HackLabs is a collection of hands-on vulnerable labs designed to practice web exploitation, privilege escalation, Active Directory attacks, and general pentesting techniques in a safe environment.
⚠️ For educational and authorized testing only.
🔗 https://t.co/yIKRr71ymP
#CyberSecurity #Pentesting #EthicalHacking #RedTeam #CTF #InfoSec #AppSec
C̶l̶a̶u̶d̶e̶ ̶B̶u̶g̶ ̶H̶u̶n̶t̶e̶r̶ is now BUG HUNTER.
We changed the name because it is no longer limited to Claude Code.
Now it is a standalone open-source CLI that runs from any terminal.
Use Ollama, Groq, DeepSeek, Claude, OpenAI or Grok.
Built for the bug bounty community.
Run it locally with Ollama - no paid AI subscription required.
We are very close to 2.5K GitHub stars. Let’s make it happen, guys.
More updates coming soon.
#OpenSource #BugBounty #CyberSecurity #AI #EthicalHacking #Ollama #GitHub #SecurityTools #BugHunter
🚨 ANOTHER MASTERCLASS FROM @3BLUE1BROWN
The compressibility of language isn’t just a math curiosity, it’s the hidden engine behind every LLM you use.
Grant’s new video reframes Shannon’s entropy through one elegant lens:
Prediction IS compression.
→ The better you predict the next word, the fewer bits you need to store it
→ Shannon measured English at ~1 bit per character: astonishingly compressible
→ This is exactly what GPT-style models optimize
→ Intelligence, in this framing, is compression
FUN FACT: Von Neumann told Shannon to name it “entropy” because nobody truly understands it anyway 😄
Decades later, that same concept became the bedrock of modern AI.
Deep-dive resources in the 🧵 ↓
🚨CloudRip Fast Cloudflare bypass scanner. A tool that helps you find the real IP addresses hiding behind Cloudflare by checking subdomains.
✅https://t.co/YQOwI5acJ0
✅ Join Telegram For More Content: https://t.co/Pz9cWGL18l
#CyberSecurity#BugBounty#EthicalHacking#Infosec
The International Cybersecurity Community for Africa (ICCA) officially launched in Kigali on 20 March 2026.
More than just an organization, ICCA is a movement focused on building a stronger, more resilient cybersecurity ecosystem across Africa through collaboration, capacity building, and shared threat intelligence.
With cyber attacks rising across the continent and a major shortage of skilled professionals, we are stepping in to bridge the gap; training talent, building local solutions, and connecting experts across borders.
This is a big step for Africa cybersecurity. And we thank partners who are in the journey with us, @teamcymru, MicroRisk Labs, @rwictchamber, @huzalabs, and the @RwandaICT.
This is just the beginning.
Free Online Cybersecurity Courses and Certifications in 2026.
Here are 15 FREE courses to help you master Cybersecurity 👇👇
1. IBM Cybersecurity Analyst Professional Certificate
🔗https://t.co/8w2KiMfUYZ
2. Microsoft Cybersecurity Analyst Professional Certificate
🔗 https://t.co/13XCEnFgLF
3. Cloud Application Development Foundations Specialization
🔗 https://t.co/lIJRv8CjrN
4. Developing Applications with Google Cloud Specialization
🔗 https://t.co/HqmTxkIONQ
5. Introduction to Cloud Computing
🔗 https://t.co/Q8tKxspuIL
6. Understanding Google Cloud Security and Operations
🔗 https://t.co/hepRgqvDGp
7. Innovating with Data and Google Cloud
🔗 https://t.co/zKWneHhtrb
8. Microsoft Azure Fundamentals: Describe cloud concepts
🔗 https://t.co/tciSIBlysA...
9. GoogleCloud: Google Cloud Computing Foundations: Cloud Computing Fundamentals
🔗 https://t.co/hcuDdWIL1J…
10. Cloud Computing Basics (Cloud 101)
🔗https://t.co/ApIf3oghQt
11. IT Fundamentals for Cybersecurity Specialization
🔗https://t.co/grNgztS9sO
12. Introduction to Cybersecurity Tools & Cyber Attacks
🔗 https://t.co/Oe7rRtqegM
13. Cyber Security Course for Beginners
https://t.co/UYTZBk8c8i…
14. Introduction to Cyber Security
https://t.co/9qGH28YLMj…
15. For Beginners
https://t.co/tk2BXQpqCL…
Happy Learning 🌟
Penetration Tester Agent - https://t.co/088JVXhCFu
You are a senior penetration tester with expertise in ethical hacking, vulnerability discovery, and security assessment. Your focus spans web applications, networks, infrastructure, and APIs with emphasis on comprehensive security testing, risk validation, and providing actionable remediation guidance.
#PenetrationTesting #EthicalHacking #VulnerabilityAssessment #AppSec #CyberSecurity #PentestAgent
Today I started something I'm really excited about.
I'm publishing a complete #SSH course on Pro TecMint that covers 54 chapters across 16 modules, from absolute beginner to enterprise.
Course Introduction is live now for Pro TecMint members. I'll be dropping new chapters regularly.
Join here to follow along: https://t.co/M6zgrQxQqN
Cyber AI Profile - https://t.co/1vq3N4BAh3 by @NIST
NIST’s preliminary draft Cyber AI Profile can help organizations strategically adopt AI while addressing and prioritizing cybersecurity risks stemming from its advancements.
The Cyber AI Profile addresses the following Focus Areas:
- Securing AI System Components (Secure)
- Conducting AI-Enabled Cyber Defense (Defend)
- Thwarting AI-enabled Cyber Attacks (Thwart)
Authors:
@KonnectedKat, Barbara Cuthill, Marissa Dotter, Michael Garris, Ishika Khemani, Bronwyn Patrick, Noah Schiro, Julie Nethery Snyder, Mohammad Zarei – @NIST, @NISTcyber, @MITREcorp
🛡️ Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code
Source: https://t.co/r6QYZ6GjyC
Security update addressing a dangerous Windows PowerShell vulnerability that allows attackers to execute malicious code on affected systems.
The vulnerability, tracked as CVE-2025-54100, was publicly disclosed on December 9, 2025, and represents a significant security risk for organizations worldwide.
The flaw stems from improper neutralization of special elements in Windows PowerShell during command injection attacks. The vulnerability enables unauthorized attackers to execute arbitrary code locally through specially crafted commands.
#cybersecuritynews #windows
🚨 POC for CVE-2025-55182 that works on Next.js 16.0.6
Here are the exact, battle-tested queries you need — Censys, Shodan, FOFA, ZoomEye, Quake, BinaryEdge, https://t.co/QCBcPytvyC, and Nuclei matchers — all tuned specifically to find Next.js RSC / React Server Components instances vulnerable to CVE-2025-55182 (React2Shell).
⸻
✅ 1. SHODAN QUERY (380K+ ASSETS)
Find all servers leaking RSC Server Actions:
Basic Query
"Vary: RSC, Next-Router-State-Tree"
More Aggressive Variant
http.headers.vary:"RSC" AND http.headers.vary:"Next-Router-State-Tree"
Superwide Coverage
"Next-Router-State-Tree" OR "x-nextjs-cache" OR "server-actions" OR "__RSC__"
Focused on Vulnerable Cache Indicators
"x-nextjs-cache: HIT" "Next-Router-State-Tree"
⸻
✅ 2. CENSYS QUERY (270K+ ASSETS)
(match the screenshot you posted)
Exact Censys Search
services.http.response.headers.vary: "RSC, Next-Router-State-Tree"
Safer Multi-Matcher
services.http.response.headers.vary: "RSC" AND services.http.response.headers.vary: "Next-Router-State-Tree"
Detect RSC Payload Exposure (critical)
services.http.response.body: "__RSC__"
Detect Flight Data Leaks
services.http.response.body: "server-reference-manifest"
⸻
✅ 3. FOFA QUERY (CHINA’S OSINT GIANT)
(VERY POWERFUL for RSC/Next.js)
Exact Header Based
header="Next-Router-State-Tree" && header="RSC"
Alternative (match screenshot patterns)
"Next-Router-State-Tree" && "x-nextjs-cache"
For massive result count
body="__RSC__" || header="server-actions"
⸻
✅ 4. ZOOMEYE QUERY
ZoomEye scans often catch Node.js apps Shodan misses.
Exact Unicode-Ready Query
"Next-Router-State-Tree" && "RSC"
Advanced
app:"Next.js" && header:"RSC"
⸻
✅ 5. QUAKE SEARCH (360K+ MATCHES)
header:"Next-Router-State-Tree" AND header:"RSC"
⸻
✅ 6. BINARYEDGE QUERY
http.response.headers.vary:"Next-Router-State-Tree"
⸻
✅ 7. https://t.co/b1z8KIFyRS QUERY
headers:"Next-Router-State-Tree" && headers:"RSC"
⸻
🎯 8. NUCLEI MATCHER (to detect RSC without scanning payloads)
If you want a nuclei detector you can plug into your scanner:
matchers:
- type: word
part: header
words:
- "RSC"
- "Next-Router-State-Tree"
- "server-actions"
- "__RSC__"
⸻
🚩 BONUS — THE MOST ADVANCED CROSS-ENGINE QUERY
Use this when you want maximum global coverage:
"Next-Router-State-Tree" OR "RSC" OR "__RSC__" OR "server-actions" OR "x-nextjs-cache" OR "Next-Server-Action"
This identifies:
•Next.js App Router
•RSC endpoints
•Server Actions
•Flight data APIs
•Pages exposing cache HITs (required for exploitation)
•Systems likely vulnerable to CVE-2025-55182 (React2Shell)
⚠️ 4 hacker groups are now using the same malware tool — CastleLoader.
It’s sold as malware-for-hire by a group called GrayBravo. They’re hitting targets from logistics to IT using fake online Booking pages and software updates.
Each attack links back to the same control servers — built to spread fast.
🔗 Read ↓ https://t.co/gcbHGpdvdm