⤷ Title: Web Monitoring Tools For OSINT Investigation
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:46:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint #monitoring #osint_investigation #ethical_hacking
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:46:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint #monitoring #osint_investigation #ethical_hacking
Medium
Web Monitoring Tools For OSINT Investigation
must-have tools for OSINT investigators
⤷ Title: PortSwigger Lab: Exploiting a mass assignment vulnerability (API Testing)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:46:27 GMT
════════════════════════
⌗ Tags: #web_app_security #web_app_pentesting #cybersecurity #penetration_testing #api_penetration_testing
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:46:27 GMT
════════════════════════
⌗ Tags: #web_app_security #web_app_pentesting #cybersecurity #penetration_testing #api_penetration_testing
Medium
PortSwigger Lab: Exploiting a mass assignment vulnerability (API Testing)
To solve the lab, find and exploit a mass assignment vulnerability to buy a Lightweight l33t Leather Jacket. You can log in to your own…
⤷ Title: How I Use netstat and ss to Catch Suspicious Connections on Linux
════════════════════════
𐀪 Author: Faruk Ahmed
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:30:17 GMT
════════════════════════
⌗ Tags: #linux #cybersecurity #ubuntu #devops
════════════════════════
𐀪 Author: Faruk Ahmed
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:30:17 GMT
════════════════════════
⌗ Tags: #linux #cybersecurity #ubuntu #devops
Medium
How I Use netstat and ss to Catch Suspicious Connections on Linux
Intro: Sometimes the biggest threats to your Linux server aren’t in the logs — they’re quietly hiding in plain sight, listening on open…
⤷ Title: XINTRA - Husky Corp Lab Walkthrough
════════════════════════
𐀪 Author: QhtSec
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:28:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #walkthrough #xintra #digital_forensics #dfir
════════════════════════
𐀪 Author: QhtSec
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:28:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #walkthrough #xintra #digital_forensics #dfir
Medium
XINTRA - Husky Corp Lab Walkthrough
SCOPING NOTE
⤷ Title: PortSwigger Lab: Finding and exploiting an unused API endpoint (API Testing)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 01:44:14 GMT
════════════════════════
⌗ Tags: #portswigger_lab #cybersecurity #web_app_security #web_app_pentesting #burpsuite
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 01:44:14 GMT
════════════════════════
⌗ Tags: #portswigger_lab #cybersecurity #web_app_security #web_app_pentesting #burpsuite
Medium
Portswigger Lab: Finding and exploiting an unused API endpoint
To solve the lab, exploit a hidden API endpoint to buy a Lightweight l33t Leather Jacket. You can log in to your own account using the…
⤷ Title: Browser Extension Recon: Finding Bugs in Official Extensions of Web Platforms
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:52:52 GMT
════════════════════════
⌗ Tags: #penetration_testing #chrome #bug_bounty #tips_and_tricks #technology
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:52:52 GMT
════════════════════════
⌗ Tags: #penetration_testing #chrome #bug_bounty #tips_and_tricks #technology
Medium
Browser Extension Recon: Finding Bugs in Official Extensions of Web Platforms
From XSS to Token Theft — How to Analyze, Reverse Engineer, and Exploit Browser Extensions for Bounties
⤷ Title: Very Vulnerable Management API (VVMA)
════════════════════════
𐀪 Author: Easpy
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:59:30 GMT
════════════════════════
⌗ Tags: #api_security #api_penetration_testing #owasp_api_security_top_10 #penetration_testing #security_testing
════════════════════════
𐀪 Author: Easpy
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:59:30 GMT
════════════════════════
⌗ Tags: #api_security #api_penetration_testing #owasp_api_security_top_10 #penetration_testing #security_testing
Medium
Very Vulnerable Management API (VVMA)
Very Vulnerable Management API (VVMA) merupakan API RESTful yang dibuat rentan dengan menggunakan Node.Js untuk tujuan pembelajaran dan…
⤷ Title: X ETH Passive Income Strategies for 2025
════════════════════════
𐀪 Author: $TY (X)
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:49:48 GMT
════════════════════════
⌗ Tags: #xs #crypto #ethereum #web3 #ties
════════════════════════
𐀪 Author: $TY (X)
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:49:48 GMT
════════════════════════
⌗ Tags: #xs #crypto #ethereum #web3 #ties
Medium
X ETH Passive Income Strategies for 2025
A Beginner's Guide To Staking $TY from X
⤷ Title: Step-by-Step Guide to Acquiring X
════════════════════════
𐀪 Author: $X (X Community)
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:14:51 GMT
════════════════════════
⌗ Tags: #crypto_guide #ethereum #xs #x_community
════════════════════════
𐀪 Author: $X (X Community)
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 02:14:51 GMT
════════════════════════
⌗ Tags: #crypto_guide #ethereum #xs #x_community
Medium
Step-by-Step Guide to Acquiring X
An easy guide to securing X.
⤷ Title: Harden-Runner: EDR for CI/CD Stops Supply Chain Attacks Cold
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 04:06:03 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CI/CD #Continuous Delivery #Continuous Integration #cybersecurity #EDR #Endpoint Detection and Response #GitHub Actions #Harden_Runner #security #StepSecurity #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 04:06:03 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CI/CD #Continuous Delivery #Continuous Integration #cybersecurity #EDR #Endpoint Detection and Response #GitHub Actions #Harden_Runner #security #StepSecurity #supply chain attack
Penetration Testing Tools
Harden-Runner: EDR for CI/CD Stops Supply Chain Attacks Cold
StepSecurity's "Harden-Runner" is a CI/CD security agent functioning as an EDR for runners, preventing exfiltration, detecting tampering, and securing over a million workflow runs weekly.
⤷ Title: Fedora Delays 32-bit Support End: Community Outcry Saves Gaming & Legacy Apps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:34:17 +0000
════════════════════════
⌗ Tags: #Linux #32_bit Support #Bazzite #Community Debate #Fedora Linux #gaming #Linux distribution #Multilib #open source #Wayland #X.org #Xlibre
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:34:17 +0000
════════════════════════
⌗ Tags: #Linux #32_bit Support #Bazzite #Community Debate #Fedora Linux #gaming #Linux distribution #Multilib #open source #Wayland #X.org #Xlibre
Penetration Testing Tools
Fedora Delays 32-bit Support End: Community Outcry Saves Gaming & Legacy Apps
Fedora Linux rejected a proposal to end 32-bit support, delaying the removal of multilib due to community backlash, especially from the gaming sector, and dismissing the Xlibre proposal.
⤷ Title: AI Chatbots Are Leading Users to Phishing Sites: New Report Reveals Dangerous “AI Search Poisoning” Threat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:31:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Chatbots #Brand Impersonation #cybersecurity #google #LLM #Netcraft #OpenAI #phishing #Scam #Search Poisoning #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:31:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Chatbots #Brand Impersonation #cybersecurity #google #LLM #Netcraft #OpenAI #phishing #Scam #Search Poisoning #Social Engineering
Penetration Testing Tools
AI Chatbots Are Leading Users to Phishing Sites: New Report Reveals Dangerous "AI Search Poisoning" Threat
AI chatbots frequently suggest incorrect or fake websites for major brands, creating a new "AI search poisoning" threat where attackers can register these domains for phishing scams.
⤷ Title: CISA Warns: TeleMessage TM SGNL Actively Exploited for Data Leaks, Patch by July 22
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:28:08 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2025_48927 #CVE_2025_48928 #cybersecurity #data leak #Exploited in Wild #Government #Heap Dump #Memory Dump #Spring Boot Actuator #TeleMessage TM SGNL #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:28:08 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2025_48927 #CVE_2025_48928 #cybersecurity #data leak #Exploited in Wild #Government #Heap Dump #Memory Dump #Spring Boot Actuator #TeleMessage TM SGNL #vulnerability
Penetration Testing Tools
CISA Warns: TeleMessage TM SGNL Actively Exploited for Data Leaks, Patch by July 22
CISA warns of active exploitation of TeleMessage TM SGNL (CVE-2025-48927, CVE-2025-48928), exposing memory dumps & passwords. Federal agencies must patch or cease use by July 22.
⤷ Title: Global E-commerce Fraud Ring Uncovered: Fake Apple, Nordstrom, Brooks Brothers Sites Steal Credit Cards
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:26:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Apple #Brooks Brothers #China #Credit Card Theft #E_commerce Fraud #Mexico #Nordstrom #Online Scams #phishing #Retail #Silent Push
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:26:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Apple #Brooks Brothers #China #Credit Card Theft #E_commerce Fraud #Mexico #Nordstrom #Online Scams #phishing #Retail #Silent Push
Penetration Testing Tools
Global E-commerce Fraud Ring Uncovered: Fake Apple, Nordstrom, Brooks Brothers Sites Steal Credit Cards
A global e-commerce fraud campaign uses thousands of fake retail websites mimicking Apple, Nordstrom, and more, to steal credit card data, with roots tied to Chinese developers.
⤷ Title: Urgent Cisco ISE/ISE-PIC Alert: Critical RCE Flaw (CVSS 10.0) Allow Unauthenticated Root Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:23:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cisco #CVE_2025_20309 #CVSS 10.0 #cybersecurity #Identity Services Engine #ISE #ISE_PIC #RCE #remote code execution #Root Privileges #Unauthenticated #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:23:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cisco #CVE_2025_20309 #CVSS 10.0 #cybersecurity #Identity Services Engine #ISE #ISE_PIC #RCE #remote code execution #Root Privileges #Unauthenticated #vulnerability
Penetration Testing Tools
Urgent Cisco ISE/ISE-PIC Alert: Critical RCE Flaw (CVSS 10.0) Allow Unauthenticated Root Access
Cisco warns of a critical flaw (CVE-2025-20309, CVSS 10.0) in ISE and ISE-PIC allowing unauthenticated remote root code execution. Apply patches immediately.
⤷ Title: Catwatchful Spyware Hacked: Critical Flaw Exposes 62,000 User Logins & Victim Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:17:01 +0000
════════════════════════
⌗ Tags: #Data Leak #Android #API Misconfiguration #Catwatchful #cybersecurity #data breach #Eric Daigle #firebase #Personal Information #Spyware #stalkerware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:17:01 +0000
════════════════════════
⌗ Tags: #Data Leak #Android #API Misconfiguration #Catwatchful #cybersecurity #data breach #Eric Daigle #firebase #Personal Information #Spyware #stalkerware
Penetration Testing Tools
Catwatchful Spyware Hacked: Critical Flaw Exposes 62,000 User Logins & Victim Data
A critical flaw in Android spyware Catwatchful exposed 62,000 user logins and data from 26,000 victim devices, including the admin's info, due to API misconfiguration.
⤷ Title: Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:14:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #Data Theft #DCPCU #Fraud #mobile security #phishing #Rogue Cell Tower #Smishing #SMS Blaster #UK police
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:14:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #Data Theft #DCPCU #Fraud #mobile security #phishing #Rogue Cell Tower #Smishing #SMS Blaster #UK police
Penetration Testing Tools
Chinese Student Jailed for Smishing: Operated Covert "SMS Blaster" in Car for Mass Phishing
A Chinese student was jailed in London for running a smishing campaign with an "SMS Blaster" hidden in his car, spoofing texts to steal data.
⤷ Title: Forminator WordPress Plugin Flaw (CVE-2025-6463, CVSS 8.8): Unauthenticated Arbitrary File Deletion Leads to Site Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:11:14 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #Plugin #RCE #remote code execution #Site Takeover #vulnerability #Wordfence #WordPress
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:11:14 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #Plugin #RCE #remote code execution #Site Takeover #vulnerability #Wordfence #WordPress
Penetration Testing Tools
Forminator WordPress Plugin Flaw (CVE-2025-6463, CVSS 8.8): Unauthenticated Arbitrary File Deletion Leads to Site Takeover
A critical flaw (CVE-2025-6463, CVSS 8.8) in Forminator WordPress plugin allows unauthenticated arbitrary file deletion, leading to site takeover.
⤷ Title: Exposed WordPress XML-RPC on akcmv.gov.lv: Brute Force and DDoS Risks
════════════════════════
𐀪 Author: Gouri Sankar A
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 04:29:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #infosec #bug_bounty #cybersecurity #bug_bounty_tips
════════════════════════
𐀪 Author: Gouri Sankar A
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 04:29:01 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #infosec #bug_bounty #cybersecurity #bug_bounty_tips
Medium
Exposed WordPress XML-RPC on akcmv.gov.lv: Brute Force and DDoS Risks
By Gouri Sankar
⤷ Title: RFD Vulnerability Hunting
════════════════════════
𐀪 Author: AbhirupKonwar
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 04:16:19 GMT
════════════════════════
⌗ Tags: #vulnerability #bug_bounty #bug_bounty_tips #pentesting #ethical_hacking
════════════════════════
𐀪 Author: AbhirupKonwar
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 04:16:19 GMT
════════════════════════
⌗ Tags: #vulnerability #bug_bounty #bug_bounty_tips #pentesting #ethical_hacking
Medium
RFD Vulnerability Hunting
Reflected File Download Bug Hunting & Pentesting
⤷ Title: Hunting SSRF in a Single Page Application (SPA) — A Bug Bounty Breakdown
════════════════════════
𐀪 Author: Jabaribrown
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:53:39 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #web_security #bug_bounty #ctf_writeup
════════════════════════
𐀪 Author: Jabaribrown
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 03:53:39 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #web_security #bug_bounty #ctf_writeup
Medium
🚛 Hunting SSRF in a Single Page Application (SPA) — A Bug Bounty Breakdown
I recently dove into a lab challenge that looked pretty quiet on the surface — but with some methodical digging, a little Burp Suite, and…