PandoraCore Lab | Exploit web | Zeroday | Hacking | Cracking | Combolist | Tools hacking | Silver bullet | hackers world
133 subscribers
7 photos
3 videos
5 files
513 links
πŸ”Ά Official channel of the PandoraCore


β˜•οΈ Owner / Main Dev: @ZenithGhost

πŸ‘€ Co-owner / Dev:

πŸ“• BlackList: @BlackList_PC

πŸ’¬ Group: @PandoraCoreGP
Download Telegram
πŸ“° FBI Arrests β€˜Most Wanted’ Developer of Ploutus ATM Malware


An alleged leader of Tren de Aragua's ATM jackpotting activities, Canelon Aguirre was on the FBI's top 10 most wanted list since March 2026. The post FBI Arrests 'Most Wanted' Developer of Ploutus ATM Malware appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Blames Contractor’s Missed Patch for ShinyHunters Breach


The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor's Missed Patch for ShinyHunters Breach appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° From statically typed languages to Python and IDE IntelliSense/Auto complete


This might be a bit odd, or maybe I'm odd, I don't know. I've been programming for 10+ years, always with statically typed languages (mainly Java, a tiny bit of Kotlin, Swift, and C many years ago). Due to a diverse set of events I wanted to learn a new language and Python looked good for it (being professionally or leisure).

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers


In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ agentscope-ai-java/importmap-lint - Validate import maps against the HTML spec resolution algorithm, and flag unvers


Validate import maps against the HTML spec resolution algorithm, and flag unversioned CDN entries.
Topics: esm, import-maps, javascript, linter, security, typescript.

Repo Info: ⭐ 20 | πŸ’» TypeScript | πŸ“„ MIT | πŸ“… 2026-09-25 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps


The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs


submitted by /u/dx7r link comments.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-21589

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day


Four incidents, four completely different initial access paths: 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence. Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical Healthcare Systems Aren't Quantum-Ready


A study of 2. 5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Bitvulnex: a vulnerable crypto exchange


submitted by /u/juliocesarfort link comments.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Native PyQt5 wheels for Windows ARM64 (because they don't exist upstream)


PyQt5-WinARM64: native PyQt5 wheels for Windows ARM64 I have released PyQt5-WinARM64, an independent distribution of PyQt5 for native Windows ARM64. https://github. com/ViciousSquid/PyQt5-WinARM64 The project provides ARM64 builds of: Qt 5 SIP PyQt5 The motivation is Windows ARM development.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ jiwoochris/artex-ko - ARTEX ν•œκ΅­μ–΄νŒ Β· AI 자율 침투 ν…ŒμŠ€νŠΈ ν”„λ ˆμž„μ›Œν¬ ν˜„μ§€ν™” (upstream: Autumn-27/ARTEX, AGPL-3.0)


ARTEX ν•œκ΅­μ–΄νŒ Β· AI 자율 침투 ν…ŒμŠ€νŠΈ ν”„λ ˆμž„μ›Œν¬ ν˜„μ§€ν™” (upstream: Autumn-27/ARTEX, AGPL-3. 0)
Topics: ai-agent, autonomous-agents, blue-team, cybersecurity, detection-engineering, i18n, korean, llm, penetration-testing, security.

Repo Info: ⭐ 77 | 🍴 30 | πŸ’» Go | πŸ“„ AGPL-3.0 | πŸ“… 2026-10-06 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System


The Arizona Supreme Court said the information was copied for people dating back as far as 30 years. The post Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona's Court System appeared first on SecurityWeek.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan


Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Python you grewI up so fast!


I received the 5th edition of Mark Lutz' 'Python Pocket Reference' today. I dug out my first edition from 1998 and found the new one is three times thicker (3/16" vs 9/16") =, 75 pages vs 254. I'm not complaining but it shows how much has been added.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Turboenv and Simple new open source projects


Hello, I created two simple open source projects that I'd like to share to add the Python community. Turboenv TurboEnv is a Python library that provides a simple and efficient way to manage environment variables in your applications. It allows you to easily load environment variables from.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° 'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates


Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Atlassian Patches Critical Vulnerability Affecting 8 Products


Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ™ agentscope-ai-java/duckdb-extension-audit - Audit which DuckDB extensions a project loads, their origin and signature state,


Audit which DuckDB extensions a project loads, their origin and signature state, and flag unsigned loading.
Topics: audit, duckdb, extensions, python, security, supply-chain.

Repo Info: ⭐ 20 | πŸ’» Python | πŸ“„ MIT | πŸ“… 2026-09-25 | 🟒 Active

πŸ”— Source

#GITHUB #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Android’s October 2026 Updates Patch 25 Vulnerabilities


The patches resolve a critical vulnerability in Android's System component that could lead to privilege escalation. The post Android's October 2026 Updates Patch 25 Vulnerabilities appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer


The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab