⤷ Title: Gigabud Abuses Android Work Profiles to Hide Bank Fraud
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:01:05 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Gigabud #GoldFactory #Group_IB #Vwork
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:01:05 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Gigabud #GoldFactory #Group_IB #Vwork
Information Security News
Gigabud Abuses Android Work Profiles to Hide Bank Fraud
An Android feature devised to separate personal and corporate applications has become a hiding place for banking fraud. Group-IB has described the pairing of Gigabud and Vwork, which, in a confirm…
⤷ Title: CVE-2026-80351 & CVE-2026-80352: 9.8 CVSS Apache Camel K Vulnerabilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:11:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Camel #Camel K #CVE_2026_80351 #CVE_2026_80352 #CVE_2026_80354 #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:11:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Camel #Camel K #CVE_2026_80351 #CVE_2026_80352 #CVE_2026_80354 #Vulnerability
Daily CyberSecurity
CVE-2026-80351 & CVE-2026-80352: 9.8 CVSS Apache Camel K Vulnerabilities
The Apache Software Foundation released patches addressing three critical Apache Camel K vulnerabilities. These flaws allow attackers to execute arbitrary code and bypass authorization checks with…
⤷ Title: ⚡ BugScanner Explained | Automated Web Recon & Vulnerability Scanning for Bug Bounty
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:47:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #hacking #bug_bounty #artificial_intelligence
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:47:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #hacking #bug_bounty #artificial_intelligence
Medium
⚡ BugScanner Explained | Automated Web Recon & Vulnerability Scanning for Bug Bounty
What if your web security reconnaissance workflow could automatically discover the attack surface, fingerprint technologies, identify…
⤷ Title: Understanding Credit Scores and Why Repair Matters | Get It Fixed | Hire Professional
════════════════════════
𐀪 Author: BlackHat
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:08:19 GMT
════════════════════════
⌗ Tags: #loans #artificial_intelligence #hacking #mortgage #money
════════════════════════
𐀪 Author: BlackHat
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:08:19 GMT
════════════════════════
⌗ Tags: #loans #artificial_intelligence #hacking #mortgage #money
Medium
Understanding Credit Scores and Why Repair Matters | Get It Fixed | Hire Professional
Understanding Credit Scores and Why Repair Matters | Ge
⤷ Title: How I Found an Account Takeover Hiding in a ‘Scan to Upload’ Button
════════════════════════
𐀪 Author: chiheb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:00:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
════════════════════════
𐀪 Author: chiheb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:00:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
Medium
How I Found an Account Takeover Hiding in a ‘Scan to Upload’ Button
Program name, domain, and a few other identifying details in this writeup have been redacted at my request — the rest is exactly how it…
⤷ Title: hc0n Christmas CTF (THM) Tryhackme Walkthrough
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:14:45 GMT
════════════════════════
⌗ Tags: #privilege_escalation #linux #tryhackme #cybersecurity #hacking
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:14:45 GMT
════════════════════════
⌗ Tags: #privilege_escalation #linux #tryhackme #cybersecurity #hacking
Medium
hc0n Christmas CTF (THM) Tryhackme Walkthrough
Description : hackt the planet
⤷ Title: MITRE ATT&CK Explained: Reading the Matrix Like a Detection Engineer
════════════════════════
𐀪 Author: Tims Tittus
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:23:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #detection_engineering #infosec #soc #threat_hunting
════════════════════════
𐀪 Author: Tims Tittus
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:23:13 GMT
════════════════════════
⌗ Tags: #cybersecurity #detection_engineering #infosec #soc #threat_hunting
Medium
MITRE ATT&CK Explained: Reading the Matrix Like a Detection Engineer
The matrix just changed for the first time in years — here’s what’s different and how detection engineers actually use it
⤷ Title: The Hacker Didn’t Hack the Website. They Tricked the Cache.
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:22:35 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: pavani
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:22:35 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking
Medium
The Hacker Didn’t Hack the Website. They Tricked the Cache.
A strange web attack where the attacker doesn’t break the application. They convince the cache to store something it shouldn’t.
⤷ Title: VulnHub: Mr. Robot — Full Walkthrough
════════════════════════
𐀪 Author: Ahmed Osman
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:21:37 GMT
════════════════════════
⌗ Tags: #penetration_testing #mr_robot #cybersecurity #vulnhub #ethical_hacking
════════════════════════
𐀪 Author: Ahmed Osman
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:21:37 GMT
════════════════════════
⌗ Tags: #penetration_testing #mr_robot #cybersecurity #vulnhub #ethical_hacking
Medium
Vulnhub: Mr.Robot — Writeup
A practical VulnHub Mr. Robot walkthrough covering reconnaissanc,web enumeration,WordPress authentication,Linux privilege escalation
⤷ Title: TargetVeil: A Local-First Pentest Data Sanitizer for Safer AI-Assisted Security Work
════════════════════════
𐀪 Author: Ilias Georgopoulos
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:08:05 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #penetration_testing #open_source #privacy #cybersecurity
════════════════════════
𐀪 Author: Ilias Georgopoulos
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 14:08:05 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #penetration_testing #open_source #privacy #cybersecurity
Medium
TargetVeil: A Local-First Pentest Data Sanitizer for Safer AI-Assisted Security Work
Redact PII, client infrastructure, credentials, and engagement identifiers before sharing penetration-testing evidence with public AI tools
⤷ Title: I Found 500 Subdomains. Then I Realized I Hadn’t Found the Attack Surface Yet
════════════════════════
𐀪 Author: Fateyaly
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #ethical_hacking #coding #cybersecurity #programming #technology
════════════════════════
𐀪 Author: Fateyaly
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:39:32 GMT
════════════════════════
⌗ Tags: #ethical_hacking #coding #cybersecurity #programming #technology
Medium
I Found 500 Subdomains. Then I Realized I Hadn’t Found the Attack Surface Yet
Why a giant subdomain list means almost nothing until DNS, ports, TLS, and HTTP tell you what’s actually alive
⤷ Title: How I stumbled into my first “AI-powered” bug bounty target and found that an AI chatbot’s memory…
════════════════════════
𐀪 Author: GAURAV RN
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:19:05 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #ai_chatbot_security #ai_security
════════════════════════
𐀪 Author: GAURAV RN
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 15:19:05 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #ai_chatbot_security #ai_security
Medium
How I stumbled into my first “AI-powered” bug bounty target and found that an AI chatbot’s memory had no lock on it 🤷
For years, my bug bounty muscle memory looked the same: pick a web app, poke the API, look for the usual suspects — broken auth, XXS …
⤷ Title: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 22:00:18 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 22:00:18 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 21:45:29 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 21:45:29 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: One Parameter. One Script Tag. One CVE.
════════════════════════
𐀪 Author: Mohammed ElKhateb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:53:24 GMT
════════════════════════
⌗ Tags: #xs #red_team #bug_bounty #cybersecurity #web_security
════════════════════════
𐀪 Author: Mohammed ElKhateb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:53:24 GMT
════════════════════════
⌗ Tags: #xs #red_team #bug_bounty #cybersecurity #web_security
Medium
🔐 One Parameter. One Script Tag. One CVE.
> 🧠 TL;DR — I found a reflected XSS in TechStore v1.0. One GET parameter, `id`, gets dropped straight into the page with no encoding and…
⤷ Title: One .svg and a CDN: How a File Extension Leaked Strangers' PII
════════════════════════
𐀪 Author: Abhinabshrestha
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:20:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web_cache_deception #bug_bounty_writeup
════════════════════════
𐀪 Author: Abhinabshrestha
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:20:50 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #web_cache_deception #bug_bounty_writeup
Medium
One .svg and a CDN: How a File Extension Leaked Strangers' PII
A walkthrough of a Web Cache Deception bug that turned a private profile API into a public one — and the story of how it got closed as a…
⤷ Title: Dari Activity Log ke Pelanggaran Privasi: Mengeksploitasi Broken Object Level Authorization
════════════════════════
𐀪 Author: 0xHunter
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:09:38 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #application_security #penetration_testing
════════════════════════
𐀪 Author: 0xHunter
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:09:38 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #application_security #penetration_testing
Medium
Dari Activity Log ke Pelanggaran Privasi: Mengeksploitasi Broken Object Level Authorization
Riwayat aktivitas akun merupakan komponen kritis dalam arsitektur keamanan aplikasi modern. Fitur ini dirancang untuk memberikan…
⤷ Title: OSAI (AI-300) and the Future of Pentesting
════════════════════════
𐀪 Author: Raad Haddad
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:02:48 GMT
════════════════════════
⌗ Tags: #security #hacking #osai #red_team #ai
════════════════════════
𐀪 Author: Raad Haddad
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 17:02:48 GMT
════════════════════════
⌗ Tags: #security #hacking #osai #red_team #ai
Medium
OSAI (AI-300) and the Future of Pentesting
I recently completed the OSAI certification, and for me, this was one of those certifications that immediately felt relevant to where…
⤷ Title: How I Found an Account Takeover Hiding in a ‘Scan to Upload’ Button
════════════════════════
𐀪 Author: chiheb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:27:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
════════════════════════
𐀪 Author: chiheb
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 16:27:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking
Medium
How I Found an Account Takeover Hiding in a ‘Scan to Upload’ Button
Program name, domain, and a few other identifying details in this writeup have been redacted at my request — the rest is exactly how it…
⤷ Title: thisisunsafe: o “atalho” escondido do Chrome que todo profissional de segurança deveria conhecer
════════════════════════
𐀪 Author: 3SC0133
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:20:53 GMT
════════════════════════
⌗ Tags: #information_security #bug_bounty #web_security #cybersecurity_news #penetration_testing
════════════════════════
𐀪 Author: 3SC0133
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 19:20:53 GMT
════════════════════════
⌗ Tags: #information_security #bug_bounty #web_security #cybersecurity_news #penetration_testing
⤷ Title: A WebSocket, a Shell, and a Critical CVE: Discovering CVE-2026–39987
════════════════════════
𐀪 Author: julichaan
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:32:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #vulnerability #hackthebox
════════════════════════
𐀪 Author: julichaan
════════════════════════
ⴵ Time: Fri, 11 Sep 2026 18:32:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #vulnerability #hackthebox
Medium
A WebSocket, a Shell, and a Critical CVE: Discovering CVE-2026–39987
There are vulnerabilities that require chaining multiple weaknesses, bypassing filters, and spending hours building an exploitation path.