⤷ Title: Critical PHP SOAP Vulnerabilities Put Web Applications at Risk of Remote Code Execution
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Tue, 12 May 2026 09:55:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_application_security #remote_code_execution #application_security #php_security
════════════════════════
𐀪 Author: Jas
════════════════════════
ⴵ Time: Tue, 12 May 2026 09:55:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_application_security #remote_code_execution #application_security #php_security
Medium
Critical PHP SOAP Vulnerabilities Put Web Applications at Risk of Remote Code Execution
Security researchers have disclosed critical vulnerabilities in PHP’s SOAP extension that could allow attackers to execute arbitrary code…
⤷ Title: Explorando Remote Code Execution (RCE) no WordPress
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
Medium
Explorando Remote Code Execution (RCE) no WordPress
Hoje executaremos um código malicioso no servidor WordPress. Para isso, temos como pré-requisito:
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
Daily CyberSecurity
Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
DevOps Alert: Over 700 laravel-lang localization package versions have been backdoored with a cross-platform 17-collector info-stealer. Audit your logs.
⤷ Title: Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
Daily CyberSecurity
Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
Urgent: TYPO3 patches a critical 9.2 CVSS flaw (CVE-2026-46725) in Content Element Selector plugin. Unauthenticated attackers can achieve full server RCE.
⤷ Title: Dual Sandbox Bypasses Threaten PHP Applications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
Daily CyberSecurity
Dual Sandbox Bypasses Threaten PHP Applications
Twig project maintainers patched critical Twig RCE flaws allowing arbitrary code execution via sandbox bypasses. Update to 3.26.0.
⤷ Title: Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
Medium
Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
A single, seemingly innocent HTTP endpoint can form a critical business-impact chain when multiple structural PHP weaknesses are stitched…
⤷ Title: exfiltration using numeric-only outputs
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
Medium
exfiltration using numeric-only outputs
after identifying a code-injection vulnerability, we always want to look around inside the compromised system. most of the time, we can…
⤷ Title: PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
Daily CyberSecurity
PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
A critical PhpSpreadsheet RCE vulnerability impacts 312 million users. Learn how the CVE-2026-45034 exploit bypasses patches and triggers code execution.