PandoraCore Lab | Exploit web | Zeroday | Hacking | Cracking | Combolist | Tools hacking | Silver bullet | hackers world
133 subscribers
7 photos
3 videos
5 files
508 links
πŸ”Ά Official channel of the PandoraCore


β˜•οΈ Owner / Main Dev: @ZenithGhost

πŸ‘€ Co-owner / Dev:

πŸ“• BlackList: @BlackList_PC

πŸ’¬ Group: @PandoraCoreGP
Download Telegram
πŸ“° I turned a low-cost RP2040-Zero into a FIDO2/WebAuthn security key


submitted by /u/KaraaslanLabs link comments.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms


Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Chinese Hackers Impersonate US Officials for AI Cyber Espionage


An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Open Build Service, one year later: command execution through Mercurial argument injection


submitted by /u/SzLam link comments.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ nealbridges/VulnHunter - Agentic AI security scanner that hunts exploitable vulnerabilities like an adver


Agentic AI security scanner that hunts exploitable vulnerabilities like an adversary, proves them with executable PoCs, and fixes them test-first. A maintained fork of Capital One's VulnHunter, rebuilt for any agent harness.
Topics: agent-harness, agentic-ai, appsec, exploit-verification, poc, sast, security, vulnerability-scanner.

Repo Info: ⭐ 100 | 🍴 17 | πŸ’» Python | πŸ“„ Apache-2.0 | πŸ“… 2026-10-05 | 🟒 Active

πŸ”— Source

#CVE #GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Need for Speed: AI-Driven Attacks Are Changing Security Strategies


AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Tuesday Daily Thread: Advanced questions


Weekly Wednesday Thread: Advanced Questions 🐍 Dive deep into Python with our Advanced Questions thread! This space is reserved for questions about more advanced Python topics, frameworks, and best practices. How it Works: Ask Away: Post your advanced Python questions here. Expert Insights: Get answers from experienced developers.

πŸ”— Source

#RSS #CyberSecurity #Security #Tutorial

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account


Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8. 8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR).

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ Perruer/keelflow - Build AI agents and LLM workflows visually. Security-maintained continuation of


Build AI agents and LLM workflows visually. Security-maintained continuation of Flowise: security fixes, Apache-2. 0 only, drop-in for your existing flows and data.

Repo Info: ⭐ 35 | 🍴 1 | πŸ’» TypeScript | πŸ“„ Apache-2.0 | πŸ“… 2026-09-25 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products


A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-21589

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach


The U. S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees.

πŸ”— Source

#RSS #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ kulchankas/paranoid - Your app is guilty until proven secure: an agent skill whose /hack-me breaks int


Your app is guilty until proven secure: an agent skill whose /hack-me breaks into your own running app, proves each bug with a real request, patches it, and re-verifies. Claude Code Β· Codex Β· Cursor.
Topics: agent-skills, ai-agents, appsec, claude-code, codex, cursor, dast, devsecops, ethical-hacking, llm.

Repo Info: ⭐ 42 | 🍴 3 | πŸ’» Python | πŸ“„ MIT | πŸ“… 2026-09-27 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports


Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies


The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Arrests β€˜Most Wanted’ Developer of Ploutus ATM Malware


An alleged leader of Tren de Aragua's ATM jackpotting activities, Canelon Aguirre was on the FBI's top 10 most wanted list since March 2026. The post FBI Arrests 'Most Wanted' Developer of Ploutus ATM Malware appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Blames Contractor’s Missed Patch for ShinyHunters Breach


The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor's Missed Patch for ShinyHunters Breach appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° From statically typed languages to Python and IDE IntelliSense/Auto complete


This might be a bit odd, or maybe I'm odd, I don't know. I've been programming for 10+ years, always with statically typed languages (mainly Java, a tiny bit of Kotlin, Swift, and C many years ago). Due to a diverse set of events I wanted to learn a new language and Python looked good for it (being professionally or leisure).

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers


In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ agentscope-ai-java/importmap-lint - Validate import maps against the HTML spec resolution algorithm, and flag unvers


Validate import maps against the HTML spec resolution algorithm, and flag unversioned CDN entries.
Topics: esm, import-maps, javascript, linter, security, typescript.

Repo Info: ⭐ 20 | πŸ’» TypeScript | πŸ“„ MIT | πŸ“… 2026-09-25 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps


The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs


submitted by /u/dx7r link comments.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-21589

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab