Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters https://hacklido.com/news/phishing-campaign-sends-millions-of-emails-using-invisible-unicode-to-evade-filters
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution https://hacklido.com/news/postgresql-fixes-12-year-old-logical-decoding-flaw-enabling-replication-role-code-execution
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic https://hacklido.com/news/new-ted-backdoor-hides-inside-victims-own-haproxy-builds-to-intercept-web-traffic
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution https://hacklido.com/news/postgresql-fixes-12-year-old-logical-decoding-flaw-enabling-replication-role-code-execution
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic https://hacklido.com/news/new-ted-backdoor-hides-inside-victims-own-haproxy-builds-to-intercept-web-traffic
HackNews
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft warns of a high-volume phishing campaign using invisible Unicode characters to bypass email filters and distribute financial-themed phishing emails.
Today News Highlights
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores https://hacklido.com/news/unpatched-magento-and-adobe-commerce-zero-day-exploited-to-backdoor-online-stores
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials https://hacklido.com/news/attackers-breached-jetbrains-cadence-via-unpatched-teamcity-extracting-aws-credentials
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code https://hacklido.com/news/critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-execute-host-code
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores https://hacklido.com/news/unpatched-magento-and-adobe-commerce-zero-day-exploited-to-backdoor-online-stores
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials https://hacklido.com/news/attackers-breached-jetbrains-cadence-via-unpatched-teamcity-extracting-aws-credentials
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code https://hacklido.com/news/critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-execute-host-code
HackNews
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
A new Magento StyleSmuggler zero-day is being actively exploited to gain unauthenticated code execution and install persistent backdoors on e-commerce servers.
Jaguar Land Rover confirms planned job cuts https://hacklido.com/news/jaguar-land-rover-confirms-planned-job-cuts
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner https://hacklido.com/news/four-revstealer-linked-modules-disable-windows-update-and-defender-to-run-a-crypto-miner
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication https://hacklido.com/news/attackers-hijack-mikrotik-routers-through-internet-exposed-ssh-without-authentication
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner https://hacklido.com/news/four-revstealer-linked-modules-disable-windows-update-and-defender-to-run-a-crypto-miner
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication https://hacklido.com/news/attackers-hijack-mikrotik-routers-through-internet-exposed-ssh-without-authentication
HackNews
Jaguar Land Rover confirms planned job cuts
Jaguar Land Rover opens a voluntary redundancy programme while targeting £1.7 billion in cost savings following a £1.9 billion impact from its 2025 cyberattack.
🚨 Day 8 | Broken Access Control, IDOR & Privilege Escalation | VAPT Training | Chitra Karanam
*We are live join now guy's.*
🎥 Join the Live Class Now:
https://youtube.com/live/-n-1usnxA74?feature=share
*We are live join now guy's.*
🎥 Join the Live Class Now:
https://youtube.com/live/-n-1usnxA74?feature=share
YouTube
Broken Access Control, IDOR & Privilege Escalation | VAPT Training | Chitra Karanam
💬 OFFICIAL WHATSAPP GROUP:
https://chat.whatsapp.com/K08LAioJ9ppHyRZBAjdznd?s=cl&p=a&mlu=4
💻 HANDS-ON LABS:
https://learn.hacklido.com/
🌐 TECHONQUER:
https://techonquer.org/vapt
🔥 DAY 8 | OWASP TOP 10 | BROKEN ACCESS CONTROL
Welcome to Day 8 of the VAPT…
https://chat.whatsapp.com/K08LAioJ9ppHyRZBAjdznd?s=cl&p=a&mlu=4
💻 HANDS-ON LABS:
https://learn.hacklido.com/
🌐 TECHONQUER:
https://techonquer.org/vapt
🔥 DAY 8 | OWASP TOP 10 | BROKEN ACCESS CONTROL
Welcome to Day 8 of the VAPT…
🔥 FUN WITH CK IS HERE! 🔥
Pure meme chaos, ChatGPT roasts, and backbencher energy! 🚨
Hit play for an instant dose of madness! 😂💥
👉 https://www.youtube.com/watch?v=Y0R9ZLg-EPc
Pure meme chaos, ChatGPT roasts, and backbencher energy! 🚨
Hit play for an instant dose of madness! 😂💥
👉 https://www.youtube.com/watch?v=Y0R9ZLg-EPc
YouTube
FUN WITH CK 😂 | Students, Exams & ChatGPT Be Like! | Funny Meme Compilation | Chitra Karanam
Student life is basically a mix of assignments, exams, coding, deadlines, and saying “I’ll start studying tomorrow.” 😂
This video captures those too-real student moments that every college student can relate to. From exam stress to last-minute preparation…
This video captures those too-real student moments that every college student can relate to. From exam stress to last-minute preparation…
VAPT Playground Quiz – Day 10
50 Cybersecurity Questions covering ISC2 CC, CEH, Security+, VAPT & Interview Questions.
Answer as fast as you can! The fastest participant gets a chance to WIN our AI Security Live Course FREE.
Plus, 20% OFF for everyone who participates and submits their answers through the Google Form.
Are you ready for the challenge?
Join. Compete. Learn. Win.https://youtube.com/live/Ct2z2_AD0lU?feature=share
50 Cybersecurity Questions covering ISC2 CC, CEH, Security+, VAPT & Interview Questions.
Answer as fast as you can! The fastest participant gets a chance to WIN our AI Security Live Course FREE.
Plus, 20% OFF for everyone who participates and submits their answers through the Google Form.
Are you ready for the challenge?
Join. Compete. Learn. Win.https://youtube.com/live/Ct2z2_AD0lU?feature=share
YouTube
VAPT Playground Quiz | 50 Cybersecurity Questions | Win a Free AI Security Course | Chitra Karanam
💬 OFFICIAL WHATSAPP GROUP:
https://chat.whatsapp.com/K08LAioJ9ppHyRZBAjdznd?s=cl&p=a&mlu=4
💻 HANDS-ON LABS:
https://learn.hacklido.com/
🌐 TECHONQUER:
https://techonquer.org/vapt
Welcome to the VAPT Playground Quiz Challenge – Day 10!
Think you have what…
https://chat.whatsapp.com/K08LAioJ9ppHyRZBAjdznd?s=cl&p=a&mlu=4
💻 HANDS-ON LABS:
https://learn.hacklido.com/
🌐 TECHONQUER:
https://techonquer.org/vapt
Welcome to the VAPT Playground Quiz Challenge – Day 10!
Think you have what…
Latest Tech News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data https://hacklido.com/news/attackers-use-passkey-phishing-to-hijack-microsoft-cloud-accounts-and-exfiltrate-data
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV https://hacklido.com/news/cisa-adds-5-actively-exploited-artifactory-screenconnect-and-routeros-flaws-to-kev
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers https://hacklido.com/news/openai-agents-linked-to-rubygems-campaign-that-gained-rce-on-rubydoc-servers
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data https://hacklido.com/news/attackers-use-passkey-phishing-to-hijack-microsoft-cloud-accounts-and-exfiltrate-data
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV https://hacklido.com/news/cisa-adds-5-actively-exploited-artifactory-screenconnect-and-routeros-flaws-to-kev
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers https://hacklido.com/news/openai-agents-linked-to-rubygems-campaign-that-gained-rce-on-rubydoc-servers
HackNews
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports https://hacklido.com/news/telegram-desktop-flaw-lets-hidden-javascript-exfiltrate-messages-from-html-exports
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials https://hacklido.com/news/3bb-attacker-used-meshcentral-backdoor-for-root-access-targeted-subscriber-credentials
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing https://hacklido.com/news/new-ddrop-attack-breaks-intel-tdx-and-amd-sev-snp-confidential-computing
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials https://hacklido.com/news/3bb-attacker-used-meshcentral-backdoor-for-root-access-targeted-subscriber-credentials
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing https://hacklido.com/news/new-ddrop-attack-breaks-intel-tdx-and-amd-sev-snp-confidential-computing
HackNews
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A Telegram Desktop flaw allowed malicious bots to hide JavaScript in exported HTML chats, potentially exposing messages and enabling fake pages when old exports
❤1
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution https://hacklido.com/news/attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers https://hacklido.com/news/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers
https://hacklido.com/news/one-extension-could-hijack-ai-assistants-across-chrome-comet-edge-opera-neon-and-claude
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers https://hacklido.com/news/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers
https://hacklido.com/news/one-extension-could-hijack-ai-assistants-across-chrome-comet-edge-opera-neon-and-claude
HackNews
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall https://hacklido.com/news/rathat-android-malware-abuses-adb-to-retain-shell-access-after-uninstall
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root https://hacklido.com/news/critical-check-point-management-flaw-lets-unauthenticated-attackers-run-code-as-root
https://hacklido.com/news/critical-docker-sandboxes-flaw-lets-malicious-guest-code-read-and-modify-macos-host-files
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root https://hacklido.com/news/critical-check-point-management-flaw-lets-unauthenticated-attackers-run-code-as-root
https://hacklido.com/news/critical-docker-sandboxes-flaw-lets-malicious-guest-code-read-and-modify-macos-host-files
HackNews
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https://hacklido.com/news/public-exploits-released-for-four-linux-kernel-flaws-that-enable-local-root
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution https://hacklido.com/news/new-wordpress-click2shell-flaw-forces-theme-installs-can-chain-to-code-execution
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 https://hacklido.com/news/transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-for-c2
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution https://hacklido.com/news/new-wordpress-click2shell-flaw-forces-theme-installs-can-chain-to-code-execution
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 https://hacklido.com/news/transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-for-c2
HackNews
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
We’re Hiring! | Video Editing Interns🎬
Techonquer is looking for creative Video Editing Interns to join our content team! 🚀
If you love editing YouTube videos, Reels & Shorts and want real-world experience working on tech & educational content, this opportunity is for you.
✨ Build your portfolio
🎥 Work on real content
📜 Internship Certificate
👉 Apply here:
https://forms.gle/ssmXuDRkRLJ466h56
Freshers & students are welcome to apply!
Techonquer is looking for creative Video Editing Interns to join our content team! 🚀
If you love editing YouTube videos, Reels & Shorts and want real-world experience working on tech & educational content, this opportunity is for you.
✨ Build your portfolio
🎥 Work on real content
📜 Internship Certificate
👉 Apply here:
https://forms.gle/ssmXuDRkRLJ466h56
Freshers & students are welcome to apply!
Google Docs
Video Editing Intern – Techonquer
Techonquer is looking for creative and passionate Video Editing Interns who want to gain real-world experience working on professional educational and technology content.
As a Video Editing Intern, you will work closely with our content team to create engaging…
As a Video Editing Intern, you will work closely with our content team to create engaging…
❤1
Day 1 of 30: Why AI Agents Broke Your Threat Model
Your threat model assumes a boundary between data and instructions.
An LLM has one input channel. The system prompt, the user question, the tool descriptions and that GitHub issue it just read are all the same buffer.
There is no boundary to defend.
https://hacklido.com/blog/1631-why-ai-agents-broke-your-threat-model
Your threat model assumes a boundary between data and instructions.
An LLM has one input channel. The system prompt, the user question, the tool descriptions and that GitHub issue it just read are all the same buffer.
There is no boundary to defend.
https://hacklido.com/blog/1631-why-ai-agents-broke-your-threat-model
HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community
Why AI Agents Broke Your Threat Model
Why AI Agents Broke Your Threat Model For about two years, the worst thing a language model could do to you was say something wrong. It could leak a system...