⤷ Title: Kernel Dynamic Offset Resolution using PDB Symbols
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 12 May 2026 21:08:21 GMT
════════════════════════
⌗ Tags: #hacking #malware #infosec #cybersecurity #pentesting
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 12 May 2026 21:08:21 GMT
════════════════════════
⌗ Tags: #hacking #malware #infosec #cybersecurity #pentesting
Medium
Kernel Dynamic Offset Resolution using PDB Symbols
Welcome to this new Medium post. Today, I’ll show you an interesting approach to resolving kernel offsets dynamically. In previous BYOVD…
⤷ Title: CVE Program Report for Quarter 1 Calendar Year (Q1 CY) 2026
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:56:07 GMT
════════════════════════
⌗ Tags: #vulnerability #infosec #information_technology #information_security #cybersecurity
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:56:07 GMT
════════════════════════
⌗ Tags: #vulnerability #infosec #information_technology #information_security #cybersecurity
Medium
CVE Program Report for Quarter 1 Calendar Year (Q1 CY) 2026
The CVE Program’s quarterly summary of program milestones and metrics for Q1 CY 2026.
⤷ Title: Understanding Kerberos Delegation and Unconstrained Delegation
════════════════════════
𐀪 Author: cyberpro151
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:36:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking #red_team #authentication
════════════════════════
𐀪 Author: cyberpro151
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:36:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking #red_team #authentication
Medium
Understanding Kerberos Delegation and Unconstrained Delegation
Introduction:
⤷ Title: TryHackMe | Monitoring AWS Logins | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:05:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #aws #tryhackme_writeup #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:05:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #aws #tryhackme_writeup #cybersecurity #tryhackme
Medium
TryHackMe | Monitoring AWS Logins | WriteUp
Explore AWS authentication, common IAM threats, and SIEM detection options.
⤷ Title: TryHackMe | Web Server Attacks — I | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:03:41 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #cyber_security_awareness
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:03:41 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #cyber_security_awareness
Medium
TryHackMe | Web Server Attacks — I | WriteUp
Enumerate and identify misconfigurations across Apache, Nginx, Node.js, and Python HTTP Server.
⤷ Title: Portswigger Tüm XSS Zafiyetleri
════════════════════════
𐀪 Author: Huseyin KALKAN
════════════════════════
ⴵ Time: Tue, 12 May 2026 23:01:12 GMT
════════════════════════
⌗ Tags: #siber_guvenlik #türkçe #xs #web_güvenliği
════════════════════════
𐀪 Author: Huseyin KALKAN
════════════════════════
ⴵ Time: Tue, 12 May 2026 23:01:12 GMT
════════════════════════
⌗ Tags: #siber_guvenlik #türkçe #xs #web_güvenliği
Medium
Portswigger Tüm XSS Zafiyetleri
XSS zafiyeti nedir?
⤷ Title: NoSQL Injection Guide: Fundamentals, Types, Exploitation, and Mitigation
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 13 May 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #nosql #cybersecurity #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 13 May 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #nosql #cybersecurity #hacking
Medium
NoSQL Injection Guide: Fundamentals, Types, Exploitation, and Mitigation
Learn the basics of NoSQL injection, attack vectors in MongoDB, and advanced exploitation and defense strategies.
⤷ Title: OSCP Dailies: THM — Roasted — Day 1
════════════════════════
𐀪 Author: MichaelLearns_
════════════════════════
ⴵ Time: Tue, 12 May 2026 23:36:30 GMT
════════════════════════
⌗ Tags: #penetration_testing #smbclient #oscp #tryhackme #nmap
════════════════════════
𐀪 Author: MichaelLearns_
════════════════════════
ⴵ Time: Tue, 12 May 2026 23:36:30 GMT
════════════════════════
⌗ Tags: #penetration_testing #smbclient #oscp #tryhackme #nmap
Medium
OSCP Dailies: THM — Roasted — Day 1
This is part of my daily labs in preparation for OSCP. I am documenting everything I am learning, tools that I am using and reflections as…
⤷ Title: Regulated, Audited, and Breached: Hardening a Legacy API Under a Financial Regulator’s Watch
════════════════════════
𐀪 Author: Ggontar
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:55:15 GMT
════════════════════════
⌗ Tags: #type_safety #api #backend #sql_injection #appsec
════════════════════════
𐀪 Author: Ggontar
════════════════════════
ⴵ Time: Tue, 12 May 2026 22:55:15 GMT
════════════════════════
⌗ Tags: #type_safety #api #backend #sql_injection #appsec
Medium
Regulated, Audited, and Breached: Hardening a Legacy API Under a Financial Regulator’s Watch
As a financial services company, we were required by our regulator to conduct penetration testing. It wasn’t a nice-to-have or a proactive…
⤷ Title: Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:36:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BitLocker bypass #CTFMON #Elevation of Privilege #GreenPlasma #infosec #Microsoft #PoC #proof_of_concept #Windows Security #Windows zero_day #WinRE #YellowKey #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:36:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BitLocker bypass #CTFMON #Elevation of Privilege #GreenPlasma #infosec #Microsoft #PoC #proof_of_concept #Windows Security #Windows zero_day #WinRE #YellowKey #zero_day
Daily CyberSecurity
Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
Urgent: Public PoC exploit code released for YellowKey (BitLocker bypass) and GreenPlasma (SYSTEM elevation). Windows 11 and Server 2025 are at high risk.
⤷ Title: Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25786 #industrial automation #infosec #Manufacturing Security #OT Security #Patch Alert #PLC Security #Siemens #SIMATIC S7 #TIA Portal #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_25786 #industrial automation #infosec #Manufacturing Security #OT Security #Patch Alert #PLC Security #Siemens #SIMATIC S7 #TIA Portal #XSS
Daily CyberSecurity
Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers
Critical Siemens Alert: 9.3 severity XSS flaws hit SIMATIC S7 PLCs. Attackers can hijack sessions via web interfaces. Update to V3.1.6 or follow mitigations.
⤷ Title: 9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:30:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BrowserStack #CI/CD security #Command Injection #CVE_2026_25244 #DevOps #GitHub Security #infosec #rce #supply chain attack #Test Automation #WebdriverIO
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:30:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BrowserStack #CI/CD security #Command Injection #CVE_2026_25244 #DevOps #GitHub Security #infosec #rce #supply chain attack #Test Automation #WebdriverIO
Daily CyberSecurity
9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers
Critical Alert: CVE-2026-25244 (CVSS 9.8) in WebdriverIO allows RCE via unsanitized git branch names. Secure your CI/CD pipeline and update to 9.24.0 now.
⤷ Title: Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:18:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Azure AI Foundry #CVE_2026_41089 #Cyber Security #Hyper_V #infosec #M365 Copilot #Microsoft #Netlogon #Patch Tuesday #rce #SSO Bypass #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:18:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Azure AI Foundry #CVE_2026_41089 #Cyber Security #Hyper_V #infosec #M365 Copilot #Microsoft #Netlogon #Patch Tuesday #rce #SSO Bypass #Windows Security
Daily CyberSecurity
Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass
Microsoft’s May 2026 update fixes 137 vulnerabilities, including 30 Critical RCE and EoP flaws. Prioritize patches for Netlogon, Office, and M365 Copilot now.
⤷ Title: CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:02:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_43898 #infosec #JavaScript Security #rce #Remote Code Execution #Sandbox Escape #SandboxJS #Supply Chain Security #Vulnerability Alert #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:02:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_43898 #infosec #JavaScript Security #rce #Remote Code Execution #Sandbox Escape #SandboxJS #Supply Chain Security #Vulnerability Alert #Web Security
Daily CyberSecurity
CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover
Critical Alert: CVE-2026-43898 (CVSS 10) in SandboxJS allows a total sandbox escape and RCE. Update to version 0.9.6 immediately to secure your host.
⤷ Title: PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
Daily CyberSecurity
PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
Sysdig warns: PraisonAI (CVE-2026-44338) exploited in under 4 hours. Attackers bypassed auth to hijack agents and drain API quotas. Update to 4.6.34 now!
⤷ Title: 9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:43:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BDAT #CVE_2026_45185 #Exim #GnuTLS #heap corruption #infosec #Mail Server Security #Patch Now #rce #SMTP CHUNKING #Vulnerability Alert #XBOW
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:43:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BDAT #CVE_2026_45185 #Exim #GnuTLS #heap corruption #infosec #Mail Server Security #Patch Now #rce #SMTP CHUNKING #Vulnerability Alert #XBOW
Daily CyberSecurity
9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover
Urgent: Exim fixes a 9.8 severity RCE (CVE-2026-45185) affecting GnuTLS builds. A single-byte heap corruption allows for server takeover. Update to 4.99.3 now!
⤷ Title: Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:29:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control #CVE_2026_26083 #CVE_2026_44277 #Cyber Security #FortiAuthenticator #Fortinet #FortiSandbox #IAM #infosec #Patch Alert #rce #Web UI Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:29:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control #CVE_2026_26083 #CVE_2026_44277 #Cyber Security #FortiAuthenticator #Fortinet #FortiSandbox #IAM #infosec #Patch Alert #rce #Web UI Security
Daily CyberSecurity
Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover
Urgent: Fortinet warns of 9.1 severity flaws in FortiSandbox (CVE-2026-26083) and FortiAuthenticator (CVE-2026-44277). Patch now to prevent unauthorized RCE.
⤷ Title: Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:27:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #CVE_2026_2291 #DHCPv6 #DNS Cache Poisoning #dnsmasq #DNSSEC #infosec #IoT security #network_security #Root Privilege Escalation #Router Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:27:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #CVE_2026_2291 #DHCPv6 #DNS Cache Poisoning #dnsmasq #DNSSEC #infosec #IoT security #network_security #Root Privilege Escalation #Router Patch
Daily CyberSecurity
Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices
In the foundational architecture of small-to-medium networks and home routing devices, dnsmasq is the open-source networking tool that quietly handles DNS forwarding, DHCP, and network boot servic…
⤷ Title: Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:01:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Casdoor #CERT/CC #CVE_2026_44213 #Cyber Security #IAM Security #infosec #MCP #Model Context Protocol #Path Traversal #Vulnerability Alert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:01:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Casdoor #CERT/CC #CVE_2026_44213 #Cyber Security #IAM Security #infosec #MCP #Model Context Protocol #Path Traversal #Vulnerability Alert
Daily CyberSecurity
Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites
Urgent: Casdoor IAM platform hit by critical file write flaw (CVE-2026-44213). Attackers can bypass sandboxes to overwrite databases and gain host access.
⤷ Title: HSC RTV CTF — Msg Packed (Reversing — 250 pts)
════════════════════════
𐀪 Author: Life of a Pentester
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:03:04 GMT
════════════════════════
⌗ Tags: #hacking #ctf #reversing #reverse_engineering #cybersecurity
════════════════════════
𐀪 Author: Life of a Pentester
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:03:04 GMT
════════════════════════
⌗ Tags: #hacking #ctf #reversing #reverse_engineering #cybersecurity
Medium
HSC RTV CTF — Msg Packed (Reversing — 250 pts)
This reversing challenge was a little easy considering you know what the MessagePack format is, which is a serialized binary data. Think of…
⤷ Title: Forest — HTB Writeup
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:13:02 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #active_directory #hackthebox
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:13:02 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #active_directory #hackthebox
Medium
Forest — HTB Writeup
Introduction: