⤷ Title: CSP bypass and Dangling Markup Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:58:15 GMT
════════════════════════
⌗ Tags: #xss_attack #css #xs #content_security_policy #cross_site_scripting
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:58:15 GMT
════════════════════════
⌗ Tags: #xss_attack #css #xs #content_security_policy #cross_site_scripting
Medium
CSP bypass and Dangling Markup Xss
🧠 What is CSP?
⤷ Title: DOM Xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:57:54 GMT
════════════════════════
⌗ Tags: #xs #jquery #css #xss_attack #dom_xss
════════════════════════
𐀪 Author: 13v! ⚔️
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:57:54 GMT
════════════════════════
⌗ Tags: #xs #jquery #css #xss_attack #dom_xss
Medium
DOM Xss
What is the DOM?
⤷ Title: Blind SQL injection with time delays and information retrieval
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:47:09 GMT
════════════════════════
⌗ Tags: #conditional_time_delay #sql_injection #blind_sql_injection
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:47:09 GMT
════════════════════════
⌗ Tags: #conditional_time_delay #sql_injection #blind_sql_injection
Medium
Blind SQL injection with time delays and information retrieval
A time delay can be triggered to determine the outcome of the query
⤷ Title: Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:15:52 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2026_41651 #Debian #Fedora #infosec #Linux Security #Pack2TheRoot #PackageKit #Patch Alert #privilege escalation #race condition #Root Exploit #Ubuntu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:15:52 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2026_41651 #Debian #Fedora #infosec #Linux Security #Pack2TheRoot #PackageKit #Patch Alert #privilege escalation #race condition #Root Exploit #Ubuntu
Daily CyberSecurity
Linux Privilege Escalation: "Pack2TheRoot" Flaw Impacts Major Distributions
The critical "Pack2TheRoot" flaw (CVE-2026-41651) in PackageKit gives root access on Linux. It went undetected for 12 years. Update to version 1.3.5 now!
⤷ Title: Over 400,000 WordPress Sites at Risk as “Breeze” Plugin Zero-Day Is Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:08:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Upload #Breeze #Cloudways #CVE_2026_3844 #CVSS 9.8 #PHP Web Shell #Plugin Vulnerability #rce #Wordfence #WordPress Exploit #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:08:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Upload #Breeze #Cloudways #CVE_2026_3844 #CVSS 9.8 #PHP Web Shell #Plugin Vulnerability #rce #Wordfence #WordPress Exploit #wordpress security
Daily CyberSecurity
Over 400,000 WordPress Sites at Risk as "Breeze" Plugin Zero-Day Is Exploited in the Wild
Critical 9.8 CVSS RCE hits 400,000+ WordPress sites using the Breeze plugin. Attackers are exploiting arbitrary file uploads. Update to v2.4.5 immediately!
⤷ Title: Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo!
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:31:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #web_security #ethical_hacking #infosec
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:31:01 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #web_security #ethical_hacking #infosec
Medium
Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo! (Hinglish Mein)
Backup Files + .env Exposure Developers Ki Sabse Badi Galti: Config Files Se Credentials Nikalo! (Hinglish Mein) Series: Bug Bounty Zero se Hero 🦸 | Article #21 By HackerMD | 17 min read Aaj Kya …
⤷ Title: Session Management Bugs — The Hidden Goldmine in Bug Bounty
════════════════════════
𐀪 Author: Pradeeptadi
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:16:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Pradeeptadi
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:16:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty
Medium
🔐 Session Management Bugs — The Hidden Goldmine in Bug Bounty
🔐 Session Management Bugs — The Hidden Goldmine in Bug Bounty Most hackers focus on: - XSS - SQL Injection - 403 bypass But they ignore one of the most critical areas: 👉 Session …
⤷ Title: Cisco notes Network Basics — Module 16:Application Service Layer
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:46:23 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #networking #infosec #ethical_hacking
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:46:23 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #networking #infosec #ethical_hacking
Medium
Cisco notes Network Basics — Module 16:Application Service Layer
Client and Server Interaction
Every day, we use the services available over networks and the internet to communicate with others and to…
Every day, we use the services available over networks and the internet to communicate with others and to…
⤷ Title: Cisco notes Network Basics — Module 15:TCP and UDP
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:45:10 GMT
════════════════════════
⌗ Tags: #ethical_hacking #information_security #web_development #infosec #cybersecurity
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:45:10 GMT
════════════════════════
⌗ Tags: #ethical_hacking #information_security #web_development #infosec #cybersecurity
Medium
Cisco notes Network Basics — Module 15:TCP and UDP
“The transport layer in both the TCP/IP and OSI models is responsible for ensuring packets are sent reliably and any missing packets are…
⤷ Title: OWASP APTS
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:59:24 GMT
════════════════════════
⌗ Tags: #ai #ai_pentesting #penetration_testing #owasp
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 03:59:24 GMT
════════════════════════
⌗ Tags: #ai #ai_pentesting #penetration_testing #owasp
Medium
OWASP APTS
Imagine you hired a robot burglar to try breaking into your house — not to steal, but to show you where the weak locks are. Useful, right…
⤷ Title: Blind SQL injection with out-of-band data exfiltration
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:02:30 GMT
════════════════════════
⌗ Tags: #out_of_band_interaction #dns_lookup #blind_sql_injection #sql_injection
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 04:02:30 GMT
════════════════════════
⌗ Tags: #out_of_band_interaction #dns_lookup #blind_sql_injection #sql_injection
Medium
Blind SQL injection with out-of-band data exfiltration
The SQL query does not return any visible response, but it can trigger an out-of-band interaction that delivers the result through a…
⤷ Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Daily CyberSecurity
Void Dokkaebi Unmasked: The "Worm-Like" Supply Chain Threat Targeting Developers
Void Dokkaebi turns developers into vectors. With 750+ infected repos and malicious VS Code tasks, this supply chain worm is hunting your CI/CD and crypto.
⤷ Title: $800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:15 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:15 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
Medium
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin Hi Everyone! I recently discovered a Broken Access Control / Privilege Escalation vulnerability in a SaaS platform …
⤷ Title: When “Safe” Isn’t Safe: Turning a Simple HTML Injection into a Real Security Story.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:02:19 GMT
════════════════════════
⌗ Tags: #user_input #injection #content_security_policy #bug_bounty #htmli
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:02:19 GMT
════════════════════════
⌗ Tags: #user_input #injection #content_security_policy #bug_bounty #htmli
Medium
When “Safe” Isn’t Safe: Turning a Simple HTML Injection into a Real Security Story.
In bug bounty hunting, not every vulnerability needs flashy payloads or JavaScript execution to matter. Sometimes, the simplest flaws —…
⤷ Title: $800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:14 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
════════════════════════
𐀪 Author: Abhi Sharma
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:03:14 GMT
════════════════════════
⌗ Tags: #privilege_escalation #bug_bounty #cybersecurity #infosec #broken_access_control
Medium
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin
$800 Bounty: Privilege Escalation via API — From Scheduler to Team Admin Hi Everyone! I recently discovered a Broken Access Control / Privilege Escalation vulnerability in a SaaS platform …
⤷ Title: Rate Limiting Failures: How Attackers Abuse APIs
════════════════════════
𐀪 Author: Cybersphere Official
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:51:19 GMT
════════════════════════
⌗ Tags: #application_security #infosec #cybersecurity #web_security #api_security
════════════════════════
𐀪 Author: Cybersphere Official
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:51:19 GMT
════════════════════════
⌗ Tags: #application_security #infosec #cybersecurity #web_security #api_security
Medium
Rate Limiting Failures: How Attackers Abuse APIs
Context
⤷ Title: Best VAPT Services | ConsultEdge Global
════════════════════════
𐀪 Author: Consultedgeglobal
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:40:03 GMT
════════════════════════
⌗ Tags: #cert_in #vapt_services #consultedge_global #cloud_devsecops #application_security
════════════════════════
𐀪 Author: Consultedgeglobal
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:40:03 GMT
════════════════════════
⌗ Tags: #cert_in #vapt_services #consultedge_global #cloud_devsecops #application_security
Medium
Best VAPT Services | ConsultEdge Global
ConsultEdge Global provides trusted VAPT services to detect and fix security vulnerabilities in applications, networks, and systems. We…
⤷ Title: From LOW to CRITICAL: How a 5-Step Vulnerability Chain Goes Undetected by Flat Scanners
════════════════════════
𐀪 Author: Eldor Zufarov
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:25:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #software_engineering #vulnerability_management #application_security
════════════════════════
𐀪 Author: Eldor Zufarov
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:25:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #software_engineering #vulnerability_management #application_security
Medium
From LOW to CRITICAL: How a 5-Step Vulnerability Chain Goes Undetected by Flat Scanners
A real scan walkthrough using DVWA
⤷ Title: The New Age of Cyber Threats: Faster, Smarter, Invisible
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:53:37 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #cybersecurity #ai #programming
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:53:37 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #cybersecurity #ai #programming
Medium
The New Age of Cyber Threats: Faster, Smarter, Invisible
Let me ask you something.
⤷ Title: SOC Topic A02- API (Application Programming Interface)
════════════════════════
𐀪 Author: Adithya Hettiarachchi
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:33:15 GMT
════════════════════════
⌗ Tags: #soc #cyber_threat_intelligence #hacking #cybersecurity #information_security
════════════════════════
𐀪 Author: Adithya Hettiarachchi
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:33:15 GMT
════════════════════════
⌗ Tags: #soc #cyber_threat_intelligence #hacking #cybersecurity #information_security
Medium
SOC Topic A02- API (Application Programming Interface)
What is an API?
⤷ Title: WaTF Bank Walkthrough (Part 2): Exploiting Android App Security Flaws
════════════════════════
𐀪 Author: George Petropoulos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:59:56 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #cybersecurity #android_development #hacking
════════════════════════
𐀪 Author: George Petropoulos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 05:59:56 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #cybersecurity #android_development #hacking
Medium
WaTF Bank Walkthrough (Part 2): Exploiting Android App Security Flaws
Android Mobile Application Security Testing Write-Up