⤷ Title: XSS to Database Exfiltration
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:58 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #web_security #bug_bounty #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:58 GMT
════════════════════════
⌗ Tags: #cross_site_scripting #web_security #bug_bounty #penetration_testing #cybersecurity
Medium
XSS to Database Exfiltration
After identifying dozens of XSS vulnerabilities, as explained in my previous write-up, the next step was to maximize their impact.
⤷ Title: JWT, OAuth, and Every Auth Method You’ll Meet in Web App Testing—Explained Simply
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #bug_bounty_writeup #ethical_hacking #bug_bounty
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:58:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #authentication #bug_bounty_writeup #ethical_hacking #bug_bounty
Medium
JWT, OAuth, and Every Auth Method You’ll Meet in Web App Testing—Explained Simply
A no-fluff guide to JWT, OAuth 2.0, sessions, MFA, and every auth method you’ll attack as a tester.
⤷ Title: The Story of 45+ Stored XSS Bugs
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:18:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #web_penetration_testing #cross_site_scripting #penetration_testing
════════════════════════
𐀪 Author: He4am
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:18:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #web_penetration_testing #cross_site_scripting #penetration_testing
Medium
The Story of 45+ Stored XSS Bugs
The simple methodology that allowed me to discover dozens of XSS bugs…
⤷ Title: HTB Academy — Windows Fundamentals
════════════════════════
𐀪 Author: akawave
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:41:45 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup
════════════════════════
𐀪 Author: akawave
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:41:45 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup
Medium
HTB Academy — Windows Fundamentals
Hi everyone!
⤷ Title: The Lethal Trifecta: How AI Agents With Tool Access Turn Prompt Injection Into RCE
════════════════════════
𐀪 Author: Engr. Ishola
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:11:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #agentic_ai #ai #rce #cyber_sec
════════════════════════
𐀪 Author: Engr. Ishola
════════════════════════
ⴵ Time: Wed, 13 May 2026 23:11:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #agentic_ai #ai #rce #cyber_sec
Medium
The Lethal Trifecta: How AI Agents With Tool Access Turn Prompt Injection Into RCE
What every security practitioner should know about the new injection sink hiding inside your AI assistants
⤷ Title: Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:19:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Canon Marketing Japan #CVE_2026_32661 #Exploit in the Wild #GUARDIANWALL MailSuite #infosec #JPCERT/CC #Mail Security #Patch Alert #rce #stack_based buffer overflow #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:19:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Canon Marketing Japan #CVE_2026_32661 #Exploit in the Wild #GUARDIANWALL MailSuite #infosec #JPCERT/CC #Mail Security #Patch Alert #rce #stack_based buffer overflow #zero_day
Daily CyberSecurity
Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
CVE-2026-32661 exploited in the wild. A 9.8 CVSS flaw in GUARDIANWALL MailSuite allows unauthenticated RCE. Apply Canon's official patches immediately.
⤷ Title: 200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Burst Statistics #CVE_2026_8181 #Cyber Security #Exploit in the Wild #infosec #MainWP #Patch Alert #rce #Wordfence #wordpress security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Burst Statistics #CVE_2026_8181 #Cyber Security #Exploit in the Wild #infosec #MainWP #Patch Alert #rce #Wordfence #wordpress security
Daily CyberSecurity
200K Sites at Risk: 9.8 CVSS RCE via Burst Statistics Auth Bypass Exploited in the Wild
200,000+ sites hit by CVE-2026-8181. A 9.8 CVSS Burst Statistics flaw allows RCE via auth bypass. 5,000+ attacks blocked. Update to 3.4.2 immediately!
⤷ Title: Architectural Breach: AMD Zen 2 Flaw Allows Higher-Privilege Instruction Corruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #BIOS Update #CPU Security #CVE_2025_54518 #EPYC #Hardware Vulnerability #infosec #Micro_op Cache #privilege escalation #Ryzen #Zen 2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #BIOS Update #CPU Security #CVE_2025_54518 #EPYC #Hardware Vulnerability #infosec #Micro_op Cache #privilege escalation #Ryzen #Zen 2
Daily CyberSecurity
Architectural Breach: AMD Zen 2 Flaw Allows Higher-Privilege Instruction Corruption
Urgent: AMD Zen 2 processors (Ryzen/EPYC) hit by CVE-2025-54518. Hardware flaw allows instruction corruption and privilege escalation. Update your BIOS now!
⤷ Title: GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:39:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CE #CVE_2026_7481 #Cyber Security #DevOps Security #dos #EE #gitlab #GitLab 18.11.3 #GitLab Security Patch #infosec #Patch Alert #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:39:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CE #CVE_2026_7481 #Cyber Security #DevOps Security #dos #EE #gitlab #GitLab 18.11.3 #GitLab Security Patch #infosec #Patch Alert #XSS
Daily CyberSecurity
GitLab Critical Patch: High-Severity XSS and Unauthenticated DoS Flaws Hit Self-Managed Instances
GitLab patches high-severity XSS (8.7 CVSS) and unauthenticated DoS flaws in versions 18.11.3, 18.10.6, and 18.9.7. Secure your DevOps pipeline now!
⤷ Title: Critical 9.6 Severity Ivanti Xtraction Flaw Exposes Sensitive Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:36:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_8043 #Cyber Security #Data Exposure #infosec #Ivanti Xtraction #Patch Update #Path Traversal #Vulnerability Alert #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:36:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_8043 #Cyber Security #Data Exposure #infosec #Ivanti Xtraction #Patch Update #Path Traversal #Vulnerability Alert #Web Security
Daily CyberSecurity
Critical 9.6 Severity Ivanti Xtraction Flaw Exposes Sensitive Data
Ivanti issues an urgent patch for CVE-2026-8043, a critical 9.6 CVSS flaw in Xtraction allowing attackers to read files and write malicious HTML. Update now!
⤷ Title: Critical MongoDB Flaw CVE-2026-8053 Paves the Way for Server Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:09:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2026_8053 #Cyber Security #database security #infosec #Mongod #mongodb #Patch Alert #rce #Time_Series Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:09:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2026_8053 #Cyber Security #database security #infosec #Mongod #mongodb #Patch Alert #rce #Time_Series Data
Daily CyberSecurity
Critical MongoDB Flaw CVE-2026-8053 Paves the Way for Server Takeover
Urgent: A memory corruption flaw in MongoDB time-series collections (CVE-2026-8053) enables server takeover. Patch to versions 8.3.2, 8.0.23, or 7.0.34 now.
⤷ Title: Exploiting LLM APIs with Excessive Agency | PortSwigger
════════════════════════
𐀪 Author: Kate D Terracore
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:58:07 GMT
════════════════════════
⌗ Tags: #ai #portswigger #llm #bug_bounty #excessive_agency
════════════════════════
𐀪 Author: Kate D Terracore
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:58:07 GMT
════════════════════════
⌗ Tags: #ai #portswigger #llm #bug_bounty #excessive_agency
Medium
Exploiting LLM APIs with Excessive Agency | PortSwigger
Excessive agency occurs when an LLM is given too much power over system APIs and can be persuaded to act unsafely, letting attackers use…
⤷ Title: SharePoint and OneDrive as Exfil Channels
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:09:14 GMT
════════════════════════
⌗ Tags: #microsoft #hacking #cybersecurity #bug_bounty #programming
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:09:14 GMT
════════════════════════
⌗ Tags: #microsoft #hacking #cybersecurity #bug_bounty #programming
Medium
SharePoint and OneDrive as Exfil Channels
Data exfiltration doesn’t always look like a hacker sending files to a sketchy IP in Eastern Europe. Modern attackers increasingly…
⤷ Title: No Password. No MFA Prompt. Just a Stolen Cookie: A Hands-On AiTM Phishing Walkthrough with Evilginx
════════════════════════
𐀪 Author: Dion Alexander
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:56:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #hacking #ethical_hacking #technology
════════════════════════
𐀪 Author: Dion Alexander
════════════════════════
ⴵ Time: Thu, 14 May 2026 02:56:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #hacking #ethical_hacking #technology
Medium
No Password. No MFA Prompt. Just a Stolen Cookie: A Hands-On AiTM Phishing Walkthrough with Evilginx
Building a custom phishlet, capturing creds and session cookies, replaying them to bypass MFA, and what defenders can actually do about it.
⤷ Title: Visibility and Control: THREATRADAR’s Dashboards and data Retention
════════════════════════
𐀪 Author: Salma El Fekih
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #data_visualization #elasticsearch #cyber_threat_intelligence #infosec #kibana
════════════════════════
𐀪 Author: Salma El Fekih
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:35:44 GMT
════════════════════════
⌗ Tags: #data_visualization #elasticsearch #cyber_threat_intelligence #infosec #kibana
Medium
Visibility and Control: THREATRADAR’s Dashboards and data Retention
Welcome to the final article of the THREATRADAR series. If you’ve followed the series, you’ve seen how raw open source data is collected…
⤷ Title: From Vercel Typosquatting to an Obfuscated macOS Malware Loader
════════════════════════
𐀪 Author: Ashish Bogati
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:35:40 GMT
════════════════════════
⌗ Tags: #infosec #malware #cybersecurity #reverse_engineering #information_security
════════════════════════
𐀪 Author: Ashish Bogati
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:35:40 GMT
════════════════════════
⌗ Tags: #infosec #malware #cybersecurity #reverse_engineering #information_security
Medium
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
ux dictonary
⤷ Title: From Detection to SOC Action : How THREATRADAR Turns MISP Into a Living Intelligence
════════════════════════
𐀪 Author: Salma El Fekih
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:14:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #misp #machine_learning #threat_intelligence #infosec
════════════════════════
𐀪 Author: Salma El Fekih
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:14:08 GMT
════════════════════════
⌗ Tags: #cybersecurity #misp #machine_learning #threat_intelligence #infosec
Medium
From Detection to SOC Action : How THREATRADAR Turns MISP Into a Living Intelligence
Welcome to the fifth article in the THREATRADAR series. We recommend reading Part 1 Design and Implementation of THREATRADAR: Open-Source…
⤷ Title: Active — HTB Writeup
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:15:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #windows #ethical_hacking #active_directory #hackthebox
════════════════════════
𐀪 Author: William Shively
════════════════════════
ⴵ Time: Thu, 14 May 2026 01:15:16 GMT
════════════════════════
⌗ Tags: #penetration_testing #windows #ethical_hacking #active_directory #hackthebox
Medium
Active — HTB Writeup
Introduction:
⤷ Title: Install LiteLLM AI Gateway Locally with OpenRouter
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:57:07 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity #how_to #penetration_testing #litellm
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:57:07 GMT
════════════════════════
⌗ Tags: #ai #cybersecurity #how_to #penetration_testing #litellm
Medium
Install LiteLLM AI Gateway Locally with OpenRouter
Hi everyone, in this article we’ll learn how we can install LiteLLM locally on our desktop.
⤷ Title: Salesforce API Attack Surface: A Practical Recon Guide
════════════════════════
𐀪 Author: Dzianis Skliar
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:48:59 GMT
════════════════════════
⌗ Tags: #reconnaissance #penetration_testing #osint
════════════════════════
𐀪 Author: Dzianis Skliar
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:48:59 GMT
════════════════════════
⌗ Tags: #reconnaissance #penetration_testing #osint
Medium
Salesforce API Attack Surface: A Practical Recon Guide
Mapping the Salesforce API surface from documentation to endpoints — and why 2025 made it the most-targeted SaaS platform of the year.
⤷ Title: RiskwareSupplyChain: A Freemium Software Supply Chain Risk Intelligence Tool
════════════════════════
𐀪 Author: grepStrength
════════════════════════
ⴵ Time: Thu, 14 May 2026 04:41:43 GMT
════════════════════════
⌗ Tags: #software_development #npm #software_engineering #application_security #cybersecurity
════════════════════════
𐀪 Author: grepStrength
════════════════════════
ⴵ Time: Thu, 14 May 2026 04:41:43 GMT
════════════════════════
⌗ Tags: #software_development #npm #software_engineering #application_security #cybersecurity
Medium
RiskwareSupplyChain: A Freemium Software Supply Chain Risk Intelligence Tool
Frustration Meets Function