⤷ Title: GigaWiper Backdoor Bundles Disk Wiping Malware and Fake Ransomware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 06:03:10 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Crucio ransomware #disk wiping malware #FlockWiper #GigaWiper #Microsoft Threat Intelligence #wiper malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 06:03:10 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Crucio ransomware #disk wiping malware #FlockWiper #GigaWiper #Microsoft Threat Intelligence #wiper malware
Daily CyberSecurity
GigaWiper Backdoor Bundles Disk Wiping Malware and Fake Ransomware
At a glance Malware family GigaWiper (Golang backdoor; code ties to Crucio and FlockWiper) Threat actor Not publicly named by Microsoft; suspected single developer Target / victims Windows systems…
⤷ Title: CISA Adds Oracle E-Business Suite and KNX Flaws to KEV Catalog
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 02:31:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2023_4346 #CVE_2026_46817 #KEV #KNX #Oracle E_Business Suite
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 02:31:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2023_4346 #CVE_2026_46817 #KEV #KNX #Oracle E_Business Suite
Daily CyberSecurity
CISA Adds Oracle E-Business Suite and KNX Flaws to KEV Catalog
TL;DR The CISA KEV catalog gained two entries on July 15, 2026. The agency confirmed active exploitation of CVE-2026-46817 in Oracle E-Business Suite and CVE-2023-4346 in KNX building automation d…
⤷ Title: Splunk Fixes Three Splunk Enterprise Vulnerabilities Led by CVE-2026-20296 CSRF Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 02:11:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2026_20296 #CVE_2026_20297 #CVE_2026_20298 #Splunk #Splunk Enterprise
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 02:11:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2026_20296 #CVE_2026_20297 #CVE_2026_20298 #Splunk #Splunk Enterprise
Daily CyberSecurity
Splunk Fixes Three Splunk Enterprise Vulnerabilities Led by CVE-2026-20296 CSRF Flaw
TL;DR Splunk released patches on July 15, 2026 for three Splunk Enterprise vulnerabilities. The most serious, CVE-2026-20296, is a cross-site request forgery (CSRF) flaw that enables SPL execution…
⤷ Title: Lessons From DAO Governance Attacks A Critical Analysis of Kelp DAO and BonkDAO
════════════════════════
𐀪 Author: Manoj Kumar Desai
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:24:58 GMT
════════════════════════
⌗ Tags: #web3 #decentralization #hacking #dao #blockchain
════════════════════════
𐀪 Author: Manoj Kumar Desai
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:24:58 GMT
════════════════════════
⌗ Tags: #web3 #decentralization #hacking #dao #blockchain
Medium
Lessons From DAO Governance Attacks A Critical Analysis of Kelp DAO and BonkDAO
Decentralization did not fail in the Kelp DAO and BonkDAO incidents governance did. When hundreds of millions can be drained either through…
⤷ Title: Authentication Security Testing Checklist for Security Researchers
════════════════════════
𐀪 Author: Chilukavarshith
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:50:16 GMT
════════════════════════
⌗ Tags: #authentication #cybersecurity #web_security #penetration_testing #owasp_top_10
════════════════════════
𐀪 Author: Chilukavarshith
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:50:16 GMT
════════════════════════
⌗ Tags: #authentication #cybersecurity #web_security #penetration_testing #owasp_top_10
Medium
Authentication Security Testing Checklist for Security Researchers
Authentication is one of the most important components of any web application. A single weakness in the authentication flow can lead to…
⤷ Title: 50+ Registration Page Vulnerabilities Every Pentester Should Validate
════════════════════════
𐀪 Author: Mehboob khan
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:48:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #ethical_hacking
════════════════════════
𐀪 Author: Mehboob khan
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:48:28 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #ethical_hacking
Medium
50+ Registration Page Vulnerabilities Every Pentester Should Validate
Free Link…
⤷ Title: Relevant Walkthrough | SMB Enumeration, IIS Exploitation & Windows Privilege Escalation
════════════════════════
𐀪 Author: TibeRius_12
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:31:01 GMT
════════════════════════
⌗ Tags: #smb_enumeration #tryhackme #privilege_escalation #penetration_testing #windows_security
════════════════════════
𐀪 Author: TibeRius_12
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:31:01 GMT
════════════════════════
⌗ Tags: #smb_enumeration #tryhackme #privilege_escalation #penetration_testing #windows_security
Medium
Relevant Walkthrough | SMB Enumeration, IIS Exploitation & Windows Privilege Escalation
Hello everyone,
⤷ Title: A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
════════════════════════
𐀪 Author: Aleens-labs
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:47:51 GMT
════════════════════════
⌗ Tags: #information_security #cve #open_source #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Aleens-labs
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:47:51 GMT
════════════════════════
⌗ Tags: #information_security #cve #open_source #cybersecurity #bug_bounty
Medium
A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fix
⤷ Title: IDOR simple way with no burpsuite banged P3
════════════════════════
𐀪 Author: Sai Jayanth
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:07:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bugs #idor #learn
════════════════════════
𐀪 Author: Sai Jayanth
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:07:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bugs #idor #learn
Medium
IDOR simple way with no burpsuite banged P3
Bug bounty hunting doesn’t always require fancy tools or complicated payloads. Sometimes, all it takes is paying attention to small…
⤷ Title: HTB Bobby’s Bistro Writeup
════════════════════════
𐀪 Author: Shenyuchao
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:01:03 GMT
════════════════════════
⌗ Tags: #htb #htb_writeup #jwt_token #sql_injection
════════════════════════
𐀪 Author: Shenyuchao
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 05:01:03 GMT
════════════════════════
⌗ Tags: #htb #htb_writeup #jwt_token #sql_injection
Medium
HTB Bobby’s Bistro Writeup
Challenge Scenario
⤷ Title: File Upload Bypass On Indrive
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
════════════════════════
𐀪 Author: Mahmoud Elsaidy
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 04:19:09 GMT
════════════════════════
⌗ Tags: #file_upload_vulnerability #amazon_s3 #bug_bounty_writeup
Medium
File Upload Bypass Using a Pre-Signed S3 URL
welcome to my first write-up. I started bug hunting about 3 months ago, and this was one of my first findings, so I would love to share it.
⤷ Title: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 12:12:23 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 12:12:23 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SingGuard-NSFA: Ant Group Open-Sources a Guardrail to Stop Malicious AI Agent Commands After the JadePuffer Attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:45:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #AI security #Ant Group #JadePuffer #SingGuard_NSFA
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:45:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #AI security #Ant Group #JadePuffer #SingGuard_NSFA
Information Security News
SingGuard-NSFA: Ant Group Open-Sources a Guardrail to Stop Malicious AI Agent Commands After the JadePuffer Attack
Merely twelve days after the first fully automated data-encryption attack came to light, Ant Group has unveiled a free tool designed to halt dangerous artificial intelligence commands before they …
⤷ Title: Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:59:04 +0000
════════════════════════
⌗ Tags: #Technology #AI #Gemini #Gemini Notebook #google #NotebookLM
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:59:04 +0000
════════════════════════
⌗ Tags: #Technology #AI #Gemini #Gemini Notebook #google #NotebookLM
Daily CyberSecurity
Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution
NotebookLM, Google’s deep-research and AI note-taking tool beloved by professionals and students alike, has officially undergone a rebrand. To align its naming with the rest of Google’…
⤷ Title: Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:02:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #Chromium #CVE_2026_15899 #CVE_2026_15900 #CVE_2026_15901 #google chrome #use after free #V8
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:02:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #Chromium #CVE_2026_15899 #CVE_2026_15900 #CVE_2026_15901 #google chrome #use after free #V8
Daily CyberSecurity
Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network
TL;DR Google pushed Chrome 150.0.7871.128/.129 to the Stable channel on July 16, 2026. The release fixes seven flaws, and three of them carry a Critical rating. Google reports no exploitation in t…
⤷ Title: Supply Chain Trojan Targets Software Developers Through Project Files
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:04:07 +0000
════════════════════════
⌗ Tags: #Malware #crypto wallet theft #developer security #Doctor Web #malware #Software Supply Chain #Supply Chain Trojan #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:04:07 +0000
════════════════════════
⌗ Tags: #Malware #crypto wallet theft #developer security #Doctor Web #malware #Software Supply Chain #Supply Chain Trojan #XMRig
Daily CyberSecurity
Supply Chain Trojan Targets Software Developers Through Project Files
At a glance Malware family Multi-stage trojan (Doctor Web: Trojan.DownLoader49, BackDoor.Siggen2.5906, Trojan.BtcMine.3956) Threat actor Unknown; not attributed Target / victims Software developer…
⤷ Title: Zero Credentials, Full Access: Inside a Complete Authorization Failure
════════════════════════
𐀪 Author: 0x-elfateh
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:36 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #authentication #api #bug_bounty
════════════════════════
𐀪 Author: 0x-elfateh
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:36 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #authentication #api #bug_bounty
Medium
Zero Credentials, Full Access: Inside a Complete Authorization Failure
Bounty Case Files #01 How multiple trust-boundary failures allowed anonymous access to premium functionality in a production API
⤷ Title: How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:31 GMT
════════════════════════
⌗ Tags: #technology #wordpress #bug_bounty #walkthrough #cybersecurity
════════════════════════
𐀪 Author: Shikhali Jamalzade
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:19:31 GMT
════════════════════════
⌗ Tags: #technology #wordpress #bug_bounty #walkthrough #cybersecurity
Medium
How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
Author: Shikhali Jamalzade GitHub: alisalive LinkedIn: camalzads Type: Independent Security Research | WordPress Plugin CVE Research
⤷ Title: SAR 2,629 For Stored XSS via svg Image Leading to ATO
════════════════════════
𐀪 Author: Anas NadY
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:18:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #penetration_testing #bug_bounty_writeup
════════════════════════
𐀪 Author: Anas NadY
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:18:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #penetration_testing #bug_bounty_writeup
Medium
SAR 2,629 For Stored XSS via svg Image Leading to ATO
REPORT BOUNTY
⤷ Title: Lab Walkthrough: Exploiting Username Enumeration via Different Responses
════════════════════════
𐀪 Author: 5um1t0x
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:09:47 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #burpsuite #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: 5um1t0x
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:09:47 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #burpsuite #penetration_testing #cybersecurity
Medium
Lab Walkthrough: Exploiting Username Enumeration via Different Responses
Introduction
⤷ Title: Finding Reflected XSS Parameters Fast: A Deep Dive into RefleX
════════════════════════
𐀪 Author: whoami_404
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:04:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #python
════════════════════════
𐀪 Author: whoami_404
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 07:04:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #python
Medium
Finding Reflected XSS Parameters Fast: A Deep Dive into RefleX
How a multi-threaded Python scanner turns manual parameter testing into an automated, context-aware workflow