⤷ Title: TryHackMe | RAG Security Fundamentals | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 17:28:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #tryhackme #tryhackme_writeup #tryhackme_walkthrough
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 17:28:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #tryhackme #tryhackme_writeup #tryhackme_walkthrough
Medium
TryHackMe | RAG Security Fundamentals | WriteUp
Learn how RAG systems work and how attackers exploit retrieval, context, and trust boundaries.
⤷ Title: SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:48:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:48:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Breaking Logic with Timing: A Race Condition Case Study (with a Vibe )
════════════════════════
𐀪 Author: WarrenMu
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:54:19 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_writeup #bug_bounty #race_condition #bug_bounty_tips
════════════════════════
𐀪 Author: WarrenMu
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:54:19 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_writeup #bug_bounty #race_condition #bug_bounty_tips
Medium
Breaking Logic with Timing: A Race Condition Case Study (with a Vibe 🎧)
Before You Start
⤷ Title: Blind SSRF Leads to Internal Service and IP Discovery with Multiple Security Impacts
════════════════════════
𐀪 Author: Mohamed M Mourad
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 19:34:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #pentesting
════════════════════════
𐀪 Author: Mohamed M Mourad
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 19:34:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #pentesting
Medium
Blind SSRF Leads to Internal Service and IP Discovery with Multiple Security Impacts
While analyzing JavaScript files, I discovered an interesting endpoint that included a JSON field called signedUri. At first, directly…
⤷ Title: Enumerating Windows Process Creation Callbacks
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:47:44 GMT
════════════════════════
⌗ Tags: #hacking #malware #pentesting #cybersecurity #infosec
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:47:44 GMT
════════════════════════
⌗ Tags: #hacking #malware #pentesting #cybersecurity #infosec
Medium
Enumerating Windows Process Creation Callbacks
Welcome to this new post. Today we’re going to look at how Windows tracks which drivers get notified every time a new process is created…
⤷ Title: The Vercel Hack of April 2026: A Wake-Up Call on Third-Party AI Integrations and “Plaintext”…
════════════════════════
𐀪 Author: Syed Talha Ahmed
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:06:35 GMT
════════════════════════
⌗ Tags: #hacking #vercel #artificial_intelligence #cybersecurity #software_development
════════════════════════
𐀪 Author: Syed Talha Ahmed
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:06:35 GMT
════════════════════════
⌗ Tags: #hacking #vercel #artificial_intelligence #cybersecurity #software_development
Medium
The Vercel Hack of April 2026: A Wake-Up Call on Third-Party AI Integrations and “Plaintext”…
By someone spending over a decade in the trenches
⤷ Title: How to Triage a Phishing Alert Faster — Without Rebuilding the Process Every TimeMost phishing…
════════════════════════
𐀪 Author: Gaurav Kundu
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:15:28 GMT
════════════════════════
⌗ Tags: #blue_team #infosec #securityoperationscenter #security #cybersecurity
════════════════════════
𐀪 Author: Gaurav Kundu
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:15:28 GMT
════════════════════════
⌗ Tags: #blue_team #infosec #securityoperationscenter #security #cybersecurity
Medium
How to Triage a Phishing Alert Faster — Without Rebuilding the Process Every TimeMost phishing…
You get the alert.
⤷ Title: Heron Walkthought
════════════════════════
𐀪 Author: Xotourlif33
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:23:09 GMT
════════════════════════
⌗ Tags: #heron_walkthought #hackthebox #vulnlab #hackthebox_writeup
════════════════════════
𐀪 Author: Xotourlif33
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 20:23:09 GMT
════════════════════════
⌗ Tags: #heron_walkthought #hackthebox #vulnlab #hackthebox_writeup
Medium
Heron Walkthought
Heron is a mini prolab by VulnLab involving ASREPRoasting, GPP password abuse, vhost discovery, RCE via web.config hijacking, lateral…
⤷ Title: Code Is Law Until It Isn’t: What Arbitrum’s Intervention Reveals About Crypto Governance
════════════════════════
𐀪 Author: Abraham
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 22:01:32 GMT
════════════════════════
⌗ Tags: #smart_contracts #blockchain #bug_bounty #cybersecurity #smart_contract_security
════════════════════════
𐀪 Author: Abraham
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 22:01:32 GMT
════════════════════════
⌗ Tags: #smart_contracts #blockchain #bug_bounty #cybersecurity #smart_contract_security
Medium
Code Is Law Until It Isn’t: What Arbitrum’s Intervention Reveals About Crypto Governance
The phrase “code is law” has long been a foundational belief in crypto. It suggests that once smart contracts are deployed, their outcomes…
⤷ Title: From Nmap to Neural Nets: Pentesting Just Leveled Up
════════════════════════
𐀪 Author: Achessa
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 21:29:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #information_technology
════════════════════════
𐀪 Author: Achessa
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 21:29:51 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #information_technology
Medium
From Nmap to Neural Nets: Pentesting Just Leveled Up
Because apparently, even cybersecurity tools are tired of waiting for us to catch up.
⤷ Title: TryHackMe: Brains (Red Teaming)
════════════════════════
𐀪 Author: Evan Manson
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 22:34:02 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #red_team #cybersecurity
════════════════════════
𐀪 Author: Evan Manson
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 22:34:02 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #red_team #cybersecurity
Medium
TryHackMe: Brains (Red Teaming)
Nmap scan shows open ports on 22, 90, and 50000. These are SSH and services for an Apache server.
⤷ Title: Microsoft Teams Exploited for Silent Enterprise Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:40:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Administrative Protocols #data exfiltration #infosec #lateral movement #Level RMM #Microsoft Defender #Microsoft Teams #Quick Assist #Rclone #social engineering #WinRM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:40:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Administrative Protocols #data exfiltration #infosec #lateral movement #Level RMM #Microsoft Defender #Microsoft Teams #Quick Assist #Rclone #social engineering #WinRM
Daily CyberSecurity
Microsoft Teams Exploited for Silent Enterprise Takeovers
Microsoft warns of a Teams campaign using fake IT support to hijack workstations via Quick Assist, move laterally with WinRM, and steal data using Rclone.
⤷ Title: Guide to SSTI (Server-Side Template Injection): Detection, Exploitation, and WAF Evasion
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #technology #bug_bounty #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:01:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #technology #bug_bounty #hacking
Medium
Guide to SSTI (Server-Side Template Injection): Detection, Exploitation, and WAF Evasion
Master SSTI, reconnaissance methodology, advanced fingerprinting, WAF evasion payloads, and impact escalation.
⤷ Title: When the Wiretap Becomes the Backdoor: Salt Typhoon and the Security Paradox at America’s Telecom…
════════════════════════
𐀪 Author: Kush Patel
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:39:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_kill_chain #cyberattack #salt_typhoon #hacking
════════════════════════
𐀪 Author: Kush Patel
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:39:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_kill_chain #cyberattack #salt_typhoon #hacking
Medium
When the Wiretap Becomes the Backdoor: Salt Typhoon and the Security Paradox at America’s Telecom Core
A deep-dive analysis of the most consequential nation-state intrusion in recent memory and what it reveals about the structural risks…
⤷ Title: HTTP Security Headers
════════════════════════
𐀪 Author: Khaled Anter
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:14:33 GMT
════════════════════════
⌗ Tags: #coding #penetration_testing #web_development #cybersecurity #software_development
════════════════════════
𐀪 Author: Khaled Anter
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:14:33 GMT
════════════════════════
⌗ Tags: #coding #penetration_testing #web_development #cybersecurity #software_development
Medium
HTTP Security Headers
Hello everyone!! In this article i will talk about some security headers. I wrote this for people like me who get confused when they see…
⤷ Title: LLM Security (THM) Tryhackme Walkthrough and Answer
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:37:08 GMT
════════════════════════
⌗ Tags: #llm #tryhackme #cybersecurity #artificial_intelligence #llm_security
════════════════════════
𐀪 Author: Lawvye
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:37:08 GMT
════════════════════════
⌗ Tags: #llm #tryhackme #cybersecurity #artificial_intelligence #llm_security
Medium
LLM Security (THM) Tryhackme Walkthrough and Answer
Description : Understand LLMs as an attack surface and get an overview of LLM security threats.
⤷ Title: Ethical Hacking Skills That Matter: What Modern Security Certifications Really Test
════════════════════════
𐀪 Author: IPSpecialist
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:15:30 GMT
════════════════════════
⌗ Tags: #it_certification #cybersecurity #network_security #cloud_security #ethical_hacking
════════════════════════
𐀪 Author: IPSpecialist
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 23:15:30 GMT
════════════════════════
⌗ Tags: #it_certification #cybersecurity #network_security #cloud_security #ethical_hacking
Medium
Ethical Hacking Skills That Matter: What Modern Security Certifications Really Test
Introduction
⤷ Title: Blind SQL injection with conditional errors
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:02:19 GMT
════════════════════════
⌗ Tags: #blind_sql_injection #conditional_error #sql_injection
════════════════════════
𐀪 Author: Bea Dela Cruz
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:02:19 GMT
════════════════════════
⌗ Tags: #blind_sql_injection #conditional_error #sql_injection
Medium
Blind SQL injection with conditional errors
The website application does not return query results but instead reveals information through an error response
⤷ Title: Critical RCE Alert: Bamboo Data Center Vulnerable to OS Command Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 02:51:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Atlassian #Bamboo #CI/CD security #CVE_2026_21571 #DevOps #infosec #os command injection #Patch Alert #rce #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 02:51:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Atlassian #Bamboo #CI/CD security #CVE_2026_21571 #DevOps #infosec #os command injection #Patch Alert #rce #Supply Chain
Daily CyberSecurity
Critical RCE Alert: Bamboo Data Center Vulnerable to OS Command Injection
Atlassian Bamboo Data Center hit by critical 9.4 RCE (CVE-2026-21571). Attackers can hijack your build pipeline. Secure your supply chain—patch now!
⤷ Title: Emergency .NET Update: Critical Data Protection Flaw Allows Authentication Forgery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 02:21:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET 10 #ASP.NET Core #Authentication Bypass #CVE_2026_40372 #Data Protection #infosec #Key Rotation #Linux Security #macOS #Microsoft #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 02:21:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET 10 #ASP.NET Core #Authentication Bypass #CVE_2026_40372 #Data Protection #infosec #Key Rotation #Linux Security #macOS #Microsoft #privilege escalation
Daily CyberSecurity
Emergency .NET Update: Critical Data Protection Flaw Allows Authentication Forgery
Microsoft's OOB update for .NET 10 (CVE-2026-40372) hits Linux/macOS users. Authentication is at risk. Stop the bypass and rotate your keys today.
⤷ Title: 7 Critical Vulnerabilities Threaten Spring Security 7.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 01:54:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_22752 #infosec #Java security #JWT Security #Patch Alert #Spring Security #Spring Security 7.0 #ssrf #TOCTOU #X.509 Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 01:54:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2026_22752 #infosec #Java security #JWT Security #Patch Alert #Spring Security #Spring Security 7.0 #ssrf #TOCTOU #X.509 Impersonation
Daily CyberSecurity
7 Critical Vulnerabilities Threaten Spring Security 7.0
The Spring Security team has issued a series of security advisories detailing seven distinct vulnerabilities impacting the widely used authentication and authorization framework. While several fla…