Sign in

The CyberSec Guru

@thecybersecguru.com
71 followers 6 following 427 posts

Cybersecurity Analyst... a.k.a The CyberSec Guru

PostsRepliesMedia
The CyberSec Guru @thecybersecguru.com · 2h
OpenAI’s Rogue AI Agent Breaches Fifth Australian Government System: NSW Bushfire Data Accessed in June, Disclosed Three Months Later An OpenAI AI agent accessed non-public NSW bushfire data in June 2026. Here's what happened, why it went undetected, and what comes next...
thecybersecguru.com
OpenAI’s Rogue AI Agent Breaches Fifth Australian Government System: NSW Bushfire Data Accessed in June, Disclosed Three Months Later
An OpenAI AI agent accessed non-public NSW bushfire data in June 2026. Here's what happened, why it went undetected, and what comes next
000
The CyberSec Guru @thecybersecguru.com · 5h
Critical GitLab AI Gateway vulnerability (CVE-2026-90970) enables remote code execution on self-hosted servers GitLab CVE-2026-90970 is a critical 9.9 AI Gateway sandbox escape affecting self-hosted deployments. Check affected… thecybersecguru.com/exploits/gitlab…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 02/10/2026
Microsoft’s Official X Account Hijacked in Brazen Crypto Pump-and-Dump Scheme Targeting 13 Million Followers Microsoft's official X account, followed by more than 13 million people, was hijacked and used to promote a… thecybersecguru.com/news/microsoft-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 02/10/2026
Critical Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited: Unauthenticated File Write Flaw Exposes Email Security Gateways Worldwide CVE-2026-104286 is an actively exploited FortiMail zero-day allowing… thecybersecguru.com/exploits/fortim…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 02/10/2026
How Many Users Can a 1-Core, 2GB RAM Server Actually Handle? We Stress-Tested It to the Breaking Point We stress-tested a 1 vCPU, 2GB RAM VPS running Nginx, Node.js and PostgreSQL. See the 2,500-user limit, CPU… thecybersecguru.com/glossary/how-ma…
Post Image
011
The CyberSec Guru @thecybersecguru.com · 02/10/2026
Apache HTTP Server 2.4.69 Patches 20 Vulnerabilities: Code Execution, Authentication Bypass, and Data Leak Risks Demand Immediate Attention Apache HTTP Server 2.4.69 fixes 20 vulnerabilities, including RCE, memory… thecybersecguru.com/news/apache-htt…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 30/09/2026
Critical Citrix NetScaler RCE (CVE-2026-88772) exploited in the wild: a deep dive into the DTLS buffer overflow Citrix NetScaler vulnerability, NetScaler RCE, Citrix zero-day, DTLS buffer overflow, CVE-2026-88771, NetScaler… thecybersecguru.com/news/citrix-net…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 29/09/2026
Spotify Down: Open.spotify.com Shows “Page Not Available” as App Stops Loading Is Spotify down today? Users report a “Page not available” error on open.spotify.com and an app that fails to load. Get outage updates and… thecybersecguru.com/news/spotify-do…
Post Image
010
The CyberSec Guru @thecybersecguru.com · 28/09/2026
Pentagon’s Defense Manpower Data Center Breach Exposes SSNs of Up to 4 Million Military Personnel in Nine-Month Undetected Intrusion A Pentagon DMDC data breach may have exposed Social Security numbers and… thecybersecguru.com/news/pentagon-d…
Post Image
100
The CyberSec Guru @thecybersecguru.com · 27/09/2026
OpenAI’s AI agents went rogue on US government sites — here’s what actually happened OpenAI AI agents probed US government websites, used publicly leaked credentials, and bypassed restrictions, raising major AI security… thecybersecguru.com/news/openai-ai-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 27/09/2026
Citrix NetScaler Zero-Days Force Emergency Shutdowns Ahead of Next Week’s Patch Citrix NetScaler zero-day reports are triggering emergency shutdowns. Here's what is known, what remains unconfirmed, and how defenders can reduce… thecybersecguru.com/news/citrix-net…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 26/09/2026
Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack... thecybersecguru.com/news/elementor-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 26/09/2026
OnePlus 15 zero-permission root exploit: critical OxygenOS flaws expose privileged services to any installed app Two critical OnePlus 15 OxygenOS flaws let zero-permission apps gain root access. Learn how the exploit works,… thecybersecguru.com/news/oneplus-15…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 25/09/2026
Understanding the Different Types of Prompt Injection Attacks Learn what prompt injection attacks are, how direct, indirect and multimodal attacks work, real-world examples, and how to protect LLM and AI… thecybersecguru.com/glossary/prompt…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 24/09/2026
Apple Is Down: iMessage, iCloud, App Store, Apple Music, Maps and More Hit by Major Outage Apple is experiencing a major service disruption affecting iMessage, iCloud, App Store, Apple Music, Maps and more.… thecybersecguru.com/news/apple-outa…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 23/09/2026
Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521) CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04,… thecybersecguru.com/news/cve-2026-8…
Post Image
001
The CyberSec Guru @thecybersecguru.com · 23/09/2026
ShinyHunters Claims Unprecedented FBI Breach: Inside the Oracle PeopleSoft Zero-Day Attack and Dark Web Turf Wars ShinyHunters claims it breached FBI systems using a previously unknown Oracle PeopleSoft zero-day, targeting FBIjobs.gov and sensitive applicant and employee data...
thecybersecguru.com
ShinyHunters Claims Unprecedented FBI Breach: Inside the Oracle PeopleSoft Zero-Day Attack and Dark Web Turf Wars
ShinyHunters claims it breached FBI systems using a previously unknown Oracle PeopleSoft zero-day, targeting FBIjobs.gov and sensitive applicant and employee data
000
The CyberSec Guru @thecybersecguru.com · 22/09/2026
Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and… thecybersecguru.com/news/cve-2026-6…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 20/09/2026
Malicious npm package ‘indexed-btree’ evades install-script defenses and detonates at runtime The malicious indexed-btree npm package bypassed npm v12 install-script defenses using a runtime trigger, Slack… thecybersecguru.com/news/indexed-bt…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 20/09/2026
The Definitive Guide to Server Message Block (SMB) and Samba: Architecture, Security, and Implementation Learn SMB and Samba from the ground up: architecture, SMB authentication, vulnerabilities, hardening, AD DC, Samba configuration and… thecybersecguru.com/networking/smb-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 20/09/2026
Public Exploits Drop for Four Linux Kernel Flaws as CISA Warns of Active Exploitation: A Complete Technical Breakdown Four Linux kernel vulnerabilities now have public root exploits, while CISA warns of… thecybersecguru.com/news/linux-kern…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 19/09/2026
How an open-weight AI model hacked TikTok: the DepthFirst Labs camera and microphone exploit Researchers at DepthFirst Labs used an AI agent to exploit TikTok code, demonstrating a zero-click RCE chain that could… thecybersecguru.com/news/tiktok-ai-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 19/09/2026
Chat Control 2.0: The September 29 Trilogue and the Future of Digital Privacy in Europe Chat Control 2.0 explained: what the September 29 EU trilogue means for encryption, private messages, detection orders, age verification… thecybersecguru.com/news/chat-contr…
Post Image
020
The CyberSec Guru @thecybersecguru.com · 19/09/2026
Click2Shell Explained: Anatomy of the Critical WordPress Pre-Auth RCE Chain Click2Shell is a critical WordPress pre-auth RCE chain patched in WordPress 7.1.1. Learn how the exploit works, its impact, PoC, and how to secure… thecybersecguru.com/news/click2shel…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 19/09/2026
The next Polyfill.io? Inside the netdna-ssl.com takeover and the supply chain risk for thousands of websites The netdna-ssl.com domain has been taken over with wildcard DNS. Here's how legacy WP Engine CDN URLs could… thecybersecguru.com/news/netdna-ssl…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 19/09/2026
Restoring Over-the-Air Television in New York City After 9/11: The Complete Technical Story of Broadcast… thecybersecguru.com/telecom/restori…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 19/09/2026
Google Gemini Autonomously Hacked Three Companies: What Went Wrong? Google Gemini autonomously hacked three real companies during an AI security test. Here’s how the sandbox failed, credentials were exposed, and what it means… thecybersecguru.com/news/google-gem…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 18/09/2026
Anatomy of HEIF Heist: How Hacktron Used Claude to Break Into OpenAI, Slack, and GitHub Enterprise HEIF Heist exposed critical flaws in image parsers used by OpenAI, Slack, Meta and GitHub. See how Claude helped researchers… thecybersecguru.com/news/heif-heist…
Post Image
001
The CyberSec Guru @thecybersecguru.com · 18/09/2026
Over 100,000 WordPress Sites Backdoored in Massive Brevo Supply Chain Attack via Stolen Cloudflare Keys Brevo supply chain attack exposed 100,000+ WordPress sites to malicious JavaScript, backdoors and ClickFix malware… thecybersecguru.com/news/brevo-supp…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 18/09/2026
The Gyazo Breach: What Actually Happened to 23.6 Million Users and 490 Million Image Records Gyazo breach exposes 23.6M user accounts and metadata from 490M images. Here's what leaked, how the attack happened, and… thecybersecguru.com/news/gyazo-brea…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 18/09/2026
Tutor LMS Critical Flaw (CVE-2026-78175) Exposes 100,000+ WordPress Sites to Remote Code Execution Tutor LMS CVE-2026-78175 is a critical RCE flaw affecting 100,000+ WordPress sites. Learn how the exploit works and how to patch it... thecybersecguru.com/news/cve-2026-7…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 18/09/2026
Cisco FMC CVE-2026-20324: critical sftunnel root RCE explained Cisco FMC CVE-2026-20324 is a critical CVSS 9.9 sftunnel flaw enabling arbitrary file writes and root command execution. Learn the impact and fix... thecybersecguru.com/news/cisco-fmc-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 18/09/2026
Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994) Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape… thecybersecguru.com/news/docker-san…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 17/09/2026
The Apple Privacy Paradox: A Forensic Analysis of Marketing Claims vs. Policy Realities For years, Apple has anchored its brand identity on a singular, uncompromising pillar: "Privacy is a fundamental human right."… thecybersecguru.com/analysis/apple-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 17/09/2026
Microsoft Copilot Users Hit by “Trouble Responding” Errors in Reported Outage Microsoft Copilot is facing reported issues on September 17, 2026. Users are seeing “trouble responding” errors after the… thecybersecguru.com/news/microsoft-…
Post Image
001
The CyberSec Guru @thecybersecguru.com · 17/09/2026
Mistral AI Source Code Allegedly for Sale on Hacking Forum, Seller Cites Unrotated Developer Secrets Mistral AI source code is allegedly being sold on a hacking forum after a threat actor claimed repeated breaches. Here’s what the… thecybersecguru.com/news/mistral-ai…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 17/09/2026
Cisco ISE Zero-Day: CVE-2026-76460 Bypasses Authentication With a Perfect CVSS 10.0 Cisco ISE CVE-2026-76460 is a critical CVSS 10 authentication bypass. Learn how the flaw enables admin and root access, IOCs,… thecybersecguru.com/news/cisco-ise-…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 16/09/2026
Salesforce Down: Service Disruption Impacts Customers Across All Regions Salesforce is down on September 16, 2026. Multiple instances across all regions are affected by severe delays, errors and service access issues... thecybersecguru.com/news/salesforce…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 15/09/2026
Ledger data breach 2026: 471,000 customer records allegedly offered for sale at $20,000 Ledger data breach 2026: 471,000 customer records are allegedly for sale for $20,000. Here's what the listing claims and what… thecybersecguru.com/news/ledger-dat…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 15/09/2026
TELUS data breach explained: customer accounts hit in a 16-month credential attack TELUS data breach exposed customer accounts during a 16-month credential attack. Learn what data was accessed, how attackers abused… thecybersecguru.com/news/telus-data…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 15/09/2026
Swiss Bitcoin Pay Breach: The Hack That Turned a “Non-Custodial” Promise Into a Custody Lesson Swiss Bitcoin Pay confirmed a security breach on September 14, 2026. Emails, Bitcoin addresses, IBANs, transaction history and hashed passwords… thecybersecguru.com/news/swiss-bitc…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 15/09/2026
Nah unfortunately.
010
The CyberSec Guru @thecybersecguru.com · 15/09/2026
T-Mobile Database Allegedly for Sale on Underground Forum: What the Listing Shows, and What It Doesn’t Is T-Mobile hacked in 2026? An alleged customer database has appeared on a dark web forum. Here's what the… thecybersecguru.com/news/t-mobile-h…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 14/09/2026
Inside Omarchy: DHH’s $18.5 million Linux distro, its security holes, and the boycott campaign against it Omarchy Linux faces backlash over serious security flaws, Docker root access risks, DHH’s controversial… thecybersecguru.com/analysis/omarch…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 13/09/2026
Check Point patches two critical VPN gateway flaws scoring 9.8 on CVSS Check Point patches two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, rated CVSS 9.8 and capable of unauthenticated remote code… thecybersecguru.com/news/check-poin…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 12/09/2026
VLC Media Player hit by two critical security flaws: heap corruption and memory disclosure putting millions at risk Two critical VLC Media Player vulnerabilities, CVE-2026-56711 and CVE-2026-73324,… thecybersecguru.com/news/vlc-media-…
Post Image
100
The CyberSec Guru @thecybersecguru.com · 12/09/2026
Revolut data breach: how a fake government email handed attackers KYC selfies, passport scans, and full Bitcoin transaction history Revolut data breach exposes KYC selfies, passport scans, IBANs and Bitcoin transaction history. Here’s… thecybersecguru.com/news/revolut-da…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 12/09/2026
The GemStuffer Incident: The OpenAI Agent Attack on RubyGems OpenAI agents attacked RubyGems in the GemStuffer incident, uploading 2,000+ malicious packages, exploiting RubyDoc RCE and targeting API keys... thecybersecguru.com/news/openai-age…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 11/09/2026
Tor’s Trust Problem: Browser 14.5, a Broken Security Slider, and a $53 Kill Switch Tor Browser 14.5 changed OS spoofing, while a security slider flaw and a $53 DDoS attack expose deeper Tor security and infrastructure risks... thecybersecguru.com/analysis/tor-br…
Post Image
000
The CyberSec Guru @thecybersecguru.com · 11/09/2026
The IDScan Data Breach: Inside the 153 Million Driver’s License Leak and the Dark Web “Nexus” Marketplace The IDScan data breach exposed a massive trove of identity documents advertised by Nexus. Here’s what… thecybersecguru.com/news/idscan-dat…
Post Image
000