⤷ Title: Hunting Exchange Server 0day like a detective
════════════════════════
𐀪 Author: Jang
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 04:45:43 GMT
════════════════════════
⌗ Tags: #exchange #cve_2026_62911 #servers #rce
════════════════════════
𐀪 Author: Jang
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 04:45:43 GMT
════════════════════════
⌗ Tags: #exchange #cve_2026_62911 #servers #rce
Medium
Hunting Exchange Server 0day like a detective
It has been a while since my last blog post, not because I didn’t do anything (or I?), I just don’t have any time/ any motivation to start…
⤷ Title: Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 11:39:48 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 11:39:48 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:34:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_65640 #Ghostscript #Imagick #Remote Code Execution #Web Security #wordpress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:34:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_65640 #Ghostscript #Imagick #Remote Code Execution #Web Security #wordpress
Daily CyberSecurity
CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution
TL;DR WordPress released version 7.0.4 on August 12, 2026, as a security-only update. It fixes CVE-2026-65640, an authenticated remote code execution flaw rated CVSS 8.8. The bug affects sites tha…
⤷ Title: ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:29:07 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ChainDrop #CI/CD security #npm Worm #supply chain attack #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:29:07 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ChainDrop #CI/CD security #npm Worm #supply chain attack #Unit 42
Daily CyberSecurity
ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
At a glance Malware family ChainDrop (Shai-Hulud code lineage) Threat actor Unattributed; possible link to TeamPCP (not confirmed) Targets Developer workstations, CI pipelines, cloud environments …
⤷ Title: Fake Zoom Installer Drops Overlord RAT on macOS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:29:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #fake Zoom installer #Jamf Threat Labs #macOS Malware #Overlord RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:29:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #fake Zoom installer #Jamf Threat Labs #macOS Malware #Overlord RAT
Daily CyberSecurity
Fake Zoom Installer Drops Overlord RAT on macOS
At a glance Malware family Overlord (open-source RAT framework) Threat actor Unattributed (suspected DPRK links noted, not confirmed) Target macOS and Windows users Delivery vector Fake Zoom insta…
⤷ Title: How Unauthenticated Queries Exposed User PII and Privileged Accounts
════════════════════════
𐀪 Author: Sudheer
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:26:04 GMT
════════════════════════
⌗ Tags: #authorization #api_security #bug_bounty #authentication #web_security_testing
════════════════════════
𐀪 Author: Sudheer
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:26:04 GMT
════════════════════════
⌗ Tags: #authorization #api_security #bug_bounty #authentication #web_security_testing
Medium
How Unauthenticated Queries Exposed User PII and Privileged Accounts
Unauthenticated API queries exposed sensitive user data and enabled enumeration of the application’s entire observed userbase.
⤷ Title: Unique Username Validation Bypass to a Stored Open Redirect: How I Escalated a Bug Bounty Finding
════════════════════════
𐀪 Author: Ankit Rathva aka Gujarati Hacker
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:17:32 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hackerone #bug_bounty_tips #bug_bounty #business_logic
════════════════════════
𐀪 Author: Ankit Rathva aka Gujarati Hacker
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:17:32 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #hackerone #bug_bounty_tips #bug_bounty #business_logic
Medium
From a Username Validation Bypass to a Stored Open Redirect: How I Escalated a Finding
How a seemingly simple input-validation issue turned into a real-world phishing and malicious-redirection scenario.
⤷ Title: EDR Bypass Without Malware: 15 LOLBAS Techniques Security Pros Need to Master
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:19:20 GMT
════════════════════════
⌗ Tags: #ethical_hacking #hacking #bug_bounty #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:19:20 GMT
════════════════════════
⌗ Tags: #ethical_hacking #hacking #bug_bounty #cybersecurity #penetration_testing
Medium
EDR Bypass Without Malware: 15 LOLBAS Techniques Security Pros Need to Master
Ever wonder why attackers can waltz right past the latest Endpoint Detection & Response (EDR) tools — no malware needed? Here’s the wild…
⤷ Title: The Bug Worth Lakhs Was Not in the Code. Here It Was and How to Report It Properly.
════════════════════════
𐀪 Author: Parag Jadhav
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:14:22 GMT
════════════════════════
⌗ Tags: #bug_bounty #generative_ai_tools #cybersecurity #business #ai_security
════════════════════════
𐀪 Author: Parag Jadhav
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:14:22 GMT
════════════════════════
⌗ Tags: #bug_bounty #generative_ai_tools #cybersecurity #business #ai_security
Medium
The Bug Worth Lakhs Was Not in the Code. Here It Was and How to Report It Properly.
Talktime with Lakshya 2047 · Null Vadodara × Lakshya 2047 Centre for Future Skills · Parul University, Vadodara, Gujarat, India
⤷ Title: How a Tampered role_id Gave Me Permanent, Invisible Control Over Other Users’ Organizations
════════════════════════
𐀪 Author: HASG
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:12:05 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #information_security #cybersecuirty #web_security
════════════════════════
𐀪 Author: HASG
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:12:05 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #information_security #cybersecuirty #web_security
Medium
How a Tampered role_id Gave Me Permanent, Invisible Control Over Other Users’ Organizations
السلام عليكم ورحمة الله وبركاته.
⤷ Title: AI Systems Can Be Attacked Too. Here Is How It Happens and What Professionals Are Doing About It.
════════════════════════
𐀪 Author: Parag Jadhav
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 05:52:37 GMT
════════════════════════
⌗ Tags: #ai_systems #hacking #cybersecurity #gujarat #bug_bounty
════════════════════════
𐀪 Author: Parag Jadhav
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 05:52:37 GMT
════════════════════════
⌗ Tags: #ai_systems #hacking #cybersecurity #gujarat #bug_bounty
Medium
AI Systems Can Be Attacked Too. Here Is How It Happens and What Professionals Are Doing About It.
Talktime with Lakshya 2047 · Null Vadodara × Lakshya 2047 Centre for Future Skills · Parul University, Vadodara, Gujarat, India
⤷ Title: The Tech-Savvy Parent’s Guide to Digital Safety in 2026: Balancing Security and Trust
════════════════════════
𐀪 Author: Promotionneverlove
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:39:55 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity
════════════════════════
𐀪 Author: Promotionneverlove
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:39:55 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity
Medium
The Tech-Savvy Parent’s Guide to Digital Safety in 2026: Balancing Security and Trust
We live in a world where the boundary between the physical and digital lives of our children has completely dissolved. Today, a child’s…
⤷ Title: Ethical Hacking Institute
════════════════════════
𐀪 Author: Cozonix
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:15:44 GMT
════════════════════════
⌗ Tags: #technology #hacking #ethical_hacking #educational #cybersecurity
════════════════════════
𐀪 Author: Cozonix
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:15:44 GMT
════════════════════════
⌗ Tags: #technology #hacking #ethical_hacking #educational #cybersecurity
Medium
Ethical Hacking Institute
Start Your Journey Into Offensive Cybersecurity
⤷ Title: Cybersecurity Training Institute
════════════════════════
𐀪 Author: Cozonix
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:49:21 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #technology #hacking #education
════════════════════════
𐀪 Author: Cozonix
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:49:21 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #technology #hacking #education
Medium
Cybersecurity Training Institute
What to Look for Before Choosing One
⤷ Title: What Is MEV? Sandwich Attacks on DEX Swaps Explained
════════════════════════
𐀪 Author: Kryllex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:11:18 GMT
════════════════════════
⌗ Tags: #ethereum #decentralized_finance #crypto #cryptocurrency #hacking
════════════════════════
𐀪 Author: Kryllex
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:11:18 GMT
════════════════════════
⌗ Tags: #ethereum #decentralized_finance #crypto #cryptocurrency #hacking
Medium
What Is MEV? Sandwich Attacks on DEX Swaps Explained
MEV stands for Maximal Extractable Value — the profit available to whoever decides the order transactions go into a block. Ordering matters…
⤷ Title: Atlassian AI Rovo Tricked Into Sending Jira and Confluence Data to Attackers
════════════════════════
𐀪 Author: Stanislav Klevtsov
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:02:45 GMT
════════════════════════
⌗ Tags: #infosec #ai #ai_agent #vulnerability #cybersecurity
════════════════════════
𐀪 Author: Stanislav Klevtsov
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:02:45 GMT
════════════════════════
⌗ Tags: #infosec #ai #ai_agent #vulnerability #cybersecurity
Medium
Atlassian AI Rovo Tricked Into Sending Jira and Confluence Data to Attackers
PromptArmor, an AI security firm, has done some security tests on Atlassian Rovo.
⤷ Title: Automating AI Safety Assessments: Multi-Turn Attacks and Logging for Modern Applications
════════════════════════
𐀪 Author: Amit Kulkarni
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 05:50:56 GMT
════════════════════════
⌗ Tags: #llm #automated_testing #python #penetration_testing #artificial_intelligence
════════════════════════
𐀪 Author: Amit Kulkarni
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 05:50:56 GMT
════════════════════════
⌗ Tags: #llm #automated_testing #python #penetration_testing #artificial_intelligence
Medium
Automating AI Safety Assessments: Multi-Turn Attacks and Logging for Modern Applications
Learn how to run multi-turn conversation attacks and classify responses to keep your production AI safe and compliant
⤷ Title: [RootMe] — PHP Upload Bypass to Root Access via SUID PrivEsc
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:43:04 GMT
════════════════════════
⌗ Tags: #tryhackme_rootme #file_upload_bypass #tryhackme #privilege_escalation #ctf
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:43:04 GMT
════════════════════════
⌗ Tags: #tryhackme_rootme #file_upload_bypass #tryhackme #privilege_escalation #ctf
Medium
[RootMe] — PHP Upload Bypass to Root Access via SUID PrivEsc
From hidden upload panel to root through PHP execution and Linux SUID privilege escalation.
⤷ Title: TryHackMe — VERA Guestbook: Exploiting an AI Authorization Flaw to Capture the Flag
════════════════════════
𐀪 Author: SYN
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:21:14 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme #ai #cybersecurity #tryhackme_walkthrough
════════════════════════
𐀪 Author: SYN
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:21:14 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme #ai #cybersecurity #tryhackme_walkthrough
Medium
TryHackMe — VERA Guestbook: Exploiting an AI Authorization Flaw to Capture the Flag
ROOM LINK: The GuestBook
⤷ Title: Overflow The Jackpot CTF — Lost Fortune Included — Short Write-up
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:37:34 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf
════════════════════════
𐀪 Author: PRiTi.EX
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:37:34 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf
Medium
Overflow The Jackpot CTF — Lost Fortune Included — Short Write-up
Solution:
⤷ Title: TryHackMe Write-Up: Solving the B1t Recovery CTF (Known-Plaintext Attack)
════════════════════════
𐀪 Author: Sushma
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:13:51 GMT
════════════════════════
⌗ Tags: #ctf #ctf_walkthrough #ctf_writeup #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: Sushma
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:13:51 GMT
════════════════════════
⌗ Tags: #ctf #ctf_walkthrough #ctf_writeup #tryhackme #tryhackme_walkthrough
Medium
TryHackMe 🔐 Write-Up: Solving the B1t Recovery CTF (Known-Plaintext Attack)
This guide demonstrates how to recover a scrambled ledger file using a Known-Plaintext Attack (KPA) on a simple XOR encryption scheme.