⤷ Title: Host Validation Bypass via Connection State Attack: Multiple Requests Over the Same TCP Connection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 07:01:21 GMT
════════════════════════
⌗ Tags: #connection_reuse_exploit #bug_bounty #routing_based_ssrf #ssrf_via_host_header #host_header_attack
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 07:01:21 GMT
════════════════════════
⌗ Tags: #connection_reuse_exploit #bug_bounty #routing_based_ssrf #ssrf_via_host_header #host_header_attack
Medium
Host Validation Bypass via Connection State Attack: Multiple Requests Over the Same TCP Connection
Discover how persistent connections and weak Host validation open the doors to internal systems.
⤷ Title: Host Validation Bypass via Connection State Attack: Multiple Requests Over the Same TCP Connection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 06:03:17 GMT
════════════════════════
⌗ Tags: #connection_reuse_exploit #bug_bounty #routing_based_ssrf #ssrf_via_host_header #host_header_attack
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 06:03:17 GMT
════════════════════════
⌗ Tags: #connection_reuse_exploit #bug_bounty #routing_based_ssrf #ssrf_via_host_header #host_header_attack
Medium
Host Validation Bypass via Connection State Attack: Multiple Requests Over the Same TCP Connection
Discover how persistent connections and weak Host validation open the doors to internal systems.
⤷ Title: Password Reset Poisoning via Dangling Markup
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 08:16:37 GMT
════════════════════════
⌗ Tags: #password_reset_poisoning #host_header_injection #dangling_markup #account_takeover #bug_bounty
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 08:16:37 GMT
════════════════════════
⌗ Tags: #password_reset_poisoning #host_header_injection #dangling_markup #account_takeover #bug_bounty
Medium
Password Reset Poisoning via Dangling Markup
Discover how attackers exploit host header injection and dangling markup to hijack accounts via poisoned password reset emails.
⤷ Title: Web Cache Poisoning via Ambiguous Requests Lead to XSS
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 07:53:53 GMT
════════════════════════
⌗ Tags: #web_cache_poisoning #bug_bounty #bug_bounty_tips #xss_via_cache_poisoning #host_header_injection
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 07:53:53 GMT
════════════════════════
⌗ Tags: #web_cache_poisoning #bug_bounty #bug_bounty_tips #xss_via_cache_poisoning #host_header_injection
Medium
Web Cache Poisoning via Ambiguous Requests Lead to XSS
Discover how subtle inconsistencies in Host header processing can poison caches and compromise users.
⤷ Title: Password Reset Poisoning via Middleware: The Hidden Flaw That Can Lead to Account Takeover
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 04:17:18 GMT
════════════════════════
⌗ Tags: #password_reset_attack #account_takeover #bug_bounty #host_header_injection #password_reset_poisoning
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 04:17:18 GMT
════════════════════════
⌗ Tags: #password_reset_attack #account_takeover #bug_bounty #host_header_injection #password_reset_poisoning
Medium
Password Reset Poisoning via Middleware: The Hidden Flaw That Can Lead to Account Takeover
How a single unchecked header can hand over your users’ accounts to attackers.
⤷ Title: HTTP Host header attacks
════════════════════════
𐀪 Author: Usama Hanif
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 22:09:23 GMT
════════════════════════
⌗ Tags: #ssrf #host_header_injection #portswigger #portswigger_lab #http_host_header_attack
════════════════════════
𐀪 Author: Usama Hanif
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 22:09:23 GMT
════════════════════════
⌗ Tags: #ssrf #host_header_injection #portswigger #portswigger_lab #http_host_header_attack
Medium
HTTP Host header attacks
APPERENTICE-PRACTITIONER Labs
⤷ Title: eJPT — 3.1 CTF 2System/Host Based Attacks
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 20:53:22 GMT
════════════════════════
⌗ Tags: #linux_exploitation #host_based_attack #penetration_testing #infosec #ethical_hacking
════════════════════════
𐀪 Author: Dharmendrakumar
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 20:53:22 GMT
════════════════════════
⌗ Tags: #linux_exploitation #host_based_attack #penetration_testing #infosec #ethical_hacking
Medium
eJPT — 3.1 CTF 2System/Host Based Attacks
⤷ Title: Tap-and-Steal: Over 760 Android Apps Exploit NFC/HCE for Payment Card Theft in Global Financial Scam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:32:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android NFC #Brazil #financial fraud #Host Card Emulation #Payment Card Theft #russia #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:32:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android NFC #Brazil #financial fraud #Host Card Emulation #Payment Card Theft #russia #Telegram C2
Daily CyberSecurity
Tap-and-Steal: Over 760 Android Apps Exploit NFC/HCE for Payment Card Theft in Global Financial Scam
Zimperium found 760+ Android apps exploiting NFC/HCE to steal payment data. The malware impersonates 20 banks across Russia, Poland, and Brazil, using Telegram for criminal coordination.
⤷ Title: NGate NFC Malware Steals Cash from ATMs by Relaying EMV Data and PINs from Victim’s Phone
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 00:58:26 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #ATM Fraud #Banking Trojan #CERT Polska #EMV Theft #Host Card Emulation #NFC_relay #NGate
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 00:58:26 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #ATM Fraud #Banking Trojan #CERT Polska #EMV Theft #Host Card Emulation #NFC_relay #NGate
Daily CyberSecurity
NGate NFC Malware Steals Cash from ATMs by Relaying EMV Data and PINs from Victim's Phone
CERT Polska exposed NGate, an Android malware that tricks users into tapping their card against their phone to steal NFC EMV data and PINs. The data is then relayed to an ATM for cash withdrawal.
⤷ Title: Critical Triofox Zero-Day (CVE-2025-12480) Under Active Exploit: Host Header Bypass Allows Unauthenticated Admin Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 02:01:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Gladinet #Host Header Spoofing #Mandiant #Triofox #UNC6485 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 02:01:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Gladinet #Host Header Spoofing #Mandiant #Triofox #UNC6485 #zero_day
Daily CyberSecurity
Critical Triofox Zero-Day (CVE-2025-12480) Under Active Exploit: Host Header Bypass Allows Unauthenticated Admin Takeover
Mandiant exposed UNC6485 exploiting a Triofox zero-day (CVE-2025-12480). The critical flaw allows unauthenticated admin takeover by spoofing the HTTP Host header to bypass authentication checks.
⤷ Title: Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_67494 #host header injection #Identity Management #ssrf #XSS #ZITADEL
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_67494 #host header injection #Identity Management #ssrf #XSS #ZITADEL
Daily CyberSecurity
Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS
ZITADEL patched three high-severity flaws. Critical SSRF (9.3) allows internal breach via x-forward-host; XSS and Host Header Injection risk account hijack. Update to v4.7.1 immediately.
⤷ Title: The 9.6 Crack in Java’s Foundation: Critical Undertow Flaw CVE-2025-12543
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 00:22:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cache Poisoning #Critical Vulnerability #CVE_2025_12543 #host header injection #Java security #JBoss EAP #Undertow #WildFly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 00:22:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cache Poisoning #Critical Vulnerability #CVE_2025_12543 #host header injection #Java security #JBoss EAP #Undertow #WildFly
Daily CyberSecurity
The 9.6 Crack in Java’s Foundation: Critical Undertow Flaw CVE-2025-12543
A foundational crack has been discovered in the bedrock of the Java web ecosystem. Undertow, the high-performance web server that powers enterprise heavyweights like WildFly and JBoss EAP, has bee…
⤷ Title: Critical Appsmith Flaw CVE-2026-22794 Allows Account Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 00:06:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #API security #Appsmith #CVE_2026_22794 #host header injection #Low Code Platform #Open Source Security #Password Reset Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 00:06:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #API security #Appsmith #CVE_2026_22794 #host header injection #Low Code Platform #Open Source Security #Password Reset Vulnerability
Daily CyberSecurity
Critical Appsmith Flaw CVE-2026-22794 Allows Account Takeover
Critical Appsmith flaw CVE-2026-22794 (CVSS 9.7) allows account takeover via Host Header Injection. Update to v1.93 immediately to secure your data.
⤷ Title: Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:46:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2026_25520 #CVE_2026_25586 #CVSS 10.0 #Host Prototype Pollution #JavaScript Security #Patch Alert #Sandbox Escape #SandboxJS #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:46:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2026_25520 #CVE_2026_25586 #CVSS 10.0 #Host Prototype Pollution #JavaScript Security #Patch Alert #Sandbox Escape #SandboxJS #Web Security
Daily CyberSecurity
Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover
Critical SandboxJS flaws (CVSS 10.0) allow sandbox escape & host takeover via prototype pollution. Update to v0.8.29 immediately to stop code execution.
⤷ Title: CVE-2025-62878: Critical 10.0 Vulnerability Found in Kubernetes Local Path Provisioner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:11:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container security #CVE_2025_62878 #CVSS 10.0 #Host Escape #K8s #Kubernetes #Local Path Provisioner #Patch Alert #Path Traversal #Rancher
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 00:11:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container security #CVE_2025_62878 #CVSS 10.0 #Host Escape #K8s #Kubernetes #Local Path Provisioner #Patch Alert #Path Traversal #Rancher
Daily CyberSecurity
CVE-2025-62878: Critical 10.0 Vulnerability Found in Kubernetes Local Path Provisioner
CVSS 10.0 Alert: Kubernetes Local Path Provisioner flaw (CVE-2025-62878) allows host file overwrites. Upgrade to v0.0.34 immediately.
⤷ Title: Critical Undertow Flaw (CVSS 9.6) Strikes HPE Telco Service Activator
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 04:20:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_12543 #Cyber Security #Host Header Validation #HPE Service Activator #Patch Alert #Session Hijacking #Telecommunications Security #Undertow HTTP Server #Web Cache Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 04:20:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_12543 #Cyber Security #Host Header Validation #HPE Service Activator #Patch Alert #Session Hijacking #Telecommunications Security #Undertow HTTP Server #Web Cache Poisoning
Daily CyberSecurity
Critical Undertow Flaw (CVSS 9.6) Strikes HPE Telco Service Activator
Critical Undertow HTTP server flaw CVE-2025-12543 (CVSS 9.6) impacts HPE Telco Service Activator, allowing cache poisoning and session hijacking. Patch now.