PandoraCore Lab | Exploit web | Zeroday | Hacking | Cracking | Combolist | Tools hacking | Silver bullet | hackers world
133 subscribers
7 photos
3 videos
5 files
507 links
πŸ”Ά Official channel of the PandoraCore


β˜•οΈ Owner / Main Dev: @ZenithGhost

πŸ‘€ Co-owner / Dev:

πŸ“• BlackList: @BlackList_PC

πŸ’¬ Group: @PandoraCoreGP
Download Telegram
πŸ“° Anyone still using Flask, or has FastAPI completely taken over? πŸ€”


​ I've been noticing a lot of developers moving towards FastAPI lately, especially for new Python backend projects. Flask used to be my go-to for lightweight APIs, but FastAPI seems to be getting all the attention now because of async support, automatic Swagger documentation, and Pydantic validation. I'm curious about what developers are actually using in production.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier


Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-88779

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ kofiadeyemiq/origin-scoped-fetch - A fetch wrapper that drops your custom auth headers when a redirect crosses to a


A fetch wrapper that drops your custom auth headers when a redirect crosses to another origin.
Topics: fetch, http, nodejs, redirects, security, typescript.

Repo Info: ⭐ 27 | πŸ’» TypeScript | πŸ“„ MIT | πŸ“… 2026-09-28 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Alleged ShinyHunters Leader Arrested in Jordan


Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline


Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8. 7 out of 10.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-88779

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Python Shellcode-Anydesk-Apc-injection-Remote-IP-Address


submitted by /u/StructBreaker link comments.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE


A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9. 3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-61500

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Exploitation Hits Rejetto HFS Vulnerability Discovered by AI


CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-61500

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ yolinc02-star/learn-by-teaching-lab - Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills


Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills
Topics: ai, analyst, architect, automater, google, java, lecturer, manager, marketer, microsoft.

Repo Info: ⭐ 53 | πŸ’» HTML | πŸ“… 2026-10-03 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2


Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports


Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° ⚑ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests


A blank field. A public repo. One reply to an email.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes


Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8. 8 on the CVSS scoring system.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-96940

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws


ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Why are companies choosing Go for backend systems when JavaScript/Node.js already works?


I'm a CS student and I'm trying to understand why Go has become so popular in backend development. Python is used everywhere for AI/ML and scripting, JavaScript/TypeScript is huge for web development, and now I keep seeing Go in backend, cloud and infrastructure roles. What makes Go so attractive to companies? Is it mainly because of performance, concurrency, simplicity and deployment? Or are there other practical reasons that I'm missing? For someone learning backend development, would it make sense to learn Node.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ VD171/VD-Google - Your Google services (RCS, Google Wallet, Play Integrity attestations) read on-d


Your Google services (RCS, Google Wallet, Play Integrity attestations) read on-device. No internet, root required.
Topics: android, attestation, google-wallet, jetpack-compose, kernelsu, kotlin, lsposed, magisk, material3, nfc.

Repo Info: ⭐ 24 | 🍴 1 | πŸ“„ AGPL-3.0 | πŸ“… 2026-10-05 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click


I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything. Every couple of days the side panel pops up a "community link" and says "100% Safe, No Spam, No Malware.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes


The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° I turned a low-cost RP2040-Zero into a FIDO2/WebAuthn security key


submitted by /u/KaraaslanLabs link comments.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms


Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab