DursGo is a web application security scanner designed for penetration testing and automated security audits. Built with Go, DursGo combines high-performance scanning with AI-powered analysis to deliver intelligent and actionable security insights.
https://t.co/5K7u2hI0wz
Loxs is an easy-to-use tool that finds web issues like LFI - OR - SQLi - XSS - CRLF.
Original version by @coffinxp7
https://t.co/K0Xx1jegSY
loxs-optimized version by @momika233
https://t.co/ry6D00z1vQ
v6.9 of xnLinkFinder is here:
✅ Allow passing of a single file as -i and searching contents (if first line starts with // or http then assumes its a file of URLs to crawl instead, as before)
✅ Improve regex timeout handling
https://t.co/hAHxqZKxOK
#BugBounty
🤘
v5.0 or waymore is here:
✅ Add new source Intelligence X (intelx,io) - requires PAID API key
✅ Add INTELX_API_KEY to config.yml
✅ Add arg -xix: exclude IntelX source (not required if API key not added)
✅ Run: pip install --upgrade waymore
https://t.co/Olv7lLQtha
#BugBounty
🤘
10 Vscode extensions to install.
1. Prettier
2. Vscode icons (I love this one)
3. Code spell checker
4. ESLint
5. Error Lens
6. Live server
7. Auto rename tag
8. GitHub Copilot
9. Git lens
10. Figma for Vscode
What's your favourite?
Compromised renderer could call startDragging (mojo IPC) to control your mouse via ui::SendMouseEvent (Windows API), allowing clicks outside the browser basically anywhere.
#BugBounty : $50k
Nice Chrome bug. Credits to OG reporter
#bugbountytips
🔒 International law enforcement has dismantled infamous cybercrime hubs linked to platforms like Cracked, Nulled, StarkRDP and Sellix.
These platforms sold malware, hack tools, and personal data.
🔗 Read more about the "Operation Talent" — https://t.co/AWFBBJNYkP
🌐🚨 Global Takedown of Cybercrime Forums in “Operation Talent”
International law enforcement agencies, led by the FBI, have reportedly seized control of Nulled[.]to, Cracked[.]io, Starkrdp[.]io, Sellix[.]io, and Mysellix[.]io — key platforms in the cybercrime ecosystem. Dubbed “Operation Talent”, the action involved collaboration between authorities in the U.S., Italy, Spain, France, Australia, Romania, and others.
Key Details:
- Platforms Targeted: Forums linked to credential stuffing tools (e.g., OpenBullet), stolen database markets, and illicit RDP hosting services.
- Data Seized: Operational logs, customer/victim records, and transaction histories allegedly confiscated to trace threat actors.
- Technical Impact: Domains now resolve to FBI-controlled servers, displaying seizure banners.
Implications:
- Retaliation Risks: Retaliatory attacks against law enforcement or cooperating organizations may increase.
- Intelligence Value: Seized data may expose attacker tactics, credentials, and infrastructure used in global cybercrime campaigns.
#CyberCrime #LawEnforcement #ThreatIntelligence #GlobalOperation
Major Cybercrime Forums Seized by International Law Enforcement in “Operation Talent”
In the “Operation Talent” operation conducted by international law enforcement, the leading forums and marketplaces of the cybercrime ecosystem, Nulled(.)to, Sellix(.)io, Mysellix(.)io, Cracked(.)io and Starkrdp(.)io platforms were seized by law enforcement! As a result of the operation, the websites were shut down and customer and victim data from these platforms were reportedly seized by law enforcement.
The customer and victim data seized as part of the operation is a valuable source of intelligence for law enforcement and intelligence analysts. This data can help decipher the credentials of potential attackers and help plan similar future operations.
In the aftermath of “Operation Talent”, there may be targeted attack attempts, especially against law enforcement agencies or private sector organizations that cooperate in these operations. It is critical for cyber threat intelligence analysts to take intensive measures against retaliatory cyber attacks during this period.
More detailed information about the scope of the operation and its impact on the cybercrime ecosystem is expected to be shared in the coming days. It is of utmost importance for experts working in the field of cyber threat intelligence to closely follow these developments and take proactive measures against possible route changes of criminals.
#cti #threatintel #cybersec #fbi #nulled #cracked
Always remember to test the API for existence of addition headers.
X-Originaal-URL: /v1/api/endpoint_here
BOOM => Entire API routes disclosure.
Credit: @driccosec#bugbountytip#bugbounty#cybersecurity
🚨 Cybersecurity Alert: A new malware loader, MintsLoader, is wreaking havoc across critical industries like energy & legal sectors.
⚠️ Delivered via spam links → JScript file → MintsLoader
🔗 Read analysis of this attack chain: https://t.co/ip8gO5nnmU