⤷ Title: BFScan: Uncover Hidden URLs, Paths, & Secrets in JAR/WAR/APK Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:39:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #apk #application security #BFScan #cybersecurity #HTTP Request Generation #JAR #OpenAPI #Secret Detection #security tool #URL Discovery #WAR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:39:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #apk #application security #BFScan #cybersecurity #HTTP Request Generation #JAR #OpenAPI #Secret Detection #security tool #URL Discovery #WAR
Penetration Testing Tools
BFScan: Uncover Hidden URLs, Paths, & Secrets in JAR/WAR/APK Files
BFScan is a powerful tool to extract URLs, paths, and secrets from JAR, WAR, and APK files, generating raw HTTP requests and OpenAPI specs for security analysis.
⤷ Title: A Secret Store Is NOT A Substitute For Actually Protecting Your API Keys
════════════════════════
𐀪 Author: Andrew Zuo
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 21:58:44 GMT
════════════════════════
⌗ Tags: #api_key #secret_store #api_security #secret_management_tools #cybersecurity
════════════════════════
𐀪 Author: Andrew Zuo
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 21:58:44 GMT
════════════════════════
⌗ Tags: #api_key #secret_store #api_security #secret_management_tools #cybersecurity
Medium
A Secret Store Is NOT A Substitute For Actually Protecting Your API Keys
I was in Cloudflare the other day and I saw this:
⤷ Title: Leaking Secrets : Building an LLM-Powered Secret Scanner for Codebases
════════════════════════
𐀪 Author: Aishwarya Athreya
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 22:44:33 GMT
════════════════════════
⌗ Tags: #secret_scanner #application_security #security_tool #llm_security
════════════════════════
𐀪 Author: Aishwarya Athreya
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 22:44:33 GMT
════════════════════════
⌗ Tags: #secret_scanner #application_security #security_tool #llm_security
Medium
Leaking Secrets : Building an LLM-Powered Secret Scanner for Codebases
Scan for secrets using regex+entropy with LLM
⤷ Title: Russian State Hackers Spy on Moscow Embassies via ISP-Level AiTM Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 02:53:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #adversary_in_the_middle #AiTM #ApolloShadow #Cyberespionage #Embassies #Moscow #russia #Secret Blizzard #SORM #turla
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 02:53:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #adversary_in_the_middle #AiTM #ApolloShadow #Cyberespionage #Embassies #Moscow #russia #Secret Blizzard #SORM #turla
Daily CyberSecurity
Russian State Hackers Spy on Moscow Embassies via ISP-Level AiTM Attacks
Microsoft reveals Russian state actor Secret Blizzard is targeting foreign embassies in Moscow with ISP-level AiTM attacks, deploying ApolloShadow malware to spy on diplomats.
⤷ Title: Preventing and Fixing Secret Leaks in Git Repos — A CloudOps Guide
════════════════════════
𐀪 Author: CloudweldOps
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 05:29:54 GMT
════════════════════════
⌗ Tags: #devops #cybersecurity #cloud_security #secret_management_tools #gitleaks
════════════════════════
𐀪 Author: CloudweldOps
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 05:29:54 GMT
════════════════════════
⌗ Tags: #devops #cybersecurity #cloud_security #secret_management_tools #gitleaks
Medium
Preventing and Fixing Secret Leaks in Git Repos — A CloudOps Guide
In the age of cloud-native development, a single leaked API key can cost thousands — or worse, lead to a breach.
From AWS access keys to…
From AWS access keys to…
⤷ Title: U.S. Airlines Caught Selling Passenger Data for Warrantless Searches
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 09:19:08 +0000
════════════════════════
⌗ Tags: #Data Leak #Airlines #Airlines Reporting Corporation #cybersecurity #Data Broker #privacy #Secret Service #Surveillance
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 09:19:08 +0000
════════════════════════
⌗ Tags: #Data Leak #Airlines #Airlines Reporting Corporation #cybersecurity #Data Broker #privacy #Secret Service #Surveillance
Penetration Testing Tools
U.S. Airlines Caught Selling Passenger Data for Warrantless Searches
A new report reveals a data broker owned by major U.S. airlines is selling billions of passenger records to government agencies for warrantless searches.
⤷ Title: MI6 Launches a Darknet Portal to Recruit Spies and Informants
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 02:25:56 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybersecurity #Darknet #Espionage #intelligence #MI6 #Secret Intelligence Service #Silent Courier #Tor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 02:25:56 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybersecurity #Darknet #Espionage #intelligence #MI6 #Secret Intelligence Service #Silent Courier #Tor
Penetration Testing Tools
MI6 Launches a Darknet Portal to Recruit Spies and Informants
MI6 has launched Silent Courier, a darknet portal and YouTube channel that allows anyone to securely and anonymously contact British intelligence.
⤷ Title: Silent Threat: Secret Service Dismantles Network Capable of Crippling NYC’s Communications
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 07:53:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Espionage #National Security #Secret Service #Telecommunications
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 07:53:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Espionage #National Security #Secret Service #Telecommunications
Penetration Testing Tools
Silent Threat: Secret Service Dismantles Network Capable of Crippling NYC's Communications
The Secret Service has dismantled a massive, covert network near the UN in NYC, capable of disrupting mobile towers and launching devastating cyberattacks.
⤷ Title: Secret Service Busts Covert Telecom Network Capable of Crippling NYC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #cybersecurity #national security #Secret Service #Telecommunications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #cybersecurity #national security #Secret Service #Telecommunications
Daily CyberSecurity
Secret Service Busts Covert Telecom Network Capable of Crippling NYC
The Secret Service has dismantled a vast telecom network near the UN capable of disabling cell towers, disrupting communications, and aiding foreign threats.
⤷ Title: Web3 Crisis: Sub-$1k Hardware Attack Fully Extracts Intel SGX Attestation Key, Compromising Encrypted Blockchains
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:43:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #blockchain #confidential computing #Crust #DCAP #Hardware Attack #Intel SGX #Phala #Secret #TEE Bypass #Web3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:43:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #blockchain #confidential computing #Crust #DCAP #Hardware Attack #Intel SGX #Phala #Secret #TEE Bypass #Web3
Penetration Testing Tools
Web3 Crisis: Sub-$1k Hardware Attack Fully Extracts Intel SGX Attestation Key, Compromising Encrypted Blockchains
Researchers extracted the Intel SGX DCAP attestation key using a sub-$1k hardware interposer. This attack breaks the root of trust, allowing attackers to forge quotes and compromise Web3 ecosystems.
⤷ Title: Hackers abused a legitimate forensic tool “Velociraptor”, to Sneak into the Networks and build…
════════════════════════
𐀪 Author: Mohana Reddy
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 07:10:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #forensic_tool_exploit #velociraptor_tool_abuse #ransomware #secret_tunnels_hack
════════════════════════
𐀪 Author: Mohana Reddy
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 07:10:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #forensic_tool_exploit #velociraptor_tool_abuse #ransomware #secret_tunnels_hack
Medium
Hackers abused a legitimate forensic tool “Velociraptor”, to Sneak into the Networks and build…
Cybersecurity is like a game where the Security Implementers try to protect computers, but the malicious actors keeps finding the new ways…
⤷ Title: Jenkins Faces Wave of Plugin Flaws, Including SAML Authentication Bypass (CVE-2025-64131)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:08:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_64131 #Jenkins #Plugin Vulnerability #SAML #Secret Exposure #Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:08:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_64131 #Jenkins #Plugin Vulnerability #SAML #Secret Exposure #Session Hijacking
Daily CyberSecurity
Jenkins Faces Wave of Plugin Flaws, Including SAML Authentication Bypass (CVE-2025-64131)
Jenkins warned of a Critical SAML Plugin flaw (CVE-2025-64131) that allows session replay/hijacking due to a missing cache. Multiple plugins also expose API tokens in plaintext.
⤷ Title: Unmasking the Code: JS Analyzer Automates JavaScript Recon & Secret Discovery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 04:44:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #API Discovery #bug bounty #Burp Suite #InfoSec 2026 #JavaScript #JS Analyzer #Pentesting #Recon #secret scanning #Static Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 04:44:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #API Discovery #bug bounty #Burp Suite #InfoSec 2026 #JavaScript #JS Analyzer #Pentesting #Recon #secret scanning #Static Analysis
Information Security News
Unmasking the Code: JS Analyzer Automates JavaScript Recon & Secret Discovery
JS Analyzer A powerful Burp Suite extension for JavaScript static analysis. Extracts API endpoints, URLs, secrets, and email addresses from JavaScript files with intelligent noise filtering. The g…
⤷ Title: Gatekeeper Breached: 4 Critical Ingress-Nginx Flaws Risk Cluster Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 10:13:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #cloud_native #container security #DevSecOps #ingress_nginx #Kubernetes #Patch Alert #rce #Secret Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 10:13:55 +0000
════════════════════════
⌗ Tags: #Vulnerability #cloud_native #container security #DevSecOps #ingress_nginx #Kubernetes #Patch Alert #rce #Secret Disclosure
Daily CyberSecurity
Gatekeeper Breached: 4 Critical Ingress-Nginx Flaws Risk Cluster Secrets
Critical Ingress-Nginx flaws (CVE-2026-1580) allow RCE and secret theft via config injection. Upgrade to v1.13.7 or v1.14.3 immediately to secure K8s.
⤷ Title: The Next.js Nightmare? Vercel Investigates “Critical” Internal Breach and Supply Chain Threat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:59:43 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity news #Data Breach #github #infosec #Next.js #npm #Secret Rotation #ShinyHunters #supply chain attack #Turbo.js #Vercel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 19 Apr 2026 23:59:43 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity news #Data Breach #github #infosec #Next.js #npm #Secret Rotation #ShinyHunters #supply chain attack #Turbo.js #Vercel
Daily CyberSecurity
The Next.js Nightmare? Vercel Investigates "Critical" Internal Breach and Supply Chain Threat
Vercel investigates a major breach by ShinyHunters. With Next.js source code and tokens at risk, developers must rotate secrets immediately. Stay updated.
⤷ Title: Supply Chain Sabotage: Bitwarden CLI Compromised in Global “Checkmarx” Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Apr 2026 01:41:43 +0000
════════════════════════
⌗ Tags: #Malware #Bitwarden #Bitwarden CLI #bw1.js #Checkmarx Campaign #cybersecurity #Dune Malware #GitHub Actions #infosec #malware #secret management #supply chain attack
Daily CyberSecurity
Supply Chain Sabotage: Bitwarden CLI Compromised in Global "Checkmarx" Campaign
Bitwarden CLI v2026.4.0 compromised in "Dune"-themed supply chain attack. Malware steals cloud secrets and SSH keys. Rotate your credentials immediately.
⤷ Title: The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
Daily CyberSecurity
The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
Socket uncovers a massive Mini Shai-Hulud breach in the Intercom PHP SDK. Malicious version 5.0.2 steals cloud secrets and GitHub tokens. Rotate keys now!
⤷ Title: Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 12:03:35 +0000
════════════════════════
⌗ Tags: #Malware #cyber_espionage #In_Memory Injection #infosec #Kazuar Backdoor #Microsoft Threat Intelligence #Module Election #P2P Botnet #Pelmeni Dropper #Secret Blizzard #turla
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 12:03:35 +0000
════════════════════════
⌗ Tags: #Malware #cyber_espionage #In_Memory Injection #infosec #Kazuar Backdoor #Microsoft Threat Intelligence #Module Election #P2P Botnet #Pelmeni Dropper #Secret Blizzard #turla
Daily CyberSecurity
Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem
Microsoft Threat Intelligence exposes a massive overhaul of the Kazuar backdoor. Secret Blizzard weaponizes a modular, multi-tiered P2P botnet.