⤷ Title: WebSockets Aren’t Scary (I Learned Them So You Don’t Have To)
════════════════════════
𐀪 Author: zero_day
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:13:19 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #cybersecurity #bug_bounty_tips #penetration_testing
════════════════════════
𐀪 Author: zero_day
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:13:19 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #cybersecurity #bug_bounty_tips #penetration_testing
Medium
WebSockets Aren’t Scary (I Learned Them So You Don’t Have To)
Hello everyone, this is Nobody. I’m really sorry that I’m late — my semester exams are coming up and I have to prepare for them. I’ll be a…
⤷ Title: The Phantom Pharmacy: How a Single Misspelled Character Put Thousands of Shoppers at Risk
════════════════════════
𐀪 Author: NekoSecurity
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:45:55 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #typosquatting
════════════════════════
𐀪 Author: NekoSecurity
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:45:55 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #typosquatting
Medium
The Phantom Pharmacy: How a Single Misspelled Character Put Thousands of Shoppers at Risk
A deep-dive into a typosquatting campaign targeting a major Southeast Asian health and beauty retail chain — and how I found it by…
⤷ Title: Why Most Penetration Testing Reports Fail (And What a Good One Looks Like)
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:32:08 GMT
════════════════════════
⌗ Tags: #saas_security #cybersecurity #application_security #penetration_testing #api_security
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:32:08 GMT
════════════════════════
⌗ Tags: #saas_security #cybersecurity #application_security #penetration_testing #api_security
Medium
Why Most Penetration Testing Reports Fail (And What a Good One Looks Like)
Most companies don’t realize they have a security problem until a deal slows down.
⤷ Title: Beyond the Classroom: Why an Ethical Hacking Course in Delhi Must Include Live-Site Audits and…
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:50:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ethical_hacking
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:50:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ethical_hacking
Medium
Beyond the Classroom: Why an Ethical Hacking Course in Delhi Must Include Live-Site Audits and…
There is a moment that every ethical hacking student in Delhi eventually encounters — and most of them encounter it at the worst possible…
⤷ Title: The Next 24 Months Will Decide Who Survives the AI Cybersecurity War
════════════════════════
𐀪 Author: Faraz Weerabangsa | BSc in MIS (Special)
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:43:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #ai #artificial_intelligence #hacking
════════════════════════
𐀪 Author: Faraz Weerabangsa | BSc in MIS (Special)
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:43:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #ai #artificial_intelligence #hacking
Medium
The Next 24 Months Will Decide Who Survives the AI Cybersecurity War
Companies that fail to adapt to AI-driven threats won’t just fall behind; they’ll be exposed.
⤷ Title: 2026’s Largest DeFi Heist: How Hackers Stole $290M from Kelp DAO via a Fatal Infrastructure Flaw
════════════════════════
𐀪 Author: Alice Hsu
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:29:57 GMT
════════════════════════
⌗ Tags: #defi #kelp_dao #hacking #solidity
════════════════════════
𐀪 Author: Alice Hsu
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:29:57 GMT
════════════════════════
⌗ Tags: #defi #kelp_dao #hacking #solidity
Medium
2026’s Largest DeFi Heist: How Hackers Stole $290M from Kelp DAO via a Fatal Infrastructure Flaw
Incident Overview
⤷ Title: eJPT - The Metasploit Framework CTF 1
════════════════════════
𐀪 Author: Francesco Pastore
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:19:36 GMT
════════════════════════
⌗ Tags: #tech #cybersecurity #technology #hacking #security
════════════════════════
𐀪 Author: Francesco Pastore
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:19:36 GMT
════════════════════════
⌗ Tags: #tech #cybersecurity #technology #hacking #security
Medium
eJPT - The Metasploit Framework CTF 1
A writeup for “The Metasploit Framework CTF 1” from the eJPT course.
⤷ Title: Bypassing File Upload Limits via Race Condition
════════════════════════
𐀪 Author: Na_stark
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:03:47 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #bugbounty_writeup #bugs #hackerone
════════════════════════
𐀪 Author: Na_stark
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:03:47 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #bugbounty_writeup #bugs #hackerone
Medium
Bypassing File Upload Limits via Race Condition
*How parallel requests can break business logic that looks rock solid on the surface*
⤷ Title: What Are the Main Aims of Penetration Testing?
════════════════════════
𐀪 Author: Nishant
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:04:13 GMT
════════════════════════
⌗ Tags: #penetration_testing #internet_security #cybersecurity #ai #latest_cyber_threats
════════════════════════
𐀪 Author: Nishant
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 09:04:13 GMT
════════════════════════
⌗ Tags: #penetration_testing #internet_security #cybersecurity #ai #latest_cyber_threats
Medium
What Are the Main Aims of Penetration Testing?
Penetration testing, often called pen testing, is one of the most effective ways to understand how secure a system really is. Instead of…
⤷ Title: Understanding Vulnerability Databases Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:43:03 GMT
════════════════════════
⌗ Tags: #red_team #tryhackme_writeup #tryhackme_walkthrough #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:43:03 GMT
════════════════════════
⌗ Tags: #red_team #tryhackme_writeup #tryhackme_walkthrough #cybersecurity #tryhackme
Medium
Understanding Vulnerability Databases Walkthrough Notes | TryHackMe
Learn about vulnerability databases, scoring systems, and exploit references.
⤷ Title: Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 16:48:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 16:48:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:41:17 +0000
════════════════════════
⌗ Tags: #Security #Malware #backdoor #Cisco #Cyber Attack #Firestarter #firewall #Linux #VPN
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:41:17 +0000
════════════════════════
⌗ Tags: #Security #Malware #backdoor #Cisco #Cyber Attack #Firestarter #firewall #Linux #VPN
Hackread
New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices
FIRESTARTER, a Linux-based backdoor, targets Cisco Firepower devices, evades patches, and enables persistent access even after firmware updates.
⤷ Title: Why Unofficial Download Sources Are Still a Security Risk in 2026
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:01:37 +0000
════════════════════════
⌗ Tags: #Security #Privacy #Cybersecurity #Downloads #Fraud #Malware #Phishing #Scam #security #VPN
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:01:37 +0000
════════════════════════
⌗ Tags: #Security #Privacy #Cybersecurity #Downloads #Fraud #Malware #Phishing #Scam #security #VPN
Hackread
Why Unofficial Download Sources Are Still a Security Risk in 2026
Security Risk in 2026: why unofficial download sources still put users at risk, and how to verify safe, official install paths before installing software.
⤷ Title: Langflow Alert: Path Traversal Flaw in Knowledge Bases API Risks Total Data Wipeout
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:48:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42048 #cybersecurity #Data Loss #infosec #Langflow #Path Traversal #Python Security #shutil.rmtree #Vulnerability Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:48:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42048 #cybersecurity #Data Loss #infosec #Langflow #Path Traversal #Python Security #shutil.rmtree #Vulnerability Research
Daily CyberSecurity
Langflow Alert: Path Traversal Flaw in Knowledge Bases API Risks Total Data Wipeout
Langflow patches a critical 9.6 CVSS path traversal vulnerability (CVE-2026-42048). Learn how an unsafe bulk delete function put entire filesystems at risk.
⤷ Title: Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:03:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Thrift #C++ #CVE_2026_41603 #cybersecurity #go #infosec #java #memory corruption #mitm #Node.js #RPC Security #swift
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:03:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Thrift #C++ #CVE_2026_41603 #cybersecurity #go #infosec #java #memory corruption #mitm #Node.js #RPC Security #swift
Daily CyberSecurity
Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws
Apache Thrift fixes critical cross-language vulnerabilities (MitM, memory corruption, DoS). Secure your Java, Go, and C++ stacks by upgrading to version 0.23.0.
⤷ Title: SVG Abuse: Account Takeover Without XSS
════════════════════════
𐀪 Author: Austin Long
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:55:42 GMT
════════════════════════
⌗ Tags: #bug_bounty #security #red_team #pentesting #cybersecurity
════════════════════════
𐀪 Author: Austin Long
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:55:42 GMT
════════════════════════
⌗ Tags: #bug_bounty #security #red_team #pentesting #cybersecurity
Medium
SVG Abuse: Account Takeover Without XSS
SVG uploads are a fun attack surface! Most testers check for XSS, but what if the Content Security Policy (CSP)is set to script-src: none?
⤷ Title: Kenapa Pendidikan Keamanan Siber di Indonesia Masih Terbatas?
════════════════════════
𐀪 Author: Ali Ridlo
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:32:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #technology #education #information_security
════════════════════════
𐀪 Author: Ali Ridlo
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:32:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #technology #education #information_security
Medium
Kenapa Pendidikan Keamanan Siber di Indonesia Masih Terbatas?
Keamanan siber kini menjadi salah satu sektor yang sangat dibutuhkan dalam era digital saat ini.
⤷ Title: Understanding Vulnerability Databases (THM) Tryhackme Walkthrough
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:59:36 GMT
════════════════════════
⌗ Tags: #hacking #database #cybersecurity #vulnerabilitydatabases #tryhackme
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:59:36 GMT
════════════════════════
⌗ Tags: #hacking #database #cybersecurity #vulnerabilitydatabases #tryhackme
Medium
Understanding Vulnerability Databases (THM) Tryhackme Walkthrough
Description : Explore vulnerability databases, their importance, and practical usage during pentesting.
⤷ Title: The 2026 Shortcut: Why a Cyber Security Diploma After 12th Beats a 4-Year B.Tech
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:47:00 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:47:00 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ethical_hacking
Medium
The 2026 Shortcut: Why a Cyber Security Diploma After 12th Beats a 4-Year B.Tech
Generation Z has a fundamentally different relationship with education than any generation before it. Where previous generations accepted…
⤷ Title: “We Didn’t Hack You.”
════════════════════════
𐀪 Author: Yua Mikanana
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:15:31 GMT
════════════════════════
⌗ Tags: #hacking #cyber_security_awareness #cybersecurity #technology #ethical_hacking
════════════════════════
𐀪 Author: Yua Mikanana
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 11:15:31 GMT
════════════════════════
⌗ Tags: #hacking #cyber_security_awareness #cybersecurity #technology #ethical_hacking
Medium
“We Didn’t Hack You.”
How Modern Breaches Happen Without Malware, Exploits, or Even Breaking In
⤷ Title: AWS Penetration Testing Part 2: S3 Bucket Enumeration — From Public Misconfiguration to Credential…
════════════════════════
𐀪 Author: Vimal Raj
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:32:07 GMT
════════════════════════
⌗ Tags: #cloud_security #s3_bucket #aws #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Vimal Raj
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:32:07 GMT
════════════════════════
⌗ Tags: #cloud_security #s3_bucket #aws #penetration_testing #cybersecurity
Medium
AWS Penetration Testing Part 2: S3 Bucket Enumeration — From Public Misconfiguration to Credential Compromise
Part 2 of my AWS pentesting series. In Part 1, I covered IAM enumeration from scratch. This post focuses on S3 — what it is, why it’s a…