⤷ Title: SNOWLIGHT Malware Campaign Exposed by Open Directories
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:28:11 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Hackers #Cyber Espionage #cybersecurity #malware #SNOWLIGHT
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:28:11 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Hackers #Cyber Espionage #cybersecurity #malware #SNOWLIGHT
Information Security News
SNOWLIGHT Malware Campaign Exposed by Open Directories
The operators behind a massive, globally coordinated hacking campaign committed a fatal operational security error. They inadvertently left directories entirely open on the centralized server util…
⤷ Title: Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:53:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #CVE_2026_59774 #Gitea #Path Traversal #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:53:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #CVE_2026_59774 #Gitea #Path Traversal #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Gitea Vulnerability CVE-2026-59774 Enables Unauthenticated Remote Code Execution
TL;DR Gitea 1.27.1 patches a critical Gitea vulnerability, CVE-2026-59774, rated CVSS 9.8. An unauthenticated attacker can read arbitrary server files through a public repository, then escalate to…
⤷ Title: Microsoft Teams Vishing Campaign STAC4749 Deploys Chaos Ransomware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chaos Ransomware #Microsoft Teams vishing #ransomware #social engineering #STAC4749 #Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chaos Ransomware #Microsoft Teams vishing #ransomware #social engineering #STAC4749 #Vishing
Daily CyberSecurity
Microsoft Teams Vishing Campaign STAC4749 Deploys Chaos Ransomware
At a glance Actor STAC4749 (unattributed threat cluster) Activity Teams vishing, remote access, ransomware Targets Dozens of North American organizations (Canada, U.S.) Scale At least three Chaos …
⤷ Title: Dysphoria Botnet Uses Blockchain Domains for C2 and Turns Victims Into Relays
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:30:09 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ddos #DDoS_for_hire #Dysphoria #Dysphoria Botnet #ENS #IoT botnet #XLab
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:30:09 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ddos #DDoS_for_hire #Dysphoria #Dysphoria Botnet #ENS #IoT botnet #XLab
Daily CyberSecurity
Dysphoria Botnet Uses Blockchain Domains for C2 and Turns Victims Into Relays
At a glance Malware family Dysphoria (jackskid/fbot-derived IoT botnet) Threat actor Unattributed; run as a commercial DDoS-for-hire service Target About 200,000 IoT and embedded Linux devices wor…
⤷ Title: 15 Ways Cybercriminals Abuse AI in Real Campaigns: Learn to Spot and Counter Modern Attacks
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:09:26 GMT
════════════════════════
⌗ Tags: #hacking #cybercrime #bug_bounty #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:09:26 GMT
════════════════════════
⌗ Tags: #hacking #cybercrime #bug_bounty #cybersecurity #penetration_testing
Medium
15 Ways Cybercriminals Abuse AI in Real Campaigns: Learn to Spot and Counter Modern Attacks
Ever catch yourself wondering if that phishing email was crafted by a person — or something smarter? Here’s a number to chew on: in 2023…
⤷ Title: Why Every Developer Should Threat Model Before Writing a Single Line of Code: A Practical Level 2…
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:36:57 GMT
════════════════════════
⌗ Tags: #data_flow_diagram #application_security #stride #threat_modeling #cybersecurity
════════════════════════
𐀪 Author: Gabriel Odusanya
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:36:57 GMT
════════════════════════
⌗ Tags: #data_flow_diagram #application_security #stride #threat_modeling #cybersecurity
Medium
Why Every Developer Should Threat Model Before Writing a Single Line of Code: A Practical Level 2 DFD Walkthrough
Understanding threat modelling, the STRIDE framework, and how a simple Data Flow Diagram can prevent security disasters before they happen.
⤷ Title: Your AI Agent Has an IDOR Problem
════════════════════════
𐀪 Author: Serhat ÇİÇEK
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:20:26 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #application_security #ai_agent #idor
════════════════════════
𐀪 Author: Serhat ÇİÇEK
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:20:26 GMT
════════════════════════
⌗ Tags: #llm #cybersecurity #application_security #ai_agent #idor
Medium
Your AI Agent Has an IDOR Problem
Everyone’s hardening LLM agents against prompt injection. The bug that actually leaks your data is broken object-level authorization…
⤷ Title: OSCP|PG|HUB
════════════════════════
𐀪 Author: Abhishek Maitra
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:44:04 GMT
════════════════════════
⌗ Tags: #oscp #provinggrounds #oscp_preparation #hacking #penetration_testing
════════════════════════
𐀪 Author: Abhishek Maitra
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:44:04 GMT
════════════════════════
⌗ Tags: #oscp #provinggrounds #oscp_preparation #hacking #penetration_testing
Medium
OSCP|PG|HUB
Initial nmap scan discovery shows port 22,80 and 8082 are open.
⤷ Title: Building a Semi-Autonomous SOC, Part 3: Automated Response & Red Team Results
════════════════════════
𐀪 Author: Edris Hassani
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:02:06 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #homelab #artificial_intelligence #automation
════════════════════════
𐀪 Author: Edris Hassani
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:02:06 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #homelab #artificial_intelligence #automation
Medium
Building a Semi-Autonomous SOC, Part 3: Automated Response & Red Team Results
By Edris Hassani and Hadi Tavana
⤷ Title: No Patch Coming: What a Recurring KNX Vulnerability Should Teach the Building Automation Industry
════════════════════════
𐀪 Author: Paul Holmes
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:01:04 GMT
════════════════════════
⌗ Tags: #building_automation #critical_infrastructure #cybersecurity #iot #infosec
════════════════════════
𐀪 Author: Paul Holmes
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:01:04 GMT
════════════════════════
⌗ Tags: #building_automation #critical_infrastructure #cybersecurity #iot #infosec
Medium
No Patch Coming: What a Recurring KNX Vulnerability Should Teach the Building Automation Industry
CISA confirmed KNX vulnerability CVE-2023–4346 has no patch and is still exploited. What it means for building automation security.
⤷ Title: How I Found and Fixed a Bug in Apple’s SwiftNIO
════════════════════════
𐀪 Author: Aruvasaga chithan A
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:43:35 GMT
════════════════════════
⌗ Tags: #bug_hunting #apple #swift #cybersecurity #infosec
════════════════════════
𐀪 Author: Aruvasaga chithan A
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:43:35 GMT
════════════════════════
⌗ Tags: #bug_hunting #apple #swift #cybersecurity #infosec
Medium
How I Found and Fixed a Bug in Apple’s SwiftNIO
Every security researcher has a different way of finding bugs.
⤷ Title: API Testing Essentials: A Beginner’s Guide to Finding Bugs Before Users Do
════════════════════════
𐀪 Author: Jyotivarshney
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:52:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #software_engineering #api #software_testing #quality_assurance
════════════════════════
𐀪 Author: Jyotivarshney
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:52:45 GMT
════════════════════════
⌗ Tags: #penetration_testing #software_engineering #api #software_testing #quality_assurance
Medium
API Testing Essentials: A Beginner’s Guide to Finding Bugs Before Users Do
Modern applications rely heavily on APIs to exchange data between clients, servers, and third-party services. While users interact with the…
⤷ Title: Burp AT: Bringing Agentic AI Into Web Application Pentesting
════════════════════════
𐀪 Author: Sandeepappsec
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:03:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #ai #cybersecurity #web_application_security #ai_security
════════════════════════
𐀪 Author: Sandeepappsec
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:03:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #ai #cybersecurity #web_application_security #ai_security
Medium
Burp AT: Bringing Agentic AI Into Web Application Pentesting
Web application penetration testing isn’t always about finding a vulnerability.
⤷ Title: TryHackMe Towel on the Sunbed Write up
════════════════════════
𐀪 Author: ayed djalil
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:27 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: ayed djalil
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:31:27 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough
Medium
TryHackMe Towel on the Sunbed Write up
Room link: https://tryhackme.com/room/hh-towelonthesunbed-61271709
⤷ Title: Nmap Advanced Port Scans | JR PT Room
════════════════════════
𐀪 Author: Anas Rah
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:28:40 GMT
════════════════════════
⌗ Tags: #reconnaissance #nmap #tryhackme #tryhackme_walkthrough #cybersecurity
════════════════════════
𐀪 Author: Anas Rah
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:28:40 GMT
════════════════════════
⌗ Tags: #reconnaissance #nmap #tryhackme #tryhackme_walkthrough #cybersecurity
Medium
Nmap Advanced Port Scans | JR PT Room
I recently completed my Nmap room in Jr Pt module. So there are many nmap scans other than basic port and hosts scan, Nmap is a lot bigger…
⤷ Title: Splunk: Data Manipulation, A TryHackMe Walkthrough
════════════════════════
𐀪 Author: DeadHack
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:27:46 GMT
════════════════════════
⌗ Tags: #tryhackme #siem #cybersecurity #splunk #security_operation_center
════════════════════════
𐀪 Author: DeadHack
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:27:46 GMT
════════════════════════
⌗ Tags: #tryhackme #siem #cybersecurity #splunk #security_operation_center
Medium
Splunk: Data Manipulation, A TryHackMe Walkthrough
This room picks up where the earlier Splunk challenges left off. Instead of focusing on searching or visualizing data that is already…
⤷ Title: Beach Bar | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:16 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #web #boot2root
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:16 GMT
════════════════════════
⌗ Tags: #tryhackme #cybersecurity #web #boot2root
Medium
Beach Bar | TryHackMe
At the Beach Bar, even shell access is complimentary. The jukebox takes requests. Any kind.
⤷ Title: Overheard at Breakfast | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hashing #osint #social_media
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 07:11:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #hashing #osint #social_media
Medium
Overheard at Breakfast | TryHackMe
Two strangers. One conversation. One profile they never meant to reveal.
⤷ Title: Packed Light
════════════════════════
𐀪 Author: Harshikachauhan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:44:02 GMT
════════════════════════
⌗ Tags: #tryhackme
════════════════════════
𐀪 Author: Harshikachauhan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:44:02 GMT
════════════════════════
⌗ Tags: #tryhackme
Medium
Packed Light
Tiny packets. Odd hours. Suspiciously regular. Someone’s smuggling out the data equivalent of a hotel towel every night, folded neatly…
⤷ Title: Complimentary
════════════════════════
𐀪 Author: Harshikachauhan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:41:23 GMT
════════════════════════
⌗ Tags: #tryhackme
════════════════════════
𐀪 Author: Harshikachauhan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:41:23 GMT
════════════════════════
⌗ Tags: #tryhackme
Medium
Complimentary
Install the free app and it hands your phone a set of cloud keys, the same set it hands everyone. They’re read-only, but read-only of every…
⤷ Title: The Concierge Knows Too Much CTF Walkthrough (TryHackMe)
════════════════════════
𐀪 Author: Vanessa3
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:31:41 GMT
════════════════════════
⌗ Tags: #aisec #ctf #ethical_hacking #tryhackme #prompt_injection_attack
════════════════════════
𐀪 Author: Vanessa3
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 06:31:41 GMT
════════════════════════
⌗ Tags: #aisec #ctf #ethical_hacking #tryhackme #prompt_injection_attack
Medium
The Concierge Knows Too Much CTF Walkthrough (TryHackMe)
The Concierge knows too much lab is a beginner-friendly CTF provides a practical introduction to the Prompt Injection vulnerability.