⤷ Title: TryHackMe — VulnNet: Active: Writeup
════════════════════════
𐀪 Author: Taher Borgi
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 19:11:05 GMT
════════════════════════
⌗ Tags: #active_directory #penetration_testing #cybersecurity #tryhackme #ethical_hacking
════════════════════════
𐀪 Author: Taher Borgi
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 19:11:05 GMT
════════════════════════
⌗ Tags: #active_directory #penetration_testing #cybersecurity #tryhackme #ethical_hacking
Medium
TryHackMe — VulnNet: Active: Writeup
Room: VulnNet: Active Difficulty: Medium Operating System: Windows Made by: @SkyWaves
⤷ Title: No Macros Required: Harvesting AD Credentials with a Simple Word Doc
════════════════════════
𐀪 Author: Will Giles | Cybersecurity
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 19:07:53 GMT
════════════════════════
⌗ Tags: #social_engineering #active_directory #active_directory_security #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Will Giles | Cybersecurity
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 19:07:53 GMT
════════════════════════
⌗ Tags: #social_engineering #active_directory #active_directory_security #cybersecurity #penetration_testing
Medium
No Macros Required: Harvesting AD Credentials with a Simple Word Doc
Exploring how a simple phishing email can turn a curious click into compromised domain credentials.
⤷ Title: LOOKBACK - TRY HACK ME- ROOM
════════════════════════
𐀪 Author: 5kullk3r
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 20:06:01 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #cybersecurity #ctf #tryhackme_writeup
════════════════════════
𐀪 Author: 5kullk3r
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 20:06:01 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #cybersecurity #ctf #tryhackme_writeup
Medium
LOOKBACK - TRY HACK ME- ROOM
Hello everyone! This is an easy rated room from the TryHackMe platform titled “LOOKBACK”
⤷ Title: The Next.js Nightmare? Vercel Investigates “Critical” Internal Breach and Supply Chain Threat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:59:43 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity news #Data Breach #github #infosec #Next.js #npm #Secret Rotation #ShinyHunters #supply chain attack #Turbo.js #Vercel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:59:43 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity news #Data Breach #github #infosec #Next.js #npm #Secret Rotation #ShinyHunters #supply chain attack #Turbo.js #Vercel
Daily CyberSecurity
The Next.js Nightmare? Vercel Investigates "Critical" Internal Breach and Supply Chain Threat
Vercel investigates a major breach by ShinyHunters. With Next.js source code and tokens at risk, developers must rotate secrets immediately. Stay updated.
⤷ Title: 7 ferramentas de engenharia social
════════════════════════
𐀪 Author: Moprius
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 00:15:26 GMT
════════════════════════
⌗ Tags: #osint #information_security #hacking #technology #cybersecurity
════════════════════════
𐀪 Author: Moprius
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 00:15:26 GMT
════════════════════════
⌗ Tags: #osint #information_security #hacking #technology #cybersecurity
Medium
7 ferramentas de engenharia social
Há um ponto em que a conversa sobre engenharia social deixa de ser abstrata e passa a tocar a infraestrutura concreta do ataque. É aí que…
⤷ Title: I created security agents workflow that auto review your PRs on Azure , Github and Gitlab
════════════════════════
𐀪 Author: Jay@ Thinkode AI +
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:08:14 GMT
════════════════════════
⌗ Tags: #browser_extension #cloud_security #penetration_testing #code_review
════════════════════════
𐀪 Author: Jay@ Thinkode AI +
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:08:14 GMT
════════════════════════
⌗ Tags: #browser_extension #cloud_security #penetration_testing #code_review
Medium
I created security agents workflow that auto review your PRs on Azure , Github and Gitlab
Hello peer developers,
⤷ Title: From Second-Order SQLi to Full RCE: Breaking Through Filters in a Multi-Tenant Export Engine
════════════════════════
𐀪 Author: Omar Elshopky (3l5h0pky)
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:02:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #cybersecurity #sql_injection #postgresql
════════════════════════
𐀪 Author: Omar Elshopky (3l5h0pky)
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:02:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_development #cybersecurity #sql_injection #postgresql
Medium
From Second-Order SQLi to Full RCE: Breaking Through Filters in a Multi-Tenant Export Engine
Turning a constrained second-order SQL injection into full RCE by bypassing filters using PostgreSQL tricks and payload reconstruction.
⤷ Title: Root Access Unlocked: FortiSandbox CVE-2026-39808 Details and PoC Exploit Publicly Disclosed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:26:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_39808 #CWE_78 #Exploit Disclosure #Fortinet Security #FortiSandbox #infosec #Patch Alert #PoC #rce #root access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:26:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_39808 #CWE_78 #Exploit Disclosure #Fortinet Security #FortiSandbox #infosec #Patch Alert #PoC #rce #root access
Daily CyberSecurity
Root Access Unlocked: FortiSandbox CVE-2026-39808 Details and PoC Exploit Publicly Disclosed
Critical 9.1 CVSS flaw in FortiSandbox: Full PoC & details for CVE-2026-39808 are now public. Unauthenticated root RCE is possible. Upgrade to 4.4.9 immediately.
⤷ Title: JanaWare’s 5-Year Geofenced Ransomware Reign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:05:39 +0000
════════════════════════
⌗ Tags: #Malware #Acronis TRU #Adwind RAT #cybersecurity #Geofencing #infosec #JanaWare #phishing #Polymorphic Malware #ransomware #SMB Security #Turkey
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:05:39 +0000
════════════════════════
⌗ Tags: #Malware #Acronis TRU #Adwind RAT #cybersecurity #Geofencing #infosec #JanaWare #phishing #Polymorphic Malware #ransomware #SMB Security #Turkey
Daily CyberSecurity
JanaWare’s 5-Year Geofenced Ransomware Reign
Acronis uncovers JanaWare, a persistent ransomware targeting Turkey since 2020. Discover how geofencing and polymorphism keep this threat in the shadows.
⤷ Title: Windows Snipping Tool Can Leak Your Identity, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:47:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #Blackarrow #Deep Link #Exploit Code #Microsoft Security #ms_screensketch #NTLM Disclosure #proof_of_concept #Tarlogic #Windows Snipping Tool #Windows vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:47:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #Blackarrow #Deep Link #Exploit Code #Microsoft Security #ms_screensketch #NTLM Disclosure #proof_of_concept #Tarlogic #Windows Snipping Tool #Windows vulnerability
Daily CyberSecurity
Windows Snipping Tool Can Leak Your Identity, PoC Available
Detailed PoC and exploit code for CVE-2026-33829 are now public. See how the Windows Snipping Tool can leak NTLM hashes and how to patch the flaw.
⤷ Title: The CVE Watchtower: Weekly Threat Intelligence Briefing (April 13 – April 19, 2026)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:29:13 +0000
════════════════════════
⌗ Tags: #Weekly Recap #AI Infrastructure #Apache ActiveMQ #CISA KEV #CVE_2026_21643 #cybersecurity #Fortinet #Legacy Software Security #MCP Security #Model Context Protocol #vulnerability management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:29:13 +0000
════════════════════════
⌗ Tags: #Weekly Recap #AI Infrastructure #Apache ActiveMQ #CISA KEV #CVE_2026_21643 #cybersecurity #Fortinet #Legacy Software Security #MCP Security #Model Context Protocol #vulnerability management
Daily CyberSecurity
The CVE Watchtower: Weekly Threat Intelligence Briefing (April 13 – April 19, 2026)
This week's digest: 1,214 new bugs, including active exploits on 2009 Excel fossils and critical 10.0 flaws in new AI/MCP infrastructure. Priority: Patch now.
⤷ Title: More Than a Miner: The Evasive MiningDropper Framework Hijacking Android Worldwide
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:00:34 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #BTMOB #cybersecurity #Cyble #infosec #Infostealer #Lumolight #Malware Delivery Framework #MiningDropper #mobile security #rat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:00:34 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #BTMOB #cybersecurity #Cyble #infosec #Infostealer #Lumolight #Malware Delivery Framework #MiningDropper #mobile security #rat
Daily CyberSecurity
More Than a Miner: The Evasive MiningDropper Framework Hijacking Android Worldwide
Cyble reveals MiningDropper, a modular Android threat delivering RATs and infostealers via multi-stage payloads. Protect your mobile devices now.
⤷ Title: Overwatch || HTB Machine | Lab
════════════════════════
𐀪 Author: #UNKNOWN
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:55:10 GMT
════════════════════════
⌗ Tags: #hackthebox #hacks #hacking #ethical_hacking
════════════════════════
𐀪 Author: #UNKNOWN
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:55:10 GMT
════════════════════════
⌗ Tags: #hackthebox #hacks #hacking #ethical_hacking
Medium
Overwatch || HTB Machine | Lab
STEP I: Start with basic enumeration part using nmap
⤷ Title: Your API Keys Aren’t Safe — And the Vercel Incident Proves It
════════════════════════
𐀪 Author: RipeLemons
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:05:15 GMT
════════════════════════
⌗ Tags: #hacking #security #ai #software_development #api
════════════════════════
𐀪 Author: RipeLemons
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 02:05:15 GMT
════════════════════════
⌗ Tags: #hacking #security #ai #software_development #api
Medium
🚨 Your API Keys Aren’t Safe — And the Vercel Incident Proves It
🚨 Your API Keys Aren’t Safe — And the Vercel Incident Proves It If you believe your credentials are safe because you’re using a trusted platform… you’re trusting the wrong …
⤷ Title: Reconstruct any Unity game with Coding Agents
════════════════════════
𐀪 Author: Alex Zeez
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:48:26 GMT
════════════════════════
⌗ Tags: #game_development #agentic_workflow #hacking #reverse_engineering #unity
════════════════════════
𐀪 Author: Alex Zeez
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:48:26 GMT
════════════════════════
⌗ Tags: #game_development #agentic_workflow #hacking #reverse_engineering #unity
Medium
Reconstruct any Unity game with Coding Agents
In 2026, de-compile, rip assets, and reconstruct nearly any C# Unity game, even if obfuscated. To prove it, I’ll show you how I did it.
⤷ Title: Vercel Got Powned By An OAuth App. Again… Here Is What Happened and What You Should Do
════════════════════════
𐀪 Author: Mandar Karhade, MD. PhD.
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:47:47 GMT
════════════════════════
⌗ Tags: #hacking #generative_ai_tools #software_development #ai_agent #artificial_intelligence
════════════════════════
𐀪 Author: Mandar Karhade, MD. PhD.
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:47:47 GMT
════════════════════════
⌗ Tags: #hacking #generative_ai_tools #software_development #ai_agent #artificial_intelligence
Medium
Vercel Got Powned By An OAuth App. Again… Here Is What Happened and What You Should Do
And if you installed the same AI tool they did, you’re already in the blast radius.
⤷ Title: Ferramentas para hacking e auditoria
════════════════════════
𐀪 Author: Moprius
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:32:32 GMT
════════════════════════
⌗ Tags: #information_security #red_team #penetration_testing #cybersecurity #hacking
════════════════════════
𐀪 Author: Moprius
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:32:32 GMT
════════════════════════
⌗ Tags: #information_security #red_team #penetration_testing #cybersecurity #hacking
Medium
Ferramentas para hacking e auditoria
A fragilidade de um sistema quase nunca se revela à primeira vista. A superfície parece estável, o serviço responde, a autenticação…
⤷ Title: Strored Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:16:16 GMT
════════════════════════
⌗ Tags: #stored_xss #css #csrf #xss_vulnerability #xss_attack
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:16:16 GMT
════════════════════════
⌗ Tags: #stored_xss #css #csrf #xss_vulnerability #xss_attack
Medium
Strored Xss
Stored XSS, where the malicious script comes from the website’s database, also known as second-order or persistent XSS.
⤷ Title: SQL injection UNION attack that retrieves data from other tables
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:03:47 GMT
════════════════════════
⌗ Tags: #union_attack #sql_injection
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 01:03:47 GMT
════════════════════════
⌗ Tags: #union_attack #sql_injection
Medium
SQL injection UNION attack that retrieves data from other tables
This is a combination of different techniques to successfully retrieve data from other tables using UNION attack
⤷ Title: Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 09:05:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 09:05:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: The Protocol That Learns from IPv6: Why the New IPv8 Draft Is Built to Save IPv4
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 03:48:36 +0000
════════════════════════
⌗ Tags: #Technology #Autonomous System Number #BGP8 #CGNAT #Data Center #IETF #Internet Protocol #IPv4 #IPv6 #IPv8 #IT Infrastructure #network_security #Networking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 03:48:36 +0000
════════════════════════
⌗ Tags: #Technology #Autonomous System Number #BGP8 #CGNAT #Data Center #IETF #Internet Protocol #IPv4 #IPv6 #IPv8 #IT Infrastructure #network_security #Networking
Daily CyberSecurity
The Protocol That Learns from IPv6: Why the New IPv8 Draft Is Built to Save IPv4
Industry stakeholders submit the IPv8 draft to the IETF. Discover how its 64-bit address space and 100% IPv4 backward compatibility aim to end address exhaustion.