⤷ Title: DoNot APT Targets Bangladesh Military With a Fake Officer Biography
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 06:13:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_35 #Bangladesh #cyber_espionage #DoNot #Remote Template Injection #RTF #South Asia #spear_phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 06:13:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT_C_35 #Bangladesh #cyber_espionage #DoNot #Remote Template Injection #RTF #South Asia #spear_phishing
Daily CyberSecurity
DoNot APT Targets Bangladesh Military With a Fake Officer Biography
At a glance Actor / group DoNot (APT-C-35); assessed by multiple vendors as India-aligned Activity type Targeted cyber-espionage via spear-phishing and RTF template injection Targets / victims Ban…
⤷ Title: System Prompt Extraction & AI Data Leakage
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:31:02 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #ai_security #dataleakage #llm
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:31:02 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty #ai_security #dataleakage #llm
Medium
System Prompt Extraction & AI Data Leakage
Hey friends! Nitin here 👋
⤷ Title: It Was Just a First Name… Until It Became a Trusted Phishing Vector.
════════════════════════
𐀪 Author: Abdelrahman Maged
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 10:23:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Abdelrahman Maged
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 10:23:21 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #ethical_hacking #cybersecurity
Medium
It Was Just a First Name… Until It Became a Trusted Phishing Vector.
“I wasn’t looking for an email vulnerability…”
⤷ Title: Breaking VulnBank: A complete web application penetration testing walkthrough
════════════════════════
𐀪 Author: Akwaeze Odera Gerald
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:14:24 GMT
════════════════════════
⌗ Tags: #secure_coding #cybersecurity #cloud_security #penetration_testing #application_security
════════════════════════
𐀪 Author: Akwaeze Odera Gerald
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:14:24 GMT
════════════════════════
⌗ Tags: #secure_coding #cybersecurity #cloud_security #penetration_testing #application_security
Medium
Breaking VulnBank: A complete web application penetration testing walkthrough
Introduction
⤷ Title: Your Car Is Spying on Itself. I Taught It to Confess.
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:47:52 GMT
════════════════════════
⌗ Tags: #programming #automotive #car_hacking #privacy #hacking
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:47:52 GMT
════════════════════════
⌗ Tags: #programming #automotive #car_hacking #privacy #hacking
Medium
Your Car Is Spying on Itself. I Taught It to Confess.
A field report from the war between automotive telemetry and the people who pay for the gas.
⤷ Title: Writeup for CyLab/picoCTF challenge “Bases”
════════════════════════
𐀪 Author: Walter Moar
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #ctf_writeup #cylab #cybersecurity #ctf #hacking
════════════════════════
𐀪 Author: Walter Moar
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #ctf_writeup #cylab #cybersecurity #ctf #hacking
Medium
Writeup for CyLab/picoCTF challenge “Bases”
Learn how CyLab’s “Bases” challenge introduces Base64 encoding, using the Linux echo and base64 commands to decode a Base64-encoded string.
⤷ Title: A SharePoint Flaw Turns One Request Into a Key That Outlives the Patch
════════════════════════
𐀪 Author: Tymoteusz `Shadyy` Netter
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:44:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #active_directory #incident_response #sharepoint #infosec
════════════════════════
𐀪 Author: Tymoteusz `Shadyy` Netter
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:44:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #active_directory #incident_response #sharepoint #infosec
Medium
A SharePoint Flaw Turns One Request Into a Key That Outlives the Patch
CVE-2026–50522 is a deserialization flaw that ends in code execution on an on-premises SharePoint server. That part a patch fixes. What it…
⤷ Title: Searchlight — IMINT — TryHackMe
════════════════════════
𐀪 Author: Subrat Keshari Sahu
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:11:59 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #cybersecurity #osint #searchlight_room
════════════════════════
𐀪 Author: Subrat Keshari Sahu
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:11:59 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #cybersecurity #osint #searchlight_room
Medium
Searchlight — IMINT — TryHackMe
Hello everyone. I have written this walkthrough to help you to complete this room.
⤷ Title: My First Real Look Inside Active Directory (And It Was Wide Open)
════════════════════════
𐀪 Author: Abdullah
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 10:12:05 GMT
════════════════════════
⌗ Tags: #linux #ads #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Abdullah
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 10:12:05 GMT
════════════════════════
⌗ Tags: #linux #ads #cybersecurity #tryhackme
Medium
My First Real Look Inside Active Directory (And It Was Wide Open)
I have been working through TryHackMe’s Jr Penetration Tester path, and I want to share one room that taught me a lot. It is called AD…
⤷ Title: Important Python Libraries for all Ethical Hackers and Cyber Security Professionals
════════════════════════
𐀪 Author: BnHany
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:28:07 GMT
════════════════════════
⌗ Tags: #ethical_hacking #python #programming #automation #cybersecurity
════════════════════════
𐀪 Author: BnHany
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:28:07 GMT
════════════════════════
⌗ Tags: #ethical_hacking #python #programming #automation #cybersecurity
Medium
Important Python Libraries for all Ethical Hackers and Cyber Security Professionals
Python is becoming the core programming language for cybersecurity. Whether you work as SOC analyst, pen tester, malware researcher…
⤷ Title: Getting Started with Docker for Application Security: Deploying OWASP crAPI
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:52:14 GMT
════════════════════════
⌗ Tags: #crapi_owasp #docker #application_security #api_security #appsec
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 11:52:14 GMT
════════════════════════
⌗ Tags: #crapi_owasp #docker #application_security #api_security #appsec
Medium
Getting Started with Docker for Application Security: Deploying OWASP crAPI
Learn how to deploy a deliberately vulnerable API using Docker and begin your API Security journey.
⤷ Title: Offlinea: A Bartender, a Headless Browser, and Five Locks
════════════════════════
𐀪 Author: Saria Mubeen
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 10:56:59 GMT
════════════════════════
⌗ Tags: #htb #challenge #ssrf
════════════════════════
𐀪 Author: Saria Mubeen
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 10:56:59 GMT
════════════════════════
⌗ Tags: #htb #challenge #ssrf
Medium
Offlinea: A Bartender, a Headless Browser, and Five Locks
Platform: HackTheBox (web) | Completed: 2026–07–23 Flag: HTB{[redacted]} Difficulty: Hard | Chain: HTTP Parameter Pollution -> SSRF ->…
⤷ Title: How Synthetic Identity Fraud is Coming for Machine Identities
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 17:15:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 17:15:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 16:58:54 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 16:58:54 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 15:30:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 15:30:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Mobile AI Assistant Vulnerabilities Expose Security Flaws
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:11:01 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Assistant #arbitrary code execution #Machine Vision Exploit #mobile security #Smartphone Vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:11:01 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Assistant #arbitrary code execution #Machine Vision Exploit #mobile security #Smartphone Vulnerability
Information Security News
Mobile AI Assistant Vulnerabilities Expose Security Flaws
The Emergence of a New Attack Vector Mobile artificial intelligence assistants, designed to operate smartphones autonomously, represent a novel tool for cyberattacks. Specialists have demonstrated…
⤷ Title: KARR Alarm Vulnerability Exposes 2 Million Cars
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 12:18:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Acrisure #Aftermarket Devices #Automotive Security #Bluetooth #Car Hacking #KARR Security System #UC San Diego
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 12:18:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #Acrisure #Aftermarket Devices #Automotive Security #Bluetooth #Car Hacking #KARR Security System #UC San Diego
Information Security News
KARR Alarm Vulnerability Exposes 2 Million Cars
Millions of vehicles across the United States carry a concealed device meant to guard them against theft. Instead, that device has allowed strangers to open doors, silence alarms, and immobilise e…
⤷ Title: CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:30:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_57239 #DLL Sideloading #Foxit PDF reader #Local Privilege Escalation #proof_of_concept #SYSTEM privileges
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:30:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_57239 #DLL Sideloading #Foxit PDF reader #Local Privilege Escalation #proof_of_concept #SYSTEM privileges
Daily CyberSecurity
CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
TL;DR A security researcher has published full details and proof-of-concept code for a Foxit PDF Reader vulnerability. Tracked as CVE-2026-57239, the flaw lets a local, unprivileged user gain NT A…
⤷ Title: Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:05:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_64642 #CVE_2026_64645 #CVE_2026_64649 #Next.js #Next.js vulnerabilities #Server_Side Request Forgery #Vercel
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:05:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_64642 #CVE_2026_64645 #CVE_2026_64649 #Next.js #Next.js vulnerabilities #Server_Side Request Forgery #Vercel
Daily CyberSecurity
Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware
TL;DR Vercel fixed three Next.js vulnerabilities, each rated CVSS 8.3. Two of them allow Server-Side Request Forgery, while the third lets crafted requests slip past middleware-based authenticatio…
⤷ Title: Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 12:58:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Infrastructure #CERT/CC #CVE_2026_14890 #CVE_2026_7301 #CVE_2026_7304 #LLM Security #Pickle Deserialization #Remote Code Execution #SGLang #unpatched #ZeroMQ
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 12:58:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Infrastructure #CERT/CC #CVE_2026_14890 #CVE_2026_7301 #CVE_2026_7304 #LLM Security #Pickle Deserialization #Remote Code Execution #SGLang #unpatched #ZeroMQ
Daily CyberSecurity
Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution
TL;DR CERT/CC published vulnerability note VU#326070 on July 16, 2026. It details an SGLang vulnerability, CVE-2026-14890, rated CVSS 9.1. An unauthenticated attacker can run code on the host, and…
⤷ Title: Python Web Penetration Testing — Day 5: Password Testing
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:49:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #technology #programming #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 13:49:27 GMT
════════════════════════
⌗ Tags: #bug_bounty #technology #programming #cybersecurity #penetration_testing
Medium
Python Web Penetration Testing — Day 5: Password Testing
Cracking Authentication Like a Pro