⤷ Title: Binary to Behavior: Decode Threats with the Unified “Malware-Check” Analysis Engine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 07:26:41 +0000
════════════════════════
⌗ Tags: #Open Source Tool #binary analyzer #cybersecurity tools #DevSecOps #Docker sandbox #dynamic analysis #malware analysis #malware_check #MobSF #reverse engineering #SARIF #Static Analysis #YARA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 07:26:41 +0000
════════════════════════
⌗ Tags: #Open Source Tool #binary analyzer #cybersecurity tools #DevSecOps #Docker sandbox #dynamic analysis #malware analysis #malware_check #MobSF #reverse engineering #SARIF #Static Analysis #YARA
Penetration Testing Tools
Binary to Behavior: Decode Threats with the Unified "Malware-Check" Analysis Engine
Detect backdoors, ransomware, and privacy leaks. Malware-Check combines YARA rules, Docker sandboxing, and MobSF for deep static and dynamic analysis.
⤷ Title: How to Build a World-Class SAST Program from Scratch
════════════════════════
𐀪 Author: Vikrant Waghmode
════════════════════════
ⴵ Time: Wed, 06 May 2026 21:44:00 GMT
════════════════════════
⌗ Tags: #semgrep #application_security #cybersecurity #static_code_analysis
════════════════════════
𐀪 Author: Vikrant Waghmode
════════════════════════
ⴵ Time: Wed, 06 May 2026 21:44:00 GMT
════════════════════════
⌗ Tags: #semgrep #application_security #cybersecurity #static_code_analysis
Medium
How to Build a World-Class SAST Program from Scratch
A practitioner’s guide to transforming static analysis security testing — from creating the vision to selecting the right tools through…
⤷ Title: From Deep Link to Shell: Easy $3000 Android Crits.
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 23:19:13 GMT
════════════════════════
⌗ Tags: #android #hackerone #static_code_analysis #rce #deeplink
════════════════════════
𐀪 Author: tinopreter
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 23:19:13 GMT
════════════════════════
⌗ Tags: #android #hackerone #static_code_analysis #rce #deeplink
Medium
From Deep Link to Shell: Easy $3000 Android Crits.
Akwaaba! gang, another part of my Static Android App Hacking series, today our focus is on exploiting Deep Links to achieve RCE. An easy…
⤷ Title: Cloudflare Launches Drop for Temporary and Permanent Static Site Hosting
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 03:17:10 +0000
════════════════════════
⌗ Tags: #Technology #cloudflare #Cloudflare Drop #Static Website #Web Hosting
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 03:17:10 +0000
════════════════════════
⌗ Tags: #Technology #cloudflare #Cloudflare Drop #Static Website #Web Hosting
Daily CyberSecurity
Cloudflare Launches Drop for Temporary and Permanent Static Site Hosting
Network service provider Cloudflare recently introduced an innovative feature named Drop. This capability allows users to host purely static websites effortlessly. According to its core design log…
⤷ Title: Intro to Malware…… | THM Walkthrough | by Dharavath Nagaraju
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:40:16 GMT
════════════════════════
⌗ Tags: #sandboxing #static_and_dynamic #malware_analysis #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:40:16 GMT
════════════════════════
⌗ Tags: #sandboxing #static_and_dynamic #malware_analysis #cybersecurity #tryhackme
Medium
Intro to Malware…… | THM Walkthrough | by Dharavath Nagaraju
This room introduces the fundamentals of malware analysis and the techniques used to safely investigate malicious software. It covers the…
⤷ Title: CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
Daily CyberSecurity
CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
TL;DR A flaw in WordPress Coding Standards lets malicious PHP run code on the machine that lints it. Tracked as CVE-2026-45293, the bug carries a CVSS score of 8.6. The advisory calls it “an…
⤷ Title: Cisco FMC Flaw CVE-2026-20316 Exploited in the Wild
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 21:43:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Actively Exploited #Cisco FMC #Cisco Secure Firewall #CVE_2026_20316 #Known Exploited Vulnerability #Static Credentials
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 21:43:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Actively Exploited #Cisco FMC #Cisco Secure Firewall #CVE_2026_20316 #Known Exploited Vulnerability #Static Credentials
Daily CyberSecurity
Cisco FMC Flaw CVE-2026-20316 Exploited in the Wild
TL;DR Cisco is warning about a Cisco FMC vulnerability under active attack. Tracked as CVE-2026-20316, it lets a remote attacker log in using a hidden static account. Cisco confirms exploitation, …
⤷ Title: Day 26: Cross-Site Scripting (XSS) - Hacker Sidekick Certified Vibe Hacker CTF Walkthrough
════════════════════════
𐀪 Author: Sofia Batala
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 04:08:16 GMT
════════════════════════
⌗ Tags: #xss_attack #xss_vulnerability #hacker_sidekick #static_code_analysis #ctf
════════════════════════
𐀪 Author: Sofia Batala
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 04:08:16 GMT
════════════════════════
⌗ Tags: #xss_attack #xss_vulnerability #hacker_sidekick #static_code_analysis #ctf
Medium
Day 26: Cross-Site Scripting (XSS) - Hacker Sidekick Certified Vibe Hacker CTF Walkthrough
## Challenge: User-provided data is rendered in HTML templates without proper encoding, allowing JavaScript injection attacks. What…
⤷ Title: Build Self-Hosted SAST with pipeline DefectDojo
════════════════════════
𐀪 Author: Rizqi Ramadhan Andriono
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 13:41:47 GMT
════════════════════════
⌗ Tags: #defectdojo #static_code_analysis #security #penetration_testing #sonarqube
════════════════════════
𐀪 Author: Rizqi Ramadhan Andriono
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 13:41:47 GMT
════════════════════════
⌗ Tags: #defectdojo #static_code_analysis #security #penetration_testing #sonarqube
Medium
Build Self-Hosted SAST with pipeline DefectDojo
Static application security testing with DefectDojo as main dashboard using open source tools; SonarQube Community version, , OSV, Semgrep…
⤷ Title: Part II: Analytic Tools
════════════════════════
𐀪 Author: EW
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 14:07:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #software_development #static_analysis #application_security
════════════════════════
𐀪 Author: EW
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 14:07:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #devsecops #software_development #static_analysis #application_security
Medium
Part II: Analytic Tools
Static vs. Dynamic Analysis: Two Essential Lenses for Secure Software
⤷ Title: Free models + open-source SAST + offensive Skills matched frontier CVE finds. Cost: about $0.
════════════════════════
𐀪 Author: MixBanana
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 11:19:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #open_source #static_analysis #application_security #artificial_intelligence
════════════════════════
𐀪 Author: MixBanana
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 11:19:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #open_source #static_analysis #application_security #artificial_intelligence
Medium
Free models + open-source SAST + offensive Skills matched frontier CVE finds. Cost: about $0.
Subtitle: Everyone argued about Sol and Mythos. I wired tools and Skills into cheap models and got the same class of bugs on public code.
⤷ Title: We Built the Only Java Static Analyzer That Finds What Semgrep, CodeQL, and the We Built the Only…
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 16:17:56 GMT
════════════════════════
⌗ Tags: #java #cybersecurity #application_security #static_analysis #spring_boot
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 16:17:56 GMT
════════════════════════
⌗ Tags: #java #cybersecurity #application_security #static_analysis #spring_boot
Medium
We Built the Only Java Static Analyzer That Finds What Semgrep, CodeQL, and the We Built the Only Java Static Analyzer That Finds…
The problem nobody talks aboutICLR 2025 IRIS Paper All Miss
⤷ Title: We Found Authorization Vulnerabilities in Two of GitHub’s Most-Starred Java Repositories — Semgrep…
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #spring_boot #application_security #java #static_analysis
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #spring_boot #application_security #java #static_analysis
Medium
We Found Authorization Vulnerabilities in Two of GitHub’s Most-Starred Java Repositories — Semgrep and CodeQL Both Missed Them
110,000 combined stars. Zero authorization findings from the industry-standard scanners. Here’s what a purpose-built tool found instead.