⤷ Title: Mobile App Pentest: iOS vs Android, A Manual Tester’s Guide to the Attack Surface Scanners Miss
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:09:24 GMT
════════════════════════
⌗ Tags: #compliance #penetration_testing #mobile_app_security #infosec #cybersecurity
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:09:24 GMT
════════════════════════
⌗ Tags: #compliance #penetration_testing #mobile_app_security #infosec #cybersecurity
Medium
Mobile App Pentest: iOS vs Android, A Manual Tester’s Guide to the Attack Surface Scanners Miss
We ran a “clean” automated scan on a fintech client’s iOS and Android apps. Both came back green. Three days into the manual engagement, we…
⤷ Title: Silent Monitor | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 07:24:06 GMT
════════════════════════
⌗ Tags: #ctf #red_team #penetration_testing #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 07:24:06 GMT
════════════════════════
⌗ Tags: #ctf #red_team #penetration_testing #cybersecurity #tryhackme
Medium
Silent Monitor | TryHackMe
Enumerate a running internal service, exploit a vulnerable web application, pivot through the system, and crack your way to root.
⤷ Title: Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:49:05 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #pentesting #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Roshan Rajbanshi
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:49:05 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #pentesting #cybersecurity #ethical_hacking
Medium
Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG Play
Slort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a…
⤷ Title: How I Found a Race Condition by Accident — And What It Actually Means
════════════════════════
𐀪 Author: Dhanshree
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:41:44 GMT
════════════════════════
⌗ Tags: #penetration_testing #security #appsec #web_application_security #security_engineer
════════════════════════
𐀪 Author: Dhanshree
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 06:41:44 GMT
════════════════════════
⌗ Tags: #penetration_testing #security #appsec #web_application_security #security_engineer
Medium
How I Found a Race Condition by Accident — And What It Actually Means
A real finding from a penetration test on an enterprise integration platform
⤷ Title: Mobile Application Security | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 07:24:17 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #cybersecurity #red_team #mobile_app_security
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 07:24:17 GMT
════════════════════════
⌗ Tags: #tryhackme #pentesting #cybersecurity #red_team #mobile_app_security
Medium
Mobile Application Security | TryHackMe
Learn mobile application pentesting through static analysis, MobSF, and the OWASP Mobile Top 10.
⤷ Title: Apple Modifies Hide My Email Feature to Use Dedicated Domain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:38:16 +0000
════════════════════════
⌗ Tags: #Apple #Domain Migration #Hide My Email #iCloud Privacy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:38:16 +0000
════════════════════════
⌗ Tags: #Apple #Domain Migration #Hide My Email #iCloud Privacy
Information Security News
Apple Hide My Email Feature Changes to Dedicated Domain
Apple updates its Hide My Email service by migrating addresses to a dedicated domain, making it easier for sites to identify private proxies.
⤷ Title: Monero P2Pool Critical Vulnerability: Urgent V4.16 Update
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:33:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #Crypto Security #Mining Vulnerability #Monero #P2Pool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:33:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #Crypto Security #Mining Vulnerability #Monero #P2Pool
Information Security News
Monero P2Pool Critical Vulnerability: Urgent V4.16 Update
A critical vulnerability in Monero P2Pool is actively exploited to steal mining rewards. Miners must urgently update to P2Pool v4.16 to secure their payouts.
⤷ Title: Silver Fox Trojan: China Cracks Down on Cybercrime Cells Across Five Provinces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:26:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:26:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals
Information Security News
Silver Fox Trojan: China Arrests Dozens in Crackdown
China dismantled Silver Fox Trojan cells across five provinces, detaining dozens tied to phishing sites and a 439-domain CNCERT-tracked campaign.
⤷ Title: Steam Workshop Flaw Exploited to Distribute Malware via Wallpaper Engine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:22:45 +0000
════════════════════════
⌗ Tags: #Malware #DarkKomet #kaspersky #Malware Campaign #Steam Workshop #Wallpaper Engine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:22:45 +0000
════════════════════════
⌗ Tags: #Malware #DarkKomet #kaspersky #Malware Campaign #Steam Workshop #Wallpaper Engine
Information Security News
Steam Workshop Malware Distributed via Wallpaper Engine
Kaspersky warns of Steam Workshop malware disguised as Wallpaper Engine files, deploying DarkKomet RATs and info stealers to compromise systems.
⤷ Title: SearchLeak: Microsoft 365 Copilot Flaw Let One Click Leak Enterprise Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:19:05 +0000
════════════════════════
⌗ Tags: #Vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:19:05 +0000
════════════════════════
⌗ Tags: #Vulnerability
Information Security News
SearchLeak: Microsoft 365 Copilot Flaw Let One Click Leak Enterprise Data
A single link to a trusted Microsoft domain could quietly turn Copilot into a data exfiltration tool. Varonis Threat Labs disclosed this flaw, naming it SearchLeak. The chain let an attacker steal…
⤷ Title: JetBrains Malicious Plugins Steal Developer API Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:16:22 +0000
════════════════════════
⌗ Tags: #Malware #Aikido Security #API Security #cyber threats #IDE Plugins #JetBrains
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:16:22 +0000
════════════════════════
⌗ Tags: #Malware #Aikido Security #API Security #cyber threats #IDE Plugins #JetBrains
Information Security News
JetBrains Malicious Plugins Steal Developer API Keys
Aikido Security discovered 15 JetBrains malicious plugins stealing developer API keys. Learn how these fake AI assistants compromise your development environment.
⤷ Title: Google Vertex AI Vulnerability Exposed in Python SDK
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:15:08 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #cybersecurity #google cloud #machine learning #Vertex AI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:15:08 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #cybersecurity #google cloud #machine learning #Vertex AI
Information Security News
Google Vertex AI Vulnerability Exposed in Python SDK
A critical Google Vertex AI vulnerability in the Python SDK allowed attackers to hijack machine learning models. Discover how to patch this dangerous flaw.
⤷ Title: Velvet Ant’s Operation Highland: A Decade Inside Critical Infrastructure
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:08:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus threat actor #Critical Infrastructure #CVE_2024_20399 #OpenSSH backdoor #Operation Highland #PAM Backdoor #Sygnia #Velvet Ant
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:08:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus threat actor #Critical Infrastructure #CVE_2024_20399 #OpenSSH backdoor #Operation Highland #PAM Backdoor #Sygnia #Velvet Ant
Daily CyberSecurity
Velvet Ant’s Operation Highland: A Decade Inside Critical Infrastructure
A China-nexus threat group known as Velvet Ant hid inside one organization’s network for nearly a decade. Sygnia’s incident response team uncovered the campaign and named it Operation …
⤷ Title: ChatGPT Scheduled Tasks Transform AI into an Active Agent
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:26:37 +0000
════════════════════════
⌗ Tags: #Technology #AI agent #ChatGPT #OpenAI #scheduled tasks #Tech News
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:26:37 +0000
════════════════════════
⌗ Tags: #Technology #AI agent #ChatGPT #OpenAI #scheduled tasks #Tech News
Daily CyberSecurity
ChatGPT Scheduled Tasks Transform AI into an Active Agent
OpenAI introduces ChatGPT Scheduled Tasks, transforming the AI into a proactive agent capable of automated monitoring and routine management.
⤷ Title: Microsoft China AI Business Thrives on OpenAI Sales
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:17:27 +0000
════════════════════════
⌗ Tags: #Technology #AI Cloud #ByteDance #Export Controls #Microsoft #OpenAI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:17:27 +0000
════════════════════════
⌗ Tags: #Technology #AI Cloud #ByteDance #Export Controls #Microsoft #OpenAI
Daily CyberSecurity
Microsoft China AI Business Thrives on OpenAI Sales
Microsoft's China AI business is thriving, with ByteDance spending $1 billion annually on OpenAI models via Azure despite US export bans.
⤷ Title: Moxa Patches NPort Flaws: Root RCE and Format String Bugs (CVE-2026-10829)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:03:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_10828 #CVE_2026_10829 #ICS security #Moxa #Moxa NPort vulnerability #NPort #serial device server
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:03:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_10828 #CVE_2026_10829 #ICS security #Moxa #Moxa NPort vulnerability #NPort #serial device server
Daily CyberSecurity
Moxa Patches NPort Flaws: Root RCE and Format String Bugs (CVE-2026-10829)
A Moxa NPort vulnerability (CVE-2026-10829) lets authenticated attackers gain root via RCE on serial device servers. Patch v1.5.1 now.
⤷ Title: AsyncRAT AI Lures Target Users Hunting AI Skills
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:03:39 +0000
════════════════════════
⌗ Tags: #Malware #AI Threats #AsyncRAT #AutoHotkey #FortiGuard Labs #Process Hollowing #rat
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:03:39 +0000
════════════════════════
⌗ Tags: #Malware #AI Threats #AsyncRAT #AutoHotkey #FortiGuard Labs #Process Hollowing #rat
Daily CyberSecurity
AsyncRAT AI Lures Target Users Hunting AI Skills
FortiGuard Labs uncovered AsyncRAT AI lures using fake AI guides and an AutoHotkey loader to inject a stealthy .NET RAT into memory.
⤷ Title: Thousands of Publicly Exposed MLflow Instances — A Hidden Risk in MLOps Infrastructure
════════════════════════
𐀪 Author: Dehacker
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:31:09 GMT
════════════════════════
⌗ Tags: #ai_security #bug_bounty #mlflow #security #mlops
════════════════════════
𐀪 Author: Dehacker
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:31:09 GMT
════════════════════════
⌗ Tags: #ai_security #bug_bounty #mlflow #security #mlops
Medium
Thousands of Publicly Exposed MLflow Instances — A Hidden Risk in MLOps Infrastructure
Summary
⤷ Title: The Password They Deleted But Never Erased
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:43:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web3 #bug_bounty_writeup #web_development
════════════════════════
𐀪 Author: morgan_hack
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:43:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web3 #bug_bounty_writeup #web_development
Medium
The Password They Deleted But Never Erased
A web server shipped its .git folder by accident — and Git never forgets.
⤷ Title: Best Cyber Security Training Institute in India
════════════════════════
𐀪 Author: Cozonix
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:41:14 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #ethical_hacking #hacking #technology #cybersecurity
════════════════════════
𐀪 Author: Cozonix
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 09:41:14 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #ethical_hacking #hacking #technology #cybersecurity
Medium
Best Cyber Security Training Institute in India
Best Cyber Security Training Institute in India -A Complete Guide to Choosing the Right Cybersecurity Career Path
⤷ Title: OWASP Top 10 2025: Application Design Flaws — part 2
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:50:38 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_development #ethical_hacking #infosec #cybersecurity
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 08:50:38 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #web_development #ethical_hacking #infosec #cybersecurity
Medium
OWASP Top 10 2025: Application Design Flaws — part 2
AS03: Cryptographic Failures