⤷ Title: ️♂️ How I Got Access to a UK Government Organization’s SMTP Server?
════════════════════════
𐀪 Author: B4LOGI
════════════════════════
ⴵ Time: Sun, 30 Mar 2025 17:40:24 GMT
════════════════════════
⌗ Tags: #infosec #unauthorized #smtp_server #cybersecurity
════════════════════════
𐀪 Author: B4LOGI
════════════════════════
ⴵ Time: Sun, 30 Mar 2025 17:40:24 GMT
════════════════════════
⌗ Tags: #infosec #unauthorized #smtp_server #cybersecurity
Medium
🕵️♂️ How I Got Access to a UK Government Organization’s SMTP Server? 📧🚨
While researching Google Dorking over my favorite cup of coffee ☕, I stumbled upon something unexpected — an exposed mail server belonging…
⤷ Title: How I Found an SMTP Injection Bug & Earned $800 in Just 30 Minutes!
════════════════════════
𐀪 Author: TheIndianNetwork
════════════════════════
ⴵ Time: Wed, 02 Apr 2025 06:42:02 GMT
════════════════════════
⌗ Tags: #smtp_injection #bug_bounty #email_spoofing #bug_bounty_tips #smtp
════════════════════════
𐀪 Author: TheIndianNetwork
════════════════════════
ⴵ Time: Wed, 02 Apr 2025 06:42:02 GMT
════════════════════════
⌗ Tags: #smtp_injection #bug_bounty #email_spoofing #bug_bounty_tips #smtp
Medium
How I Found an SMTP Injection Bug & Earned $800 in Just 30 Minutes!
Bug bounty hunting is full of surprises, and sometimes, the easiest vulnerabilities can pay the most. This is the story of how I stumbled…
⤷ Title: Malicious Python Packages Exploited Gmail as Covert Command-and-Control Channels
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 02 May 2025 00:20:40 +0000
════════════════════════
⌗ Tags: #Malware #Command and Control #gmail #malware #PyPI #Python #SMTP tunneling #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 02 May 2025 00:20:40 +0000
════════════════════════
⌗ Tags: #Malware #Command and Control #gmail #malware #PyPI #Python #SMTP tunneling #Socket #supply chain attack
Daily CyberSecurity
Malicious Python Packages Exploited Gmail as Covert Command-and-Control Channels
Socket discovers Python packages abusing Gmail SMTP for covert C2 tunnels, evading firewalls and exfiltrating data through trusted email infrastructure.
⤷ Title: HTB Solution: SMTP
════════════════════════
𐀪 Author: Nabin Saru
════════════════════════
ⴵ Time: Wed, 21 May 2025 01:31:32 GMT
════════════════════════
⌗ Tags: #htb #cybersecurity #smtp #htb_academy #solutions
════════════════════════
𐀪 Author: Nabin Saru
════════════════════════
ⴵ Time: Wed, 21 May 2025 01:31:32 GMT
════════════════════════
⌗ Tags: #htb #cybersecurity #smtp #htb_academy #solutions
Medium
HTB Solution: SMTP
Solution for the Footprinting: SMTP module.
⤷ Title: Postfish (Proving Grounds) — OSEP-Focused Write-Up
════════════════════════
𐀪 Author: Amatheusfeitosam
════════════════════════
ⴵ Time: Sun, 08 Jun 2025 01:29:33 GMT
════════════════════════
⌗ Tags: #linux_priv_esc #proving_grounds_practice #penetration_testing #smtp_server #post_exploitation
════════════════════════
𐀪 Author: Amatheusfeitosam
════════════════════════
ⴵ Time: Sun, 08 Jun 2025 01:29:33 GMT
════════════════════════
⌗ Tags: #linux_priv_esc #proving_grounds_practice #penetration_testing #smtp_server #post_exploitation
Medium
Postfish (Proving Grounds) — OSEP-Focused Write-Up
Goal: Document a realistic and practical approach aligned with the OSEP mindset. Focused on post-exploitation, lateral movement, and…
⤷ Title: Internal Penetration Test Report
════════════════════════
𐀪 Author: Amatheusfeitosam
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 14:19:35 GMT
════════════════════════
⌗ Tags: #smtp #penetration_testing #cybersecurity #kali #linux_privesc
════════════════════════
𐀪 Author: Amatheusfeitosam
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 14:19:35 GMT
════════════════════════
⌗ Tags: #smtp #penetration_testing #cybersecurity #kali #linux_privesc
Medium
Internal Penetration Test Report
Initial Access & Enumeration — SMTP Vuln
⤷ Title: Opossum Attack: New Vulnerability Compromises Encrypted TLS Connections, Allowing MitM & Data Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:26:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Desynchronization #FTP #http #Man in the Middle #mitm #Opossum Attack #Opportunistic TLS #SMTP #tls #Transport Layer Security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:26:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Desynchronization #FTP #http #Man in the Middle #mitm #Opossum Attack #Opportunistic TLS #SMTP #tls #Transport Layer Security #Vulnerability
Daily CyberSecurity
Opossum Attack: New Vulnerability Compromises Encrypted TLS Connections, Allowing MitM & Data Injection
The Opossum Attack is a new desynchronization flaw exploiting implicit/opportunistic TLS in protocols like HTTP, allowing MitM to compromise encrypted connections. Over 3M servers affected.
⤷ Title: Opossum Attack: New TLS Flaw Injects Malicious Data Into Encrypted Sessions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:23:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Encryption #ftp #HTTP #man_in_the_middle #Opossum #POP3 #security flaw #SMTP #TLS #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:23:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Encryption #ftp #HTTP #man_in_the_middle #Opossum #POP3 #security flaw #SMTP #TLS #vulnerability
Penetration Testing Tools
Opossum Attack: New TLS Flaw Injects Malicious Data Into Encrypted Sessions
A new TLS vulnerability, "Opossum," allows attackers to inject malicious messages into encrypted sessions by desynchronizing client and server views.
⤷ Title: Urgent Sophos Firewall Update: Two Critical RCE Flaws (CVE-2025-6704, CVE-2025-7624) Patched via Hotfixes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 02:07:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_6704 #CVE_2025_7624 #cybersecurity #HA Mode #Hotfix #rce #Remote Code Execution #SMTP Proxy #Sophos Firewall #SPX #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 02:07:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_6704 #CVE_2025_7624 #cybersecurity #HA Mode #Hotfix #rce #Remote Code Execution #SMTP Proxy #Sophos Firewall #SPX #Vulnerability
Daily CyberSecurity
Urgent Sophos Firewall Update: Two Critical RCE Flaws (CVE-2025-6704, CVE-2025-7624) Patched via Hotfixes
Sophos patched five flaws in Sophos Firewall, including two critical RCEs (CVE-2025-6704, CVE-2025-7624) allowing remote attackers to take control under specific conditions.
⤷ Title: ✉️SMTP Enumeration: The Ethical Hacker’s Guide to Uncovering Email Vulnerabilities
════════════════════════
𐀪 Author: Rajkumar Kumawat
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 15:21:40 GMT
════════════════════════
⌗ Tags: #smtp #penetration_testing #red_team #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Rajkumar Kumawat
════════════════════════
ⴵ Time: Sat, 02 Aug 2025 15:21:40 GMT
════════════════════════
⌗ Tags: #smtp #penetration_testing #red_team #ethical_hacking #cybersecurity
Medium
✉️SMTP Enumeration: The Ethical Hacker’s Guide to Uncovering Email Vulnerabilities
By Rajkumar Kumawat 🔗 GitHub: Rjkumarkumawat
⤷ Title: Broadcom Fixes Multiple VMware vCenter and NSX Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 02:04:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CVE_2025_41250 #cybersecurity #NSX #security update #SMTP Header Injection #Username Enumeration #vCenter #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 02:04:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CVE_2025_41250 #cybersecurity #NSX #security update #SMTP Header Injection #Username Enumeration #vCenter #vmware
Daily CyberSecurity
Broadcom Fixes Multiple VMware vCenter and NSX Vulnerabilities
Broadcom patches three vulnerabilities in VMware vCenter and NSX. The flaws could lead to SMTP header injection and username enumeration, increasing the risk of unauthorized access.
⤷ Title: Room 109-SMTP: The Hidden Recon Goldmine Every Hacker Uses
════════════════════════
𐀪 Author: blackXmask
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 19:30:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #viral #hacking #smtp_server #reconnaissance
════════════════════════
𐀪 Author: blackXmask
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 19:30:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #viral #hacking #smtp_server #reconnaissance
Medium
Room 109-SMTP: The Hidden Recon Goldmine Every Hacker Uses
A beginner‑friendly guide covering how SMTP works, why it’s still used today, and how attackers leverage VRFY/EXPN, open relays, and…
⤷ Title: Phantom v3.5 Alert: New Info-Stealer Disguised as Adobe Update Uses SMTP to Loot Digital Lives
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:11:31 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Installer #Credential Theft #crypto wallet #info_stealer #JavaScript malware #K7 Security Labs #malware #Phantom Stealer #powershell #SMTP Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:11:31 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Installer #Credential Theft #crypto wallet #info_stealer #JavaScript malware #K7 Security Labs #malware #Phantom Stealer #powershell #SMTP Exfiltration
Daily CyberSecurity
Phantom v3.5 Alert: New Info-Stealer Disguised as Adobe Update Uses SMTP to Loot Digital Lives
Phantom v3.5 info-stealer targets passwords and crypto via a fake Adobe installer. It uses SMTP to exfiltrate data directly to attackers.
⤷ Title: Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
Daily CyberSecurity
Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
NIST warns of a critical Exim 4.99 flaw. A failed SQLi patch allows attackers to poison SQLite records and trigger a 1.5MB heap buffer overflow.
⤷ Title: The Outlook Freeze: New Windows 11 Update Breaks POP3 Accounts in Outlook Classic
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 10:34:33 +0000
════════════════════════
⌗ Tags: #Windows #Email Issues #KB5074109 #Microsoft Bug #Microsoft Outlook #Outlook Classic #Patch Tuesday 2026 #POP3 #SMTP #Windows 11 #Windows Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 Jan 2026 10:34:33 +0000
════════════════════════
⌗ Tags: #Windows #Email Issues #KB5074109 #Microsoft Bug #Microsoft Outlook #Outlook Classic #Patch Tuesday 2026 #POP3 #SMTP #Windows 11 #Windows Update
Daily CyberSecurity
The Outlook Freeze: New Windows 11 Update Breaks POP3 Accounts in Outlook Classic
Outlook Classic is freezing for POP3 users following the Jan 2026 KB5074109 update. Learn how to fix the "white screen" bug and restore your email.
⤷ Title: APT41’s New “Zero-Detection” Backdoor Targets Linux Workloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba Cloud #APT41 #Breakglass Intelligence #Cloud Security #Credential Harvesting #cybersecurity #ELF Backdoor #infosec #Linux Malware #SMTP C2 #Winnti
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba Cloud #APT41 #Breakglass Intelligence #Cloud Security #Credential Harvesting #cybersecurity #ELF Backdoor #infosec #Linux Malware #SMTP C2 #Winnti
Daily CyberSecurity
APT41’s New "Zero-Detection" Backdoor Targets Linux Workloads
APT41's new zero-detection ELF backdoor uses SMTP (Port 25) to hijack Linux cloud workloads invisibly. Secure your credentials—audit your SMTP traffic today.
⤷ Title: Network Enumeration Report (SMB, SMTP, SNMP, Metasploit)
════════════════════════
𐀪 Author: Youssef Ashraf
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 19:23:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #smtp #smb #snmp #ethical_hacking
════════════════════════
𐀪 Author: Youssef Ashraf
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 19:23:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #smtp #smb #snmp #ethical_hacking
Medium
Network Enumeration Report (SMB, SMTP, SNMP, Metasploit)
Enumeration is a critical phase in penetration testing where attackers actively gather detailed information from target systems. This phase…
⤷ Title: 9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:43:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BDAT #CVE_2026_45185 #Exim #GnuTLS #heap corruption #infosec #Mail Server Security #Patch Now #rce #SMTP CHUNKING #Vulnerability Alert #XBOW
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 01:43:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BDAT #CVE_2026_45185 #Exim #GnuTLS #heap corruption #infosec #Mail Server Security #Patch Now #rce #SMTP CHUNKING #Vulnerability Alert #XBOW
Daily CyberSecurity
9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover
Urgent: Exim fixes a 9.8 severity RCE (CVE-2026-45185) affecting GnuTLS builds. A single-byte heap corruption allows for server takeover. Update to 4.99.3 now!