⤷ Title: PortSwigger : SQL Injection in WHERE Clause Allowing Retrieval of Hidden Data
════════════════════════
𐀪 Author: Imajinasidanar
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 20:00:29 GMT
════════════════════════
⌗ Tags: #writeup #web_security #portswigger #cybersecurity #sql_injection
════════════════════════
𐀪 Author: Imajinasidanar
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 20:00:29 GMT
════════════════════════
⌗ Tags: #writeup #web_security #portswigger #cybersecurity #sql_injection
Medium
PortSwigger : SQL Injection in WHERE Clause Allowing Retrieval of Hidden Data
In this lab, the website has a SQL injection vulnerability in the product category filter. When a user chooses a category, the application…
⤷ Title: Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)
════════════════════════
𐀪 Author: Mohamed AboElKheir
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:52:17 GMT
════════════════════════
⌗ Tags: #ai #software_development #software_engineering #cybersecurity #application_security
════════════════════════
𐀪 Author: Mohamed AboElKheir
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:52:17 GMT
════════════════════════
⌗ Tags: #ai #software_development #software_engineering #cybersecurity #application_security
Medium
Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)
Welcome to another story in the Lessons Learned series, where we discuss real-world vulnerabilities from the perspective of an application…
⤷ Title: Loly | Proving Grounds | OSCP Preparation
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:38:29 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #hacking #ctf #security
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:38:29 GMT
════════════════════════
⌗ Tags: #infosec #ethical_hacking #hacking #ctf #security
Medium
Loly | Proving Grounds | OSCP Preparation
As always, we start off with a nmap scan of the target:
⤷ Title: Footprinting Lab — Easy (Walkthrough)
════════════════════════
𐀪 Author: th3V0!D
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:14:13 GMT
════════════════════════
⌗ Tags: #hackthebox #cybersecurity #red_team #hacking #penetration_testing
════════════════════════
𐀪 Author: th3V0!D
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:14:13 GMT
════════════════════════
⌗ Tags: #hackthebox #cybersecurity #red_team #hacking #penetration_testing
Medium
Footprinting Lab — Easy (Walkthrough)
We were commissioned by the company Inlanefreight Ltd to test three different servers in their internal network. The company uses many…
⤷ Title: Wardriving — Pasándolo bien con las redes WiFi del barrio
════════════════════════
𐀪 Author: BeachO
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:02:28 GMT
════════════════════════
⌗ Tags: #wifi #wifihacking #español #hacking #wardriving
════════════════════════
𐀪 Author: BeachO
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:02:28 GMT
════════════════════════
⌗ Tags: #wifi #wifihacking #español #hacking #wardriving
Medium
Wardriving — Pasándolo bien con las redes WiFi del barrio
Discreción o potencia, todo junto no puede ser
⤷ Title: The Four Reflexes That Separate Real SOC Analysts From People Who Memorized the Definitions
════════════════════════
𐀪 Author: Jbird
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:00:17 GMT
════════════════════════
⌗ Tags: #information_security #information_technology #infosec #career_development #cybersecurity
════════════════════════
𐀪 Author: Jbird
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 22:00:17 GMT
════════════════════════
⌗ Tags: #information_security #information_technology #infosec #career_development #cybersecurity
Medium
The Four Reflexes That Separate Real SOC Analysts From People Who Memorized the Definitions
Two analysts can have the same certs and one freezes on a live alert while the other moves. The difference is four reflexes, not…
⤷ Title: Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:45:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2026_28742 #Device Takeover #Hard_Coded Key #IoT security #Naxclow #Smart Doorbell
Daily CyberSecurity
Naxclow IoT Vulnerabilities: 7 Flaws Let Attackers Hijack Doorbells and Cameras
CISA warns of 7 Naxclow IoT vulnerabilities, including a hard-coded key (CVE-2026-28742) enabling device takeover of doorbells and cameras.
⤷ Title: FreeSWITCH Heap Buffer Overflow Bugs Expose Servers to Pre-Auth Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:01:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_49840 #CVE_2026_49841 #FreeSWITCH #Heap Buffer Overflow #libesl #mod_verto
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:01:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_49840 #CVE_2026_49841 #FreeSWITCH #Heap Buffer Overflow #libesl #mod_verto
Daily CyberSecurity
FreeSWITCH Heap Buffer Overflow Bugs Expose Servers to Pre-Auth Attacks
Two pre-auth FreeSWITCH heap buffer overflow bugs (CVE-2026-49841, CVE-2026-49840) hit mod_verto and libesl. Update to v1.11.1 to stay safe.
⤷ Title: Thousands of phpBB Forums Exposed by Critical Authentication Bypass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 00:27:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #Authentication Bypass #CVE_2026_48611 #OAuth #phpBB #phpBB 3.3.17
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 00:27:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #Authentication Bypass #CVE_2026_48611 #OAuth #phpBB #phpBB 3.3.17
Daily CyberSecurity
Thousands of phpBB Forums Exposed by Critical Authentication Bypass
A critical phpBB authentication bypass (CVE-2026-48611) lets attackers hijack any account on thousands of forums. Update to 3.3.17 now.
⤷ Title: LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 00:00:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CageFS #CloudLinux #CPanel #CVE_2026_54420 #LiteSpeed #privilege escalation #Shared Hosting
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 00:00:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CageFS #CloudLinux #CPanel #CVE_2026_54420 #LiteSpeed #privilege escalation #Shared Hosting
Daily CyberSecurity
LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)
CVE-2026-54420, a LiteSpeed cPanel privilege escalation flaw, is exploited in the wild to gain root on shared hosting. Patch to plugin v2.4.8 now.
⤷ Title: MSRPM Internals: What the AMD APM Actually Means
════════════════════════
𐀪 Author: Matheus Santos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:43:48 GMT
════════════════════════
⌗ Tags: #amd #hacking #software_architecture #hypervisors #programming
════════════════════════
𐀪 Author: Matheus Santos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 01:43:48 GMT
════════════════════════
⌗ Tags: #amd #hacking #software_architecture #hypervisors #programming
Medium
MSRPM Internals: What the AMD APM Actually Means
Astaroth Development Notes — MSR Permission Map Implementation
⤷ Title: I Cleared the eWPT — Here’s Everything You Need to Know
════════════════════════
𐀪 Author: Divya
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 00:04:31 GMT
════════════════════════
⌗ Tags: #penetration_testing #certification #security
════════════════════════
𐀪 Author: Divya
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 00:04:31 GMT
════════════════════════
⌗ Tags: #penetration_testing #certification #security
Medium
I Cleared the eWPT — Here’s Everything You Need to Know
Divya Gupta
⤷ Title: Velvet Ant Hid in Air-Gapped Network for 10 Years
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:49:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #air_gapped network #China APT #cybersecurity #OpenSSH Compromise #Operation Highland #PAM Backdoor #Velvet Ant
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:49:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #air_gapped network #China APT #cybersecurity #OpenSSH Compromise #Operation Highland #PAM Backdoor #Velvet Ant
Information Security News
Velvet Ant Hid in Air-Gapped Network for 10 Years
Sygnia exposes Operation Highland: China-linked Velvet Ant persisted for nearly 10 years in an air-gapped network by backdooring PAM and OpenSSH.
⤷ Title: CVE-2026-46316: KVM arm64 Guest Escapes to Host
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:47:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #ARM64 #cloud security #CVE_2026_46316 #KVM Escape #Linux Kernel #Virtual Machine Escape
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:47:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #ARM64 #cloud security #CVE_2026_46316 #KVM Escape #Linux Kernel #Virtual Machine Escape
Information Security News
CVE-2026-46316: KVM arm64 Guest Escapes to Host
CVE-2026-46316 is a critical Linux KVM arm64 flaw scoring 9.3 that lets a guest VM escape to the host kernel via a vGIC-ITS race condition.
⤷ Title: phpBB Authentication Bypass Fixed in Version 3.3.17
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:35:00 +0000
════════════════════════
⌗ Tags: #Vulnerability #Aikido Security #authentication bypass #Forum Security #phpBB #Session Hijacking #Web Vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:35:00 +0000
════════════════════════
⌗ Tags: #Vulnerability #Aikido Security #authentication bypass #Forum Security #phpBB #Session Hijacking #Web Vulnerability
Information Security News
phpBB Authentication Bypass Fixed in Version 3.3.17
A critical phpBB authentication bypass in 3.3.16 and earlier lets attackers hijack any user session with a single HTTP request. Update now.
⤷ Title: AMD Denied $10K Bounty After CVE-2026-40677 Fix
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:32:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #AMD #bug bounty #CVE_2026_40677 #MitM Attack #MrBruh #Vulnerability Disclosure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:32:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #AMD #bug bounty #CVE_2026_40677 #MitM Attack #MrBruh #Vulnerability Disclosure
Information Security News
AMD Denied $10K Bounty After CVE-2026-40677 Fix
Researcher MrBruh found CVE-2026-40677 in AMD's update utility, reported it properly, and was denied a $10,000 bounty after AMD changed its own rules.
⤷ Title: 152 Chrome Wallpaper Extensions Hid Ad Tracking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:27:13 +0000
════════════════════════
⌗ Tags: #Malware #Ad Tracking #Browser Malware #Chrome extensions #Chrome Web Store #Live Wallpaper #Socket Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:27:13 +0000
════════════════════════
⌗ Tags: #Malware #Ad Tracking #Browser Malware #Chrome extensions #Chrome Web Store #Live Wallpaper #Socket Security
Information Security News
152 Chrome Wallpaper Extensions Hid Ad Tracking
Socket found 152 Chrome live wallpaper extensions secretly faking Google search traffic and harvesting user data for ad networks.
⤷ Title: Anthropic Mythos Restrictions: White House AI Security Concerns
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:24:18 +0000
════════════════════════
⌗ Tags: #Technology #AI security #Anthropic #export controls #Fable 5 #Mythos 5
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:24:18 +0000
════════════════════════
⌗ Tags: #Technology #AI security #Anthropic #export controls #Fable 5 #Mythos 5
Information Security News
Anthropic Mythos Restrictions: White House AI Security
The White House enacted Anthropic Mythos restrictions following national security concerns regarding potential Chinese cyber-espionage access to the AI.
⤷ Title: Three Tornado Security Vulnerabilities Patched in Version 6.5.6
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:31:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Leak #CVE_2026_49853 #CVE_2026_49854 #CVE_2026_49855 #gzip bomb #Python #SimpleAsyncHTTPClient #tornado
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:31:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Leak #CVE_2026_49853 #CVE_2026_49854 #CVE_2026_49855 #gzip bomb #Python #SimpleAsyncHTTPClient #tornado
Daily CyberSecurity
Three Tornado Security Vulnerabilities Patched in Version 6.5.6
Three Tornado security vulnerabilities (CVE-2026-49853, CVE-2026-49855, CVE-2026-49854) risk credential leaks and DoS. Update to Tornado 6.5.6 now.
⤷ Title: Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:12:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Browser Mode #CDP #CVE_2026_53633 #npm #rce #Supply Chain #Vite #Vitest
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:12:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Browser Mode #CDP #CVE_2026_53633 #npm #rce #Supply Chain #Vite #Vitest
Daily CyberSecurity
Vitest RCE Vulnerability (CVSS 9.8): Public PoC Disclosed for Testing Tool With 57M Weekly Downloads (CVE-2026-53633)
A critical Vitest RCE vulnerability (CVE-2026-53633, CVSS 9.8) has public PoC code. Browser Mode flaw enables config overwrite and remote code execution.
⤷ Title: Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:01:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #Certificate Validation #crypton_x509_validation #CVE_2026_9648 #Haskell #tls #X.509 NameConstraints
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 02:01:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #Certificate Validation #crypton_x509_validation #CVE_2026_9648 #Haskell #tls #X.509 NameConstraints
Daily CyberSecurity
Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)
A Haskell TLS vulnerability (CVE-2026-9648) lets attackers bypass X.509 NameConstraints to impersonate domains. Update crypton-x509-validation to 1.9.1.