■■■■□ Purple Operations Limited has released a new offensive cyber research report covering 3 side-channel attack vectors: – PJL/SNMP printer dead drops, – ultrasonic browser-to-receiver transfer, – and SNMP trap covert channels.
All posts by John Doe
July 19, 2026 at 11:39PM
🔴Yet another website: darknetlist.is
July 19, 2026 at 09:00PM
■■■■■ A researcher tested Kimi K3 and the results are positive for hacker community. An interesting thread: https://x.com/i/status/2078542913144054087
July 19, 2026 at 02:45PM
■■■■■ Samsung Kernel UAF (CVE-2026-20971) https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/
July 19, 2026 at 02:15PM
■■■□□ Japan: Cyberattack on Nichirei Disrupts Food Supply to All KFC Branches in Japan 🍔 Nichirei, a company that provides refrigerated and frozen storage, transportation, and distribution services for food products, has confirmed that attackers have successfully breached the company’s systems. As a result of the incident, the company has disconnected some of its systems,…
July 19, 2026 at 02:12PM
■■■■□ CVE-2026-9039 An EV charger’s charging port is a network port. Researchers found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage. https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
July 19, 2026 at 01:23PM
■■□□□ An interesting thread on surveillance AI software, open sourced! https://x.com/i/status/2078521434264265158 https://github.com/ShinMegamiBoson/OpenPlanter
July 19, 2026 at 03:52AM
■■■■□ Chinese Backdoor for Telecom Systems Backdoor that the Chinese have been using to maintain persistence across telecom systems. The backdoor attaches itself to a raw network socket and inspects incoming traffic. It sees packets before firewall rules have a chance to process them. So even if your firewall is configured correctly, the backdoor can…
July 19, 2026 at 12:52AM
✅CVE-2026-63030: Unauthenticated SQL injection in WordPress core chaining to RCE. No credentials, no configuration. One endpoint: POST /wp-json/batch/v1. The REST batch endpoint builds two parallel arrays ($matches and $validation) that fall out of step when a sub-request path fails wp_parse_url(). A sub-request gets dispatched under a different handler’s context. The PoC nests this route confusion…
July 18, 2026 at 10:02PM
■■■□□ 🇨🇳 China just torched the U.S. AI lead in a single afternoon. Moonshot AI, a little-known Beijing startup, dropped Kimi K3 on Thursday and it instantly kicked into the top tier of global models. It beat Anthropic’s Fable 5 and OpenAI’s GPT-5.6 Sol on coding tests, then edged out Opus 4.8 on a broader…
