⤷ Title: Explorando Remote Code Execution (RCE) no WordPress
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
════════════════════════
𐀪 Author: Link
════════════════════════
ⴵ Time: Tue, 12 May 2026 15:22:36 GMT
════════════════════════
⌗ Tags: #wordpress #php #pentesting #cybersecurity #rce
Medium
Explorando Remote Code Execution (RCE) no WordPress
Hoje executaremos um código malicioso no servidor WordPress. Para isso, temos como pré-requisito:
⤷ Title: Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:34:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD security #Composer #Credential Theft #CVE_2026_45793 #DevSecOps #GitHub Actions #GitHub Token #Information Disclosure #Nils Adermann #php
Daily CyberSecurity
Urgent Update: Composer Vulnerability Leaks GitHub Secrets in Plaintext Logs (CVE-2026-45793)
Composer CVE-2026-45793 leaks GitHub tokens into CI/CD logs due to a validation error. Update to version 2.9.8 now and audit your GitHub Action logs.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:24:14 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #Composer Backdoor #Credential Harvesting #Cyber Security #DevOps Security #flipboxstudio #info_stealer #Laravel Lang #PHP RCE #supply chain attack
Daily CyberSecurity
Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor
DevOps Alert: Over 700 laravel-lang localization package versions have been backdoored with a cross-platform 17-collector info-stealer. Audit your logs.
⤷ Title: Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 01:17:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ceselector #Content Element Selector #CVE_2026_46725 #Cyber Security #infosec #Insecure Deserialization #Patch Alert #PHP Object Injection #Remote Code Execution #TYPO3 Extension #TYPO3_EXT_SA_2026_013
Daily CyberSecurity
Critical TYPO3 Extension Exploit: Content Element Selector Flaw (CVE-2026-46725) Triggers Unauthenticated RCE
Urgent: TYPO3 patches a critical 9.2 CVSS flaw (CVE-2026-46725) in Content Element Selector plugin. Unauthenticated attackers can achieve full server RCE.
⤷ Title: Dual Sandbox Bypasses Threaten PHP Applications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 01:30:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_46633 #CVE_2026_46640 #PHP Security #Remote Code Execution #Sandbox Bypass #Twig Engine
Daily CyberSecurity
Dual Sandbox Bypasses Threaten PHP Applications
Twig project maintainers patched critical Twig RCE flaws allowing arbitrary code execution via sandbox bypasses. Update to 3.26.0.
⤷ Title: Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
Medium
Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
A single, seemingly innocent HTTP endpoint can form a critical business-impact chain when multiple structural PHP weaknesses are stitched…
⤷ Title: exfiltration using numeric-only outputs
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
Medium
exfiltration using numeric-only outputs
after identifying a code-injection vulnerability, we always want to look around inside the compromised system. most of the time, we can…
⤷ Title: PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
Daily CyberSecurity
PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
A critical PhpSpreadsheet RCE vulnerability impacts 312 million users. Learn how the CVE-2026-45034 exploit bypasses patches and triggers code execution.
⤷ Title: Part 3/3: Exploiting phpinfo() — Turning Information into Compromise
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
Medium
🎓 Part 3/3: Exploiting phpinfo() — Turning Information into Compromise 🎓
Finding a phpinfo() file is just the beginning. The real value comes from analyzing its contents and using that data to advance your…