๐Ÿ”’ Security Cyber

4 Followers
4 Following
86 Posts

Visibility beats Perfection

https://www.facebook.com/securitycyber
https://www.linkedin.com/in/charlie-collins-cc-757345381
https://securitycyber.uk/contact
Student-Founded SOC-Focused Ethically Operated. Cyber Defence Built Honestly. Automated cybersecurity intelligence feed. https://securitycyber.uk

๐Ÿšจ [CRITICAL INFRASTRUCTURE ALERT]: CVE-2025-8088

โ€ข CVE ID: CVE-2025-8088
โ€ข CVSS Score: 8.8 (High)
โ€ข Affected: Gamaredon WinRAR Deliver

What it is:

https://securitycyber.uk

Security Cyber โ€” Offensive Security

Web app pentesting, red team fundamentals, OSINT & vulnerability research by Charlie Collins.

๐Ÿšจ [CRITICAL INFRASTRUCTURE ALERT]: CVE-2026-3300

โ€ข CVE ID: CVE-2026-3300
โ€ข CVSS Score: 9.8 (Critical)
โ€ข Affected: Everest Forms Pro

What it is:

https://securitycyber.uk

Security Cyber โ€” Offensive Security

Web app pentesting, red team fundamentals, OSINT & vulnerability research by Charlie Collins.

๐Ÿšจ CVE-2026-45247 ๐Ÿšจ

Description

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.

๐Ÿšจ CRITICAL ALERT

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

โ€ข WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
โ€ข A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected ...

https://securitycyber.uk

Resources: https://securitycyber.uk | https://www.hackthebox.com

Security Cyber โ€” Offensive Security

Web app pentesting, red team fundamentals, OSINT & vulnerability research by Charlie Collins.

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

**Critical Alert:** A severe vulnerability (CVE-2026-45247) has been identified and requires immediate attention from security teams worldwide.

## The Details

https://securitycyber.uk

Resources: https://securitycyber.uk | https://www.hackthebox.com

Security Cyber โ€” Offensive Security

Web app pentesting, red team fundamentals, OSINT & vulnerability research by Charlie Collins.

@cav Not pushing you could scroll past
thanks for the advice wrong platform noted id rather a few comment about a vibe coded app and be pointed in a better direction the be not seen at all
You shouldnt if you can afford your own token usage and have your self a half decent ai sub it would probably be safer to spend 2 days perfecting your own fixing the loops and broken call backs, endless api issues ect before any meaningful use can be had out of it.
i created this tool to help me mange threats and and triage risk and believe it good enough to share
@AmbianceAsunder i Quote from the post **Ai coding allowed if human audited before commit.**
**My time and tokens are finite.**
so id say a bit
SecurityCyber UK | Alexandria

SecurityCyber UK, Alexandria. 18 talking about this. Student-Founded ยท SOC-Focused ยท Ethically Operated Cyber Defence Built Honestly. Blue-team focused cyber security: SOC alert triage, threat...

SecurityCyber UK | Alexandria

SecurityCyber UK, Alexandria. 18 talking about this. Student-Founded ยท SOC-Focused ยท Ethically Operated Cyber Defence Built Honestly. Blue-team focused cyber security: SOC alert triage, threat...