⤷ Title: Spring Boot Actuator expuesto conduce a Account Takeover (ATO)
════════════════════════
𐀪 Author: Miguel Segovia Gil
════════════════════════
ⴵ Time: Sun, 24 May 2026 23:10:05 GMT
════════════════════════
⌗ Tags: #appsec #bug_bounty #bugbounty_writeup #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: Miguel Segovia Gil
════════════════════════
ⴵ Time: Sun, 24 May 2026 23:10:05 GMT
════════════════════════
⌗ Tags: #appsec #bug_bounty #bugbounty_writeup #cybersecurity #bug_bounty_tips
Medium
Spring Boot Actuator expuesto conduce a Account Takeover (ATO)
Los actuators de Spring Boot se emplean para exponer información operacional de la aplicación en tiempo de ejecución, incluyendo estado del…
⤷ Title: Rolling Dice on a $60 handheld
════════════════════════
𐀪 Author: Ming
════════════════════════
ⴵ Time: Mon, 25 May 2026 00:15:13 GMT
════════════════════════
⌗ Tags: #coding #computer_graphics #game_development #software_development #hacking
════════════════════════
𐀪 Author: Ming
════════════════════════
ⴵ Time: Mon, 25 May 2026 00:15:13 GMT
════════════════════════
⌗ Tags: #coding #computer_graphics #game_development #software_development #hacking
Medium
Rolling Dice on a $60 handheld
In the last post, “Porting Raylib to a $60 GBA clone”, I described how I convinced Raylib to draw 3D scenes on a budget handheld — the…
⤷ Title: Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:20:02 +0000
════════════════════════
⌗ Tags: #Data Breaches #Cyber Attack #Cybersecurity #data breach #Instagram #OnlyFans #Privacy #Spotify #twitter #Web Scraping
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:20:02 +0000
════════════════════════
⌗ Tags: #Data Breaches #Cyber Attack #Cybersecurity #data breach #Instagram #OnlyFans #Privacy #Spotify #twitter #Web Scraping
Hackread
Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
A hacker is selling a 340M OnlyFans user database allegedly built by matching old breach data and public profiles to real OnlyFans accounts.
⤷ Title: NLnet Labs Issues Urgent Security Release for Unbound Resolver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 02:12:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DNS Security #DNSSEC #NLnet Labs #Patch Update #Remote Code Execution #Unbound
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 02:12:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DNS Security #DNSSEC #NLnet Labs #Patch Update #Remote Code Execution #Unbound
Daily CyberSecurity
NLnet Labs Issues Urgent Security Release for Unbound Resolver
NLnet Labs patches a critical Unbound DNSSEC validation vulnerability allowing unauthenticated remote code execution. Update to 1.25.1.
⤷ Title: Critical Unauthenticated RCE Flaw Threatens Kopia Backup Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:42:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45695 #Kopia #Kopia SSH #ProxyCommand injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:42:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45695 #Kopia #Kopia SSH #ProxyCommand injection
Daily CyberSecurity
Critical Unauthenticated RCE Flaw Threatens Kopia Backup Servers
A critical unauthenticated RCE flaw (CVE-2026-45695) impacts Kopia backup servers. Learn how the Kopia SSH ProxyCommand injection exploit operates and how to patch it.
⤷ Title: Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
Daily CyberSecurity
Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
Urgent: TYPO3 patches a critical 9.2 CVSS flaw (CVE-2026-46725) in Content Element Selector plugin. Unauthenticated attackers can achieve full server RCE.
⤷ Title: Over-the-Air Root Risk: Seven Critical FreeBSD Security Advisories Fix Wi-Fi RCE and Kernel Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:01:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #bsdconfig #bsdinstall #Capsicum Sandboxing #CVE_2026_45250 #CVE_2026_45255 #Cyber Security #freebsd #infosec #Kernel Stack Overflow #Patch Alert #use after free #Wi_Fi RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:01:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #bsdconfig #bsdinstall #Capsicum Sandboxing #CVE_2026_45250 #CVE_2026_45255 #Cyber Security #freebsd #infosec #Kernel Stack Overflow #Patch Alert #use after free #Wi_Fi RCE
Daily CyberSecurity
Over-the-Air Root Risk: Seven Critical FreeBSD Security Advisories Fix Wi-Fi RCE and Kernel Flaws
The FreeBSD Project fixes seven vulnerabilities, including a zero-interaction Wi-Fi shell expansion RCE (CVE-2026-45255) and severe kernel leaks.
⤷ Title: AI Security Path- TryHackMe- Module 3(Part 1)
════════════════════════
𐀪 Author: Swarupa Jeedimetla
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:39:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #tryhackme #ai_security
════════════════════════
𐀪 Author: Swarupa Jeedimetla
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:39:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #tryhackme #ai_security
Medium
AI Security Path- TryHackMe- Module 3(Part 1)
Why Prompt Injection Is Different
⤷ Title: TryHackMe: Prompt Injection Writeup
════════════════════════
𐀪 Author: Tega Akperiojire (cyber_with_tega)
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:37:33 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #prompt_injection #ai #security
════════════════════════
𐀪 Author: Tega Akperiojire (cyber_with_tega)
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:37:33 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #prompt_injection #ai #security
Medium
TryHackMe: Prompt Injection Writeup
What if you could trick a chatbot to divulging sensitive information
⤷ Title: Wireshark 4.6.6
════════════════════════
𐀪 Author: Manula Udyoga
════════════════════════
ⴵ Time: Mon, 25 May 2026 02:36:40 GMT
════════════════════════
⌗ Tags: #packet_analysis #ethical_hacking #wireshark #cybersecurity #threat_hunting
════════════════════════
𐀪 Author: Manula Udyoga
════════════════════════
ⴵ Time: Mon, 25 May 2026 02:36:40 GMT
════════════════════════
⌗ Tags: #packet_analysis #ethical_hacking #wireshark #cybersecurity #threat_hunting
Medium
🔍 Wireshark 4.6.6 Released: Critical Security Fixes, Stability Improvements & Enhanced Protocol Support 🚀
The cybersecurity community has welcomed the release of Wireshark 4.6.6, the latest update to the world’s most widely used network protocol…
⤷ Title: The War for Your Documents: Why The Document Foundation is Challenging Microsoft’s OOXML Monopoly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:16:58 +0000
════════════════════════
⌗ Tags: #Technique #Digital Sovereignty #Document Interoperability #Excel 1900 Leap Year Bug #LibreOffice #Microsoft Office Monopoly #ODF vs OOXML #Open Source Ethos #OpenDocument Format #The Document Foundation #Vendor Lock_in
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:16:58 +0000
════════════════════════
⌗ Tags: #Technique #Digital Sovereignty #Document Interoperability #Excel 1900 Leap Year Bug #LibreOffice #Microsoft Office Monopoly #ODF vs OOXML #Open Source Ethos #OpenDocument Format #The Document Foundation #Vendor Lock_in
Information Security News
The War for Your Documents: Why The Document Foundation is Challenging Microsoft’s OOXML Monopoly
The Document Foundation (TDF), the steward of the open-source office suite LibreOffice, has long been embroiled in an
⤷ Title: I Found 3 Critical Vulnerabilities in an AI-Powered SOC Platform — Full Attack Chain
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Mon, 25 May 2026 04:16:03 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #penetration_testing #cybersecurity #bug_bounty #ctf_writeup
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Mon, 25 May 2026 04:16:03 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #penetration_testing #cybersecurity #bug_bounty #ctf_writeup
Medium
I Compromised Every Tenant on an AI-Powered SOC Platform — Full Attack Chain
Author: Shikhali Jamalzade Github: github.com/alisalive Linkedin: linkedin.com/in/camalzads
⤷ Title: My Experience With H&M’s Bug Bounty Program
════════════════════════
𐀪 Author: licohunter
════════════════════════
ⴵ Time: Mon, 25 May 2026 03:22:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #bug_bounty_hunter
════════════════════════
𐀪 Author: licohunter
════════════════════════
ⴵ Time: Mon, 25 May 2026 03:22:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #bug_bounty_hunter
Medium
My Experience With H&M’s Bug Bounty Program
Lessons From Reporting Multiple Vulnerabilities to H&M’s Bug Bounty Program
⤷ Title: Why Hack Me — Writeup
════════════════════════
𐀪 Author: n3erajan
════════════════════════
ⴵ Time: Mon, 25 May 2026 04:00:04 GMT
════════════════════════
⌗ Tags: #tryhackme #penetration_testing #ethical_hacking #cybersecurity #ctf
════════════════════════
𐀪 Author: n3erajan
════════════════════════
ⴵ Time: Mon, 25 May 2026 04:00:04 GMT
════════════════════════
⌗ Tags: #tryhackme #penetration_testing #ethical_hacking #cybersecurity #ctf
Medium
Why Hack Me — Writeup
Introduction
⤷ Title: Bounty Hacker — TryHackMe Writeup | FTP, Hydra & Tar Privesc
════════════════════════
𐀪 Author: Sanihpullat
════════════════════════
ⴵ Time: Mon, 25 May 2026 03:06:43 GMT
════════════════════════
⌗ Tags: #ctf_writeup #cybersecurity #penetration_testing #ethical_hacking #tryhackme
════════════════════════
𐀪 Author: Sanihpullat
════════════════════════
ⴵ Time: Mon, 25 May 2026 03:06:43 GMT
════════════════════════
⌗ Tags: #ctf_writeup #cybersecurity #penetration_testing #ethical_hacking #tryhackme
Medium
Bounty Hacker — TryHackMe Writeup | FTP, Hydra & Tar Privesc
In this walkthrough I go through the Bounty Hacker room on TryHackMe — a beginner-friendly Linux box covering enumeration, FTP…
⤷ Title: The “Noise Filter” Method – How I Stop Wasting Hours on False Positives
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Mon, 25 May 2026 04:57:09 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_hunter #bug_bounty_writeup #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: Decline
════════════════════════
ⴵ Time: Mon, 25 May 2026 04:57:09 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_hunter #bug_bounty_writeup #bug_bounty #bugbounty_writeup
Medium
The “Noise Filter” Method – How I Stop Wasting Hours on False Positives
6 months of chasing nothing taught me this 5-minute check.
⤷ Title: TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 25 May 2026 11:29:13 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 25 May 2026 11:29:13 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:47:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #Banking Trojan #Cyber Security #Fileless Execution #In_Memory Exploit #infosec #Malware_as_a_Service #Pix_QR Interception #Powershell obfuscation #SHADOW_WATER_063 #TrendAI Counter Threat Unit
Daily CyberSecurity
In-Memory Financial Theft: Inside Banana RAT’s Operator-Driven Attacks on Brazilian Banks
TrendAI exposes Banana RAT, a fileless banking trojan by SHADOW-WATER-063 that uses in-memory execution and fake UI overlays to hijack Pix-QR transfers.
⤷ Title: I Found SSL Validation Completely Disabled in an Open-Source Financial App — Here’s How It Works
════════════════════════
𐀪 Author: Yehor Mamaiev
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:33:22 GMT
════════════════════════
⌗ Tags: #open_source #android #mobile_security #security #application_security
════════════════════════
𐀪 Author: Yehor Mamaiev
════════════════════════
ⴵ Time: Mon, 25 May 2026 06:33:22 GMT
════════════════════════
⌗ Tags: #open_source #android #mobile_security #security #application_security
Medium
I Found SSL Validation Completely Disabled in an Open-Source Financial App — Here’s How It Works
“It’s open source — someone must have reviewed the security.”
⤷ Title: Building A Scam Investigation Lab — Inside The Scam Industry (Part 6)
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Mon, 25 May 2026 05:59:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint #data_analysis #security #hacking
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Mon, 25 May 2026 05:59:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint #data_analysis #security #hacking
Medium
🔍 Building A Scam Investigation Lab — Inside The Scam Industry (Part 6)
SCAN SMARTER, NOT HARDER — by Ghostyjoe™
⤷ Title: Cybercrime in the Digital Age: Threats, Impacts, and Solutions
════════════════════════
𐀪 Author: Pranav Apsingekar
════════════════════════
ⴵ Time: Mon, 25 May 2026 05:20:23 GMT
════════════════════════
⌗ Tags: #phishing #cybersecurity #hacking #cyberattack #malware
════════════════════════
𐀪 Author: Pranav Apsingekar
════════════════════════
ⴵ Time: Mon, 25 May 2026 05:20:23 GMT
════════════════════════
⌗ Tags: #phishing #cybersecurity #hacking #cyberattack #malware
Medium
Cybercrime in the Digital Age: Threats, Impacts, and Solutions
In today’s interconnected world, technology has transformed the way people communicate, work, shop, and store information. While the…