⤷ Title: ClickFix 2026: New AppleScript Malware Held macOS Users Hostage for Passwords
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:11:34 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #ClickFix #Crypto theft #cybersecurity #Infostealer #macOS #macOS Tahoe #malware #Netskope #phishing #Session Hijacking #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:11:34 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript #ClickFix #Crypto theft #cybersecurity #Infostealer #macOS #macOS Tahoe #malware #Netskope #phishing #Session Hijacking #social engineering
Daily CyberSecurity
ClickFix 2026: New AppleScript Malware Held macOS Users Hostage for Passwords
Netskope uncovers a ClickFix macOS campaign that holds the UI hostage to steal system passwords, Keychains, and 200+ browser extensions.
⤷ Title: Mailcow Critical Alert: Unauthenticated XSS Threatens Admin Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 13:55:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admin Dashboard #Autodiscover #CVE_2026_40872 #docker #Email Security #infosec #mailcow #Patch Alert #Redis #Session Hijacking #Stored XSS #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 13:55:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admin Dashboard #Autodiscover #CVE_2026_40872 #docker #Email Security #infosec #mailcow #Patch Alert #Redis #Session Hijacking #Stored XSS #Web Security
Daily CyberSecurity
Mailcow Critical Alert: Unauthenticated XSS Threatens Admin Takeover
Unauthenticated attackers can hijack mailcow admin sessions via a critical CVSS 9.3 Stored XSS in Autodiscover logs. Patch to version 2026-03b immediately.
⤷ Title: The AI-Powered Cybercrime Factory: Unmasking the Bluekit “All-in-One” Phishing Revolution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 06:30:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #Bluekit #Credential Theft #cybersecurity #infosec #Phishing_as_a_Service #Quishing #Session Hijacking #social engineering #Threat Intel #Varonis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 06:30:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #Bluekit #Credential Theft #cybersecurity #infosec #Phishing_as_a_Service #Quishing #Session Hijacking #social engineering #Threat Intel #Varonis
Daily CyberSecurity
The AI-Powered Cybercrime Factory: Unmasking the Bluekit "All-in-One" Phishing Revolution
Varonis uncovers Bluekit, a new phishing-as-a-service kit using AI and 40+ templates to automate session hijacking and credential theft. See how it works.
⤷ Title: Cookies Explained: How Websites Remember You, And How Attackers Exploit It
════════════════════════
𐀪 Author: Amarachi Onyekachi
════════════════════════
ⴵ Time: Tue, 05 May 2026 06:42:46 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #cookies #web_security #session_management
════════════════════════
𐀪 Author: Amarachi Onyekachi
════════════════════════
ⴵ Time: Tue, 05 May 2026 06:42:46 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #cookies #web_security #session_management
Medium
Cookies Explained: How Websites Remember You, And How Attackers Exploit It
How cookies work, why they matter, and how attackers exploit them.
⤷ Title: Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 01:01:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Wicket #CVE_2026_40010 #CVE_2026_43646 #CVE_2026_43975 #infosec #Java security #Patch Alert #Path Traversal #Session Fixation #web development #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 01:01:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Wicket #CVE_2026_40010 #CVE_2026_43646 #CVE_2026_43975 #infosec #Java security #Patch Alert #Path Traversal #Session Fixation #web development #XSS
Daily CyberSecurity
Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass
Apache Wicket 10.9.0 fixes 3 Critical flaws: Path Traversal (CVE-2026-43975), Session Fixation, and Resource Guard bypass. Secure your Java apps and patch now!
⤷ Title: A Simple Session Management Bug Every Beginner Bug Hunter Should Test.
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Fri, 15 May 2026 10:23:43 GMT
════════════════════════
⌗ Tags: #simple_bugs #bug_bounty #session_management #p4_bugs
════════════════════════
𐀪 Author: kjulius
════════════════════════
ⴵ Time: Fri, 15 May 2026 10:23:43 GMT
════════════════════════
⌗ Tags: #simple_bugs #bug_bounty #session_management #p4_bugs
Medium
A Simple Session Management Bug Every Beginner Bug Hunter Should Test.
When beginners start bug bounty hunting, most of them spend hours testing XSS payloads, SQL injection, IDORs, and other well-known…
⤷ Title: Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
⌗ Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 08:04:06 +0000
════════════════════════
⌗ Tags: #Malware #@antv Malicious Packages #atool Maintainer Account #CI/CD Secret Stealer #Claude Code Backdoor #OIDC Token Hijacking #Session P2P Network #Shai_Hulud npm Attack #Sigstore Provenance Forgery #Software Supply Chain Worm #Visual Studio Code Malware
Penetration Testing Tools
Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
The npm ecosystem has been subjected to a massive, highly coordinated supply-chain assault. Within a compressed one-hour envelope,
⤷ Title: Anonymity Stripped: Unsecured Kibana and Dozzle Dashboards Leak 22 Million FTF Live Video Chat Records
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:26:05 +0000
════════════════════════
⌗ Tags: #Data Leak #Burhan LTD #Cooy Ads Ltd #Data Leak Cybernews #De_anonymization Risk #Dozzle Docker Logs #FTF Live Video Chat #Real_time Token Leak #Regional CERT Escalation #Session Metadata Exposure #Unsecured Kibana Dashboard
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:26:05 +0000
════════════════════════
⌗ Tags: #Data Leak #Burhan LTD #Cooy Ads Ltd #Data Leak Cybernews #De_anonymization Risk #Dozzle Docker Logs #FTF Live Video Chat #Real_time Token Leak #Regional CERT Escalation #Session Metadata Exposure #Unsecured Kibana Dashboard
Penetration Testing Tools
Anonymity Stripped: Unsecured Kibana and Dozzle Dashboards Leak 22 Million FTF Live Video Chat Records
The FTF Live video-chat ecosystem, which explicitly guaranteed its consumer base absolute anonymity during randomized social interactions, has
⤷ Title: Bypassing MFA: Gremlin Stealer Evolves into Advanced Memory-Resident Session Hijacker
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:26:35 +0000
════════════════════════
⌗ Tags: #Malware #Chromium Browsers #Clipboard Hijacker #Control Flow Flattening #Cyber Security #Discord Token Stealer #Gremlin Stealer #infosec #Infostealer #MFA Bypass #Session Hijacking #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 May 2026 07:26:35 +0000
════════════════════════
⌗ Tags: #Malware #Chromium Browsers #Clipboard Hijacker #Control Flow Flattening #Cyber Security #Discord Token Stealer #Gremlin Stealer #infosec #Infostealer #MFA Bypass #Session Hijacking #Unit 42
Daily CyberSecurity
Bypassing MFA: Gremlin Stealer Evolves into Advanced Memory-Resident Session Hijacker
Unit 42 exposes the new Gremlin stealer. It uses memory-resident techniques to hijack active browser session tokens and completely bypass MFA.
⤷ Title: Splunk Patches High-Severity Bugs Granting DoS and Internal Log Leaks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 May 2026 01:20:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #CVE_2026_20238 #CVE_2026_20239 #CVE_2026_20240 #Cyber Security #Denial of Service #infosec #Log Leak #Session Cookie Exposure #Splunk AI Toolkit #Splunk Enterprise
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 May 2026 01:20:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #CVE_2026_20238 #CVE_2026_20239 #CVE_2026_20240 #Cyber Security #Denial of Service #infosec #Log Leak #Session Cookie Exposure #Splunk AI Toolkit #Splunk Enterprise
Daily CyberSecurity
Splunk Patches High-Severity Bugs Granting DoS and Internal Log Leaks
Splunk releases coordinated patches for CVE-2026-20240 and adjacent flaws exposing raw session cookies, data filters, and triggering server DoS.