Stop relying on basic searches. Use Google Dorking (`filetype:pdf` or `intitle:index of`) to find exposed sensitive docs. Pro-tip: Combine Shodan with `port:80` filters to map internal infrastructure before attackers do. #OSINT #InfoSec #CyberSecurity
Ethical Hacker
@cybercod.bsky.social
Ethical Hacking & Cybersecurity terminaltools.blogspot.com
🚨 EUVD-2026-53399 📊 n/a 🏢 Apache Software Foundation 📝 Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53399 #cybersecurity #infosec #cve #euvd
Fresh from CyberIntel: Russia's Struggle to Utilize Partner Aid in Ukraine Conflict https://cyberintelnews.com/ #AI #GenAI #Cybersecurity
🚨 EUVD-2026-53392 📊 7.6/10 🏢 flarum 📝 Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account ac... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53392 #cybersecurity #infosec #cve #euvd
Stop treating the OWASP Top 10 like a checklist and start treating it like a threat model. Pro-tip: Focus on business logic flaws; automated scanners almost always miss them. Security isn't a plugin, it’s a mindset. #WebSecurity #OWASP #InfoSec
ASN: AS4766 Korea Telecom Country: KR City: Seoul State: Seoul Scanned: 2025-05-06T10:36:19 https://computernewb.com/vncresolver/browse#id/66116371 #vnc #infosec
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook #potatosecurity #mashing #news #infosec #security #technology #privacy
CVE-2026-66747 - cpe2801 firmware The Zbtlink router has a hidden program that allows an attacker to control the router remotely without a password. This could allow an attacker to make changes to… Too many irrelevant or confusing CVEs? Use stackflag.com #cpe2801firmware #zbtlink #CVE #infosec
CVE-2026-66747: Zbtlink Router Has Root Access Implant
The Zbtlink router has a hidden program that allows an attacker to control the router remotely without a password.
stackflag.com
CVE-2026-71235 - magistrala An attacker with a Magistrala account can run malicious code to access and modify sensitive data, potentially leading to data breaches or disruptions. This is a concern because… Too many irrelevant or confusing CVEs? Use stackflag.com #magistrala #absmach #CVE #infosec
CVE-2026-71235: Magistrala IoT Platform: Unrestricted Code Execution in Rules Engine
An attacker with a Magistrala account can run malicious code to access and modify sensitive data, potentially leading to data breaches or disruptions.
stackflag.com
CVE-2026-71237 - iot-php Miantang IoT-PHP's login feature is vulnerable to unauthorized access. An attacker can bypass the login system and extract sensitive data from the database. To protect your system,… Too many irrelevant or confusing CVEs? Use stackflag.com #iotphp #miantang #CVE #infosec
CVE-2026-71237: Miantang IoT-PHP: Unauthenticated Password Bypass and Data Theft
Miantang IoT-PHP's login feature is vulnerable to unauthorized access. An attacker can bypass the login system and extract sensitive data from the database.
stackflag.com
Open VSX removed 77 malicious extensions mimicking legitimate tools, highlighting software supply chain risks. #OpenVSX #SoftwareSupplyChain #Cybersecurity #DeveloperTools #Malware thedailytechfeed.com/open-vsx-rem...
OpenAI and Anthropic models ‘went rogue’ during UK cybersecurity test www.theguardian.com/technology/2...
OpenAI and Anthropic models ‘went rogue’ during UK cybersecurity test
AI Security Institute says tools engaged in potentially harmful activity and incident reveals new type of risk
theguardian.com
Residents are raising alarms over mysterious automated license-plate cameras, questioning their purpose and who controls the data! Click to read more! #CrescentCityDelNorteCounty #CA #CrescentCityPrivacy #SurveillanceEthics #CitizenPortal #DataPrivacy #PublicAccountability
Residents press council on automated license‑plate cameras; staff says devices are county installations
Two public commenters raised privacy and cybersecurity concerns about automated license‑plate readers at Washington/Northcrest; Chief Griffin and staff said the cameras were installed by the county and the city currently lacks direct access despite a prior MOU.
citizenportal.ai
🚨 Your RMM tool is now the attacker's foothold. CISA added CVE-2026-18577 to KEV after real customer compromises. https://www.yazoul.net/news/article/cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-customer-compromises/ by Yazoul AI #CyberSecurity #PatchNow
CVE-2026-18556-CVE-2026-18577
yazoul.net
White House presenting a finalized AI oversight framework to tech giants today. Ah yes, letting multi-billion-dollar hype machines grade their own cybersecurity homework. What could possibly go wrong? #AI #TechPolicy
🚨 EUVD-2024-1174 📊 5.4/10 🏢 Red Hat 📝 A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1174 #cybersecurity #infosec #cve #euvd
🚨 EUVD-2026-52870 📊 9.3/10 🏢 Keysight 📝 Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafte... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52870 #cybersecurity #infosec #cve #euvd
Must be nice to be using unlimited taxpayer funds on these vanity projects rather than snap, medical, education, cybersecurity, infrastructure, national security, disaster relief, etc, etc,etc. grift grift grift is the Republican mantra
Aspiring Security Analyst? Stop obsessing over certifications and start building in a lab. Pro-tip: Knowing *how* to write a YARA rule is more impressive than memorizing the CIA triad. Get hands-on or get left behind. 🛡️💻 #CyberSecurity #InfoSec
🚨 EUVD-2026-52660 📊 9.1/10 🏢 Eclipse Foundation 📝 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and ... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52660 #cybersecurity #infosec #cve #euvd
A CyLab Security Academy sponsorship is more than logo placement. It supports free cybersecurity, AI, blockchain, and emerging technology education while creating opportunities to engage learners, educators, and future talent. Sponsorship levels are available for organizations of all sizes.
Isn't it amazing that this ignorant administration and DOD would announce this information after dismantling our National Security Dept, our Cybersecurity Dept, our DOD, our FBI, etc.. Are they hoping some foreign country will attack us?
🚨 EUVD-2026-52725 📊 9.3/10 🏢 openmeter 📝 OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can c... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52725 #cybersecurity #infosec #cve #euvd
Stop scrolling through thousands of packets. Use display filters like `http.request.method == "POST"` or `tcp.analysis.retransmission` to cut the noise instantly. Work smarter, not harder. #Wireshark #CyberSecurity #BlueTeam
Stop scrolling through thousands of packets. Use display filters like `http.request.method == "POST"` or `tcp.analysis.retransmission` to cut the noise instantly. Save your eyes and find the threat faster. 🕵️♂️ #Wireshark #CyberSecurity #NetSec
🌊 ABYSSAL · critical with a public exploit CVE-2024-21893: A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivant… CVSS 8.2 · EPSS 100.0% · CISA KEV · 0day https://beta.vulnsea.com/cve/CVE-2024-21893 #CVE #infosec #cybersecurity #threatintel
CVE-2024-21893 — A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…
beta.vulnsea.com