⤷ Title: MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 21:36:41 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 21:36:41 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:19:17 +0000
════════════════════════
⌗ Tags: #Data Breaches #Artificial Intelligence #Security #AI #AI Agents #Credit Cards #Cyber Attack #Cyber Crime #Cybersecurity #data breach #Gambit Security
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:19:17 +0000
════════════════════════
⌗ Tags: #Data Breaches #Artificial Intelligence #Security #AI #AI Agents #Credit Cards #Cyber Attack #Cyber Crime #Cybersecurity #data breach #Gambit Security
Hackread
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
⤷ Title: I Bypassed OTP Verification by Changing One Response
════════════════════════
𐀪 Author: Sahilmaurya
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:29:09 GMT
════════════════════════
⌗ Tags: #otp_bypass #bug_bounty_writeup #bug_bounty #otp_verification #hacking
════════════════════════
𐀪 Author: Sahilmaurya
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:29:09 GMT
════════════════════════
⌗ Tags: #otp_bypass #bug_bounty_writeup #bug_bounty #otp_verification #hacking
Medium
I Bypassed OTP Verification by Changing One Response
How a simple response manipulation allowed me to continue registration without a valid OTP
⤷ Title: I Took Over a Media Giant’s Subdomain with a Free Netlify Account and a Ten-Minute Attention Span
════════════════════════
𐀪 Author: Abdul Moeez Khan
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 15:52:02 GMT
════════════════════════
⌗ Tags: #dns #cybersecurity #bug_bounty #penetration_testing #infosec
════════════════════════
𐀪 Author: Abdul Moeez Khan
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 15:52:02 GMT
════════════════════════
⌗ Tags: #dns #cybersecurity #bug_bounty #penetration_testing #infosec
Medium
I Took Over a Media Giant’s Subdomain with a Free Netlify Account and a Ten-Minute Attention Span
A story about a forgotten CNAME record, a platform that trusts you a little too much, and why “it’s just a subdomain” is the wrong way to…
⤷ Title: 153 Million Driver’s Licenses Just Leaked on the Dark Web
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:33:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #darkweb #identity_theft #data_breach
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:33:40 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #darkweb #identity_theft #data_breach
Medium
153 Million Driver’s Licenses Just Leaked on the Dark Web
A researcher searched a dark web database with no query at all — just hit “search” — and got back 11.5 million pages of results.
⤷ Title: The Login Field That Could Hand Attackers Root on Your Firewall’s Brain
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:33:12 GMT
════════════════════════
⌗ Tags: #network_security #infosec #technews #cybersecurity #vulnerability_management
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:33:12 GMT
════════════════════════
⌗ Tags: #network_security #infosec #technews #cybersecurity #vulnerability_management
Medium
The Login Field That Could Hand Attackers Root on Your Firewall’s Brain
The Login Field That Could Hand Attackers Root on Your Firewall’s Brain
⤷ Title: The Linux cmp Command: A SOC Analyst’s Guide to Byte-Level File Comparison
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:33:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #soc #file_integrity_monitoring #linux
════════════════════════
𐀪 Author: Xpert4Cyber
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:33:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #soc #file_integrity_monitoring #linux
Medium
The Linux cmp Command: A SOC Analyst’s Guide to Byte-Level File Comparison
It was 2 a.m. when a SOC analyst noticed something small but wrong: a configuration file on a backup server had a modified timestamp — but…
⤷ Title: Critical Next.js SVG Vulnerability Shows How Image Generation Can Become a Server Attack Surface
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:15:05 GMT
════════════════════════
⌗ Tags: #software_security #cybersecurity #opensource_security #cloud_security #penetration_testing
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:15:05 GMT
════════════════════════
⌗ Tags: #software_security #cybersecurity #opensource_security #cloud_security #penetration_testing
Medium
Critical Next.js SVG Vulnerability Shows How Image Generation Can Become a Server Attack Surface
Modern web applications increasingly generate images dynamically for social media previews, Open Graph metadata, dashboards, personalized…
⤷ Title: AWS Attack Surface: How a Security Researcher Sees AWS
════════════════════════
𐀪 Author: Paraskhorwal
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:50:39 GMT
════════════════════════
⌗ Tags: #information_security #aws #cloud_computing #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Paraskhorwal
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:50:39 GMT
════════════════════════
⌗ Tags: #information_security #aws #cloud_computing #penetration_testing #cybersecurity
Medium
AWS Attack Surface: How a Security Researcher Sees AWS
An AWS environment is more than a list of public IPs. A useful attack-surface map connects accounts, regions, resources, identities…
⤷ Title: Portal Drop | TryHackMe CTF Writeup
════════════════════════
𐀪 Author: Wynn
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:27:33 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #ctf #ctf_writeup #cybersecurity
════════════════════════
𐀪 Author: Wynn
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:27:33 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #ctf #ctf_writeup #cybersecurity
Medium
Portal Drop | TryHackMe CTF Writeup
Access room: https://tryhackme.com/room/portaldrop
⤷ Title: Community Cyber Safety Benefits: Preventing Small Business Ransomware | Protecting Municipal…
════════════════════════
𐀪 Author: SMATCHOICHEHACKERS NEWS
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:17:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking #community_management #ransomware_prevention #secure_business #cybersecurity
════════════════════════
𐀪 Author: SMATCHOICHEHACKERS NEWS
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:17:59 GMT
════════════════════════
⌗ Tags: #ethical_hacking #community_management #ransomware_prevention #secure_business #cybersecurity
Medium
Community Cyber Safety Benefits: Preventing Small Business Ransomware | Protecting Municipal Digital Services - Smatchoicehackers.com
Cyber Safety
⤷ Title: Connected HTB Writeup
════════════════════════
𐀪 Author: Tinny
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:26:05 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ctf #security #pentesting #cybersecurity
════════════════════════
𐀪 Author: Tinny
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:26:05 GMT
════════════════════════
⌗ Tags: #ethical_hacking #ctf #security #pentesting #cybersecurity
Medium
Connected HTB Writeup
Rooting FreePBX: From CVE-2025–57819 to Root via DAHDI and incron
⤷ Title: PortSwigger Lab: Web shell upload via extension blacklist bypass
════════════════════════
𐀪 Author: sa0k0
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:20:29 GMT
════════════════════════
⌗ Tags: #file_upload #htaccess #rce #burpsuite #extension_blacklist
════════════════════════
𐀪 Author: sa0k0
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 17:20:29 GMT
════════════════════════
⌗ Tags: #file_upload #htaccess #rce #burpsuite #extension_blacklist
Medium
PortSwigger Lab: Web shell upload via extension blacklist bypass
Lab Information:
⤷ Title: Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 23:36:30 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 23:36:30 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Apache Doris Vulnerabilities Patched in New Updates
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:29:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Doris #CVE_2026_31377 #CVE_2026_96443 #cybersecurity #database security #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 16:29:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Doris #CVE_2026_31377 #CVE_2026_96443 #cybersecurity #database security #Remote Code Execution #Vulnerability
Daily CyberSecurity
Apache Doris Vulnerabilities Patched in New Updates
TL;DR The Apache Software Foundation addressed two security flaws in its real-time analytics database. These Apache Doris vulnerabilities allow remote attackers to access cluster metadata or execu…
⤷ Title: When a UUID Becomes a Password: Principal-Unbound Capabilities in Nezha
════════════════════════
𐀪 Author: Berkan SAL
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 19:30:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability_research #web_security #bug_bounty #authorization
════════════════════════
𐀪 Author: Berkan SAL
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 19:30:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability_research #web_security #bug_bounty #authorization
Medium
When a UUID Becomes a Password: Principal-Unbound Capabilities in Nezha
A random identifier can be impossible to guess and still be an authorization vulnerability.
⤷ Title: $5,400 for a Regex That Trusted the Wrong Domain: CORS Misconfiguration to Full Account Data Theft
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 19:06:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #pentesting #cybersecurity #security
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 19:06:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #pentesting #cybersecurity #security
Medium
$5,400 for a Regex That Trusted the Wrong Domain: CORS Misconfiguration to Full Account Data Theft
Some vulnerabilities take real cleverness to find. This one took reading a single response header carefully enough to notice it was doing…
⤷ Title: The OWASP Top 10 Is Not a Checklist — It’s a Way of Thinking
════════════════════════
𐀪 Author: Jakkali Lokesh
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 18:47:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #ethical_hacking #information_security #bug_bounty
════════════════════════
𐀪 Author: Jakkali Lokesh
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 18:47:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #ethical_hacking #information_security #bug_bounty
Medium
The OWASP Top 10 Is Not a Checklist — It’s a Way of Thinking
A practical 2026 guide to finding broken trust, bad assumptions, and real security flaws in modern web applications.
⤷ Title: IRC Cloudflare Blocklist CTF | Full Penetration Testing Challenge
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 18:26:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #artificial_intelligence #hacking #bug_bounty
════════════════════════
𐀪 Author: Pentester Club
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 18:26:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #artificial_intelligence #hacking #bug_bounty
Medium
🔥 IRC Cloudflare Blocklist CTF | Full Penetration Testing Challenge
What happens when an apparently simple CTF combines IRC, web reconnaissance, IP blocklists, Cloudflare security controls, HTTP behavior…
⤷ Title: VAPT Day 2: Planning, Scoping & Rules of Engagement
My VAPT Learning Journey — Day 2
When people…
════════════════════════
𐀪 Author: saurabh
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 19:52:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity #ethical_hacking #security
My VAPT Learning Journey — Day 2
When people…
════════════════════════
𐀪 Author: saurabh
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 19:52:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #cybersecurity #ethical_hacking #security
Medium
VAPT Day 2: Planning, Scoping & Rules of Engagement
My VAPT Learning Journey — Day 2
When people…
My VAPT Learning Journey — Day 2
When people…
VAPT Day 2: Planning, Scoping & Rules of Engagement My VAPT Learning Journey — Day 2 When people think about penetration testing, they often imagine tools such as Nmap, Burp Suite, Metasploit …
⤷ Title: An AI Agent Swarm Hit 440 PaperCut Servers in 26 Seconds Per Target.
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 18:40:11 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #ai_agent #information_security #hacking
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 18:40:11 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #ai_agent #information_security #hacking
Medium
An AI Agent Swarm Hit 440 PaperCut Servers in 26 Seconds Per Target. The Education Sector Didn’t Stand a Chance.
How a Russian-speaking threat actor used OpenAI Codex and DeepSeek to build the fastest credential-to-domain-admin pipeline we’ve ever…