⤷ Title: How I Discovered an API Authorization Flaw Exposing 100+ User Phone Numbers and Sensitive Campaign…
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 23:19:11 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Tue, 18 Aug 2026 23:19:11 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
How I Discovered an API Authorization Flaw Exposing 100+ User Phone Numbers and Sensitive Campaign…
Yoo, it’s been a while since I published a write-up.
⤷ Title: DOJ Charges 17 Iranians in Mabna Institute Cyber Theft
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:48:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DOJ indictment #Iran cyber theft #IRGC #Mabna Institute #Spearphishing #State_Sponsored Hacking #university hacking
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:48:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DOJ indictment #Iran cyber theft #IRGC #Mabna Institute #Spearphishing #State_Sponsored Hacking #university hacking
Daily CyberSecurity
DOJ Charges 17 Iranians in Mabna Institute Cyber Theft
At a glance Actor or group Mabna Institute (Iran-based), allegedly for the IRGC Activity type Spearphishing, credential theft, data exfiltration (hacking-for-hire) Targets Universities, private co…
⤷ Title: CISA KEV Adds Four Exploited Flaws in SharePoint, vCenter
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:41:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV Catalog #CVE_2026_33824 #CVE_2026_55040 #CVE_2026_59310 #Known Exploited Vulnerabilities #Sharepoint #VMware vCenter
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:41:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV Catalog #CVE_2026_33824 #CVE_2026_55040 #CVE_2026_59310 #Known Exploited Vulnerabilities #Sharepoint #VMware vCenter
Daily CyberSecurity
CISA KEV Adds Four Exploited Flaws in SharePoint, vCenter
TL;DR CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 18, 2026. Each entry rests on evidence of active exploitation. The flaws hit Microsoft, Broadcom, and…
⤷ Title: CVE-2026-17482: IBM Remote Code Execution Flaw (CVSS 9.8)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:33:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_17482 #IBM #rce #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:33:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_17482 #IBM #rce #Remote Code Execution
Daily CyberSecurity
CVE-2026-17482: IBM Remote Code Execution Flaw (CVSS 9.8)
TL;DR Security researchers discovered multiple severe vulnerabilities in IBM Documentation Offline. Most notably, a critical IBM remote code execution flaw allows attackers to run malicious comman…
⤷ Title: Chrome Update Fixes 15 Flaws, Two Critical in WebGL, Dawn
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:29:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #CVE_2026_76034 #CVE_2026_76036 #google chrome #V8 #WebGL
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:29:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #Chrome Security Update #CVE_2026_76034 #CVE_2026_76036 #google chrome #V8 #WebGL
Daily CyberSecurity
Chrome Update Fixes 15 Flaws, Two Critical in WebGL, Dawn
TL;DR Google shipped a Chrome security update on August 26, 2026. It fixes 15 vulnerabilities, including two critical buffer overflows. Both critical bugs sit in the browser’s graphics stack…
⤷ Title: Armored Likho Still Toolkit Deploys Covert Spying Implants
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:15:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ArmoredLikho #Cyberespionage #infosec #kaspersky #StillToolkit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:15:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ArmoredLikho #Cyberespionage #infosec #kaspersky #StillToolkit
Daily CyberSecurity
Armored Likho Still Toolkit Deploys Covert Spying Implants
At a glance Actor or group: Armored Likho (also known as Eagle Werewolf) Activity type: Cyber espionage and audio surveillance Targets or victims: Private individuals, government bodies, IT firms,…
⤷ Title: Building Stealthy C2 Infrastructure with Sliver and Re-director Red Teaming Part — 2
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:38:24 GMT
════════════════════════
⌗ Tags: #walkthrough #red_team #hacking #penetration_testing #ctf_writeup
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:38:24 GMT
════════════════════════
⌗ Tags: #walkthrough #red_team #hacking #penetration_testing #ctf_writeup
Medium
Building Stealthy C2 Infrastructure with Sliver and Re-director Red Teaming Part — 2
In modern red teaming, setting up a secure and stealthy Command-and-Control (C2) infrastructure is essential for success. After acquiring…
⤷ Title: Why Domain Reputation Matters in Red Teaming Part - 1
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:06:32 GMT
════════════════════════
⌗ Tags: #red_team #hacking #walkthrough #ctf #penetration_testing
════════════════════════
𐀪 Author: Md. Imran Chowdhury
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 01:06:32 GMT
════════════════════════
⌗ Tags: #red_team #hacking #walkthrough #ctf #penetration_testing
Medium
Why Domain Reputation Matters in Red Teaming Part - 1
In the world of modern red teaming, infrastructure is king. The ability to evade security controls, minimize detection, and deliver…
⤷ Title: Balance — Product Release Notes: July 2026
════════════════════════
𐀪 Author: Josh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:58:20 GMT
════════════════════════
⌗ Tags: #balance_now #product_release_notes #trading_as_a_service #penetration_testing #alessandro_tocco
════════════════════════
𐀪 Author: Josh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:58:20 GMT
════════════════════════
⌗ Tags: #balance_now #product_release_notes #trading_as_a_service #penetration_testing #alessandro_tocco
Medium
Balance — Product Release Notes: July 2026
In July, we welcomed Alessandro Tocco as our new Chief Compliance and Risk Officer (CCRO), further strengthening our executive team. In…
⤷ Title: GitLab Fixed a Remote Code Execution Bug in June and Skipped the CVE.
════════════════════════
𐀪 Author: Amit Spitzer
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:41:22 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #vulnerability_management #venture_capital #api_security
════════════════════════
𐀪 Author: Amit Spitzer
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 00:41:22 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #vulnerability_management #venture_capital #api_security
Medium
GitLab Fixed a Remote Code Execution Bug in June and Skipped the CVE. Forty-Four Days Later, Someone Weaponized the Diff.
Ask any security team how they decide what to patch first, and most will point to a CVSS score. That number comes from a CVE. And a CVE…
⤷ Title: CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:25:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple Security #authentication bypass #Cryptojacking #CVE_2026_65400 #macos #Monero Miner #Screen Sharing
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:25:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple Security #authentication bypass #Cryptojacking #CVE_2026_65400 #macos #Monero Miner #Screen Sharing
Information Security News
CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Attackers have begun exploiting a critical vulnerability in macOS’s built-in Screen Sharing feature to gain access to Mac computers without any valid credentials whatsoever. In several confi…
⤷ Title: BeyondTrust EPM Flaws Allow Windows Privilege Escalation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:50:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BeyondTrust #BeyondTrust vulnerability #CVE_2026_40144 #CVE_2026_40145 #Endpoint Privilege Management #privilege escalation #Windows Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:50:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BeyondTrust #BeyondTrust vulnerability #CVE_2026_40144 #CVE_2026_40145 #Endpoint Privilege Management #privilege escalation #Windows Security
Daily CyberSecurity
BeyondTrust EPM Flaws Allow Windows Privilege Escalation
TL;DR BeyondTrust patched two high-severity flaws in Endpoint Privilege Management for Windows. This BeyondTrust vulnerability pair can lead to local privilege escalation. The company found both t…
⤷ Title: Gmail Verified Sender Program Launch 2026
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:56:56 +0000
════════════════════════
⌗ Tags: #Technology #Email Security #gmail #google #Political Campaigns #Spam Filters
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:56:56 +0000
════════════════════════
⌗ Tags: #Technology #Email Security #gmail #google #Political Campaigns #Spam Filters
Daily CyberSecurity
Gmail Verified Sender Program Launch 2026
Tech giants face intense scrutiny as the 2026 US Mid-term Elections approach. They must carefully balance algorithmic neutrality with mounting political pressure. Recently, Google quietly revealed…
⤷ Title: CVE-2026-60702 (CVSS 9.9): Oracle WebLogic Takeover Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:41:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60698 #CVE_2026_60702 #CVE_2026_60977 #Oracle Fusion Middleware #Oracle WebLogic vulnerability #Server Takeover #WebLogic
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:41:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60698 #CVE_2026_60702 #CVE_2026_60977 #Oracle Fusion Middleware #Oracle WebLogic vulnerability #Server Takeover #WebLogic
Daily CyberSecurity
CVE-2026-60702 (CVSS 9.9): Oracle WebLogic Takeover Flaw
TL;DR Oracle patched nine flaws in WebLogic Server in a special August 2026 update. Five carry critical scores. The top Oracle WebLogic vulnerability, CVE-2026-60702, scores a CVSS of 9.9. Success…
⤷ Title: The bug that made a forum grind to 32 seconds a page — for $1,024
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:48:13 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #cybersecurity #bug_bounty #hacking
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:48:13 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #cybersecurity #bug_bounty #hacking
Medium
The bug that made a forum grind to 32 seconds a page — for $1,024
Nine drafts. No admin access. Just an oversized text field nobody thought to check.
⤷ Title: No Login. No Cookie. Just a UUID — Breaking DHL’s Shipment Authorization
════════════════════════
𐀪 Author: Zuksh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:55:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #ethical_hacking #api_security #cybersecurity
════════════════════════
𐀪 Author: Zuksh
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:55:02 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #ethical_hacking #api_security #cybersecurity
Medium
No Login. No Cookie. Just a UUID — Breaking DHL’s Shipment Authorization
Hello Hackers,
⤷ Title: Defensive Security Intro — Try Hack Me
════════════════════════
𐀪 Author: Chittanoori Divyashrith
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:48:16 GMT
════════════════════════
⌗ Tags: #defensive_security_intro #cybersecurity #cyber_security_101 #tryhackme
════════════════════════
𐀪 Author: Chittanoori Divyashrith
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:48:16 GMT
════════════════════════
⌗ Tags: #defensive_security_intro #cybersecurity #cyber_security_101 #tryhackme
Medium
Defensive Security Intro — Try Hack Me
Task 1 — Introduction
⤷ Title: Hacker Holidays 2026 | Day 7 Do Not Disturb | TryHackMe
════════════════════════
𐀪 Author: Life of a Pentester
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:19:14 GMT
════════════════════════
⌗ Tags: #walkthrough #tryhackme_walkthrough #ctf_writeup #tryhackme #ssti_rce
════════════════════════
𐀪 Author: Life of a Pentester
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 02:19:14 GMT
════════════════════════
⌗ Tags: #walkthrough #tryhackme_walkthrough #ctf_writeup #tryhackme #ssti_rce
Medium
Hacker Holidays 2026 | Day 7 Do Not Disturb | TryHackMe
In this boot2root machine, we’re going to be using simple but yet effective tools we normally use in CTFs and also on Penetration Tests…
⤷ Title: File Upload Security: Polyglots, Content-Type Confusion, and Storage Risks
════════════════════════
𐀪 Author: CYBER MIND SPACE
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:46:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #file_upload_security #cybersecurity #cybermindspace #php
════════════════════════
𐀪 Author: CYBER MIND SPACE
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:46:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #file_upload_security #cybersecurity #cybermindspace #php
Medium
File Upload Security: Polyglots, Content-Type Confusion, and Storage Risks
The file passed image validation. It was also PHP. That’s the whole attack.
⤷ Title: OSINT: The Internet Knows More About You Than You Think
════════════════════════
𐀪 Author: Oryvorix
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 05:33:59 GMT
════════════════════════
⌗ Tags: #bug_bounty #cyber_security_awareness #google #osint #cybersecurity
════════════════════════
𐀪 Author: Oryvorix
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 05:33:59 GMT
════════════════════════
⌗ Tags: #bug_bounty #cyber_security_awareness #google #osint #cybersecurity
Medium
OSINT: The Internet Knows More About You Than You Think
Have you ever searched your own name on Google just to see what shows up?
⤷ Title: OpenAI Codex Security vs Anthropic Claude Security vs Google CodeMender: Who Is Building the Future…
════════════════════════
𐀪 Author: D09r
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 05:29:40 GMT
════════════════════════
⌗ Tags: #app_security #application_security #appsec #claude_security #code_security
════════════════════════
𐀪 Author: D09r
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 05:29:40 GMT
════════════════════════
⌗ Tags: #app_security #application_security #appsec #claude_security #code_security
Medium
OpenAI Codex Security vs Anthropic Claude Security vs Google CodeMender: Who Is Building the Future of AI-Powered AppSec?
Application security is entering a new phase.