⤷ Title: New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 14:24:37 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 14:24:37 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Apache Kvrocks Vulnerabilities Fix Five Severe Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:58:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Kvrocks #CVE_2026_41566 #CVE_2026_46752 #CVE_2026_54226 #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:58:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Kvrocks #CVE_2026_41566 #CVE_2026_46752 #CVE_2026_54226 #Vulnerability
Daily CyberSecurity
Apache Kvrocks Vulnerabilities Fix Five Severe Flaws
Five Apache Kvrocks vulnerabilities, including CVSS 10 NoSQL database flaws, expose servers to DoS and overflow attacks. Patch to version 2.16.0 now.
⤷ Title: AutoJack AI Agent Exploit Unveiled
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:52:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI agent #AutoGen Studio #AutoJack #cybersecurity #Exploit #rce #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:52:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI agent #AutoGen Studio #AutoJack #cybersecurity #Exploit #rce #Vulnerability
Daily CyberSecurity
AutoJack AI Agent Exploit Unveiled
Discover the AutoJack AI agent exploit! We explore the AutoGen Studio vulnerability that allows remote code execution via local MCP WebSockets.
⤷ Title: Windows Crypto Clipper Malware Exposed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:01:49 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #cybersecurity #malware #Microsoft Threat Intelligence #Tor routed cryptocurrency stealer #Windows crypto clipper malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:01:49 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #cybersecurity #malware #Microsoft Threat Intelligence #Tor routed cryptocurrency stealer #Windows crypto clipper malware
Daily CyberSecurity
Windows Crypto Clipper Malware Exposed
Microsoft discovered a new Windows crypto clipper malware. This Tor routed cryptocurrency stealer uses USB drives to spread and steal wallet addresses.
⤷ Title: Excessive Data Exposure via Unauthenticated GraphQL Endpoint
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:20:53 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #graphql #web_security #cybersecurity_research
════════════════════════
𐀪 Author: 0xPinocchioSec
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:20:53 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #graphql #web_security #cybersecurity_research
Medium
Excessive Data Exposure via Unauthenticated GraphQL Endpoint
Bug Bounty Write-up | Information Disclosure | GraphQL Security
⤷ Title: Insecure Deserialization: The Silent Code Executor Hackers Love — By GrayXploit Security Research…
════════════════════════
𐀪 Author: Grayxploit
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:02:25 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #owasp #bug_bounty #red_team
════════════════════════
𐀪 Author: Grayxploit
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:02:25 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #owasp #bug_bounty #red_team
Medium
Insecure Deserialization: The Silent Code Executor Hackers Love — By GrayXploit Security Research Team
“Give me control over what your app trusts, and I’ll own your server.” — Every exploit developer who has touched a Java serialization bug
⤷ Title: Cordyceps: The CI/CD Exploit That Let Any Free GitHub Account Hijack Microsoft, Google, and Apache
════════════════════════
𐀪 Author: Abhijith
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:00:43 GMT
════════════════════════
⌗ Tags: #infosec #open_source #appsec #devsecops #cybersecurity
════════════════════════
𐀪 Author: Abhijith
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:00:43 GMT
════════════════════════
⌗ Tags: #infosec #open_source #appsec #devsecops #cybersecurity
Medium
Cordyceps: The CI/CD Exploit That Let Any Free GitHub Account Hijack Microsoft, Google, and Apache
A parasitic fungus takes over its host’s body and controls it from within. Security researchers just found something eerily similar living…
⤷ Title: How I Actually Find Freelance Pentest Clients Without a Sales Background
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:20:08 GMT
════════════════════════
⌗ Tags: #business #freelancing #cybersecurity #penetration_testing #careers
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:20:08 GMT
════════════════════════
⌗ Tags: #business #freelancing #cybersecurity #penetration_testing #careers
Medium
How I Actually Find Freelance Pentest Clients Without a Sales Background
Nobody taught me how to sell. Here’s the system I accidentally built that brings in consulting work without a single cold call.
⤷ Title: TryHackMe “Forward” Writeup | sAMAccountName Spoofing to Domain Admin (CVE-2021–42278 & 42287)
════════════════════════
𐀪 Author: matteo-iacovantuono
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:06:38 GMT
════════════════════════
⌗ Tags: #penetration_testing #ctf #tryhackme #ctf_writeup #active_directory
════════════════════════
𐀪 Author: matteo-iacovantuono
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:06:38 GMT
════════════════════════
⌗ Tags: #penetration_testing #ctf #tryhackme #ctf_writeup #active_directory
Medium
TryHackMe “Forward” Writeup | sAMAccountName Spoofing to Domain Admin (CVE-2021–42278 & 42287)
Introduction
⤷ Title: Blueprint — TryHackMe WriteUp with Flags
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:55:03 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #ctf #tryhackme #cybersecurity
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:55:03 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme_writeup #ctf #tryhackme #cybersecurity
Medium
Blueprint — TryHackMe WriteUp with Flags
Blueprint — TryHackMe WriteUp with Flags Date: 31/08/2025 Room Link: https://tryhackme.com/room/blueprint My Profile: https://tryhackme.com/p/RayenHafsawy 🧭 Introduction This room chains an …
⤷ Title: Free cybersecurity certifications in 2026
════════════════════════
𐀪 Author: Abdul Samad
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:17:36 GMT
════════════════════════
⌗ Tags: #ethical_hacking #career_development #certification #cybersecurity #online_learning
════════════════════════
𐀪 Author: Abdul Samad
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 09:17:36 GMT
════════════════════════
⌗ Tags: #ethical_hacking #career_development #certification #cybersecurity #online_learning
Medium
Free cybersecurity certifications in 2026
Free Cybersecurity Certifications in 2026: Which Ones Are Actually Worth Your Time?
⤷ Title: Lab 22: OS command injection, simple case
════════════════════════
𐀪 Author: Tkacala
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:02:40 GMT
════════════════════════
⌗ Tags: #ethical_hacking #web_security #burpsuite #portswigger #cybersecurity
════════════════════════
𐀪 Author: Tkacala
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 08:02:40 GMT
════════════════════════
⌗ Tags: #ethical_hacking #web_security #burpsuite #portswigger #cybersecurity
Medium
Lab 22: OS command injection, simple case
Objective
⤷ Title: Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 16:47:31 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 16:47:31 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 14:53:03 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 14:53:03 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:43:57 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Cyber Crime #Brasil #Brazil #Cyber Attack #Cybersecurity #Emergency Alerts #Rio de JaneirO #São Paulo
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:43:57 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Cyber Crime #Brasil #Brazil #Cyber Attack #Cybersecurity #Emergency Alerts #Rio de JaneirO #São Paulo
Hackread
Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil
Brazil’s alert system was taken offline after a fake emergency alert reached phones, with officials investigating a suspected cyberattack and security failure.
⤷ Title: Siri Restricts External URL Summarization in iOS 27 Beta
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:01:24 +0000
════════════════════════
⌗ Tags: #Technology #Apple Intelligence #iOS 27 #Siri #Tech News #Web Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:01:24 +0000
════════════════════════
⌗ Tags: #Technology #Apple Intelligence #iOS 27 #Siri #Tech News #Web Security
Daily CyberSecurity
Siri Restricts External URL Summarization in iOS 27 Beta
Discover why Apple restricts Siri URL summarization in iOS 27. Learn about the new security controls, prompt injection protection, and web traffic impacts.
⤷ Title: The True Cost of Artificial Intelligence: Enterprises Impose Restrictions
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:56:46 +0000
════════════════════════
⌗ Tags: #Technology #Accenture #artificial intelligence #enterprise AI #Tech News #Token Costs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:56:46 +0000
════════════════════════
⌗ Tags: #Technology #Accenture #artificial intelligence #enterprise AI #Tech News #Token Costs
Daily CyberSecurity
The True Cost of Artificial Intelligence: Enterprises Impose Restrictions
Discover why global enterprises are restricting enterprise AI tools due to soaring token costs and inefficient usage by non-technical staff.
⤷ Title: Bug Bounty for Beginners 2026 Earn Your First $100 with Ethical Hacking | Step-by-Step Blueprint…
════════════════════════
𐀪 Author: R.H Rizvi
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:32:16 GMT
════════════════════════
⌗ Tags: #hacking #programming #technology #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: R.H Rizvi
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 11:32:16 GMT
════════════════════════
⌗ Tags: #hacking #programming #technology #cybersecurity #bug_bounty
Medium
Bug Bounty for Beginners 2026 Earn Your First $100 with Ethical Hacking | Step-by-Step Blueprint…
Ninety percent of beginners who start bug bounty hunting in 2026 will quit before they earn a single dollar. Not because they lack…
⤷ Title: Lab 3: Blind OS Command Injection with Output Redirection — PortSwigger Web Security Academy…
════════════════════════
𐀪 Author: Nitish Mukhiya
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:26:41 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #os_command_injection #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Nitish Mukhiya
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:26:41 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #os_command_injection #ethical_hacking #cybersecurity
Medium
Lab 3: Blind OS Command Injection with Output Redirection — PortSwigger Web Security Academy Walkthrough (Part 3 of 5)
Turning a silent vulnerability into a readable one: how redirecting command output into a public directory lets you read RCE results…
⤷ Title: Lab 2: Blind OS Command Injection with Time Delays — PortSwigger Web Security Academy Walkthrough…
════════════════════════
𐀪 Author: Nitish Mukhiya
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:18:51 GMT
════════════════════════
⌗ Tags: #os_command_injection #cybersecurity #bug_bounty #pentesting #ethical_hacking
════════════════════════
𐀪 Author: Nitish Mukhiya
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:18:51 GMT
════════════════════════
⌗ Tags: #os_command_injection #cybersecurity #bug_bounty #pentesting #ethical_hacking
Medium
Lab 2: Blind OS Command Injection with Time Delays — PortSwigger Web Security Academy Walkthrough (Part 2 of 5)
When the server stays silent: how to prove Remote Code Execution using nothing but a stopwatch and the Linux sleep command.
⤷ Title: Why Business Logic Vulnerabilities Require a New Generation of Application Security Testing
════════════════════════
𐀪 Author: James Miller
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:52:30 GMT
════════════════════════
⌗ Tags: #application_security #web_application_security
════════════════════════
𐀪 Author: James Miller
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 10:52:30 GMT
════════════════════════
⌗ Tags: #application_security #web_application_security
Medium
Why Business Logic Vulnerabilities Require a New Generation of Application Security Testing
Most organizations believe they have a reasonable understanding of their application security posture. Their scanners run regularly…