⤷ Title: AI Model Hidden Backdoor Vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:39:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Backdoor #machine learning #Supply Chain
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:39:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Backdoor #machine learning #Supply Chain
Information Security News
AI Model Hidden Backdoor Vulnerability
Changing AI behavior is much easier and cheaper than many people thought. Cyber expert Katie Paxton-Fear put a hidden flaw into an open AI model. Amazingly, she finished this task in just about on…
⤷ Title: World Leaks Exposes Kudankulam Nuclear Plant Files in a Breach of India’s Reliance Group
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:15:58 +0000
════════════════════════
⌗ Tags: #Data Leak #data breach #Kudankulam #Nuclear Security #Reliance Group #World Leaks
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:15:58 +0000
════════════════════════
⌗ Tags: #Data Leak #data breach #Kudankulam #Nuclear Security #Reliance Group #World Leaks
Information Security News
World Leaks Exposes Kudankulam Nuclear Plant Files in a Breach of India’s Reliance Group
A major leak has struck documents tied to the construction of India’s largest nuclear power plant. Alleged engineering-system blueprints, supplier details, inspection reports, and insurance …
⤷ Title: Millions of Shark Robot Vacuums Exposed to Remote Code Execution via a SharkNinja Cloud Flaw
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:39:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #IoT Security #RCE #Robot Vacuum #Shark #SharkNinja
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:39:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #IoT Security #RCE #Robot Vacuum #Shark #SharkNinja
Information Security News
Millions of Shark Robot Vacuums Exposed to Remote Code Execution via a SharkNinja Cloud Flaw
Robot vacuums have long roamed our homes unattended. Yet on certain Shark models, the cleaning came bundled with an unnoticed doorway for strangers. A security researcher uncovered a critical vuln…
⤷ Title: Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:30:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT36 #ControlR #India #Operation ShadowRecruit #SheetAgent
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:30:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT36 #ControlR #India #Operation ShadowRecruit #SheetAgent
Daily CyberSecurity
Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems
Operation ShadowRecruit targets Indian job seekers with SheetAgent RAT, abusing ControlR and Google Sheets for C2. Seqrite links it to APT36. #OperationShadowRecruit #APT36 #SheetAgent #Malware #I…
⤷ Title: LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:11:45 +0000
════════════════════════
⌗ Tags: #Malware #Blackpoint Cyber #DNS tunneling #LabubaRAT #rat #Rust malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:11:45 +0000
════════════════════════
⌗ Tags: #Malware #Blackpoint Cyber #DNS tunneling #LabubaRAT #rat #Rust malware
Daily CyberSecurity
LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts
At a Glance Malware family LabubaRAT (previously undocumented) Threat actor Unattributed; no group named Targets Windows hosts; no victim count published Delivery vector Not documented in the repo…
⤷ Title: From Ping to Pwn: What I Learned Breaking DVWA, Juice Shop, and Two Vulnerable APIs
════════════════════════
𐀪 Author: Mubbashir Khan Israil Khan Pathan
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:24:53 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #penetration_testing #cybersecurity #web_security
════════════════════════
𐀪 Author: Mubbashir Khan Israil Khan Pathan
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:24:53 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #penetration_testing #cybersecurity #web_security
Medium
From Ping to Pwn: What I Learned Breaking DVWA, Juice Shop, and Two Vulnerable APIs
A few weeks ago I set out to do something more useful than watching another course on OWASP Top 10 — I wanted to actually break things…
⤷ Title: HwatNetOps: From Portal to User Flag — A Web CTF Walkthrough
════════════════════════
𐀪 Author: Ranaabdullahsaif
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:34:23 GMT
════════════════════════
⌗ Tags: #hacking #ctf_writeup #ctf #red_teaming
════════════════════════
𐀪 Author: Ranaabdullahsaif
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:34:23 GMT
════════════════════════
⌗ Tags: #hacking #ctf_writeup #ctf #red_teaming
Medium
HwatNetOps: From Portal to User Flag — A Web CTF Walkthrough
Introduction
⤷ Title: Sunset: 1 Walkthrough -Vulnhub
════════════════════════
𐀪 Author: ABHAY BRAHMA MANOJKUMAR
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:12:01 GMT
════════════════════════
⌗ Tags: #hacking #red_team #pentesting #ctf_walkthrough #cybersecurity
════════════════════════
𐀪 Author: ABHAY BRAHMA MANOJKUMAR
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:12:01 GMT
════════════════════════
⌗ Tags: #hacking #red_team #pentesting #ctf_walkthrough #cybersecurity
Medium
Sunset: 1 Walkthrough -Vulnhub
“Sunset” created by the skilled author “Whitecr0wz,” is a beginner-level Capture The Flag machine. The main objective is to discover the…
⤷ Title: Why AI Is Making Hackers Faster Than Ever
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:04:49 GMT
════════════════════════
⌗ Tags: #hacking #artificial_intelligence #cybersecurity #technology #ai
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:04:49 GMT
════════════════════════
⌗ Tags: #hacking #artificial_intelligence #cybersecurity #technology #ai
Medium
Why AI Is Making Hackers Faster Than Ever
The threat landscape has fundamentally shifted. What once took a skilled attacker days or weeks now takes minutes — and every organization…
⤷ Title: Data Exfiltration method
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:12:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_development #infosec #cyber_security_awareness
════════════════════════
𐀪 Author: ExploitHunter
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:12:25 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_development #infosec #cyber_security_awareness
Medium
Data Exfiltration method
Introduction
⤷ Title: ETI Helps in Protection Against Cyber Attacks!
════════════════════════
𐀪 Author: Eman Khalid
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:56:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #etis #threat_intelligence #eunomatix #infosec
════════════════════════
𐀪 Author: Eman Khalid
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:56:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #etis #threat_intelligence #eunomatix #infosec
Medium
ETI Helps in Protection Against Cyber Attacks!
Most cyber attacks targeting employees do not arrive through technical exploits. They arrive through links. A phishing email. A malicious…
⤷ Title: Your AI Agent Can Contain a Breach in 90 Seconds. It Can Also Become One
════════════════════════
𐀪 Author: satyam kumar
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:26:34 GMT
════════════════════════
⌗ Tags: #security_operations #artificial_intelligence #ai_agent #cybersecurity #infosec
════════════════════════
𐀪 Author: satyam kumar
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:26:34 GMT
════════════════════════
⌗ Tags: #security_operations #artificial_intelligence #ai_agent #cybersecurity #infosec
Medium
Your AI Agent Can Contain a Breach in 90 Seconds. It Can Also Become One
The agentic SOC is real. The architecture that makes it safe is bounding authority — not raising intelligence.
⤷ Title: AD Credentials Harvesting & DCSync Attack — (Full Write-up)
════════════════════════
𐀪 Author: NASRALLAH SALEH (Xiro0x)
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:01:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #azure_active_directory #windows #tryhackme #pentesting
════════════════════════
𐀪 Author: NASRALLAH SALEH (Xiro0x)
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:01:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #azure_active_directory #windows #tryhackme #pentesting
Medium
AD Credentials Harvesting & DCSync Attack — (Full Write-up)
Conceptual Overview & Kill Chain
⤷ Title: SQLi UNION attack,finding a column containing text
════════════════════════
𐀪 Author: @i.ogore
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:09:12 GMT
════════════════════════
⌗ Tags: #sql_injection #burpsuite #portswigger #cybersecurity
════════════════════════
𐀪 Author: @i.ogore
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:09:12 GMT
════════════════════════
⌗ Tags: #sql_injection #burpsuite #portswigger #cybersecurity
Medium
SQLi UNION attack,finding a column containing text
I spent my afternoon poking at PortSwigger’s Web Security Academy again, and this one’s a fun little logic puzzle. The lab is called “SQL…
⤷ Title: New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:40:56 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:40:56 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:37:11 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:37:11 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:08:43 +0000
════════════════════════
⌗ Tags: #Malware #calendar C2 #Cavern framework #cyber_espionage #DNS tunneling #HOLLOWGRAPH malware #Lyceum #Microsoft 365 Security #Microsoft Graph API abuse
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:08:43 +0000
════════════════════════
⌗ Tags: #Malware #calendar C2 #Cavern framework #cyber_espionage #DNS tunneling #HOLLOWGRAPH malware #Lyceum #Microsoft 365 Security #Microsoft Graph API abuse
Daily CyberSecurity
HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
At a glance Malware family HOLLOWGRAPH, linked with high confidence to the Cavern backdoor framework Threat actor Unattributed. Low-confidence possible link to Lyceum, an Iranian-nexus group and O…
⤷ Title: CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:00:24 +0000
════════════════════════
⌗ Tags: #Malware #CrashStealer #Cryptocurrency Wallet #Infostealer #Jamf Threat Labs #macOS Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:00:24 +0000
════════════════════════
⌗ Tags: #Malware #CrashStealer #Cryptocurrency Wallet #Infostealer #Jamf Threat Labs #macOS Malware
Daily CyberSecurity
CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
At a Glance Field Detail Malware family CrashStealer (native C++ macOS infostealer) Threat actor Unattributed; part of a larger multi-platform operation Targets macOS users, especially cryptocurre…
⤷ Title: How a Single UUID Change Led to an IDOR Vulnerability
════════════════════════
𐀪 Author: Prachi_Tyagi
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:34:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #idor #ethical_hacking #vulnerability
════════════════════════
𐀪 Author: Prachi_Tyagi
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:34:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #idor #ethical_hacking #vulnerability
Medium
How a Single UUID Change Led to an IDOR Vulnerability
During one of my recent penetration testing engagements, I discovered an IDOR vulnerability with a surprisingly simple test — replacing a…
⤷ Title: # From “users” to “admin”: How a Simple Response Copy-Paste Led to Privilege Escalation
════════════════════════
𐀪 Author: Pankaj Kumar Yadav
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:33:52 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #software_development #cyber_security_awareness #bug_bounty #infosec
════════════════════════
𐀪 Author: Pankaj Kumar Yadav
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:33:52 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #software_development #cyber_security_awareness #bug_bounty #infosec
Medium
# From “users” to “admin”: How a Simple Response Copy-Paste Led to Privilege Escalation
While updating my profile as a normal user, the API response included a `role` field set to `”users”`. I copied that exact value into the…
⤷ Title: Why Machine Learning Belongs in the Future of Web Application Security
════════════════════════
𐀪 Author: Gladioswaf
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:47:07 GMT
════════════════════════
⌗ Tags: #web_security #application_security #cybersecurity #machine_learning #api_security
════════════════════════
𐀪 Author: Gladioswaf
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:47:07 GMT
════════════════════════
⌗ Tags: #web_security #application_security #cybersecurity #machine_learning #api_security
Medium
Why Machine Learning Belongs in the Future of Web Application Security
Most WAF failures are not missed detections. They are requests the WAF never fully read, or parsed differently from your application — and…