πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 27 Mar 2023 17:02:07 GMT
βββββββββββββββ
βοΈTitle: Securing Physical Access to the Network
βββββββββββββββ
πLink: https://medium.com/p/e3cdcc44975b
βββββββββββββββ
Tags: #network_security #locks #unauthorized_access #physical_security #cybersecurity
βββββββββββββββ
πDate: Mon, 27 Mar 2023 17:02:07 GMT
βββββββββββββββ
βοΈTitle: Securing Physical Access to the Network
βββββββββββββββ
πLink: https://medium.com/p/e3cdcc44975b
βββββββββββββββ
Tags: #network_security #locks #unauthorized_access #physical_security #cybersecurity
Medium
Securing Physical Access to the Network
This is about literally having physical barriers to protect your network from being physically touched by bad people. Network security mustβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 16 Aug 2023 02:52:25 GMT
βββββββββββββββ
βοΈTitle: Finding Unauthorized API Access in Android Application
βββββββββββββββ
πLink: https://medium.com/p/e6a4bd7898de
βββββββββββββββ
Tags: #unauthorized_access #android #idor #pentesting #api
βββββββββββββββ
πDate: Wed, 16 Aug 2023 02:52:25 GMT
βββββββββββββββ
βοΈTitle: Finding Unauthorized API Access in Android Application
βββββββββββββββ
πLink: https://medium.com/p/e6a4bd7898de
βββββββββββββββ
Tags: #unauthorized_access #android #idor #pentesting #api
Medium
Finding Unauthorized API Access in Android Application
During my free time, i downloaded a android application from google play store for fun, i have actually known this application for a longβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 02 Oct 2023 10:13:17 GMT
βββββββββββββββ
βοΈTitle: Gaining Admin Access via GraphQL
βββββββββββββββ
πLink: https://medium.com/p/95255372afa0
βββββββββββββββ
Tags: #privilege_escalation #unauthorized_access #penetration_testing
βββββββββββββββ
πDate: Mon, 02 Oct 2023 10:13:17 GMT
βββββββββββββββ
βοΈTitle: Gaining Admin Access via GraphQL
βββββββββββββββ
πLink: https://medium.com/p/95255372afa0
βββββββββββββββ
Tags: #privilege_escalation #unauthorized_access #penetration_testing
Medium
Gaining Admin Access via GraphQL
This is a simple story about chaining 2 vulnerabilities to gain access to an administrative website. Iβm going to share the thought processβ¦
β€· Title: Day 3| The WebStrike Challenge: Unraveling a Cyber Mystery in Real Time
ββββββββββββββββββββββββ
πͺ Author: Manish Rawat
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 13 Feb 2025 14:46:05 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #cyber_security_awareness #data_breach #wireshark #unauthorized_access
ββββββββββββββββββββββββ
πͺ Author: Manish Rawat
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 13 Feb 2025 14:46:05 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #cyber_security_awareness #data_breach #wireshark #unauthorized_access
Medium
Day 3| The WebStrike Challenge: Unraveling a Cyber Mystery in Real Time
Welcome to My Cybersecurity Adventure!
β€· Title: Critical phpMyAdmin Authentication Bypass via Shodan Dorking
ββββββββββββββββββββββββ
πͺ Author: Youssefhussein
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 27 Feb 2025 17:47:13 GMT
ββββββββββββββββββββββββ
β Tags: #dorking #unauthorized_access #shodan #authentication_bypass #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Youssefhussein
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 27 Feb 2025 17:47:13 GMT
ββββββββββββββββββββββββ
β Tags: #dorking #unauthorized_access #shodan #authentication_bypass #bug_bounty
Medium
Introduction
Introduction
β€· Title: Hacking Open Docker Registries: Pulling, Extracting, and Exploiting Images.
ββββββββββββββββββββββββ
πͺ Author: nav1n
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 19 Mar 2025 07:32:12 GMT
ββββββββββββββββββββββββ
β Tags: #rce_vulnerability #docker #sql_injection #bug_bounty #unauthorized_access
ββββββββββββββββββββββββ
πͺ Author: nav1n
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 19 Mar 2025 07:32:12 GMT
ββββββββββββββββββββββββ
β Tags: #rce_vulnerability #docker #sql_injection #bug_bounty #unauthorized_access
Medium
Hacking Open Docker Registries: Pulling, Extracting, and Exploiting Images.
Discovering secrets in exposed container images and leveraging misconfigurations for deeper access
β€· Title: Hacking Open Docker Registries: Pulling, Extracting, and Exploiting Images.
ββββββββββββββββββββββββ
πͺ Author: nav1n
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 20 Mar 2025 03:06:45 GMT
ββββββββββββββββββββββββ
β Tags: #rce_vulnerability #docker #sql_injection #bug_bounty #unauthorized_access
ββββββββββββββββββββββββ
πͺ Author: nav1n
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 20 Mar 2025 03:06:45 GMT
ββββββββββββββββββββββββ
β Tags: #rce_vulnerability #docker #sql_injection #bug_bounty #unauthorized_access
Medium
Hacking Open Docker Registries: Pulling, Extracting, and Exploiting Images.
Discovering secrets in exposed container images and leveraging misconfigurations for deeper access
β€· Title: οΈββοΈ How I Got Access to a UK Government Organizationβs SMTP Server?
ββββββββββββββββββββββββ
πͺ Author: B4LOGI
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 30 Mar 2025 17:40:24 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #unauthorized #smtp_server #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: B4LOGI
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 30 Mar 2025 17:40:24 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #unauthorized #smtp_server #cybersecurity
Medium
π΅οΈββοΈ How I Got Access to a UK Government Organizationβs SMTP Server? π§π¨
While researching Google Dorking over my favorite cup of coffee β, I stumbled upon something unexpectedβββan exposed mail server belongingβ¦
β€· Title: VMware Cloud Foundation Vulnerable to Unauthorized Access and Data Exposure
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 20 May 2025 10:27:15 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Cloud Security #CVEs #Data Exposure #security #unauthorized access #VMware Cloud Foundation
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 20 May 2025 10:27:15 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Cloud Security #CVEs #Data Exposure #security #unauthorized access #VMware Cloud Foundation
Daily CyberSecurity
VMware Cloud Foundation Vulnerable to Unauthorized Access and Data Exposure
Learn about new vulnerabilities in VMware Cloud Foundation that could lead to unauthorized access, info disclosure, and unapproved actions.
β€· Title: Cisco Zero-Day CVE-2025-20362 Under Attack: VPN Flaw in ASA/FTD Exposes Restricted Resources
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 26 Sep 2025 00:30:49 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #ASA #cisco #CVE_2025_20362 #FTD #Secure Firewall #security update #unauthorized access #vpn #zero_day
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 26 Sep 2025 00:30:49 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #ASA #cisco #CVE_2025_20362 #FTD #Secure Firewall #security update #unauthorized access #vpn #zero_day
Daily CyberSecurity
Cisco Zero-Day CVE-2025-20362 Under Attack: VPN Flaw in ASA/FTD Exposes Restricted Resources
Cisco patches CVE-2025-20362, a medium-high zero-day vulnerability in ASA/FTD VPN web servers that is being exploited to gain unauthorized access to restricted resources.
β€· Title: Invisible Hijack: New Agent Session Smuggling Attack Forces AI to Buy Stock Silently
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 04 Nov 2025 04:24:58 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #A2A Protocol #Agent Session Smuggling #AI security #Gemini #Multi_Agent Systems #Unauthorized Transactions #Unit 42
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 04 Nov 2025 04:24:58 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #A2A Protocol #Agent Session Smuggling #AI security #Gemini #Multi_Agent Systems #Unauthorized Transactions #Unit 42
Penetration Testing Tools
Invisible Hijack: New Agent Session Smuggling Attack Forces AI to Buy Stock Silently
Unit 42 detailed "Agent Session Smuggling," where a malicious agent injects hidden commands to coerce client AIs into unauthorized actions, like buying stock.
β€· Title: How a Throwaway Email Walked Me Into Someone Elseβs Tenant β Unauthorized PII Information Access
ββββββββββββββββββββββββ
πͺ Author: Thamotharan Vajramani
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 20 May 2026 16:41:42 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty_tips #bug_bounty_writeup #unauthorized_access #improper_access_control #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Thamotharan Vajramani
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 20 May 2026 16:41:42 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty_tips #bug_bounty_writeup #unauthorized_access #improper_access_control #bug_bounty
Medium
How a Throwaway Email Walked Me Into Someone Elseβs Tenant β Unauthorized PII Information Access
By Thamotharan Vajramani
β€· Title: VaultJacking: Exploiting Google Sync Infrastructure via Intercepted PINs
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 29 May 2026 09:41:23 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #cross_site authentication data theft #Google Workspace proxy environment hijacking #iCloud Keychain vs Google security architecture #multi_platform synchronized repository dump #PhishU Adversary_in_the_Middle framework #session cookie token theft mitigations #synchronization PIN credential exfiltration #unauthorized trusted device registry #VaultJacking Google password phishing #WebAuthn hardware perimeter bypass
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 29 May 2026 09:41:23 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #cross_site authentication data theft #Google Workspace proxy environment hijacking #iCloud Keychain vs Google security architecture #multi_platform synchronized repository dump #PhishU Adversary_in_the_Middle framework #session cookie token theft mitigations #synchronization PIN credential exfiltration #unauthorized trusted device registry #VaultJacking Google password phishing #WebAuthn hardware perimeter bypass
Information Security News
VaultJacking: Exploiting Google Sync Infrastructure via Intercepted PINs
The Genesis of the VaultJacking Attack Vector A solitary numeric PIN can transform Googleβs password repository into an unsecured gateway. Consequently, the emerging VaultJacking phishing methodolβ¦
β€· Title: Progress Software Shuts Down ShareFile Over External Threat
ββββββββββββββββββββββββ
πͺ Author: Nam Phong
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 14 Jul 2026 13:30:47 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #CVE_2026_2699 #Data Security Incident #Enterprise File Sharing #Progress Software #ShareFile #Storage Zone Controller #Unauthorized Access
ββββββββββββββββββββββββ
πͺ Author: Nam Phong
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 14 Jul 2026 13:30:47 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #CVE_2026_2699 #Data Security Incident #Enterprise File Sharing #Progress Software #ShareFile #Storage Zone Controller #Unauthorized Access
Information Security News
Progress Software Shuts Down ShareFile Over External Threat
Corporate storage systems are rarely taken offline unless the risk is serious. Progress Software has asked customers to shut down their ShareFile Storage Zone Controller servers immediately. The rβ¦
β€· Title: RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys
ββββββββββββββββββββββββ
πͺ Author: Nam Phong
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 04 Aug 2026 12:32:10 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #AI Agent security #AI Infrastructure #CVE_2026_59726 #MCP Bridge #Prompt Injection #Ruflo Vulnerability #RufRoot #Unauthorized RCE
ββββββββββββββββββββββββ
πͺ Author: Nam Phong
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 04 Aug 2026 12:32:10 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #AI Agent security #AI Infrastructure #CVE_2026_59726 #MCP Bridge #Prompt Injection #Ruflo Vulnerability #RufRoot #Unauthorized RCE
Information Security News
RufRoot CVE-2026-59726: Unauthenticated RCE in Ruflo MCP Bridge Exposes AI Agent Keys
A single unauthenticated POST request was sufficient to open a command shell inside one of the most widely deployed AI agent orchestration platforms on GitHub. From that foothold, an attacker coulβ¦