⤷ Title: ⚠️ Postman e a Exposição de Segredos: O Que Você Precisa Saber
════════════════════════
𐀪 Author: Fernando Silva
════════════════════════
ⴵ Time: Sun, 25 May 2025 22:40:56 GMT
════════════════════════
⌗ Tags: #security #data_exploration #appsec #api_security
════════════════════════
𐀪 Author: Fernando Silva
════════════════════════
ⴵ Time: Sun, 25 May 2025 22:40:56 GMT
════════════════════════
⌗ Tags: #security #data_exploration #appsec #api_security
Medium
⚠️ Postman e a Exposição de Segredos: O Que Você Precisa Saber
O Postman é uma ferramenta extremamente popular entre desenvolvedores para testar APIs e facilitar a colaboração em ambientes de…
⤷ Title: Sara: RouterOS Security Inspector
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:30:55 +0000
════════════════════════
⌗ Tags: #Data Forensics #Network Defense #Vulnerability Assessment #RouterOS #RouterOS Security #Sara #security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:30:55 +0000
════════════════════════
⌗ Tags: #Data Forensics #Network Defense #Vulnerability Assessment #RouterOS #RouterOS Security #Sara #security
Penetration Testing Tools
Sara: RouterOS Security Inspector
Sara uses netmiko to remotely connect via SSH to RouterOS devices. It executes RouterOS system commands to extract configuration data and analyze it
⤷ Title: ulexecve: Execute dynamic or statically compiled ELF Linux binaries without ever calling execve()
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:11:30 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #anti_forensics
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:11:30 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #anti_forensics
Penetration Testing Tools
ulexecve: Execute dynamic or statically compiled ELF Linux binaries without ever calling execve()
on a target machine and then being able to execute this script to then stealthily execute arbitrary binaries is very useful from an anti-forensic
⤷ Title: Critical Pre-Auth RCE: vBulletin Flaw Allows Full Server Compromise (PoC Available)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:50:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #php #PoC #pre_authentication #rce #Remote Code Execution #security #vBulletin
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:50:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #php #PoC #pre_authentication #rce #Remote Code Execution #security #vBulletin
Daily CyberSecurity
Critical Pre-Auth RCE: vBulletin Flaw Allows Full Server Compromise (PoC Available)
A critical pre-authentication RCE vulnerability in vBulletin 5.x and 6.x allows full server compromise. A PoC exploit is available.
⤷ Title: Critical WSO2 Flaw: Unauthenticated Account Takeover Risk (CVSS 9.8)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:44:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #cybersecurity #SOAP service #WSO2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:44:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Account Takeover #cybersecurity #SOAP service #WSO2
Daily CyberSecurity
Critical WSO2 Flaw: Unauthenticated Account Takeover Risk (CVSS 9.8)
A critical WSO2 vulnerability (CVE-2024-6914, CVSS 9.8) allows unauthenticated account takeover via a SOAP service, including admin access.
⤷ Title: Sony Camera Hack (CVSS 9.4): Default Credential Flaw Risks Full Control (PoC)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:40:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #camera vulnerability #CVSS 9.4 #cybersecurity #default credentials #PoC #SNC_series #sony
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:40:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #camera vulnerability #CVSS 9.4 #cybersecurity #default credentials #PoC #SNC_series #sony
Daily CyberSecurity
Sony Camera Hack (CVSS 9.4): Default Credential Flaw Risks Full Control (PoC)
A high-severity vulnerability (CVSS 9.4) in Sony SNC-series cameras allows remote admin access due to hard-coded default credentials. PoC exists.
⤷ Title: Decade of Stealth: China-Linked TA-ShadowCricket Targets Asia-Pacific
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:35:48 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #china #cyber_espionage #cybersecurity #malware #Shadow Force #TA_ShadowCricket
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:35:48 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #china #cyber_espionage #cybersecurity #malware #Shadow Force #TA_ShadowCricket
Daily CyberSecurity
Decade of Stealth: China-Linked TA-ShadowCricket Targets Asia-Pacific
TA-ShadowCricket (formerly Shadow Force), a China-linked group, has been active for over a decade, targeting Asia-Pacific government and enterprise networks.
⤷ Title: DOUBLELOADER Malware Uses ALCATRAZ Obfuscator to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:30:39 +0000
════════════════════════
⌗ Tags: #Malware #ALCATRAZ #cybersecurity #DOUBLELOADER #Infostealer #malware #Obfuscation #Rhadamanthys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:30:39 +0000
════════════════════════
⌗ Tags: #Malware #ALCATRAZ #cybersecurity #DOUBLELOADER #Infostealer #malware #Obfuscation #Rhadamanthys
Daily CyberSecurity
DOUBLELOADER Malware Uses ALCATRAZ Obfuscator to Evade Detection
A new malware family, DOUBLELOADER, leverages the ALCATRAZ obfuscator to deploy RHADAMANTHYS infostealer with advanced evasion techniques.
⤷ Title: NPM Recon: Malicious Packages Found Stealing Internal Network IPs and Hostnames
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:24:19 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Data Theft #developer #malware #network mapping #npm #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:24:19 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Data Theft #developer #malware #network mapping #npm #Supply Chain
Daily CyberSecurity
NPM Recon: Malicious Packages Found Stealing Internal Network IPs and Hostnames
An active npm malware campaign uses over 60 packages to steal internal/external IP addresses, hostnames, and user paths, designed for enterprise network mapping.
⤷ Title: Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:20:40 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #Government #malware #phishing #russia #TAG_110 #Tajikistan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:20:40 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #Government #malware #phishing #russia #TAG_110 #Tajikistan
Daily CyberSecurity
Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
Russian-aligned TAG-110 (APT28) is launching a cyber-espionage campaign using macro-enabled Word docs to target Tajikistan's public sector for intelligence.
⤷ Title: Persistent DoS: Unauthenticated Attacker Crashes GNOME RDP (Even After Systemd)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cyber Threat #dos #gnome #Linux #RDP #security #systemd #unauthenticated
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cyber Threat #dos #gnome #Linux #RDP #security #systemd #unauthenticated
Daily CyberSecurity
Persistent DoS: Unauthenticated Attacker Crashes GNOME RDP (Even After Systemd)
An unauthenticated flaw in GNOME's remote desktop (CVE-2025-5024) allows attackers to repeatedly crash Linux environments, preventing recovery even after systemd restarts.
⤷ Title: Qakbot Mastermind Indicted: Russian Architect of $50M Malware Empire Charged
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:12:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #botnet #Cybercrime #DOJ #indictment #malware #QakBot #ransomware #Rustam Rafailevich Gallyamov
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:12:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #botnet #Cybercrime #DOJ #indictment #malware #QakBot #ransomware #Rustam Rafailevich Gallyamov
Daily CyberSecurity
Qakbot Mastermind Indicted: Russian Architect of $50M Malware Empire Charged
The alleged architect of the Qakbot malware empire, Rustam Rafailevich Gallyamov, has been indicted, facing charges and a $24M crypto seizure.
⤷ Title: Chrome Web Store Under Siege: 40+ Malicious Extensions Found Stealing Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:09:04 +0000
════════════════════════
⌗ Tags: #Malware #browser hijacking #Chrome extensions #cybersecurity #data exfiltration #deception #malware #phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:09:04 +0000
════════════════════════
⌗ Tags: #Malware #browser hijacking #Chrome extensions #cybersecurity #data exfiltration #deception #malware #phishing
Daily CyberSecurity
Chrome Web Store Under Siege: 40+ Malicious Extensions Found Stealing Data
Over 40 malicious Chrome extensions, disguised as legitimate tools, are stealing cookies, logins, and impersonating users, many still live on the Web Store.
⤷ Title: Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:02:30 +0000
════════════════════════
⌗ Tags: #Malware #captcha #ClickFix #clipboard injection #cybersecurity #malware #social engineering #Windows Run dialog
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:02:30 +0000
════════════════════════
⌗ Tags: #Malware #captcha #ClickFix #clipboard injection #cybersecurity #malware #social engineering #Windows Run dialog
Daily CyberSecurity
Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware
The "ClickFix" campaign tricks users with fake CAPTCHAs, leading them to paste malicious commands into the Windows Run dialog, delivering infostealers.
⤷ Title: My Token, Your Token, Whose Token? Understanding CSRF through Portswigger’s Web Security Academy
════════════════════════
𐀪 Author: Rhythm Babu Kafle
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:15:34 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #portswigger #csrf
════════════════════════
𐀪 Author: Rhythm Babu Kafle
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:15:34 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #cybersecurity #portswigger #csrf
Medium
My Token, Your Token, Whose Token? Understanding CSRF through Portswigger’s Web Security Academy
So basic concept first. Can I send friend requests from your Facebook Account? Or block someone from your account? No, right? This magic…
⤷ Title: Prototype Pollution Vulnerability Testing — Full Step-by-Step Guide (with Examples)
════════════════════════
𐀪 Author: d1lv3rdn4
════════════════════════
ⴵ Time: Sun, 25 May 2025 23:19:20 GMT
════════════════════════
⌗ Tags: #app_security #pentesting #bug_bounty #hacking
════════════════════════
𐀪 Author: d1lv3rdn4
════════════════════════
ⴵ Time: Sun, 25 May 2025 23:19:20 GMT
════════════════════════
⌗ Tags: #app_security #pentesting #bug_bounty #hacking
Medium
🔥 Prototype Pollution Vulnerability Testing — Full Step-by-Step Guide (with Examples)
By me, Cybersecurity Enthusiast | Ethical n00b | AppSec Researcher aka nub
⤷ Title: 184 Million Passwords Found in Huge Breach — Check If You’re Affected
════════════════════════
𐀪 Author: Sareena
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:26:05 GMT
════════════════════════
⌗ Tags: #facebook #google #cybersecurity #passwords #hacking
════════════════════════
𐀪 Author: Sareena
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:26:05 GMT
════════════════════════
⌗ Tags: #facebook #google #cybersecurity #passwords #hacking
Medium
184 Million Passwords Found in Huge Breach — Check If You’re Affected
Massive Data Breach Exposes Millions of Logins from Google, Microsoft, and Tiktok
⤷ Title: Introducción a Splunk
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:01:29 GMT
════════════════════════
⌗ Tags: #infosec #soc #cybersecurity #blue_team #data_analysis
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:01:29 GMT
════════════════════════
⌗ Tags: #infosec #soc #cybersecurity #blue_team #data_analysis
Medium
Introducción a Splunk
Guía práctica de introducción a Splunk: indexación, búsquedas, SPL, roles, alertas, dashboards y comandos clave.
⤷ Title: Parental Controls 101: How to Keep Your Kids Safe Online Without Being the ‘Bad Guy’
════════════════════════
𐀪 Author: Samir Karim
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:37:38 GMT
════════════════════════
⌗ Tags: #safe_kids_usa #cybersecurity #parental_control #cyber_security_awareness
════════════════════════
𐀪 Author: Samir Karim
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:37:38 GMT
════════════════════════
⌗ Tags: #safe_kids_usa #cybersecurity #parental_control #cyber_security_awareness
Medium
Parental Controls 101: How to Keep Your Kids Safe Online Without Being the ‘Bad Guy’
Let’s face it, the internet can feel like the Wild West when you’re a parent. One minute your kid is watching funny cat videos, the next…
⤷ Title: Apple Patches Two Actively Exploited Vulnerabilities — Just Playing Audio Could Compromise Your…
════════════════════════
𐀪 Author: Hazko-stack
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:27:52 GMT
════════════════════════
⌗ Tags: #hacker #exploits_zero_day #apple #bug_hunting #cybersecurity
════════════════════════
𐀪 Author: Hazko-stack
════════════════════════
ⴵ Time: Mon, 26 May 2025 01:27:52 GMT
════════════════════════
⌗ Tags: #hacker #exploits_zero_day #apple #bug_hunting #cybersecurity
Medium
🔐 Apple Patches Two Actively Exploited Vulnerabilities — Just Playing Audio Could Compromise Your Device
Apple has rolled out a critical security update to address two zero-day vulnerabilities that are being actively exploited in the wild…
⤷ Title: Splunk: Exploring SPL Tryhackme Walkthrough
════════════════════════
𐀪 Author: Raymond Ebonine
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:22:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #splunk_query_language #splunk #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: Raymond Ebonine
════════════════════════
ⴵ Time: Mon, 26 May 2025 00:22:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #splunk_query_language #splunk #tryhackme #tryhackme_walkthrough
Medium
Splunk: Exploring SPL Tryhackme Walkthrough
A simplified walkthrough of TryHackMe’s Splunk: Exploring SPL room. Learn SPL queries, log analysis, and practical SIEM skills.