⤷ Title: Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 18:51:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 18:51:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:00:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Cybersecurity #DDOS #FortiGuard #Fortinet #IoT #Mirai #Nexcorium #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:00:59 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Cybersecurity #DDOS #FortiGuard #Fortinet #IoT #Mirai #Nexcorium #Vulnerability
Hackread
New Mirai Variant Nexcorium Hijacks DVR Devices for DDoS Attacks
Fortinet team has discovered Nexcorium, a new Mirai-based malware targeting TBK DVR systems to turn them into a botnet for DDoS attacks.
⤷ Title: Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:30:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40477 #CVE_2026_40478 #infosec #Java security #Patch Alert #rce #Server Side Template Injection #Spring Security #ssti #Thymeleaf #web development
Daily CyberSecurity
Critical 9.1 SSTI Flaws Unmasked in Thymeleaf Template Engine
Thymeleaf 3.1.4 fixes two critical 9.1 CVSS vulnerabilities. Unauthenticated attackers can bypass security for SSTI. Audit your user input and patch today!
⤷ Title: Critical 9.1 CVSS Flaw in Horner Automation PLCs Invites Industrial Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:05:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #brute force attack #Cscape #CVE_2026_6284 #Horner Automation #ICS security #industrial control systems #PLC #SCADA Security #XL4 #XL7
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:05:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #brute force attack #Cscape #CVE_2026_6284 #Horner Automation #ICS security #industrial control systems #PLC #SCADA Security #XL4 #XL7
Daily CyberSecurity
Critical 9.1 CVSS Flaw in Horner Automation PLCs Invites Industrial Takeovers
Critical 9.1 CVSS flaw in Horner Automation PLCs allows unauthenticated brute force attacks. Secure your industrial systems—patch XL4, XL7, and Cscape now!
⤷ Title: Account Takeover via OAuth Redirect Uri Manipulation
════════════════════════
𐀪 Author: Skysenz
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:43:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Skysenz
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:43:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
Medium
Account Takeover via OAuth Redirect Uri Manipulation
Dalam dunia aplikasi web modern, OAuth telah menjadi standar untuk fitur “Social Login” (Login dengan Google, Facebook, dkk). Meskipun…
⤷ Title: Race Condition Exploitation in Poll Systems: How I Manipulated Votes with a Single Account
════════════════════════
𐀪 Author: Jonathangeorge
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:36:23 GMT
════════════════════════
⌗ Tags: #race_condition #bug_bounty #hackerone #ethical_hacking #bug_bounty_writeup
════════════════════════
𐀪 Author: Jonathangeorge
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:36:23 GMT
════════════════════════
⌗ Tags: #race_condition #bug_bounty #hackerone #ethical_hacking #bug_bounty_writeup
Medium
Race Condition Exploitation in Poll Systems: How I Manipulated Votes with a Single Account
While testing a bug bounty program on HackerOne, I discovered a forum where users can interact with each other. The forum allows users to…
⤷ Title: ⚡ Cross-Site Scripting (XSS) — From Input to Browser Control
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:55:44 GMT
════════════════════════
⌗ Tags: #security #hacking #linux #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:55:44 GMT
════════════════════════
⌗ Tags: #security #hacking #linux #bug_bounty #cybersecurity
Medium
⚡ Cross-Site Scripting (XSS) — From Input to Browser Control
✍️ Introduction
⤷ Title: From Image Upload to Admin Panel: How a Simple SSRF Led to Massive PII Disclosure and earned $$$$
════════════════════════
𐀪 Author: Sagar Dhoot
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:50:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec #ssrf #ethical_hacking
════════════════════════
𐀪 Author: Sagar Dhoot
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:50:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec #ssrf #ethical_hacking
Medium
From Image Upload to Admin Panel: How a Simple SSRF Led to Massive PII Disclosure and earned $$$$
Some vulnerabilities start with complex exploit chains. Others start with a profile picture upload.
⤷ Title: How I Made €200 Just by Changing a Response
════════════════════════
𐀪 Author: Dheeraj
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:19:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #penetration_testing #web_security #cybersecurity
════════════════════════
𐀪 Author: Dheeraj
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:19:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #bug_bounty #penetration_testing #web_security #cybersecurity
Medium
How I Made €200 Just by Changing a Response
No complex payloads.
No SQL injection.
No brute force.
No SQL injection.
No brute force.
⤷ Title: One AI Tool. 17 Organizations Destroyed.
════════════════════════
𐀪 Author: Dark Energy Articles
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:38:40 GMT
════════════════════════
⌗ Tags: #ai #hacking #technology #science #cybersecurity
════════════════════════
𐀪 Author: Dark Energy Articles
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:38:40 GMT
════════════════════════
⌗ Tags: #ai #hacking #technology #science #cybersecurity
Medium
One AI Tool. 17 Organizations Destroyed.
Cybersecurity has always been a cat-and-mouse game between defenders and attackers. But in late 2025, the mouse got superpowers. A lone…
⤷ Title: Load Testing at Scale: I Stress-Tested My API with k6
════════════════════════
𐀪 Author: Navanath Jadhav
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:24:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #backend_development #software_development #programming #coding
════════════════════════
𐀪 Author: Navanath Jadhav
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:24:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #backend_development #software_development #programming #coding
Medium
Load Testing at Scale: I Stress-Tested My API with k6
“How many users can your API actually handle?”
⤷ Title: Burp Suite Was Blind to This App Until I Found the HTTP/2 Issue
════════════════════════
𐀪 Author: Selamawit Alemu
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:34:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #http2 #burpsuite #penetration_testing
════════════════════════
𐀪 Author: Selamawit Alemu
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:34:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_security #http2 #burpsuite #penetration_testing
Medium
Burp Suite Was Blind to This App Until I Found the HTTP/2 Issue
When Burp/ZAP Miss Traffic: Debugging HTTP/2 Issues in a Web App
⤷ Title: Title: My First Penetration Testing Agreement — What I Built and What I Learned.
════════════════════════
𐀪 Author: Yankho Funsani
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:29:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Yankho Funsani
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:29:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing
Medium
Title: My First Penetration Testing Agreement — What I Built and What I Learned.
Title: My First Penetration Testing Agreement — What I Built and What I Learned. The Assignment As part of my cybersecurity learning journey with #ParoCyber, I was tasked with drafting a …
⤷ Title: TryHackMe — “Letter” Room Walkthrough
════════════════════════
𐀪 Author: Dharmik Varia
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:58:53 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #tryhackme_writeup #osint #cybersecurity
════════════════════════
𐀪 Author: Dharmik Varia
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:58:53 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #tryhackme_writeup #osint #cybersecurity
Medium
TryHackMe — “Letter” Room Walkthrough
Room Link: https://tryhackme.com/room/letter
Difficulty: Easy
Category: OSINT / Historical Research
Difficulty: Easy
Category: OSINT / Historical Research
⤷ Title: Prompt Injection | TryHackMe
════════════════════════
𐀪 Author: Binish Alamgir
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:41:51 GMT
════════════════════════
⌗ Tags: #prompt_injection #ai_security #tryhackme #prompt_security
════════════════════════
𐀪 Author: Binish Alamgir
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:41:51 GMT
════════════════════════
⌗ Tags: #prompt_injection #ai_security #tryhackme #prompt_security
Medium
Prompt Injection | TryHackMe
Task 1 Introduction:
⤷ Title: GLITCH — TryHackMe Write-up (Command Injection + Privilege Escalation)
════════════════════════
𐀪 Author: Bruno Porfiro
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:21:43 GMT
════════════════════════
⌗ Tags: #pentesting #tryhackme_writeup #tryhackme #ctf_writeup #ctf
════════════════════════
𐀪 Author: Bruno Porfiro
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:21:43 GMT
════════════════════════
⌗ Tags: #pentesting #tryhackme_writeup #tryhackme #ctf_writeup #ctf
Medium
GLITCH — TryHackMe Write-up (Command Injection + Privilege Escalation)
Introdução
⤷ Title: Introduction to the World of OT/ICS
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:03:20 GMT
════════════════════════
⌗ Tags: #ics_security #tryhackme_writeup #ot_security #tryhackme_walkthrough #tryhackme
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 14:03:20 GMT
════════════════════════
⌗ Tags: #ics_security #tryhackme_writeup #ot_security #tryhackme_walkthrough #tryhackme
Medium
Introduction to the World of OT/ICS
Learn what Operational Technology (OT) and Industrial Control Systems (ICS) are, and how they function.
⤷ Title: Data Representation Walkthrough (TryHackMe)
════════════════════════
𐀪 Author: ittz_Madushan
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:57:25 GMT
════════════════════════
⌗ Tags: #data_representation #tryhackme #walkthrough
════════════════════════
𐀪 Author: ittz_Madushan
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 13:57:25 GMT
════════════════════════
⌗ Tags: #data_representation #tryhackme #walkthrough
Medium
Data Representation Walkthrough (TryHackMe)
In this Write-up, We will explore how computers represent numbers and colors. Data Representation room by TryHackMe
⤷ Title: Tomghost — TryHackMe WalkThrough
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:56:04 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #cybersecurity #tryhackme_walkthrough #ctf
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:56:04 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #cybersecurity #tryhackme_walkthrough #ctf
Medium
Tomghost — TryHackMe WalkThrough
Date: 17/04/2026
⤷ Title: Bug Bounty 2026: Why the “End of the World” is Actually a $500k Opportunity
════════════════════════
𐀪 Author: EMTIAZ AHMED
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 15:39:41 GMT
════════════════════════
⌗ Tags: #security #hacking #ai_security #bug_bounty #bounties
════════════════════════
𐀪 Author: EMTIAZ AHMED
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 15:39:41 GMT
════════════════════════
⌗ Tags: #security #hacking #ai_security #bug_bounty #bounties
Medium
Bug Bounty 2026: Why the “End of the World” is Actually a $500k Opportunity
The “death” of bug bounty hunting has been predicted every year since 2015. Yet, here we are in 2026, and the industry is more lucrative —…
⤷ Title: Mirage (LFI) WebVerse
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 16:11:01 GMT
════════════════════════
⌗ Tags: #hacking #lfi #ctf_writeup #ctf #webverse
════════════════════════
𐀪 Author: 7s26Simon
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 16:11:01 GMT
════════════════════════
⌗ Tags: #hacking #lfi #ctf_writeup #ctf #webverse
Medium
Mirage (LFI) WebVerse
Lab can be found at: https://webverselabs-pro.com/