⤷ Title: From Deep Link to Shell: Easy $3000 Android Crits.
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 23:19:13 GMT
════════════════════════
⌗ Tags: #android #hackerone #static_code_analysis #rce #deeplink
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 23:19:13 GMT
════════════════════════
⌗ Tags: #android #hackerone #static_code_analysis #rce #deeplink
Medium
From Deep Link to Shell: Easy $3000 Android Crits.
Akwaaba! gang, another part of my Static Android App Hacking series, today our focus is on exploiting Deep Links to achieve RCE. An easy…
⤷ Title: SimpleHelp Authentication Bypass Exploited in the Wild to Deploy TaskWeaver and Djinn Stealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:43:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_48558 #Djinn Stealer #information stealer #MSP Security #OIDC #RMM security #SimpleHelp #TaskWeaver
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:43:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_48558 #Djinn Stealer #information stealer #MSP Security #OIDC #RMM security #SimpleHelp #TaskWeaver
Daily CyberSecurity
SimpleHelp Authentication Bypass Exploited in the Wild to Deploy TaskWeaver and Djinn Stealer
On 29 June 2026, CISA added CVE-2026-48558 to its Known Exploited Vulnerabilities catalog. The flaw is a critical SimpleHelp authentication bypass in the OIDC login flow. Attackers now use it in t…
⤷ Title: Critical wolfSSL Security Vulnerabilities Expose IoT Systems
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:20:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_11310 #CVE_2026_11999 #CVE_2026_6679 #tls #wolfSSL
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:20:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_11310 #CVE_2026_11999 #CVE_2026_6679 #tls #wolfSSL
Daily CyberSecurity
Critical wolfSSL Security Vulnerabilities Expose IoT Systems
TL;DR Developers patched six high-severity wolfSSL security vulnerabilities in the embedded SSL library. These flaws include an X.509 trust-chain bypass and dangerous heap buffer overflows. Admini…
⤷ Title: EVoke Systems Vulnerabilities Expose Charging Stations
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:00:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40702 #CVE_2026_50176 #CVE_2026_54479 #cybersecurity #EV Charging #EVoke Systems
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:00:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_40702 #CVE_2026_50176 #CVE_2026_54479 #cybersecurity #EV Charging #EVoke Systems
Daily CyberSecurity
EVoke Systems Vulnerabilities Expose Charging Stations
TL;DR Four critical security flaws currently impact all versions of the EVoke Systems Charging Station Management System. These EVoke Systems vulnerabilities allow attackers to hijack active sessi…
⤷ Title: Four Critical Cacti Vulnerabilities Fixed in 1.2.31
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:21:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cacti #CVE_2026_39893 #CVE_2026_39938 #CVE_2026_39948 #CVE_2026_39955 #lfi #network monitoring #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:21:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cacti #CVE_2026_39893 #CVE_2026_39938 #CVE_2026_39948 #CVE_2026_39955 #lfi #network monitoring #sql injection
Daily CyberSecurity
Four Critical Cacti Vulnerabilities Fixed in 1.2.31
TL;DR Cacti fixed four critical flaws in version 1.2.31. Three allow pre-authentication SQL injection, and one allows unauthenticated local file inclusion. All four score between 9.3 and 9.8. Why …
⤷ Title: We Rebuilt Every Lab from Scratch — Here’s What Changed
════════════════════════
𐀪 Author: Erkan Kavas
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:44:55 GMT
════════════════════════
⌗ Tags: #hackmetoo #bug_bounty #cybersecurity #education
════════════════════════
𐀪 Author: Erkan Kavas
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:44:55 GMT
════════════════════════
⌗ Tags: #hackmetoo #bug_bounty #cybersecurity #education
Medium
We Rebuilt Every Lab from Scratch — Here’s What Changed
When I first built the labs for Hackmetoo, the goal was simple: get working content in front of learners fast. PHP files, inline CSS, some…
⤷ Title: 10 Burp Suite Extensions Every Pentester Should Know (And How to Actually Use Them)
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:19:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #bug_bounty #ethical_hacking #medium
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:19:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #bug_bounty #ethical_hacking #medium
Medium
10 Burp Suite Extensions Every Pentester Should Know (And How to Actually Use Them)
I remember the first time I opened Burp Suite and thought it was enough on its own.
⤷ Title: Tuesday Morning Threat Report: Jun 30, 2026
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:23:18 GMT
════════════════════════
⌗ Tags: #vulnerability #hacking #cybersecurity
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:23:18 GMT
════════════════════════
⌗ Tags: #vulnerability #hacking #cybersecurity
Medium
Tuesday Morning Threat Report: Jun 30, 2026
Where the news is always bad, but the analysis is always good.
⤷ Title: Nobody Is Coming to Tell You How to Pay
════════════════════════
𐀪 Author: S6 Tech
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:49:04 GMT
════════════════════════
⌗ Tags: #small_business #technology #infosec #cybersecurity #ransomware
════════════════════════
𐀪 Author: S6 Tech
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 01:49:04 GMT
════════════════════════
⌗ Tags: #small_business #technology #infosec #cybersecurity #ransomware
Medium
Nobody Is Coming to Tell You How to Pay
A new ransomware strain leaves no instructions to pay, and AI just compressed the attack window from days to hours. Here is the one free…
⤷ Title: GOAD-Light Walkthrough
════════════════════════
𐀪 Author: Ouakidiyassine
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:09:23 GMT
════════════════════════
⌗ Tags: #active_directory #penetration_testing #pentesting
════════════════════════
𐀪 Author: Ouakidiyassine
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:09:23 GMT
════════════════════════
⌗ Tags: #active_directory #penetration_testing #pentesting
Medium
GOAD-Light Walkthrough
2 domains: sevenkingdoms.local north.sevenkingdoms.local so kingslanding.sevenkingdoms.local(192.168.56.10) must be a DC in the first domain the north.sevenkingdoms.local has two subdomains one of …
⤷ Title: ICMP Tunneling & Pivoting to a Domain Controller
════════════════════════
𐀪 Author: Nouman Ali Khan
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:07:25 GMT
════════════════════════
⌗ Tags: #hackthebox #tunneling #penetration_testing #icmp_tunneling #pivoting
════════════════════════
𐀪 Author: Nouman Ali Khan
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:07:25 GMT
════════════════════════
⌗ Tags: #hackthebox #tunneling #penetration_testing #icmp_tunneling #pivoting
⤷ Title: HTB Enigma Writeup
════════════════════════
𐀪 Author: Lukasjohannesmoeller
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:46:23 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #ctf_writeup #hackthebox
════════════════════════
𐀪 Author: Lukasjohannesmoeller
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:46:23 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #ctf_writeup #hackthebox
Medium
HTB Enigma Writeup
Foothold
⤷ Title: Intigriti June Bonus Challenge 2026 — Leaky Jar Write-up
════════════════════════
𐀪 Author: Ryuk0x01
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:09:08 GMT
════════════════════════
⌗ Tags: #csrf #bug_bounty_writeup #intigriti #ctf #ctf_writeup
════════════════════════
𐀪 Author: Ryuk0x01
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 00:09:08 GMT
════════════════════════
⌗ Tags: #csrf #bug_bounty_writeup #intigriti #ctf #ctf_writeup
Medium
Intigriti June Bonus Challenge 2026 — Leaky Jar Write-up
Introduction
⤷ Title: Adblock for YouTube Hides Dangerous Extension Architecture
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:26:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Adblock for YouTube #Chrome extension #cybersecurity #data privacy #malware
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:26:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Adblock for YouTube #Chrome extension #cybersecurity #data privacy #malware
Information Security News
Adblock for YouTube Hides Dangerous Extension Architecture
A popular ad-blocking extension on YouTube proves far more perilous than its Chrome Web Store page suggests. Researchers from Island dismantled Adblock for YouTube recently. Consequently, they dis…
⤷ Title: iPhone 18 Pro Secrets Leaked in Tata Electronics Breach
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:54:34 +0000
════════════════════════
⌗ Tags: #Data Leak #Apple #Data Breach #iPhone 18 Pro #ransomware #Supply Chain #Tata Electronics #World Leaks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:54:34 +0000
════════════════════════
⌗ Tags: #Data Leak #Apple #Data Breach #iPhone 18 Pro #ransomware #Supply Chain #Tata Electronics #World Leaks
Daily CyberSecurity
iPhone 18 Pro Secrets Leaked in Tata Electronics Breach
India’s Tata Group suffered a hacker attack earlier. Its subsidiary, Tata Electronics, assembles products for Apple, so it held various internal secrets from Apple and its component supplier…
⤷ Title: WhatsApp Usernames Let You Hide Your Phone Number
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:44:08 +0000
════════════════════════
⌗ Tags: #Technology #messaging #Meta #Phone Number #privacy #Usernames #WhatsApp
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:44:08 +0000
════════════════════════
⌗ Tags: #Technology #messaging #Meta #Phone Number #privacy #Usernames #WhatsApp
Daily CyberSecurity
WhatsApp Usernames Let You Hide Your Phone Number
To strengthen user privacy further, WhatsApp — Meta’s messaging app — has announced that it will formally introduce a “Usernames” feature later this year. In the future, when use…
⤷ Title: WSO2 API Manager Hit by CVSS 10 Auth Bypass and Six More Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 02:42:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #Authentication Bypass #CVE_2026_1728 #CVE_2026_3418 #CVE_2026_4052 #CVE_2026_5430 #WSO2 #WSO2 API Manager
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 02:42:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #Authentication Bypass #CVE_2026_1728 #CVE_2026_3418 #CVE_2026_4052 #CVE_2026_5430 #WSO2 #WSO2 API Manager
Daily CyberSecurity
WSO2 API Manager Hit by CVSS 10 Auth Bypass and Six More Flaws
TL;DR WSO2 patched seven vulnerabilities across its API platform, including WSO2 API Manager, in June 2026. The worst, CVE-2026-5430, scores a maximum 10 and bypasses JWT authentication. The rest …
⤷ Title: Synology MailPlus Server Patched for CVSS 10 Flaw CVE-2026-13136
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 02:11:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_15660 #CVE_2026_13135 #CVE_2026_13136 #DSM #MailPlus Server #NAS #Synology
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 02:11:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_15660 #CVE_2026_13135 #CVE_2026_13136 #DSM #MailPlus Server #NAS #Synology
Daily CyberSecurity
Synology MailPlus Server Patched for CVSS 10 Flaw CVE-2026-13136
TL;DR Synology fixed three vulnerabilities in Synology MailPlus Server, the email package for its NAS devices. The most severe, CVE-2026-13136, carries a maximum CVSS score of 10. Admins should up…
⤷ Title: ⚡ WhiteWidow: The Ultimate SQL Injection Scanner for Security Professionals
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:43:31 GMT
════════════════════════
⌗ Tags: #hacking #artificial_intelligence #web3 #sql #cybersecurity
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 03:43:31 GMT
════════════════════════
⌗ Tags: #hacking #artificial_intelligence #web3 #sql #cybersecurity
⤷ Title: Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 10:34:06 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 10:34:06 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Poisoned Tenant Attack Abuses OpenAI Organization Invites
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 05:24:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChatGPT #OpenAI #phishing #Poisoned Tenant #Push Security #SaaS Security #Social Engineering
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 05:24:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChatGPT #OpenAI #phishing #Poisoned Tenant #Push Security #SaaS Security #Social Engineering
Information Security News
Poisoned Tenant Attack Abuses OpenAI Organization Invites
Attackers have begun creating fake ChatGPT workspaces dressed up as real companies. Then they invite employees through genuine OpenAI emails. The scheme is dangerous precisely because it does not …