⤷ Title: TAMECAT: Iranian APT42 Group New PowerShell Backdoor Targeting Military and Government Officials
════════════════════════
𐀪 Author: Excalibra
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:44:12 GMT
════════════════════════
⌗ Tags: #powershell #malware #hacking #cybersecurity
════════════════════════
𐀪 Author: Excalibra
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:44:12 GMT
════════════════════════
⌗ Tags: #powershell #malware #hacking #cybersecurity
Medium
TAMECAT: APT42’s New PowerShell Backdoor Targeting Military and Government Officials
The Iranian APT42 group is conducting espionage attacks against high-ranking military and government officials using the TAMECAT…
⤷ Title: Unauthenticated SSRF via /api/cors on Multiple Subdomains
════════════════════════
𐀪 Author: Bex01
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:11:29 GMT
════════════════════════
⌗ Tags: #infosec
════════════════════════
𐀪 Author: Bex01
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:11:29 GMT
════════════════════════
⌗ Tags: #infosec
Medium
Unauthenticated SSRF via /api/cors on Multiple Subdomains
السلام عليكم ورحمة الله وبركاته
⤷ Title: Network Services — THM
════════════════════════
𐀪 Author: Fadybasem - ( SilentN0va )
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 20:16:25 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #network_security #ethical_hacking #technology
════════════════════════
𐀪 Author: Fadybasem - ( SilentN0va )
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 20:16:25 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #network_security #ethical_hacking #technology
Medium
Network Services — THM
الفرق بين “اختراق الشبكات” و”اختراق الواي فاي”
⤷ Title: Tryhackme room Blue كيف تحل لاب ويندوز 7 ؟
════════════════════════
𐀪 Author: Moahmmed
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:45:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #tryhackme #ethical_hacking
════════════════════════
𐀪 Author: Moahmmed
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:45:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #tryhackme #ethical_hacking
Medium
Tryhackme room Blue كيف تحل لاب ويندوز 7 ؟
شرح عملي لحل لاب Blue في TryHackMe، بداية من مرحلة جمع المعلومات وحتى استغلال الثغرة ورفع الصلاحيات.
⤷ Title: A Quick Win: From WebDAV to Root
════════════════════════
𐀪 Author: NullxCipher
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 20:11:43 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #php_reverse_shell #tryhackme #thm_writeup #webdav
════════════════════════
𐀪 Author: NullxCipher
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 20:11:43 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #php_reverse_shell #tryhackme #thm_writeup #webdav
Medium
A Quick Win: From WebDAV to Root
I started with a simple target:
⤷ Title: Elastic Stack: The Basics — TryHackMe Writeup
════════════════════════
𐀪 Author: Hitesh kumar
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:13:41 GMT
════════════════════════
⌗ Tags: #dfir #tryhackme_walkthrough #elasticsearch #tryhackme #elk
════════════════════════
𐀪 Author: Hitesh kumar
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 19:13:41 GMT
════════════════════════
⌗ Tags: #dfir #tryhackme_walkthrough #elasticsearch #tryhackme #elk
Medium
Elastic Stack: The Basics — TryHackMe Writeup
Hello everyone so today i will be writing about Elastic stack: the Basics room (answers will be provided in the screenshorts)
⤷ Title: イスラエルPillar SecurityがGoogle Antigravityの脆弱性を報告 (2026年4月29日公開)
════════════════════════
𐀪 Author: Eiji Sasahara (笹原英司), Ph.D., MBA
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 20:01:01 GMT
════════════════════════
⌗ Tags: #prompt_injection #google_antigravity #pillar_security #rce_vulnerability
════════════════════════
𐀪 Author: Eiji Sasahara (笹原英司), Ph.D., MBA
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 20:01:01 GMT
════════════════════════
⌗ Tags: #prompt_injection #google_antigravity #pillar_security #rce_vulnerability
Medium
イスラエルPillar SecurityがGoogle Antigravityの脆弱性を報告 (2026年4月29日公開)
2026年4月20日、イスラエル・テルアビブのAIセキュリティ専門企業 ピラーセキュリティ(Pillar Security)は、「Antigravityにおけるプロンプトインジェクションに起因したRCEとサンドボックス脱出」と題する記事を公開した。
⤷ Title: New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:33:11 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Scams and Fraud #Cyber Attack #Cybersecurity #DHL #Forcepoint #Fraud #Password #Phishing #Scam
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:33:11 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Scams and Fraud #Cyber Attack #Cybersecurity #DHL #Forcepoint #Fraud #Password #Phishing #Scam
Hackread
New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords
Forcepoint’s X-Labs reports an 11-step DHL phishing scam that uses fake OTP codes and EmailJS to harvest user credentials and device telemetry.
⤷ Title: Escaping the Sandbox: Client-Side Template Injection (CSTI) via Outdated AngularJS
════════════════════════
𐀪 Author: Mustafa
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 22:44:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Mustafa
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 22:44:13 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity
Medium
Escaping the Sandbox: Client-Side Template Injection (CSTI) via Outdated AngularJS
Introduction
⤷ Title: Bypassing 4-Digit MFA — A HackSmarter Lab Writeup
════════════════════════
𐀪 Author: Cyberologist
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:32:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #web_security #cybersecurity #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: Cyberologist
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:32:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #web_security #cybersecurity #bug_bounty #penetration_testing
Medium
Bypassing 4-Digit MFA — A HackSmarter Lab Writeup
Platform: HackSmarter Challenge: Bypass MFA Difficulty: Beginner Tools Used: Burp Suite Community Edition, OpenVPN
⤷ Title: Prototype Pollution
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:23:12 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #information_security #bug_bounty #javascript #cybersecurity
════════════════════════
𐀪 Author: Marduk I Am
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:23:12 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #information_security #bug_bounty #javascript #cybersecurity
Medium
Prototype Pollution
Turning Property Lookups into Code Execution
⤷ Title: COMMON HTTP ERROR CODES & Bypass Techniques
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:01:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bypass #http_status_code #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:01:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bypass #http_status_code #bug_bounty_tips #bug_bounty
Medium
🎓 COMMON HTTP ERROR CODES & Bypass Techniques 🎓
HTTP error codes are not just roadblocks — they’re clues. Understanding what each code means and how to bypass them is essential for web…
⤷ Title: The Identity That Dies With the Session
════════════════════════
𐀪 Author: Seven Cubed Seven Labs
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:24:48 GMT
════════════════════════
⌗ Tags: #identity_management #cybersecurity #passwordless #infosec #authentication
════════════════════════
𐀪 Author: Seven Cubed Seven Labs
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 21:24:48 GMT
════════════════════════
⌗ Tags: #identity_management #cybersecurity #passwordless #infosec #authentication
Medium
The Identity That Dies With the Session
Why Every Credential Breach Shared the Same Structural Flaw — And What Identity Architecture Replaces It
⤷ Title: ClickUp Discloses Exposure of Customer Emails and API Token
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:08:43 +0000
════════════════════════
⌗ Tags: #Data Leak #2026 #API security #ClickUp #Configuration Error #cybersecurity #Data Breach #Feature Flags #HackerOne #infosec #leak #PII Exposure #Split.io
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:08:43 +0000
════════════════════════
⌗ Tags: #Data Leak #2026 #API security #ClickUp #Configuration Error #cybersecurity #Data Breach #Feature Flags #HackerOne #infosec #leak #PII Exposure #Split.io
Daily CyberSecurity
ClickUp Discloses Exposure of Customer Emails and API Token
ClickUp discloses a configuration flaw exposing 893 emails and a live API token via Split.io feature flags. Learn how client-side SDKs became a public leak.
⤷ Title: Git Push to Root: AI-Augmented Research Uncovers Critical GitHub RCE (CVE-2026-3854)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 23:57:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Reverse Engineering #Backend Security #CVE_2026_3854 #GHES #git #github #infosec #rce #Remote Code Execution #Vulnerability #Wiz Research #X_Stat Header
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 23:57:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Reverse Engineering #Backend Security #CVE_2026_3854 #GHES #git #github #infosec #rce #Remote Code Execution #Vulnerability #Wiz Research #X_Stat Header
Daily CyberSecurity
Git Push to Root: AI-Augmented Research Uncovers Critical GitHub RCE (CVE-2026-3854)
Wiz Research reveals CVE-2026-3854, a critical GitHub RCE. One git push could expose millions of repos. GHES users must patch to v3.19.3 immediately.
⤷ Title: Prototype Pollution Guide: Vulnerabilities, Attack Vectors, and RCE
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #web_development #technology #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #web_development #technology #bug_bounty
Medium
Prototype Pollution Guide: Vulnerabilities, Attack Vectors, and RCE
Learn what Prototype Pollution is, its RCE and XSS risks, and how to detect this critical vulnerability in JavaScript.
⤷ Title: The $292 Million KelpDAO Hack — What It Means for DeFi Security in 2026
════════════════════════
𐀪 Author: grace brume
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 22:54:24 GMT
════════════════════════
⌗ Tags: #ethereum #hacking #crypto_2026 #kelp_dao #rseth
════════════════════════
𐀪 Author: grace brume
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 22:54:24 GMT
════════════════════════
⌗ Tags: #ethereum #hacking #crypto_2026 #kelp_dao #rseth
Medium
The $292 Million KelpDAO Hack — What It Means for DeFi Security in 2026
North Korea’s Lazarus Group didn’t find a bug. They found something worse — a single point of trust. Here’s the full story of the largest…
⤷ Title: How I Built a Cybersecurity Lab at Home
════════════════════════
𐀪 Author: Berat Aslan
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:33:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #tech #information_security #ethical_hacking
════════════════════════
𐀪 Author: Berat Aslan
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:33:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #tech #information_security #ethical_hacking
Medium
How I Built a Cybersecurity Lab at Home
One of the most common pieces of advice people hear when they want to learn cybersecurity is “build a lab.” It’s good advice, but most of…
⤷ Title: Evde Siber Güvenlik Labı Nasıl Kurdum?
════════════════════════
𐀪 Author: Berat Aslan
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:24:38 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #cybersecurity #information_security #tech
════════════════════════
𐀪 Author: Berat Aslan
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 00:24:38 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #cybersecurity #information_security #tech
Medium
Evde Siber Güvenlik Labı Nasıl Kurdum?
Siber güvenlik öğrenmek isteyenlerin en çok duyduğu tavsiye “lab kur” oluyor. Haklı bir tavsiye ama çoğu zaman kimse bunun nasıl…
⤷ Title: Checkmarx Falls Victim to Credential Harvesting Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 01:54:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #breach #Checkmarx #cybersecurity #data exfiltration #GitHub Security #infosec #LAPSUS$ #Malicious code #Software Integrity #supply chain attack #Trivy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 01:54:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #breach #Checkmarx #cybersecurity #data exfiltration #GitHub Security #infosec #LAPSUS$ #Malicious code #Software Integrity #supply chain attack #Trivy
Daily CyberSecurity
Checkmarx Falls Victim to Credential Harvesting Attack
Checkmarx discloses a major GitHub breach via a Trivy supply chain flaw. Attackers injected malicious code and exfiltrated data for a month. Get the facts.
⤷ Title: CISA Sounds the Alarm: State-Sponsored Hackers Weaponize New Windows and ScreenConnect Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 01:45:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT28 #CISA #ConnectWise #CVE_2024_1708 #CVE_2026_32202 #cyber_espionage #Fancy Bear #infosec #KEV Catalog #Kimsuky #Patch Alert #ToddlerShark #Windows Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 01:45:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT28 #CISA #ConnectWise #CVE_2024_1708 #CVE_2026_32202 #cyber_espionage #Fancy Bear #infosec #KEV Catalog #Kimsuky #Patch Alert #ToddlerShark #Windows Shell
Daily CyberSecurity
CISA Sounds the Alarm: State-Sponsored Hackers Weaponize New Windows and ScreenConnect Flaws
CISA warns as North Korean and Russian hackers weaponize ConnectWise and Windows Shell flaws. Patch by May 12, 2026, to prevent state-sponsored espionage.