Web appOpen in Telegram
HHACKLIDO | Cyber Security

HACKLIDO | Cyber Security

@hacklido · channel · Tech · indexed since 2026-05-27
8 034subscribers−30 in a week
426average post reach
5.3%ER — reach to subscribers
40posts in 30 days
H
HACKLIDO | Cyber Security
Link
click to show
Day 1 of 30: Why AI Agents Broke Your Threat Model Your threat model assumes a boundary between data and instructions. An LLM has one input channel. The system prompt, the user question, the tool descriptions and that GitHub issue it just read are all the same buffer. There is no boundary to defend. https://hacklido.com/blog/1631-why-ai-agents-broke-your-threat-model
3 · 445 ·
Link
click to show
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure https://hacklido.com/news/clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors https://hacklido.com/news/jade-sleet-linked-to-indian-it-provider-breach-with-flatroof-and-roofdeck-backdoors Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws https://hacklido.com/news/claude-opus-5-helped-researchers-take-over-openai-staff-accounts-via-chained-flaws
2 · 477 ·
HACKLIDO | Cyber Security
Link
click to show
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR https://hacklido.com/news/fake-lastpass-authenticator-installer-abuses-microsoft-signed-driver-to-kill-antivirus-and-edr Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto https://hacklido.com/news/contagious-interview-campaign-compromises-30-000-devices-steals-10-71m-in-crypto Google Fined €403 Million Over GDPR Violations Tied to Location Data https://hacklido.com/news/google-fined-403-million-over-gdpr-violations-tied-to-location-data
1 · 433 ·
HACKLIDO | Cyber Security
Link
click to show
The Lethal Trifecta Checklist https://hacklido.com/blog/1640-the-lethal-trifecta-checklist Silent Witness - Digital Forensics CTF Writeup https://hacklido.com/blog/1638-silent-witness-digital-forensics-ctf-writeup Technical Write-up: Temporal Anomaly https://hacklido.com/blog/1637-technical-write-up-temporal-anomaly Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials https://hacklido.com/news/malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credentials WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers https://hacklido.com/news/wordpress-issues-patch-for-critical-flaw-that-can-enable-code-execution-on-some-servers Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks https://hacklido.com/news/check-point-warns-of-management-server-zero-day-exploited-in-targeted-attacks
2 · 383 ·
Photo
click to show
🚀 NEW CHALLENGE LAUNCHED | HACKLIDO ROOT QUEST 🔥 A brand-new Web Security challenge, “Forminator”, is now live on Hacklido Root Quest! 🎯 Category: Web ⚡ Difficulty: Medium ⭐ Points: 400 Put your web security and exploitation skills to the test, identify the vulnerability, and work your way to the flag. Can you solve it before others? 👉 Start the Challenge: https://learn.hacklido.com/rootquest/forminator 🏆 Think. Hunt. Exploit. Pwn.
1 · 378 ·
HACKLIDO | Cyber Security
Link
click to show
30-Day Agentic AI Hacking Series | Day 5 🚀 Day 5 covers OWASP Top 10 for Agentic Applications and key security risks in AI agents. 📚 Today's Blog: https://hacklido.com/blog/1643-owasp-top-10-for-agentic-applications 📰 Daily Cyber Tech News: 🔹 Terraform Providers Deliver Go Malware https://hacklido.com/news/attackers-use-malicious-terraform-providers-to-deliver-go-malware-via-hashicorp-registry 🔹 MikroTrick Takes Over MikroTik Routers https://hacklido.com/news/mikrotrick-chain-let-attackers-take-over-mikrotik-routers-without-a-password-or-ssh-key 🔹 Windows Malware Uses AI Models to Vote https://hacklido.com/news/this-windows-malware-is-built-to-let-up-to-four-ai-models-vote-on-its-next-move
3 · 394 ·
H
Link
click to show
Become a job-ready Cyber Threat Intelligence Analyst. Learn OSINT, Threat Hunting, Malware Intelligence, Infrastructure Tracking, Dark Web Intelligence, MITRE ATT&CK, MISP and OpenCTI. 📅 Start Date: 5 october 2026 ⏳ Duration: 12 Weeks 📚 Level: Basic to Advanced 💰 Fee: ₹8,000 only 💳 Easy Installments: Pay ₹4,000 at registration and the remaining ₹4,000 after one month. Enroll Now: https://techonquer.org/threat-intelligence-training 📘 Syllabus: https://techonquer.org/public/uploads/2026/09/techonquer-threat-intelligence-syllabus-removed-e9632ee5.pdf
3 · 426 ·
HACKLIDO | Cyber Security
Link
click to show
📰 Today's Cyber News Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer https://hacklido.com/news/hacked-ukrainian-sites-serve-fake-cloudflare-clickfix-lures-for-psychedelic-stealer Placeholder third-party.com Referenced Across 1,700+ Repositories Now Serves Malicious Content https://hacklido.com/news/placeholder-third-party-com-referenced-across-1-700-repositories-now-serves-malicious-content Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions| https://hacklido.com/news/unpatched-oneplus-flaws-let-installed-android-apps-gain-root-without-permissions 📚 Today's Blogs What Is the General Data Protection Regulation (GDPR) and Why Is It Important for Businesses? https://hacklido.com/blog/1647-what-is-the-general-data-protection-regulation-gdpr-and-why-is-it-important-for-businesses How to Fix PST to EML Conversion Errors in Outlook: A Complete Troubleshooting Guide https://hacklido.com/blog/1645-how-to-fix-pst-to-eml-conversion-errors-in-outlook-a-complete-troubleshooting-guide Gh0st RAT Attack https://hacklido.com/blog/1644-gh0st-rat-attack
1 · 422 ·
H
Link
click to show
* Mapping the Attack Surface of a Real Agent Deployment
1 · 395 ·
H
HACKLIDO | Cyber Security
Link
click to show
📚 Today's Blogs Build Your Agent Hacking Lab http://hacklido.com/blog/1655-build-your-agent-hacking-lab Mapping the Attack Surface of a Real Agent Deployment https://hacklido.com/blog/1654-mapping-the-attack-surface-of-a-real-agent-deployment MSG Files Explained: Structure, Storage, and Access https://hacklido.com/blog/1652-msg-files-explained-structure-storage-and-access 📰 Today's Cyber Tech News Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware https://hacklido.com/news/compromised-github-actions-came-back-online-and-resumed-executing-mini-shai-hulud-malware PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence https://hacklido.com/news/pamstealer-macos-malware-adds-live-c2-payload-decryption-and-multi-layer-persistence Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise https://hacklido.com/news/bitget-says-suspected-north-korean-hackers-stole-351-6m-after-backend-compromise
4 · 391 ·
HACKLIDO | Cyber Security
Link
click to show
Blogs Tool Poisoning: How Malicious Tools Can Compromise AI Agent Workflows https://hacklido.com/blog/1658-tool-poisoning Whitespace Message Forensics: Steganography Hidden in Plain Sight https://hacklido.com/blog/1657-whitespace-message-forensics-steganography News Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells https://hacklido.com/news/attackers-bypass-wafs-to-exploit-oracle-peoplesoft-flaw-and-deploy-web-shells Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials https://hacklido.com/news/lunex-stealer-abuses-amd-driver-to-disable-security-monitoring-and-steal-browser-credentials Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation https://hacklido.com/news/warning-two-unpatched-citrix-netscaler-rce-zero-days-under-active-exploitation
2 · 338 ·
HACKLIDO | Cyber Security
Link
click to show
Today’s Blogs Web3 Bug Bounty Roadmap: From Zero to Your First Smart Contract Finding https://hacklido.com/blog/1659-web3-bug-bounty-roadmap-from-zero-to-your-first-smart-contract-finding Day 9 AI Agent Hacking Series Rug Pulls and Silent Redefinition https://hacklido.com/blog/1660-rug-pulls-and-silent-redefinition Today’s Tech News Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks https://hacklido.com/news/apple-patches-coregraphics-flaw-possibly-exploited-in-targeted-attacks Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks https://hacklido.com/news/hackers-use-needymantis-to-maintain-long-term-access-in-breached-networks Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M https://hacklido.com/news/bitget-says-attacker-exploited-third-party-security-product-flaw-to-steal-388m
2 · 320 ·
HACKLIDO | Cyber Security
Link
click to show
Today’s Blogs Tool Shadowing and Cross-Server Attacks https://hacklido.com/blog/1663-tool-shadowing-and-cross-server-attacks How to Start Ethical Hacking in 2026: The Roadmap Nobody Gives You Straight https://hacklido.com/blog/1662-how-to-start-ethical-hacking-in-2026-the-roadmap-nobody-gives-you-straight Today’s Tech News OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions https://hacklido.com/news/openai-shelves-gpt-6-1-astra-after-tests-find-deception-and-unauthorized-actions 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent https://hacklido.com/news/101-malicious-npm-packages-add-developers-whatsapp-accounts-to-groups-without-consent Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown https://hacklido.com/news/kiteworks-fixes-critical-flaw-found-during-nine-hour-precautionary-shutdown Russia's Star Blizzard Targets 100 Organizations With Fake Event Invites to Deliver Backdoor https://hacklido.com/news/russia-s-star-blizzard-targets-100-organizations-with-fake-event-invites-to-deliver-backdoor New Spectre v2 BTR Attack Leaks Linux Memory Despite Existing Defenses https://hacklido.com/news/new-spectre-v2-btr-attack-leaks-linux-memory-despite-existing-defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks https://hacklido.com/news/french-tax-data-theft-using-stolen-staff-passwords-went-undetected-for-seven-weeks
1 · 295 ·
H
HACKLIDO | Cyber Security
Link
click to show
Today’s Blogs The Confused Deputy and OAuth Weaknesses in MCP https://hacklido.com/blog/1666-the-confused-deputy-and-oauth-weaknesses-in-mcp How to Learn Red Teaming in 2026: From Operator Basics to Full Engagements https://hacklido.com/blog/1667-how-to-learn-red-teaming-in-2026-from-operator-basics-to-full-engagements Today’s Tech News Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version https://hacklido.com/news/google-rolls-out-gemini-4-argon-to-trusted-cyber-defenders-plans-guardrail-free-version Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path https://hacklido.com/news/apple-coregraphics-poc-emerges-as-whatsapp-pdf-checks-hint-at-possible-delivery-path
1 · 308 ·
HACKLIDO | Cyber Security
Link
click to show
Today’s Blogs How to Learn Red Teaming in 2026: From Operator Basics to Full Engagements https://hacklido.com/blog/1667-how-to-learn-red-teaming-in-2026-from-operator-basics-to-full-engagements Today’s Tech News Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers https://hacklido.com/news/police-arrest-16-year-old-suspected-of-running-killsec-seize-ransomware-leak-site-and-servers WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory https://hacklido.com/news/wordpress-backdoor-rebuilds-itself-after-cleanup-using-files-database-and-shared-memory
2 · 280 ·
H
Link
click to show
Today on HACKLIDO New in the 30 Days of Agent Hacking series: Day 13: The postmark-mcp Incident The first malicious MCP server caught in the wild. No zero day, just one line. Around 15 clean versions to build trust, then a release that quietly copied your email to an attacker address. The tool still worked, which is exactly why nobody noticed. https://hacklido.com/blog/1669-case-study-the-postmark-mcp-incident Security news today: GitLab patches a critical 9.9 AI Gateway flaw allowing command execution on self-hosted servers https://hacklido.com/news/gitlab-patches-critical-9-9-ai-gateway-flaw-allowing-command-execution-on-self-hosted-servers Antino backdoor uses Outlook and OneDrive for C2 in a China-nexus espionage campaign https://hacklido.com/news/antino-backdoor-uses-outlook-and-onedrive-for-c2-in-china-nexus-espionage-campaign Dell CSM flaws enable unauthenticated admin access and root on Kubernetes nodes https://hacklido.com/news/dell-csm-flaws-enable-unauthenticated-admin-access-and-root-on-kubernetes-nodes
2 · 244 ·
H
HACKLIDO | Cyber Security
Link
click to show
📰 Latest Tech & Cybersecurity News 1. ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members https://hacklido.com/news/shinyhunters-suspect-rey-reportedly-detained-in-jordan-helping-fbi-identify-group-members 2. China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AiTM Phishing https://hacklido.com/news/china-aligned-ta419-targets-u-s-ai-policy-experts-with-microsoft-aitm-phishing 3. MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics https://hacklido.com/news/mi5-says-china-s-mss-funded-research-involving-100-u-k-linked-academics 📚 Latest Cybersecurity Blogs 4. How to Build a Cyber Security Portfolio That Actually Gets Interviews https://hacklido.com/blog/1673-how-to-build-a-cyber-security-portfolio-that-actually-gets-interviews 5. Build and Exploit a Vulnerable MCP Server https://hacklido.com/blog/1672-build-and-exploit-a-vulnerable-mcp-server 🔐 Keep Learning. Keep Testing. Keep Publishing. Explore more cybersecurity content, practical guides, CTF writeups, and latest security news on HackLido. 
1 · 105 ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count