⤷ Title: The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
Daily CyberSecurity
The Sleeper in Your IDE: Unmasking the 73-Extension "GlassWorm" Espionage Campaign
Socket uncovers GlassWorm: a 73-extension sleeper campaign on Open VSX targeting VS Code and Cursor. Stealthy .node binaries turn trusted tools into malware.
⤷ Title: AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:11:58 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Code Editor #API keys #Credential Theft #Cursor AI #cybersecurity #Developer Tools #Extension Security #infosec #macOS #security vulnerability #SQLite #windows
Daily CyberSecurity
AI’s Open Secret: Why Your Cursor Extensions Can Silently Siphon Your API Keys
Cursor AI editor found storing API keys and tokens in an unprotected SQLite database, allowing extensions to steal credentials silently. CVSS 8.2. No patch yet.
⤷ Title: BUG-BOUNTY SERIES 8: DNS Enumeration.
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:27:14 GMT
════════════════════════
⌗ Tags: #linux #bug_bounty
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:27:14 GMT
════════════════════════
⌗ Tags: #linux #bug_bounty
Medium
BUG-BOUNTY SERIES 8: DNS Enumeration. Menggali Informasi Infrastruktur untuk Menemukan Celah Tersembunyi
Setelah pada Series 7 kita berhasil mengidentifikasi subdomain dan memperluas attack surface, langkah berikutnya yang tidak kalah penting…
⤷ Title: BUG-BOUNTY SERIES 7: Subdomain Enumeration & Attack Surface Mapping.
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:21:19 GMT
════════════════════════
⌗ Tags: #linux #bug_bounty
════════════════════════
𐀪 Author: Krisna Wahyu Andriawan
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:21:19 GMT
════════════════════════
⌗ Tags: #linux #bug_bounty
Medium
BUG-BOUNTY SERIES 7: Subdomain Enumeration & Attack Surface Mapping. Mengungkap Aset Tersembunyi dalam Target
Dalam praktik Bug Bounty, banyak vulnerability tidak ditemukan pada domain utama, melainkan pada subdomain yang terlupakan, tidak…
⤷ Title: Automating Endpoint Discovery & Testing — The Bug Hunter’s Workflow
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:04:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #security #bug_bounty #infosec
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:04:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #security #bug_bounty #infosec
Medium
🚀 Automating Endpoint Discovery & Testing — The Bug Hunter’s Workflow
From Manual Guessing → Full Recon Automation
⤷ Title: SHADOW PROTOCOL
Chapter 1: The One Who Said No (Revised)
The rain in Guwahati didn’t bother…
════════════════════════
𐀪 Author: Tapudhan Rongpee
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:44:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
Chapter 1: The One Who Said No (Revised)
The rain in Guwahati didn’t bother…
════════════════════════
𐀪 Author: Tapudhan Rongpee
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:44:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
Medium
SHADOW PROTOCOL
Chapter 1: The One Who Said No (Revised)
The rain in Guwahati didn’t bother…
Chapter 1: The One Who Said No (Revised)
The rain in Guwahati didn’t bother…
SHADOW PROTOCOL Chapter 1: The One Who Said No (Revised) The rain in Guwahati didn’t bother Tapudhan Rongpee. What bothered him… was silence. Tapan hadn’t replied in 12 minutes. That wasn’t …
⤷ Title: 10 Cybersecurity Best Practices to Protect Your Data in 2026
════════════════════════
𐀪 Author: CyberAlchemist Fahad
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:54:15 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #privacy #mystery #hacking
════════════════════════
𐀪 Author: CyberAlchemist Fahad
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:54:15 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #privacy #mystery #hacking
Medium
10 Cybersecurity Best Practices to Protect Your Data in 2026
It was 3 AM. The city was asleep, but my screen was alive with a flickering light. Somewhere, thousands of miles away, a silent shadow was…
⤷ Title: Kali Linux Desktop Customization
════════════════════════
𐀪 Author: fsocietyhub
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:37:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #infosec #kali_linux #linux
════════════════════════
𐀪 Author: fsocietyhub
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:37:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #infosec #kali_linux #linux
Medium
Kali Linux Desktop Customization
Engineering the custom fsocietyhub desktop experience
⤷ Title: TryHackMe — Brains Writeup
════════════════════════
𐀪 Author: Rootseekerx0x
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:16:40 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #tryhackme #cybersecurity #red_team
════════════════════════
𐀪 Author: Rootseekerx0x
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:16:40 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #tryhackme #cybersecurity #red_team
Medium
TryHackMe — Brains Writeup
Difficulty: Easy–Medium Room: https://tryhackme.com/room/brains Category: Web Exploitation / RCE / Blue Team Analysis Tools Used: Nmap…
⤷ Title: Extract | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:51:22 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #cybersecurity #vulnerability
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:51:22 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #cybersecurity #vulnerability
Medium
Extract | TryHackMe
Can you extract the secrets from the library?
⤷ Title: Chaining Vulnerabilities | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:48:15 GMT
════════════════════════
⌗ Tags: #chaining_vulnerabilities #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:48:15 GMT
════════════════════════
⌗ Tags: #chaining_vulnerabilities #tryhackme #cybersecurity
Medium
Chaining Vulnerabilities | TryHackMe
Learn how to chain vulnerabilities! From Low to High!
⤷ Title: Best Ethical Hacking Training in Noida | Ducat India
════════════════════════
𐀪 Author: Ehsankkhan
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 06:59:19 GMT
════════════════════════
⌗ Tags: #ethical #ethical_ai #ethical_hacking
════════════════════════
𐀪 Author: Ehsankkhan
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 06:59:19 GMT
════════════════════════
⌗ Tags: #ethical #ethical_ai #ethical_hacking
Medium
Best Ethical Hacking Training in Noida | Ducat India
In today’s digital era, cybersecurity has become a paramount concern for individuals and
⤷ Title: Best Ethical Hacking Training in Noida | Ducat India
════════════════════════
𐀪 Author: Rabh
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 06:57:00 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ethical_ai #ethical
════════════════════════
𐀪 Author: Rabh
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 06:57:00 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ethical_ai #ethical
Medium
Best Ethical Hacking Training in Noida | Ducat India
In today’s digital era, cybersecurity has become a paramount concern for individuals and
⤷ Title: Best Ethical Hacking Training in Noida | Ducat India
════════════════════════
𐀪 Author: SalezTech
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 06:56:05 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ethical_ai #ethical
════════════════════════
𐀪 Author: SalezTech
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 06:56:05 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ethical_ai #ethical
Medium
Best Ethical Hacking Training in Noida | Ducat India
In today’s digital era, cybersecurity has become a paramount concern for individuals and
⤷ Title: Menguak Celah Keamanan SQL Injection: Eksperimen Login Sederhana pada Aplikasi Berbasis PHP
════════════════════════
𐀪 Author: Gfierazchaa
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:24:12 GMT
════════════════════════
⌗ Tags: #web_development #sql_injection #keamanan_web #programing_web
════════════════════════
𐀪 Author: Gfierazchaa
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:24:12 GMT
════════════════════════
⌗ Tags: #web_development #sql_injection #keamanan_web #programing_web
Medium
Menguak Celah Keamanan SQL Injection: Eksperimen Login Sederhana pada Aplikasi Berbasis PHP
1. Pendahuluan
⤷ Title: Analisis Kerentanan SQL Injection: Studi Eksperimental pada Sistem Autentikasi Berbasis PHP dan…
════════════════════════
𐀪 Author: Ubaydillahrafi
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:00:56 GMT
════════════════════════
⌗ Tags: #sql_injection
════════════════════════
𐀪 Author: Ubaydillahrafi
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 07:00:56 GMT
════════════════════════
⌗ Tags: #sql_injection
Medium
Analisis Kerentanan SQL Injection: Studi Eksperimental pada Sistem Autentikasi Berbasis PHP dan…
1. Pendahuluan
⤷ Title: New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 14:54:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 14:54:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: NVIDIA Patches High-Severity “Prompt Injection” Flaw in NemoClaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 09:01:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_24222 #CVE_2026_24231 #cybersecurity #infosec #nvidia #NVIDIA NemoClaw #Patch Alert #Prompt injection #Sandbox Security #ssrf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 09:01:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_24222 #CVE_2026_24231 #cybersecurity #infosec #nvidia #NVIDIA NemoClaw #Patch Alert #Prompt injection #Sandbox Security #ssrf
Daily CyberSecurity
NVIDIA Patches High-Severity "Prompt Injection" Flaw in NemoClaw
NVIDIA patches a critical 8.6 CVSS flaw in NemoClaw. Prompt injection could leak sensitive host secrets. Upgrade to v0.0.18 to secure your AI agent sandboxes.
⤷ Title: Authenticated SSRF and Graph API Authorization Bypass via URL Normalization in a Vendor-Authored…
════════════════════════
𐀪 Author: Gouri Sankar A
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 10:29:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec
════════════════════════
𐀪 Author: Gouri Sankar A
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 10:29:45 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec
Medium
Authenticated SSRF and Graph API Authorization Bypass via URL Normalization in a Vendor-Authored…
Hey folks, I am back with a new writeup. This one is about two chained vulnerabilities I found in a vendor-authored MCP server…
⤷ Title: AI-Powered Pentesting: How a Team of Digital Interns is Revolutionizing Cybersecurity
════════════════════════
𐀪 Author: Tamer Hellah
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 10:39:23 GMT
════════════════════════
⌗ Tags: #red_team #application_security #ai_agent #penetration_testing #ethical_hacking
════════════════════════
𐀪 Author: Tamer Hellah
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 10:39:23 GMT
════════════════════════
⌗ Tags: #red_team #application_security #ai_agent #penetration_testing #ethical_hacking
Medium
🤖 AI-Powered Pentesting: How a Team of Digital Interns is Revolutionizing Cybersecurity
The Scaling Crisis Nobody’s Talking About
⤷ Title: Your Brain Is the Biggest Vulnerability
════════════════════════
𐀪 Author: theAutoBot
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 09:23:42 GMT
════════════════════════
⌗ Tags: #hacking #phishing_awareness #social_engineering #human_hacking
════════════════════════
𐀪 Author: theAutoBot
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 09:23:42 GMT
════════════════════════
⌗ Tags: #hacking #phishing_awareness #social_engineering #human_hacking
Medium
Your Brain Is the Biggest Vulnerability
Firewalls can be patched. Passwords can be reset. But the 3-pound organ behind your eyes? That’s a zero-day exploit that’s been in…