47:50 GMT
════════════════════════
⌗ Tags: #software_development #docker #cybersecurity #web_development #hacking
════════════════════════
𐀪 Author: Ishant
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:47:50 GMT
════════════════════════
⌗ Tags: #software_development #docker #cybersecurity #web_development #hacking
Medium
Docker — A Nonsense Guide
When you move deeper into development or cybersecurity, you’ll eventually hit the problem of “it works on my machine” vs “it breaks…
⤷ Title: Hiding root detection using eBPF — kernel-level syscall interception
════════════════════════
𐀪 Author: Haxymad
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:11:21 GMT
════════════════════════
⌗ Tags: #reverse_engineering #cybersecurity #security #hacking #rasp
════════════════════════
𐀪 Author: Haxymad
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:11:21 GMT
════════════════════════
⌗ Tags: #reverse_engineering #cybersecurity #security #hacking #rasp
Medium
Hiding root detection using eBPF — kernel-level syscall interception
Hiding root detection from the kernel using eBPF
⤷ Title: Worker Factory Start Routine Injection
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 20:55:05 GMT
════════════════════════
⌗ Tags: #pentesting #cyber_security_awareness #infosec #cybersecurity #malware
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 20:55:05 GMT
════════════════════════
⌗ Tags: #pentesting #cyber_security_awareness #infosec #cybersecurity #malware
Medium
Worker Factory Start Routine Injection
Welcome to a new Medium post. In this article, I’ll walk you through an interesting and practical process injection technique presented by…
⤷ Title: AI Models & Data Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:14:14 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme_walkthrough #tryhackme #ai_security #cybersecurity
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 19:14:14 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme_walkthrough #tryhackme #ai_security #cybersecurity
Medium
AI Models & Data Walkthrough Notes | TryHackMe
AI models and data notes from TryHackMe room overview
⤷ Title: Attackers Actively Exploiting Critical Vulnerability in Ninja Forms — File Upload Plugin
════════════════════════
𐀪 Author: Wordfence
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 21:27:04 GMT
════════════════════════
⌗ Tags: #wordpress #bug_bounty #cybersecurity_news #wordpress_security #cybersecurity
════════════════════════
𐀪 Author: Wordfence
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 21:27:04 GMT
════════════════════════
⌗ Tags: #wordpress #bug_bounty #cybersecurity_news #wordpress_security #cybersecurity
Medium
Attackers Actively Exploiting Critical Vulnerability in Ninja Forms — File Upload Plugin
⤷ Title: TryHackMe: Defensive Security Intro Writeup
════════════════════════
𐀪 Author: Jonathan Sanfer
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 21:36:39 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #infosec #digital_forensics #blue_team
════════════════════════
𐀪 Author: Jonathan Sanfer
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 21:36:39 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #infosec #digital_forensics #blue_team
Medium
TryHackMe: Defensive Security Intro Writeup
Introduction
⤷ Title: OT/ICS: Introduction · TryHackMe Walkthrough
════════════════════════
𐀪 Author: RosanaFSS
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 22:03:11 GMT
════════════════════════
⌗ Tags: #technology #tryhackme_walkthrough #ethical_hacking #tryhackme #cybersecurity
════════════════════════
𐀪 Author: RosanaFSS
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 22:03:11 GMT
════════════════════════
⌗ Tags: #technology #tryhackme_walkthrough #ethical_hacking #tryhackme #cybersecurity
Medium
OT/ICS: Introduction · TryHackMe Walkthrough
Learn what Operational Technology (OT) and Industrial Control Systems (ICS) are, and how they function.
⤷ Title: Guía Completa de Vulnerabilidades JWT: Detección, Explotación y Bypass de WAF
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #technology #cybersecurity #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 00:01:01 GMT
════════════════════════
⌗ Tags: #hacking #technology #cybersecurity #bug_bounty #penetration_testing
Medium
Guía Completa de Vulnerabilidades JWT: Detección, Explotación y Bypass de WAF
Domina los fundamentos de JSON Web Tokens, metodologías de ataque como Key Confusion y estrategias avanzadas de bypass de seguridad.
⤷ Title: Password Reset Token Remains Valid After Email Change Leading to Account Takeover .
════════════════════════
𐀪 Author: Ali Mostafa
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 23:11:04 GMT
════════════════════════
⌗ Tags: #web_security #owasp_top_10 #account_takeover #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Ali Mostafa
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 23:11:04 GMT
════════════════════════
⌗ Tags: #web_security #owasp_top_10 #account_takeover #cybersecurity #bug_bounty
Medium
Password Reset Token Remains Valid After Email Change Leading to Account Takeover .
Introduction :
⤷ Title: C*pher*torm CTF Wr*te-Up
════════════════════════
𐀪 Author: isa ergişi
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 00:11:15 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ctf #penetration_testing #cybersecurity #red_team
════════════════════════
𐀪 Author: isa ergişi
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 00:11:15 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ctf #penetration_testing #cybersecurity #red_team
Medium
C*pher*torm CTF Wr*te-Up
Post-Exploitation Focused Analysis
⤷ Title: 220 Million at Risk: Critical 9.4 CVSS Remote Code Execution Hits protobuf.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVSS 9.4 #infosec #JavaScript Security #Node.js Security #Patch Alert #protobuf.js #Protocol Buffers #rce #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:54:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVSS 9.4 #infosec #JavaScript Security #Node.js Security #Patch Alert #protobuf.js #Protocol Buffers #rce #web development
Daily CyberSecurity
220 Million at Risk: Critical 9.4 CVSS Remote Code Execution Hits protobuf.js
A critical 9.4 CVSS vulnerability in protobuf.js puts 220 million monthly downloads at risk of RCE. Patch your Node.js and browser apps to version 8.0.1+.
⤷ Title: High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@angular/platform_server #Angular #CVE #infosec #javascript #Origin Hijacking #Server_Side Rendering #SSR #ssrf #TypeScript #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #@angular/platform_server #Angular #CVE #infosec #javascript #Origin Hijacking #Server_Side Rendering #SSR #ssrf #TypeScript #Web Security
Daily CyberSecurity
High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering
Angular patches a critical 8.7 SSRF flaw in @angular/platform-server. Attackers can hijack SSR origins via URL normalization. Patch v19, v20, or v21 now!
⤷ Title: CISA Adds Critical Apache ActiveMQ RCE Flaw to KEV Catalog
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:53:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache ActiveMQ #CISA KEV #CVE_2026_34197 #cybersecurity #infosec #Jolokia #Message Broker Security #Patch Alert #rce #Remote Code Execution #Spring Framework
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:53:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache ActiveMQ #CISA KEV #CVE_2026_34197 #cybersecurity #infosec #Jolokia #Message Broker Security #Patch Alert #rce #Remote Code Execution #Spring Framework
Daily CyberSecurity
CISA Adds Critical Apache ActiveMQ RCE Flaw to KEV Catalog
CISA adds CVE-2026-34197 to KEV. Apache ActiveMQ's Jolokia bridge flaw allows RCE via remote Spring XML loading. Remediate by April 30, 2026. Patch now!
⤷ Title: The Invisible Patch: How PolinRider Rewrites Git History to Hide North Korean Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #DPRK #Git History #github #infosec #Lazarus Group #malware #North Korea #PolinRider #supply chain attack #TasksJacker #VS Code Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #DPRK #Git History #github #infosec #Lazarus Group #malware #North Korea #PolinRider #supply chain attack #TasksJacker #VS Code Extensions
Daily CyberSecurity
The Invisible Patch: How PolinRider Rewrites Git History to Hide North Korean Malware
Security researchers from the OpenSourceMalware (OSM) team have uncovered a massive and rapidly expanding threat campaign targeting the heart of the developer ecosystem. The actor, dubbed PolinRid…
⤷ Title: How I Hunt Threats Without Any Alerts
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:39:41 GMT
════════════════════════
⌗ Tags: #programming #threat_hunting #bug_bounty #cybersecurity #hacking
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:39:41 GMT
════════════════════════
⌗ Tags: #programming #threat_hunting #bug_bounty #cybersecurity #hacking
Medium
How I Hunt Threats Without Any Alerts
Waiting for the SIEM to fire is how you miss the things that matter most.
⤷ Title: Article 1: Points Are Money: The Case for LARS ( Loyalty Application Risk Scoring) Framework
════════════════════════
𐀪 Author: Tanmay Bhattacharjee
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:05:26 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bug_bounty #penetration_testing #information_security #cybersecurity
════════════════════════
𐀪 Author: Tanmay Bhattacharjee
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:05:26 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bug_bounty #penetration_testing #information_security #cybersecurity
Medium
Article 1: Points Are Money: The Case for LARS ( Loyalty Application Risk Scoring) Framework
3:14 AM
⤷ Title: The $10,000 Tap: How “Convenience” Created a Multi-Thousand Dollar Security Hole
════════════════════════
𐀪 Author: Purvansh Bhatt
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:19:32 GMT
════════════════════════
⌗ Tags: #red_team #online_payments #hacking #man_in_the_middle_attack #cybersecurity_awareness
════════════════════════
𐀪 Author: Purvansh Bhatt
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:19:32 GMT
════════════════════════
⌗ Tags: #red_team #online_payments #hacking #man_in_the_middle_attack #cybersecurity_awareness
Medium
The $10,000 Tap: How “Convenience” Created a Multi-Thousand Dollar Security Hole
A recent demonstration by Veritasium, featuring tech reviewer MKBHD and cybersecurity researchers from the University of Surrey, just…
⤷ Title: Weekly Threat Intelligence Report 13 Apr 2026
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:09:28 GMT
════════════════════════
⌗ Tags: #threat_intelligence #cyberattack #infosec #hacking #cybersecurity
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 02:09:28 GMT
════════════════════════
⌗ Tags: #threat_intelligence #cyberattack #infosec #hacking #cybersecurity
Medium
Weekly Threat Intelligence Report 13 Apr 2026
This document summarizes key cyber threats identified between Apr 6 and Apr 12, 2026, including related threat events