⤷ Title: How I Ran a Company’s Own Internal Workflows With a Free Account
════════════════════════
𐀪 Author: 0x-elfateh
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:14:59 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #cybersecurity #infosec
════════════════════════
𐀪 Author: 0x-elfateh
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:14:59 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunting #cybersecurity #infosec
Medium
How I Ran a Company’s Own Internal Workflows With a Free Account 👀
Bounty Case Files #02 | How a Broken Function-Level Authorization vulnerability allowed a free-tier user to enumerate and execute internal…
⤷ Title: Blinding EDRs to Thread Creation via BYOVD
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 20:54:16 GMT
════════════════════════
⌗ Tags: #infosec #hacking #pentesting #malware #cybersecurity
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 20:54:16 GMT
════════════════════════
⌗ Tags: #infosec #hacking #pentesting #malware #cybersecurity
Medium
Blinding EDRs to Thread Creation via BYOVD
Welcome to this new Medium post, in this one we will see how to enumerate and unlink thread creation callbacks registered through…
⤷ Title: Getting a Shell Out of the Cloud: Reverse Shells, Tunnels & Exfil
════════════════════════
𐀪 Author: zeyneppcelikk
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:21:56 GMT
════════════════════════
⌗ Tags: #reverse_shell #penetration_testing #cloud_security #gcp #red_team
════════════════════════
𐀪 Author: zeyneppcelikk
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:21:56 GMT
════════════════════════
⌗ Tags: #reverse_shell #penetration_testing #cloud_security #gcp #red_team
Medium
Getting a Shell Out of the Cloud: Reverse Shells, Tunnels & Exfil
Attacking Google Cloud — Part 2 / 7
⤷ Title: Weaponizing AutoGPT’s Email Block for Error-Based Internal SSRF and Banner Grabbing
════════════════════════
𐀪 Author: Pavan Nallamothu
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:30:17 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #auto_gpt #ssrf #cve
════════════════════════
𐀪 Author: Pavan Nallamothu
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 21:30:17 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #auto_gpt #ssrf #cve
Medium
Weaponizing AutoGPT’s Email Block for Error-Based Internal SSRF and Banner Grabbing
You type `smtp_server: 10.0.0.5` into a text field.
⤷ Title: Case Study: Navigating the Responsible Disclosure Dilemma
════════════════════════
𐀪 Author: Jafarlimahir
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 20:41:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #information_security #disclosure #ethical_hacking
════════════════════════
𐀪 Author: Jafarlimahir
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 20:41:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #information_security #disclosure #ethical_hacking
Medium
Case Study: Navigating the Responsible Disclosure Dilemma
Executive Summary
⤷ Title: How I Discovered an API Authorization Flaw Exposing 100+ User Phone Numbers and Sensitive Campaign…
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 23:19:11 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 23:19:11 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
How I Discovered an API Authorization Flaw Exposing 100+ User Phone Numbers and Sensitive Campaign…
Yoo, it’s been a while since I published a write-up.
⤷ Title: DOJ Charges 17 Iranians in Mabna Institute Cyber Theft
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:48:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DOJ indictment #Iran cyber theft #IRGC #Mabna Institute #Spearphishing #State_Sponsored Hacking #university hacking
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:48:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DOJ indictment #Iran cyber theft #IRGC #Mabna Institute #Spearphishing #State_Sponsored Hacking #university hacking
Daily CyberSecurity
DOJ Charges 17 Iranians in Mabna Institute Cyber Theft
At a glance Actor or group Mabna Institute (Iran-based), allegedly for the IRGC Activity type Spearphishing, credential theft, data exfiltration (hacking-for-hire) Targets Universities, private co…
⤷ Title: CISA KEV Adds Four Exploited Flaws in SharePoint, vCenter
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:41:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV Catalog #CVE_2026_33824 #CVE_2026_55040 #CVE_2026_59310 #Known Exploited Vulnerabilities #Sharepoint #VMware vCenter
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:41:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV Catalog #CVE_2026_33824 #CVE_2026_55040 #CVE_2026_59310 #Known Exploited Vulnerabilities #Sharepoint #VMware vCenter
Daily CyberSecurity
CISA KEV Adds Four Exploited Flaws in SharePoint, vCenter
TL;DR CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 18, 2026. Each entry rests on evidence of active exploitation. The flaws hit Microsoft, Broadcom, and…
⤷ Title: CVE-2026-17482: IBM Remote Code Execution Flaw (CVSS 9.8)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:33:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_17482 #IBM #rce #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:33:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_17482 #IBM #rce #Remote Code Execution
Daily CyberSecurity
CVE-2026-17482: IBM Remote Code Execution Flaw (CVSS 9.8)
TL;DR Security researchers discovered multiple severe vulnerabilities in IBM Documentation Offline. Most notably, a critical IBM remote code execution flaw allows attackers to run malicious comman…
⤷ Title: Chrome Update Fixes 15 Flaws, Two Critical in WebGL, Dawn
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:29:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #CVE_2026_76034 #CVE_2026_76036 #google chrome #V8 #WebGL
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:29:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #CVE_2026_76034 #CVE_2026_76036 #google chrome #V8 #WebGL
Daily CyberSecurity
Chrome Update Fixes 15 Flaws, Two Critical in WebGL, Dawn
TL;DR Google shipped a Chrome security update on August 26, 2026. It fixes 15 vulnerabilities, including two critical buffer overflows. Both critical bugs sit in the browser’s graphics stack…
⤷ Title: Armored Likho Still Toolkit Deploys Covert Spying Implants
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:15:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ArmoredLikho #Cyberespionage #infosec #kaspersky #StillToolkit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:15:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ArmoredLikho #Cyberespionage #infosec #kaspersky #StillToolkit
Daily CyberSecurity
Armored Likho Still Toolkit Deploys Covert Spying Implants
At a glance Actor or group: Armored Likho (also known as Eagle Werewolf) Activity type: Cyber espionage and audio surveillance Targets or victims: Private individuals, government bodies, IT firms,…
⤷ Title: Building Stealthy C2 Infrastructure with Sliver and Re-director Red Teaming Part — 2
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:38:24 GMT
════════════════════════
⌗ Tags: #walkthrough #red_team #hacking #penetration_testing #ctf_writeup
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:38:24 GMT
════════════════════════
⌗ Tags: #walkthrough #red_team #hacking #penetration_testing #ctf_writeup
Medium
Building Stealthy C2 Infrastructure with Sliver and Re-director Red Teaming Part — 2
In modern red teaming, setting up a secure and stealthy Command-and-Control (C2) infrastructure is essential for success. After acquiring…
⤷ Title: Why Domain Reputation Matters in Red Teaming Part - 1
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:06:32 GMT
════════════════════════
⌗ Tags: #red_team #hacking #walkthrough #ctf #penetration_testing
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:06:32 GMT
════════════════════════
⌗ Tags: #red_team #hacking #walkthrough #ctf #penetration_testing
Medium
Why Domain Reputation Matters in Red Teaming Part - 1
In the world of modern red teaming, infrastructure is king. The ability to evade security controls, minimize detection, and deliver…
⤷ Title: Balance — Product Release Notes: July 2026
════════════════════════
𐀪 Author: Josh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:58:20 GMT
════════════════════════
⌗ Tags: #balance_now #product_release_notes #trading_as_a_service #penetration_testing #alessandro_tocco
════════════════════════
𐀪 Author: Josh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:58:20 GMT
════════════════════════
⌗ Tags: #balance_now #product_release_notes #trading_as_a_service #penetration_testing #alessandro_tocco
Medium
Balance — Product Release Notes: July 2026
In July, we welcomed Alessandro Tocco as our new Chief Compliance and Risk Officer (CCRO), further strengthening our executive team. In…
⤷ Title: GitLab Fixed a Remote Code Execution Bug in June and Skipped the CVE.
════════════════════════
𐀪 Author: Amit Spitzer
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:41:22 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #vulnerability_management #venture_capital #api_security
════════════════════════
𐀪 Author: Amit Spitzer
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:41:22 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #vulnerability_management #venture_capital #api_security
Medium
GitLab Fixed a Remote Code Execution Bug in June and Skipped the CVE. Forty-Four Days Later, Someone Weaponized the Diff.
Ask any security team how they decide what to patch first, and most will point to a CVSS score. That number comes from a CVE. And a CVE…
⤷ Title: CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:25:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple Security #authentication bypass #Cryptojacking #CVE_2026_65400 #macos #Monero Miner #Screen Sharing
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:25:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple Security #authentication bypass #Cryptojacking #CVE_2026_65400 #macos #Monero Miner #Screen Sharing
Information Security News
CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Attackers have begun exploiting a critical vulnerability in macOS’s built-in Screen Sharing feature to gain access to Mac computers without any valid credentials whatsoever. In several confi…
⤷ Title: BeyondTrust EPM Flaws Allow Windows Privilege Escalation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:50:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BeyondTrust #BeyondTrust vulnerability #CVE_2026_40144 #CVE_2026_40145 #Endpoint Privilege Management #privilege escalation #Windows Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:50:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BeyondTrust #BeyondTrust vulnerability #CVE_2026_40144 #CVE_2026_40145 #Endpoint Privilege Management #privilege escalation #Windows Security
Daily CyberSecurity
BeyondTrust EPM Flaws Allow Windows Privilege Escalation
TL;DR BeyondTrust patched two high-severity flaws in Endpoint Privilege Management for Windows. This BeyondTrust vulnerability pair can lead to local privilege escalation. The company found both t…
⤷ Title: Gmail Verified Sender Program Launch 2026
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:56:56 +0000
════════════════════════
⌗ Tags: #Technology #Email Security #gmail #google #Political Campaigns #Spam Filters
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:56:56 +0000
════════════════════════
⌗ Tags: #Technology #Email Security #gmail #google #Political Campaigns #Spam Filters
Daily CyberSecurity
Gmail Verified Sender Program Launch 2026
Tech giants face intense scrutiny as the 2026 US Mid-term Elections approach. They must carefully balance algorithmic neutrality with mounting political pressure. Recently, Google quietly revealed…
⤷ Title: CVE-2026-60702 (CVSS 9.9): Oracle WebLogic Takeover Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:41:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60698 #CVE_2026_60702 #CVE_2026_60977 #Oracle Fusion Middleware #Oracle WebLogic vulnerability #Server Takeover #WebLogic
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:41:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60698 #CVE_2026_60702 #CVE_2026_60977 #Oracle Fusion Middleware #Oracle WebLogic vulnerability #Server Takeover #WebLogic
Daily CyberSecurity
CVE-2026-60702 (CVSS 9.9): Oracle WebLogic Takeover Flaw
TL;DR Oracle patched nine flaws in WebLogic Server in a special August 2026 update. Five carry critical scores. The top Oracle WebLogic vulnerability, CVE-2026-60702, scores a CVSS of 9.9. Success…
⤷ Title: The bug that made a forum grind to 32 seconds a page — for $1,024
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:48:13 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #cybersecurity #bug_bounty #hacking
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:48:13 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #cybersecurity #bug_bounty #hacking
Medium
The bug that made a forum grind to 32 seconds a page — for $1,024
Nine drafts. No admin access. Just an oversized text field nobody thought to check.
⤷ Title: No Login. No Cookie. Just a UUID — Breaking DHL’s Shipment Authorization
════════════════════════
𐀪 Author: Zuksh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:55:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #ethical_hacking #api_security #cybersecurity
════════════════════════
𐀪 Author: Zuksh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:55:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #ethical_hacking #api_security #cybersecurity
Medium
No Login. No Cookie. Just a UUID — Breaking DHL’s Shipment Authorization
Hello Hackers,
❤1