⤷ Title: Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:10:04 +0000
════════════════════════
⌗ Tags: #Data Breaches #Cyber Crime #Security #Canvas #Cyber Attack #Cybersecurity #Data leak #Instructure #Ransom #ShinyHunters
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:10:04 +0000
════════════════════════
⌗ Tags: #Data Breaches #Cyber Crime #Security #Canvas #Cyber Attack #Cybersecurity #Data leak #Instructure #Ransom #ShinyHunters
Hackread
Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak
Instructure has reached an agreement with the ShinyHunters group to return and destroy stolen Canvas data, protecting millions of student records from a public leak.
⤷ Title: I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Wed, 13 May 2026 22:02:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #writeup #bug_bounty #web_penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Wed, 13 May 2026 22:02:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #writeup #bug_bounty #web_penetration_testing #cybersecurity
Medium
I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain
Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzads
⤷ Title: 1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in…
════════════════════════
𐀪 Author: Wordfence
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:37:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #wordpress
════════════════════════
𐀪 Author: Wordfence
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:37:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #wordpress
Medium
1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in…
On March 21, 2026, the Wordfence Intelligence Vulnerability Database received submissions for two vulnerabilities in Avada Builder, a…
⤷ Title: Bug Bounty: The Reward Hunters of the Digital World
════════════════════════
𐀪 Author: Ziya Gokalp
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:32:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #cyberattack #bounty_hunter #bug_bounty
════════════════════════
𐀪 Author: Ziya Gokalp
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:32:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #cyberattack #bounty_hunter #bug_bounty
Medium
Bug Bounty: The Reward Hunters of the Digital World
Introduction
⤷ Title: A $250,000 Chrome Sandbox Escape: Breaking Out of the Browser from the Inside
════════════════════════
𐀪 Author: Yua Mikanana
════════════════════════
ⴵ Time: Wed, 13 May 2026 22:54:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #hacking #ethical_hacking #technology
════════════════════════
𐀪 Author: Yua Mikanana
════════════════════════
ⴵ Time: Wed, 13 May 2026 22:54:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #hacking #ethical_hacking #technology
Medium
A $250,000 Chrome Sandbox Escape: Breaking Out of the Browser from the Inside
Reference and source credit: https://issues.chromium.org/issues/412578726
⤷ Title: OverTheWire Bandit Walkthrough — Level 2 → 3 | 30-Day Cybersecurity Learning Journey (Day 3)
════════════════════════
𐀪 Author: William | Cybersecurity & SOC Analyst
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:32:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #linux #ctf #security #infosec
════════════════════════
𐀪 Author: William | Cybersecurity & SOC Analyst
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:32:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #linux #ctf #security #infosec
Medium
OverTheWire Bandit Walkthrough — Level 2 → 3 | 30-Day Cybersecurity Learning Journey (Day 3)
Reading a file with spaces in its name and why handling filenames correctly is a daily reality in Linux security work.
⤷ Title: Mitmproxy as Alternative to Burp Suite Macros
════════════════════════
𐀪 Author: Revan A
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:00:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #red_team #pentesting #cybersecurity
════════════════════════
𐀪 Author: Revan A
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:00:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #red_team #pentesting #cybersecurity
Medium
Mitmproxy as Alternative to Burp Suite Macros
Beberapa aplikasi atau website udah terapin “signature”. Dan biasanya pentester kesulitan, jadi gw mau kasih alternatif, yaitu mitmproxy
⤷ Title: VulnHub — Shenron: 1 | Full Walkthrough
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:37:45 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ctf_writeup #vulnhub #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Wed, 13 May 2026 21:37:45 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ctf_writeup #vulnhub #cybersecurity #penetration_testing
Medium
VulnHub — Shenron: 1 | Full Walkthrough
Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzads Platform: VulnHub Machine: Shenron: 1 by…
⤷ Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
Hackread
TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
TeamPCP claims to be selling alleged Mistral AI repositories on a hacker forum after the Mini Shai-Hulud attack targeted npm and PyPI ecosystems.
⤷ Title: OPNsense Critical Root RCE (CVE-2026-44194 & CVE-2026-45158) Details and PoC Disclosed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:54:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_44194 #CVE_2026_45158 #Cyber Security #DHCP Security #firewall security #infosec #OPNsense #Patch Alert #PoC #proof_of_concept #rce #root access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:54:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_44194 #CVE_2026_45158 #Cyber Security #DHCP Security #firewall security #infosec #OPNsense #Patch Alert #PoC #proof_of_concept #rce #root access
Daily CyberSecurity
OPNsense Critical Root RCE (CVE-2026-44194 & CVE-2026-45158) Details and PoC Disclosed
Urgent: Public PoC for OPNsense CVE-2026-44194 and CVE-2026-45158. Critical flaws allow root command execution via DHCP and User sync. Update to 26.1.8 now!
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Critical 18-Year-Old NGINX RCE (CVE-2026-42945) and GitHub PoC Disclosed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:20:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_42945 #Cyber Security #github #Heap Buffer Overflow #infosec #nginx #NGINX Plus #Patch Alert #PoC #proof_of_concept #rce #Rewrite Module
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:20:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_42945 #Cyber Security #github #Heap Buffer Overflow #infosec #nginx #NGINX Plus #Patch Alert #PoC #proof_of_concept #rce #Rewrite Module
Daily CyberSecurity
Critical 18-Year-Old NGINX RCE (CVE-2026-42945) and GitHub PoC Disclosed
Security researcher Zhenpeng (Leo) Lin of depthfirst has unveiled a critical, 18-year-old vulnerability lurking within NGINX. The flaw, tracked as CVE-2026-42945 (CVSS 9.2), is a deterministic hea…
⤷ Title: XSS to Database Exfiltration
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:58 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #web_security #bug_bounty #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:58 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #web_security #bug_bounty #penetration_testing #cybersecurity
Medium
XSS to Database Exfiltration
After identifying dozens of XSS vulnerabilities, as explained in my previous write-up, the next step was to maximize their impact.
⤷ Title: JWT, OAuth, and Every Auth Method You’ll Meet in Web App Testing—Explained Simply
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #bug_bounty_writeup #ethical_hacking #bug_bounty
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #bug_bounty_writeup #ethical_hacking #bug_bounty
Medium
JWT, OAuth, and Every Auth Method You’ll Meet in Web App Testing—Explained Simply
A no-fluff guide to JWT, OAuth 2.0, sessions, MFA, and every auth method you’ll attack as a tester.
⤷ Title: The Story of 45+ Stored XSS Bugs
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:18:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #web_penetration_testing #cross_site_scripting #penetration_testing
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:18:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #web_penetration_testing #cross_site_scripting #penetration_testing
Medium
The Story of 45+ Stored XSS Bugs
The simple methodology that allowed me to discover dozens of XSS bugs…
⤷ Title: HTB Academy — Windows Fundamentals
════════════════════════
𐀪 Author: akawave
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:41:45 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup
════════════════════════
𐀪 Author: akawave
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:41:45 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup
Medium
HTB Academy — Windows Fundamentals
Hi everyone!
⤷ Title: The Lethal Trifecta: How AI Agents With Tool Access Turn Prompt Injection Into RCE
════════════════════════
𐀪 Author: Engr. Ishola
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:11:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #agentic_ai #ai #rce #cyber_sec
════════════════════════
𐀪 Author: Engr. Ishola
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:11:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #agentic_ai #ai #rce #cyber_sec
Medium
The Lethal Trifecta: How AI Agents With Tool Access Turn Prompt Injection Into RCE
What every security practitioner should know about the new injection sink hiding inside your AI assistants
⤷ Title: Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:19:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Canon Marketing Japan #CVE_2026_32661 #Exploit in the Wild #GUARDIANWALL MailSuite #infosec #JPCERT/CC #Mail Security #Patch Alert #rce #stack_based buffer overflow #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:19:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Canon Marketing Japan #CVE_2026_32661 #Exploit in the Wild #GUARDIANWALL MailSuite #infosec #JPCERT/CC #Mail Security #Patch Alert #rce #stack_based buffer overflow #zero_day
Daily CyberSecurity
Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
CVE-2026-32661 exploited in the wild. A 9.8 CVSS flaw in GUARDIANWALL MailSuite allows unauthenticated RCE. Apply Canon's official patches immediately.
⤷ Title: 200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Burst Statistics #CVE_2026_8181 #Cyber Security #Exploit in the Wild #infosec #MainWP #Patch Alert #rce #Wordfence #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Burst Statistics #CVE_2026_8181 #Cyber Security #Exploit in the Wild #infosec #MainWP #Patch Alert #rce #Wordfence #wordpress security
Daily CyberSecurity
200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild
200,000+ sites hit by CVE-2026-8181. A 9.8 CVSS Burst Statistics flaw allows RCE via auth bypass. 5,000+ attacks blocked. Update to 3.4.2 immediately!
⤷ Title: Architectural Breach: AMD Zen 2 Flaw Allows Higher-Privilege Instruction Corruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #BIOS Update #CPU Security #CVE_2025_54518 #EPYC #Hardware Vulnerability #infosec #Micro_op Cache #privilege escalation #Ryzen #Zen 2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #BIOS Update #CPU Security #CVE_2025_54518 #EPYC #Hardware Vulnerability #infosec #Micro_op Cache #privilege escalation #Ryzen #Zen 2
Daily CyberSecurity
Architectural Breach: AMD Zen 2 Flaw Allows Higher-Privilege Instruction Corruption
Urgent: AMD Zen 2 processors (Ryzen/EPYC) hit by CVE-2025-54518. Hardware flaw allows instruction corruption and privilege escalation. Update your BIOS now!
⤷ Title: GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:39:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CE #CVE_2026_7481 #Cyber Security #DevOps Security #dos #EE #gitlab #GitLab 18.11.3 #GitLab Security Patch #infosec #Patch Alert #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:39:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CE #CVE_2026_7481 #Cyber Security #DevOps Security #dos #EE #gitlab #GitLab 18.11.3 #GitLab Security Patch #infosec #Patch Alert #XSS
Daily CyberSecurity
GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances
GitLab patches high-severity XSS (8.7 CVSS) and unauthenticated DoS flaws in versions 18.11.3, 18.10.6, and 18.9.7. Secure your DevOps pipeline now!