⤷ Title: Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
Daily CyberSecurity
Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
Froxlor faces two critical flaws, including a CVSS 10. Learn how path traversal and config injection allow persistent RCE. Patch your server management today!
⤷ Title: Critical Command Injection Flaw Hits upKeeper Instant Privilege Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:03:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admin Rights #Argument Injection #CVE_2026_2449 #CWE_88 #infosec #LocalSystem #Patch Alert #privilege escalation #upKeeper #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:03:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admin Rights #Argument Injection #CVE_2026_2449 #CWE_88 #infosec #LocalSystem #Patch Alert #privilege escalation #upKeeper #Windows Security
Daily CyberSecurity
Critical Command Injection Flaw Hits upKeeper Instant Privilege Access
Critical 9.1 flaw in upKeeper Instant Privilege allows standard users to gain LocalSystem rights via command injection. Patch to v1.6.0.4576 immediately.
⤷ Title: ⚙️ 13. — Referer — Based Access Control
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:11:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #portswigger #web_security #cybersecurity
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:11:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #portswigger #web_security #cybersecurity
Medium
⚙️ 13. — Referer — Based Access Control
Difficulty: 🟡 Practitioner
⤷ Title: ⚙️ 12. — Multi-step process with no access control on one step
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #bug_bounty #portswigger
════════════════════════
𐀪 Author: The4v1
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #bug_bounty #portswigger
Medium
⚙️ 12. — Multi-step process with no access control on one step
Difficulty: 🟡 Practitioner
⤷ Title: I hacked deeper into a network without moving — here’s how SSH pivoting works
════════════════════════
𐀪 Author: Saswata Mohapatra || Ringo
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:22:53 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #networking #penetration_testing #infosec
════════════════════════
𐀪 Author: Saswata Mohapatra || Ringo
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:22:53 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #networking #penetration_testing #infosec
Medium
I hacked deeper into a network without moving — here’s how SSH pivoting works
Last week, I was staring at a machine I couldn’t reach. The firewall was blocking me. Every tool timed out. Then I remembered — I didn’t…
⤷ Title: When AI Becomes the Attacker: Inside a 195 Million Record Cyber Breach
════════════════════════
𐀪 Author: Sharanraju
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:45:07 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #data_breach #infosec #cybersecurity
════════════════════════
𐀪 Author: Sharanraju
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:45:07 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #data_breach #infosec #cybersecurity
Medium
🚨 When AI Becomes the Attacker: Inside a 195 Million Record Cyber Breach
It didn’t take a massive hacking group.
⤷ Title: Detecting Web Attacks: Reconstructing an Attack from Logs and Network Traffic
════════════════════════
𐀪 Author: Rishit Goel
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 10:50:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #network_security #infosec #blue_team #data_breach
════════════════════════
𐀪 Author: Rishit Goel
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 10:50:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #network_security #infosec #blue_team #data_breach
Medium
Detecting Web Attacks: Reconstructing an Attack from Logs and Network Traffic
A real-world walkthrough of how attackers are detected through patterns, logs, and network traffic
⤷ Title: CyberWarFare Labs — Certified Cyber Security Engineer [CCSE] — My Experience and Review
════════════════════════
𐀪 Author: Chicken0248
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:12:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberwarfare_labs #cybersecurity_engineer #penetration_testing
════════════════════════
𐀪 Author: Chicken0248
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:12:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberwarfare_labs #cybersecurity_engineer #penetration_testing
Medium
CyberWarFare Labs — Certified Cyber Security Engineer [CCSE] — My Experience and Review
Hello everyone, it’s me, Chicken0248, back again with another course and exam I just passed — the Certified Cyber Security Engineer (CCSE)…
⤷ Title: TryHackMe | LLMborghini | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:20:20 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #prompt_injection #ctf #tryhackme
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:20:20 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #prompt_injection #ctf #tryhackme
Medium
TryHackMe | LLMborghini | WriteUp
Put your indirect prompt injection skills to the test in this AI security challenge.
⤷ Title: SigHunt — TryHackMe
════════════════════════
𐀪 Author: Nway Nway Zay Ya
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:55:40 GMT
════════════════════════
⌗ Tags: #detection_engineering #tryhackme_walkthrough #tryhackme #cybersecurity #writeup
════════════════════════
𐀪 Author: Nway Nway Zay Ya
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:55:40 GMT
════════════════════════
⌗ Tags: #detection_engineering #tryhackme_walkthrough #tryhackme #cybersecurity #writeup
Medium
SigHunt — TryHackMe
This is my walkthrough for SigHunt, a premium room from TryHackMe, part of the Detection Engineering module and SOC Level 2 learning path.
⤷ Title: Securing AI Systems Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:53:03 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme_walkthrough #ai_security #ai_systems #tryhackme
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:53:03 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme_walkthrough #ai_security #ai_systems #tryhackme
Medium
Securing AI Systems Walkthrough Notes | TryHackMe
Securing AI systems by mapping risks and applying security practices
⤷ Title: AI Threat Modelling — Tryhackme
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:21:01 GMT
════════════════════════
⌗ Tags: #tryhackme_answer #ai_threat_modelling #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:21:01 GMT
════════════════════════
⌗ Tags: #tryhackme_answer #ai_threat_modelling #tryhackme #tryhackme_walkthrough
Medium
AI Threat Modelling — Tryhackme
Warning: For educational purposes only.
⤷ Title: Securing AI Systems — Tryhackme
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:11:01 GMT
════════════════════════
⌗ Tags: #tryhackme_answer #securing_ai_systems #tryhackme
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:11:01 GMT
════════════════════════
⌗ Tags: #tryhackme_answer #securing_ai_systems #tryhackme
Medium
Securing AI Systems — Tryhackme
Warning: For educational purposes only.
⤷ Title: Prompt Engineering — tryhackme
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:06:01 GMT
════════════════════════
⌗ Tags: #questions_answers #tryhackme #prompt_engineering
════════════════════════
𐀪 Author: Andreyna Marques Carvalho
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:06:01 GMT
════════════════════════
⌗ Tags: #questions_answers #tryhackme #prompt_engineering
Medium
Prompt Engineering — tryhackme
Warning: For educational purposes only.
⤷ Title: Kali Linux Commands Every Beginner Must Know | by Karanam Shrivasta (15 years old )
════════════════════════
𐀪 Author: Karanam Shrivasta
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ai #technology #cybersecur #machine_learning
════════════════════════
𐀪 Author: Karanam Shrivasta
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ai #technology #cybersecur #machine_learning
Medium
Kali Linux Commands Every Beginner Must Know | by Karanam Shrivasta (15 years old )
Karanam Shrivasta 15-year-old cybersecurity enthusiast with 300+ badges and 170+ certifications.
⤷ Title: Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 18:51:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 18:51:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:00:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Cybersecurity #DDOS #FortiGuard #Fortinet #IoT #Mirai #Nexcorium #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:00:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Cybersecurity #DDOS #FortiGuard #Fortinet #IoT #Mirai #Nexcorium #Vulnerability
Hackread
New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks
Fortinet team has discovered Nexcorium, a new Mirai-based malware targeting TBK DVR systems to turn them into a botnet for DDoS attacks.
⤷ Title: Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
Daily CyberSecurity
Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
Thymeleaf 3.1.4 fixes two critical 9.1 CVSS vulnerabilities. Unauthenticated attackers can bypass security for SSTI. Audit your user input and patch today!
⤷ Title: Critical 9.1 CVSS Flaw in Horner Automation PLCs Invites Industrial Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:05:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #brute force attack #Cscape #CVE_2026_6284 #Horner Automation #ICS security #industrial control systems #PLC #SCADA Security #XL4 #XL7
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:05:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #brute force attack #Cscape #CVE_2026_6284 #Horner Automation #ICS security #industrial control systems #PLC #SCADA Security #XL4 #XL7
Daily CyberSecurity
Critical 9.1 CVSS Flaw in Horner Automation PLCs Invites Industrial Takeovers
Critical 9.1 CVSS flaw in Horner Automation PLCs allows unauthenticated brute force attacks. Secure your industrial systems—patch XL4, XL7, and Cscape now!
⤷ Title: Account Takeover via OAuth Redirect Uri Manipulation
════════════════════════
𐀪 Author: Skysenz
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:43:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Skysenz
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:43:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
Medium
Account Takeover via OAuth Redirect Uri Manipulation
Dalam dunia aplikasi web modern, OAuth telah menjadi standar untuk fitur “Social Login” (Login dengan Google, Facebook, dkk). Meskipun…
⤷ Title: Race Condition Exploitation in Poll Systems: How I Manipulated Votes with a Single Account
════════════════════════
𐀪 Author: Jonathangeorge
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:36:23 GMT
════════════════════════
⌗ Tags: #race_condition #bug_bounty #hackerone #ethical_hacking #bug_bounty_writeup
════════════════════════
𐀪 Author: Jonathangeorge
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:36:23 GMT
════════════════════════
⌗ Tags: #race_condition #bug_bounty #hackerone #ethical_hacking #bug_bounty_writeup
Medium
Race Condition Exploitation in Poll Systems: How I Manipulated Votes with a Single Account
While testing a bug bounty program on HackerOne, I discovered a forum where users can interact with each other. The forum allows users to…