⤷ Title: GraphQL API Vulnerability: From Lab Swagger to Battle-Ready
════════════════════════
𐀪 Author: Vrajbhai
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:01:22 GMT
════════════════════════
⌗ Tags: #api #graphql #bug_bounty #vulnerability #cybersecurity
════════════════════════
𐀪 Author: Vrajbhai
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:01:22 GMT
════════════════════════
⌗ Tags: #api #graphql #bug_bounty #vulnerability #cybersecurity
Medium
GraphQL API Vulnerability: From Lab Swagger to Battle-Ready
GraphQL is quickly becoming the standard for modern APIs, but as the saying goes, “with great power comes great responsibility” — or in our…
⤷ Title: If Carrie Bradshaw was a Security Engineer in the AI era, she would write this article
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:55:30 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #threat_modeling #ai #application_security
════════════════════════
𐀪 Author: h@shtalk
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:55:30 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #threat_modeling #ai #application_security
Medium
If Carrie Bradshaw was a Security Engineer in the AI era, she would write this article
A security engineer’s honest, slightly unhinged, deeply practical guide to actually using AI in your daily workflow
⤷ Title: GOAD — MiniLAB Walkthrough
════════════════════════
𐀪 Author: serkanbenol
════════════════════════
ⴵ Time: Sun, 10 May 2026 20:07:27 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #pentesting #active_directory #hacks
════════════════════════
𐀪 Author: serkanbenol
════════════════════════
ⴵ Time: Sun, 10 May 2026 20:07:27 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #pentesting #active_directory #hacks
Medium
GOAD — MiniLAB Walkthrough
GOAD (Game of Active Directory) is a fantastic lab for practicing AD pentest techniques. In this post, I’ll walk through how I fully…
⤷ Title: The great 2026 Canvas-ocalypse
════════════════════════
𐀪 Author: Bryan Alexander
════════════════════════
ⴵ Time: Sun, 10 May 2026 20:00:38 GMT
════════════════════════
⌗ Tags: #university #college #hacking #edtech #technology
════════════════════════
𐀪 Author: Bryan Alexander
════════════════════════
ⴵ Time: Sun, 10 May 2026 20:00:38 GMT
════════════════════════
⌗ Tags: #university #college #hacking #edtech #technology
Medium
The great 2026 Canvas-ocalypse
Posted on May 10, 2026 by Bryan Alexander
⤷ Title: Passkeys Aren’t Nearly as Effective as We Thought
════════════════════════
𐀪 Author: Curtis Brazzell
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:51:15 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #information_security #cyber_security_awareness #infosec
════════════════════════
𐀪 Author: Curtis Brazzell
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:51:15 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #information_security #cyber_security_awareness #infosec
Medium
Passkeys Aren’t Nearly as Effective as We Thought
At Least, Not How Most Are Implemented Today
⤷ Title: Thoughts About Certified Offensive AI Expert (COAE)
════════════════════════
𐀪 Author: Ahmad Allobani
════════════════════════
ⴵ Time: Sun, 10 May 2026 20:19:26 GMT
════════════════════════
⌗ Tags: #ai #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Ahmad Allobani
════════════════════════
ⴵ Time: Sun, 10 May 2026 20:19:26 GMT
════════════════════════
⌗ Tags: #ai #penetration_testing #cybersecurity
Medium
Thoughts About Certified Offensive AI Expert (COAE)
Everyone talks about AI. I break it.
⤷ Title: Breaking Out of the Matryoshka — A TryHackMe Container Escape Walkthrough
════════════════════════
𐀪 Author: Th3B0yWh0L1v3d
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:30:31 GMT
════════════════════════
⌗ Tags: #docker #cybersecurity #ctf_writeup #container_security #tryhackme
════════════════════════
𐀪 Author: Th3B0yWh0L1v3d
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:30:31 GMT
════════════════════════
⌗ Tags: #docker #cybersecurity #ctf_writeup #container_security #tryhackme
Medium
Breaking Out of the Matryoshka — A TryHackMe Container Escape Walkthrough
“You set up a containment unit designed to trap and contain even the most nefarious viruses, but you accidentally got trapped in it while…
⤷ Title: Stack Trace Exposure via Malformed Authorization Header
════════════════════════
𐀪 Author: Hamza
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:22:03 GMT
════════════════════════
⌗ Tags: #offensive_security #bugs #security #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Hamza
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:22:03 GMT
════════════════════════
⌗ Tags: #offensive_security #bugs #security #cybersecurity #bug_bounty
Medium
Stack Trace Exposure via Malformed Authorization Header
Weakness: Information Exposure Through an Error Message
Severity:Medium (6.1)
Status: Triaged (Open) — Fix Pending
Severity:Medium (6.1)
Status: Triaged (Open) — Fix Pending
⤷ Title: Exposed Database Dump via Directory Listing on ETH Zurich Infrastructure
════════════════════════
𐀪 Author: Hamza
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:21:34 GMT
════════════════════════
⌗ Tags: #bug_bounty #security #cybersecurity
════════════════════════
𐀪 Author: Hamza
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:21:34 GMT
════════════════════════
⌗ Tags: #bug_bounty #security #cybersecurity
Medium
Exposed Database Dump via Directory Listing on ETH Zurich Infrastructure
Weakness:Sensitive Information Disclosure / Improper Access Control
Severity: High
Status: Resolved
Program: Responsible Disclosure…
Severity: High
Status: Resolved
Program: Responsible Disclosure…
⤷ Title: Detecting Remote Thread Creation with Windows Driver
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 10 May 2026 21:15:16 GMT
════════════════════════
⌗ Tags: #pentesting #malware #cybersecurity #hacking #infosec
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 10 May 2026 21:15:16 GMT
════════════════════════
⌗ Tags: #pentesting #malware #cybersecurity #hacking #infosec
Medium
Detecting Remote Thread Creation with Windows Driver
Welcome to this new Medium post, today I will show you an interesting way used by security software to detect the remote thread creation in…
⤷ Title: OSCP Dailies: THM — Attacktive Directory — Day 3
════════════════════════
𐀪 Author: MichaelLearns_
════════════════════════
ⴵ Time: Sun, 10 May 2026 21:13:52 GMT
════════════════════════
⌗ Tags: #impacket #kerbrute #oscp #tryhackme #pentesting
════════════════════════
𐀪 Author: MichaelLearns_
════════════════════════
ⴵ Time: Sun, 10 May 2026 21:13:52 GMT
════════════════════════
⌗ Tags: #impacket #kerbrute #oscp #tryhackme #pentesting
Medium
OSCP Dailies: THM — Attacktive Directory — Day 3
This is part of my daily labs in preparation for OSCP. I am documenting everything I am learning, tools that I am using and reflections as…
⤷ Title: Cicada
════════════════════════
𐀪 Author: Mohamed Hassan
════════════════════════
ⴵ Time: Sun, 10 May 2026 21:33:31 GMT
════════════════════════
⌗ Tags: #windows #windows_pentesting #network_penetration #hackthebox_writeup
════════════════════════
𐀪 Author: Mohamed Hassan
════════════════════════
ⴵ Time: Sun, 10 May 2026 21:33:31 GMT
════════════════════════
⌗ Tags: #windows #windows_pentesting #network_penetration #hackthebox_writeup
Medium
Cicada
Machines from HTB
⤷ Title: Prompt Injection Was Just the Beginning: Real AI Supply Chain Attacks Are Here in 2026
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:07:43 GMT
════════════════════════
⌗ Tags: #vector_database #indirect_prompt_injection #supply_chain_security #api_security #ai_security
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:07:43 GMT
════════════════════════
⌗ Tags: #vector_database #indirect_prompt_injection #supply_chain_security #api_security #ai_security
Medium
Prompt Injection Was Just the Beginning: Real AI Supply Chain Attacks Are Here in 2026
How indirect prompt injection, vector database poisoning, and agentic trust exploits are reshaping enterprise AI security.
⤷ Title: Remote Code Execution via Insecure Deserialization in Wazuh XDR/SIEM (CVE-2026–25769)
════════════════════════
𐀪 Author: Kevin Dicks
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:24:11 GMT
════════════════════════
⌗ Tags: #cve #insecure_deserialization #rce
════════════════════════
𐀪 Author: Kevin Dicks
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:24:11 GMT
════════════════════════
⌗ Tags: #cve #insecure_deserialization #rce
Medium
Remote Code Execution via Insecure Deserialization in Wazuh XDR/SIEM (CVE-2026–25769)
Abstract
⤷ Title: Data Destruction and Memory Poisoning: Spring AI Vulnerabilities Threaten LLM Integrity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 00:27:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_41705 #CVE_2026_41712 #CVE_2026_41713 #cybersecurity #Data Leakage #DevSecOps #LLM Vulnerabilities #Milvus VectorStore #Prompt injection #Spring AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 00:27:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_41705 #CVE_2026_41712 #CVE_2026_41713 #cybersecurity #Data Leakage #DevSecOps #LLM Vulnerabilities #Milvus VectorStore #Prompt injection #Spring AI
Daily CyberSecurity
Data Destruction and Memory Poisoning: Spring AI Vulnerabilities Threaten LLM Integrity
Protect your AI apps. Spring AI issues urgent patches for three critical vulnerabilities causing data destruction, memory poisoning, and user data leaks.
⤷ Title: Burp Suite Enterprise resource exhaustion via huge request body
════════════════════════
𐀪 Author: Armarms
════════════════════════
ⴵ Time: Mon, 11 May 2026 00:57:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability #application_security #cybersecurity #web_security
════════════════════════
𐀪 Author: Armarms
════════════════════════
ⴵ Time: Mon, 11 May 2026 00:57:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability #application_security #cybersecurity #web_security
Medium
Burp Suite Enterprise resource exhaustion via huge request body
Burp Suite Enterprise resource exhaustion via huge request body The /api-internal/login endpoint had no request body size limits at all. Zero checks in Jetty, no proxy limits, nothing. I sent one …
⤷ Title: HackTheBox: Campfire-1 Sherlock Walkthrough
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Sun, 10 May 2026 23:01:00 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox_walkthrough #cybersecurity #dfir #hackthebox
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Sun, 10 May 2026 23:01:00 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox_walkthrough #cybersecurity #dfir #hackthebox
Medium
HackTheBox: Campfire-1 Sherlock Walkthrough
Detecting Kerberoasting Activity: Correlating Kerberos Events, PowerShell Logs, and Prefetch Artifacts
⤷ Title: I Exploited a Banking API Using Burp Suite, JWT Manipulation, and Authorization Bypass Testing
════════════════════════
𐀪 Author: Hafsah Ashraf
════════════════════════
ⴵ Time: Sun, 10 May 2026 23:18:54 GMT
════════════════════════
⌗ Tags: #api_security #pentesting
════════════════════════
𐀪 Author: Hafsah Ashraf
════════════════════════
ⴵ Time: Sun, 10 May 2026 23:18:54 GMT
════════════════════════
⌗ Tags: #api_security #pentesting
Medium
I Exploited a Banking API Using Burp Suite, JWT Manipulation, and Authorization Bypass Testing
Most people learning cybersecurity spend time reading about vulnerabilities.
⤷ Title: Beyond Text: How Google Gemini’s New Multimodal RAG Turns Images and PDFs into Actionable Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 02:54:20 +0000
════════════════════════
⌗ Tags: #Technology #AI Development #AI Studio #enterprise AI #File Search #Gemini Embedding 2 #Google Cloud #Google Gemini API #Knowledge Base #Multimodal RAG #PDF Analysis #RAG Workflow #Vector Search
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 02:54:20 +0000
════════════════════════
⌗ Tags: #Technology #AI Development #AI Studio #enterprise AI #File Search #Gemini Embedding 2 #Google Cloud #Google Gemini API #Knowledge Base #Multimodal RAG #PDF Analysis #RAG Workflow #Vector Search
Daily CyberSecurity
Beyond Text: How Google Gemini’s New Multimodal RAG Turns Images and PDFs into Actionable Intelligence
Google Gemini API expands file search with Multimodal RAG. Featuring image-text retrieval, custom metadata, and page-level citations for enterprise AI.
⤷ Title: Optimization or Artifice? The Truth Behind the Windows 11 “Low Latency Profile” and CPU Speed Bursts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 02:50:47 +0000
════════════════════════
⌗ Tags: #Windows #CPU Boost #Hardware Performance #Low Latency Profile #Microsoft #Operating System Optimization #Scott Hanselman #Start Menu Fix #Tech News 2026 #UI Performance #Windows 11 #Windows 11 Lag
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 02:50:47 +0000
════════════════════════
⌗ Tags: #Windows #CPU Boost #Hardware Performance #Low Latency Profile #Microsoft #Operating System Optimization #Scott Hanselman #Start Menu Fix #Tech News 2026 #UI Performance #Windows 11 #Windows 11 Lag
Daily CyberSecurity
Optimization or Artifice? The Truth Behind the Windows 11 "Low Latency Profile" and CPU Speed Bursts
Microsoft is testing a "Low Latency Profile" to fix Windows 11 UI lag with 3-second CPU bursts. Is it lazy engineering or a sophisticated industry standard?
⤷ Title: Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 02:15:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache CloudStack #Backup Plugin #Cloud Security #CVE_2026_25077 #CVE_2026_25199 #DevOps #Infrastructure Security #KVM RCE #Patch Alert #Proxmox #VM Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 02:15:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache CloudStack #Backup Plugin #Cloud Security #CVE_2026_25077 #CVE_2026_25199 #DevOps #Infrastructure Security #KVM RCE #Patch Alert #Proxmox #VM Hijacking
Daily CyberSecurity
Patch Now: Apache CloudStack Plugs Proxmox and KVM Exploits in New LTS Release
Urgent: Apache CloudStack patches critical flaws (CVE-2026-25199, CVE-2026-25077) enabling VM hijacking and KVM host RCE. Secure your cloud environment now.