π° Anyone still using Flask, or has FastAPI completely taken over? π€
β I've been noticing a lot of developers moving towards FastAPI lately, especially for new Python backend projects. Flask used to be my go-to for lightweight APIs, but FastAPI seems to be getting all the attention now because of async support, automatic Swagger documentation, and Pydantic validation. I'm curious about what developers are actually using in production.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
β I've been noticing a lot of developers moving towards FastAPI lately, especially for new Python backend projects. Flask used to be my go-to for lightweight APIs, but FastAPI seems to be getting all the attention now because of async support, automatic Swagger documentation, and Pydantic validation. I'm curious about what developers are actually using in production.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Reddit
From the Python community on Reddit
Explore this post and more from the Python community
π° Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-88779
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-88779
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.
π kofiadeyemiq/origin-scoped-fetch - A fetch wrapper that drops your custom auth headers when a redirect crosses to a
A fetch wrapper that drops your custom auth headers when a redirect crosses to another origin.
Topics: fetch, http, nodejs, redirects, security, typescript.
Repo Info: β 27 | π» TypeScript | π MIT | π 2026-09-28 | π’ Active
π Source
#GITHUB #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A fetch wrapper that drops your custom auth headers when a redirect crosses to another origin.
Topics: fetch, http, nodejs, redirects, security, typescript.
Repo Info: β 27 | π» TypeScript | π MIT | π 2026-09-28 | π’ Active
π Source
#GITHUB #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
GitHub
GitHub - kofiadeyemiq/origin-scoped-fetch: A fetch wrapper that drops your custom auth headers when a redirect crosses to anotherβ¦
A fetch wrapper that drops your custom auth headers when a redirect crosses to another origin. - kofiadeyemiq/origin-scoped-fetch
π° Alleged ShinyHunters Leader Arrested in Jordan
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Alleged ShinyHunters Leader Arrested in Jordan
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.
π° New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8. 7 out of 10.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-88779
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8. 7 out of 10.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-88779
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Python Shellcode-Anydesk-Apc-injection-Remote-IP-Address
submitted by /u/StructBreaker link comments.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
submitted by /u/StructBreaker link comments.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Reddit
From the ReverseEngineering community on Reddit: Python Shellcode-Anydesk-Apc-injection-Remote-IP-Address
Explore this post and more from the ReverseEngineering community
π° Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9. 3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-61500
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9. 3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-61500
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-61500
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-61500
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.
π° **Wordpress libheif RCE**
submitted by /u/adrian_rt [link] [comments].
π [Source](https://www.reddit.com/r/netsec/comments/1wy4edi/wordpress_libheif_rce/)
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
submitted by /u/adrian_rt [link] [comments].
π [Source](https://www.reddit.com/r/netsec/comments/1wy4edi/wordpress_libheif_rce/)
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Reddit
From the netsec community on Reddit: Wordpress libheif RCE
Explore this post and more from the netsec community
π yolinc02-star/learn-by-teaching-lab - Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills
Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills
Topics: ai, analyst, architect, automater, google, java, lecturer, manager, marketer, microsoft.
Repo Info: β 53 | π» HTML | π 2026-10-03 | π’ Active
π Source
#GITHUB #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills
Topics: ai, analyst, architect, automater, google, java, lecturer, manager, marketer, microsoft.
Repo Info: β 53 | π» HTML | π 2026-10-03 | π’ Active
π Source
#GITHUB #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
GitHub
GitHub - yolinc02-star/learn-by-teaching-lab: Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills
Practical IT Teaching Hub 2026: Learn, Build and Share Real Skills - yolinc02-star/learn-by-teaching-lab
π° Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).
π° β‘ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A blank field. A public repo. One reply to an email.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8. 8 on the CVSS scoring system.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-96940
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8. 8 on the CVSS scoring system.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-96940
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.
π° Why are companies choosing Go for backend systems when JavaScript/Node.js already works?
I'm a CS student and I'm trying to understand why Go has become so popular in backend development. Python is used everywhere for AI/ML and scripting, JavaScript/TypeScript is huge for web development, and now I keep seeing Go in backend, cloud and infrastructure roles. What makes Go so attractive to companies? Is it mainly because of performance, concurrency, simplicity and deployment? Or are there other practical reasons that I'm missing? For someone learning backend development, would it make sense to learn Node.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
I'm a CS student and I'm trying to understand why Go has become so popular in backend development. Python is used everywhere for AI/ML and scripting, JavaScript/TypeScript is huge for web development, and now I keep seeing Go in backend, cloud and infrastructure roles. What makes Go so attractive to companies? Is it mainly because of performance, concurrency, simplicity and deployment? Or are there other practical reasons that I'm missing? For someone learning backend development, would it make sense to learn Node.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Reddit
From the Python community on Reddit
Explore this post and more from the Python community
π VD171/VD-Google - Your Google services (RCS, Google Wallet, Play Integrity attestations) read on-d
Your Google services (RCS, Google Wallet, Play Integrity attestations) read on-device. No internet, root required.
Topics: android, attestation, google-wallet, jetpack-compose, kernelsu, kotlin, lsposed, magisk, material3, nfc.
Repo Info: β 24 | π΄ 1 | π AGPL-3.0 | π 2026-10-05 | π’ Active
π Source
#GITHUB #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Your Google services (RCS, Google Wallet, Play Integrity attestations) read on-device. No internet, root required.
Topics: android, attestation, google-wallet, jetpack-compose, kernelsu, kotlin, lsposed, magisk, material3, nfc.
Repo Info: β 24 | π΄ 1 | π AGPL-3.0 | π 2026-10-05 | π’ Active
π Source
#GITHUB #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything. Every couple of days the side panel pops up a "community link" and says "100% Safe, No Spam, No Malware.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything. Every couple of days the side panel pops up a "community link" and says "100% Safe, No Spam, No Malware.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Reddit
From the netsec community on Reddit: SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
Posted by Huge-Skirt-6990 - 15 votes and 0 comments
π° ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Dark Reading
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
π° I turned a low-cost RP2040-Zero into a FIDO2/WebAuthn security key
submitted by /u/KaraaslanLabs link comments.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
submitted by /u/KaraaslanLabs link comments.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Reddit
From the ReverseEngineering community on Reddit: I turned a low-cost RP2040-Zero into a FIDO2/WebAuthn security key
Explore this post and more from the ReverseEngineering community
π° 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.