⤷ Title: Local Authority — picoCTF Write-up | Exposing Credentials Through Client-Side JavaScript
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 05:52:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #ctf #cybersecurity #web_security
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 05:52:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #ctf #cybersecurity #web_security
Medium
Local Authority — picoCTF Write-up | Exposing Credentials Through Client-Side JavaScript
Introduction
⤷ Title: Library — CyberQ Walkthrough
════════════════════════
𐀪 Author: Harsh
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 04:20:37 GMT
════════════════════════
⌗ Tags: #smb_enumeration #walkthrough #windows_privilege_esc #ntlm_cracking #sql_injection
════════════════════════
𐀪 Author: Harsh
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 04:20:37 GMT
════════════════════════
⌗ Tags: #smb_enumeration #walkthrough #windows_privilege_esc #ntlm_cracking #sql_injection
Medium
Library — CyberQ Walkthrough
## Overview
⤷ Title: RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:47:25 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:47:25 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Tajin Group Phishing Network Linked to Guarantee Marketplaces
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:11:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:11:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals
Daily CyberSecurity
Tajin Group Phishing Network Linked to Guarantee Marketplaces
At a glance Actor or group: Tajin Group (suspected Chinese-speaking cybercriminal syndicate) Activity type: Phishing, payment card theft, and money laundering Targets or victims: Mainland Chinese …
⤷ Title: Critical Google Chrome Vulnerabilities Fixed in Update
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:20:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_93372 #CVE_2026_93374 #CVE_2026_93377 #google chrome #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:20:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_93372 #CVE_2026_93374 #CVE_2026_93377 #google chrome #Vulnerability
Daily CyberSecurity
Critical Google Chrome Vulnerabilities Fixed in Update
TL;DR Google released security updates on September 17, 2026, addressing sixteen vulnerabilities in its web browser. These Google Chrome vulnerabilities include two critical flaws that permit memo…
⤷ Title: Critical Dokploy OS Command Injection Exposes Servers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:12:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_72878 #Dokploy #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:12:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_72878 #Dokploy #Vulnerability
Daily CyberSecurity
Critical Dokploy OS Command Injection Exposes Servers
A severe Dokploy OS command injection vulnerability threatens self-hosted Platform as a Service (PaaS) environments. Tracked in vulnerability note VU#280377 and assigned CVE-2026-72878, this criti…
⤷ Title: GhostCode Phishing Kit Targets Enterprise Microsoft Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:11:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #GhostCode #Microsoft 365 #OAuth #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:11:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #GhostCode #Microsoft 365 #OAuth #phishing
Daily CyberSecurity
GhostCode Phishing Kit Targets Enterprise Microsoft Accounts
At a glance Actor or group: Unidentified cybercrime group (financially motivated threat actors) Activity type: Device code phishing, OAuth token theft, and business email compromise Targets or vic…
⤷ Title: I’m Starting My 100-Hour Bug Bounty Challenge — Here’s My Method
════════════════════════
𐀪 Author: Mansigolecha
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:47:26 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #artificial_intelligence #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Mansigolecha
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:47:26 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #artificial_intelligence #cybersecurity #penetration_testing
Medium
I’m Starting My 100-Hour Bug Bounty Challenge — Here’s My Method
https://medium.com/@mansigolecha84_17480/im-starting-my-100-hour-bug-bounty-challenge-here-s-my-method-f26a40f02df5?source=friends_link&sk=b…
⤷ Title: How a Random Password-less “SSO Token” Let a Full Account Takeover
════════════════════════
𐀪 Author: #$ubh@nk@r
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:25:04 GMT
════════════════════════
⌗ Tags: #infosec #web_security #cybersecurity #hacker #bug_bounty
════════════════════════
𐀪 Author: #$ubh@nk@r
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:25:04 GMT
════════════════════════
⌗ Tags: #infosec #web_security #cybersecurity #hacker #bug_bounty
Medium
How a Random Password-less “SSO Token” Let a Full Account Takeover
What’s up folks. So this one wasn’t some deep, multi-hour recon grind — it was one of those bugs that just falls into your lap while you’re…
⤷ Title: CVE-2026–2619: How a Read-Only GitLab Auditor Could Modify Vulnerability Flags
════════════════════════
𐀪 Author: KabishDahal
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:51:38 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty_writeup #gitlab #access_control #cybersecurity
════════════════════════
𐀪 Author: KabishDahal
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:51:38 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty_writeup #gitlab #access_control #cybersecurity
Medium
CVE-2026–2619: How a Read-Only GitLab Auditor Could Modify Vulnerability Flags
An authorization flaw in GitLab’s AI detection API, the evidence behind my report, and the permission change that fixed it.
⤷ Title: Visitor Management as an Essential Part of Corporate Security
════════════════════════
𐀪 Author: PT Neuronworks Indonesia
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:22:00 GMT
════════════════════════
⌗ Tags: #systems_thinking #visitor_experience #neuronworks #application_security #security
════════════════════════
𐀪 Author: PT Neuronworks Indonesia
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:22:00 GMT
════════════════════════
⌗ Tags: #systems_thinking #visitor_experience #neuronworks #application_security #security
Medium
Visitor Management as an Essential Part of Corporate Security
A company lobby is often the first point of contact between visitors and the workplace. Behind the reception process, however, there are…
⤷ Title: The Life and Death of Browser Security
════════════════════════
𐀪 Author: Danny Lin
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:54:13 GMT
════════════════════════
⌗ Tags: #browser_security #cloudmosa #infosec #cybersecurity #ai_assisted_threats
════════════════════════
𐀪 Author: Danny Lin
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:54:13 GMT
════════════════════════
⌗ Tags: #browser_security #cloudmosa #infosec #cybersecurity #ai_assisted_threats
Medium
The Life and Death of Browser Security
The browser was never meant to become a battlefield.
⤷ Title: I Scored 10 Pentesting Vendors on Whether Their “AI” Actually Tests Anything
════════════════════════
𐀪 Author: Anonymous brat
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:23:57 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #pentesting #ai_agent #ai
════════════════════════
𐀪 Author: Anonymous brat
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:23:57 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #pentesting #ai_agent #ai
Medium
I Scored 10 Pentesting Vendors on Whether Their “AI” Actually Tests Anything
Most AI claims on pentest vendor pages are true. A surprising number just aren’t about pentesting.
⤷ Title: Escaping the Image Folder: File Path Traversal, Simple Case
════════════════════════
𐀪 Author: Kaustubh Asthana
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:18:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #web_penetration_testing #burpsuite #portswigger
════════════════════════
𐀪 Author: Kaustubh Asthana
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:18:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #web_penetration_testing #burpsuite #portswigger
Medium
Escaping the Image Folder: File Path Traversal, Simple Case
Lab eight in my Web Security Academy series — the first one where the vulnerability lives in the filesystem, not the login form
⤷ Title: My First Cybersecurity Lab: What I Learned from TryHackMe
════════════════════════
𐀪 Author: Oduwaugo
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:16:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybersecurity_careers #learning_in_public #tryhackme #information_security
════════════════════════
𐀪 Author: Oduwaugo
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:16:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybersecurity_careers #learning_in_public #tryhackme #information_security
Medium
My First Cybersecurity Lab: What I Learned from TryHackMe
Moving from cybersecurity theory to hands-on practice and what my first lab experience taught me.
⤷ Title: Reset Password Vulnerability
════════════════════════
𐀪 Author: Sourabh Jala
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:31:01 GMT
════════════════════════
⌗ Tags: #reset_password_root #authentication #cybersecurity #ethical_hacking #testing
════════════════════════
𐀪 Author: Sourabh Jala
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:31:01 GMT
════════════════════════
⌗ Tags: #reset_password_root #authentication #cybersecurity #ethical_hacking #testing
Medium
Reset Password Vulnerability
Authentication / Password Reset Testing
⤷ Title: Apache Struts 2 REST Plugin XStream Deserialization: When XML Requests Become Remote Code Execution
════════════════════════
𐀪 Author: EternalSec
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:24:01 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #rce #web_security #cybersecurity #apache_struts_2
════════════════════════
𐀪 Author: EternalSec
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:24:01 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #rce #web_security #cybersecurity #apache_struts_2
Medium
Apache Struts 2 REST Plugin XStream Deserialization: When XML Requests Become Remote Code Execution
A trusted XML request should never be able to decide which Java objects your server creates.
⤷ Title: Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:03 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:03 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Synology DSM Patches 8 Flaws, Two Critical Unauthenticated
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:41:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_13639 #CVE_2026_13684 #DiskStation Manager #DSM #NAS security #Synology
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:41:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_13639 #CVE_2026_13684 #DiskStation Manager #DSM #NAS security #Synology
Daily CyberSecurity
Synology DSM Patches 8 Flaws, Two Critical Unauthenticated
TL;DR Synology patched eight Synology DSM vulnerabilities in advisory SA_26_13. Two are critical and need no login. Both let a remote attacker read or write files and cause denial of service on Di…
⤷ Title: Critical HCL BigFix Vulnerabilities Expose Admin Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_18963 #CVE_2026_67100 #CVE_2026_67101 #HCL BigFix #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_18963 #CVE_2026_67100 #CVE_2026_67101 #HCL BigFix #sql injection
Daily CyberSecurity
Critical HCL BigFix Vulnerabilities Expose Admin Accounts
HCL Technologies released security updates, addressing five severe HCL BigFix vulnerabilities. These critical software defects allow unauthenticated attackers to execute arbitrary database command…
⤷ Title: 4 Linux Kernel LPE Flaws Disclosed With Public PoC Exploits
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_80844 #CVE_2026_81000 #DirtyAH6 #Linux Kernel #Local Privilege Escalation #privilege escalation #proof_of_concept
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_80844 #CVE_2026_81000 #DirtyAH6 #Linux Kernel #Local Privilege Escalation #privilege escalation #proof_of_concept
Daily CyberSecurity
4 Linux Kernel LPE Flaws Disclosed With Public PoC Exploits
TL;DR A researcher disclosed four Linux kernel privilege escalation flaws on September 18, 2026. Each one can give a local user root on affected systems. The full technical details and proof-of-co…