⤷ Title: Guía Maestra de SSRF: Estrategias de Explotación y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 00:01:04 GMT
════════════════════════
⌗ Tags: #web_development #technology #hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 00:01:04 GMT
════════════════════════
⌗ Tags: #web_development #technology #hacking #cybersecurity #bug_bounty
Medium
Guía Maestra de SSRF: Estrategias de Explotación y Mitigación
Aprende a detectar y explotar vulnerabilidades SSRF en entornos Cloud-Native, desde servicios de metadata hasta evasión de filtros.
⤷ Title: Day 10: Bypassing SameSite Lax with Method Override (CSRF Lab Walkthrough)
════════════════════════
𐀪 Author: zero_day
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 23:45:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty_tips #cybersecurity #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: zero_day
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 23:45:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty_tips #cybersecurity #bug_bounty_writeup #bug_bounty
Medium
Day 10: Bypassing SameSite Lax with Method Override (CSRF Lab Walkthrough)
hello everyone, this is nobody.
⤷ Title: Race Condition Allows Users to Obtain More Than 1 Free Domain
════════════════════════
𐀪 Author: rozzen
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 23:12:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #vulnerability
════════════════════════
𐀪 Author: rozzen
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 23:12:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #vulnerability
Medium
Race Condition Allows Users to Obtain More Than 1 Free Domain
Disclaimer: This is a report from someone else that I am studying, not my own finding. (Source: Automattic | Report #2616045 — Race…
⤷ Title: What a TryHackMe Live Session Taught Me About AI, Cybersecurity, and the Skills That Will Matter…
════════════════════════
𐀪 Author: Mansi Mahamuni
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 00:47:06 GMT
════════════════════════
⌗ Tags: #ai_in_cybersecurity #agentic_ai #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Mansi Mahamuni
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 00:47:06 GMT
════════════════════════
⌗ Tags: #ai_in_cybersecurity #agentic_ai #cybersecurity #tryhackme
Medium
What a TryHackMe Live Session Taught Me About AI, Cybersecurity, and the Skills That Will Matter…
I attended a live session today hosted by TryHackMe Co-Founder Ashu Savani and Eva Benn, and it left me thinking about something that many…
⤷ Title: HackTheBox — Logging
════════════════════════
𐀪 Author: sn0x
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 23:15:47 GMT
════════════════════════
⌗ Tags: #hackthebox #htb #htb_writeup #ctf #hackthebox_writeup
════════════════════════
𐀪 Author: sn0x
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 23:15:47 GMT
════════════════════════
⌗ Tags: #hackthebox #htb #htb_writeup #ctf #hackthebox_writeup
Medium
HackTheBox — Logging
Authorized lab environment. Educational purposes only.
⤷ Title: Unpatched and Exposed: Public PoC Released for Critical 9.8 CVSS Xiongmai IP Camera Flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:31:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA Warning #CVE_2025_65856 #IoT security #IP Camera Security #no patch #ONVIF Vulnerability #PoC Exploit #Xiongmai #XM530
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:31:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA Warning #CVE_2025_65856 #IoT security #IP Camera Security #no patch #ONVIF Vulnerability #PoC Exploit #Xiongmai #XM530
Daily CyberSecurity
Unpatched and Exposed: Public PoC Released for Critical 9.8 CVSS Xiongmai IP Camera Flaw
Critical 9.8 CVSS auth bypass hits Xiongmai IP cameras. Public PoC is live with NO patch available. Secure your live feeds and isolate your devices now!
⤷ Title: Operational Blackout: How Kyber Ransomware Targets the Heart of Virtualized Environments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:00:08 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #data recovery #Hyper_V #infosec #Kyber Ransomware #Rapid7 #Rust malware #Virtualization Attack #VMware ESXi #VSS Wipe #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:00:08 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #data recovery #Hyper_V #infosec #Kyber Ransomware #Rapid7 #Rust malware #Virtualization Attack #VMware ESXi #VSS Wipe #Windows Security
Daily CyberSecurity
Operational Blackout: How Kyber Ransomware Targets the Heart of Virtualized Environments
Researchers at Rapid7 have uncovered Kyber, a specialized ransomware family that recently hit enterprise environments with a coordinated, dual-platform attack. Unlike common strains that focus on …
⤷ Title: Supply Chain Sabotage: Bitwarden CLI Compromised in Global “Checkmarx” Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
Daily CyberSecurity
Supply Chain Sabotage: Bitwarden CLI Compromised in Global "Checkmarx" Campaign
Bitwarden CLI v2026.4.0 compromised in "Dune"-themed supply chain attack. Malware steals cloud secrets and SSH keys. Rotate your credentials immediately.
⤷ Title: Arcane Door Reopened: The Cisco Firepower Backdoor That Only a Hard Reboot Can Kill
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:28:24 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Arcane Door #ASA #backdoor #cisco #Cisco Talos #CVE_2025_20333 #cyber_espionage #FIREPOWER #FIRESTARTER #FTD #infosec #LINA Process #UAT_4356
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:28:24 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Arcane Door #ASA #backdoor #cisco #Cisco Talos #CVE_2025_20333 #cyber_espionage #FIREPOWER #FIRESTARTER #FTD #infosec #LINA Process #UAT_4356
Daily CyberSecurity
Arcane Door Reopened: The Cisco Firepower Backdoor That Only a Hard Reboot Can Kill
Cisco Talos uncovers the FIRESTARTER backdoor in Arcane Door's latest attack on Firepower devices. Patch CVE-2025-20333 now to stop state-sponsored espionage.
⤷ Title: Harvester APT Goes Cross-Platform: New Linux Backdoor Abuses Microsoft Graph API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:08:40 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Carbon Black #cyber_espionage #GoGra #Harvester #infosec #Linux Backdoor #Malware Analysis #Microsoft Graph API #South Asia Security #Symantec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:08:40 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Carbon Black #cyber_espionage #GoGra #Harvester #infosec #Linux Backdoor #Malware Analysis #Microsoft Graph API #South Asia Security #Symantec
Daily CyberSecurity
Harvester APT Goes Cross-Platform: New Linux Backdoor Abuses Microsoft Graph API
Harvester APT expands to Linux using Microsoft Graph API for C2. Learn how the "GoGra" variant uses Outlook and "Zomato Pizza" lures to evade detection.
⤷ Title: Bug Bounty Series— Part 1 (Bug Bounty Basics)
════════════════════════
𐀪 Author: Aditya Kumar
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:01:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty #hacking
════════════════════════
𐀪 Author: Aditya Kumar
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:01:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty #hacking
Medium
Bug Bounty Series— Part 1 (Bug Bounty Basics)
Inside: A deep dive into the lessons learned and techniques applied during my latest hands-on experiments.
⤷ Title: Name Calling — BlueHens CTF 2026 Forensics Writeup
════════════════════════
𐀪 Author: Z3DX
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:26:32 GMT
════════════════════════
⌗ Tags: #hacking #forensics #cyper_security #ctf
════════════════════════
𐀪 Author: Z3DX
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:26:32 GMT
════════════════════════
⌗ Tags: #hacking #forensics #cyper_security #ctf
Medium
Name Calling — BlueHens CTF 2026 Forensics Writeup
This write-up covers the “Name Calling” challenge from BlueHens CTF 2026. It shows how a small clue in network traffic can lead to hidden…
⤷ Title: Weekly Threat Intelligence Report 20 Apr 2026
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:25:58 GMT
════════════════════════
⌗ Tags: #cyberattack #cybersecurity #infosec #hacking #threat_intelligence
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:25:58 GMT
════════════════════════
⌗ Tags: #cyberattack #cybersecurity #infosec #hacking #threat_intelligence
Medium
Weekly Threat Intelligence Report 20 Apr 2026
This document summarizes key cyber threats identified between Apr 13 and Apr 19, 2026, including related threat events
⤷ Title: OSINT Challenge Writeup: Glasses 2 | BlueHens CTF 2026
════════════════════════
𐀪 Author: Z3DX
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:24:46 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ctf #osint
════════════════════════
𐀪 Author: Z3DX
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 02:24:46 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ctf #osint
Medium
OSINT Challenge Writeup: Glasses 2 | BlueHens CTF 2026
This writeup explores my approach to solving the “Glasses 2” OSINT challenge from BlueHens CTF 2026, breaking down the investigation…
⤷ Title: The Hidden Risks in AI Training Model Poisoning and Supply Chain Attacks in LLMs
════════════════════════
𐀪 Author: Chidubem Chukwu
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:56:15 GMT
════════════════════════
⌗ Tags: #redteam_tool #hacking #pentesting #ai_agent
════════════════════════
𐀪 Author: Chidubem Chukwu
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:56:15 GMT
════════════════════════
⌗ Tags: #redteam_tool #hacking #pentesting #ai_agent
Medium
The Hidden Risks in AI Training Model Poisoning and Supply Chain Attacks in LLMs
Large Language Models (LLMs) are quickly becoming part of real systems, from chatbots and internal tools to decision-making platforms. Most…
⤷ Title: Cronos — HTB Writeup
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:50:38 GMT
════════════════════════
⌗ Tags: #hacking #hackthebox #pentesting
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:50:38 GMT
════════════════════════
⌗ Tags: #hacking #hackthebox #pentesting
Medium
Cronos — HTB Writeup
Introduction:
⤷ Title: The Great Linux Purge: Why the Kernel is Dumping 27,000 Lines of Code to Stop the AI Vulnerability Deluge
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:46:25 +0000
════════════════════════
⌗ Tags: #Linux #AI security #Cybersecurity 2026 #ISA #Kernel Maintenance #Legacy Hardware #Linux Kernel #Network Drivers #open_source #PCMCIA #vulnerability management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:46:25 +0000
════════════════════════
⌗ Tags: #Linux #AI security #Cybersecurity 2026 #ISA #Kernel Maintenance #Legacy Hardware #Linux Kernel #Network Drivers #open_source #PCMCIA #vulnerability management
Daily CyberSecurity
The Great Linux Purge: Why the Kernel is Dumping 27,000 Lines of Code to Stop the AI Vulnerability Deluge
Linux maintainers propose purging 27,646 lines of legacy network code to combat a flood of AI-generated vulnerability reports and focus on modern security.
⤷ Title: The Local Guardian: OpenAI Unveils a 1.5B Open-Source Model to Redact PII Locally
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:43:45 +0000
════════════════════════
⌗ Tags: #Technology #1.5B Model #Cybersecurity 2026 #Data Privacy #GPT_OSS #LLM Security #Local AI #machine_learning #open_source #OpenAI #PII Redaction #Privacy Filter
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:43:45 +0000
════════════════════════
⌗ Tags: #Technology #1.5B Model #Cybersecurity 2026 #Data Privacy #GPT_OSS #LLM Security #Local AI #machine_learning #open_source #OpenAI #PII Redaction #Privacy Filter
Daily CyberSecurity
The Local Guardian: OpenAI Unveils a 1.5B Open-Source Model to Redact PII Locally
OpenAI's new 1.5B Privacy Filter uses semantic reasoning to tag sensitive data locally. Run PII protection on consumer hardware with 128K context support.
⤷ Title: The Notification Trap: How Apple’s New iOS Patch Blocks Forensic Recovery of “Deleted” Signal Messages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:40:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple Security Update #CVE_2026_28950 #Data Privacy #Disappearing Messages #encryption #fbi #Forensic Security #iOS 18.7.8 #iOS 26.4.2 #Signal App
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:40:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple Security Update #CVE_2026_28950 #Data Privacy #Disappearing Messages #encryption #fbi #Forensic Security #iOS 18.7.8 #iOS 26.4.2 #Signal App
Daily CyberSecurity
The Notification Trap: How Apple’s New iOS Patch Blocks Forensic Recovery of "Deleted" Signal Messages
Apple’s iOS 26.4.2 fixes a flaw (CVE-2026-28950) that let the FBI recover deleted Signal messages from notification logs. Update now to secure your private chats.
⤷ Title: The Cloud Runs Dry: ClawCloud Abruptly Terminates Container Services—Is Your Data Safe?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:37:06 +0000
════════════════════════
⌗ Tags: #Technology #ClawCloud Run #Cloud Computing #Container Deployment #Data Migration #Docker Hosting #Infrastructure Alert #Premium Refunds #SaaS Shutdown #Service Termination #Tech News 2026
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:37:06 +0000
════════════════════════
⌗ Tags: #Technology #ClawCloud Run #Cloud Computing #Container Deployment #Data Migration #Docker Hosting #Infrastructure Alert #Premium Refunds #SaaS Shutdown #Service Termination #Tech News 2026
Daily CyberSecurity
The Cloud Runs Dry: ClawCloud Abruptly Terminates Container Services—Is Your Data Safe?
ClawCloud Run is shutting down. With free tiers ending May 11, 2026, and a strict refund deadline of May 20, users must migrate data immediately to avoid loss.
⤷ Title: Open Redirect Simple Bug, Powerful Chains: Phishing Se OAuth Bypass Tak! (Hinglish Mein)
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:31:03 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #web_security #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Hacker MD
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 04:31:03 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #web_security #bug_bounty #cybersecurity
Medium
Open Redirect Simple Bug, Powerful Chains: Phishing Se OAuth Bypass Tak! (Hinglish Mein)
Series: Bug Bounty Zero se Hero 🦸 | Article #22 By HackerMD | 16 min read