⤷ Title: FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:34:22 +0000
════════════════════════
⌗ Tags: #Security #Data Breaches #Bob Diachenko #Cyber Attack #Cybersecurity #firewall #FortiBleed #FortiGate #Fortinet #VPN
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:34:22 +0000
════════════════════════
⌗ Tags: #Security #Data Breaches #Bob Diachenko #Cyber Attack #Cybersecurity #firewall #FortiBleed #FortiGate #Fortinet #VPN
Hackread
FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries
Researchers say FortiBleed used stolen and tested credentials to access exposed Fortinet firewalls, putting major organizations and public agencies at risk now.
⤷ Title: Critical Apache Shiro LDAP Injection Flaw Uncovered
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:36:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Shiro #Authentication Bypass #CVE_2026_49268 #LDAP injection #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:36:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Shiro #Authentication Bypass #CVE_2026_49268 #LDAP injection #Vulnerability
Daily CyberSecurity
Critical Apache Shiro LDAP Injection Flaw Uncovered
A critical Apache Shiro LDAP Injection vulnerability in DefaultLdapRealm, CVE-2026-49268, allows authentication bypass. Update your framework immediately.
⤷ Title: SSTImap & SSTI Prevention: Letting the Tool Do the Work
════════════════════════
𐀪 Author: Moncef fennan
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 17:45:24 GMT
════════════════════════
⌗ Tags: #web_development #pentesting #ssti #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Moncef fennan
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 17:45:24 GMT
════════════════════════
⌗ Tags: #web_development #pentesting #ssti #cybersecurity #bug_bounty
Medium
SSTImap & SSTI Prevention: Letting the Tool Do the Work
We did it manually. Now let’s see what happens when you hand it to a tool. Last part of the SSTI series.
⤷ Title: Unauthenticated IDOR on NASA’s GitLab Instance — From Recon to Bypass
════════════════════════
𐀪 Author: Ghaddarittoo
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:57:29 GMT
════════════════════════
⌗ Tags: #nasa #bug_bounty #security_research #bugcrowd #broken_access_control
════════════════════════
𐀪 Author: Ghaddarittoo
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:57:29 GMT
════════════════════════
⌗ Tags: #nasa #bug_bounty #security_research #bugcrowd #broken_access_control
Medium
Unauthenticated IDOR on NASA’s GitLab Instance — From Recon to Bypass
Target: gitlab.smce.nasa.gov Program: NASA VDP (Bugcrowd) Severity: P3 — Broken Access Control / IDOR Status: Resolved
⤷ Title: “Bug Bounty Bootcamp #48: OAuth + XSS ”
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:43:57 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty #cybersecurity #hacking
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:43:57 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty #cybersecurity #hacking
Medium
“Bug Bounty Bootcamp #48: OAuth + XSS ”
The Ultimate Account Takeover One-Two Punch
⤷ Title: SSTI Exploitation in Twig: Same Idea, Different Language
════════════════════════
𐀪 Author: Moncef fennan
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:12:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #ssti #cybersecurity #software_development #pentesting
════════════════════════
𐀪 Author: Moncef fennan
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:12:15 GMT
════════════════════════
⌗ Tags: #bug_bounty #ssti #cybersecurity #software_development #pentesting
Medium
SSTI Exploitation in Twig: Same Idea, Different Language
Jinja2 was Python. Twig is PHP. The vulnerability is the same — the path looks completely different. Part 3 of the SSTI series.
⤷ Title: “Supplier ADP Pilot Update” — Additional Supplier CNA Participants Wanted!
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:21:53 GMT
════════════════════════
⌗ Tags: #software_development #infosec #software_engineering #vulnerability #cybersecurity
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:21:53 GMT
════════════════════════
⌗ Tags: #software_development #infosec #software_engineering #vulnerability #cybersecurity
Medium
“Supplier ADP Pilot Update” — Additional Supplier CNA Participants Wanted!
The CVE™ Program’s “Supplier CVE Numbering Authority (CNA) as Authorized Data Publisher Pilot (SADP Pilot)” has been up and running in…
⤷ Title: DC-1 VulnHub Walkthrough:
════════════════════════
𐀪 Author: Anuja
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 17:38:09 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #vulnhub #ctf #walkthrough
════════════════════════
𐀪 Author: Anuja
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 17:38:09 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #vulnhub #ctf #walkthrough
Medium
DC-1 VulnHub Walkthrough:
A beginner-friendly penetration testing walkthrough of the DC-1 boot2root machine
⤷ Title: From Default Credentials to Operating System Access: Exploiting PostgreSQL in Metasploitable 2
════════════════════════
𐀪 Author: VISHAL PRAJAPATI
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:06:04 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #linux #postgresql #cybersecurity
════════════════════════
𐀪 Author: VISHAL PRAJAPATI
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:06:04 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #linux #postgresql #cybersecurity
Medium
From Default Credentials to Operating System Access: Exploiting PostgreSQL in Metasploitable 2
When people think about penetration testing, they often imagine sophisticated exploits and advanced malware. In reality, many compromises…
⤷ Title: Twitter API OAuth: A 2013 Implementation Revisited — What Broke, What Survived, and What It Taught…
════════════════════════
𐀪 Author: Rajan Patekar
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:19:10 GMT
════════════════════════
⌗ Tags: #oauth2 #csharp #api_security #ai_governance #software_development
════════════════════════
𐀪 Author: Rajan Patekar
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 16:19:10 GMT
════════════════════════
⌗ Tags: #oauth2 #csharp #api_security #ai_governance #software_development
Medium
Twitter API OAuth: A 2013 Implementation Revisited — What Broke, What Survived, and What It Taught Me About API Security
Author’s Note: Back in 2013, I wrote one of my earliest technical articles on CodeProject — a step-by-step guide to integrating Twitter API…
⤷ Title: GCUP V2 Writeup: Bookstore
════════════════════════
𐀪 Author: Youssef Abid
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 17:45:44 GMT
════════════════════════
⌗ Tags: #ctf #ctf_writeup #rce #web_exploitation
════════════════════════
𐀪 Author: Youssef Abid
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 17:45:44 GMT
════════════════════════
⌗ Tags: #ctf #ctf_writeup #rce #web_exploitation
Medium
GCUP V2 Writeup: Bookstore
Bookstore Category: Web / RCE Difficulty: Hard
⤷ Title: Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 23:44:24 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 23:44:24 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 23:06:28 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 23:06:28 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 20:28:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 20:28:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Splunk AI Toolkit Vulnerabilities: Critical RCE & Data Risks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 19:26:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_20265 #CVE_2026_20266 #cybersecurity #os command injection #Splunk AI Toolkit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 19:26:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_20265 #CVE_2026_20266 #cybersecurity #os command injection #Splunk AI Toolkit
Daily CyberSecurity
Splunk AI Toolkit Vulnerabilities: Critical RCE & Data Risks
New Splunk AI Toolkit vulnerabilities, including severe OS command injection (CVE-2026-20266), expose systems to attacks. Patch your instances immediately.
⤷ Title: Active Gravity SMTP Vulnerability Exploited in the Wild
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 19:15:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4020 #cybersecurity #Gravity SMTP #Vulnerability #wordpress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 19:15:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_4020 #cybersecurity #Gravity SMTP #Vulnerability #wordpress
Daily CyberSecurity
Active Gravity SMTP Vulnerability Exploited in the Wild
Attackers are actively exploiting a critical Gravity SMTP vulnerability (CVE-2026-4020) causing sensitive information exposure. Update your plugin now.
⤷ Title: Cisco ISE Vulnerabilities: Critical RCE and Info Disclosure Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:43:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cisco ISE #CVE_2026_20181 #CVE_2026_20190 #cybersecurity #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:43:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cisco ISE #CVE_2026_20181 #CVE_2026_20190 #cybersecurity #Remote Code Execution
Daily CyberSecurity
Cisco ISE Vulnerabilities: Critical RCE and Info Disclosure Flaws
Critical Cisco ISE vulnerabilities expose networks to Remote Code Execution (CVE-2026-20181) and data theft (CVE-2026-20190). Patch affected systems now.
⤷ Title: What Does “Intuition Work” Mean for Security Engineers — and Are You Ready for It?
════════════════════════
𐀪 Author: Forcepoint
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:21:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #future_of_work #artificial_intelligence #software_engineering
════════════════════════
𐀪 Author: Forcepoint
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:21:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #future_of_work #artificial_intelligence #software_engineering
Medium
What Does “Intuition Work” Mean for Security Engineers — and Are You Ready for It?
For years the narrative was about augmentation: AI makes security engineers faster, more accurate, better at handling volume. The human…
⤷ Title: How I prevented claude from writing to remote-settings.json
════════════════════════
𐀪 Author: petereonwrites
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:42:54 GMT
════════════════════════
⌗ Tags: #operating_systems #claude_code #hacking
════════════════════════
𐀪 Author: petereonwrites
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:42:54 GMT
════════════════════════
⌗ Tags: #operating_systems #claude_code #hacking
Medium
How I prevented claude from writing to remote-settings.json
If you work for an organization with highly valuable intellectual property and use the claude instance provided by your corporate…
⤷ Title: Detecting Domain Impersonation in Email: Using Regex + Transport Rules to Stop Polymorphic Phishing…
════════════════════════
𐀪 Author: Marvin Sewell
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:27:42 GMT
════════════════════════
⌗ Tags: #ai #hacking #penetration_testing #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Marvin Sewell
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:27:42 GMT
════════════════════════
⌗ Tags: #ai #hacking #penetration_testing #cybersecurity #artificial_intelligence
Medium
Detecting Domain Impersonation in Email: Using Regex + Transport Rules to Stop Polymorphic Phishing…
As many analysts quickly learn, Business Email Compromise (BEC) and phishing emails rarely rely on malware anymore — they rely on trust…
⤷ Title: SQL Injection:The Vulnerability That Refuses to Retire
════════════════════════
𐀪 Author: Sushmitha Amarnath
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:34:00 GMT
════════════════════════
⌗ Tags: #sql_injection #cybersecurity_awareness #database #stored_procedure #infosec
════════════════════════
𐀪 Author: Sushmitha Amarnath
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 18:34:00 GMT
════════════════════════
⌗ Tags: #sql_injection #cybersecurity_awareness #database #stored_procedure #infosec
Medium
SQL Injection:The Vulnerability That Refuses to Retire
SQL injection has been a named, well-understood vulnerability class since the late 1990s. It has its own OWASP category, its own automated…