for my Redteam fellas follow this telegram channel
https://t.me/RedTeamGarage
it has a good resource and content
@AfroSec
https://t.me/RedTeamGarage
it has a good resource and content
@AfroSec
Telegram
RedTeamGarage
Empowering Cybersecurity Enthusiasts with cutting-edge offensive security skills and a collaborative community for knowledge sharing and support.
https://www.redteamgarage.com
https://www.redteamgarage.com
β‘1β€1π1
week ago found this user info leak
which i was trying to use the platform as a regular user then something bugs me then i intercepted the req using ctr + alt + c then refresh the page and saw a recursive request and response to a graphql endpoint
the thing that makes me laugh is that the version of api that i found was protected but when i tried it by downgrading the version bruhh boom even there is a gui, users and admins i can extract them then do what attackers do but fortunately am ethicalπ
anyways dont submit ur real identity to eth sites they are soo fucked up fr
@AfroSec
which i was trying to use the platform as a regular user then something bugs me then i intercepted the req using ctr + alt + c then refresh the page and saw a recursive request and response to a graphql endpoint
the thing that makes me laugh is that the version of api that i found was protected but when i tried it by downgrading the version bruhh boom even there is a gui, users and admins i can extract them then do what attackers do but fortunately am ethicalπ
anyways dont submit ur real identity to eth sites they are soo fucked up fr
@AfroSec
π6π€―2π€1
AfroSec
shall we dominate π ? real org btw @AfroSec
they hosted some trash vibe coded app on there DC mtsm how unlucky they are lol ππ like the DMZ security protocols are disables or misconfigured idk tbh
and even their email gateways is fucked up like i can send a spoofed email to anyone
i just did some initial access methodologies and it was successful π
@AfroSec
and even their email gateways is fucked up like i can send a spoofed email to anyone
i just did some initial access methodologies and it was successful π
@AfroSec
β‘3π2
Forwarded from INSA Cyber Talent Center
π Registration Requirements β INSA Cyber Talent Challenge 2026
β’ Registration must be completed using a National ID (except for foreign nationals).
β’ After completing National ID verification/registration, applicants must proceed to the main portal and complete the application form.
β’ Any Ethiopian citizen aged 11 years and above with talent and passion is eligible to apply.
. Registration Deadline β° May 17
β’ The summer camp will be hosted at the following universities:
1. Addis Ababa Science and Technology University
2. Bahir Dar University
3. Haramaya University
4. Jimma University
5. Debre Berhan University
6. Wolaita Sodo University
Preferred Fields/Streams
Applicants should demonstrate interest, talent, and passion in areas such as:
β’ Cybersecurity
β’ Software Development
β’ Embedded Systems
β’ Aerospace
β’ Emerging Technologies
Selection Criteria
Applicants should:
β’ Successfully pass the INSAβs selection test/challenge
β’ Be willing and ready to learn new skills and participate in practical activities
β’ Have strong problem-solving ability and self-learning discipline
β’ Maintain good ethical behavior and discipline
β Individuals Not Eligible for Registration
1. Applicants who do not have genuine interest, passion, and talent in Cybersecurity and related technology fields.
2. Individuals who previously participated in the 4-round INSA summer camp/program are not eligible to register again.
β οΈ Important Notice: Submitting fully AI-generated responses in the application form is strictly prohibited. The system only provides a one-time warning and will not tolerate repeated attempts. Continued violations may result in automatic disqualification from the registration process.
π― Benefits for Participants
Selected participants may gain access to:
β’ Employment opportunities at INSA
β’ Startup and innovation opportunities
β’ Additional training and career development benefits
π More information: https://t.me/insactc
π Registration Portal: https://ctc.insa.gov.et/registration
β’ Registration must be completed using a National ID (except for foreign nationals).
β’ After completing National ID verification/registration, applicants must proceed to the main portal and complete the application form.
β’ Any Ethiopian citizen aged 11 years and above with talent and passion is eligible to apply.
. Registration Deadline β° May 17
β’ The summer camp will be hosted at the following universities:
1. Addis Ababa Science and Technology University
2. Bahir Dar University
3. Haramaya University
4. Jimma University
5. Debre Berhan University
6. Wolaita Sodo University
Preferred Fields/Streams
Applicants should demonstrate interest, talent, and passion in areas such as:
β’ Cybersecurity
β’ Software Development
β’ Embedded Systems
β’ Aerospace
β’ Emerging Technologies
Selection Criteria
Applicants should:
β’ Successfully pass the INSAβs selection test/challenge
β’ Be willing and ready to learn new skills and participate in practical activities
β’ Have strong problem-solving ability and self-learning discipline
β’ Maintain good ethical behavior and discipline
β Individuals Not Eligible for Registration
1. Applicants who do not have genuine interest, passion, and talent in Cybersecurity and related technology fields.
2. Individuals who previously participated in the 4-round INSA summer camp/program are not eligible to register again.
β οΈ Important Notice: Submitting fully AI-generated responses in the application form is strictly prohibited. The system only provides a one-time warning and will not tolerate repeated attempts. Continued violations may result in automatic disqualification from the registration process.
π― Benefits for Participants
Selected participants may gain access to:
β’ Employment opportunities at INSA
β’ Startup and innovation opportunities
β’ Additional training and career development benefits
π More information: https://t.me/insactc
π Registration Portal: https://ctc.insa.gov.et/registration
π4
What Would It Be
STRAENGE
π₯3β‘2π1
Forwarded from vx-underground
Media is too big
VIEW IN TELEGRAM
Company: makes spooky pseudo-canine humanoid robots thingies
Government: Lets use it to kill people (probably)
Government: Lets use it to kill people (probably)
π2π1π―1
Forwarded from The Hacker News
π¨ WARNING: The self-spreading βMini Shai-Huludβ worm compromised npm & PyPI packages tied to TanStack, Mistral AI, Guardrails AI, OpenSearch & more.
The attack used GitHub OIDC token hijacking and cache poisoning to spread credential-stealing malware across 42 TanStack packages and 84 versions.
Check your dependencies immediately β https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html
The attack used GitHub OIDC token hijacking and cache poisoning to spread credential-stealing malware across 42 TanStack packages and 84 versions.
Check your dependencies immediately β https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html
β‘2π€―1
Forwarded from yoseph.won (Yoseph Wondimu π)
Not even close to where I want to be
but far from where it all started
and that's enough to keep me going π€
but far from where it all started
and that's enough to keep me going π€
β‘13