Hacking  H | EXPLOIT | GHDB |    2026()  2025()  2024()  2023() | HACKING CATEGORY
HOME  Reconnaissance(10)  Resource Development(8)  Initial Access(10)  Execution(14)  Persistence(20)  Privilege Escalation(14)  Defense Evasion(43)  Credential Access(17)  Discovery(32)  Lateral Movement(9)  Collection(17)  Command and Control(17)  Exfiltration(9)  Impact(14) | TOOL

DATE

NAME

INFO

CATEGORY

SUBCATE

25.9.26

Vshell Vshell: A Chinese-Language Alternative to Cobalt Strike HACKING HACKING

21.9.26

LLMShare LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms HACKING AI

17.9.26

BragJack

BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants

HACKING

AI

6.9.26

StyleSmuggler StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack HACKING HACKING

4.9.26

ASCII smuggling ASCII smuggling crosses over from AI prompt injection to phishing evasion HACKING AI
28.8.26 Drive-By Agent Hijacking Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning HACKING AI
28.8.26 Power Leak Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration HACKING AI
25.8.26 Early Cascade Injection: From Windows Process Creation to Stealthy Injection In this blog post we introduce a novel process injection technique named Early Cascade Injection, explore Windows process creation, and identify how several Endpoint Detection and Response systems (EDRs) initialize their in-process detection capabilities. HACKING WINDOWS
25.8.26 EarlyBird Technique: An Advanced Malware Evasion Strategy As of recent advancements, malware authors are leveraging artificial intelligence (AI) and machine learning (ML) to dynamically alter their evasion techniques. This means that malware can now adapt in real-time to changes in security environments, such as modifications in antivirus software or intrusion detection systems, making traditional static signature-based defences increasingly ineffective. HACKING MALWARE
24.8.26 Heaven's Gate Heaven’s Gate is a malware technique that hides dangerous 64-bit code inside seemingly harmless 32-bit processes. This clever trick makes it much harder for security tools to catch malware in action, giving attackers a major advantage in the cyber cat-and-mouse game HACKING MALWARE

20.8.26

Cryptographic Payload Injection Cryptographic Payload Injection: A Novel Jailbreak Technique Against Gemini HACKING AI

20.8.26

Zombie Credit Cards Attack When Zombie Credit Cards Attack: UMass Researchers Discover Loophole That Can Reanimate Expired Cards HACKING HACKING

20.8.26

XRING XRING: Crashing XQUIC with spec-compliant QPACK instructions HACKING HACKING

31.7.26

ClickFix, EtherHiding & a DPRK Wallet Trail A fake macOS "update" screen convinced a victim to paste one command into Terminal, installing a Node.js backdoor that takes its orders from an Ethereum smart contract. We reverse-engineered every stage, then followed the money on-chain. HACKING HACKING

27.7.26

DNS Poisoning Tactics DNS Poisoning Tactics Expand to Hospitality Wi-Fi HACKING HACKING

26.7.26

Slopsquatting Slopsquatting is a type of cybersquatting. It is the practice of registering a non-existent software package name that a large language model (LLM) may hallucinate in its output, whereby someone unknowingly may copy-paste and install the software package without realizing it is fake. Attempting to install a non-existent package should result in an error, but some have exploited this for their gain in the form of typosquatting HACKING Cybersquatting
14.7.26 ClaudeBleed Reopened Eight Claude for Chrome releases later, the bypass is still six lines of JavaScript. We reported it to Anthropic in May. The code is unchanged in the latest version. HACKING AI
11.7.26 Bypassing Tangem Card Security with a Laser Attack After uncovering a genuine check bypass on the Tangem Android application and a brute-force attack on the card's authentication protocol, the Ledger Donjon turned its attention to the card itself with more advanced tools and sophisticated techniques. What we found is a critical vulnerability that lets an attacker with physical access to a single Tangem card reset its password and steal all associated funds. HACKING CARD
11.7.26 Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys attackers used access to a trusted developer's account to slip a backdoor into a widely used software development kit for the Injective blockchain. Disguised as harmless analytics, the code quietly captured wallet recovery phrases and private keys and sent them to an attacker-controlled server the moment a wallet was created or loaded. HACKING CRYPTOCURRENCY
6.7.26 Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-judge analysis, but it remains unclear whether they withstand adaptive evasions that preserve malicious behavior while changing payload appearance. HACKING AI MALWARE
1.7.26 Phantom Squatting Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector HACKING AI
1.7.26 ClickFix: The Gift That Keeps On Giving In the beginning of June I presented the session ClickFix: The Gift That Keeps On Giving at OrangeCon. ClickFix emerged around 2024 and saw a 517% increase in 2025 as described by SANS, the effectiveness of this technique is something we will have to deal with for the upcoming years. HACKING ClickFix
30.6.26 GuardFall GuardFall: a universal shell injection vulnerability in open-source AI agents HACKING AI
30.6.26 BioShocking AI BioShocking AI: “Gaming” the AI Browser and Escaping its Guardrails HACKING AI
21.6.26 SearchLeak SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon HACKING M365 COPILOT
17.6.26 Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE HACKING HACKING
11.6.26 NPM Ignore Scripts Best NPM Ignore Scripts Best Practices as Security Mitigation for Malicious Packages HACKING HACKING
6.6.26 TanStack Supply Chain Attack On 11 May 2026, the threat actor group TeamPCP compromised 42 TanStack npm packages by chaining three GitHub Actions vulnerabilities to hijack the project's legitimate CI/CD pipeline. The attackers then published 84 malicious package versions carrying valid SLSA Build Level 3 provenance attestations, making them indistinguishable from legitimate releases by standard verification methods. HACKING HACKING
3.6.26 FlagLeft FlagLeft: We Found A Forgotten Flag That Turned Microsoft 365 Apps Into a Silent Account Takeover Pipeline for Billions of Users HACKING HACKING
3.6.26 1-Click GitHub Token Stealing via a VSCode Bug Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones. HACKING HACKING
31.5.26 LLMShare LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms HACKING AI
30.5.26 SymJack SymJack: the approval prompt is lying to you. A symlink-hijack RCE in six AI coding agents HACKING AI
30.5.26 TrustFall TrustFall: coding agent security flaw enables one-click RCE in Claude, Cursor, Gemini CLI and GitHub Copilot HACKING AI
20.5.26 Trapdoor funnels malvertising into ad fraud HUMAN’s Satori Threat Intelligence and Research Team has identified and has disrupted an ad fraud and malvertising operation dubbed Trapdoor. The operation encompasses 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains that together form a multi-stage fraud pipeline HACKING HACKING
9.5.26 CallPhantom tricks Fake call logs, real payments: How CallPhantom tricks Android users HACKING HACKING
25.4.26 PhantomRPC PhantomRPC: A new privilege escalation technique in Windows RPC HACKING HACKING
24.4.26 AdaptixC2 AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks HACKING TOOLS
23.4.26 Checkmarx KICS images Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions HACKING HACKING
8.4.26 Python-Based Backdoor and Changes in Distribution Techniques Malicious LNK Files Distributing a Python-Based Backdoor and Changes in Distribution Techniques (Kimsuky Group) HACKING MALWARE
8.4.26 Handala Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment HACKING MALWARE
8.4.26 Qilin EDR killer infection chain Endpoint detection and response (EDR) tools are widely deployed and far more capable than traditional antivirus. As a result, attackers use EDR killers to disable or bypass them. HACKING RANSOMWARE
8.4.26 DPRK Malware Modularity DPRK Malware Modularity: Diversity and Functional Specialization HACKING MALWARE
5.4.26 RoadK1ll RoadK1ll: A WebSocket Based Pivoting Implant HACKING HACKING
5.4.26 Cookie-controlled PHP webshells Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments HACKING HACKING
26.3.26 Poisoned Typeface Poisoned Typeface: How Simple Font Rendering Poisons Every AI Assistant, And Only Microsoft Cares

HACKING

AI

26.3.26 WebRTC skimmer bypasses Sansec discovered a payment skimmer that uses WebRTC DataChannels to receive its payload and exfiltrate stolen data, bypassing CSP and HTTP-based security tools. HACKING HACKING
26.3.26 ShadowPrompt ShadowPrompt: How Any Website Could Have Hijacked Claude's Chrome Extension HACKING AI

25.3.26

Microsoft 365 Token Attack Infrastructure Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure HACKING HACKING

25.3.26

HwAudKiller

From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill

HACKING

TOOL

25.3.26

Supply Chain Attack in litellm 1.82.8 on PyPI

A compromised release steals credentials and spreads to Kubernetes clusters. First reported to PyPI by FutureSearch.

HACKING

HACKING

20.3.26 The technology behind EDR killers ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers HACKING EDR
16.3.26 Evil evolution Across three recent campaigns, Sophos X-Ops notes shifts in both lures and malware capabilities, as threat actors leveraging ClickFix techniques increasingly target macOS users with infostealers HACKING HACKING
10.3.26 GhostClaw GhostClaw Unmasked: A Malicious npm Package Impersonating OpenClaw to Steal Everything HACKING MALWARE
9.3.26 Pixel Perfect Pixel Perfect: Sold Extension Injects Code Through Pixel HACKING HACKING
1.3.26 Log Poisoning in OpenClaw It is important to be clear here: this is not a traditional remote code execution vulnerability. Instead, its an indirect prompt injection risk, where exploitation depends on context. HACKING AI
20.2.26 AgreeToSteal AgreeToSteal: The First Malicious Outlook Add-In Leads to 4,000 Stolen Credentials HACKING HACKING
11.2.26 LABYRINTH CHOLLIMA LABYRINTH CHOLLIMA Evolves into Three Adversaries HACKING CLUSTER
9.2.26 TeamPCP Threat Alert: TeamPCP, An Emerging Force in the Cloud Native and Ransomware Landscape HACKING CLUSTER
9.2.26 Vortex Werewolf (SkyCloak) A new cluster is distributing malware via phishing. We demonstrate how the attack works through fake pages simulating file downloads from Telegram. HACKING CLUSTER
6.2.26 DKnife Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework HACKING HACKING
18.1.26 WhisperPair Hijacking Bluetooth Accessories Using Google Fast Pair HACKING Bluetooth
16.1.26 Reprompt Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data HACKING AI
7.1.26 Prompt poaching Prompt poaching runs rampant in extensions HACKING AI
3.1.26 MongoDB Unauthenticated Attacker Sensitive Memory Leak The Situation: A major vulnerability allows unauthenticated attackers to remotely leak sensitive data from MongoDB server memory. No login is required. HACKING HACKING