⤷ Title: How a Random Password-less “SSO Token” Let a Full Account Takeover
════════════════════════
𐀪 Author: #$ubh@nk@r
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:25:04 GMT
════════════════════════
⌗ Tags: #infosec #web_security #cybersecurity #hacker #bug_bounty
════════════════════════
𐀪 Author: #$ubh@nk@r
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:25:04 GMT
════════════════════════
⌗ Tags: #infosec #web_security #cybersecurity #hacker #bug_bounty
Medium
How a Random Password-less “SSO Token” Let a Full Account Takeover
What’s up folks. So this one wasn’t some deep, multi-hour recon grind — it was one of those bugs that just falls into your lap while you’re…
⤷ Title: CVE-2026–2619: How a Read-Only GitLab Auditor Could Modify Vulnerability Flags
════════════════════════
𐀪 Author: KabishDahal
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:51:38 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty_writeup #gitlab #access_control #cybersecurity
════════════════════════
𐀪 Author: KabishDahal
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:51:38 GMT
════════════════════════
⌗ Tags: #application_security #bug_bounty_writeup #gitlab #access_control #cybersecurity
Medium
CVE-2026–2619: How a Read-Only GitLab Auditor Could Modify Vulnerability Flags
An authorization flaw in GitLab’s AI detection API, the evidence behind my report, and the permission change that fixed it.
⤷ Title: Visitor Management as an Essential Part of Corporate Security
════════════════════════
𐀪 Author: PT Neuronworks Indonesia
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:22:00 GMT
════════════════════════
⌗ Tags: #systems_thinking #visitor_experience #neuronworks #application_security #security
════════════════════════
𐀪 Author: PT Neuronworks Indonesia
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:22:00 GMT
════════════════════════
⌗ Tags: #systems_thinking #visitor_experience #neuronworks #application_security #security
Medium
Visitor Management as an Essential Part of Corporate Security
A company lobby is often the first point of contact between visitors and the workplace. Behind the reception process, however, there are…
⤷ Title: The Life and Death of Browser Security
════════════════════════
𐀪 Author: Danny Lin
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:54:13 GMT
════════════════════════
⌗ Tags: #browser_security #cloudmosa #infosec #cybersecurity #ai_assisted_threats
════════════════════════
𐀪 Author: Danny Lin
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:54:13 GMT
════════════════════════
⌗ Tags: #browser_security #cloudmosa #infosec #cybersecurity #ai_assisted_threats
Medium
The Life and Death of Browser Security
The browser was never meant to become a battlefield.
⤷ Title: I Scored 10 Pentesting Vendors on Whether Their “AI” Actually Tests Anything
════════════════════════
𐀪 Author: Anonymous brat
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:23:57 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #pentesting #ai_agent #ai
════════════════════════
𐀪 Author: Anonymous brat
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:23:57 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #pentesting #ai_agent #ai
Medium
I Scored 10 Pentesting Vendors on Whether Their “AI” Actually Tests Anything
Most AI claims on pentest vendor pages are true. A surprising number just aren’t about pentesting.
⤷ Title: Escaping the Image Folder: File Path Traversal, Simple Case
════════════════════════
𐀪 Author: Kaustubh Asthana
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:18:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #web_penetration_testing #burpsuite #portswigger
════════════════════════
𐀪 Author: Kaustubh Asthana
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:18:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #web_penetration_testing #burpsuite #portswigger
Medium
Escaping the Image Folder: File Path Traversal, Simple Case
Lab eight in my Web Security Academy series — the first one where the vulnerability lives in the filesystem, not the login form
⤷ Title: My First Cybersecurity Lab: What I Learned from TryHackMe
════════════════════════
𐀪 Author: Oduwaugo
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:16:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybersecurity_careers #learning_in_public #tryhackme #information_security
════════════════════════
𐀪 Author: Oduwaugo
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:16:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybersecurity_careers #learning_in_public #tryhackme #information_security
Medium
My First Cybersecurity Lab: What I Learned from TryHackMe
Moving from cybersecurity theory to hands-on practice and what my first lab experience taught me.
⤷ Title: Reset Password Vulnerability
════════════════════════
𐀪 Author: Sourabh Jala
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:31:01 GMT
════════════════════════
⌗ Tags: #reset_password_root #authentication #cybersecurity #ethical_hacking #testing
════════════════════════
𐀪 Author: Sourabh Jala
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 07:31:01 GMT
════════════════════════
⌗ Tags: #reset_password_root #authentication #cybersecurity #ethical_hacking #testing
Medium
Reset Password Vulnerability
Authentication / Password Reset Testing
⤷ Title: Apache Struts 2 REST Plugin XStream Deserialization: When XML Requests Become Remote Code Execution
════════════════════════
𐀪 Author: EternalSec
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:24:01 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #rce #web_security #cybersecurity #apache_struts_2
════════════════════════
𐀪 Author: EternalSec
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:24:01 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #rce #web_security #cybersecurity #apache_struts_2
Medium
Apache Struts 2 REST Plugin XStream Deserialization: When XML Requests Become Remote Code Execution
A trusted XML request should never be able to decide which Java objects your server creates.
⤷ Title: Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:03 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:03 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Synology DSM Patches 8 Flaws, Two Critical Unauthenticated
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:41:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_13639 #CVE_2026_13684 #DiskStation Manager #DSM #NAS security #Synology
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:41:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_13639 #CVE_2026_13684 #DiskStation Manager #DSM #NAS security #Synology
Daily CyberSecurity
Synology DSM Patches 8 Flaws, Two Critical Unauthenticated
TL;DR Synology patched eight Synology DSM vulnerabilities in advisory SA_26_13. Two are critical and need no login. Both let a remote attacker read or write files and cause denial of service on Di…
⤷ Title: Critical HCL BigFix Vulnerabilities Expose Admin Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_18963 #CVE_2026_67100 #CVE_2026_67101 #HCL BigFix #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_18963 #CVE_2026_67100 #CVE_2026_67101 #HCL BigFix #sql injection
Daily CyberSecurity
Critical HCL BigFix Vulnerabilities Expose Admin Accounts
HCL Technologies released security updates, addressing five severe HCL BigFix vulnerabilities. These critical software defects allow unauthenticated attackers to execute arbitrary database command…
⤷ Title: 4 Linux Kernel LPE Flaws Disclosed With Public PoC Exploits
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_80844 #CVE_2026_81000 #DirtyAH6 #Linux Kernel #Local Privilege Escalation #privilege escalation #proof_of_concept
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_80844 #CVE_2026_81000 #DirtyAH6 #Linux Kernel #Local Privilege Escalation #privilege escalation #proof_of_concept
Daily CyberSecurity
4 Linux Kernel LPE Flaws Disclosed With Public PoC Exploits
TL;DR A researcher disclosed four Linux kernel privilege escalation flaws on September 18, 2026. Each one can give a local user root on affected systems. The full technical details and proof-of-co…
⤷ Title: PAPERMILL Cybercrime Cluster Delivers VenomRAT via Tax Lures
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:00:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DLL Sideloading #PAPERMILL #Silver Fox #VenomRAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:00:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DLL Sideloading #PAPERMILL #Silver Fox #VenomRAT
Daily CyberSecurity
PAPERMILL Cybercrime Cluster Delivers VenomRAT via Tax Lures
At a glance Actor or group: PAPERMILL (suspected Silver Fox-adjacent cluster) Activity type: Tax-themed phishing, DLL sideloading, and remote access trojan deployment Targets or victims: Enterpris…
⤷ Title: Mass Assignment to Admin: How a Missing Allow-List Let Me Self-Promote to Administrator
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:23:20 GMT
════════════════════════
⌗ Tags: #bola #penetration_testing #bug_bounty #mass_assignment
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:23:20 GMT
════════════════════════
⌗ Tags: #bola #penetration_testing #bug_bounty #mass_assignment
Medium
Mass Assignment to Admin: How a Missing Allow-List Let Me Self-Promote to Administrator
CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes CWE-269: Improper Privilege Management CVSS 3.1…
⤷ Title: Google Just Warned That AI Agents Are Hunting Bugs for Hackers.
════════════════════════
𐀪 Author: Riya Limba
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:19:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Riya Limba
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:19:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #bug_bounty_tips #bug_bounty_writeup
Medium
Google Just Warned That AI Agents Are Hunting Bugs for Hackers. Here’s What That Means for Bug Bounty Beginners Like Me.
A mass credential-harvesting campaign was completed in under six hours. No human sat at the keyboard for most of it.
⤷ Title: How I Use AI for Bug Hunting (Without Losing My Mind)
════════════════════════
𐀪 Author: Sukhveer Singh
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:13:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_hunting #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Sukhveer Singh
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:13:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_hunting #bug_bounty_tips #bug_bounty_writeup
Medium
How I Use AI for Bug Hunting (Without Losing My Mind)
I used to spend hours grepping through code, chasing false positives, and manually testing endpoints until my eyes glazed over. Now I let…
⤷ Title: Web LLM Attacks: Understanding the New Web Application Attack Surface
════════════════════════
𐀪 Author: Mazen Elsayed
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:46:59 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #artificial_intelligence #llm
════════════════════════
𐀪 Author: Mazen Elsayed
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:46:59 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #artificial_intelligence #llm
Medium
Web LLM Attacks: Understanding the New Web Application Attack Surface
Introduction
⤷ Title: How WPA-PSK Works—and How Hackers Crack Weak Wi-Fi Passwords
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:09:08 GMT
════════════════════════
⌗ Tags: #hacking #wifihacking #programming #research #cybersecurity
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:09:08 GMT
════════════════════════
⌗ Tags: #hacking #wifihacking #programming #research #cybersecurity
Medium
How WPA-PSK Works—and How Hackers Crack Weak Wi-Fi Passwords
A practical journey through WPA-PSK architecture, the 4-way handshake, handshake capture, and password cracking using all kinds of probable…
⤷ Title: HackTheBox — Orion Writeup: 15 Minutes to User, 90 Minutes of Overthinking to Root
════════════════════════
𐀪 Author: PhongTapCode
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:24:02 GMT
════════════════════════
⌗ Tags: #ctf_writeup #pentesting #infosec #hackthebox #ctf
════════════════════════
𐀪 Author: PhongTapCode
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:24:02 GMT
════════════════════════
⌗ Tags: #ctf_writeup #pentesting #infosec #hackthebox #ctf
Medium
HackTheBox — Orion Writeup: 15 Minutes to User, 90 Minutes of Overthinking to Root
The title says it all: 15 minutes to snag user.txt, and a painful 90 minutes wasted looking for something I had already seen. How did I end…
⤷ Title: Reflected XSS via dangerouslySetInnerHTML: When the API Is Safe but the Frontend Isn’t
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:12:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #reflected_xss #xss_attack #xss_vulnerability
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:12:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #reflected_xss #xss_attack #xss_vulnerability
Medium
Reflected XSS via dangerouslySetInnerHTML: When the API Is Safe but the Frontend Isn’t
CWE-79: Improper Neutralization of Input During Web Page Generation CVSS 3.1: 6.1 (Medium) — AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N