JWT SQL Injection
jti (JWT ID) is stored in a DB to prevent token replay.
That lookup is injectable.
"jti": "' OR '1'='1"
Try it: https://t.co/A01VkoVnjK
Full technique: https://t.co/r4ePoKUoFo
#hack2earn#bugbounty#jwt
Mapa ekosistema informacione bezbednosti Srbije je objavljena!
🎥 Vođena tura - https://t.co/lLVoDmmmQt
🗺️ Samostalno istraživanje - https://t.co/DphHp6CZbp
Mapa povezuje 800+ aktera, projekata i inicijativa koji oblikuju razvoj informacione bezbednosti u našoj zemlji.
https://t.co/r67jck8ZGo just got a visual refresh 🌟
Explore 600+ documented DLL Hijacking cases, including:
• JSON/CSV/YAML feeds
• Sigma detection content for every DLL
• A single Sigma rule covering all DLLs
Check it out: https://t.co/2PJCgKEZwO
Hello
I have added more malware to the malware collection place. I have added 150,000 malwares and a bunch of malware reversing papers coupled with malwares.
Please download the malware. Please see subsequent post.
https://t.co/HDTpR7UxxK
🚨 🇷🇸 CYBER THREAT INTELLIGENCE ALERT: POTENTIAL DATA BREACH — BEOTELNET (TELEKOM)
⚠️ MEDIUM PRIORITY: THREAT ACTIVITY DETECTED
[STATUS: UNCONFIRMED / UNDER INVESTIGATION / NO VERIFIED EVIDENCE OF IMPACT]
An announcement has been detected on forums dedicated to malicious activity, in which a user identified as QilinZeus claims to have breached the systems of BeotelNet—a company affiliated with Telekom in Serbia.
🏢 Affected Entity: 🌐 BeotelNet (Telekom Serbia).
👤 Threat Actor: 🛡️ QilinZeus.
📅 Date of Record: 2026-05-29.
📊 Reported Scope: The actor claims to possess over 150,000 records spanning the period from 2020 to 2026, including personal data such as names, JMBG (National Identification Numbers), addresses, phone numbers, and email addresses.
🔍 Evidence Status
Although the actor has published a sample of the allegedly exfiltrated data, the current situation is classified as follows:
Absence of Evidence of Impact: To date, there is no visible or confirmed evidence validating that BeotelNet's infrastructure has actually been compromised, or that the exposed data originates from a recent breach.
Nature of the Report: This appears to be an extortion attempt in which the actor seeks an agreement for the deletion of the database prior to a deadline set for June 1, 2026.
🛡️ Mitigation Recommendations
🔎 Security Audit: BeotelNet's IT teams are advised to conduct a comprehensive review of their access logs and systems to rule out any actual intrusion.
⚡ Strategic Monitoring Tools
🌐 Intelligence Platform: https://t.co/wk9bZJ2Nli
🛡️ Security Verification: https://t.co/5LuqwzYuS6
#CyberSecurity #DataLeak #Serbia #BeotelNet #Telekom #QilinZeus #ThreatIntelligence #CyberAlert #VECERT #UnderInvestigation #NoConfirmation
DriverSentinel - a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the https://t.co/mgCBT3MISw database. https://t.co/HBFTG3sMqR
🔍BIRN otkriva: MUP Srbije poseduje još dva sistema za prepoznavanje lica koja do sada nisu bila poznata domaćoj javnosti. Oba omogućavaju obradu biometrijskih podataka u realnom vremenu.
https://t.co/4P4VWROueW
Kako tehnologija oblikuje javni prostor i građanska prava? TikTok propaganda u Srbiji, sloboda okupljanja i AI deregulacija - teme su novog SHARE Biltena.
https://t.co/7zEC3g7eAI
Kada popadaju telefoni, socijalne mreže, struja i dostavljači hrane, ja ću javiti vašoj rodbini da ste gladni i sa puno slobodnog vremena rešili da postanete radioamateri.