⤷ Title: Apache Fory Vulnerability: High Severity Flaw Bypasses Core Java Serialization Checks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 16:36:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fory #CVE_2026_50076 #deserialization flaw #fory_core #Java security #Software Patch
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 16:36:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fory #CVE_2026_50076 #deserialization flaw #fory_core #Java security #Software Patch
Daily CyberSecurity
Apache Fory Vulnerability: High Severity Flaw Bypasses Core Java Serialization Checks
Learn how a new Apache Fory vulnerability impacts Java platforms. Apply the urgent Apache Fory vulnerability patch to protect your enterprise nodes.
⤷ Title: Spring Boot 4.1’s New SSRF Filter Never Touched My Feign Calls — Here’s the Trap
════════════════════════
𐀪 Author: HobbiesPark
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #spring_security #java #spring_boot #microservices #ssrf
════════════════════════
𐀪 Author: HobbiesPark
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #spring_security #java #spring_boot #microservices #ssrf
Medium
Spring Boot 4.1’s New SSRF Filter Never Touched My Feign Calls — Here’s the Trap
I upgraded a service to Spring Boot 4.1, switched on its new SSRF filter, and braced for the usual fallout — a global block rule shredding…
⤷ Title: How Spring Data JPA Protects You from SQL Injection Without You Knowing
════════════════════════
𐀪 Author: Najee Shaheen
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 09:24:52 GMT
════════════════════════
⌗ Tags: #spring_boot #backend_development #sql_injection #java #cybersecurity
════════════════════════
𐀪 Author: Najee Shaheen
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 09:24:52 GMT
════════════════════════
⌗ Tags: #spring_boot #backend_development #sql_injection #java #cybersecurity
Medium
How Spring Data JPA Protects You from SQL Injection Without You Knowing
SQL injection has been a known vulnerability for 25 years, and we’re not making good progress at preventing it.
⤷ Title: Unlock Your Future with Java Training: The Ultimate Guide to Mastering Programming
════════════════════════
𐀪 Author: KOMAL PAL
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 02:34:40 GMT
════════════════════════
⌗ Tags: #javascript #java #digital_marketing #ethical_hacking #python
════════════════════════
𐀪 Author: KOMAL PAL
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 02:34:40 GMT
════════════════════════
⌗ Tags: #javascript #java #digital_marketing #ethical_hacking #python
Medium
Unlock Your Future with Java Training: The Ultimate Guide to Mastering Programming
In today’s fast-paced digital world, Java training stands out as a gateway to lucrative tech careers. Whether you’re a fresh graduate or a…
⤷ Title: How Your Spring Boot API Leaks Data (And Why Adding an Auth Check Isn’t the Fix)
════════════════════════
𐀪 Author: Najee Shaheen
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 15:28:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #idor #application_security #java #spring_boot
════════════════════════
𐀪 Author: Najee Shaheen
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 15:28:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #idor #application_security #java #spring_boot
Medium
How Your Spring Boot API Leaks Data (And Why Adding an Auth Check Isn’t the Fix)
BOLA/IDOR is the #1 API vulnerability on OWASP’s list. Most backend developers ship it constantly without knowing its name.
⤷ Title: Public PoC Exploit Released for fastjson 1.2.83 Remote Code Execution Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:18:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Deserialization #Fastjson #fastjson2 #FearsOff #java #proof_of_concept #QVD_2026_43021 #Remote Code Execution #SafeMode #Spring Boot
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:18:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Deserialization #Fastjson #fastjson2 #FearsOff #java #proof_of_concept #QVD_2026_43021 #Remote Code Execution #SafeMode #Spring Boot
Daily CyberSecurity
Public PoC Exploit Released for fastjson 1.2.83 Remote Code Execution Flaw
TL;DR Researcher Kirill Firsov disclosed a fastjson RCE on July 19, 2026. It affects fastjson 1.2.68 through 1.2.83 under stock default settings. Full technical details are public, and third parti…
⤷ Title: Web Frameworks: Java | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #red_team #java #cybersecurity #tryhackme
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:01 GMT
════════════════════════
⌗ Tags: #red_team #java #cybersecurity #tryhackme
Medium
Web Frameworks: Java | TryHackMe
Review Spring Boot source, find the framework-specific sinks, and exploit each on the lab machine.
⤷ Title: Day 204 — How to Renew an Application Certificate and Create a Java JKS Truststore
════════════════════════
𐀪 Author: Alok Rahul
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 07:21:39 GMT
════════════════════════
⌗ Tags: #java #application_security #software_engineering #software_development
════════════════════════
𐀪 Author: Alok Rahul
════════════════════════
ⴵ Time: Sat, 25 Jul 2026 07:21:39 GMT
════════════════════════
⌗ Tags: #java #application_security #software_engineering #software_development
Medium
Day 204 — How to Renew an Application Certificate and Create a Java JKS Truststore
22nd July 2026, Netherlands — Certificates are commonly used to secure communication between applications, APIs, databases, message…
⤷ Title: We Built the Only Java Static Analyzer That Finds What Semgrep, CodeQL, and the We Built the Only…
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 16:17:56 GMT
════════════════════════
⌗ Tags: #java #cybersecurity #application_security #static_analysis #spring_boot
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 16:17:56 GMT
════════════════════════
⌗ Tags: #java #cybersecurity #application_security #static_analysis #spring_boot
Medium
We Built the Only Java Static Analyzer That Finds What Semgrep, CodeQL, and the We Built the Only Java Static Analyzer That Finds…
The problem nobody talks aboutICLR 2025 IRIS Paper All Miss
⤷ Title: 7 Reasons Why Java Frameworks are Used for API Development
════════════════════════
𐀪 Author: Sahil Khurana
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 04:51:49 GMT
════════════════════════
⌗ Tags: #scalable_systems #backend_performance #api_development #application_security #java_frameworks
════════════════════════
𐀪 Author: Sahil Khurana
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 04:51:49 GMT
════════════════════════
⌗ Tags: #scalable_systems #backend_performance #api_development #application_security #java_frameworks
Medium
7 Reasons Why Java Frameworks are Used for API Development
There’s no shortage of options for building an API in 2026. Node.js, Go, FastAPI, Kotlin, Rust — all of these show up in production, all of…
⤷ Title: We Found Authorization Vulnerabilities in Two of GitHub’s Most-Starred Java Repositories — Semgrep…
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #spring_boot #application_security #java #static_analysis
════════════════════════
𐀪 Author: Suman Lamichhane
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #spring_boot #application_security #java #static_analysis
Medium
We Found Authorization Vulnerabilities in Two of GitHub’s Most-Starred Java Repositories — Semgrep and CodeQL Both Missed Them
110,000 combined stars. Zero authorization findings from the industry-standard scanners. Here’s what a purpose-built tool found instead.
⤷ Title: Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:35:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts #CVE_2026_73631 #CVE_2026_73632 #CVE_2026_73633 #CVE_2026_73634 #CVE_2026_73635 #Denial of Service #Java Web Security #JSON Plugin #Struts 2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 13:35:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts #CVE_2026_73631 #CVE_2026_73632 #CVE_2026_73633 #CVE_2026_73634 #CVE_2026_73635 #Denial of Service #Java Web Security #JSON Plugin #Struts 2
Daily CyberSecurity
Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs
Apache patched five bugs in Struts 2 this week. Three of them count as Apache Struts DoS flaws that a remote user can trigger. The other two leak data through a shared state bug in the JSON plugin…
⤷ Title: CVE-2026–40901: DataEase Root RCE via Unfiltered Quartz Deserialization
════════════════════════
𐀪 Author: Guidancewhite
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 06:57:55 GMT
════════════════════════
⌗ Tags: #sql_injection #rce #vulnerability #database #java
════════════════════════
𐀪 Author: Guidancewhite
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 06:57:55 GMT
════════════════════════
⌗ Tags: #sql_injection #rce #vulnerability #database #java
Medium
CVE-2026–40901: DataEase Root RCE via Unfiltered Quartz Deserialization
1. Overview
⤷ Title: Hack The Box:MODULE 06 — JAVA SCRIPT DEOBFUSCATION
════════════════════════
𐀪 Author: Hassan
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 17:29:42 GMT
════════════════════════
⌗ Tags: #hackthebox #hackthebox_writeup #javadeobfuscation #java_deofuscation
════════════════════════
𐀪 Author: Hassan
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 17:29:42 GMT
════════════════════════
⌗ Tags: #hackthebox #hackthebox_writeup #javadeobfuscation #java_deofuscation
Medium
Hack The Box:MODULE 06 — JAVA SCRIPT DEOBFUSCATION
From here you can access the room: https://academy.hackthebox.com/app/module/41
⤷ Title: What Closing 9 High-Severity Security Findings Taught Me About Auth, CSRF, and SSRF
════════════════════════
𐀪 Author: Md Farazul Haque
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 09:16:14 GMT
════════════════════════
⌗ Tags: #java #security #spring_boot #xss_vulnerability
════════════════════════
𐀪 Author: Md Farazul Haque
════════════════════════
ⴵ Time: Sun, 13 Sep 2026 09:16:14 GMT
════════════════════════
⌗ Tags: #java #security #spring_boot #xss_vulnerability
Medium
What Closing 9 High-Severity Security Findings Taught Me About Auth, CSRF, and SSRF
Over the past year I worked through two internal security reviews on a production Spring Boot service, closing nine High-severity findings…
⤷ Title: I had a lot of fun writing Java client for SMB from scratch
════════════════════════
𐀪 Author: Jakub Stonavsky
════════════════════════
ⴵ Time: Mon, 14 Sep 2026 16:04:18 GMT
════════════════════════
⌗ Tags: #software_testing #cybersecurity #java #reverse_engineering #penetration_testing
════════════════════════
𐀪 Author: Jakub Stonavsky
════════════════════════
ⴵ Time: Mon, 14 Sep 2026 16:04:18 GMT
════════════════════════
⌗ Tags: #software_testing #cybersecurity #java #reverse_engineering #penetration_testing
Medium
I had a lot of fun writing Java client for SMB from scratch
I needed to support SMB protocol in VirtuProbe, and decided to ejnoy another RFC and code my own client library.
⤷ Title: Yapay Zekâ ile Güvenli Kod Geliştirme: Java Spring Boot, React ve PostgreSQL ile Secure SDLC
════════════════════════
𐀪 Author: Tunahan Güral
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 10:58:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_coding #application_security #java #artificial_intelligence
════════════════════════
𐀪 Author: Tunahan Güral
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 10:58:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #secure_coding #application_security #java #artificial_intelligence
Medium
Yapay Zekâ ile Güvenli Kod Geliştirme: Java Spring Boot, React ve PostgreSQL ile Secure SDLC
Yapay zekâ destekli kod geliştirme araçları artık yazılım geliştirme süreçlerinin önemli bir parçası haline geldi. Bir REST API oluşturmak…
⤷ Title: Production Java Security as a System of Enforced Invariants
════════════════════════
𐀪 Author: Weissmann Tobi
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 23:45:18 GMT
════════════════════════
⌗ Tags: #java #spring_boot #security #architecture #application_security
════════════════════════
𐀪 Author: Weissmann Tobi
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 23:45:18 GMT
════════════════════════
⌗ Tags: #java #spring_boot #security #architecture #application_security
Medium
Production Java Security as a System of Enforced Invariants
A Principal Engineer Design Paper for Spring Boot, OAuth2, Multi-Tenancy, Kubernetes, Supply Chain, and Security Operations
⤷ Title: 48 Hours to Launch: The Pen Test That Stopped Our Release
════════════════════════
𐀪 Author: Pramodreddypandiri
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 01:54:38 GMT
════════════════════════
⌗ Tags: #java #devops #penetration_testing #security
════════════════════════
𐀪 Author: Pramodreddypandiri
════════════════════════
ⴵ Time: Sun, 04 Oct 2026 01:54:38 GMT
════════════════════════
⌗ Tags: #java #devops #penetration_testing #security
Medium
48 Hours to Launch: The Pen Test That Stopped Our Release
What a last-minute security finding taught me about shipping software responsibly.
⤷ Title: Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 14:47:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts #CVE_2026_104711 #CVE_2026_104713 #CVE_2026_104714 #Denial of Service #Java security #OGNL Injection #Struts 7.4.0
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 14:47:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts #CVE_2026_104711 #CVE_2026_104713 #CVE_2026_104714 #Denial of Service #Java security #OGNL Injection #Struts 7.4.0
Daily CyberSecurity
Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS
TL;DR The Apache Struts team has fixed four Apache Struts vulnerabilities in Struts 7.4.0 and 6.12.0. The most serious, CVE-2026-104711, allows OGNL injection that may lead to remote code executio…