🔒 Public and Private Medical Community Targeted by China-Nexus Threat Actor Pur...

📝 Written by: Patrick Whitsell, John McGuiness Google Threat Intellig...

https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research/

📰 Threat Intelligence

#Pentesting #InfoSec

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research | Google Cloud Blog

UNC6508 leveraged Google Workspace compliance rules and REDCap vulnerabilities for intelligence collection.

Google Cloud Blog
Enterprise SSO with SAML: one XML signature wrapping attack = access to every app in scope. This week I broke down XSW variants, void canonicalization bypass, NameID comment injection, and attribute-based escalation. Five quick checks that cover most real-world SAML bugs, all automatable with SAMLRaider. https://www.kayssel.com/newsletter/issue-54/
#InfoSec #CyberSecurity #Pentesting #BugBounty #OffSec #SAMl #SSo
SAML SSO Exploitation: Breaking the Trust Chain

XML signature wrapping variants, void canonicalization bypass, NameID comment injection, SAML attribute injection, and token replay against enterprise SSO

Kayssel
Owned Callfuscated from Hack The Box!

I have just owned challenge Callfuscated from Hack The Box

Owned Bobby's Bistro from Hack The Box!

I have just owned challenge Bobby's Bistro from Hack The Box

Owned Sattrack from Hack The Box!

I have just owned challenge Sattrack from Hack The Box

260611 rootshell.online

YouTube

I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.

Hack Hub is a curated directory of useful security resources.

https://hackhub.fyi

#CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech

Hack Hub

Discover curated cybersecurity resources, tools, blogs, platforms and technical references.

Hack Hub

🔑 GitHub pulls pin on npm's auto-run scripts

📝 GitHub will change npm's defaults so the install command no longer runs scripts automa...

https://www.theregister.com/devops/2026/06/10/github-pulls-pin-on-npms-auto-run-scripts/5253453

📰 www.theregister.com - Articles

#DevSecOps #Pentesting

GitHub pulls pin on npm's auto-run scripts

Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors

theregister
Owned Espresso from Hack The Box!

I have just owned challenge Espresso from Hack The Box