
YoKo Kho
60K posts

YoKo Kho
@YoKoAcc
Independent | Top 60 Bugcrowd | OSCP, CRTO, eWPTX, eCPTX | https://t.co/VA42ZpFqGJ | https://t.co/yHuJFexKd1 (Bahasa Indonesia) Free!








Do you know Windows keeps a record of programs you ran, even after you delete them? Attackers forget this. Forensic analysts don’t.




This is bad. Putty level bad. notepad-plus-plus.org/news/hijacked-…



Windows keeps a permanent record of every USB device you’ve ever plugged in even after it’s removed.







MongoBleed (CVE-2025-14847) is basically Heartbleed for MongoDB - unauthenticated memory disclosure - public POC, trivial to exploit - leaks creds, tokens, cloud keys straight from RAM - huge exposed surface on the internet Good writeups and technical details here: doublepulsar.com/merry-christma… ox.security/blog/attackers… blog.ecapuano.com/p/hunting-mong… Patch fast, rotate secrets, and assume exposed instances were scanned(!)






🚨North Korean threat actors are hiding malware in JSON storage services during fake developer interviews. With 400+ suspected victims, this campaign is actively targeting developers. Full analysis on our blog: blog.nviso.eu/2025/11/13/con…


















