⤷ Title: Path Traversal Vulnerability in Go: From Source Code Review to Exploitation
════════════════════════
𐀪 Author: Sanaullah Aman Korai
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 18:47:27 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_security #ethical_hacking #cybersecurity #go_programming
════════════════════════
𐀪 Author: Sanaullah Aman Korai
════════════════════════
ⴵ Time: Sat, 04 Apr 2026 18:47:27 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_security #ethical_hacking #cybersecurity #go_programming
Medium
Path Traversal Vulnerability in Go: From Source Code Review to Exploitation
Introduction
⤷ Title: Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 09:15:50 +0000
════════════════════════
⌗ Tags: #Malware #CrystalX RAT #Cyber Trolling #Go malware #infosec #kaspersky #MaaS #Malware Analysis #Prankware #Remote Access Trojan #spyware #Telegram #Webcrystal RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 09:15:50 +0000
════════════════════════
⌗ Tags: #Malware #CrystalX RAT #Cyber Trolling #Go malware #infosec #kaspersky #MaaS #Malware Analysis #Prankware #Remote Access Trojan #spyware #Telegram #Webcrystal RAT
Daily CyberSecurity
Trolling as a Service: How the New CrystalX RAT Uses "Prankware" to Torture Its Victims
Kaspersky uncovers CrystalX RAT, a malicious MaaS on Telegram that pairs data theft with "prankware" to troll victims and lock systems. Patch now!
⤷ Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Daily CyberSecurity
The 1,700-Package Blitz: North Korea’s "Contagious Interview" Infiltrates Every Major Dev Registry
North Korea’s "Contagious Interview" campaign expands to 1,700+ malicious packages across npm, PyPI, and more. Learn how to protect your dev environment.
⤷ Title: Team Cymru Mapped the Yurei Ransomware Toolkit Before It Could Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:20:15 +0000
════════════════════════
⌗ Tags: #Malware #Double Extortion #go programming #infosec #open_source malware #Prince ransomware #Ransomware Tool Matrix #SatanLockv2 #Team Cymru #threat intelligence #Yurei ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:20:15 +0000
════════════════════════
⌗ Tags: #Malware #Double Extortion #go programming #infosec #open_source malware #Prince ransomware #Ransomware Tool Matrix #SatanLockv2 #Team Cymru #threat intelligence #Yurei ransomware
Daily CyberSecurity
Team Cymru Mapped the Yurei Ransomware Toolkit Before It Could Strike
Team Cymru unmasks Yurei ransomware, a "Stranger Things" themed operation built on open-source code. Learn how proactive telemetry mapped their toolkit.
⤷ Title: The High-Stakes Return of 0xFFF: ‘notnullOSX’ Stealer Targets macOS Crypto Whales
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:30:33 +0000
════════════════════════
⌗ Tags: #Malware #0xFFF #alh1mik #ClickFix #Crypto Stealer #cyber_espionage #DeFi Security #Go malware #Hardware Wallet #macOS Malware #Moonlock Lab #notnullOSX
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 02:30:33 +0000
════════════════════════
⌗ Tags: #Malware #0xFFF #alh1mik #ClickFix #Crypto Stealer #cyber_espionage #DeFi Security #Go malware #Hardware Wallet #macOS Malware #Moonlock Lab #notnullOSX
Daily CyberSecurity
The High-Stakes Return of 0xFFF: 'notnullOSX' Stealer Targets macOS Crypto Whales
Moonlock Lab reveals notnullOSX, a predatory macOS stealer targeting crypto users with $10k+ holdings. See how it uses ClickFix to hijack wallet apps.
⤷ Title: CVE-2026-40884: Critical 9.8 Bypass Hits goshs SFTP Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 12:06:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_40884 #CVSS 9.8 #cybersecurity #Go Security #goshs #infosec #pentesting tools #SFTP #SimpleHTTPServer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 12:06:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_40884 #CVSS 9.8 #cybersecurity #Go Security #goshs #infosec #pentesting tools #SFTP #SimpleHTTPServer
Daily CyberSecurity
CVE-2026-40884: Critical 9.8 Bypass Hits goshs SFTP Servers
Critical 9.8 flaw in goshs (CVE-2026-40884) allows unauthenticated SFTP access when using specific auth syntax. Secure your files—upgrade to v2.0.0-beta.6 now!
⤷ Title: Unpatch Ollama Flaw: Malicious Model Uploads Can Leak Server Heap Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 13:05:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_5757 #GGUF #Go Security #Heap Leak #Information Disclosure #infosec #LLM Security #Ollama #Quantization Engine #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 13:05:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_5757 #GGUF #Go Security #Heap Leak #Information Disclosure #infosec #LLM Security #Ollama #Quantization Engine #zero_day
Daily CyberSecurity
Unpatch Ollama Flaw: Malicious Model Uploads Can Leak Server Heap Memory
A critical unauthenticated remote information disclosure vulnerability has been uncovered in Ollama, the popular open-source tool used to run LLMs on macOS, Windows, and Linux. The flaw, tracked a…
⤷ Title: Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:03:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Thrift #C++ #CVE_2026_41603 #cybersecurity #go #infosec #java #memory corruption #mitm #Node.js #RPC Security #swift
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 12:03:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Thrift #C++ #CVE_2026_41603 #cybersecurity #go #infosec #java #memory corruption #mitm #Node.js #RPC Security #swift
Daily CyberSecurity
Apache Thrift Issues Massive Patch for Critical Cross-Language Flaws
Apache Thrift fixes critical cross-language vulnerabilities (MitM, memory corruption, DoS). Secure your Java, Go, and C++ stacks by upgrading to version 0.23.0.
⤷ Title: Minirat’s Stealth Supply Chain Attack Targets macOS Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 01:59:57 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #2026 #cybersecurity #developer security #go #infosec #macOS #Malware Analysis #Minirat #npm #Remote Access Trojan #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 01:59:57 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #2026 #cybersecurity #developer security #go #infosec #macOS #Malware Analysis #Minirat #npm #Remote Access Trojan #supply chain attack
Daily CyberSecurity
Minirat’s Stealth Supply Chain Attack Targets macOS Developers
Minirat, a Go-based macOS RAT, exploits npm supply chains to bypass security. It features VM detection, AES encryption, and persistence. Secure your dev tools.
⤷ Title: Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
Daily CyberSecurity
Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
Socket uncovers a BufferZoneCorp "sleeper" campaign targeting Ruby and Go. Malicious packages steal SSH keys and subvert CI/CD pipelines. Patch now!
⤷ Title: Poisoned Code: Stealthy Malicious Go Module Backdoor Discovered in Long-Running Typosquat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 09:01:53 +0000
════════════════════════
⌗ Tags: #Malware #DNS TXT backdoor #Go module #proxy.golang.org #rce #Remote Code Execution #shopspring/decimal #shopsprint/decimal #Socket Security #supply chain attack #typosquat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 09:01:53 +0000
════════════════════════
⌗ Tags: #Malware #DNS TXT backdoor #Go module #proxy.golang.org #rce #Remote Code Execution #shopspring/decimal #shopsprint/decimal #Socket Security #supply chain attack #typosquat
Daily CyberSecurity
Poisoned Code: Stealthy Malicious Go Module Backdoor Discovered in Long-Running Typosquat
Security researchers have exposed a malicious Go module backdoor hidden inside the shopsprint/decimal package that executes code using stealthy DNS TXT records.
⤷ Title: AI Honeypots Snare Decentralized Cryptominer Dropper
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 06:03:24 +0000
════════════════════════
⌗ Tags: #Malware #Akamai SIRT #cryptomining #Go malware #libp2p #Ollama Security #P2P Malware #threat intelligence #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Jun 2026 06:03:24 +0000
════════════════════════
⌗ Tags: #Malware #Akamai SIRT #cryptomining #Go malware #libp2p #Ollama Security #P2P Malware #threat intelligence #XMRig
Daily CyberSecurity
AI Honeypots Snare Decentralized Cryptominer Dropper
Akamai SIRT uncovers a new P2P cryptominer malware threat. Learn how Ollama endpoint attacks use decentralized libp2p networks to evade detection.
⤷ Title: Prinz Eugen Ransomware Encrypts Recent Files First and Leaves No Note
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 03:41:09 +0000
════════════════════════
⌗ Tags: #Malware #Go Malware #Prinz Eugen #ransomware #RDP #Standard Bank #ThreatDown
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 03:41:09 +0000
════════════════════════
⌗ Tags: #Malware #Go Malware #Prinz Eugen #ransomware #RDP #Standard Bank #ThreatDown
Information Security News
Prinz Eugen Ransomware Encrypts Recent Files First and Leaves No Note
At a Glance Field Detail Malware family Prinz Eugen (Go-based ransomware, .prinzeugen extension) Threat actor Prinz Eugen group; linked to the operator handle ROOTBOY (suspected) Victims At least …
⤷ Title: PolinRider Supply Chain Attack Spans npm, Go, Chrome
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 08:38:34 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #Go Modules Security #North Korea Hackers #NPM Malware #PolinRider #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 08:38:34 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #Go Modules Security #North Korea Hackers #NPM Malware #PolinRider #supply chain attack
Information Security News
PolinRider Supply Chain Attack Spans npm, Go, Chrome
PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The ca…
⤷ Title: Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 07:59:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60004 #diffpatch #Git Hook #Gitea #go #rce #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 07:59:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60004 #diffpatch #Git Hook #Gitea #go #rce #Remote Code Execution
Daily CyberSecurity
Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed
TL;DR A critical Gitea RCE flaw now has public details and a proof-of-concept exploit. Tracked as CVE-2026-60004, it scores a CVSS of 9.8. A user with repository write access can run shell command…