⤷ Title: Your AI Agent Can Contain a Breach in 90 Seconds. It Can Also Become One
════════════════════════
𐀪 Author: satyam kumar
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:26:34 GMT
════════════════════════
⌗ Tags: #security_operations #artificial_intelligence #ai_agent #cybersecurity #infosec
════════════════════════
𐀪 Author: satyam kumar
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:26:34 GMT
════════════════════════
⌗ Tags: #security_operations #artificial_intelligence #ai_agent #cybersecurity #infosec
Medium
Your AI Agent Can Contain a Breach in 90 Seconds. It Can Also Become One
The agentic SOC is real. The architecture that makes it safe is bounding authority — not raising intelligence.
⤷ Title: AD Credentials Harvesting & DCSync Attack — (Full Write-up)
════════════════════════
𐀪 Author: NASRALLAH SALEH (Xiro0x)
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:01:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #azure_active_directory #windows #tryhackme #pentesting
════════════════════════
𐀪 Author: NASRALLAH SALEH (Xiro0x)
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:01:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #azure_active_directory #windows #tryhackme #pentesting
Medium
AD Credentials Harvesting & DCSync Attack — (Full Write-up)
Conceptual Overview & Kill Chain
⤷ Title: SQLi UNION attack,finding a column containing text
════════════════════════
𐀪 Author: @i.ogore
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:09:12 GMT
════════════════════════
⌗ Tags: #sql_injection #burpsuite #portswigger #cybersecurity
════════════════════════
𐀪 Author: @i.ogore
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 06:09:12 GMT
════════════════════════
⌗ Tags: #sql_injection #burpsuite #portswigger #cybersecurity
Medium
SQLi UNION attack,finding a column containing text
I spent my afternoon poking at PortSwigger’s Web Security Academy again, and this one’s a fun little logic puzzle. The lab is called “SQL…
⤷ Title: New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:40:56 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:40:56 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:37:11 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 14:37:11 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:08:43 +0000
════════════════════════
⌗ Tags: #Malware #calendar C2 #Cavern framework #cyber_espionage #DNS tunneling #HOLLOWGRAPH malware #Lyceum #Microsoft 365 Security #Microsoft Graph API abuse
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:08:43 +0000
════════════════════════
⌗ Tags: #Malware #calendar C2 #Cavern framework #cyber_espionage #DNS tunneling #HOLLOWGRAPH malware #Lyceum #Microsoft 365 Security #Microsoft Graph API abuse
Daily CyberSecurity
HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
At a glance Malware family HOLLOWGRAPH, linked with high confidence to the Cavern backdoor framework Threat actor Unattributed. Low-confidence possible link to Lyceum, an Iranian-nexus group and O…
⤷ Title: CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:00:24 +0000
════════════════════════
⌗ Tags: #Malware #CrashStealer #Cryptocurrency Wallet #Infostealer #Jamf Threat Labs #macOS Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:00:24 +0000
════════════════════════
⌗ Tags: #Malware #CrashStealer #Cryptocurrency Wallet #Infostealer #Jamf Threat Labs #macOS Malware
Daily CyberSecurity
CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
At a Glance Field Detail Malware family CrashStealer (native C++ macOS infostealer) Threat actor Unattributed; part of a larger multi-platform operation Targets macOS users, especially cryptocurre…
⤷ Title: How a Single UUID Change Led to an IDOR Vulnerability
════════════════════════
𐀪 Author: Prachi_Tyagi
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:34:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #idor #ethical_hacking #vulnerability
════════════════════════
𐀪 Author: Prachi_Tyagi
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:34:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #idor #ethical_hacking #vulnerability
Medium
How a Single UUID Change Led to an IDOR Vulnerability
During one of my recent penetration testing engagements, I discovered an IDOR vulnerability with a surprisingly simple test — replacing a…
⤷ Title: # From “users” to “admin”: How a Simple Response Copy-Paste Led to Privilege Escalation
════════════════════════
𐀪 Author: Pankaj Kumar Yadav
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:33:52 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #software_development #cyber_security_awareness #bug_bounty #infosec
════════════════════════
𐀪 Author: Pankaj Kumar Yadav
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:33:52 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #software_development #cyber_security_awareness #bug_bounty #infosec
Medium
# From “users” to “admin”: How a Simple Response Copy-Paste Led to Privilege Escalation
While updating my profile as a normal user, the API response included a `role` field set to `”users”`. I copied that exact value into the…
⤷ Title: Why Machine Learning Belongs in the Future of Web Application Security
════════════════════════
𐀪 Author: Gladioswaf
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:47:07 GMT
════════════════════════
⌗ Tags: #web_security #application_security #cybersecurity #machine_learning #api_security
════════════════════════
𐀪 Author: Gladioswaf
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:47:07 GMT
════════════════════════
⌗ Tags: #web_security #application_security #cybersecurity #machine_learning #api_security
Medium
Why Machine Learning Belongs in the Future of Web Application Security
Most WAF failures are not missed detections. They are requests the WAF never fully read, or parsed differently from your application — and…
⤷ Title: Can Public Wi-Fi Really Hack Your Phone? 11 Risks You Must Know (2026 Guide)
════════════════════════
𐀪 Author: Qnaydshackersacadamy
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:53:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #hacking
════════════════════════
𐀪 Author: Qnaydshackersacadamy
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:53:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #hacking
Medium
Can Public Wi-Fi Really Hack Your Phone? 11 Risks You Must Know (2026 Guide)
Wondering if that airport or café Wi-Fi is safe? Learn how public Wi-Fi attacks actually work, the real risks, and how to protect your…
⤷ Title: A White Screen Led Me to a Much Bigger WordPress Problem
════════════════════════
𐀪 Author: Ashish Dwivedi
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:53:24 GMT
════════════════════════
⌗ Tags: #security #hacking #freelancing #wordpress #software_development
════════════════════════
𐀪 Author: Ashish Dwivedi
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 07:53:24 GMT
════════════════════════
⌗ Tags: #security #hacking #freelancing #wordpress #software_development
Medium
The Website Was Back Online. But Was the Attacker Still Inside?
What started as a WordPress debugging issue turned into a full security investigation and raised a harder question:
⤷ Title: Rooting DC-3: A Single Port, a Joomla SQL Injection, and a Kernel Exploit
════════════════════════
𐀪 Author: Sithum Ranasinghe
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:38:00 GMT
════════════════════════
⌗ Tags: #ctf #vulnhub #penetration_testing
════════════════════════
𐀪 Author: Sithum Ranasinghe
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:38:00 GMT
════════════════════════
⌗ Tags: #ctf #vulnhub #penetration_testing
Medium
Rooting DC-3: A Single Port, a Joomla SQL Injection, and a Kernel Exploit
The third box in VulnHub’s DC series strips things down to one open port, forcing a full attack chain out of a single vulnerable web…
⤷ Title: Guided Pentest: Web “THM Room”
════════════════════════
𐀪 Author: Mohamed Elkashory
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:01:50 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #web_security
════════════════════════
𐀪 Author: Mohamed Elkashory
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:01:50 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #web_security
Medium
Guided Pentest: Web “THM Room”
Learn web app pentesting by chaining vulnerabilities from recon to full server compromise.
⤷ Title: Jangow: 1.0.1 VulnHub Walkthrough | From Reconnaissance to Root
════════════════════════
𐀪 Author: Rayixcy
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:39:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #ctf #vulnhub_walkthrough #penetration_testing
════════════════════════
𐀪 Author: Rayixcy
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:39:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #ctf #vulnhub_walkthrough #penetration_testing
Medium
Jangow: 1.0.1 VulnHub Walkthrough | From Reconnaissance to Root
Introduction
⤷ Title: No simulator wins: benchmarking the state of AI Pentesting (the finding as headline)
════════════════════════
𐀪 Author: Rui Fernandes
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:01:04 GMT
════════════════════════
⌗ Tags: #offensive_security #artificial_intelligence #cybersecurity #reinforcement_learning #penetration_testing
════════════════════════
𐀪 Author: Rui Fernandes
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:01:04 GMT
════════════════════════
⌗ Tags: #offensive_security #artificial_intelligence #cybersecurity #reinforcement_learning #penetration_testing
Medium
No simulator wins: benchmarking the state of AI Pentesting (the finding as headline)
Reinforcement Learning agents are getting scary good at hacking, at least on paper. Drop one into a simulated network, and it’ll learn, all…
⤷ Title: Registry Rogue Hunting: A Playbook Walkthrough of Windows Persistence Forensics
════════════════════════
𐀪 Author: Pop123
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:33:44 GMT
════════════════════════
⌗ Tags: #persistence #tryhackme #cybersecurity #tutorial #windows
════════════════════════
𐀪 Author: Pop123
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:33:44 GMT
════════════════════════
⌗ Tags: #persistence #tryhackme #cybersecurity #tutorial #windows
Medium
Registry Rogue Hunting: A Playbook Walkthrough of Windows Persistence Forensics
Endpoint Forensics: Rooting Out Malicious Run Keys, Service Hijacks, and Scheduled Tasks in Active Directory Workstations
⤷ Title: Startup — TryHackMe WriteUp with Flags
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:31:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #tryhackme #tryhackme_writeup #ctf #tryhackme_walkthrough
════════════════════════
𐀪 Author: Rayenhafsawy
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:31:06 GMT
════════════════════════
⌗ Tags: #ctf_writeup #tryhackme #tryhackme_writeup #ctf #tryhackme_walkthrough
Medium
Startup — TryHackMe WriteUp with Flags
Startup — TryHackMe WriteUp with Flags Date: 31/01/2026 Room Link: https://tryhackme.com/room/startup My Profile: https://tryhackme.com/p/RayenHafsawy 🧭 Introduction This lab chains anonymous …
⤷ Title: How I Made My First Dollar in Cybersecurity (2026 Guide)
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:42:30 GMT
════════════════════════
⌗ Tags: #ethical_hacking #technology #cybersecurity #side_hustle #career_advice
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:42:30 GMT
════════════════════════
⌗ Tags: #ethical_hacking #technology #cybersecurity #side_hustle #career_advice
Medium
How I Made My First Dollar in Cybersecurity (2026 Guide)
I made my first real money in cybersecurity long before I had a job title.
⤷ Title: Build a Free AI-Powered Automated Cybersecurity Workspace on Kali Linux
════════════════════════
𐀪 Author: Punih3r7
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:22:41 GMT
════════════════════════
⌗ Tags: #open_source #hexstrike_ai #cybersecurity_ai_tools #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Punih3r7
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 09:22:41 GMT
════════════════════════
⌗ Tags: #open_source #hexstrike_ai #cybersecurity_ai_tools #ethical_hacking #cybersecurity
Medium
Build a Free AI-Powered Automated Cybersecurity Workspace on Kali Linux
Build an AI-powered penetration testing assistant using HexStrike AI, Roo Code, and OpenRouter — without paying for multiple AI…
⤷ Title: The Day the Network Started Talking to the Wrong Computer
════════════════════════
𐀪 Author: Alvanoshjojo
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:52:27 GMT
════════════════════════
⌗ Tags: #network_sniffing #ethical_hacking #arp_poisoning #arp_spoofing #networking
════════════════════════
𐀪 Author: Alvanoshjojo
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 08:52:27 GMT
════════════════════════
⌗ Tags: #network_sniffing #ethical_hacking #arp_poisoning #arp_spoofing #networking
Medium
The Day the Network Started Talking to the Wrong Computer
Understanding Network Sniffing Through the Story of ARP Poisoning