⤷ Title: Air Serbia Hit by Major Cyberattack: Internal Systems Disrupted, Active Directory Compromised
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:42:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:42:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals
Penetration Testing Tools
Air Serbia Hit by Major Cyberattack: Internal Systems Disrupted, Active Directory Compromised
Air Serbia is battling an ongoing cyberattack that has crippled internal operations, disrupted payroll, and potentially compromised Active Directory. An infostealer is suspected.
⤷ Title: hoaxshell: A Windows reverse shell payload generator and handler
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:04:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #hoaxshell #Windows reverse shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:04:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #hoaxshell #Windows reverse shell
Penetration Testing Tools
hoaxshell: A Windows reverse shell payload generator and handler
hoaxshell is an unconventional Windows reverse shell, currently undetected by Microsoft Defender and other AV solutions
⤷ Title: Abusing Active Directory Certificate Services (Part 2)
════════════════════════
𐀪 Author: Kassie Kimball
════════════════════════
ⴵ Time: Thu, 12 Oct 2023 15:44:18 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
════════════════════════
𐀪 Author: Kassie Kimball
════════════════════════
ⴵ Time: Thu, 12 Oct 2023 15:44:18 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 2) - Black Hills Information Security, Inc.
Misconfigurations in Active Directory Certificate Services (ADCS) can introduce critical vulnerabilities into an Enterprise Active Directory environment, such as paths of escalation from low privileged accounts to domain administrator.
⤷ Title: Abusing Active Directory Certificate Services (Part 1)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 05 Oct 2023 16:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 05 Oct 2023 16:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 1) - Black Hills Information Security, Inc.
Active Directory Certificate Services (ADCS) is used for public key infrastructure in an Active Directory environment. ADCS is widely used in enterprise Active Directory environments for managing certificates for systems, users, applications, and more.
⤷ Title: Intigriti Bug Bytes #226 - July 2025 🚀
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
Intigriti
Intigriti Bug Bytes #226 - July 2025 🚀
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Exploiting Log4Shell (Log4J) in 2025 An indispensable GitHub recon tool (not the one you have in mi...
⤷ Title: Apps Behind Walls: The Story of OS Sandboxes
════════════════════════
𐀪 Author: Natarajan C K
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:31:49 GMT
════════════════════════
⌗ Tags: #systems_thinking #operating_systems #sandbox #bug_bounty #security
════════════════════════
𐀪 Author: Natarajan C K
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:31:49 GMT
════════════════════════
⌗ Tags: #systems_thinking #operating_systems #sandbox #bug_bounty #security
Medium
Apps Behind Walls: The Story of OS Sandboxes
Imagine a group of toddlers playing in a sandbox. The sandbox has raised walls and soft sand inside, keeping the kids entertained — but…
⤷ Title: CTF Day(36)
════════════════════════
𐀪 Author: Ahmed Narmer
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:08:09 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ctf #web_pen_testing #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Ahmed Narmer
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:08:09 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ctf #web_pen_testing #bug_bounty #cybersecurity
Medium
CTF Day(36)
picoCTF Web Exploitation: Java Code Analysis!?!
⤷ Title: “How CVE-2025–4123 Turned Grafana Into a Hacker’s Playground”
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:59:11 GMT
════════════════════════
⌗ Tags: #hacking #technology #bug_bounty #programming #cybersecurity
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:59:11 GMT
════════════════════════
⌗ Tags: #hacking #technology #bug_bounty #programming #cybersecurity
Medium
“How CVE-2025–4123 Turned Grafana Into a Hacker’s Playground”
What started as a path traversal led to XSS, SSRF, and full account compromise.
⤷ Title: Payload in the Haystack: Using Wayback & ParamSpider to Find a Forgotten Upload Endpoint
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:56:13 GMT
════════════════════════
⌗ Tags: #infosec #hacking #cybersecurity #money #bug_bounty
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:56:13 GMT
════════════════════════
⌗ Tags: #infosec #hacking #cybersecurity #money #bug_bounty
Medium
🧨 Payload in the Haystack: Using Wayback & ParamSpider to Find a Forgotten Upload Endpoint 📦
Free Link 🎈
⤷ Title: Part 2: Automating Mobile API Discovery Using AI
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:16:16 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #ai #cybersecurity #information_security
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:16:16 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #ai #cybersecurity #information_security
Medium
Part 2: Automating Mobile API Discovery Using AI
“Why tap on screens when you can script your recon?”
⤷ Title: I Found a Broken API in a Mobile App — Without Touching the App
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:11:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #mobile_app_development #bug_bounty #information_security #infosec
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:11:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #mobile_app_development #bug_bounty #information_security #infosec
Medium
I Found a Broken API in a Mobile App — Without Touching the App
“Sometimes, you don’t need to touch the app to break the backend. You just need to know where to look.”
⤷ Title: API07:2023 — Server-Side Request Forgery (SSRF)
════════════════════════
𐀪 Author: Suhel Kathi
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:29:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_app_security #api_security #ssrf #owasp_top_10
════════════════════════
𐀪 Author: Suhel Kathi
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:29:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_app_security #api_security #ssrf #owasp_top_10
Medium
API07:2023 — Server-Side Request Forgery (SSRF)
“When your server becomes an attacker’s puppet.”
⤷ Title: How to Set Up a Professional Hacking Lab: A Practical Guide for Ethical Hackers and Bug Bounty…
════════════════════════
𐀪 Author: Santhosh Adiga U
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:09:58 GMT
════════════════════════
⌗ Tags: #hacking_tools #bug_bounty #penetration_testing #ethical_hacking #hacking_lab
════════════════════════
𐀪 Author: Santhosh Adiga U
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:09:58 GMT
════════════════════════
⌗ Tags: #hacking_tools #bug_bounty #penetration_testing #ethical_hacking #hacking_lab
Medium
How to Set Up a Professional Hacking Lab: A Practical Guide for Ethical Hackers and Bug Bounty Hunters
Secure, anonymous, and fully equipped.
⤷ Title: WPA3 Demystified — The New Era of Wi-Fi Security(Part 4)
════════════════════════
𐀪 Author: Amitishacked
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:07:05 GMT
════════════════════════
⌗ Tags: #cybersecurity #networking #wifi #bug_bounty #wpa3
════════════════════════
𐀪 Author: Amitishacked
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:07:05 GMT
════════════════════════
⌗ Tags: #cybersecurity #networking #wifi #bug_bounty #wpa3
Medium
📶 WPA3 Demystified — The New Era of Wi-Fi Security(Part 4)
If you’ve read my previous blogs about Wi-Fi, you already know how wireless communication works, what 2.4GHz vs. 5GHz means, and why WPA2…
⤷ Title: Abusing Broken Access Control and SQL Injection in the Wild
════════════════════════
𐀪 Author: RyuuKhagetsu
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 06:46:43 GMT
════════════════════════
⌗ Tags: #writeup #pentest #sql_injection #bug_bounty #broken_access_control
════════════════════════
𐀪 Author: RyuuKhagetsu
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 06:46:43 GMT
════════════════════════
⌗ Tags: #writeup #pentest #sql_injection #bug_bounty #broken_access_control
Medium
Abusing Broken Access Control and SQL Injection in the Wild
What started as a simple favor turned into a bug bounty-style finding.
⤷ Title: Vibe Coding Has Arrived. Your Security Model Is Obsolete.
════════════════════════
𐀪 Author: Taimur Ijlal
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 06:44:18 GMT
════════════════════════
⌗ Tags: #aws #coding #cybersecurity #vibe_coding #application_security
════════════════════════
𐀪 Author: Taimur Ijlal
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 06:44:18 GMT
════════════════════════
⌗ Tags: #aws #coding #cybersecurity #vibe_coding #application_security
Medium
Vibe Coding Has Arrived. Your Security Model Is Obsolete.
The next wave of vulnerabilities won’t come from developers — it’ll come from everyone else.
⤷ Title: What the Job Market Can Teach Us About App Security (Spoiler: It’s Kinda Broken)
════════════════════════
𐀪 Author: Chris J Shelby
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 16:53:58 GMT
════════════════════════
⌗ Tags: #resume_bots #owasp_top_10 #application_security #ai_in_hiring #developer_life
════════════════════════
𐀪 Author: Chris J Shelby
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 16:53:58 GMT
════════════════════════
⌗ Tags: #resume_bots #owasp_top_10 #application_security #ai_in_hiring #developer_life
Medium
What the Job Market Can Teach Us About App Security (Spoiler: It’s Kinda Broken)
AI resume bots, broken CAPTCHAs, and why your ATS might be a sitting duck
⤷ Title: The ROI of Threat Modeling
════════════════════════
𐀪 Author: BJ Edward Taduran
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 06:05:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #return_on_investment #threat_modeling #application_security #leadership
════════════════════════
𐀪 Author: BJ Edward Taduran
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 06:05:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #return_on_investment #threat_modeling #application_security #leadership
Medium
The ROI of Threat Modeling
I recently had discussions with established companies about the gaps in their threat modeling implementation. This inspired me to create a…
⤷ Title: Revolucionando o DevSecOps: IA, Automação e o Fim da Segurança como “Blocker”
════════════════════════
𐀪 Author: Leonardo Nunes Beda
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 20:30:40 GMT
════════════════════════
⌗ Tags: #strategy #software_development #ai #application_security #devsecops
════════════════════════
𐀪 Author: Leonardo Nunes Beda
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 20:30:40 GMT
════════════════════════
⌗ Tags: #strategy #software_development #ai #application_security #devsecops
Medium
Revolucionando o DevSecOps: IA, Automação e o Fim da Segurança como “Blocker”
Como a tecnologia pode capacitar desenvolvedores, redefinir o papel dos times de segurança e tornar a proteção de produtos uma vantagem…
⤷ Title: O Elo Perdido: Por que a Cultura e a Falta de Talentos Minam a Segurança de Produtos Digitais
════════════════════════
𐀪 Author: Leonardo Nunes Beda
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 20:01:06 GMT
════════════════════════
⌗ Tags: #security_leadership #application_security #software_development #secure_development #product_security
════════════════════════
𐀪 Author: Leonardo Nunes Beda
════════════════════════
ⴵ Time: Thu, 17 Jul 2025 20:01:06 GMT
════════════════════════
⌗ Tags: #security_leadership #application_security #software_development #secure_development #product_security
Medium
O Elo Perdido: Por que a Cultura e a Falta de Talentos Minam a Segurança de Produtos Digitais
A pressão por entregas rápidas e a escassez de profissionais qualificados criaram uma dívida de segurança que ameaça o crescimento das…
⤷ Title: Redeemer Lab Walkthrough Hack the Box Starting point: Exploring Redis Security Essentials
════════════════════════
𐀪 Author: Gopal Mohan
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:59:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #hackthebox #ctf #hacking
════════════════════════
𐀪 Author: Gopal Mohan
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:59:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #hackthebox #ctf #hacking
Medium
Redeemer Lab Walkthrough Hack the Box Starting point: Exploring Redis Security Essentials
If you’re new to cybersecurity, HTB’s Redeemer lab is a fantastic way to practice basic service enumeration and data retrieval —…