⤷ Title: The Cryptography Trojan: Malicious Go Module Impersonates Foundational Library to Steal Passwords and Deploy Root Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:43:46 +0000
════════════════════════
⌗ Tags: #Malware #APT31 #cryptography #CVE_2026 #go #Golang #infosec #Linux Security #malware #Open Source Security #Rekoobe #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:43:46 +0000
════════════════════════
⌗ Tags: #Malware #APT31 #cryptography #CVE_2026 #go #Golang #infosec #Linux Security #malware #Open Source Security #Rekoobe #supply chain attack
Daily CyberSecurity
The Cryptography Trojan: Malicious Go Module Impersonates Foundational Library to Steal Passwords and Deploy Root Backdoors
Socket uncovers a malicious Go module mimicking golang.org/x/crypto. It steals passwords via ReadPassword and deploys the Rekoobe backdoor on Linux systems.
⤷ Title: Security Alert: “Hackerbot-Claw” Autonomous Campaign Exploits GitHub Actions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 04:53:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2026 cyber threats #autonomous bot #Christopher Robinson #CI/CD security #Cloud Security #DevSecOps #GitHub Actions #hackerbot_claw #Open Source Security #OpenSSF #pwn request #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 04:53:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2026 cyber threats #autonomous bot #Christopher Robinson #CI/CD security #Cloud Security #DevSecOps #GitHub Actions #hackerbot_claw #Open Source Security #OpenSSF #pwn request #supply chain attack
Daily CyberSecurity
Security Alert: "Hackerbot-Claw" Autonomous Campaign Exploits GitHub Actions
OpenSSF warns of "hackerbot-claw," an autonomous AI bot exploiting GitHub Actions to hijack repositories. Secure your CI/CD pipeline before it’s too late.
⤷ Title: Critical Vulnerabilities in AVideo: From SQL Injection to Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:43:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AVideo #CVE_2026_28501 #CVE_2026_28502 #infosec #Open Source Security #Patch Alert #rce #Remote Code Execution #sql injection #sqli #Video Streaming Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:43:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AVideo #CVE_2026_28501 #CVE_2026_28502 #infosec #Open Source Security #Patch Alert #rce #Remote Code Execution #sql injection #sqli #Video Streaming Security
Daily CyberSecurity
Critical Vulnerabilities in AVideo: From SQL Injection to Remote Code Execution
AVideo patches two critical flaws (CVE-2026-28501 & 28502) allowing unauthenticated SQL injection and remote code execution. Update to version 23 now.
⤷ Title: Stream Hijacked: Critical Zero-Click Command Injection Flaw Exposed in AVideo-Encoder
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:22:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AVideo_Encoder #Command Injection #CVE_2026_29058 #cybersecurity #infosec #Open Source Security #Patch Alert #unauthenticated RCE #Vulnerability #YouPHPTube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:22:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AVideo_Encoder #Command Injection #CVE_2026_29058 #cybersecurity #infosec #Open Source Security #Patch Alert #unauthenticated RCE #Vulnerability #YouPHPTube
Daily CyberSecurity
Stream Hijacked: Critical Zero-Click Command Injection Flaw Exposed in AVideo-Encoder
A critical 9.8 CVSS flaw (CVE-2026-29058) in AVideo-Encoder allows unauthenticated remote attackers to execute arbitrary system commands. Patch now.
⤷ Title: Beyond the Perimeter: Auditing Active Directory Security with ADPulse’s 35-Point Automated Scan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 08:28:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD misconfiguration #AD security #ADPulse #Domain Controller #IT Administration #LDAP auditing #open source security #Penetration Testing #security reporting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 08:28:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD misconfiguration #AD security #ADPulse #Domain Controller #IT Administration #LDAP auditing #open source security #Penetration Testing #security reporting
Information Security News
Beyond the Perimeter: Auditing Active Directory Security with ADPulse’s 35-Point Automated Scan
ADPulse — Active Directory Security Scanner ADPulse is an open-source Active Directory security auditing tool that connects to a domain controller via LDAP(S), runs 35 automated security checks, a…
⤷ Title: AI vs. Bugs: OpenAI Launches “Codex Security” to Revolutionize AppSec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 07 Mar 2026 02:45:12 +0000
════════════════════════
⌗ Tags: #Technology #Agentic AI #Application Security #AppSec #Codex Security #cybersecurity #DevSecOps #infosec #Open Source Security #OpenAI #vulnerability management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 07 Mar 2026 02:45:12 +0000
════════════════════════
⌗ Tags: #Technology #Agentic AI #Application Security #AppSec #Codex Security #cybersecurity #DevSecOps #infosec #Open Source Security #OpenAI #vulnerability management
Daily CyberSecurity
AI vs. Bugs: OpenAI Launches "Codex Security" to Revolutionize AppSec
OpenAI launches Codex Security, an advanced AI agent that uses reasoning to find and fix complex vulnerabilities without the noise of false positives.
⤷ Title: Broadcast Lockdown: The CVSS 9.8 Flaw in AVideo That Grants Total Server Control
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 03:54:01 +0000
════════════════════════
⌗ Tags: #Vulnerability #AVideo #Command Injection #CVE_2026_29058 #CWE_78 #FFmpeg exploit #open source security #RCE #Server Hijacking #Tech News 2026 #Video Streaming Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 03:54:01 +0000
════════════════════════
⌗ Tags: #Vulnerability #AVideo #Command Injection #CVE_2026_29058 #CWE_78 #FFmpeg exploit #open source security #RCE #Server Hijacking #Tech News 2026 #Video Streaming Security
Penetration Testing Tools
Broadcast Lockdown: The CVSS 9.8 Flaw in AVideo That Grants Total Server Control
A critical vulnerability has been unearthed within the AVideo platform, empowering adversaries to hijack video broadcasts and commandeer
⤷ Title: Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 09:24:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 09:24:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
Penetration Testing Tools
Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
Stop dependency confusion before it starts. DepConfuse is an SBOM-first tool that scans 20+ registries to secure your software supply chain from package takeover.
⤷ Title: The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
Daily CyberSecurity
The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
The Axios npm hijack exposed millions to a RAT. Discover how North Korean-nexus actor UNC1069 used a masterful phishing ruse to bypass 2FA and steal credentials.
⤷ Title: Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 14:30:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Management #CVE_2026_3429 #CVE_2026_4636 #cybersecurity #IAM Security #infosec #Keycloak #MFA Bypass #Open Source Security #Token Theft #UMA #Vert.x
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 14:30:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Management #CVE_2026_3429 #CVE_2026_4636 #cybersecurity #IAM Security #infosec #Keycloak #MFA Bypass #Open Source Security #Token Theft #UMA #Vert.x
Daily CyberSecurity
Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
Keycloak 26.5.7 fixes critical flaws including MFA bypass (CVE-2026-3429) and UMA token theft. Protect your IAM infrastructure—upgrade to the latest version.
⤷ Title: Budibase Patches Critical RCE and SSRF Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 14:30:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation Security #Budibase #CVE_2026_31818 #CVE_2026_35216 #cybersecurity #infosec #Low Code Security #Open Source Security #rce #ssrf #Webhook Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 14:30:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Automation Security #Budibase #CVE_2026_31818 #CVE_2026_35216 #cybersecurity #infosec #Low Code Security #Open Source Security #rce #ssrf #Webhook Exploit
Daily CyberSecurity
Budibase Patches Critical RCE and SSRF Vulnerabilities
Critical 9.6 CVSS flaws in Budibase allow unauthenticated RCE and data exfiltration via SSRF. Secure your internal tools—update to v3.33.4 now.
⤷ Title: The Podcast Trap: How UNC1069’s AI Deepfakes Are Poisoning the Global npm Registry
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:35:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #axios #Deepfake #InfoSec 2026 #Node.js #North Korea #npm #open source security #SILENCELIFT #Social Engineering #supply chain attack #UNC1069 #WAVESHAPER
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 09:35:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #axios #Deepfake #InfoSec 2026 #Node.js #North Korea #npm #open source security #SILENCELIFT #Social Engineering #supply chain attack #UNC1069 #WAVESHAPER
Penetration Testing Tools
The Podcast Trap: How UNC1069’s AI Deepfakes Are Poisoning the Global npm Registry
What begins as a mundane exchange—an invitation to a podcast or a routine professional briefing—may serve as the
⤷ Title: The Human Element: How a Single GitHub Token Leak Put Apache HTTP Server in the Spotlight
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:08:27 +0000
════════════════════════
⌗ Tags: #Data Leak #Apache HTTP Server #Credential Management #Cybersecurity 2026 #data leak #GitHub Secret Scanning #GitHub Token #HTTPD #Human Error #infosec #Open Source Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Apr 2026 08:08:27 +0000
════════════════════════
⌗ Tags: #Data Leak #Apache HTTP Server #Credential Management #Cybersecurity 2026 #data leak #GitHub Secret Scanning #GitHub Token #HTTPD #Human Error #infosec #Open Source Security
Daily CyberSecurity
The Human Element: How a Single GitHub Token Leak Put Apache HTTP Server in the Spotlight
A developer's "human error" leaked sensitive GitHub tokens in an Apache HTTP Server update. Learn how GitHub's safety nets prevented a major security breach.
⤷ Title: Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 12:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVSS 10 #cybersecurity #Froxlor #infosec #Open Source Security #Path Traversal #PHP Security #rce #Server Management #vulnerability management #Web Shell
Daily CyberSecurity
Froxlor’s CVSS 10 Flaw Turns Config Files into Persistent Backdoors
Froxlor faces two critical flaws, including a CVSS 10. Learn how path traversal and config injection allow persistent RCE. Patch your server management today!
⤷ Title: Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 13:13:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CRM #CVE_2026_23500 #cybersecurity #Dolibarr #ERP #infosec #Open Source Security #Patch Alert #PDF Conversion #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 13:13:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CRM #CVE_2026_23500 #cybersecurity #Dolibarr #ERP #infosec #Open Source Security #Patch Alert #PDF Conversion #rce
Daily CyberSecurity
Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
Dolibarr ERP faces a critical 9.4 CVSS RCE flaw (CVE-2026-23500) in its PDF conversion logic. Unsanitized commands allow full system takeover. Upgrade to 23.0!
⤷ Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Daily CyberSecurity
Void Dokkaebi Unmasked: The "Worm-Like" Supply Chain Threat Targeting Developers
Void Dokkaebi turns developers into vectors. With 750+ infected repos and malicious VS Code tasks, this supply chain worm is hunting your CI/CD and crypto.
⤷ Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Penetration Testing Tools
RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
RubyGems has temporarily suspended the registration of new accounts following a pervasive assault on the Ruby ecosystem. According
⤷ Title: Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
⌗ Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
════════════════════════
𐀪 Author: Stanley A.
════════════════════════
ⴵ Time: Thu, 04 Jun 2026 14:06:00 GMT
════════════════════════
⌗ Tags: #penetration_testing #open_source_security #third_party_risk #supply_chain_security #cybersecurity
Medium
Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk
“We audited our own code. Our dependencies are someone else’s problem.” — A common assumption. Until it isn’t.
⤷ Title: How I Found CVE-2026–50131: An Incomplete SSRF Fix in Fedify
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 22:47:46 GMT
════════════════════════
⌗ Tags: #ssrf #cve #cybersecurity #open_source_security #vulnerability
════════════════════════
𐀪 Author: Chaitanya Garware
════════════════════════
ⴵ Time: Fri, 19 Jun 2026 22:47:46 GMT
════════════════════════
⌗ Tags: #ssrf #cve #cybersecurity #open_source_security #vulnerability
Medium
How I Found CVE-2026–50131: An Incomplete SSRF Fix in Fedify
There is a very specific feeling you get when you are reading security code and something looks almost right.
⤷ Title: From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for…
════════════════════════
𐀪 Author: eL Njas!™
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
⌗ Tags: #vulnhunter #open_source #infosec #open_source_security #finance
════════════════════════
𐀪 Author: eL Njas!™
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:09:22 GMT
════════════════════════
⌗ Tags: #vulnhunter #open_source #infosec #open_source_security #finance
Medium
From Breach to Blueprint: Why Capital One’s Open-Source AI Security Tool Signals a New Era for Finance and Cyber Defense.
Capital One Financial Corporation is one of the largest financial institutions in the United States, headquartered in McLean, Virginia…