Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports https://hacklido.com/news/telegram-desktop-flaw-lets-hidden-javascript-exfiltrate-messages-from-html-exports
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials https://hacklido.com/news/3bb-attacker-used-meshcentral-backdoor-for-root-access-targeted-subscriber-credentials
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing https://hacklido.com/news/new-ddrop-attack-breaks-intel-tdx-and-amd-sev-snp-confidential-computing
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials https://hacklido.com/news/3bb-attacker-used-meshcentral-backdoor-for-root-access-targeted-subscriber-credentials
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing https://hacklido.com/news/new-ddrop-attack-breaks-intel-tdx-and-amd-sev-snp-confidential-computing
HackNews
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A Telegram Desktop flaw allowed malicious bots to hide JavaScript in exported HTML chats, potentially exposing messages and enabling fake pages when old exports
β€1
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution https://hacklido.com/news/attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers https://hacklido.com/news/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers
https://hacklido.com/news/one-extension-could-hijack-ai-assistants-across-chrome-comet-edge-opera-neon-and-claude
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers https://hacklido.com/news/three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers
https://hacklido.com/news/one-extension-could-hijack-ai-assistants-across-chrome-comet-edge-opera-neon-and-claude
HackNews
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall https://hacklido.com/news/rathat-android-malware-abuses-adb-to-retain-shell-access-after-uninstall
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root https://hacklido.com/news/critical-check-point-management-flaw-lets-unauthenticated-attackers-run-code-as-root
https://hacklido.com/news/critical-docker-sandboxes-flaw-lets-malicious-guest-code-read-and-modify-macos-host-files
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root https://hacklido.com/news/critical-check-point-management-flaw-lets-unauthenticated-attackers-run-code-as-root
https://hacklido.com/news/critical-docker-sandboxes-flaw-lets-malicious-guest-code-read-and-modify-macos-host-files
HackNews
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https://hacklido.com/news/public-exploits-released-for-four-linux-kernel-flaws-that-enable-local-root
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution https://hacklido.com/news/new-wordpress-click2shell-flaw-forces-theme-installs-can-chain-to-code-execution
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 https://hacklido.com/news/transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-for-c2
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution https://hacklido.com/news/new-wordpress-click2shell-flaw-forces-theme-installs-can-chain-to-code-execution
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 https://hacklido.com/news/transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-for-c2
HackNews
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Weβre Hiring! | Video Editing Internsπ¬
Techonquer is looking for creative Video Editing Interns to join our content team! π
If you love editing YouTube videos, Reels & Shorts and want real-world experience working on tech & educational content, this opportunity is for you.
β¨ Build your portfolio
π₯ Work on real content
π Internship Certificate
π Apply here:
https://forms.gle/ssmXuDRkRLJ466h56
Freshers & students are welcome to apply!
Techonquer is looking for creative Video Editing Interns to join our content team! π
If you love editing YouTube videos, Reels & Shorts and want real-world experience working on tech & educational content, this opportunity is for you.
β¨ Build your portfolio
π₯ Work on real content
π Internship Certificate
π Apply here:
https://forms.gle/ssmXuDRkRLJ466h56
Freshers & students are welcome to apply!
Google Docs
Video Editing Intern β Techonquer
Techonquer is looking for creative and passionate Video Editing Interns who want to gain real-world experience working on professional educational and technology content.
As a Video Editing Intern, you will work closely with our content team to create engagingβ¦
As a Video Editing Intern, you will work closely with our content team to create engagingβ¦
β€1
Day 1 of 30: Why AI Agents Broke Your Threat Model
Your threat model assumes a boundary between data and instructions.
An LLM has one input channel. The system prompt, the user question, the tool descriptions and that GitHub issue it just read are all the same buffer.
There is no boundary to defend.
https://hacklido.com/blog/1631-why-ai-agents-broke-your-threat-model
Your threat model assumes a boundary between data and instructions.
An LLM has one input channel. The system prompt, the user question, the tool descriptions and that GitHub issue it just read are all the same buffer.
There is no boundary to defend.
https://hacklido.com/blog/1631-why-ai-agents-broke-your-threat-model
HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community
Why AI Agents Broke Your Threat Model
Why AI Agents Broke Your Threat Model For about two years, the worst thing a language model could do to you was say something wrong. It could leak a system...
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure https://hacklido.com/news/clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors https://hacklido.com/news/jade-sleet-linked-to-indian-it-provider-breach-with-flatroof-and-roofdeck-backdoors
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws https://hacklido.com/news/claude-opus-5-helped-researchers-take-over-openai-staff-accounts-via-chained-flaws
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors https://hacklido.com/news/jade-sleet-linked-to-indian-it-provider-breach-with-flatroof-and-roofdeck-backdoors
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws https://hacklido.com/news/claude-opus-5-helped-researchers-take-over-openai-staff-accounts-via-chained-flaws
HackNews
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR https://hacklido.com/news/fake-lastpass-authenticator-installer-abuses-microsoft-signed-driver-to-kill-antivirus-and-edr
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto https://hacklido.com/news/contagious-interview-campaign-compromises-30-000-devices-steals-10-71m-in-crypto
Google Fined β¬403 Million Over GDPR Violations Tied to Location Data https://hacklido.com/news/google-fined-403-million-over-gdpr-violations-tied-to-location-data
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto https://hacklido.com/news/contagious-interview-campaign-compromises-30-000-devices-steals-10-71m-in-crypto
Google Fined β¬403 Million Over GDPR Violations Tied to Location Data https://hacklido.com/news/google-fined-403-million-over-gdpr-violations-tied-to-location-data
HackNews
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
π₯1
Day 14 | API Security Explained | API Hacking, Authentication & Common Vulnerabilities | Free VAPT Training | Chitra Karanamπ
*We are Live join now guys*
π₯ Live Class: https://youtube.com/live/CwfL4MxniwA?feature=share
@β¨allβ©
*We are Live join now guys*
π₯ Live Class: https://youtube.com/live/CwfL4MxniwA?feature=share
@β¨allβ©
YouTube
API Security Explained | Day 14 | VAPT Training | Chitra Karanam
π¬ Join the Official WhatsApp Group:
https://chat.whatsapp.com/K08LAioJ9ppHyRZBAjdznd?s=cl&p=a&mlu=4
π» Hands-on Cybersecurity Labs:
https://learn.hacklido.com/
π Techonquer Website:
https://techonquer.org/
π― VAPT Training:
https://techonquer.org/vapt-trainingβ¦
https://chat.whatsapp.com/K08LAioJ9ppHyRZBAjdznd?s=cl&p=a&mlu=4
π» Hands-on Cybersecurity Labs:
https://learn.hacklido.com/
π Techonquer Website:
https://techonquer.org/
π― VAPT Training:
https://techonquer.org/vapt-trainingβ¦
β€1
The Lethal Trifecta Checklist
https://hacklido.com/blog/1640-the-lethal-trifecta-checklist
Silent Witness - Digital Forensics CTF Writeup
https://hacklido.com/blog/1638-silent-witness-digital-forensics-ctf-writeup
Technical Write-up: Temporal Anomaly
https://hacklido.com/blog/1637-technical-write-up-temporal-anomaly
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials https://hacklido.com/news/malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credentials
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
https://hacklido.com/news/wordpress-issues-patch-for-critical-flaw-that-can-enable-code-execution-on-some-servers
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks https://hacklido.com/news/check-point-warns-of-management-server-zero-day-exploited-in-targeted-attacks
https://hacklido.com/blog/1640-the-lethal-trifecta-checklist
Silent Witness - Digital Forensics CTF Writeup
https://hacklido.com/blog/1638-silent-witness-digital-forensics-ctf-writeup
Technical Write-up: Temporal Anomaly
https://hacklido.com/blog/1637-technical-write-up-temporal-anomaly
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials https://hacklido.com/news/malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credentials
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
https://hacklido.com/news/wordpress-issues-patch-for-critical-flaw-that-can-enable-code-execution-on-some-servers
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks https://hacklido.com/news/check-point-warns-of-management-server-zero-day-exploited-in-targeted-attacks
HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community
The Lethal Trifecta Checklist
The Lethal Trifecta Checklist Day 1 named the three conditions. Day 2 put them on the loop. Day 3 showed you the protocol that carries them. Today we turn...
π NEW CHALLENGE LAUNCHED | HACKLIDO ROOT QUEST
π₯ A brand-new Web Security challenge, βForminatorβ, is now live on Hacklido Root Quest!
π― Category: Web
β‘ Difficulty: Medium
β Points: 400
Put your web security and exploitation skills to the test, identify the vulnerability, and work your way to the flag. Can you solve it before others?
π Start the Challenge:
https://learn.hacklido.com/rootquest/forminator
π Think. Hunt. Exploit. Pwn.
π₯ A brand-new Web Security challenge, βForminatorβ, is now live on Hacklido Root Quest!
π― Category: Web
β‘ Difficulty: Medium
β Points: 400
Put your web security and exploitation skills to the test, identify the vulnerability, and work your way to the flag. Can you solve it before others?
π Start the Challenge:
https://learn.hacklido.com/rootquest/forminator
π Think. Hunt. Exploit. Pwn.
β€1
30-Day Agentic AI Hacking Series | Day 5 π
Day 5 covers OWASP Top 10 for Agentic Applications and key security risks in AI agents.
π Today's Blog:
https://hacklido.com/blog/1643-owasp-top-10-for-agentic-applications
π° Daily Cyber Tech News:
πΉ Terraform Providers Deliver Go Malware
https://hacklido.com/news/attackers-use-malicious-terraform-providers-to-deliver-go-malware-via-hashicorp-registry
πΉ MikroTrick Takes Over MikroTik Routers
https://hacklido.com/news/mikrotrick-chain-let-attackers-take-over-mikrotik-routers-without-a-password-or-ssh-key
πΉ Windows Malware Uses AI Models to Vote
https://hacklido.com/news/this-windows-malware-is-built-to-let-up-to-four-ai-models-vote-on-its-next-move
Day 5 covers OWASP Top 10 for Agentic Applications and key security risks in AI agents.
π Today's Blog:
https://hacklido.com/blog/1643-owasp-top-10-for-agentic-applications
π° Daily Cyber Tech News:
πΉ Terraform Providers Deliver Go Malware
https://hacklido.com/news/attackers-use-malicious-terraform-providers-to-deliver-go-malware-via-hashicorp-registry
πΉ MikroTrick Takes Over MikroTik Routers
https://hacklido.com/news/mikrotrick-chain-let-attackers-take-over-mikrotik-routers-without-a-password-or-ssh-key
πΉ Windows Malware Uses AI Models to Vote
https://hacklido.com/news/this-windows-malware-is-built-to-let-up-to-four-ai-models-vote-on-its-next-move
HACKLIDO - Cybersecurity Blogs, CTF Writeups & Infosec Community
OWASP Top 10 for Agentic Applications
OWASP Top 10 for Agentic Applications, in Plain Language For four days you have been finding attack chains by structure. The lethal trifecta checklist give...
Become a job-ready Cyber Threat Intelligence Analyst. Learn OSINT, Threat Hunting, Malware Intelligence, Infrastructure Tracking, Dark Web Intelligence, MITRE ATT&CK, MISP and OpenCTI.
π Start Date: 5 october 2026
β³ Duration: 12 Weeks
π Level: Basic to Advanced
π° Fee: βΉ8,000 only
π³ Easy Installments: Pay βΉ4,000 at registration and the remaining βΉ4,000 after one month.
Enroll Now: https://techonquer.org/threat-intelligence-training
π Syllabus: https://techonquer.org/public/uploads/2026/09/techonquer-threat-intelligence-syllabus-removed-e9632ee5.pdf
π Start Date: 5 october 2026
β³ Duration: 12 Weeks
π Level: Basic to Advanced
π° Fee: βΉ8,000 only
π³ Easy Installments: Pay βΉ4,000 at registration and the remaining βΉ4,000 after one month.
Enroll Now: https://techonquer.org/threat-intelligence-training
π Syllabus: https://techonquer.org/public/uploads/2026/09/techonquer-threat-intelligence-syllabus-removed-e9632ee5.pdf
Techonquer
Threat Intelligence Course Online | 12 Weeks | Techonquer
Learn threat intelligence from scratch in 12 weeks. OSINT, malware analysis, threat hunting, MITRE ATT&CK, MISP and OpenCTI. Job-ready, hands-on training.
π° Today's Cyber News
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
https://hacklido.com/news/hacked-ukrainian-sites-serve-fake-cloudflare-clickfix-lures-for-psychedelic-stealer
Placeholder third-party.com Referenced Across 1,700+ Repositories Now Serves Malicious Content
https://hacklido.com/news/placeholder-third-party-com-referenced-across-1-700-repositories-now-serves-malicious-content
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions|
https://hacklido.com/news/unpatched-oneplus-flaws-let-installed-android-apps-gain-root-without-permissions
π Today's Blogs
What Is the General Data Protection Regulation (GDPR) and Why Is It Important for Businesses?
https://hacklido.com/blog/1647-what-is-the-general-data-protection-regulation-gdpr-and-why-is-it-important-for-businesses
How to Fix PST to EML Conversion Errors in Outlook: A Complete Troubleshooting Guide
https://hacklido.com/blog/1645-how-to-fix-pst-to-eml-conversion-errors-in-outlook-a-complete-troubleshooting-guide
Gh0st RAT Attack
https://hacklido.com/blog/1644-gh0st-rat-attack
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
https://hacklido.com/news/hacked-ukrainian-sites-serve-fake-cloudflare-clickfix-lures-for-psychedelic-stealer
Placeholder third-party.com Referenced Across 1,700+ Repositories Now Serves Malicious Content
https://hacklido.com/news/placeholder-third-party-com-referenced-across-1-700-repositories-now-serves-malicious-content
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions|
https://hacklido.com/news/unpatched-oneplus-flaws-let-installed-android-apps-gain-root-without-permissions
π Today's Blogs
What Is the General Data Protection Regulation (GDPR) and Why Is It Important for Businesses?
https://hacklido.com/blog/1647-what-is-the-general-data-protection-regulation-gdpr-and-why-is-it-important-for-businesses
How to Fix PST to EML Conversion Errors in Outlook: A Complete Troubleshooting Guide
https://hacklido.com/blog/1645-how-to-fix-pst-to-eml-conversion-errors-in-outlook-a-complete-troubleshooting-guide
Gh0st RAT Attack
https://hacklido.com/blog/1644-gh0st-rat-attack
HackNews
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer