⤷ Title: Apache Struts 2 REST Plugin XStream Deserialization: When XML Requests Become Remote Code Execution
════════════════════════
𐀪 Author: EternalSec
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:24:01 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #rce #web_security #cybersecurity #apache_struts_2
════════════════════════
𐀪 Author: EternalSec
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 06:24:01 GMT
════════════════════════
⌗ Tags: #vulnerability_assessment #rce #web_security #cybersecurity #apache_struts_2
Medium
Apache Struts 2 REST Plugin XStream Deserialization: When XML Requests Become Remote Code Execution
A trusted XML request should never be able to decide which Java objects your server creates.
⤷ Title: Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:03 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 14:48:03 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Synology DSM Patches 8 Flaws, Two Critical Unauthenticated
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:41:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_13639 #CVE_2026_13684 #DiskStation Manager #DSM #NAS security #Synology
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:41:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_13639 #CVE_2026_13684 #DiskStation Manager #DSM #NAS security #Synology
Daily CyberSecurity
Synology DSM Patches 8 Flaws, Two Critical Unauthenticated
TL;DR Synology patched eight Synology DSM vulnerabilities in advisory SA_26_13. Two are critical and need no login. Both let a remote attacker read or write files and cause denial of service on Di…
⤷ Title: Critical HCL BigFix Vulnerabilities Expose Admin Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_18963 #CVE_2026_67100 #CVE_2026_67101 #HCL BigFix #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_18963 #CVE_2026_67100 #CVE_2026_67101 #HCL BigFix #sql injection
Daily CyberSecurity
Critical HCL BigFix Vulnerabilities Expose Admin Accounts
HCL Technologies released security updates, addressing five severe HCL BigFix vulnerabilities. These critical software defects allow unauthenticated attackers to execute arbitrary database command…
⤷ Title: 4 Linux Kernel LPE Flaws Disclosed With Public PoC Exploits
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_80844 #CVE_2026_81000 #DirtyAH6 #Linux Kernel #Local Privilege Escalation #privilege escalation #proof_of_concept
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_80844 #CVE_2026_81000 #DirtyAH6 #Linux Kernel #Local Privilege Escalation #privilege escalation #proof_of_concept
Daily CyberSecurity
4 Linux Kernel LPE Flaws Disclosed With Public PoC Exploits
TL;DR A researcher disclosed four Linux kernel privilege escalation flaws on September 18, 2026. Each one can give a local user root on affected systems. The full technical details and proof-of-co…
⤷ Title: PAPERMILL Cybercrime Cluster Delivers VenomRAT via Tax Lures
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:00:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DLL Sideloading #PAPERMILL #Silver Fox #VenomRAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:00:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DLL Sideloading #PAPERMILL #Silver Fox #VenomRAT
Daily CyberSecurity
PAPERMILL Cybercrime Cluster Delivers VenomRAT via Tax Lures
At a glance Actor or group: PAPERMILL (suspected Silver Fox-adjacent cluster) Activity type: Tax-themed phishing, DLL sideloading, and remote access trojan deployment Targets or victims: Enterpris…
⤷ Title: Mass Assignment to Admin: How a Missing Allow-List Let Me Self-Promote to Administrator
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:23:20 GMT
════════════════════════
⌗ Tags: #bola #penetration_testing #bug_bounty #mass_assignment
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:23:20 GMT
════════════════════════
⌗ Tags: #bola #penetration_testing #bug_bounty #mass_assignment
Medium
Mass Assignment to Admin: How a Missing Allow-List Let Me Self-Promote to Administrator
CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes CWE-269: Improper Privilege Management CVSS 3.1…
⤷ Title: Google Just Warned That AI Agents Are Hunting Bugs for Hackers.
════════════════════════
𐀪 Author: Riya Limba
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:19:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Riya Limba
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:19:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #bug_bounty_tips #bug_bounty_writeup
Medium
Google Just Warned That AI Agents Are Hunting Bugs for Hackers. Here’s What That Means for Bug Bounty Beginners Like Me.
A mass credential-harvesting campaign was completed in under six hours. No human sat at the keyboard for most of it.
⤷ Title: How I Use AI for Bug Hunting (Without Losing My Mind)
════════════════════════
𐀪 Author: Sukhveer Singh
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:13:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_hunting #bug_bounty_tips #bug_bounty_writeup
════════════════════════
𐀪 Author: Sukhveer Singh
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:13:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_hunting #bug_bounty_tips #bug_bounty_writeup
Medium
How I Use AI for Bug Hunting (Without Losing My Mind)
I used to spend hours grepping through code, chasing false positives, and manually testing endpoints until my eyes glazed over. Now I let…
⤷ Title: Web LLM Attacks: Understanding the New Web Application Attack Surface
════════════════════════
𐀪 Author: Mazen Elsayed
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:46:59 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #artificial_intelligence #llm
════════════════════════
𐀪 Author: Mazen Elsayed
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:46:59 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #artificial_intelligence #llm
Medium
Web LLM Attacks: Understanding the New Web Application Attack Surface
Introduction
⤷ Title: How WPA-PSK Works—and How Hackers Crack Weak Wi-Fi Passwords
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:09:08 GMT
════════════════════════
⌗ Tags: #hacking #wifihacking #programming #research #cybersecurity
════════════════════════
𐀪 Author: A. AntorCSE404
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:09:08 GMT
════════════════════════
⌗ Tags: #hacking #wifihacking #programming #research #cybersecurity
Medium
How WPA-PSK Works—and How Hackers Crack Weak Wi-Fi Passwords
A practical journey through WPA-PSK architecture, the 4-way handshake, handshake capture, and password cracking using all kinds of probable…
⤷ Title: HackTheBox — Orion Writeup: 15 Minutes to User, 90 Minutes of Overthinking to Root
════════════════════════
𐀪 Author: PhongTapCode
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:24:02 GMT
════════════════════════
⌗ Tags: #ctf_writeup #pentesting #infosec #hackthebox #ctf
════════════════════════
𐀪 Author: PhongTapCode
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:24:02 GMT
════════════════════════
⌗ Tags: #ctf_writeup #pentesting #infosec #hackthebox #ctf
Medium
HackTheBox — Orion Writeup: 15 Minutes to User, 90 Minutes of Overthinking to Root
The title says it all: 15 minutes to snag user.txt, and a painful 90 minutes wasted looking for something I had already seen. How did I end…
⤷ Title: Reflected XSS via dangerouslySetInnerHTML: When the API Is Safe but the Frontend Isn’t
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:12:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #reflected_xss #xss_attack #xss_vulnerability
════════════════════════
𐀪 Author: Neel Chauhan
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:12:55 GMT
════════════════════════
⌗ Tags: #penetration_testing #reflected_xss #xss_attack #xss_vulnerability
Medium
Reflected XSS via dangerouslySetInnerHTML: When the API Is Safe but the Frontend Isn’t
CWE-79: Improper Neutralization of Input During Web Page Generation CVSS 3.1: 6.1 (Medium) — AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
⤷ Title: Content Discovery | TryHackMe
════════════════════════
𐀪 Author: Tabrizabuzarov
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:01:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Tabrizabuzarov
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 08:01:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing
Medium
Content Discovery | TryHackMe
Hesabat / Write-up: TryHackMe-də Veb Enumeration (Acme IT Support / THM Web Framework)
⤷ Title: Jax Sucks Alot (THM) Walkthrough
════════════════════════
𐀪 Author: L4ZZ3RJ0D
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:10 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #info_sec_writeups #tryhackme #insecure_deserialization
════════════════════════
𐀪 Author: L4ZZ3RJ0D
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:25:10 GMT
════════════════════════
⌗ Tags: #ctf #tryhackme_walkthrough #info_sec_writeups #tryhackme #insecure_deserialization
Medium
Jax Sucks Alot (THM) Walkthrough
“In JavaScript, everything is a terrible mistake.” Horror LLC said it themselves, right there in the brief, and by the end of this room I…
⤷ Title: 10 GitHub Repositories Every Blue Teamer Must Bookmark
════════════════════════
𐀪 Author: Munaza Cyber
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:10:10 GMT
════════════════════════
⌗ Tags: #soc_analyst #tech #cybersecurity #careers #ethical_hacking
════════════════════════
𐀪 Author: Munaza Cyber
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:10:10 GMT
════════════════════════
⌗ Tags: #soc_analyst #tech #cybersecurity #careers #ethical_hacking
Medium
10 GitHub Repositories Every Blue Teamer Must Bookmark
If you're learning blue teaming, SOC analysis, threat hunting, incident response, or detection engineering, GitHub can become one of your…
⤷ Title: What Is Ethical Hacking? A Complete Beginner’s Guide to Ethical Hacking
════════════════════════
𐀪 Author: QNAYDS Academy
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:05:31 GMT
════════════════════════
⌗ Tags: #beginners_guide #qnayds #ethical_hacking #manjeri #cybersecurity
════════════════════════
𐀪 Author: QNAYDS Academy
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 09:05:31 GMT
════════════════════════
⌗ Tags: #beginners_guide #qnayds #ethical_hacking #manjeri #cybersecurity
Medium
What Is Ethical Hacking? A Complete Beginner’s Guide to Ethical Hacking
What Is Ethical Hacking?
⤷ Title: WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 16:10:06 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 16:10:06 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Markdown Renderers: The XSS Factory Hiding in Every Modern App
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #ethical_hacking #bug_bounty_tips #cybersecurity
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #ethical_hacking #bug_bounty_tips #cybersecurity
⤷ Title: How to Pick the Right Penetration Test When There Are More Than a Dozen Kinds
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:31:15 GMT
════════════════════════
⌗ Tags: #infosec #application_security #penetration_testing #cloud_security #cybersecurity
════════════════════════
𐀪 Author: Invadel
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:31:15 GMT
════════════════════════
⌗ Tags: #infosec #application_security #penetration_testing #cloud_security #cybersecurity
Medium
How to Pick the Right Penetration Test When There Are More Than a Dozen Kinds
A buyer’s map of pentest types by target, tester knowledge, starting point and cadence, and a plain way to choose your first one
⤷ Title: OpenAI Got Hacked by Anthropic’s AI Models
════════════════════════
𐀪 Author: Jim Clyde Monge
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:05:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #anthropics #hacking #hacktronai #openai
════════════════════════
𐀪 Author: Jim Clyde Monge
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 11:05:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #anthropics #hacking #hacktronai #openai
Medium
OpenAI Got Hacked by Anthropic’s AI Models
How three researchers used Opus 5 to compromise the world’s most powerful AI company in under 72 hours.