⤷ Title: Task 2.3 -> Vulnerability Assessment (OpenVAS)
════════════════════════
𐀪 Author: Gunay Safarzadeh
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 12:34:09 GMT
════════════════════════
⌗ Tags: #vulnerability_management #cybersecurity #openvas #tryhackme
════════════════════════
𐀪 Author: Gunay Safarzadeh
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 12:34:09 GMT
════════════════════════
⌗ Tags: #vulnerability_management #cybersecurity #openvas #tryhackme
Medium
Task 2.3 -> Vulnerability Assessment (OpenVAS)
Giriş
⤷ Title: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 19:45:21 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 19:45:21 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Operation STANDOFF: Multi-Operator Intrusion Analysis
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:10:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BOTNET #infostealers #Multi_Operator Campaign #Operation STANDOFF #VMRay Labs
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:10:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BOTNET #infostealers #Multi_Operator Campaign #Operation STANDOFF #VMRay Labs
Information Security News
Operation STANDOFF: Multi-Operator Intrusion Analysis
Unveiling Operation STANDOFF A singular malicious installer served as the entry point into a vast criminal ecosystem that concurrently compromised endpoints, exfiltrated sensitive data, hijacked v…
⤷ Title: Apple Patches Critical Hide My Email Vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:15:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #data leak #Hide My Email #icloud #privacy vulnerability
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:15:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #data leak #Hide My Email #icloud #privacy vulnerability
Information Security News
Apple Patches Critical Hide My Email Vulnerability
A Persistent Privacy Breach A security feature engineered to safeguard authentic email credentials inadvertently disclosed them to external senders for over a year. Apple resolved a severe flaw wi…
⤷ Title: NadMesh Botnet Targets AI Services and Cloud Environments
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:30:58 +0000
════════════════════════
⌗ Tags: #Malware #AI infrastructure threat #cybersecurity #NadMesh botnet
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:30:58 +0000
════════════════════════
⌗ Tags: #Malware #AI infrastructure threat #cybersecurity #NadMesh botnet
Daily CyberSecurity
NadMesh Botnet Targets AI Services and Cloud Environments
The NadMesh botnet recently emerged as a significant danger to modern cloud networks. Researchers observed this Go-based malware operation spreading widely in early July 2026. Therefore, this AI i…
⤷ Title: CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:04:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_50454 #Elevation of Privilege #Local Privilege Escalation #proof_of_concept #UAC bypass #Windows 11 #Windows AppResolver LPE
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:04:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_50454 #Elevation of Privilege #Local Privilege Escalation #proof_of_concept #UAC bypass #Windows 11 #Windows AppResolver LPE
Daily CyberSecurity
CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM
TL;DR A researcher has published a write-up and proof-of-concept code for the Windows AppResolver LPE. The chain abuses a missing capability check in Windows.UI.Storage.dll to bypass UAC and reach…
⤷ Title: Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 13:15:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #control_plane traffic #CVE_2026_16242 #hosted control planes #Konnectivity vulnerability #Kubernetes Security #mitm #proxy server
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 13:15:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #control_plane traffic #CVE_2026_16242 #hosted control planes #Konnectivity vulnerability #Kubernetes Security #mitm #proxy server
Daily CyberSecurity
Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic
A critical Konnectivity vulnerability lets a remote attacker slip into a cluster without any credentials. Tracked as CVE-2026-16242, it carries a CVSS score of 9.4. The flaw sits in the Konnectivi…
⤷ Title: Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 13:03:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Cleartext Credentials #CVE_2026_55985 #CVE_2026_61884 #ICS #OT Security #TPDIN_Monitor_WEB2 #Tycon Systems #unpatched
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 13:03:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Cleartext Credentials #CVE_2026_55985 #CVE_2026_61884 #ICS #OT Security #TPDIN_Monitor_WEB2 #Tycon Systems #unpatched
Daily CyberSecurity
Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
TL;DR CISA published advisory ICSA-26-202-01 on July 21, 2026. It covers a critical Tycon authentication bypass in the TPDIN-Monitor-WEB2 power monitor. Tycon Systems never replied to CISA, so no …
⤷ Title: GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 12:43:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #backdoor #credential dumping #cyber_espionage #GoSerpent #kaspersky #Southeast Asia #Stowaway #TetrisPhantom #TmcLoader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 12:43:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #backdoor #credential dumping #cyber_espionage #GoSerpent #kaspersky #Southeast Asia #Stowaway #TetrisPhantom #TmcLoader
Daily CyberSecurity
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes a possible link to TetrisPhantom. Target /…
⤷ Title: How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.
════════════════════════
𐀪 Author: Vishw Bhatt
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:52:09 GMT
════════════════════════
⌗ Tags: #admin_panel #file_upload #bug_bounty
════════════════════════
𐀪 Author: Vishw Bhatt
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:52:09 GMT
════════════════════════
⌗ Tags: #admin_panel #file_upload #bug_bounty
Medium
How I Found a Bug Worth $3,500 — In a Feature Nobody Was Watching.
A storage-exhaustion flaw. A stored XSS that waited for an admin. Both hiding in the same “boring” file upload form that hadn’t been…
⤷ Title: Invitation Link doesn’t expire after used .
════════════════════════
𐀪 Author: David Demean
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:27:07 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #hackerone #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: David Demean
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:27:07 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #hackerone #cybersecurity #bug_bounty
Medium
Invitation Link doesn’t expire after used .
Hi Hackers , I’m David Demean .
I work as a penetration tester on HackerOne.
I work as a penetration tester on HackerOne.
⤷ Title: How I Found a Security Vulnerability in the CBSE Class 12 Result Portal and Reported It Responsibly
════════════════════════
𐀪 Author: Priyank Rastogi
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:54:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #cbse #cbse_12_result #cert_in #responsible_disclosure
════════════════════════
𐀪 Author: Priyank Rastogi
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:54:31 GMT
════════════════════════
⌗ Tags: #bug_bounty #cbse #cbse_12_result #cert_in #responsible_disclosure
Medium
How I Found a Security Vulnerability in the CBSE Class 12 Result Portal and Reported It Responsibly
A first-time security researcher’s journey from discovery to official CERT-In acknowledgement
⤷ Title: Empty Page Leaked a JWT — Privilege Escalation From the Lowest Role
════════════════════════
𐀪 Author: ali alhassoun
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:20:33 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: ali alhassoun
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:20:33 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
Empty Page Leaked a JWT — Privilege Escalation From the Lowest Role
The Context
⤷ Title: The Vulnerability Count in AI-Generated Code Just Tripled, Twice, in a Row
════════════════════════
𐀪 Author: Bhavyansh
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #application_security #vibe_coding #claude_code #ai_security #software_engineering
════════════════════════
𐀪 Author: Bhavyansh
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #application_security #vibe_coding #claude_code #ai_security #software_engineering
Medium
The Vulnerability Count in AI-Generated Code Just Tripled, Twice, in a Row
Georgia Tech tracked CVEs traceable to AI coding tools — 6, then 15, then 35 in three straight months.
⤷ Title: Anatomy of a Leak: From Breach to Breach Forum
════════════════════════
𐀪 Author: Yassin Hamada
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:36:25 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #data_breach #hacking #yassin_hamada
════════════════════════
𐀪 Author: Yassin Hamada
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:36:25 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #data_breach #hacking #yassin_hamada
Medium
Anatomy of a Leak: From Breach to Breach Forum
Part III — What actually happens to your data after the headline fades
⤷ Title: Billing THM write-up
════════════════════════
𐀪 Author: Creepus
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #writeup #tryhackme #hacking #solved #blog
════════════════════════
𐀪 Author: Creepus
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #writeup #tryhackme #hacking #solved #blog
Medium
Billing THM write-up
Introduction
⤷ Title: From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for…
════════════════════════
𐀪 Author: eL Njas!™
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
⌗ Tags: #vulnhunter #open_source #infosec #open_source_security #finance
════════════════════════
𐀪 Author: eL Njas!™
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
⌗ Tags: #vulnhunter #open_source #infosec #open_source_security #finance
Medium
From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for Finance and Cyber Defense.
Capital One Financial Corporation is one of the largest financial institutions in the United States, headquartered in McLean, Virginia…
⤷ Title: I got tired of spraying RCE payloads that never fire — so I built a tool that only sends the ones…
════════════════════════
𐀪 Author: ahmad kabiri
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:42:15 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #security #rce
════════════════════════
𐀪 Author: ahmad kabiri
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:42:15 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #security #rce
Medium
I got tired of spraying RCE payloads that never fire — so I built a tool that only sends the ones…
Sink-aware payload generation, and why “did it actually execute?” is the question most tools quietly ignore
⤷ Title: Best Ethical Hacking Training in Noida | Ducat India
════════════════════════
𐀪 Author: Gayatri
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:07:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking
════════════════════════
𐀪 Author: Gayatri
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 14:07:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking
Medium
Best Ethical Hacking Training in Noida | Ducat India
In today’s digital era, cybersecurity has become a paramount concern for individuals and
⤷ Title: Content Security Policy Explained ️
════════════════════════
𐀪 Author: Marcelo Domingues
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #csp #web_development #header #xs #security
════════════════════════
𐀪 Author: Marcelo Domingues
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #csp #web_development #header #xs #security
⤷ Title: “Owls Blog” | CyberTalents | Bypassing a Regex Filter to Exploit SQL Injection | Web Exploitation
════════════════════════
𐀪 Author: Dr_ro0t
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:34:50 GMT
════════════════════════
⌗ Tags: #sql_injection #ctf_writeup #web_exploitation #ctf
════════════════════════
𐀪 Author: Dr_ro0t
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:34:50 GMT
════════════════════════
⌗ Tags: #sql_injection #ctf_writeup #web_exploitation #ctf
Medium
“Owls Blog” | CyberTalents | Bypassing a Regex Filter to Exploit SQL Injection | Web Exploitation
Challenge description