⤷ Title: Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 14:40:51 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 14:40:51 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: uBlock Origin Blocks ClickFix Malware Pop-ups
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:51:57 +0000
════════════════════════
⌗ Tags: #Malware #ad blocker #BNB Chain #browser security #ClickFix #Malware Protection #Social Engineering #UBlock Origin
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:51:57 +0000
════════════════════════
⌗ Tags: #Malware #ad blocker #BNB Chain #browser security #ClickFix #Malware Protection #Social Engineering #UBlock Origin
Information Security News
uBlock Origin Blocks ClickFix Malware Pop-ups
uBlock Origin, the popular ad-blocking extension, has gained new capabilities to protect users. It now detects and blocks websites that display malicious ClickFix pop-ups. These sites try to trick…
⤷ Title: GamersFirst Anti-Cheat Driver Has 3 CVEs in Windows
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:51:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #CERT/CC #CVE_2026_12168 #GamersFirst Anti_Cheat #Kernel Driver Vulnerability #Little Orbit #privilege escalation #Windows Kernel
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:51:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #CERT/CC #CVE_2026_12168 #GamersFirst Anti_Cheat #Kernel Driver Vulnerability #Little Orbit #privilege escalation #Windows Kernel
Information Security News
GamersFirst Anti-Cheat Driver Has 3 CVEs in Windows
An anti-cheat system designed to keep games fair has instead introduced a serious security gap. CERT/CC at Carnegie Mellon University disclosed three vulnerabilities in the GamersFirst Anti-Cheat …
⤷ Title: SpaceXAI: Elon Musk’s Orbital Data Centers Vision
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:54:07 +0000
════════════════════════
⌗ Tags: #Technology #artificial intelligence #Elon Musk #orbital data centers #SpaceXAI #Starmind
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:54:07 +0000
════════════════════════
⌗ Tags: #Technology #artificial intelligence #Elon Musk #orbital data centers #SpaceXAI #Starmind
Daily CyberSecurity
SpaceXAI: Elon Musk’s Orbital Data Centers Vision
Five months after Elon Musk amalgamated his artificial intelligence and space enterprises, xAI formally announced its rebranding to SpaceXAI. This novel brand identity and logo recently made their…
⤷ Title: ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
Daily CyberSecurity
ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
At a glance Details Actor or group ARToken operators; assessed as an EvilTokens affiliate panel Activity type Phishing-as-a-service (PhaaS) with device code phishing and token theft Targets Micros…
⤷ Title: Critical IBM Power HMC Vulnerability Exposes Systems
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:29:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_12943 #IBM #Power HMC #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:29:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_12943 #IBM #Power HMC #Vulnerability
Daily CyberSecurity
Critical IBM Power HMC Vulnerability Exposes Systems
TL;DR IBM disclosed a critical CVSS 9.8 flaw, tracked as CVE-2026-12943, in its Power Hardware Management Console (HMC). This IBM Power HMC vulnerability allows unauthenticated attackers to run ar…
⤷ Title: RustDuck Botnet: A Two-Stage DDoS Threat Shifting From C to Rust
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 07:50:38 +0000
════════════════════════
⌗ Tags: #Malware #botnet #ddos #IoT security #Rust malware #RustDuck
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 07:50:38 +0000
════════════════════════
⌗ Tags: #Malware #botnet #ddos #IoT security #Rust malware #RustDuck
Daily CyberSecurity
RustDuck Botnet: A Two-Stage DDoS Threat Shifting From C to Rust
At a Glance Malware family RustDuck Threat actor Unattributed Targets / victims IoT devices, web apps, and enterprise servers; 59 victim IPs and 203 attack incidents in XLab telemetry Delivery vec…
⤷ Title: The Path of the Serpent: How I Turned a P5 Open Redirect into a $7,500 RCE on Ragnar Lothbrok
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:20:14 GMT
════════════════════════
⌗ Tags: #xs #bug_bounty #open_redirect #rce
════════════════════════
𐀪 Author: 0B1To_X_ucH!h4
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:20:14 GMT
════════════════════════
⌗ Tags: #xs #bug_bounty #open_redirect #rce
Medium
🐍 The Path of the Serpent: How I Turned a P5 Open Redirect into a $7,500 RCE on Ragnar Lothbrok
From “not worth fixing” to “critical infrastructure breach” — the 3-week journey that proved low bugs hide high impact
⤷ Title: Business Logic Bypass: The Export Limit Bypass
════════════════════════
𐀪 Author: YAMIKA SOLANKI
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:07:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #business_logic #application_security #cybersecurity
════════════════════════
𐀪 Author: YAMIKA SOLANKI
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:07:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #business_logic #application_security #cybersecurity
Medium
Business Logic Bypass: The Export Limit Bypass
Business logic vulnerabilities don’t always involve complex exploits. Sometimes, all it takes is changing a single value that an…
⤷ Title: OWASP Top 10 2025 A01: Where Broken Access Control Fails in Real Applications
════════════════════════
𐀪 Author: Przemyslaw
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:19:58 GMT
════════════════════════
⌗ Tags: #appsec #cybersecurity #application_security #security
════════════════════════
𐀪 Author: Przemyslaw
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:19:58 GMT
════════════════════════
⌗ Tags: #appsec #cybersecurity #application_security #security
Medium
OWASP Top 10 2025 A01: Where Broken Access Control Fails in Real Applications
Authentication works. The UI looks correct. The happy path passes. But access control still fails when the application checks the wrong…
⤷ Title: Wireless Network Testing
════════════════════════
𐀪 Author: R. Mahathi
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:45:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #vulnerability_assessment #network_security #vapt
════════════════════════
𐀪 Author: R. Mahathi
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:45:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #vulnerability_assessment #network_security #vapt
Medium
Wireless Network Testing
The Network Perimeter Nobody Walks Around to Check
⤷ Title: Host & Network Penetration Testing: Exploitation CTF 3 — eJPT (INE)
════════════════════════
𐀪 Author: Suraj Apar
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:02:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #ejpt #ctf #penetration_testing
════════════════════════
𐀪 Author: Suraj Apar
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:02:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #ejpt #ctf #penetration_testing
Medium
Host & Network Penetration Testing: Exploitation CTF 3 — eJPT (INE)
A walkthrough covering ProFTPD mod_copy exploitation, local service banner grabbing, SMB brute-force with webshell upload, and SUID binary…
⤷ Title: Exploring SQLMAP
════════════════════════
𐀪 Author: Salma Fouad
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:32:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme #offensive_security #sqlmap
════════════════════════
𐀪 Author: Salma Fouad
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:32:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #tryhackme #offensive_security #sqlmap
Medium
Exploring SQLMAP
What is SQLMap, and how to use it to exploit a web application?
⤷ Title: Kioptrix 2: Walkthrough and Write-up
════════════════════════
𐀪 Author: Rajany Hacker
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:14:15 GMT
════════════════════════
⌗ Tags: #kioptrix_level_2 #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Rajany Hacker
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:14:15 GMT
════════════════════════
⌗ Tags: #kioptrix_level_2 #cybersecurity #penetration_testing
Medium
Kioptrix 2: Walkthrough and Write-up
In this write-up, we will walk through the step-by-step penetration testing process for the classic Kioptrix vulnerable machine. This lab…
⤷ Title: TryHackMe DiskFiltration: Forensic Analysis of a Data Breach
════════════════════════
𐀪 Author: Fuad Khan
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:52:25 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #digital_forensics
════════════════════════
𐀪 Author: Fuad Khan
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:52:25 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #digital_forensics
Medium
TryHackMe DiskFiltration: Forensic Analysis of a Data Breach
This walkthrough dissects the TryHackMe DiskFiltration challenge, where we trace a data breach back to a former employee by analyzing…
⤷ Title: What I Learned from Completing the Cyber Security 101 Path on TryHackMe
════════════════════════
𐀪 Author: Prabhat bansal
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:50:14 GMT
════════════════════════
⌗ Tags: #networking #linux #cybersecurity #beginner #tryhackme
════════════════════════
𐀪 Author: Prabhat bansal
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:50:14 GMT
════════════════════════
⌗ Tags: #networking #linux #cybersecurity #beginner #tryhackme
Medium
What I Learned from Completing the Cyber Security 101 Path on TryHackMe
Introduction
⤷ Title: Day 2: What Is a Security Operations Center (SOC)? Understanding the Heart of Modern Cyber Defense
════════════════════════
𐀪 Author: SIAM AHMED
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:36:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #blue_team #learning #soc_analyst #cybersecurity
════════════════════════
𐀪 Author: SIAM AHMED
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:36:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #blue_team #learning #soc_analyst #cybersecurity
Medium
Day 2: What Is a Security Operations Center (SOC)? Understanding the Heart of Modern Cyber Defense
Cyberattacks don’t happen only during business hours. Organizations face phishing campaigns, ransomware, insider threats, credential…
⤷ Title: Exploiting Common Vulnerabilities in Metasploitable 2
════════════════════════
𐀪 Author: Aneesh Kv
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:59:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking
════════════════════════
𐀪 Author: Aneesh Kv
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:59:44 GMT
════════════════════════
⌗ Tags: #ethical_hacking
Medium
Exploiting Common Vulnerabilities in Metasploitable 2
In this section, we demonstrate several well-known vulnerabilities included in Metasploitable 2. These exploits are performed only within…
⤷ Title: PortSwigger — Exploiting AI Agents to Trigger Secondary Vulnerabilities
════════════════════════
𐀪 Author: Sequer
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:59:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #prompt_injection_attack #ai_security #web_security #ssrf
════════════════════════
𐀪 Author: Sequer
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:59:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #prompt_injection_attack #ai_security #web_security #ssrf
Medium
PortSwigger — Exploiting AI Agents to Trigger Secondary Vulnerabilities
This post walks through the solution to PortSwigger Web Security Academy’s Web LLM Attacks lab, Exploiting AI agents to trigger secondary…
⤷ Title: 4 Best Email Security Solutions to Keep Employee Inboxes Safe
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 10:39:25 +0000
════════════════════════
⌗ Tags: #Security #AI #Business #Cybersecurity #Email Security #emails #Privacy
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 10:39:25 +0000
════════════════════════
⌗ Tags: #Security #AI #Business #Cybersecurity #Email Security #emails #Privacy
Hackread
4 Best Email Security Solutions to Keep Employee Inboxes Safe
Compare leading and best email security solutions with AI threat detection, phishing defense, malware blocking, and DLP features for teams.
⤷ Title: Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 11:35:07 GMT
════════════════════════
⌗ Tags: #akamai #xss_attack #bug_bounty #xs #bugbounty_writeup
════════════════════════
𐀪 Author: Alvin Ferdiansyah
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 11:35:07 GMT
════════════════════════
⌗ Tags: #akamai #xss_attack #bug_bounty #xs #bugbounty_writeup
Medium
Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account Takeover
One click, eight seconds, nine webhook hits. It started with a single bracket character that broke an Akamai WAF rule.