πŸ‘οΈ8,960
GitHubLinkedIn
Cybersecurity and Techβ€’β€’6 min readβ€’1014 words

πŸš€ Security - Vulnerability Disclosure

πŸ‘οΈ0reads (human + AI)πŸ€–0AI ingestions
⚑Direct Technical Summary

Vulnerability disclosure is a critical aspect of cybersecurity, and recent events have highlighted the importance of responsible disclosure. This article summarizes key points from

πŸš€ Security - Vulnerability Disclosure

Vulnerability disclosure is a critical aspect of cybersecurity, and recent events have highlighted the importance of responsible disclosure. This article summarizes key points from recent Twitter threads on vulnerability disclosure.

Key Points:
β€’ Vulnerability disclosure is a complex issue, with various stakeholders having different opinions on the best approach.
β€’ The lack of transparency in vulnerability disclosure can lead to delayed patching and increased risk for organizations.
β€’ Responsible disclosure is essential to ensure that vulnerabilities are addressed in a timely manner.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’ Vulnerability Disclosure β†— - Brief description


πŸš€ Security - Recent Attacks

Recent attacks have targeted US and EU organizations, highlighting the need for robust security measures. This article summarizes key points from recent Twitter threads on recent attacks.

Key Points:
β€’ Recent attacks have targeted trusted business systems and workflows, highlighting the need for increased security measures.
β€’ Attackers have used various tactics, including M365 session hijacking and remote-control malware.
β€’ Close the gaps these attacks exposed to prevent future breaches.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’ Anyrun App β†— - Brief description


πŸš€ Security - Cyber Risks in Fashion

Cyber risks are a growing concern for fashion and luxury brands. This article summarizes key points from a recent Twitter thread on cyber risks in fashion.

Key Points:
β€’ Fashion execs are concerned about cyber risks, but not always the next collection.
β€’ Join Justine Phillips, Sandra Joyce & Amy Melican for a look at the cyber risks targeting fashion & luxury brands.
β€’ Register today: https:// goo.gle/4cnsqPA

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’

Image

Image


β€’ Google Cloud Security β†— - Brief description


πŸš€ Security - Industry Criticism

Industry criticism is a growing concern, with some critics accusing labs of pulling punches publicly. This article summarizes key points from a recent Twitter thread on industry criticism.

Key Points:
β€’ The sad thing about the space right now is watching people pull punches publicly because they hope to land a job at one of the labs.
β€’ Same with companies playing nice with labs hoping to catch the PR wave.
β€’ This behavior can lead to a lack of transparency and accountability in the industry.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’ HackingLZ β†— - Brief description


πŸš€ Security - Malware Campaigns

Malware campaigns are a growing concern, with various types of malware being used to target organizations. This article summarizes key points from a recent Twitter thread on malware campaigns.

Key Points:
β€’ A csv formatted list of #malspam campaigns that crossed my path in August to include subject, #malware type, c2, hash, and email exfil addresses.
β€’ The list highlights the diversity of malware campaigns and the need for robust security measures.
β€’ The list can be found here: https:// gist.github.com/silence-is-bes t/df9627fac2f23aaa0a17cd7ff3cb71f8 …

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’

Image

Image


β€’
Image

Image


β€’ James_inthe_box β†— - Brief description


πŸš€ Security - Unpatched Microsoft Exchange Servers

Unpatched Microsoft Exchange servers are a growing concern, with nearly 22,000 servers exposed online. This article summarizes key points from a recent Twitter thread on unpatched Microsoft Exchange servers.

Key Points:
β€’ Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability.
β€’ The vulnerability allows attackers to hijack all user mailboxes.
β€’ Organizations must patch their servers immediately to prevent breaches.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’ BleepinComputer β†— - Brief description


πŸš€ Security - ICS/Ot Coverage

ICS/Ot coverage is a growing concern, with various technologies being targeted by attackers. This article summarizes key points from a recent Twitter thread on ICS/Ot coverage.

Key Points:
β€’ we’ve significantly expanded ics / ot coverage at infrawatch.
β€’ 500+ technologies across water, rail, solar, manufacturing, agriculture and other industrial systems.
β€’ if it’s exposed to the public internet, we want to know what it is, where it is, and when it changes.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’

Image

Image


β€’ LloydLabs β†— - Brief description


πŸš€ Security - CVE-2026-9586

CVE-2026-9586 is a SQLi-to-RCE vulnerability in #Sangoma #Switchvox. This article summarizes key points from a recent Twitter thread on CVE-2026-9586.

Key Points:
β€’ Today we are disclosing the technical details of CVE-2026-9586, a SQLi-to-RCE in #Sangoma #Switchvox.
β€’ On 30 Aug 2026, we received honeypot alerts of valid exploitation attempts across multiple internet sensors deployed in coordination with
β€’ The vulnerability was reported in April 2026.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’ Horizon3Attack β†— - Brief description


πŸš€ Security - ENDLESSDOORS Implant

The ENDLESSDOORS implant is a growing concern, with various devices being targeted by attackers. This article summarizes key points from a recent Twitter thread on the ENDLESSDOORS implant.

Key Points:
β€’ We bought an $88 router on Amazon looking for the ENDLESSDOORS implant.
β€’ We found two others instead DARKLANTERN gives anyone on the Internet an unauthenticated root shell.
β€’ SPEAKINGSTONE phones home to ZBT infrastructure and supports remote surveillance.

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’

Image

Image


β€’ craiu β†— - Brief description


πŸš€ Security - Compromised VPN Credentials

Compromised VPN credentials are a growing concern, with various devices being targeted by attackers. This article summarizes key points from a recent Twitter thread on compromised VPN credentials.

Key Points:
β€’ "The server contained a ZIP file called sonic_scan.zip, in which a Python script and a file, data.txt, with potentially compromised VPN credentials were present."
β€’ Read the full report: https:// buff.ly/gqcQEdG
β€’ #DFIR #ThreatIntel

πŸ”— Resources:

β€’ Original post URL β†— - Original source
β€’

Image

Image


β€’ TheDFIRReport β†— - Brief description

πŸ“‚Source / Implementation:Cybersecurity and Tech / resources-200.md
GitHub Repository↗

Related Cybersecurity and Tech Breakdowns

Drishtant Ghosh (Drix10)
Drishtant Ghosh (Drix10)β€’Author & Engineer

Technical founder and engineer working across AI systems, developer infrastructure, and cybersecurity.