⤷ Title: Intigriti July 2026 CTF Write-Up: Exploiting JSON Parser Differential (Duplicate-Key Confusion) to…
════════════════════════
𐀪 Author: Zabed Ullah Poyel
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 04:23:17 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #bug_bounty_writeup #web_security #intigriti #ctf_writeup
════════════════════════
𐀪 Author: Zabed Ullah Poyel
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 04:23:17 GMT
════════════════════════
⌗ Tags: #ctf_walkthrough #bug_bounty_writeup #web_security #intigriti #ctf_writeup
Medium
Intigriti July 2026 CTF Write-Up: Exploiting JSON Parser Differential (Duplicate-Key Confusion) to…
Challenge: Canonically Yours
Platform: Intigriti Monthly CTF — July 2026
Category: Web Security / Broken Access Control
Vulnerability: JSON…
Platform: Intigriti Monthly CTF — July 2026
Category: Web Security / Broken Access Control
Vulnerability: JSON…
⤷ Title: CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 12:30:13 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 12:30:13 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: KindaRails2Shell: Ruby on Rails CVE-2026-66066 RCE Flaw
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:28:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Storage #CVE_2026_66066 #cybersecurity #KindaRails2Shell #Ruby on Rails
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:28:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Storage #CVE_2026_66066 #cybersecurity #KindaRails2Shell #Ruby on Rails
Information Security News
KindaRails2Shell: Ruby on Rails CVE-2026-66066 RCE Flaw
A crafted image can turn a standard avatar upload form into a covert conduit for stealing web application secrets. A vulnerable Ruby on Rails server may expose encryption keys, database passwords,…
⤷ Title: SNOWLIGHT Malware Campaign Exposed by Open Directories
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:28:11 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Hackers #Cyber Espionage #cybersecurity #malware #SNOWLIGHT
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:28:11 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Hackers #Cyber Espionage #cybersecurity #malware #SNOWLIGHT
Information Security News
SNOWLIGHT Malware Campaign Exposed by Open Directories
The operators behind a massive, globally coordinated hacking campaign committed a fatal operational security error. They inadvertently left directories entirely open on the centralized server util…
⤷ Title: Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:53:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #CVE_2026_59774 #Gitea #Path Traversal #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:53:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #CVE_2026_59774 #Gitea #Path Traversal #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
TL;DR Gitea 1.27.1 patches a critical Gitea vulnerability, CVE-2026-59774, rated CVSS 9.8. An unauthenticated attacker can read arbitrary server files through a public repository, then escalate to…
⤷ Title: Microsoft Teams Vishing Campaign STAC4749 Deploys Chaos Ransomware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chaos Ransomware #Microsoft Teams vishing #ransomware #social engineering #STAC4749 #Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chaos Ransomware #Microsoft Teams vishing #ransomware #social engineering #STAC4749 #Vishing
Daily CyberSecurity
Microsoft Teams Vishing Campaign STAC4749 Deploys Chaos Ransomware
At a glance Actor STAC4749 (unattributed threat cluster) Activity Teams vishing, remote access, ransomware Targets Dozens of North American organizations (Canada, U.S.) Scale At least three Chaos …
⤷ Title: Dysphoria Botnet Uses Blockchain Domains for C2 and Turns Victims Into Relays
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:30:09 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ddos #DDoS_for_hire #Dysphoria #Dysphoria Botnet #ENS #IoT botnet #XLab
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:30:09 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ddos #DDoS_for_hire #Dysphoria #Dysphoria Botnet #ENS #IoT botnet #XLab
Daily CyberSecurity
Dysphoria Botnet Uses Blockchain Domains for C2 and Turns Victims Into Relays
At a glance Malware family Dysphoria (jackskid/fbot-derived IoT botnet) Threat actor Unattributed; run as a commercial DDoS-for-hire service Target About 200,000 IoT and embedded Linux devices wor…
⤷ Title: 15 Ways Cybercriminals Abuse AI in Real Campaigns: Learn to Spot and Counter Modern Attacks
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:09:26 GMT
════════════════════════
⌗ Tags: #hacking #cybercrime #bug_bounty #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:09:26 GMT
════════════════════════
⌗ Tags: #hacking #cybercrime #bug_bounty #cybersecurity #penetration_testing
Medium
15 Ways Cybercriminals Abuse AI in Real Campaigns: Learn to Spot and Counter Modern Attacks
Ever catch yourself wondering if that phishing email was crafted by a person — or something smarter? Here’s a number to chew on: in 2023…
⤷ Title: Why Every Developer Should Threat Model Before Writing a Single Line of Code: A Practical Level 2…
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:36:57 GMT
════════════════════════
⌗ Tags: #data_flow_diagram #application_security #stride #threat_modeling #cybersecurity
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:36:57 GMT
════════════════════════
⌗ Tags: #data_flow_diagram #application_security #stride #threat_modeling #cybersecurity
Medium
Why Every Developer Should Threat Model Before Writing a Single Line of Code: A Practical Level 2 DFD Walkthrough
Understanding threat modelling, the STRIDE framework, and how a simple Data Flow Diagram can prevent security disasters before they happen.
⤷ Title: Your AI Agent Has an IDOR Problem
════════════════════════
𐀪 Author: Serhat ÇİÇEK
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:20:26 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #application_security #ai_agent #idor
════════════════════════
𐀪 Author: Serhat ÇİÇEK
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:20:26 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #application_security #ai_agent #idor
Medium
Your AI Agent Has an IDOR Problem
Everyone’s hardening LLM agents against prompt injection. The bug that actually leaks your data is broken object-level authorization…
⤷ Title: OSCP|PG|HUB
════════════════════════
𐀪 Author: Abhishek Maitra
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:44:04 GMT
════════════════════════
⌗ Tags: #oscp #provinggrounds #oscp_preparation #hacking #penetration_testing
════════════════════════
𐀪 Author: Abhishek Maitra
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:44:04 GMT
════════════════════════
⌗ Tags: #oscp #provinggrounds #oscp_preparation #hacking #penetration_testing
Medium
OSCP|PG|HUB
Initial nmap scan discovery shows port 22,80 and 8082 are open.
⤷ Title: Building a Semi-Autonomous SOC, Part 3: Automated Response & Red Team Results
════════════════════════
𐀪 Author: Edris Hassani
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:02:06 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #homelab #artificial_intelligence #automation
════════════════════════
𐀪 Author: Edris Hassani
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:02:06 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #homelab #artificial_intelligence #automation
Medium
Building a Semi-Autonomous SOC, Part 3: Automated Response & Red Team Results
By Edris Hassani and Hadi Tavana
⤷ Title: No Patch Coming: What a Recurring KNX Vulnerability Should Teach the Building Automation Industry
════════════════════════
𐀪 Author: Paul Holmes
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:01:04 GMT
════════════════════════
⌗ Tags: #building_automation #critical_infrastructure #cybersecurity #iot #infosec
════════════════════════
𐀪 Author: Paul Holmes
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:01:04 GMT
════════════════════════
⌗ Tags: #building_automation #critical_infrastructure #cybersecurity #iot #infosec
Medium
No Patch Coming: What a Recurring KNX Vulnerability Should Teach the Building Automation Industry
CISA confirmed KNX vulnerability CVE-2023–4346 has no patch and is still exploited. What it means for building automation security.
⤷ Title: How I Found and Fixed a Bug in Apple’s SwiftNIO
════════════════════════
𐀪 Author: Aruvasaga chithan A
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:43:35 GMT
════════════════════════
⌗ Tags: #bug_hunting #apple #swift #cybersecurity #infosec
════════════════════════
𐀪 Author: Aruvasaga chithan A
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:43:35 GMT
════════════════════════
⌗ Tags: #bug_hunting #apple #swift #cybersecurity #infosec
Medium
How I Found and Fixed a Bug in Apple’s SwiftNIO
Every security researcher has a different way of finding bugs.
⤷ Title: API Testing Essentials: A Beginner’s Guide to Finding Bugs Before Users Do
════════════════════════
𐀪 Author: Jyotivarshney
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:52:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #software_engineering #api #software_testing #quality_assurance
════════════════════════
𐀪 Author: Jyotivarshney
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:52:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #software_engineering #api #software_testing #quality_assurance
Medium
API Testing Essentials: A Beginner’s Guide to Finding Bugs Before Users Do
Modern applications rely heavily on APIs to exchange data between clients, servers, and third-party services. While users interact with the…
⤷ Title: Burp AT: Bringing Agentic AI Into Web Application Pentesting
════════════════════════
𐀪 Author: Sandeepappsec
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:03:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #ai #cybersecurity #web_application_security #ai_security
════════════════════════
𐀪 Author: Sandeepappsec
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:03:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #ai #cybersecurity #web_application_security #ai_security
Medium
Burp AT: Bringing Agentic AI Into Web Application Pentesting
Web application penetration testing isn’t always about finding a vulnerability.
⤷ Title: TryHackMe Towel on the Sunbed Write up
════════════════════════
𐀪 Author: ayed djalil
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:27 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: ayed djalil
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:27 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough
Medium
TryHackMe Towel on the Sunbed Write up
Room link: https://tryhackme.com/room/hh-towelonthesunbed-61271709
⤷ Title: Nmap Advanced Port Scans | JR PT Room
════════════════════════
𐀪 Author: Anas Rah
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:28:40 GMT
════════════════════════
⌗ Tags: #reconnaissance #nmap #tryhackme #tryhackme_walkthrough #cybersecurity
════════════════════════
𐀪 Author: Anas Rah
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:28:40 GMT
════════════════════════
⌗ Tags: #reconnaissance #nmap #tryhackme #tryhackme_walkthrough #cybersecurity
Medium
Nmap Advanced Port Scans | JR PT Room
I recently completed my Nmap room in Jr Pt module. So there are many nmap scans other than basic port and hosts scan, Nmap is a lot bigger…
⤷ Title: Splunk: Data Manipulation, A TryHackMe Walkthrough
════════════════════════
𐀪 Author: DeadHack
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:27:46 GMT
════════════════════════
⌗ Tags: #tryhackme #siem #cybersecurity #splunk #security_operation_center
════════════════════════
𐀪 Author: DeadHack
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:27:46 GMT
════════════════════════
⌗ Tags: #tryhackme #siem #cybersecurity #splunk #security_operation_center
Medium
Splunk: Data Manipulation, A TryHackMe Walkthrough
This room picks up where the earlier Splunk challenges left off. Instead of focusing on searching or visualizing data that is already…
⤷ Title: Beach Bar | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:16 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #web #boot2root
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:16 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #web #boot2root
Medium
Beach Bar | TryHackMe
At the Beach Bar, even shell access is complimentary. The jukebox takes requests. Any kind.
⤷ Title: Overheard at Breakfast | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hashing #osint #social_media
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hashing #osint #social_media
Medium
Overheard at Breakfast | TryHackMe
Two strangers. One conversation. One profile they never meant to reveal.