置顶推文
Abdulmuiz| Cybersecurity
442 posts

Abdulmuiz| Cybersecurity
@MuizRecon
Web Application Security | API Security | Security Researcher| SOC & Detection Foundation
Lagos 加入时间 Nisan 2025
234 关注274 粉丝
Abdulmuiz| Cybersecurity 已转推

🚨 Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code
Source: cybersecuritynews.com/microsoft-edge…
Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems.
An attacker who can trick a user into opening a malicious file or visiting a crafted page could exploit this flaw alongside other bugs to run code in the logged-in user's context.
📌 CVE-2026-45495 (CVSS 7.5): This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge
📌 CVE-2026-45494 (CVSS 5.0): A navigation-handling weakness that can enable cross-origin script injection; user interaction required.
📌 CVE-2026-45492 (CVSS 4.3): Insufficient origin validation in cross-device managed sign-in, which can expose restricted functionality and be chained with other issues.
#cybersecuritynews #MicrosoftEdge

English
Abdulmuiz| Cybersecurity 已转推

‼️🚨 A new npm supply-chain attack compromised 57 packages across over 286 malicious versions in under 2 hours. The attackers used self-replicating malware, a new version of the Miasma worm, which also used evasion techniques to stay under the radar.
The payload targets CI/CD and developer credentials, including GitHub Actions secrets, cloud credentials, Vault tokens, SSH keys, npm and GitHub tokens, and password-manager stores. This variant also injects AI coding assistant config files at `.claude`, `.cursor`, `.gemini`, and `.vscode` paths, a separate persistence and repo-poisoning angle.


English

@TheHackersNews This is why API keys and cloud credentials are now the real perimeter. Once they’re stolen, the attacker becomes a trusted user.
English

🚨 Hackers turned hijacked cloud servers into a hidden email-sending network.
AWS. Google Cloud. Azure.
PCPJack tested which hosts could send mail, kept the working ones, and synced the proxy list every 5 minutes. What they planned to use it for is still unknown.
The setup was still live when found.
Learn more: thehackernews.com/2026/06/pcpjac…

English

🚨 AWS, Azure, and Google Cloud servers are being compromised and turned into SMTP and SOCKS5 proxy networks 😳😱 It’s no longer just data theft.
Attackers are using stolen cloud accounts to quietly build hidden infrastructure.
Your cloud is now the weapon !🗡️
The Hacker News@TheHackersNews
🚨 Hackers turned hijacked cloud servers into a hidden email-sending network. AWS. Google Cloud. Azure. PCPJack tested which hosts could send mail, kept the working ones, and synced the proxy list every 5 minutes. What they planned to use it for is still unknown. The setup was still live when found. Learn more: thehackernews.com/2026/06/pcpjac…
English

Honestly, I’ve come to realize the gap between school and industry shocked me a bit. I’ve learned more from asking questions than just trying to sound smart, and turns out curiosity is really what you need.
Abdulmuiz| Cybersecurity@MuizRecon
Okay, let me just say it: I've been interning at one of Africa's biggest conglomerates, and I still can't fully process it, ngl.
English

@gabbytech01 True, it is not only lack of skills, but also lack of direction. That gap is costing people a lot.
English

Check out my latest article: How Modern APIs Expanded the Web Application Attack Surface and What Security Teams Are Missing linkedin.com/pulse/how-mode… via @LinkedIn
English

After battling for my life with X support, @MuizRecon is finally free again. 😭😭Got a new month gift too. We move.

English
Abdulmuiz| Cybersecurity 已转推
Abdulmuiz| Cybersecurity 已转推









