⤷ Title: ClickFix 2026: New AppleScript Malware Held macOS Users Hostage for Passwords
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:11:34 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #ClickFix #Crypto theft #cybersecurity #Infostealer #macOS #macOS Tahoe #malware #Netskope #phishing #Session Hijacking #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:11:34 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #ClickFix #Crypto theft #cybersecurity #Infostealer #macOS #macOS Tahoe #malware #Netskope #phishing #Session Hijacking #social engineering
Daily CyberSecurity
ClickFix 2026: New AppleScript Malware Held macOS Users Hostage for Passwords
Netskope uncovers a ClickFix macOS campaign that holds the UI hostage to steal system passwords, Keychains, and 200+ browser extensions.
⤷ Title: Fuzzing 101: How Security Researchers Find Bugs Before Hackers Do
════════════════════════
𐀪 Author: Parth Patel
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:31:01 GMT
════════════════════════
⌗ Tags: #software_engineering #hacking #vulnerability_research #cybersecurity #programming
════════════════════════
𐀪 Author: Parth Patel
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:31:01 GMT
════════════════════════
⌗ Tags: #software_engineering #hacking #vulnerability_research #cybersecurity #programming
Medium
🔬 Fuzzing 101: How Security Researchers Find Bugs Before Hackers Do
Some of the most critical vulnerabilities ever found — in browsers, operating systems, and cryptographic libraries — were discovered…
⤷ Title: Agent T Challenge — Fixed Python code| TryHackMe
════════════════════════
𐀪 Author: Tengku M Zulfadli
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:49:50 GMT
════════════════════════
⌗ Tags: #tryhackme #nmap #python_programming #gobuster
════════════════════════
𐀪 Author: Tengku M Zulfadli
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:49:50 GMT
════════════════════════
⌗ Tags: #tryhackme #nmap #python_programming #gobuster
Medium
Agent T Challenge — Fixed Python code| TryHackMe
Agent T discovered a website that looks fairly normal at first, but after a bit of interaction, something doesn’t quite feel right with the…
⤷ Title: OWASP API Security Top 10–1 | MayankNingania | TryHackMe
════════════════════════
𐀪 Author: Mayank Ningania
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:25:28 GMT
════════════════════════
⌗ Tags: #mayankningania #owasp_api_security_top_10 #tryhackme_walkthrough #tryhackme_writeup #tryhackme
════════════════════════
𐀪 Author: Mayank Ningania
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:25:28 GMT
════════════════════════
⌗ Tags: #mayankningania #owasp_api_security_top_10 #tryhackme_walkthrough #tryhackme_writeup #tryhackme
Medium
OWASP API Security Top 10–1 | MayankNingania | TryHackMe
Task 1 : Introduction
⤷ Title: CSP bypass and Dangling Markup Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:58:15 GMT
════════════════════════
⌗ Tags: #xss_attack #css #xs #content_security_policy #cross_site_scripting
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:58:15 GMT
════════════════════════
⌗ Tags: #xss_attack #css #xs #content_security_policy #cross_site_scripting
Medium
CSP bypass and Dangling Markup Xss
🧠 What is CSP?
⤷ Title: DOM Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:57:54 GMT
════════════════════════
⌗ Tags: #xs #jquery #css #xss_attack #dom_xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:57:54 GMT
════════════════════════
⌗ Tags: #xs #jquery #css #xss_attack #dom_xss
Medium
DOM Xss
What is the DOM?
⤷ Title: Blind SQL injection with time delays and information retrieval
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:47:09 GMT
════════════════════════
⌗ Tags: #conditional_time_delay #sql_injection #blind_sql_injection
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:47:09 GMT
════════════════════════
⌗ Tags: #conditional_time_delay #sql_injection #blind_sql_injection
Medium
Blind SQL injection with time delays and information retrieval
A time delay can be triggered to determine the outcome of the query
⤷ Title: Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:15:52 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2026_41651 #Debian #Fedora #infosec #Linux Security #Pack2TheRoot #PackageKit #Patch Alert #privilege escalation #race condition #Root Exploit #Ubuntu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:15:52 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2026_41651 #Debian #Fedora #infosec #Linux Security #Pack2TheRoot #PackageKit #Patch Alert #privilege escalation #race condition #Root Exploit #Ubuntu
Daily CyberSecurity
Linux Privilege Escalation: "Pack2TheRoot" Flaw Impacts Major Distributions
The critical "Pack2TheRoot" flaw (CVE-2026-41651) in PackageKit gives root access on Linux. It went undetected for 12 years. Update to version 1.3.5 now!
⤷ Title: Over 400,000 WordPress Sites at Risk as “Breeze” Plugin Zero-Day Is Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:08:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Upload #Breeze #Cloudways #CVE_2026_3844 #CVSS 9.8 #PHP Web Shell #Plugin Vulnerability #rce #Wordfence #WordPress Exploit #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:08:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Upload #Breeze #Cloudways #CVE_2026_3844 #CVSS 9.8 #PHP Web Shell #Plugin Vulnerability #rce #Wordfence #WordPress Exploit #wordpress security
Daily CyberSecurity
Over 400,000 WordPress Sites at Risk as "Breeze" Plugin Zero-Day Is Exploited in the Wild
Critical 9.8 CVSS RCE hits 400,000+ WordPress sites using the Breeze plugin. Attackers are exploiting arbitrary file uploads. Update to v2.4.5 immediately!
⤷ Title: Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo!
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:31:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #web_security #ethical_hacking #infosec
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:31:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #web_security #ethical_hacking #infosec
Medium
Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo! (Hinglish Mein)
Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo! (Hinglish Mein) Series: Bug Bounty Zero se Hero 🦸 | Article #21 By HackerMD | 17 min read Aaj Kya …
⤷ Title: Session Management Bugs — The Hidden Goldmine in Bug Bounty
════════════════════════
𐀪 Author: Pradeeptadi
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:16:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Pradeeptadi
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:16:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
Medium
🔐 Session Management Bugs — The Hidden Goldmine in Bug Bounty
🔐 Session Management Bugs — The Hidden Goldmine in Bug Bounty Most hackers focus on: - XSS - SQL Injection - 403 bypass But they ignore one of the most critical areas: 👉 Session …
⤷ Title: Cisco notes Network Basics — Module 16:Application Service Layer
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:46:23 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #networking #infosec #ethical_hacking
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:46:23 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #networking #infosec #ethical_hacking
Medium
Cisco notes Network Basics — Module 16:Application Service Layer
Client and Server Interaction
Every day, we use the services available over networks and the internet to communicate with others and to…
Every day, we use the services available over networks and the internet to communicate with others and to…
⤷ Title: Cisco notes Network Basics — Module 15:TCP and UDP
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:45:10 GMT
════════════════════════
⌗ Tags: #ethical_hacking #information_security #web_development #infosec #cybersecurity
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:45:10 GMT
════════════════════════
⌗ Tags: #ethical_hacking #information_security #web_development #infosec #cybersecurity
Medium
Cisco notes Network Basics — Module 15:TCP and UDP
“The transport layer in both the TCP/IP and OSI models is responsible for ensuring packets are sent reliably and any missing packets are…
⤷ Title: OWASP APTS
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:59:24 GMT
════════════════════════
⌗ Tags: #ai #ai_pentesting #penetration_testing #owasp
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:59:24 GMT
════════════════════════
⌗ Tags: #ai #ai_pentesting #penetration_testing #owasp
Medium
OWASP APTS
Imagine you hired a robot burglar to try breaking into your house — not to steal, but to show you where the weak locks are. Useful, right…
⤷ Title: Blind SQL injection with out-of-band data exfiltration
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:02:30 GMT
════════════════════════
⌗ Tags: #out_of_band_interaction #dns_lookup #blind_sql_injection #sql_injection
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:02:30 GMT
════════════════════════
⌗ Tags: #out_of_band_interaction #dns_lookup #blind_sql_injection #sql_injection
Medium
Blind SQL injection with out-of-band data exfiltration
The SQL query does not return any visible response, but it can trigger an out-of-band interaction that delivers the result through a…
⤷ Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Daily CyberSecurity
Void Dokkaebi Unmasked: The "Worm-Like" Supply Chain Threat Targeting Developers
Void Dokkaebi turns developers into vectors. With 750+ infected repos and malicious VS Code tasks, this supply chain worm is hunting your CI/CD and crypto.
⤷ Title: $800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:15 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:15 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
Medium
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin Hi Everyone! I recently discovered a Broken Access Control / Privilege Escalation vulnerability in a SaaS platform …
⤷ Title: When “Safe” Isn’t Safe: Turning a Simple HTML Injection into a Real Security Story.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:02:19 GMT
════════════════════════
⌗ Tags: #user_input #injection #content_security_policy #bug_bounty #htmli
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:02:19 GMT
════════════════════════
⌗ Tags: #user_input #injection #content_security_policy #bug_bounty #htmli
Medium
When “Safe” Isn’t Safe: Turning a Simple HTML Injection into a Real Security Story.
In bug bounty hunting, not every vulnerability needs flashy payloads or JavaScript execution to matter. Sometimes, the simplest flaws —…
⤷ Title: $800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:14 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:14 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
Medium
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin Hi Everyone! I recently discovered a Broken Access Control / Privilege Escalation vulnerability in a SaaS platform …
⤷ Title: Rate Limiting Failures: How Attackers Abuse APIs
════════════════════════
𐀪 Author: Cybersphere Official
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:51:19 GMT
════════════════════════
⌗ Tags: #application_security #infosec #cybersecurity #web_security #api_security
════════════════════════
𐀪 Author: Cybersphere Official
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:51:19 GMT
════════════════════════
⌗ Tags: #application_security #infosec #cybersecurity #web_security #api_security
Medium
Rate Limiting Failures: How Attackers Abuse APIs
Context
⤷ Title: Best VAPT Services | ConsultEdge Global
════════════════════════
𐀪 Author: Consultedgeglobal
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:40:03 GMT
════════════════════════
⌗ Tags: #cert_in #vapt_services #consultedge_global #cloud_devsecops #application_security
════════════════════════
𐀪 Author: Consultedgeglobal
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:40:03 GMT
════════════════════════
⌗ Tags: #cert_in #vapt_services #consultedge_global #cloud_devsecops #application_security
Medium
Best VAPT Services | ConsultEdge Global
ConsultEdge Global provides trusted VAPT services to detect and fix security vulnerabilities in applications, networks, and systems. We…