⤷ Title: Race Condition & Atomic Violation: Race-Free Denomination app
════════════════════════
𐀪 Author: Alborz Nazari
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:36:29 GMT
════════════════════════
⌗ Tags: #dclk_singleton #race_condition #hacking #atomicity #threat_modeling
════════════════════════
𐀪 Author: Alborz Nazari
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:36:29 GMT
════════════════════════
⌗ Tags: #dclk_singleton #race_condition #hacking #atomicity #threat_modeling
Medium
Race Condition & Atomic Violation: Race-Free Denomination app
*by Alborz Nazari*
⤷ Title: The Problem With Permanent Chats (And What I Built Instead)
════════════════════════
𐀪 Author: Sonu Samrat
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:34:39 GMT
════════════════════════
⌗ Tags: #social_media #hacking #cybersecurity #technology #software_development
════════════════════════
𐀪 Author: Sonu Samrat
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:34:39 GMT
════════════════════════
⌗ Tags: #social_media #hacking #cybersecurity #technology #software_development
Medium
The Problem With Permanent Chats (And What I Built Instead)
## The problem nobody talks about
⤷ Title: TryHackMe CTF ContAInment walkthrough
════════════════════════
𐀪 Author: Konstantin Sakhchinskiy
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 21:36:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #tryhackme_walkthrough #ai #tryhackme
════════════════════════
𐀪 Author: Konstantin Sakhchinskiy
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 21:36:20 GMT
════════════════════════
⌗ Tags: #penetration_testing #hacking #tryhackme_walkthrough #ai #tryhackme
Medium
TryHackMe CTF ContAInment walkthrough
The ContAInment room: https://tryhackme.com/room/containment
⤷ Title: De la consultoria al Hacking Ético:
Por qué decidí romper lo que defiendo
════════════════════════
𐀪 Author: manoli101
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:41:32 GMT
════════════════════════
⌗ Tags: #oscp_preparation #penetration_testing #ethical_hacking #career_change #cybersecurity
Por qué decidí romper lo que defiendo
════════════════════════
𐀪 Author: manoli101
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:41:32 GMT
════════════════════════
⌗ Tags: #oscp_preparation #penetration_testing #ethical_hacking #career_change #cybersecurity
Medium
De la consultoria al Hacking Ético:
Por qué decidí romper lo que defiendo
Por qué decidí romper lo que defiendo
Una historia de identidad, reconversión y la obsesión que no me deja dormir
⤷ Title: TryHackMe — Capture!
════════════════════════
𐀪 Author: Kira @ hKiSec
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:27:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf #ctf_writeup #tryhackme #web_application_security
════════════════════════
𐀪 Author: Kira @ hKiSec
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 22:27:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf #ctf_writeup #tryhackme #web_application_security
Medium
TryHackMe — Capture!
Bypassing CAPTCHA & User Enumeration with Python
⤷ Title: SNORT
════════════════════════
𐀪 Author: Abdelrahman
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 21:30:08 GMT
════════════════════════
⌗ Tags: #snortlab #tryhackme_snort #tryhackme #snort
════════════════════════
𐀪 Author: Abdelrahman
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 21:30:08 GMT
════════════════════════
⌗ Tags: #snortlab #tryhackme_snort #tryhackme #snort
Medium
SNORT
Section 1: Introduction to Snort
⤷ Title: Authentication bypass via unauthenticated JWT generation on a telecom provider
════════════════════════
𐀪 Author: Amrgomaa
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:39:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #shodan #bug_bounty_writeup #bug_bounty #jwt
════════════════════════
𐀪 Author: Amrgomaa
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:39:11 GMT
════════════════════════
⌗ Tags: #penetration_testing #shodan #bug_bounty_writeup #bug_bounty #jwt
Medium
Authentication bypass via unauthenticated JWT generation on a telecom provider
How a hardcoded Lambda URL in a JS bundle led to admin token generation with no credentials required — and a full chain to AWS credential…
⤷ Title: Day 9: How I Bypassed Double CSRF Token Validation Using Only an IMG Tag
════════════════════════
𐀪 Author: zero_day
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:21:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_writeup #penetration_testing #bug_bounty_tips
════════════════════════
𐀪 Author: zero_day
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:21:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_writeup #penetration_testing #bug_bounty_tips
Medium
Day 9: How I Bypassed Double CSRF Token Validation Using Only an IMG Tag
When the server checks if two tokens match but forgets to check if they’re valid.
⤷ Title: ARP poisoning and man-in-the-middle attacks
════════════════════════
𐀪 Author: Ilgar Alakbarov
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:45:15 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #networking
════════════════════════
𐀪 Author: Ilgar Alakbarov
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:45:15 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #networking
Medium
ARP poisoning and man-in-the-middle attacks
The Invisible Handshake
⤷ Title: Threat Actors: Who is Targeting Your Network?
════════════════════════
𐀪 Author: Mahdi
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:24:30 GMT
════════════════════════
⌗ Tags: #hacker #infosec #programming #hacking #cybersecurity
════════════════════════
𐀪 Author: Mahdi
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:24:30 GMT
════════════════════════
⌗ Tags: #hacker #infosec #programming #hacking #cybersecurity
Medium
Threat Actors: Who is Targeting Your Network?
In the world of Blue teaming, knowing your enemy is very important. We can gain some information about the attacker by analyzing their…
⤷ Title: ServMon | HackTheBox | OSCP Preparation
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:13:01 GMT
════════════════════════
⌗ Tags: #technology #hacking #ctf #tech #oscp
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:13:01 GMT
════════════════════════
⌗ Tags: #technology #hacking #ctf #tech #oscp
Medium
ServMon | HackTheBox | OSCP Preparation
Got halfway through this one and left it on the back burner for a while; definitely a fun box. Helps you understand how to chain LFI into…
⤷ Title: Advanced Nmap — SMB Enumeration, OS Detection & Suspicious PHP Files
════════════════════════
𐀪 Author: Juan Manuel Yepes
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:46:17 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing #nmap
════════════════════════
𐀪 Author: Juan Manuel Yepes
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:46:17 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #penetration_testing #nmap
Medium
Advanced Nmap — SMB Enumeration, OS Detection & Suspicious PHP Files
The first scan maps the surface. The second scan goes deeper: scripted SMB enumeration, OS fingerprinting, workgroup discovery, and hunting…
⤷ Title: Hacking Clankers Market b01lers CTF Writeup
════════════════════════
𐀪 Author: S0n1c_404
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:01:34 GMT
════════════════════════
⌗ Tags: #penetration_testing #capture_the_flag #ethical_hacking_python #cybersecurity_ctf_web
════════════════════════
𐀪 Author: S0n1c_404
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:01:34 GMT
════════════════════════
⌗ Tags: #penetration_testing #capture_the_flag #ethical_hacking_python #cybersecurity_ctf_web
Medium
Hacking Clankers Market b01lers CTF Writeup
وَقُل رَّبِّ زِدْنِي عِلْمًا” — [طه: 114]
⤷ Title: What is a Shell?
════════════════════════
𐀪 Author: 7FINGER-KNIGHT-HACK
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:52:06 GMT
════════════════════════
⌗ Tags: #life_hacking #cyberattack #penetration_testing #reverse_shell #cybersecurity
════════════════════════
𐀪 Author: 7FINGER-KNIGHT-HACK
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:52:06 GMT
════════════════════════
⌗ Tags: #life_hacking #cyberattack #penetration_testing #reverse_shell #cybersecurity
Medium
What is a Shell?
The Silent Gateway Between You and the Machine
⤷ Title: AI Security Path- TryHackMe- Module 2(Part 1)
════════════════════════
𐀪 Author: Swarupa Jeedimetla
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:11:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #tryhackme #ai_security
════════════════════════
𐀪 Author: Swarupa Jeedimetla
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 00:11:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #tryhackme #ai_security
Medium
AI Security Path- TryHackMe- Module 2(Part 1)
Think of traditional software like a calculator predictable, rule-bound, and easy to trace when something goes wrong. Now compare that to…
⤷ Title: Securing Cloud APIs in Azure: Detecting and Preventing Token Replay Using Identity and Context with…
════════════════════════
𐀪 Author: Prasoon Mathur
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:50:18 GMT
════════════════════════
⌗ Tags: #api_security #cloud_security #cybersecurity #azure #zero_trust
════════════════════════
𐀪 Author: Prasoon Mathur
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 23:50:18 GMT
════════════════════════
⌗ Tags: #api_security #cloud_security #cybersecurity #azure #zero_trust
Medium
Securing Cloud APIs in Azure: Detecting and Preventing Token Replay Using Identity and Context with…
A practical lab demonstrating how valid tokens can be misused and how context-based controls enforce Zero Trust at the API gateway
⤷ Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Daily CyberSecurity
CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
CVE-2026-33626: A critical SSRF in LMDeploy exploited in under 13 hours. Learn how attackers hijack AI nodes and how to secure your inference cloud now.
⤷ Title: TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
Daily CyberSecurity
TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
Checkmarx Docker images and VS Code extensions hijacked by TeamPCP to siphon cloud secrets and spread via npm. Audit your "Dune" repositories today.
⤷ Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
Daily CyberSecurity
Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
Critical supply chain attack hits Xinference (v2.6.0-2.6.2). TeamPCP’s malware siphons cloud credentials and MLOps secrets. Audit your MLOps pipeline today.
⤷ Title: PureRAT Unmasked: The Stealthy, Multi-Stage “Dynamic Loader” Targeting Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:00:16 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #Malware Analysis #Process Hollowing #PureRAT #rat #Remote Access Trojan #steganography #Trellix #UAC bypass
Daily CyberSecurity
PureRAT Unmasked: The Stealthy, Multi-Stage "Dynamic Loader" Targeting Windows
Trellix uncovers PureRAT, a modular Trojan hiding malware in PNG images. Learn how it uses steganography and fileless delivery to bypass Windows security.
⤷ Title: Microsoft Defender Zero-Day “BlueHammer” Hits KEV Catalog Following Researcher’s Protest
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:53:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BlueHammer #CISA KEV #CVE_2026_33825 #Huntress Labs #infosec #Local Privilege Escalation #LPE #Microsoft Defender #Microsoft Security #RedSun #SAM Database #TOCTOU #UnDefend
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 01:53:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BlueHammer #CISA KEV #CVE_2026_33825 #Huntress Labs #infosec #Local Privilege Escalation #LPE #Microsoft Defender #Microsoft Security #RedSun #SAM Database #TOCTOU #UnDefend
Daily CyberSecurity
Microsoft Defender Zero-Day "BlueHammer" Hits KEV Catalog Following Researcher's Protest
CISA adds BlueHammer (CVE-2026-33825) to the KEV catalog. This Microsoft Defender LPE exploit uses TOCTOU to hijack SAM databases. Patch by May 6, 2026.