⤷ Title: The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
Daily CyberSecurity
The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
The Axios npm hijack exposed millions to a RAT. Discover how North Korean-nexus actor UNC1069 used a masterful phishing ruse to bypass 2FA and steal credentials.
⤷ Title: Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 14:30:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Management #CVE_2026_3429 #CVE_2026_4636 #cybersecurity #IAM Security #infosec #Keycloak #MFA Bypass #Open Source Security #Token Theft #UMA #Vert.x
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 14:30:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Management #CVE_2026_3429 #CVE_2026_4636 #cybersecurity #IAM Security #infosec #Keycloak #MFA Bypass #Open Source Security #Token Theft #UMA #Vert.x
Daily CyberSecurity
Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
Keycloak 26.5.7 fixes critical flaws including MFA bypass (CVE-2026-3429) and UMA token theft. Protect your IAM infrastructure—upgrade to the latest version.
⤷ Title: Budibase Patches Critical RCE and SSRF Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 14:30:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation Security #Budibase #CVE_2026_31818 #CVE_2026_35216 #cybersecurity #infosec #Low Code Security #Open Source Security #rce #ssrf #Webhook Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 14:30:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation Security #Budibase #CVE_2026_31818 #CVE_2026_35216 #cybersecurity #infosec #Low Code Security #Open Source Security #rce #ssrf #Webhook Exploit
Daily CyberSecurity
Budibase Patches Critical RCE and SSRF Vulnerabilities
Critical 9.6 CVSS flaws in Budibase allow unauthenticated RCE and data exfiltration via SSRF. Secure your internal tools—update to v3.33.4 now.
⤷ Title: The Podcast Trap: How UNC1069’s AI Deepfakes Are Poisoning the Global npm Registry
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:35:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #axios #Deepfake #InfoSec 2026 #Node.js #North Korea #npm #open source security #SILENCELIFT #Social Engineering #supply chain attack #UNC1069 #WAVESHAPER
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:35:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #axios #Deepfake #InfoSec 2026 #Node.js #North Korea #npm #open source security #SILENCELIFT #Social Engineering #supply chain attack #UNC1069 #WAVESHAPER
Penetration Testing Tools
The Podcast Trap: How UNC1069’s AI Deepfakes Are Poisoning the Global npm Registry
What begins as a mundane exchange—an invitation to a podcast or a routine professional briefing—may serve as the
⤷ Title: The Human Element: How a Single GitHub Token Leak Put Apache HTTP Server in the Spotlight
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:08:27 +0000
════════════════════════
⌗ Tags: #Data Leak #Apache HTTP Server #Credential Management #Cybersecurity 2026 #data leak #GitHub Secret Scanning #GitHub Token #HTTPD #Human Error #infosec #Open Source Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:08:27 +0000
════════════════════════
⌗ Tags: #Data Leak #Apache HTTP Server #Credential Management #Cybersecurity 2026 #data leak #GitHub Secret Scanning #GitHub Token #HTTPD #Human Error #infosec #Open Source Security
Daily CyberSecurity
The Human Element: How a Single GitHub Token Leak Put Apache HTTP Server in the Spotlight
A developer's "human error" leaked sensitive GitHub tokens in an Apache HTTP Server update. Learn how GitHub's safety nets prevented a major security breach.
⤷ Title: Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
Daily CyberSecurity
Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
Froxlor faces two critical flaws, including a CVSS 10. Learn how path traversal and config injection allow persistent RCE. Patch your server management today!
⤷ Title: Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 13:13:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CRM #CVE_2026_23500 #cybersecurity #Dolibarr #ERP #infosec #Open Source Security #Patch Alert #PDF Conversion #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 13:13:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CRM #CVE_2026_23500 #cybersecurity #Dolibarr #ERP #infosec #Open Source Security #Patch Alert #PDF Conversion #rce
Daily CyberSecurity
Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
Dolibarr ERP faces a critical 9.4 CVSS RCE flaw (CVE-2026-23500) in its PDF conversion logic. Unsanitized commands allow full system takeover. Upgrade to 23.0!
⤷ Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Daily CyberSecurity
Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
A new report from researchers at TrendMicro has exposed the evolution of Void Dokkaebi (also known as Famous Chollima), a North Korea-aligned intrusion set that has transitioned from traditional s…
⤷ Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Penetration Testing Tools
RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
RubyGems has temporarily suspended the registration of new accounts following a pervasive assault on the Ruby ecosystem. According
⤷ Title: Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
⌗ Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
⌗ Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
Medium
Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
“We audited our own code. Our dependencies are someone else’s problem.” — A common assumption. Until it isn’t.
⤷ Title: How I Found CVE-2026–50131: An Incomplete SSRF Fix in Fedify
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 22:47:46 GMT
════════════════════════
⌗ Tags: #ssrf #cve #cybersecurity #open_source_security #vulnerability
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 22:47:46 GMT
════════════════════════
⌗ Tags: #ssrf #cve #cybersecurity #open_source_security #vulnerability
Medium
How I Found CVE-2026–50131: An Incomplete SSRF Fix in Fedify
There is a very specific feeling you get when you are reading security code and something looks almost right.
⤷ Title: From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for…
════════════════════════
𐀪 Author: eL Njas!™
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
⌗ Tags: #vulnhunter #open_source #infosec #open_source_security #finance
════════════════════════
𐀪 Author: eL Njas!™
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
⌗ Tags: #vulnhunter #open_source #infosec #open_source_security #finance
Medium
From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for Finance and Cyber Defense.
Capital One Financial Corporation is one of the largest financial institutions in the United States, headquartered in McLean, Virginia…
⤷ Title: Amazon Links North Korean Hackers to NPM Supply Chain Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 08:01:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon Threat Intelligence #DPRK #North Korea #npm #Open Source Security #Sapphire Sleet #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 08:01:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon Threat Intelligence #DPRK #North Korea #npm #Open Source Security #Sapphire Sleet #supply chain attack
Daily CyberSecurity
Amazon Links North Korean Hackers to NPM Supply Chain Attacks
At a glance Actor DPRK-linked group (Sapphire Sleet, Stardust Chollima, BlueNoroff, UNC1069) Activity NPM supply chain compromise via maintainer social engineering Targets Users of the axios, debu…