Elektrine lite

← Feed

thecybersecguru

thecybersecguru@infosec.exchange

Posts

  • Post #4479593

    What Happened to HackerOne? HackerOne has changed significantly from the bug bounty platform many researchers knew in the late 2010s. Its current direction is increasingly centered around Hai, AI-assisted triage, vulnerability validation, agentic testing, continuous testing and CTEM. But the question isn't simply whether HackerOne uses AI. It's how researcher submissions, security intelligence and AI-driven workflows fit together, and what that means for the role and value of human vu...

  • Post #4478956

    Dead Internet Theory is getting harder to dismiss. Cloudflare says automated systems now account for more web requests than humans in its measurements. The company is also forecasting that machine-generated traffic could become roughly 1,000× human traffic within five years if current trends continue or as they put it "Humans may become a rounding error on the internet". That doesn't mean 57% of internet users are bots. Web requests and human users are very different measurements...

  • Post #4426070

    Zapscape (CVE-2026-64561) is another reminder that the hypervisor boundary is only as strong as the code implementing it. The vulnerability is a guest-to-host escape in Linux KVM's x86 Shadow MMU. The root cause is a stale-root validation ordering bug that allows the page fault handler to continue using an invalidated shadow MMU root after quota reclaim, ultimately leading to a use-after-free primitive. Public research demonstrates a complete guest-to-host escape chain, although exploitatio...

  • Post #4359162

    ARP is one of those protocols everyone can define, but far fewer can explain in detail. I put together a comprehensive guide covering protocol internals, operating system behavior, Wireshark analysis, security implications, and modern enterprise defenses. Feedback is welcome. https://thecybersecguru.com/networking/address-resolution-protocol-arp/ #Networking #CyberSecurity #IPv4 #Wireshark

  • Post #4330229

    OpenAI's rogue AI agent reached farther than we thought. New reporting confirms the autonomous system also exploited a Modal-hosted customer environment before continuing its campaign against Hugging Face. Full technical breakdown: https://thecybersecguru.com/news/openai-rogue-ai-agent-second-company-modal-hugging-face/ Modal itself wasn't breached. Instead, the agent identified an unauthenticated code execution endpoint, gained a foothold, and used it as an intermediate stag...

  • Post #4330228

    🚨 BREAKING: A GrapheneOS user is facing federal charges after allegedly using a duress password that instantly wiped his phone during a US border search. This isn't just about one Pixel phone. The case could reshape how courts view encryption, digital privacy, and your right to secure your data for years to come. We break down: • What the duress password actually does • Why the data can't be recovered • The technology behind GrapheneOS • Why this case could become a landmark l...

  • Post #4330227

    One of the most common mistakes after getting RCE is wasting time searching for the right reverse shell payload. I put together a practical Reverse Shell Cheat Sheet covering: • Bash, Python, PHP & PowerShell • Netcat, Socat & pwncat listeners • TTY upgrades • Web shells • Base64 & URL-encoded payloads • MSFVenom payload generation Built for Hack The Box, CTFs, ProLabs, and real-world penetration testing. 🔗 https://thecybersecguru.com/bmc-series/reverse-shell-cheat-sh...

  • Post #4330226

    A researcher has demonstrated what appears to be an authenticated RCE against MariaDB 13.0.1-rc. The public video shows successful code execution as the mysql service account, but the underlying vulnerability, affected code path, and exploit technique remain undisclosed. I analyzed the demonstration and separated confirmed observations from speculation. https://thecybersecguru.com/exploits/mariadb-13-0-1-rc-authenticated-rce-analysis/ #MariaDB #DatabaseSecurity #Linux #CyberSecurity #RCE #Ca...

  • Post #4330225

    Can't wait for my GW Ultra 2 to arrive! Just 2 more days😭

  • Post #4330224

    The Hugging Face incident may not have been an isolated case. OpenAI has reportedly uncovered additional AI agent containment escapes during its ongoing investigation. What exactly happened, what "escaped containment" really means, and why it matters for AI security: https://thecybersecguru.com/news/openai-ai-agent-containment-escapes-hugging-face-investigation/ #OpenAI #AISafety #CyberSecurity #AI #InfoSec

  • Post #4330223

    Cryptocurrency is often reduced to price charts and speculation. But the technology itself is far more interesting. It combines cryptography, distributed systems, networking, consensus algorithms, and economics to solve a decades-old computer science problem: transferring digital value without a trusted intermediary. https://thecybersecguru.com/crypto-series/what-is-cryptocurrency/ I put together a technical, beginner-friendly guide covering: • What cryptocurrency actually is • Why Bitcoin...

  • Post #4330222

    🚨 Amgen discloses a material cybersecurity incident Threat actors exfiltrated patient protected health information (PHI) and proprietary corporate data from cloud environments operated by third-party providers. At this time, Amgen says there is no identified impact on manufacturing, financial reporting systems, or its ability to serve patients. However, the full scope of the stolen data, including potential intellectual property and R&D information, remains under investigation. This i...

  • Post #4330221

    🚨 300,000 Robinhood customer records are allegedly up for sale. A threat actor claims to have breached Robinhood Securities, advertising a database containing names, email addresses, phone numbers, account types, and dates of birth. Robinhood has not confirmed a new breach, and the authenticity of the data remains unverified. But if genuine, it could fuel phishing, identity theft, and account takeover attempts. Here's everything we know so far 👇 🔗 https://thecybersecguru.com/news/rob...

  • Post #4278700

    🚨 BREAKING SECURITY ALERT — COLDCARD FIRMWARE INCIDENT🚨 Coinkite has issued an urgent advisory affecting COLDCARD hardware wallets after discovering that certain firmware versions reduced entropy during seed generation, potentially weakening the randomness behind BIP-39 recovery phrases. This comes in the wake of a coordinated theft of ~594.48 BTC (~$38M) from roughly 500 wallets in ~25 minutes. While the timing is alarming, Coinkite has NOT confirmed any direct link between the firmware issue...

  • Post #4266057

    🚨 BREAKING: Anthropic has confirmed that Claude AI compromised 3 real organizations during cybersecurity evaluations after a misconfigured test environment accidentally exposed the public internet. One model uploaded real malware to PyPI, another breached a live production database and continued attacking after recognizing the target was real, while a third compromised an internet-facing application using basic flaws like SQL injection and exposed credentials. 🔎 Full technical breakdown: https...

  • Post #4249693

    🚨 BREAKING: If you manage Cisco firewalls, stop what you're doing and check this. Cisco has confirmed active exploitation of CVE-2026-20316, a hardcoded credentials flaw in Secure Firewall Management Center (FMC). ⚠️ No authentication required. ⚠️ No workaround available. ⚠️ Attackers can remotely log in using a built-in low-privileged account and potentially chain additional vulnerabilities for greater impact. Cisco has released hotfixes, and CISA has already added the flaw to its Known Exp...

  • Post #4242318

    🚨 Revolut is investigating claims that an alleged database containing records linked to 75 million users is being sold on a cybercrime forum. The reported dataset allegedly includes customer information such as: • Partial payment card details • Email addresses • Phone numbers • Device information • Hashed credentials However, there is currently no confirmed evidence of a new breach. Revolut says it has found no signs of unauthorized access to its systems, and researchers have not independently...

  • Post #4233870

    The worst thing about most Airport WiFi? the firewall. The block port 22 too🙂

  • Post #4229516

    🚨 BREAKING: A coordinated cyberattack targeted 30+ community water systems across Minnesota, disrupting operational technology (OT) and temporarily taking one treatment plant offline. State and federal agencies, including CISA, FBI, and EPA, are investigating. Officials say there is no evidence that drinking water quality was compromised, and the attack has not yet been attributed to any threat actor. Full analysis, technical breakdown, and what this means for critical infrastructure security:...

  • Post #4228924

    🚨 Critical VMware Advisory Broadcom has patched multiple critical VMware vulnerabilities affecting vCenter Server and ESXi, including an authentication bypass (CVSS 9.8), directory traversal leading to RCE (CVSS 9.8), and a VM escape via VMXNET3 (CVSS 9.3). Organizations should prioritize patching vCenter and ESXi infrastructure as soon as possible. Technical breakdown, affected versions, and mitigation: https://thecybersecguru.com/news/critical-vmware-vcenter-auth-bypass-rce-vm-escape-vulnera...

  • Post #4136245

    Should I write something on CAN Bus? Basically, networking protocol used by your car?

  • Post #4136244

    Which one to get? Was using Galaxy Watch 6 classic. Watch died last month. GW9 or Ultra 2? Battey life priority with better battery when connected to LTE

  • Post #4136243

    🚨 New Linux Local Privilege Escalation Vulnerability RefluXFS (CVE-2026-64600) is a newly disclosed race condition in the Linux kernel's XFS copy-on-write path that can allow an unprivileged local user to gain root privileges, even on systems with SELinux Enforcing. The flaw affects XFS filesystems with reflink enabled and has existed since Linux kernel 4.11 (2017). Enterprise distributions including RHEL, Oracle Linux, Amazon Linux, and Fedora may be impacted if vulnerable configurati...

  • Post #4136242

    🚨 **Oracle just dropped its biggest security update ever.** **1,449 security patches.** **1,434 CVEs.** **334 products.** **10 vulnerabilities with a perfect CVSS 10.0 score.** But the real story isn't the number. It's that AI is fundamentally changing vulnerability discovery. Vendors are finding flaws faster than ever, which means defenders now face an unprecedented patch management challenge. In this deep dive, I break down: • Why Oracle's patch count exploded • The...

  • Post #4136241

    🇮🇳 India has ordered GitHub to remove Jack Dorsey's Bitchat repositories. The official notice cites concerns that Bitchat's decentralized Bluetooth mesh architecture, lack of mandatory user registration, and absence of centralized logging could hinder lawful interception and criminal investigations. The repositories were targeted under Section 79(3)(b) of the IT Act and the IT Rules, 2021 India has directed GitHub to disable access to the repositories of Bitchat, Jack Dorsey&...

  • Post #4118045

    Threat Actor Claims 130GB Microsoft Corporate Data Breach A threat actor claims to have breached Microsoft and exfiltrated approximately 130 GB of corporate data, allegedly published on a TOR-based leak site. Full technical analysis: https://thecybersecguru.com/news/alleged-microsoft-data-breach-130gb-leak/ The claimed dataset reportedly includes PII, authentication-related information, password hashes, employee and customer records, internal service tickets, access permissions, and other cor...

  • Post #4118034

    Threat Actor Claims 130GB Microsoft Corporate Data Breach A threat actor claims to have breached Microsoft and exfiltrated approximately 130 GB of corporate data, allegedly published on a TOR-based leak site. The claimed dataset reportedly includes PII, authentication-related information, password hashes, employee and customer records, internal service tickets, access permissions, and other corporate data. These claims remain unverified. Microsoft has not publicly confirmed that a breach occu...

  • Post #4117523

    Public AI share links are not the same as private links. Users discovered that site:claude.ai/share and site:claude.ai/public/artifacts searches returned publicly shared Claude conversations, exposing resumes, business discussions, and other sensitive content that had been indexed by search engines. Reports indicate Google began removing many results, but the incident is a reminder that public share pages can become discoverable unless they're removed or unshared. If you've ever shared...

  • Post #4116558

    🚨 Alleged Microsoft Data Breach Claims Surface A threat actor claims to have breached Microsoft and exfiltrated approximately 130GB of corporate data, which is allegedly being published on a TOR-based leak site. The claimed dataset reportedly includes PII, employee and customer contact information, authentication-related data, password hashes, portal identities, corporate account information, internal service tickets, access permissions, and other internal records. At this time, these claims...

  • Post #4116133

    Releasing first introductory video of introduction to cybersecurity course in 24 hours. Stay tuned! Also, feedbacks much appreciated