⤷ Title: Hackers Hijack Toptal GitHub to Spread Devastating Malware Through npm
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:58:15 GMT
════════════════════════
⌗ Tags: #information_security #ai #github #cybersecurity #supply_chain
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:58:15 GMT
════════════════════════
⌗ Tags: #information_security #ai #github #cybersecurity #supply_chain
Medium
Hackers Hijack Toptal GitHub to Spread Devastating Malware Through npm
In the latest blow to the already fragile software supply chain, threat actors breached Toptal’s GitHub organization and published 10…
⤷ Title: The ‘Coding’ Conundrum: Why Our Boardrooms Don’t Speak Security (And How to Fix It)
════════════════════════
𐀪 Author: Manan Kharbanda
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:52:08 GMT
════════════════════════
⌗ Tags: #business_strategy #ciso #boardroom #cybersecurity #leadership
════════════════════════
𐀪 Author: Manan Kharbanda
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:52:08 GMT
════════════════════════
⌗ Tags: #business_strategy #ciso #boardroom #cybersecurity #leadership
Medium
The ‘Coding’ Conundrum: Why Our Boardrooms Don’t Speak Security (And How to Fix It)
How a parliamentary moment in Ghana exposed the global crisis in cybersecurity leadership communication
⤷ Title: Build, Clone, Defend: Long-Range RFID Attacks Explained
════════════════════════
𐀪 Author: Stingrai
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:51:51 GMT
════════════════════════
⌗ Tags: #physical_security #penetration_testing #rfid #pentesting #cybersecurity
════════════════════════
𐀪 Author: Stingrai
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:51:51 GMT
════════════════════════
⌗ Tags: #physical_security #penetration_testing #rfid #pentesting #cybersecurity
Medium
Build, Clone, Defend: Long-Range RFID Attacks Explained
Learn how we built a portable 125kHz RFID cloner with 1–2m range. Understand real-world risks and discover key strategies to prevent…
⤷ Title: Build-Vulnlab Write-up
════════════════════════
𐀪 Author: t0x1k
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:38:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup
════════════════════════
𐀪 Author: t0x1k
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:38:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf_writeup
Medium
Build-Vulnlab Write-up
Build is the second machine that I completed labeled as an easy Linux machine. I will start off with an nmap scan to locate which ports are…
⤷ Title: AI Security Newsletter — July, 2025
════════════════════════
𐀪 Author: Tal Eliyahu
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:38:12 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #llm #ai #security
════════════════════════
𐀪 Author: Tal Eliyahu
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:38:12 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #llm #ai #security
Medium
AI Security Newsletter — July, 2025
A digest of AI security research, insights, reports, upcoming events, and tools & resources. Follow AI Security community on Twitter and…
⤷ Title: Why I’m Scary Excited to Help You Master Your Personal Tech
════════════════════════
𐀪 Author: Dan Christ
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:36:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #tech_tips #personal_productivity #generative_ai_tools #digital_wellbeing
════════════════════════
𐀪 Author: Dan Christ
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 21:36:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #tech_tips #personal_productivity #generative_ai_tools #digital_wellbeing
Medium
Why I’m Scary Excited to Help You Master Your Personal Tech
I feel better when I meditate. It helps me focus and calms the squirrel brain that dominates much of the time.
⤷ Title: SQL injection attack, querying the database type and version on MySQL and Microsoft
════════════════════════
𐀪 Author: Zabed Ullah Poyel
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 22:43:31 GMT
════════════════════════
⌗ Tags: #web_security #sql_injection #sqli #sql_vulnerabilities #sql_injection_attack
════════════════════════
𐀪 Author: Zabed Ullah Poyel
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 22:43:31 GMT
════════════════════════
⌗ Tags: #web_security #sql_injection #sqli #sql_vulnerabilities #sql_injection_attack
Medium
SQL injection attack, querying the database type and version on MySQL and Microsoft
The application’s product category filter is vulnerable to SQL injection, allowing attackers to manipulate the SQL query using UNION-based…
⤷ Title: Sandman: NTP based backdoor for red team engagements
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:35:01 +0000
════════════════════════
⌗ Tags: #Open Source Tool #NTP backdoor #Sandman
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:35:01 +0000
════════════════════════
⌗ Tags: #Open Source Tool #NTP backdoor #Sandman
Penetration Testing Tools
Sandman: NTP based backdoor for red team engagements
Sandman is a backdoor that meant to work on hardened networks during red team engagements. Sandman works as a stager and leverages NTP
⤷ Title: Windows 11 Beta Unleashes Copilot+ AI Assistant, Redesigned Settings, & Enhanced Recall for Insiders
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:22:56 +0000
════════════════════════
⌗ Tags: #Windows #AI Assistant #Beta channel #Click to Do #Copilot #Microsoft #Recall #Settings #Windows 11 #Windows Insider
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:22:56 +0000
════════════════════════
⌗ Tags: #Windows #AI Assistant #Beta channel #Click to Do #Copilot #Microsoft #Recall #Settings #Windows 11 #Windows Insider
Penetration Testing Tools
Windows 11 Beta Unleashes Copilot+ AI Assistant, Redesigned Settings, & Enhanced Recall for Insiders
Microsoft's latest Windows 11 Beta (26120.5722) introduces an AI assistant for settings, a redesigned welcome screen, enhanced Click to Do, and improved Recall features for Insiders.
⤷ Title: AI is Flooding Bug Bounty Programs with Fake Vulnerability Reports: A New “Trust Trap” Emerges
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:07:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #bug bounty #cybersecurity #HackerOne #Hallucinations #Open Collective #spam #Trust Trap #Vulnerability Reports
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:07:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #bug bounty #cybersecurity #HackerOne #Hallucinations #Open Collective #spam #Trust Trap #Vulnerability Reports
Penetration Testing Tools
AI is Flooding Bug Bounty Programs with Fake Vulnerability Reports: A New "Trust Trap" Emerges
AI-generated, fictional vulnerability reports are flooding bug bounty programs, creating a "trust trap" that wastes expert time and threatens to overwhelm open-source projects.
⤷ Title: SharpSCCM: post-exploitation tool designed to leverage SCCM for lateral movement
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:55:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Lateral Movement #SCCM #SCCM lateral movement
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:55:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Lateral Movement #SCCM #SCCM lateral movement
Penetration Testing Tools
SharpSCCM: post-exploitation tool designed to leverage SCCM for lateral movement
SharpSCCM is a post-exploitation tool designed to leverage Microsoft Endpoint Configuration Manager (SCCM) for lateral movement
⤷ Title: Ubuntu 25.04 on Snapdragon X Still Plagued by Endless Boot Loops, Despite Latest Build
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:44:21 +0000
════════════════════════
⌗ Tags: #Linux #Acer Swift 14 AI #ARM #Canonical #Development #Laptop #Snapdragon X #Stability #Testing #ubuntu
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:44:21 +0000
════════════════════════
⌗ Tags: #Linux #Acer Swift 14 AI #ARM #Canonical #Development #Laptop #Snapdragon X #Stability #Testing #ubuntu
Penetration Testing Tools
Ubuntu 25.04 on Snapdragon X Still Plagued by Endless Boot Loops, Despite Latest Build
Ubuntu 25.04 test builds for Snapdragon X laptops now boot on Acer Swift 14 AI, but the system enters an endless restart loop after installation, hindering stability.
⤷ Title: Linux Kernel Set to Remove Obscure 31-Year-Old ELF Header Limitation in Version 6.17
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:30:59 +0000
════════════════════════
⌗ Tags: #Linux #ARM64 #ELF #Kernel Development #Linux Kernel #Obscure Bug #open source #Page Size
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:30:59 +0000
════════════════════════
⌗ Tags: #Linux #ARM64 #ELF #Kernel Development #Linux Kernel #Obscure Bug #open source #Page Size
Penetration Testing Tools
Linux Kernel Set to Remove Obscure 31-Year-Old ELF Header Limitation in Version 6.17
A 31-year-old, undocumented ELF header limitation in the Linux kernel is set for removal in version 6.17, allowing ARM64 binaries to execute flawlessly on 4KB page size systems.
⤷ Title: SSRF via Host Header Injection — A Prank Gone Vulnerable
════════════════════════
𐀪 Author: Minio Haxer
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:03:53 GMT
════════════════════════
⌗ Tags: #bugs #bug_bounty_tips #cybersecurity #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Minio Haxer
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:03:53 GMT
════════════════════════
⌗ Tags: #bugs #bug_bounty_tips #cybersecurity #bug_bounty #bug_bounty_writeup
Medium
SSRF via Host Header Injection — A Prank Gone Vulnerable
🕵️♂️ How I Made a Server Talk to Me (Host Header Injection to SSRF) 🎯💣
⤷ Title: Identification and Authentication Failures (OWASP A07): For hacking, bug bounty and web development
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:02:28 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing #web_development #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:02:28 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing #web_development #bug_bounty
Medium
Identification and Authentication Failures (OWASP A07): For hacking, bug bounty and web development
Discover how login and authentication vulnerabilities affect websites. Learn how to exploit them and protect yourself!
⤷ Title: Ultimate API Bug Bounty: Find & Secure Hidden API Endpoints
════════════════════════
𐀪 Author: Israel Aráoz Severiche
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:42:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #api #cybersecurity #hacking
════════════════════════
𐀪 Author: Israel Aráoz Severiche
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:42:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #api #cybersecurity #hacking
Medium
Ultimate API Bug Bounty: Find & Secure Hidden API Endpoints
This guide shows you simple, step‑by‑step methods to find hidden API endpoints. You’ll learn passive techniques like scanning JavaScript…
⤷ Title: Leak of Internal Reference Name at Multiple Locations.
════════════════════════
𐀪 Author: xploiterr
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:15:29 GMT
════════════════════════
⌗ Tags: #improper_access_control #bug_bounty #bugbounty_tips
════════════════════════
𐀪 Author: xploiterr
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:15:29 GMT
════════════════════════
⌗ Tags: #improper_access_control #bug_bounty #bugbounty_tips
Medium
Leak of Internal Reference Name at Multiple Locations.
Hi Everyone,
⤷ Title: The RAT That Fights Back: XWorm v6 and the New Era of Stealthy Cyber Threats
════════════════════════
𐀪 Author: Robert Encarnacao
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:02:29 GMT
════════════════════════
⌗ Tags: #threat_intelligence #infosec #malware_analysis #cybersecurity #remoteaccesstrojan
════════════════════════
𐀪 Author: Robert Encarnacao
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:02:29 GMT
════════════════════════
⌗ Tags: #threat_intelligence #infosec #malware_analysis #cybersecurity #remoteaccesstrojan
Medium
The RAT That Fights Back: XWorm v6 and the New Era of Stealthy Cyber Threats
In a darkened corporate office at 2 AM, a lone webcam light flickers on a laptop, illuminating an empty conference room. There’s no one…
⤷ Title: Fileless Virus vs Rootkit
════════════════════════
𐀪 Author: Cyber T
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:59:10 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #hacking #malware #osint
════════════════════════
𐀪 Author: Cyber T
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:59:10 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #hacking #malware #osint
Medium
Fileless Virus vs Rootkit
What’s the Difference?
⤷ Title: How to Recover Lost Cryptocurrency or Access Your Wallet
════════════════════════
𐀪 Author: Simone Bianca
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:36:41 GMT
════════════════════════
⌗ Tags: #recovery #cybersecurity #blockchain #crytocurrency #bitcoin
════════════════════════
𐀪 Author: Simone Bianca
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:36:41 GMT
════════════════════════
⌗ Tags: #recovery #cybersecurity #blockchain #crytocurrency #bitcoin
Medium
How to Recover Lost Cryptocurrency or Access Your Wallet
I’m incredibly grateful to Ghost Mystery Recovery Hacker for helping me recover my lost funds. After falling victim to an online scam, I…
⤷ Title: OAuth is not for Authentication — A common misconception
════════════════════════
𐀪 Author: Ayyappan Subramanian
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:33:24 GMT
════════════════════════
⌗ Tags: #soc_analyst #oauth #cybersecurity #identity_management #oidc
════════════════════════
𐀪 Author: Ayyappan Subramanian
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:33:24 GMT
════════════════════════
⌗ Tags: #soc_analyst #oauth #cybersecurity #identity_management #oidc
Medium
OAuth is not for Authentication — A common misconception
OAuth has become so popular in a way that it is easy to forget what it was actually designed for — and what it wasn’t. You’ve probably…