⤷ Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Daily CyberSecurity
AI "Vibe Coding" Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
AI "vibe coding" and the EvilTokens PhaaS platform are supercharging device code phishing to bypass Microsoft 365 MFA. Secure your network today!
⤷ Title: Microsoft Explains the New “SecureBoot” Folder in Windows 11 KB5089549 Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
⌗ Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:43:42 +0000
════════════════════════
⌗ Tags: #Windows #C:\Windows\SecureBoot #Detect_SecureBootCertUpdateStatus #Device Security #Enterprise Fleet Management #KB5089549 #PowerShell Script #Secure Boot Expiration #Trust Chain Renovation #UEFI CA 2023 #Windows 11 May Update
Daily CyberSecurity
Microsoft Explains the New "SecureBoot" Folder in Windows 11 KB5089549 Update
Seeing a new SecureBoot folder under C:Windows? Microsoft confirms it is part of an essential KB5089549 update to replace expiring 2011 UEFI certificates.
⤷ Title: Curiosity, never giving up, and a little adventure — that’s all it takes!
════════════════════════
𐀪 Author: Ghost
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:57:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacker #ethical_hacking #red_team #penetration_testing
════════════════════════
𐀪 Author: Ghost
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:57:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacker #ethical_hacking #red_team #penetration_testing
Medium
Curiosity, never giving up, and a little adventure — that’s all it takes!
You guys want to see some real hacking? Well, get ready — let’s goooooooooooooooooooooooooooooooooo!
⤷ Title: The XSS Escalation Playbook: From Basic Reflection to DOM Breakouts
════════════════════════
𐀪 Author: Sau Rav
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:33:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_attack #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Sau Rav
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:33:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_attack #penetration_testing #cybersecurity
Medium
The XSS Escalation Playbook: From Basic Reflection to DOM Breakouts
A comprehensive breakdown of mapping, context breakouts, WAF evasion, and DOM architecture attacks.
⤷ Title: The Ultimate Guide to Launching a Cyber Security Career: Why Hands-On Summer Internship Training is…
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:59:51 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Varun Papnai
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:59:51 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ethical_hacking
Medium
The Ultimate Guide to Launching a Cyber Security Career: Why Hands-On Summer Internship Training is…
The landscape of entry-level engineering and technology recruitment has fundamentally shifted. Gone are the days when a stellar academic…
⤷ Title: Exposing the Scam Industry — Ethical Investigation, OSINT & Scam Infrastructure Analysis (Series…
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:21:21 GMT
════════════════════════
⌗ Tags: #hacking #security #true_crime #money #osint
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:21:21 GMT
════════════════════════
⌗ Tags: #hacking #security #true_crime #money #osint
Medium
🎭 Exposing the Scam Industry — Ethical Investigation, OSINT & Scam Infrastructure Analysis (Series Introduction)
By Ghostyjoe
⤷ Title: Network Revision — PART 6
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:59:59 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_development #ethical_hacking #infosec #cybersecurity
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Tue, 19 May 2026 04:59:59 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_development #ethical_hacking #infosec #cybersecurity
Medium
Network Revision — PART 6
Module 3 How the web works ?
⤷ Title: The Dark Side of QR Codes Nobody Talks About
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:45:23 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:45:23 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing
Medium
The Dark Side of QR Codes Nobody Talks About
How One Simple Scan Can Open the Door to Scams, Malware, and Digital Theft 📱⚠️
⤷ Title: TryHackMe — GamingServer Writeup
════════════════════════
𐀪 Author: Mahmoudaltawel
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:36:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #ethical_hacking #penetration_testing #ctf
════════════════════════
𐀪 Author: Mahmoudaltawel
════════════════════════
ⴵ Time: Tue, 19 May 2026 05:36:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #ethical_hacking #penetration_testing #ctf
Medium
TryHackMe — GamingServer Writeup
By: Mahmoud Ayman
⤷ Title: Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 19 May 2026 13:19:23 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 19 May 2026 13:19:23 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Phoenix Invicta Extension Malware Strips CSP Headers to Bypass Manifest V3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:08:50 +0000
════════════════════════
⌗ Tags: #Malware #7AI Threat Intelligence #browser extension malware #Content Security Policy Stripping #JavaScript Backdoor #lottingem.com #Manifest V3 Bypass #MyColorPick #Phoenix Invicta #Search Engine Ad Fraud #statsdata.online
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:08:50 +0000
════════════════════════
⌗ Tags: #Malware #7AI Threat Intelligence #browser extension malware #Content Security Policy Stripping #JavaScript Backdoor #lottingem.com #Manifest V3 Bypass #MyColorPick #Phoenix Invicta #Search Engine Ad Fraud #statsdata.online
Penetration Testing Tools
Phoenix Invicta Extension Malware Strips CSP Headers to Bypass Manifest V3
Popular browser extensions have historically been perceived as benign, utilitarian artifacts—innocuous implements such as color droppers, ad-blockers, or
⤷ Title: Suspected Iranian Hackers Breach US Gas Station Fuel Monitoring Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:02:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATG Vulnerability #Automatic Tank Gauge #CISA Alert #Critical Infrastructure Security #Handala Persona #Industrial Control Systems #Iran State Hackers #Operational Technology #threat intelligence 2026 #US Fuel Station Cyberattack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:02:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATG Vulnerability #Automatic Tank Gauge #CISA Alert #Critical Infrastructure Security #Handala Persona #Industrial Control Systems #Iran State Hackers #Operational Technology #threat intelligence 2026 #US Fuel Station Cyberattack
Penetration Testing Tools
Suspected Iranian Hackers Breach US Gas Station Fuel Monitoring Systems
American fueling stations have fallen victim to a coordinated cyber-infiltration campaign. Unidentified adversaries breached the telemetry frameworks responsible
⤷ Title: The SNEK Initiative Drops “Eris”: New Post-Exploit Framework Abuses Windows Fax Service for SYSTEM Root
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:29:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Session Takeover #Eris Exploit #local privilege escalation #MinGW_w64 Compilation #Post_Exploitation Tool #Registry Hijack #Silent Cleanup Task #The SNEK Initiative #User Account Control Bypass #Windows Fax Service
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:29:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Session Takeover #Eris Exploit #local privilege escalation #MinGW_w64 Compilation #Post_Exploitation Tool #Registry Hijack #Silent Cleanup Task #The SNEK Initiative #User Account Control Bypass #Windows Fax Service
Penetration Testing Tools
The SNEK Initiative Drops "Eris": New Post-Exploit Framework Abuses Windows Fax Service for SYSTEM Root
A novel exploitation framework designed to escalate execution privileges within the Windows environment, designated as Eris, has emerged
⤷ Title: VulnCheck Warns of Active Cisco Zero-Day and Massive Server Exploitation Wave
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #Attack Surface Management #Cisco Catalyst Zero Day #CVE_2026_20182 #NGINX CVE_2026_42945 #Probllama CVE_2024_37032 #ProFTPD SQL Injection #threat intelligence 2026 #UAT_8616 #VulnCheck Report #WordPress Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability #Attack Surface Management #Cisco Catalyst Zero Day #CVE_2026_20182 #NGINX CVE_2026_42945 #Probllama CVE_2024_37032 #ProFTPD SQL Injection #threat intelligence 2026 #UAT_8616 #VulnCheck Report #WordPress Security
Penetration Testing Tools
VulnCheck Warns of Active Cisco Zero-Day and Massive Server Exploitation Wave
A constellation of severe vulnerabilities sweeping across ubiquitous server frameworks and third-party extensions has emerged as the focal
⤷ Title: Linus Torvalds Slams AI Bug Hunters for Clogging Linux Security Pipelines
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:09:03 +0000
════════════════════════
⌗ Tags: #Linux #AI Bug Reports #Drive_By Bug Hunting #Duplicate Vulnerabilities #Greg Kroah_Hartman #Linus Torvalds #Linux 7.1 Release Candidate #Linux Security Mailing List #Open Source Documentation #Patch Management #Vulnerability Triage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:09:03 +0000
════════════════════════
⌗ Tags: #Linux #AI Bug Reports #Drive_By Bug Hunting #Duplicate Vulnerabilities #Greg Kroah_Hartman #Linus Torvalds #Linux 7.1 Release Candidate #Linux Security Mailing List #Open Source Documentation #Patch Management #Vulnerability Triage
Penetration Testing Tools
Linus Torvalds Slams AI Bug Hunters for Clogging Linux Security Pipelines
Linus Torvalds has once again given voice to a sentiment that had been quietly permeating the developer community
⤷ Title: NATS-as-C2: Critical Langflow Exploit Exploded to Fuel “LLMjacking” and Cloud Credential Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting
Penetration Testing Tools
NATS-as-C2: Critical Langflow Exploit Exploded to Fuel "LLMjacking" and Cloud Credential Theft
Forensic specialists from Sysdig have intercepted an anomalous command architecture governing a malicious network, wherein the adversaries abandoned
⤷ Title: Resurgent Tycoon 2FA Adopts OAuth Device Code Phishing to Hijack Microsoft 365
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Cyber Security #Device Authorization Grant #eSentire TRU #infosec #MFA Bypass #Microsoft 365 #Multi_Factor Authentication #OAuth 2.0 #PhaaS #Phishing_as_a_Service #Tycoon 2FA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud Security #Cyber Security #Device Authorization Grant #eSentire TRU #infosec #MFA Bypass #Microsoft 365 #Multi_Factor Authentication #OAuth 2.0 #PhaaS #Phishing_as_a_Service #Tycoon 2FA
Daily CyberSecurity
Resurgent Tycoon 2FA Adopts OAuth Device Code Phishing to Hijack Microsoft 365
Despite a global takedown, Tycoon 2FA is back. It now abuses Microsoft's device code flow to bypass MFA entirely. Disabling this flow is critical.
⤷ Title: Chinese APT FamousSparrow Weaponizes Evolved Deed RAT Against Azerbaijani Energy Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:06:15 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Bitdefender Labs #cyber_espionage #Deed RAT #DLL Sideloading #Energy Sector Security #FamousSparrow #infosec #Microsoft Exchange #ProxyNotShell #South Caucasus #TernDoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:06:15 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Bitdefender Labs #cyber_espionage #Deed RAT #DLL Sideloading #Energy Sector Security #FamousSparrow #infosec #Microsoft Exchange #ProxyNotShell #South Caucasus #TernDoor
Daily CyberSecurity
Chinese APT FamousSparrow Weaponizes Evolved Deed RAT Against Azerbaijani Energy Infrastructure
Bitdefender exposes a persistent FamousSparrow campaign using advanced DLL sideloading and Deed RAT to compromise energy infrastructure. Patch now!
⤷ Title: I Got Admin Access to Chhattisgarh CCTNS in One Login Attempt
════════════════════════
𐀪 Author: Siddharth
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:32:52 GMT
════════════════════════
⌗ Tags: #government #hacking #bug_bounty #bug_bounty_tips
════════════════════════
𐀪 Author: Siddharth
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:32:52 GMT
════════════════════════
⌗ Tags: #government #hacking #bug_bounty #bug_bounty_tips
Medium
I Got Admin Access to Chhattisgarh CCTNS in One Login Attempt🚨
It was past midnight when I tried it.
⤷ Title: 7 Recon Tricks That Paid Me Bounties
════════════════════════
𐀪 Author: cyber-ninjaaa
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:26:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #hacking
════════════════════════
𐀪 Author: cyber-ninjaaa
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:26:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #hacking
Medium
7 Recon Tricks That Paid Me Bounties
Find your first bug by doing recon differently. Not harder. Just different.Most people run the same tools. Subfinder. Amass default mode…
⤷ Title: The Dark Side of the OSI Model: How Hackers Target Each Layer
════════════════════════
𐀪 Author: Singhreetika
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:57:24 GMT
════════════════════════
⌗ Tags: #security #hacking #cybersecurity #networking #learning
════════════════════════
𐀪 Author: Singhreetika
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:57:24 GMT
════════════════════════
⌗ Tags: #security #hacking #cybersecurity #networking #learning
Medium
The Dark Side of the OSI Model: How Hackers Target Each Layer
When most beginners learn the OSI Model, they usually memorize the seven layers to clear interviews or exams.