tgindex
ThreatXEd Security

ThreatXEd Security

Статистика
@ThreatXSecurityанглийский

Welcome to ThreatXEd Security! At ThreatXEd , we don’t just hand you the solutions; we equip you with the skills to solve challenges on your own, for a lifetime. DM us on @threatx_support

Последний пост
8 авг.
Последнее чтение
14:23
Постов за неделю
0
Всего постов
38
Тип
открытый
Язык
английский
В каталоге с
13 авг.
Подписчики
1 457
+11 за 3 дн.
Сутки
+2
+0,14%
Неделя
 
Месяц
 
Просмотров на пост
403
37 постов
Вовлечённость
27,7%
к подписчикам
Постов в день
0,0
всего 38
Упоминаний
1
каналов
Охват размещения
оценка
1/24сутки в ленте
335
1/48двое суток
383
1/72трое суток
414

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • ‼️ CSS inside webmail can capture passwords and take over accounts. New research demos also show CSS/HTML attack paths across Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that can leak tokens, hijack UI actions, or lead to account takeover. See what email CSS can now do: https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html

  • ⚡ UPDATE - Coldcard-linked theft estimates have jumped from $70 million to $88.6 million. Galaxy Research says two more suspected sweep waves bring the total to 1,367.05 BTC across 4,585 addresses. The activity appears ongoing, and the third wave may involve a different operator. Read: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html

  • 🛑 Attackers hijacked Adform’s shared tracking script to swap crypto wallet addresses in users’ browsers. The code could rewrite addresses copied, pasted, or entered into forms while the page remained open. How the adtech supply-chain attack worked: https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • Congratulations to our Talent Center community members on graduating from the Ethiopian Artificial Intelligence Institute! Your hard work, dedication, and commitment have paid off. We are proud of your achievement and wish you continued success as you apply your knowledge and skills to make a positive impact. Congratulations, graduates! !

  • 1Password Partners with Anthropic to Give Claude Access to Your Credentials 1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values. Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself. Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies. @Cyber_Security_Channel

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • ThreatXEd Security pinned a photo

  • видео или голосовое, без подписи

  • Today marks a special milestone. Proud to announce that ThreatX has officially graduated from the AI startup center 2026 Startup Incubation Program organized by the Ethiopian Artificial Intelligence Institute. This journey has been filled with learning, challenges, innovation, and growth. Thank you to everyone who supported us along the way. This is not the finish line it’s the beginning of an even bigger journey. Here’s to building technology that creates real impact.

  • 🧩 ThreatXEd Friday Challenge: The Cookie That Trusted Itself You're testing a private portal. Logged in as a regular user, you check your cookies and find session_role, holding the value dXNlcg==. You decode it out of curiosity it just says "user". Here's the twist: there's no signature, no server-side lookup happening. The app appears to trust whatever value sits in that cookie directly, and uses it to decide what you're allowed to see. Your turn: 1️⃣ What class of vulnerability is this and why does encoding a value (instead of encrypting or signing it) fail to protect it? 2️⃣ What would you change in the cookie's value, and what would you expect to happen if the server truly has no additional validation? #FridayChallenge #ThreatXEd

  • 🛑 A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root access. On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit. Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

ThreatXEd Security — tgindex