All Posts

CVE-2026-15748

Critical WordPress Alert: Dissecting CVE-2026-15748 (Forminator RCE) & CVE-2026-15826 (UPB Auth Bypass)

The CyberSec Guru

CVE-2026-15748 enables critical Forminator RCE, while CVE-2026-15826 allows User Profile Builder authentication bypass. Learn how to detect and patch both

CVE-2026-19478

Critical GitLab GraphQL Vulnerability CVE-2026-19478: Patch Now to Prevent Unauthenticated Project Modification

The CyberSec Guru

GitLab patched critical CVE-2026-19478, a CVSS 9.4 GraphQL flaw allowing unauthenticated attackers to modify or delete public projects

Github Down

GitHub Suffers Widespread Service Disruption, API Errors Reach 20% as Webhooks, Actions and Pull Requests Degrade

The CyberSec Guru

GitHub is experiencing widespread service disruption affecting APIs, Actions, Webhooks, Pull Requests, Copilot, authentication and repository downloads

Hack The Box (HTB) Attack Paths

Hack The Box Attack Paths: The Complete Easy to Insane Methodology Guide

The CyberSec Guru

Master Hack The Box attack paths with this complete guide to Easy, Medium, Hard and Insane Linux and Windows machines, from enumeration to root

VMware vCenter CVE-2026-59310

The Anatomy of the VMware vCenter Syslog Exploitation and the Babuk ESXi Ransomware Campaign

The CyberSec Guru

VMware vCenter CVE-2026-59310 is being actively exploited to compromise vCenter servers and deploy Babuk-derived ransomware on ESXi hosts

Azure data exfiltration

The Identity Perimeter is Broken: Inside the Azure Exfiltration Campaign Targeting Global Enterprises

The CyberSec Guru

A major Azure data exfiltration campaign allegedly exposed millions of employee records from global enterprises. Here's every affected organization

A Brand-New Account, a “0-Day,” and a JPEG: Assessing the Alleged Discord Steganography Bypass

The CyberSec Guru

A new alleged Discord “0-day” claims JPEG steganography can bypass content scanning. We examine the claim, LSB hiding, JPEG payloads, and what actually happens

SafePal data breach

The Wallet Is Safe. The Customer List Wasn’t: Inside SafePal’s Order-Tracking Breach

The CyberSec Guru

SafePal's 2026 data breach exposed 39,798 customers. Here's what was leaked, how the order-tracking flaw worked, and whether your crypto is actually at risk

file transfer cheatsheet

File Transfer Cheat Sheet: The Practical Hacking Cheatsheet Series

The CyberSec Guru

Master file transfers in HTB with this practical cheat sheet covering Linux, Windows, Netcat, SMB, SCP, PowerShell, Base64, HTTP, SSH, Chisel and Ligolo-ng

Brave 1.93 GPU fingerprinting

The GPU Serial Number: How Brave Is Fighting the Next Generation of Web Tracking

The CyberSec Guru

Your GPU can help websites recognize your device. See how Brave 1.93 uses farbling to hide WebGL and WebGPU identifiers and disrupt fingerprint tracking