⤷ Title: Bug Hunting: A Practical Guide to Finding Vulnerabilities That Actually Pay
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:26:22 GMT
════════════════════════
⌗ Tags: #programming #technology #bug_bounty #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:26:22 GMT
════════════════════════
⌗ Tags: #programming #technology #bug_bounty #cybersecurity #penetration_testing
Medium
Bug Hunting: A Practical Guide to Finding Vulnerabilities That Actually Pay
A beginner-friendly breakdown of recon, payloads, and vulnerability discovery.
⤷ Title: JWT Authentication Bypass via kid Header Path Traversal
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:09:35 GMT
════════════════════════
⌗ Tags: #authentication_bypass #jwt_authentication_bypass #bug_bounty #jwt_kid_vulnerability #path_traversal_exploit
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:09:35 GMT
════════════════════════
⌗ Tags: #authentication_bypass #jwt_authentication_bypass #bug_bounty #jwt_kid_vulnerability #path_traversal_exploit
Medium
JWT Authentication Bypass via kid Header Path Traversal
Understanding how insecure key lookups enable forged tokens and admin-level compromise.
⤷ Title: Tracking Hackers Online ️♂️: A Dark Web OSINT Story
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:09:26 GMT
════════════════════════
⌗ Tags: #programming #technology #cybersecurity #bug_bounty #ai
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:09:26 GMT
════════════════════════
⌗ Tags: #programming #technology #cybersecurity #bug_bounty #ai
Medium
Tracking Hackers Online 🕵️♂️🌑: A Dark Web OSINT Story
Hi Vipul from The Hacker’s Log here — ready to take you inside the real world of cyber investigation. Today, we’re going deep — into the…
⤷ Title: Free Linux hardening service
════════════════════════
𐀪 Author: ronin255
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:31:31 GMT
════════════════════════
⌗ Tags: #linux_server #hacking #web_server_hardening #linux_hardening
════════════════════════
𐀪 Author: ronin255
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:31:31 GMT
════════════════════════
⌗ Tags: #linux_server #hacking #web_server_hardening #linux_hardening
Medium
Free Linux Server hardening service
Linux, khususnya distribusi Ubuntu Server, adalah salah satu pilihan paling populer untuk membangun web server. Stabilitas, keamanan, dan…
⤷ Title: Tải Tiệm Lẩu Đường Hạnh Phúc Mod Apk (Vô Hạn Tiền, Kim Cương) V5.2.1
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:50:17 GMT
════════════════════════
⌗ Tags: #apkpure #games #hacking
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:50:17 GMT
════════════════════════
⌗ Tags: #apkpure #games #hacking
Medium
Tải Tiệm Lẩu Đường Hạnh Phúc Mod Apk (Vô Hạn Tiền, Kim Cương) V5.2.1
Tiệm Lẩu Đường Hạnh Phúc là một trò chơi di động hấp dẫn, kết hợp giữa yếu tố quản lý thời gian và mô phỏng. Trong game, người chơi sẽ vào…
⤷ Title: How to Do Threat Modelling with STRIDE (Step by Step on a Simple Web App)
════════════════════════
𐀪 Author: Akshat Patel
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:55:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_hunting #ssdlc #threat_modeling #threat_intelligence
════════════════════════
𐀪 Author: Akshat Patel
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:55:09 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_hunting #ssdlc #threat_modeling #threat_intelligence
Medium
How to Do Threat Modelling with STRIDE (Step by Step on a Simple Web App)
This is my first time doing practical threat modelling on a (toy) system end-to-end. It’s not a production app, but it was enough to make…
⤷ Title: 94 Percent of LLMs Shown to Be Vulnerable to Attack
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:45:07 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #research #llm #cybersecurity #ai_security
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:45:07 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #research #llm #cybersecurity #ai_security
Medium
94 Percent of LLMs Shown to Be Vulnerable to Attack
The unfortunate truth is that poorly designed and improperly secured Artificial Intelligence integrations can be misused or exploited by…
⤷ Title: From Code to Defense: My First Steps into Cybersecurity as a .NET/Java Developer
════════════════════════
𐀪 Author: Barbaros Emre Alagöz
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:40:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #test_automation
════════════════════════
𐀪 Author: Barbaros Emre Alagöz
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:40:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #test_automation
Medium
From Code to Defense: My First Steps into Cybersecurity as a .NET/Java Developer
Over the last weeks I’ve been moving from “just writing code” into thinking like a defender.
⤷ Title: HashJack: The Hidden URL Trick That Manipulates AI Browsers
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:32:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai_security #browser_security #hashjack #llm_security
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:32:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai_security #browser_security #hashjack #llm_security
Medium
HashJack: The Hidden URL Trick That Manipulates AI Browsers
Artificial intelligence in the browser was supposed to be the upgrade we all wanted. A built-in assistant that reads pages for us, extracts…
⤷ Title: The OSINT Mindset, Thinking Like an Investigator
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:09:20 GMT
════════════════════════
⌗ Tags: #critical_thinking #cybersecurity #investing #osint #digital_detective
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:09:20 GMT
════════════════════════
⌗ Tags: #critical_thinking #cybersecurity #investing #osint #digital_detective
Medium
The OSINT Mindset, Thinking Like an Investigator
It’s Not About the Tools, It’s About the Questions You Ask Before You Search.
⤷ Title: Cybersecurity: ความจริงที่ SME มองข้ามไม่ได้อีกต่อไป และวิธีที่ Krungsri Business Online Mobile…
════════════════════════
𐀪 Author: Krungsri Nimble
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:02:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #krungsri_nimble #trust #small_business
════════════════════════
𐀪 Author: Krungsri Nimble
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:02:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #krungsri_nimble #trust #small_business
Medium
🔐 Cybersecurity: ความจริงที่ SME มองข้ามไม่ได้อีกต่อไป และวิธีที่ Krungsri Business Online Mobile เปลี่ยนเกมความปลอดภัยให้ธุรกิจไทย
มีข้อมูลหนึ่งที่น่าตกใจ แต่สะท้อนสถานการณ์จริงของ SME ไทยในปีนี้อย่างชัดเจน:
⤷ Title: Cicada — HTB Walkthrough | From Enumeration to PrivEsc with SeBackupPrivilege (Smart Path)
════════════════════════
𐀪 Author: Xploitnik
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:25:12 GMT
════════════════════════
⌗ Tags: #htb #penetration_testing #ctf #windows #cybersecurity
════════════════════════
𐀪 Author: Xploitnik
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:25:12 GMT
════════════════════════
⌗ Tags: #htb #penetration_testing #ctf #windows #cybersecurity
Medium
🐞 Cicada — HTB Walkthrough | From Enumeration to PrivEsc with SeBackupPrivilege (Smart Path)
This is a focused, methodical walkthrough of the Cicada machine from Hack The Box, highlighting real-world attacker behavior, clean…
⤷ Title: VPN for China: Only 5 still work in the 2025 real-world test
════════════════════════
𐀪 Author: Safelyo VPN
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:21:33 GMT
════════════════════════
⌗ Tags: #technology #vpn #cybersecurity #privacy #safelyo
════════════════════════
𐀪 Author: Safelyo VPN
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:21:33 GMT
════════════════════════
⌗ Tags: #technology #vpn #cybersecurity #privacy #safelyo
Medium
VPN for China: Only 5 still work in the 2025 real-world test
The Challenge of Connectivity in China
⤷ Title: Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:28:06 +0000
════════════════════════
⌗ Tags: #Technology #AI Confession #AI safety #Hallucination #LLM Training #OpenAI #Reward Hacking #Sycophancy #transparency
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:28:06 +0000
════════════════════════
⌗ Tags: #Technology #AI Confession #AI safety #Hallucination #LLM Training #OpenAI #Reward Hacking #Sycophancy #transparency
Daily CyberSecurity
Honesty is the Best Policy: OpenAI Trains AI Models to 'Confess' Errors and Hallucinations
OpenAI is testing a "Confession" mechanism to reduce hallucinations. Models are trained to disclose internal flaws and lies, rewarding them for candor over accuracy.
⤷ Title: New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:23:12 +0000
════════════════════════
⌗ Tags: #Android #30_Second Delay #android #Call Scam #Cash App #Financial Security #fraud protection #Google Play Services #JPMorgan Chase #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:23:12 +0000
════════════════════════
⌗ Tags: #Android #30_Second Delay #android #Call Scam #Cash App #Financial Security #fraud protection #Google Play Services #JPMorgan Chase #social engineering
Daily CyberSecurity
New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use
Google expanded Android's call-scam protection. It detects suspicious calls while financial apps are open, triggering a 30-second mandatory pause for users.
⤷ Title: Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:19:39 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Censorship #End_to_End Encryption #FaceTime #Network Blockade #Roskomnadzor #russia #Tech Policy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:19:39 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Censorship #End_to_End Encryption #FaceTime #Network Blockade #Roskomnadzor #russia #Tech Policy
Daily CyberSecurity
Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime
Russia imposed a network-level blockade on Apple's encrypted FaceTime service, citing its alleged use for coordinating fraud and terrorist attacks, making the app unusable.
⤷ Title: Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache HTTP Server #CVE_2025_59775 #NTLM Leak #ssrf #suexec Bypass #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache HTTP Server #CVE_2025_59775 #NTLM Leak #ssrf #suexec Bypass #Windows Security
Daily CyberSecurity
Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
Apache HTTP Server 2.4.66 patched five flaws. Key fixes include a moderate SSRF flaw (CVE-2025-59775) that risks NTLM hash leakage on Windows, and a mod_userdir/suexec bypass. Update immediately.
⤷ Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Daily CyberSecurity
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy "Smart Mining" Evasion
ASEC exposed PrintMiner, a Monero cryptominer spreading via USB LNK files. It uses DLL Side-Loading (printui.exe) and "Smart Mining" to suspend activity when games or Task Manager are opened.
⤷ Title: The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:21:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:21:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
Apache patched a Catastrophic XXE flaw (CVE-2025-66516, CVSS 10.0) in Tika Core. The bug is exploitable via malicious XFA data inside a PDF, risking server-side data disclosure and RCE. Update immediately.
⤷ Title: “React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
Daily CyberSecurity
"React2Shell" Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
Amazon exposed Chinese APTs exploiting the React2Shell zero-day (CVE-2025-55182, CVSS 10.0) hours after disclosure. Earth Lamia and Jackpot Panda are actively targeting unpatched Next.js servers for reconnaissance.