‼️ CVE-2026-41940: A high-performance, multi-threaded security auditing tool designed to detect CVE-2026-41940, a critical Authentication Bypass vulnerability in cPanel & WHM.
https://t.co/N5bKlx0vZK
OSINT: Gathering Information on a WhatsApp Account
A phone number alone can reveal profile photos, status updates, and linked devices.
Our guide shows exactly how you can legally and effectively extract intelligence from WhatsApp accounts!
https://t.co/Bpj624Clbm
@three_cube
The Malware Analysis labs just got a serious upgrade.
You can now choose your environment:
• REMnux - Linux
• FLARE VM - Windows
We added FLARE VM because a lot of you wanted a Windows-based option for malware analysis.
At the same time, we separated Incident Response from Malware Analysis so each one can stand on its own with a cleaner, more focused workflow.
We also rebuilt the malware workspace so the active question stays visible on the right, alongside a practical reference of the tools you can use to inspect malicious artefacts and work through the lab.
These changes are now live.
And they land just ahead of our biggest case yet, dropping soon:
a full domain compromise that started from a NetSupport infection! 🔜
‼️ A "Pegasus-Like" zero-click RAT spyware targeting Android and iOS is being sold on a popular cybercrime forum.
Threat Actor: xone9to1
Date: 04-02-2026
Category: Malware / Spyware
Threat actor is advertising a zero-click RAT spyware claiming to work without APK/IPA installation, compatible with iPhone 17 iOS 26.2 and Android 5 to 16.
Features include device information gathering, network and SIM details, live GPS location with history, real-time notification monitoring, call logs, contacts manager, SMS manager with OTP viewer, WhatsApp call and message monitoring, and access to all social media accounts (Google, Facebook, Instagram, Twitter, Telegram, Spotify, etc.).
Advanced capabilities include device controls (lock, power off, ringer, brightness), botnet controls with DDoS, file manager with encryption, live surveillance (front/back camera, screen recording, microphone access), keylogger, and banking/crypto stealer modules targeting MetaMask, Trust, Binance, UPI, Apple Pay, Google Pay, and PayPal.
A demo video is included as proof of concept.
GhostKatz bypasses EDR by dumping LSASS credentials directly from physical memory. Learn how this new Red Team tool abuses signed drivers to stay invisible.
https://t.co/z8PD6ZSmNE
PentestAgent : is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
- https://t.co/vCVmr1s3E6
#infosec#cybersec#bugbountytips
Google Dorks for Bug Bounty
- Juicy extensions and endpoints
- Open redirects
- Code leaks
- Cloud storages
- File upload endpoints and so on.
https://t.co/0Q2g26YkvO
Evading Elastic Security - Deep dive into bypassing detections through string obfuscation, symbol randomization, XOR-encoded fragments & behavioral evasion techniques
https://t.co/WB3JF52E4l
#infosec#redteam#linux#rootkit#elastic#malware#rootkits
Leaked system prompts for CHATGPT, GEMINI, GROK, CLAUDE, PERPLEXITY, CURSOR, DEVIN, REPLIT, AND MORE! - AI systems transparency for all https://t.co/ATxe71jcE5
GitHub - morpheuslord/GPT_Vuln-analyzer: Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports based on Nmap scan data, and DNS scan information. It can also https://t.co/WIy4ugiSXQ
Released GHunt 2.3.3 with a new module : 🕷️ Spiderdal !
Put a domain name and quickly find tied assets, including the hidden ones, by abusing Google's assets links statements.
New way for doing recon before a pentest ! 🥳