⤷ Title: Filtros em APIs REST não são só query params
════════════════════════
𐀪 Author: Erik Barroso
════════════════════════
ⴵ Time: Thu, 07 May 2026 22:11:41 GMT
════════════════════════
⌗ Tags: #filtros #sql_injection #sql #api #rest_api
════════════════════════
𐀪 Author: Erik Barroso
════════════════════════
ⴵ Time: Thu, 07 May 2026 22:11:41 GMT
════════════════════════
⌗ Tags: #filtros #sql_injection #sql #api #rest_api
Medium
Você provavelmente está implementando filtros errado na sua API REST
Filtros parecem apenas query params, mas envolvem validação, segurança, autorização, performance, paginação, cache e consistência de…
⤷ Title: ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:55:50 +0000
════════════════════════
⌗ Tags: #Hacking News #Data Breaches #Security #Canvas #Cyber Attack #Cyber Crime #Cybersecurity #Instructure #LMS #Ransom #ShinyHunters #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:55:50 +0000
════════════════════════
⌗ Tags: #Hacking News #Data Breaches #Security #Canvas #Cyber Attack #Cyber Crime #Cybersecurity #Instructure #LMS #Ransom #ShinyHunters #Vulnerability
Hackread
ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected
ShinyHunters hackers defaced the official Canvas LMS portal after breaching Instructure systems, disrupting university access worldwide.
⤷ Title: A Critical IDOR That Allowed Me to Delete Any User Account
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:40:39 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #hackerone #bug_bounty #bugcrowd
════════════════════════
𐀪 Author: mrx_w_
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:40:39 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #hackerone #bug_bounty #bugcrowd
Medium
A Critical IDOR That Allowed Me to Delete Any User Account
Hi, I’m mrx_w_ (Adem Ziane Berroudja), a bug bounty hunter on Bugcrowd. You can find me on Twitter and LinkedIn under mrx_w_. In this…
⤷ Title: How CrowdStrike Outran SentinelOne While Running the Same Race
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Fri, 08 May 2026 00:36:29 GMT
════════════════════════
⌗ Tags: #cyberattack #crowdstrike #cybersecurity #hacking #sentinelone
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Fri, 08 May 2026 00:36:29 GMT
════════════════════════
⌗ Tags: #cyberattack #crowdstrike #cybersecurity #hacking #sentinelone
Medium
How CrowdStrike Outran SentinelOne While Running the Same Race
How CrowdStrike Outran SentinelOne While Running the Same Race CrowdStrike now generates roughly five times the revenue of SentinelOne, trades at five times the EV-to-revenue multiple, and commands a …
⤷ Title: More than a Ping Sweep: A Pentester’s Enumeration Methodology
════════════════════════
𐀪 Author: Andrew Chacon
════════════════════════
ⴵ Time: Fri, 08 May 2026 00:20:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #infosec #ethical_hacking #hacking
════════════════════════
𐀪 Author: Andrew Chacon
════════════════════════
ⴵ Time: Fri, 08 May 2026 00:20:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #infosec #ethical_hacking #hacking
Medium
More than a Ping Sweep: A Pentester’s Enumeration Methodology
Pentesting is as much about the process as it is about the tools we use. What a successful engagement really comes down to is how thorough…
⤷ Title: DiskFiltration — TryHackMe Writeup
════════════════════════
𐀪 Author: empise
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:57:53 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #cybersecurity #tryhackme_writeup #digital_forensics
════════════════════════
𐀪 Author: empise
════════════════════════
ⴵ Time: Thu, 07 May 2026 23:57:53 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #cybersecurity #tryhackme_writeup #digital_forensics
Medium
DiskFiltration — TryHackMe Writeup
After spending some time on Modules I decided to take a chip at a challenge and this caught my eye :)
⤷ Title: AWS Elastic Beanstalk Pentesting with AWS CLI
════════════════════════
𐀪 Author: Abdiraxman Omar
════════════════════════
ⴵ Time: Fri, 08 May 2026 00:56:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #cloud_security #aws #pentesting
════════════════════════
𐀪 Author: Abdiraxman Omar
════════════════════════
ⴵ Time: Fri, 08 May 2026 00:56:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #cloud_security #aws #pentesting
Medium
AWS Elastic Beanstalk Pentesting with AWS CLI
Disclaimer: This walkthrough was performed in a controlled lab environment for educational and authorized security testing purposes only.
⤷ Title: Embargo Broken: Public PoC Released for “Dirty Frag” Linux Kernel Exploit Granting Instant Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:39:52 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2026_Pending #cybersecurity #Dirty Frag #Hyunwoo Kim #infosec #Linux Kernel #Local Privilege Escalation #LPE #Page Cache #PoC #Root Exploit #v4bel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:39:52 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2026_Pending #cybersecurity #Dirty Frag #Hyunwoo Kim #infosec #Linux Kernel #Local Privilege Escalation #LPE #Page Cache #PoC #Root Exploit #v4bel
Daily CyberSecurity
Embargo Broken: Public PoC Released for "Dirty Frag" Linux Kernel Exploit Granting Instant Root Access
Dirty Frag PoC released! Researcher v4bel discloses a universal Linux root exploit targeting the page cache. No patches yet—apply module mitigations now!
⤷ Title: Critical 9.9 CVSS Rancher Fleet Flaw Grants Full Cluster-Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:29:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_41050 #cybersecurity #Fleet #GitOps #Helm Deployer #infosec #Kubernetes Security #Multi_tenancy #Patch Alert #ServiceAccount Impersonation #SUSE Rancher
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:29:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_41050 #cybersecurity #Fleet #GitOps #Helm Deployer #infosec #Kubernetes Security #Multi_tenancy #Patch Alert #ServiceAccount Impersonation #SUSE Rancher
Daily CyberSecurity
Critical 9.9 CVSS Rancher Fleet Flaw Grants Full Cluster-Admin Access
Rancher Fleet fixes a 9.9 CVSS flaw (CVE-2026-41050) allowing tenants to bypass ServiceAccount isolation and steal secrets. Upgrade your GitOps engine now!
⤷ Title: Zabbix Flaws Allow Monitored Hosts to Hijack Admin Dashboards
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:10:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23926 #CVE_2026_23928 #cybersecurity #infosec #network monitoring #Oracle Injection #Patch Alert #Stored XSS #XSS #Zabbix #Zabbix Agent 2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:10:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_23926 #CVE_2026_23928 #cybersecurity #infosec #network monitoring #Oracle Injection #Patch Alert #Stored XSS #XSS #Zabbix #Zabbix Agent 2
Daily CyberSecurity
Zabbix Flaws Allow Monitored Hosts to Hijack Admin Dashboards
Zabbix fixes high-severity XSS (CVE-2026-23926) and Oracle injection flaws. Don't let your monitoring tool become a backdoor—upgrade your Zabbix server now!
⤷ Title: خلل في التحكم بالوصول / IDOR في تدفق دعوة المجموعة
════════════════════════
𐀪 Author: Ahmed Atef (0xMintsX)
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:24:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #access_control #cybersecurity #web_application_security #api_security
════════════════════════
𐀪 Author: Ahmed Atef (0xMintsX)
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:24:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #access_control #cybersecurity #web_application_security #api_security
Medium
خلل في التحكم بالوصول / IDOR في تدفق دعوة المجموعة
{وَآتَاكُم م كُلِّ مَا سَأَلْتُمُوهُ ۚ وَإِن تَعُدُّوا نِعْمَتَ اللَّهِ لا تُحْصُوهُ ۗ }
⤷ Title: The Invisible Lock: Hunting a Broken Request Signing Mechanism in a Mobile App
════════════════════════
𐀪 Author: Blue_eye
════════════════════════
ⴵ Time: Fri, 08 May 2026 02:31:00 GMT
════════════════════════
⌗ Tags: #hacking #software_development #mobile #cryptography
════════════════════════
𐀪 Author: Blue_eye
════════════════════════
ⴵ Time: Fri, 08 May 2026 02:31:00 GMT
════════════════════════
⌗ Tags: #hacking #software_development #mobile #cryptography
Medium
The Invisible Lock: Hunting a Broken Request Signing Mechanism in a Mobile App
An educational deep dive into mobile application security assessment, reverse engineering, and the illusion of security through obscurity.
⤷ Title: Breaking Authentication Through Password Change Logic Flaws — PortSwigger Lab Walkthrough
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:04:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybernerddd #hacking #ctf #portswigger
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:04:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybernerddd #hacking #ctf #portswigger
Medium
Breaking Authentication Through Password Change Logic Flaws — PortSwigger Lab Walkthrough
Authentication mechanisms are often heavily protected against brute-force attacks on the main login page. However, developers sometimes…
⤷ Title: JetBrains Lab Write-Up | By BnHany
════════════════════════
𐀪 Author: BnHany
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:13:02 GMT
════════════════════════
⌗ Tags: #infosec #network_security #soc_analyst #cybersecurity #network_forensics
════════════════════════
𐀪 Author: BnHany
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:13:02 GMT
════════════════════════
⌗ Tags: #infosec #network_security #soc_analyst #cybersecurity #network_forensics
Medium
JetBrains Lab Write-Up | By BnHany
⚠️ Disclaimer ⚠️ This write-up is for educational purposes only. It is meant to explain the thought process and steps taken to solve the…
⤷ Title: API 2 : Broken Authentication
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:58:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #api_security #cybersecurity #web_security #owasp_api_security_top_10
════════════════════════
𐀪 Author: Vaibhav
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:58:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #api_security #cybersecurity #web_security #owasp_api_security_top_10
Medium
API 2 : Broken Authentication
Theory
⤷ Title: Panduan Expert Tools Katana dalam Penetration Testing
════════════════════════
𐀪 Author: Ahmat Prayoga Sembiring
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:44:53 GMT
════════════════════════
⌗ Tags: #offensive_security #ethical_hacking #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: Ahmat Prayoga Sembiring
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:44:53 GMT
════════════════════════
⌗ Tags: #offensive_security #ethical_hacking #bug_bounty #penetration_testing
Medium
Panduan Expert Tools Katana dalam Penetration Testing
“Saat pentest web, masalah terbesar bukan langsung cari celah.
Tapi… kita bahkan tidak tahu semua endpoint yang ada di aplikasi itu.”
Tapi… kita bahkan tidak tahu semua endpoint yang ada di aplikasi itu.”
⤷ Title: Slort | ProvingGrounds | OSCP Preparation
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Fri, 08 May 2026 03:14:02 GMT
════════════════════════
⌗ Tags: #hacking #hacker #bug_bounty #ethical_hacking #ctf
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Fri, 08 May 2026 03:14:02 GMT
════════════════════════
⌗ Tags: #hacking #hacker #bug_bounty #ethical_hacking #ctf
Medium
Slort | ProvingGrounds | OSCP Preparation
Lets start off with a nmap scan against the target:
⤷ Title: The Great Canvas Compromise: What Happens When Bots Take Over Collaborative Pixel Art
════════════════════════
𐀪 Author: Biplove Yadav
════════════════════════
ⴵ Time: Fri, 08 May 2026 03:30:23 GMT
════════════════════════
⌗ Tags: #ransomware #technews #canvas #hacking
════════════════════════
𐀪 Author: Biplove Yadav
════════════════════════
ⴵ Time: Fri, 08 May 2026 03:30:23 GMT
════════════════════════
⌗ Tags: #ransomware #technews #canvas #hacking
Medium
The Great Canvas Compromise: What Happens When Bots Take Over Collaborative Pixel Art
A deep dive into the recent canvas hack, the rise of pixel-perfect botnets, and how the internet community is fighting back.
⤷ Title: Palo Alto PAN-OS Zero-Day CVE-2026–0300 — State-Sponsored Attackers Have Had Root Access to Your…
════════════════════════
𐀪 Author: Sai kiran
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:33:14 GMT
════════════════════════
⌗ Tags: #firewall_security #infosec #cybersecurity #zero_day #patch
════════════════════════
𐀪 Author: Sai kiran
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:33:14 GMT
════════════════════════
⌗ Tags: #firewall_security #infosec #cybersecurity #zero_day #patch
Medium
Palo Alto PAN-OS Zero-Day CVE-2026–0300 — State-Sponsored Attackers Have Had Root Access to Your…
CVSS 9.3. No authentication. No patch until May 13. And Unit 42 has confirmed a likely state-sponsored threat actor has been exploiting…
⤷ Title: ⚠️ Parameter Tampering Attacks Explained With Examples
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:30:47 GMT
════════════════════════
⌗ Tags: #infosec #web_development #cyber_security_awareness #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:30:47 GMT
════════════════════════
⌗ Tags: #infosec #web_development #cyber_security_awareness #ethical_hacking #cybersecurity
Medium
⚠️ Parameter Tampering Attacks Explained With Examples
🧠 Introduction
⤷ Title: Directory Brute Forcing: Finding Hidden Files and Folders
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:23:50 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_development #cybersecurity #ethical_hacking #infosec
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Fri, 08 May 2026 04:23:50 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_development #cybersecurity #ethical_hacking #infosec
Medium
Directory Brute Forcing: Finding Hidden Files and Folders
Introduction