⤷ Title: Explorando Remote Code Execution (RCE) no WordPress
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
Medium
Explorando Remote Code Execution (RCE) no WordPress
Hoje executaremos um código malicioso no servidor WordPress. Para isso, temos como pré-requisito:
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
Daily CyberSecurity
Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
DevOps Alert: Over 700 laravel-lang localization package versions have been backdoored with a cross-platform 17-collector info-stealer. Audit your logs.
⤷ Title: Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
Daily CyberSecurity
Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
Urgent: TYPO3 patches a critical 9.2 CVSS flaw (CVE-2026-46725) in Content Element Selector plugin. Unauthenticated attackers can achieve full server RCE.
⤷ Title: Dual Sandbox Bypasses Threaten PHP Applications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
Daily CyberSecurity
Dual Sandbox Bypasses Threaten PHP Applications
Twig project maintainers patched critical Twig RCE flaws allowing arbitrary code execution via sandbox bypasses. Update to 3.26.0.
⤷ Title: Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
Medium
Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
A single, seemingly innocent HTTP endpoint can form a critical business-impact chain when multiple structural PHP weaknesses are stitched…
⤷ Title: exfiltration using numeric-only outputs
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
Medium
exfiltration using numeric-only outputs
after identifying a code-injection vulnerability, we always want to look around inside the compromised system. most of the time, we can…
⤷ Title: PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
Daily CyberSecurity
PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
A critical PhpSpreadsheet RCE vulnerability impacts 312 million users. Learn how the CVE-2026-45034 exploit bypasses patches and triggers code execution.
⤷ Title: Part 3/3: Exploiting phpinfo() — Turning Information into Compromise
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
Medium
🎓 Part 3/3: Exploiting phpinfo() — Turning Information into Compromise 🎓
Finding a phpinfo() file is just the beginning. The real value comes from analyzing its contents and using that data to advance your…
⤷ Title: CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 00:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CodeIgniter #CVE_2026_48062 #File Upload Vulnerability #PHP Security #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 00:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CodeIgniter #CVE_2026_48062 #File Upload Vulnerability #PHP Security #rce
Daily CyberSecurity
CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
A serious CodeIgniter vulnerability has put many PHP web applications at risk. Tracked as CVE-2026-48062, the flaw carries a critical CVSS score of 9.8. Moreover, it can hand attackers full arbitr…
⤷ Title: Analysis CVE-2026–48907 — Joomla JCE
════════════════════════
𐀪 Author: xpl0dec
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 13:11:53 GMT
════════════════════════
⌗ Tags: #php #hacking #proof_of_concept #vulnerability #cybersecurity
════════════════════════
𐀪 Author: xpl0dec
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 13:11:53 GMT
════════════════════════
⌗ Tags: #php #hacking #proof_of_concept #vulnerability #cybersecurity
Medium
Analysis CVE-2026–48907 — Joomla JCE
Sekitar beberapa hari lalu, terdapat kerentanan pada extension JCE(Joomla Content Editor) yang digunakan CMS joomla untuk menggantikan…
⤷ Title: Secure by Design: Implementing Advanced Security in Laravel
════════════════════════
𐀪 Author: Hector Canovas
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:29:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #php #software_architecture #laravel
════════════════════════
𐀪 Author: Hector Canovas
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:29:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #php #software_architecture #laravel
Medium
Secure by Design: Implementing Advanced Security in Laravel
Strengthen Your Laravel Fortress Against Modern Threats
⤷ Title: PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 02:41:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12184 #CVE_2026_14355 #Denial of Service #memory corruption #php #PHP_FPM #Remote DoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 02:41:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12184 #CVE_2026_14355 #Denial of Service #memory corruption #php #PHP_FPM #Remote DoS
Daily CyberSecurity
PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
TL;DR The PHP team fixed two flaws, including a PHP remote DoS that can crash a whole PHP-FPM pool. CVE-2026-12184 (CVSS 8.2) triggers on a failed TLS handshake with a remote server. A second bug,…
⤷ Title: CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
Daily CyberSecurity
CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
TL;DR PHP Composer, the main dependency manager for the language, patched three security flaws. The most serious, CVE-2026-59948, is an arbitrary file write rated CVSS 7.0. A malicious package can…
⤷ Title: Hwat Hell Machine Hacking | Achieving Reverse Shell and Capturing the Flags
════════════════════════
𐀪 Author: ABDUL AHAD
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 16:39:11 GMT
════════════════════════
⌗ Tags: #hacking #web_enumeration #ctf #php_reverse_shell #sql_injection
════════════════════════
𐀪 Author: ABDUL AHAD
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 16:39:11 GMT
════════════════════════
⌗ Tags: #hacking #web_enumeration #ctf #php_reverse_shell #sql_injection
Medium
Hwat Hell Machine Hacking | Achieving Reverse Shell and Capturing the Flags
hwats hell machine
⤷ Title: A Crypto Zero-Day Huntress
════════════════════════
𐀪 Author: CypherBlush™
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:27:29 GMT
════════════════════════
⌗ Tags: #infosec #women_in_tech #php #defi #cryptocurrency
════════════════════════
𐀪 Author: CypherBlush™
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:27:29 GMT
════════════════════════
⌗ Tags: #infosec #women_in_tech #php #defi #cryptocurrency
Medium
A Crypto Zero-Day Huntress
Securing Crypto Wallet Architecture
⤷ Title: Source Code Review: PHP | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:08 GMT
════════════════════════
⌗ Tags: #tryhackme #php #cybersecurity #red_team
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:08 GMT
════════════════════════
⌗ Tags: #tryhackme #php #cybersecurity #red_team
Medium
Source Code Review: PHP | TryHackMe
Learn the basics of source code review for PHP.
⤷ Title: CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
Daily CyberSecurity
CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
TL;DR A flaw in WordPress Coding Standards lets malicious PHP run code on the machine that lints it. Tracked as CVE-2026-45293, the bug carries a CVSS score of 8.6. The advisory calls it “an…