⤷ Title: HackTheBox Password Attacks; Attacking Windows Credential Manager
════════════════════════
𐀪 Author: Taxaneh
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 13:34:21 GMT
════════════════════════
⌗ Tags: #windows #hacking #hack_the_box_writeup #htb_writeup #credentials
════════════════════════
𐀪 Author: Taxaneh
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 13:34:21 GMT
════════════════════════
⌗ Tags: #windows #hacking #hack_the_box_writeup #htb_writeup #credentials
⤷ Title: Top 3 tools for Bug Bounty/Pentesting (2025)
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 16:22:33 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 16:22:33 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked
Medium
Top 3 tools for Bug Bounty/Pentesting (2025)
There are lots of web app security tools. Some of them are very well known, like BurpSuite, Nmap, Nuclei, ffuf, etc, whilst others, even…
⤷ Title: Your “Everyone” Problem: Exposing Share Access at Scale
════════════════════════
𐀪 Author: Moritz Rauch
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 13:04:56 GMT
════════════════════════
⌗ Tags: #credentials #access_control #penetration_testing #active_directory #cybersecurity
════════════════════════
𐀪 Author: Moritz Rauch
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 13:04:56 GMT
════════════════════════
⌗ Tags: #credentials #access_control #penetration_testing #active_directory #cybersecurity
Medium
Your “Everyone” Problem: Exposing Share Access at Scale
Introducing Pillage Suite — a toolset to enumerate, index and analyze effective permissions and file contents in all your network shares
⤷ Title: Bug Hunting Journey: Discovering UID and Email Token Exposure in Encoded URLs
════════════════════════
𐀪 Author: Faxcel
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 07:43:07 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #vulnerability #cybersecurity
════════════════════════
𐀪 Author: Faxcel
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 07:43:07 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #vulnerability #cybersecurity
Medium
Bug Hunting Journey: Discovering UID and Email Token Exposure in Encoded URLs
Hello readers, Thank you for taking the time to read my write-up. Today, I want to share one of my bug hunting findings. While it was…
⤷ Title: The Quiet Threat: Why Ransomware and Infostealers Are Succeeding Where Encryption Fails
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 23:21:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blue Report #Credentials #cybersecurity #Data Exfiltration #Infostealer #Lateral Movement #Picus Security #ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 23:21:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blue Report #Credentials #cybersecurity #Data Exfiltration #Infostealer #Lateral Movement #Picus Security #ransomware
Penetration Testing Tools
The Quiet Threat: Why Ransomware and Infostealers Are Succeeding Where Encryption Fails
A new report reveals ransomware is shifting from encryption to "quiet" tactics like credential theft and data exfiltration, rendering traditional defenses ineffective.
⤷ Title: Digiever NVR Flaws (CVE-2025-10264, CVE-2025-10265) Let Hackers Steal Credentials & Take Control
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Sep 2025 00:30:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #credentials #CVE #cybersecurity #Digiever #NVR #Remote Code Execution #security advisory #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Sep 2025 00:30:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #credentials #CVE #cybersecurity #Digiever #NVR #Remote Code Execution #security advisory #Vulnerability
Daily CyberSecurity
Digiever NVR Flaws (CVE-2025-10264, CVE-2025-10265) Let Hackers Steal Credentials & Take Control
Two critical vulnerabilities (CVSS 10 & 9.8) in Digiever NVRs allow unauthenticated attackers to steal credentials and execute commands. Update your firmware immediately.
⤷ Title: Old or Unused Breached Data Can Still Complete Full Profiles of Potential Attack Targets
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 00:20:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #darkweb #credentials #data_analysis
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 00:20:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #darkweb #credentials #data_analysis
Medium
Old or Unused Breached Data Can Still Complete Full Profiles of Potential Attack Targets
Misconceptions About Immediate Use
⤷ Title: A New Crisis for CrowdStrike: A Self-Replicating Worm Has Compromised Its NPM Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 03:59:30 +0000
════════════════════════
⌗ Tags: #Malware #credentials theft #CrowdStrike #cybersecurity #malware #NPM packages #self_replicating worm #Shai_Hulud #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 03:59:30 +0000
════════════════════════
⌗ Tags: #Malware #credentials theft #CrowdStrike #cybersecurity #malware #NPM packages #self_replicating worm #Shai_Hulud #supply chain attack
Daily CyberSecurity
A New Crisis for CrowdStrike: A Self-Replicating Worm Has Compromised Its NPM Packages
A new worm, Shai-Hulud, has compromised CrowdStrike’s NPM packages. The malware steals credentials and can spread rapidly across the developer ecosystem.
⤷ Title: Warning: Popular Apps Leaking Your Private Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 20 Sep 2025 00:00:35 +0000
════════════════════════
⌗ Tags: #Data Leak #App Vulnerability #credentials #cybersecurity #Data Breach #mobile security #PII #Public Wi_Fi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 20 Sep 2025 00:00:35 +0000
════════════════════════
⌗ Tags: #Data Leak #App Vulnerability #credentials #cybersecurity #Data Breach #mobile security #PII #Public Wi_Fi
Daily CyberSecurity
Warning: Popular Apps Leaking Your Private Data
Two popular apps, one for healthcare and one for jewelry, are leaking sensitive user data over unencrypted connections. Learn how this vulnerability puts you at risk.
⤷ Title: Advanced Credential Dumping Techniques with Mimikatz
════════════════════════
𐀪 Author: Esra Kayhan
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 07:21:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #mimikatz #credentials #techniques #security
════════════════════════
𐀪 Author: Esra Kayhan
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 07:21:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #mimikatz #credentials #techniques #security
Medium
🔑 Advanced Credential Dumping Techniques with Mimikatz
Today, we’re diving into a topic you’ve probably heard about but might be hesitant to explore in depth: Mimikatz and its advanced…
⤷ Title: PhantomRaven Attack: New Malware Steals CI/CD Secrets via AI Slopsquatting on npm
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:06:02 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD #Credentials #Generative AI #npm #PhantomRaven #security #Slopsquatting #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:06:02 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD #Credentials #Generative AI #npm #PhantomRaven #security #Slopsquatting #Supply Chain
Penetration Testing Tools
PhantomRaven Attack: New Malware Steals CI/CD Secrets via AI Slopsquatting on npm
New PhantomRaven npm malware uses AI "slopsquatting" and invisible dynamic dependencies to steal GitHub, GitLab, and CI/CD tokens. Update vigilance now.
⤷ Title: Avoid Leaking Secrets In Your Code
════════════════════════
𐀪 Author: Til Schwarze
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 14:18:39 GMT
════════════════════════
⌗ Tags: #secrets #information_security #credentials #python #hacking
════════════════════════
𐀪 Author: Til Schwarze
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 14:18:39 GMT
════════════════════════
⌗ Tags: #secrets #information_security #credentials #python #hacking
Medium
Avoid Leaking Secrets In Your Code
With many new faces in the coding communtiy, one problem has been appearing more and more. Developers hard-code their secrets (API-Keys…
⤷ Title: TryHackMEVMs: BruteMe
════════════════════════
𐀪 Author: Justin Jude Cabodil
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 11:26:58 GMT
════════════════════════
⌗ Tags: #credentials #tryhackme #brute_force #hacking #linux
════════════════════════
𐀪 Author: Justin Jude Cabodil
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 11:26:58 GMT
════════════════════════
⌗ Tags: #credentials #tryhackme #brute_force #hacking #linux
Medium
TryHackMEVMs: BruteMe
Vulnerability Assessment and Penetration Test Report
⤷ Title: Top 3 tools for Bug Bounty/Pentesting (2025)
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:32:45 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:32:45 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked
Medium
Top 3 tools for Bug Bounty/Pentesting (2025)
There are lots of web app security tools. Some of them are very well known, like BurpSuite, Nmap, Nuclei, ffuf, etc, whilst others, even…
⤷ Title: SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
Daily CyberSecurity
SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
SantaStealer, a new MaaS info-stealer, is being aggressively marketed on the dark web. It's a BluelineStealer rebrand that uses C code and open-source libraries to steal crypto wallets and credentials, despite having amateur anti-analysis features.
⤷ Title: From recon to AWS and DB credentials leaked
════════════════════════
𐀪 Author: pr1vacy
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 04:02:50 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #ssrf
════════════════════════
𐀪 Author: pr1vacy
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 04:02:50 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #ssrf
Medium
From recon to AWS and DB credentials leaked
Hi everyone, it’s me pr1vacy from Abyssal Hunter.
Today, I’m sharing a write-up on how I turned my recon phase into an AWS and DB…
Today, I’m sharing a write-up on how I turned my recon phase into an AWS and DB…
⤷ Title: API Keys, Tokens & Secrets: How They Leak and How Developers can Avoid it
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 01:21:19 GMT
════════════════════════
⌗ Tags: #api #sdlc #credentials #api_key #application_security
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 01:21:19 GMT
════════════════════════
⌗ Tags: #api #sdlc #credentials #api_key #application_security
Medium
API Keys, Tokens & Secrets: How They Leak and How Developers can Avoid it
Credential exposures are one of the fastest paths to compromise. In 2024 alone, GitHub detected over 39M leaked secrets across its…
⤷ Title: Install dan Penggunaan Bettercap Bahasa Indo
════════════════════════
𐀪 Author: Hananda Gagas
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 09:14:45 GMT
════════════════════════
⌗ Tags: #sniffing #indonesia #red_team #hacking #credentials
════════════════════════
𐀪 Author: Hananda Gagas
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 09:14:45 GMT
════════════════════════
⌗ Tags: #sniffing #indonesia #red_team #hacking #credentials
Medium
Install dan Penggunaan Bettercap Bahasa Indo
Halo guys, ini tulisan pertama gw semoga membantu :)
⤷ Title: Cap Machine / writeup / IDOR, PCAP ...
════════════════════════
𐀪 Author: Achraf Nouri
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 16:26:52 GMT
════════════════════════
⌗ Tags: #credentials_reuse #penetration_testing #pcap_analysis #idor_vulnerability
════════════════════════
𐀪 Author: Achraf Nouri
════════════════════════
ⴵ Time: Thu, 19 Feb 2026 16:26:52 GMT
════════════════════════
⌗ Tags: #credentials_reuse #penetration_testing #pcap_analysis #idor_vulnerability
Medium
Cap Machine / writeup / IDOR, PCAP ...
Machine Name: CAP Difficulty: Easy Operating System: Linux Category: Web / Credential Reuse / Linux Capabilities Author: Achraf Nouri Cap is an easy Linux machine that demonstrates several …
⤷ Title: Desert Power in the Code: How the “Mini Shai-Hulud” Malware Burrows into SAP’s npm Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 04 May 2026 07:44:09 +0000
════════════════════════
⌗ Tags: #Malware #@cap_js #CI/CD Security #CircleCI #cloud security #Credentials Theft #Cyber Security 2026 #GitHub Actions #malware #Mini Shai_Hulud #npm #SAP #supply chain attack
Information Security News
Desert Power in the Code: How the "Mini Shai-Hulud" Malware Burrows into SAP’s npm Supply Chain
Adversaries have once again targeted the npm supply chain, though this incursion pursued a surgical and perilous objective: