DEV Community

Security Cyber profile picture

Security Cyber

Student-Founded · SOC-Focused · Ethically Operated Cyber Defence Built Honestly. Blue-team focused cyber security: SOC alert triage, threat detection, log analysis, incident response, OSINT, and web

Location Balloch Scotland Joined Joined on  Personal website https://securitcyber.uk twitter website
Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

Comments
2 min read

Want to connect with Security Cyber?

Create an account to connect with Security Cyber. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Comments
3 min read
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Comments
2 min read
Ransomware Operators Keep Business Hours. The Data Proves It

Ransomware Operators Keep Business Hours. The Data Proves It

Comments
2 min read
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password

CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password

Comments
1 min read
CIFSwitch, a Linux Root Bug Hidden in Plain Sight for 19 Years

CIFSwitch, a Linux Root Bug Hidden in Plain Sight for 19 Years

Comments
1 min read
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 99

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 99

Comments
2 min read
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 99

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 99

Comments
1 min read
CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers

CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers

Comments
2 min read
<![CDATA[Friday Squid Blogging: Another Squid]]>

<![CDATA[Friday Squid Blogging: Another Squid]]>

Comments
1 min read
VRP 2025 Year in Review: Google's Bug Bounty Program Hits Major Milestones

VRP 2025 Year in Review: Google's Bug Bounty Program Hits Major Milestones

Comments
2 min read
Google Workspace's Continuous Approach to Mitigating Indirect Prompt Injections

Google Workspace's Continuous Approach to Mitigating Indirect Prompt Injections

Comments
4 min read
🔒 Protecting Cookies with Device Bound Session Credentials

🔒 Protecting Cookies with Device Bound Session Credentials

Comments
1 min read
Bringing Rust to the Pixel Baseband

Bringing Rust to the Pixel Baseband

Comments
1 min read
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Comments
2 min read
The Compliance Floor: Why Certifications Are Not Enough Security Cyber

The Compliance Floor: Why Certifications Are Not Enough Security Cyber

Comments
3 min read
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Comments
2 min read
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Comments
2 min read
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Comments
3 min read
The Zero Day Lie

The Zero Day Lie

Comments
3 min read
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Comments
1 min read
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Comments
2 min read
The Zero Day Lie

The Zero Day Lie

Comments
3 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
The World Cup Is the Greatest Phishing Engine Ever Built

The World Cup Is the Greatest Phishing Engine Ever Built

Comments
3 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
The World Cup Is the Greatest Phishing Engine Ever Built

The World Cup Is the Greatest Phishing Engine Ever Built

Comments
3 min read
The World Cup Is the Greatest Phishing Engine Ever Built

The World Cup Is the Greatest Phishing Engine Ever Built

Comments
3 min read
The Compliance Trap: Why Your Certificates Won't Stop a Breach

The Compliance Trap: Why Your Certificates Won't Stop a Breach

Comments
3 min read
The Compliance Trap

The Compliance Trap

Comments
5 min read
CVE Alert: Check Your Systems

CVE Alert: Check Your Systems

Comments
1 min read
The Zero-Day Lie

The Zero-Day Lie

Comments
3 min read
Chrome 148 Update Patches 151 Vulnerabilities: What Security Teams Need to Know

Chrome 148 Update Patches 151 Vulnerabilities: What Security Teams Need to Know

Comments
1 min read
Gogs Zero-Day Exposes Servers to Remote Code Execution: What Security Teams Need to Know

Gogs Zero-Day Exposes Servers to Remote Code Execution: What Security Teams Need to Know

Comments
1 min read
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty: What Security Teams Need to Know

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty: What Security Teams Need to Know

Comments
1 min read
Anti-DDoS Firm Heaped Attacks on Brazilian ISPs: What Security Teams Need to Know

Anti-DDoS Firm Heaped Attacks on Brazilian ISPs: What Security Teams Need to Know

Comments
1 min read
Canvas Breach Disrupts Schools & Colleges Nationwide: What Security Teams Need to Know

Canvas Breach Disrupts Schools & Colleges Nationwide: What Security Teams Need to Know

Comments
1 min read
Patch Tuesday, May 2026 Edition: What Security Teams Need to Know

Patch Tuesday, May 2026 Edition: What Security Teams Need to Know

Comments
1 min read
Lawmakers Demand Answers as CISA Tries to Contain Data Leak: What Security Teams Need to Know

Lawmakers Demand Answers as CISA Tries to Contain Data Leak: What Security Teams Need to Know

Comments
1 min read
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks: What Security Teams Need to Know

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks: What Security Teams Need to Know

Comments
1 min read
New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power use: What Security Teams Need to Know

New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power use: What Security Teams Need to Know

Comments
1 min read
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More: What Security Teams Need to Know

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More: What Security Teams Need to Know

Comments
1 min read
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer: What Security Teams Need to Know

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer: What Security Teams Need to Know

Comments
1 min read
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code: What Security Teams Need to Know

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code: What Security Teams Need to Know

Comments
1 min read
Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels: What Security Teams Need to Know

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels: What Security Teams Need to Know

Comments
1 min read
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks: What Security Teams Need to Know

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks: What Security Teams Need to Know

Comments
1 min read
Starting Security Cyber: A New Voice in Cybersecurity

Starting Security Cyber: A New Voice in Cybersecurity

Comments
1 min read
loading...