PandoraCore Lab | Exploit web | Zeroday | Hacking | Cracking | Combolist | Tools hacking | Silver bullet | hackers world
133 subscribers
7 photos
3 videos
5 files
513 links
πŸ”Ά Official channel of the PandoraCore


β˜•οΈ Owner / Main Dev: @ZenithGhost

πŸ‘€ Co-owner / Dev:

πŸ“• BlackList: @BlackList_PC

πŸ’¬ Group: @PandoraCoreGP
Download Telegram
πŸ“° Who’s Tracking You? Use This New Service to Find Out


It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Canadian Man Pleads Guilty in Snowflake Extortions


A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A surveillance photo of Connor Riley Moucka, a.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Read This Before You Buy That TV Streaming Stick


Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro FalΓ© is a threat researcher with the security firm Bitsight.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool #Report #Tutorial

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° FBI Seizes NetNut Proxy Platform, Popa Botnet


The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies NASDAQ: ALAR. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. The NetNut homepage today was replaced by this seizure banner from the FBI.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Scattered Spider Hackers Plead Guilty on Day 1 of Trial


Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial. Owen Flowers (left) 18, and Thalha Jubair, 20.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets


Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn.

πŸ”— Source

#RSS #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories


Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure


Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (.

πŸ”— Source

#RSS #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack


Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-68820

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers


Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-94127

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware


A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-85880 CVE-2026-87491 CVE-2026-85046

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° EDR Evasion Stack Helps Process Injection Slip Past Defenses


A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.

πŸ”— Source

#RSS #CyberSecurity #Security #Tool

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical F5 BIG-IP Vulnerability Exploited as Zero-Day


Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key


Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-67279 CVE-2026-86060

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Adobe Patches Critical Flaws in Connect, AEM Forms


The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry


Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/.

πŸ”— Source

#RSS #CyberSecurity #Security #Report

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks


Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.

πŸ”— Source

#RSS #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Arista Urges Immediate Patching of Exploited VCO Zero-Day


Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input


A new security vulnerability in Next. js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° **Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape**


A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.

πŸ”— [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)

#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab
πŸ“° Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials


A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.

πŸ”— Source

#RSS #CVE #CyberSecurity #Security CVE-2026-90898

━━━━━━━━━━━━━━━

πŸ”Ή Admin
@ZenithGhost

πŸ”Έ Channel
@PandoraCoreLab