최근 ZeroPath Research를 통해 ProFTPD의 특정 모듈(mod_sql)에서 발생하는 심각한 보안 취약점(CVE-2026-42167)이 공개되었습니다.
이 취약점은 인증 우회는 물론, 특정 조건에서 서버의 제어권을 완전히 탈취할 수 있는 위험성을 내포하고 있습니다.
https://t.co/DHQA7HbiIP
Bug Bounty Full Course: Recon, Dorking, XSS/LFI, CORS & Open Redirect on Live Targets | YesWeHack
✅ Subdomain Recon
✅ Google Dorking
✅ XSS & LFI
✅ CORS Misconfiguration
✅ Open Redirect Mass Hunt
Perfect for beginners👇
https://t.co/1AUJ6O0W76
현재 GPT 5.5 Pro 코딩 성능 근황
Codex 도 아닌 일반 GPT 5.5 Pro 대화 10번만으로 마인크래프트 비슷한 카피 게임을 만들어버림
만든 사람은 잘 하면 3번만으로도 될거같다고 함.
정말 충격적인건 코딩 전용인 Codex가 아니고 '일반 대화' 창에서 만든거라는 것임.
Attackers are exploiting CVE-2024-3721 in TBK DVRs to deploy Mirai variant Nexcorium.
It spreads via old exploits and default creds, persists on devices, and launches DDoS attacks. EoL TP-Link routers are also being targeted via known flaws.
🔗 Read → https://t.co/gApGzKzd6V
HORMUZ UPDATE:
Iran has now turned back 20 vessels attempting to cross the Strait of Hormuz today and the US "blockade" has turned back a total of 23 vessels.
It appears we are now entering a complete shutdown of the Strait of Hormuz.
Prior to the US blockade, vessels from Iran and Iran's allies were permitted to sail through the Strait of Hormuz.
Now, under the US "blockade," the US is prohibiting vessels from accessing Iran's ports and coast.
We may be seeing the first ever complete shutdown of Hormuz.
More details to come shortly.
⚠️ Researchers uncovered PowMix Botnet, active since Dec 2025.
Randomized C2 beaconing and phishing ZIP → LNK → PowerShell chains enable in-memory control and persistence.
RondoDox separately exploits 170+ flaws for DDoS and crypto mining.
🔗Read → https://t.co/JA2t5bNfBz
A fully local 26B MoE model was built for red teaming and bug hunting.
Trained on elite bug reports and real evasion tactics. DPO fine-tuned for hunter mindset.
Claude sees your payloads in logs; that's why BugTraceAI Apex 26B local MoE for real red teamers.
- executes WAF bypasses with internal thinking blocks.
- It enforces deep internal reasoning before generating any output.
- Delivers production-grade WAF/EDR evasion with AES-256-GCM obfuscation.
- Zero refusals, Trained on real-world elite reports and evasion techniques.
Fits in 16.7GB. Runs on RTX 3060.
- https://t.co/FfnGgGXoQy
⚠️ ALERT - CPUID’s site was compromised for ~19 hours, serving trojanized CPU-Z and HWMonitor installers.
Attackers used DLL sideloading to pair legit apps with a malicious file, deploying STX RAT.
150+ victims reported before detection.
🔗 Read → https://t.co/3Oshrvbawo
⚠️ A compromised AI library exposed developer machines.
1,705 packages pulled infected LiteLLM versions, harvesting SSH keys and cloud creds from local systems via dependencies.
It worked because secrets sit in plaintext across files and tools.
🔗 How one dependency exposed thousands of environments → https://t.co/OKB9Rgfsiw
Introducing Claude Code Security, now in limited research preview.
It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss.
Learn more: https://t.co/n4SZ9EIklG