PandoraCore Lab | Exploit web | Zeroday | Hacking | Cracking | Combolist | Tools hacking | Silver bullet | hackers world
133 subscribers
7 photos
3 videos
5 files
513 links
πŸ”Ά Official channel of the PandoraCore


β˜•οΈ Owner / Main Dev: @ZenithGhost

πŸ‘€ Co-owner / Dev:

πŸ“• BlackList: @BlackList_PC

πŸ’¬ Group: @PandoraCoreGP
Download Telegram
πŸ“° Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account


Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8. 8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR).

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ Perruer/keelflow - Build AI agents and LLM workflows visually. Security-maintained continuation of


Build AI agents and LLM workflows visually. Security-maintained continuation of Flowise: security fixes, Apache-2. 0 only, drop-in for your existing flows and data.

Repo Info: ⭐ 35 | 🍴 1 | πŸ’» TypeScript | πŸ“„ Apache-2.0 | πŸ“… 2026-09-25 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products


A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-21589

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach


The U. S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees.

πŸ”— Source

#RSS #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ kulchankas/paranoid - Your app is guilty until proven secure: an agent skill whose /hack-me breaks int


Your app is guilty until proven secure: an agent skill whose /hack-me breaks into your own running app, proves each bug with a real request, patches it, and re-verifies. Claude Code Β· Codex Β· Cursor.
Topics: agent-skills, ai-agents, appsec, claude-code, codex, cursor, dast, devsecops, ethical-hacking, llm.

Repo Info: ⭐ 42 | 🍴 3 | πŸ’» Python | πŸ“„ MIT | πŸ“… 2026-09-27 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports


Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies


The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Arrests β€˜Most Wanted’ Developer of Ploutus ATM Malware


An alleged leader of Tren de Aragua's ATM jackpotting activities, Canelon Aguirre was on the FBI's top 10 most wanted list since March 2026. The post FBI Arrests 'Most Wanted' Developer of Ploutus ATM Malware appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Blames Contractor’s Missed Patch for ShinyHunters Breach


The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor's Missed Patch for ShinyHunters Breach appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° From statically typed languages to Python and IDE IntelliSense/Auto complete


This might be a bit odd, or maybe I'm odd, I don't know. I've been programming for 10+ years, always with statically typed languages (mainly Java, a tiny bit of Kotlin, Swift, and C many years ago). Due to a diverse set of events I wanted to learn a new language and Python looked good for it (being professionally or leisure).

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers


In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ agentscope-ai-java/importmap-lint - Validate import maps against the HTML spec resolution algorithm, and flag unvers


Validate import maps against the HTML spec resolution algorithm, and flag unversioned CDN entries.
Topics: esm, import-maps, javascript, linter, security, typescript.

Repo Info: ⭐ 20 | πŸ’» TypeScript | πŸ“„ MIT | πŸ“… 2026-09-25 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps


The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs


submitted by /u/dx7r link comments.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-21589

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day


Four incidents, four completely different initial access paths: 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence. Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical Healthcare Systems Aren't Quantum-Ready


A study of 2. 5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Bitvulnex: a vulnerable crypto exchange


submitted by /u/juliocesarfort link comments.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Native PyQt5 wheels for Windows ARM64 (because they don't exist upstream)


PyQt5-WinARM64: native PyQt5 wheels for Windows ARM64 I have released PyQt5-WinARM64, an independent distribution of PyQt5 for native Windows ARM64. https://github. com/ViciousSquid/PyQt5-WinARM64 The project provides ARM64 builds of: Qt 5 SIP PyQt5 The motivation is Windows ARM development.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ jiwoochris/artex-ko - ARTEX ν•œκ΅­μ–΄νŒ Β· AI 자율 침투 ν…ŒμŠ€νŠΈ ν”„λ ˆμž„μ›Œν¬ ν˜„μ§€ν™” (upstream: Autumn-27/ARTEX, AGPL-3.0)


ARTEX ν•œκ΅­μ–΄νŒ Β· AI 자율 침투 ν…ŒμŠ€νŠΈ ν”„λ ˆμž„μ›Œν¬ ν˜„μ§€ν™” (upstream: Autumn-27/ARTEX, AGPL-3. 0)
Topics: ai-agent, autonomous-agents, blue-team, cybersecurity, detection-engineering, i18n, korean, llm, penetration-testing, security.

Repo Info: ⭐ 77 | 🍴 30 | πŸ’» Go | πŸ“„ AGPL-3.0 | πŸ“… 2026-10-06 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System


The Arizona Supreme Court said the information was copied for people dating back as far as 30 years. The post Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona's Court System appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan


Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab