⤷ Title: Eksperimen Keamanan Web: Analisis SQL Injection dan Cross-Site Scripting (XSS) pada Aplikasi Web…
════════════════════════
𐀪 Author: Shlyptr
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 11:13:48 GMT
════════════════════════
⌗ Tags: #sql_injection
════════════════════════
𐀪 Author: Shlyptr
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 11:13:48 GMT
════════════════════════
⌗ Tags: #sql_injection
Medium
Eksperimen Keamanan Web: Analisis SQL Injection dan Cross-Site Scripting (XSS) pada Aplikasi Web Modern
Penulis: Sherly Putri Mata Kuliah: Pemrograman Web Topik: Keamanan Web
⤷ Title: $500 OAuth Account Fusion Pre-Takeover Attack
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 11:19:12 GMT
════════════════════════
⌗ Tags: #authentication_bypass #account_takeover #hackerone #bug_bounty_writeup #oauth
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 11:19:12 GMT
════════════════════════
⌗ Tags: #authentication_bypass #account_takeover #hackerone #bug_bounty_writeup #oauth
Medium
$500 OAuth Account Fusion Pre-Takeover Attack
Akwaaba! guys. Read my previous blog on Android Intent Redirection, an easy $2000 for mobile app hackers. At times, a simple path tweak can…
⤷ Title: Legacy Leak: Deprecated GNU C Library Functions Spark New Security Fears
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:30:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2026_5435 #CVE_2026_6238 #DNS Vulnerability #glibc #GNU C Library #infosec #Legacy Code #Linux Security #open_source #Patch Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:30:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2026_5435 #CVE_2026_6238 #DNS Vulnerability #glibc #GNU C Library #infosec #Legacy Code #Linux Security #open_source #Patch Alert
Daily CyberSecurity
Legacy Leak: Deprecated GNU C Library Functions Spark New Security Fears
glibc warns of critical flaws (CVE-2026-5435 & CVE-2026-6238) in deprecated DNS functions. Patch legacy apps to avoid buffer overflows and memory leaks.
⤷ Title: The Shittrix Disclosure: 89 Flaws Collapse 20 Years of Trust in Citrix and XCP-ng
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:04:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #Bootkit #Citrix #Cloud Security #CVSS 9.9 #Hypervisor #infosec #Jakob Wolffhechel #Shittrix #Storage Security #Virtualization Security #XCP_ng #XenServer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:04:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #Bootkit #Citrix #Cloud Security #CVSS 9.9 #Hypervisor #infosec #Jakob Wolffhechel #Shittrix #Storage Security #Virtualization Security #XCP_ng #XenServer
Daily CyberSecurity
The Shittrix Disclosure: 89 Flaws Collapse 20 Years of Trust in Citrix and XCP-ng
Jakob Wolffhechel reveals "Shittrix," 89 critical flaws in Citrix XenServer & XCP-ng. CVSS 9.9 bugs allow full host takeover. Assume compromise today.
⤷ Title: A Practical Guide to BloodHound Data Collection
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #Blue Team Tools #General InfoSec Tips & Tricks #How_To #Informational #Red Team #Red Team Tools #Active Directory #bloodhound
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #Blue Team Tools #General InfoSec Tips & Tricks #How_To #Informational #Red Team #Red Team Tools #Active Directory #bloodhound
Black Hills Information Security, Inc.
A Practical Guide to BloodHound Data Collection - Black Hills Information Security, Inc.
This blog will not dive too deeply into BloodHound itself; instead, we will focus on various methods to collect AD data to provide BloodHound as input.
⤷ Title: Self-XSS + CSRF Leading to Account Takeover (50-Character Payload Limit Challenge)
════════════════════════
𐀪 Author: CANITEY
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:32:10 GMT
════════════════════════
⌗ Tags: #csrf #xss_attack #bugbounty_writeup #account_takeover_attacks #bug_bounty
════════════════════════
𐀪 Author: CANITEY
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:32:10 GMT
════════════════════════
⌗ Tags: #csrf #xss_attack #bugbounty_writeup #account_takeover_attacks #bug_bounty
Medium
Self-XSS + CSRF Leading to Account Takeover (50-Character Payload Limit Challenge)
Hey everyone, it’s been a while — Canitey here again.
⤷ Title: Finding an IDOR in Tesla From the Outside
════════════════════════
𐀪 Author: Asjad Butt
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:59:27 GMT
════════════════════════
⌗ Tags: #hacking #software_development #tesla #bugcrowd #bug_bounty
════════════════════════
𐀪 Author: Asjad Butt
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:59:27 GMT
════════════════════════
⌗ Tags: #hacking #software_development #tesla #bugcrowd #bug_bounty
Medium
Finding an IDOR in Tesla From the Outside
When you’re testing applications, you’ll eventually hit a wall — a point where the intended user flow just isn’t accessible.
⤷ Title: Encoding Bypasses | Complete Guide
════════════════════════
𐀪 Author: Amrsmooke
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:12:32 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #hacking #bug_bounty #encoding
════════════════════════
𐀪 Author: Amrsmooke
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:12:32 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #hacking #bug_bounty #encoding
Medium
Encoding Bypasses | Complete Guide
Common Encoding Types in Security
⤷ Title: Threat Modeling AI Systems: A Complete Playbook for Practitioners
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:00:55 GMT
════════════════════════
⌗ Tags: #ai_agent #ai_security #application_security #llm #threat_modeling
════════════════════════
𐀪 Author: Brett Crawley
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 10:00:55 GMT
════════════════════════
⌗ Tags: #ai_agent #ai_security #application_security #llm #threat_modeling
Medium
Threat Modeling AI Systems: A Complete Playbook for Practitioners
The Blast Radius — Edition [4]
⤷ Title: How I Reproduced WannaCry in a Lab — And What It Taught Me About Ransomware Defense
════════════════════════
𐀪 Author: Sukansh
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:10:49 GMT
════════════════════════
⌗ Tags: #infosec #programming #cybersecurity #ethical_hacking #malware_analysis
════════════════════════
𐀪 Author: Sukansh
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:10:49 GMT
════════════════════════
⌗ Tags: #infosec #programming #cybersecurity #ethical_hacking #malware_analysis
Medium
How I Reproduced WannaCry in a Lab — And What It Taught Me About Ransomware Defense
A step-by-step walkthrough of simulating the EternalBlue exploit chain, observing file encryption behavior, and building detection rules…
⤷ Title: Kerberoasting in 2026: Why “We Didn’t Crack It” Is Still a Critical Active Directory Finding
════════════════════════
𐀪 Author: Cameron Bardin (MDVKG)
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:26:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #active_directory #kerberoasting #kerberos #penetration_testing
════════════════════════
𐀪 Author: Cameron Bardin (MDVKG)
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:26:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #active_directory #kerberoasting #kerberos #penetration_testing
Medium
Kerberoasting in 2026: Why “We Didn’t Crack It” Is Still a Critical Active Directory Finding
And why “we ran the wordlist and got nothing” is the most dangerous sentence in a pentest debrief.
⤷ Title: Masquerade CTF Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:47:02 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #tryhackme_writeup #tryhackme #tryhackme_walkthrough #ctf_writeup
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 13:47:02 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #tryhackme_writeup #tryhackme #tryhackme_walkthrough #ctf_writeup
Medium
Masquerade CTF Notes | TryHackMe
Analyze malware traffic, decrypt payloads, and uncover attacker commands.
⤷ Title: The Dorking Manifesto: Uncovering the Hidden Web
════════════════════════
𐀪 Author: Ishant
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:47:41 GMT
════════════════════════
⌗ Tags: #ethical_hacking #osint #open_source #google_dorking #cybersecurity
════════════════════════
𐀪 Author: Ishant
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:47:41 GMT
════════════════════════
⌗ Tags: #ethical_hacking #osint #open_source #google_dorking #cybersecurity
Medium
The Dorking Manifesto: Uncovering the Hidden Web
“The internet forgets nothing. It only hides things badly.”
⤷ Title: Cyber Security: The First Line of Defense in a Connected World
════════════════════════
𐀪 Author: Arti Sandip Jadhav
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:39:39 GMT
════════════════════════
⌗ Tags: #ethical_hacking #online_safety #cybersecurity #data_security #technolo
════════════════════════
𐀪 Author: Arti Sandip Jadhav
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:39:39 GMT
════════════════════════
⌗ Tags: #ethical_hacking #online_safety #cybersecurity #data_security #technolo
Medium
🔐 Cyber Security: The First Line of Defense in a Connected World
Cybersecurity Is Now More Important Than Ever Before!
⤷ Title: Part 2 : Cross-Site Scripting (XSS)
════════════════════════
𐀪 Author: Protégé IGDTUW
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:14:58 GMT
════════════════════════
⌗ Tags: #xss_attack #web_attack #xss_vulnerability #xss_bypass
════════════════════════
𐀪 Author: Protégé IGDTUW
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:14:58 GMT
════════════════════════
⌗ Tags: #xss_attack #web_attack #xss_vulnerability #xss_bypass
Medium
Part 2 : Cross-Site Scripting (XSS)
Real-World Web Attacks Explained
⤷ Title: Part 1 : SQL Injection Attacks
════════════════════════
𐀪 Author: Protégé IGDTUW
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:15:49 GMT
════════════════════════
⌗ Tags: #sql_server #web_attack #sql #sql_injection
════════════════════════
𐀪 Author: Protégé IGDTUW
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 14:15:49 GMT
════════════════════════
⌗ Tags: #sql_server #web_attack #sql #sql_injection
Medium
Part 1 : SQL Injection Attacks
Real-World Web Attacks Explained
⤷ Title: Polymarket Rejects Data Breach Claims as Hacker Alleges 300K Records Stolen
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 16:22:03 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #Cyber Attack #Cybersecurity #data breach #Polymarket #Vulnerability #Xorcat
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 16:22:03 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #Cyber Attack #Cybersecurity #data breach #Polymarket #Vulnerability #Xorcat
Hackread
Polymarket Rejects Data Breach Claims as Hacker Alleges 300K Records Stolen
A hacker using the alias "Xorcat" claims to have breached Polymarket using API flaws, but research suggests the leak could be just data scraping incident.
⤷ Title: The “Mini Shai-Hulud” Attack Hijacking SAP Developer Pipelines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:04:51 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js/sqlite #aws security #Azure #Bun runtime #CI/CD security #credential stealer #infosec #Kubernetes #mbt #Mini Shai_Hulud #npm malware #SAP #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:04:51 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js/sqlite #aws security #Azure #Bun runtime #CI/CD security #credential stealer #infosec #Kubernetes #mbt #Mini Shai_Hulud #npm malware #SAP #supply chain attack
Daily CyberSecurity
The "Mini Shai-Hulud" Attack Hijacking SAP Developer Pipelines
SAP developers are under attack. A surgical credential stealer hijacks CI/CD runners and cloud tokens via npm preinstall hooks. Rotate all secrets immediately.
⤷ Title: When AI Coding Assistants Become Attack Vectors: Cursor Vulnerability Raises Developer Security…
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:00:54 GMT
════════════════════════
⌗ Tags: #application_security #ai_coding #devsecops #cybersecurity #ai
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:00:54 GMT
════════════════════════
⌗ Tags: #application_security #ai_coding #devsecops #cybersecurity #ai
Medium
When AI Coding Assistants Become Attack Vectors: Cursor Vulnerability Raises Developer Security…
The rapid adoption of AI powered coding assistants is transforming software development, but it is also introducing new security risks. A…
⤷ Title: Most Hacked Businesses Do the Wrong Things First
════════════════════════
𐀪 Author: Jusjaesho
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:40:17 GMT
════════════════════════
⌗ Tags: #incident_response #hacking #data_breach #small_business #cybersecurity
════════════════════════
𐀪 Author: Jusjaesho
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:40:17 GMT
════════════════════════
⌗ Tags: #incident_response #hacking #data_breach #small_business #cybersecurity
Medium
Most Hacked Businesses Do the Wrong Things First
The instinct is to panic. That’s understandable. What’s less understandable is that most of the advice circulating about what to do after a…
⤷ Title: entry 003 · SOC journey
════════════════════════
𐀪 Author: Naana Sarkodie
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:33:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #information_security #cyber_security_awareness #infosec #data_privacy
════════════════════════
𐀪 Author: Naana Sarkodie
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 15:33:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #information_security #cyber_security_awareness #infosec #data_privacy
Medium
entry 003 · SOC journey
Controls, categories and the data we are all protecting