⤷ Title: Living Off the HTA Land: How Hackers Weaponize a 1999 Windows Utility for Silent Malware Delivery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:04:27 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Info Harvester #ClickFix Social Engineering LummaStealer #ClipBanker Crypto Stealer #CountLoader Staging Framework #Emmenhtal Loader #HTML Application HTA Payload #Living off the Land Binaries #MSHTA Weaponization Malware Delivery #mshta.exe Windows Binary #PurpleFox Rootkit Lineage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:04:27 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Info Harvester #ClickFix Social Engineering LummaStealer #ClipBanker Crypto Stealer #CountLoader Staging Framework #Emmenhtal Loader #HTML Application HTA Payload #Living off the Land Binaries #MSHTA Weaponization Malware Delivery #mshta.exe Windows Binary #PurpleFox Rootkit Lineage
Penetration Testing Tools
Living Off the HTA Land: How Hackers Weaponize a 1999 Windows Utility for Silent Malware Delivery
Threat actors are increasingly weaponizing MSHTA, a legacy Windows utility, as a highly efficient conduit to execute malicious
⤷ Title: HTML Injection in Outbound Emails: An Overlooked Security Risk
════════════════════════
𐀪 Author: vibhuti bhatt
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 12:26:37 GMT
════════════════════════
⌗ Tags: #html_injection #vulnerability #application_security #pentesting #injection_in_email
════════════════════════
𐀪 Author: vibhuti bhatt
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 12:26:37 GMT
════════════════════════
⌗ Tags: #html_injection #vulnerability #application_security #pentesting #injection_in_email
Medium
HTML Injection in Outbound Emails: An Overlooked Security Risk
Introduction
⤷ Title: Telegram Bots Receive Rich HTML and Markdown Formatting Options
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 08:44:45 +0000
════════════════════════
⌗ Tags: #Technology #bot development #HTML formatting #Markdown #Rich Text #Telegram Bots
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 08:44:45 +0000
════════════════════════
⌗ Tags: #Technology #bot development #HTML formatting #Markdown #Rich Text #Telegram Bots
Daily CyberSecurity
Telegram Bots Receive Rich HTML and Markdown Formatting Options
Pavel Durov recently announced expanded capabilities for all automated systems on the platform. Specifically, Telegram now supports intricate HTML and Markdown structures. Consequently, bots can g…
⤷ Title: I Turned a “What’s Your Name?” Field Into a Malicious Link — My First HTML Injection
════════════════════════
𐀪 Author: Prashant Raj
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:46:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_hunting #html_injection #technology
════════════════════════
𐀪 Author: Prashant Raj
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 10:46:00 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #bug_hunting #html_injection #technology
Medium
I Turned a “What’s Your Name?” Field Into a Malicious Link — My First HTML Injection
TryHackMe — How Websites Work
⤷ Title: I Found a Bug That Looks Harmless But Can Still Get You Paid
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 00:03:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #html #medium #bug_bounty
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
ⴵ Time: Thu, 18 Jun 2026 00:03:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #html #medium #bug_bounty
Medium
I Found a Bug That Looks Harmless But Can Still Get You Paid
Here is everything I know about HTML Injection, how I test for it, how people bypass filters, and what it actually scores on CVSS
⤷ Title: bWAPP HTML Injection — Reflected (URL) and Stored (Blog)
════════════════════════
𐀪 Author: Kamal S
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 14:03:38 GMT
════════════════════════
⌗ Tags: #injection #html_injection #owasp #bug_bounty #bwapp
════════════════════════
𐀪 Author: Kamal S
════════════════════════
ⴵ Time: Sun, 21 Jun 2026 14:03:38 GMT
════════════════════════
⌗ Tags: #injection #html_injection #owasp #bug_bounty #bwapp
Medium
bWAPP HTML Injection — Reflected (URL) and Stored (Blog)
Web applications heavily rely on user input, but improper handling of this input often introduces security vulnerabilities. One such…
⤷ Title: CSRF: When Your Browser Snitches Behind Your Back
════════════════════════
𐀪 Author: Ziyad
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 01:34:55 GMT
════════════════════════
⌗ Tags: #web_development #html #csrf #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Ziyad
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 01:34:55 GMT
════════════════════════
⌗ Tags: #web_development #html #csrf #cybersecurity #penetration_testing
Medium
CSRF: When Your Browser Snitches Behind Your Back
What are CSRFs ?
⤷ Title: From a “Self-XSS” to a Convincing UI Spoof: A Bug Bounty Story That Ended as a Duplicate.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 19:47:30 GMT
════════════════════════
⌗ Tags: #phishing #html #reflected_xss #self_xss #bug_bounty
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Fri, 26 Jun 2026 19:47:30 GMT
════════════════════════
⌗ Tags: #phishing #html #reflected_xss #self_xss #bug_bounty
Medium
From a “Self-XSS” to a Convincing UI Spoof: A Bug Bounty Story That Ended as a Duplicate.
There’s a special kind of pain in bug bounty. Not getting an Out of Scope. Not getting an informative.
⤷ Title: GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection
Daily CyberSecurity
GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
TL;DR This GitLab patch release, shipped on July 8, 2026, covers versions 19.1.2, 19.0.4, and 18.11.7. The update fixes eight security flaws across Community and Enterprise Edition. The most sever…
⤷ Title: How I Turned an “Informative” HTML Injection into My First Paid Bounty
════════════════════════
𐀪 Author: Muhammadmaftuhk
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 23:57:41 GMT
════════════════════════
⌗ Tags: #web_security #html_injection #bug_bounty #bug_bounty_writeup #cybersecurity
════════════════════════
𐀪 Author: Muhammadmaftuhk
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 23:57:41 GMT
════════════════════════
⌗ Tags: #web_security #html_injection #bug_bounty #bug_bounty_writeup #cybersecurity
Medium
How I Turned an “Informative” HTML Injection into My First Paid Bounty
TL;DR: HTML Injection is often marked as Informative or N/A by triagers. However, by demonstrating how a hidden CSS overlay bypassed the…