fa
Feedback
ThreatXEd Security

ThreatXEd Security

رفتن به کانال در Telegram

Welcome to ThreatXEd Security! At ThreatXEd , we don’t just hand you the solutions; we equip you with the skills to solve challenges on your own, for a lifetime. DM us on @threatx_support

نمایش بیشتر
1 462
مشترکین
+224 ساعت
+17 روز
+330 روز

در حال بارگیری داده...

کانال‌های مشابه
هیچ داده‌ای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
سپتامبر '26
سپتامبر '26
+25
در 0 کانال‌ها
اوت '26
+97
در 0 کانال‌ها
Get PRO
ژوئیه '26
+107
در 0 کانال‌ها
Get PRO
ژوئن '26
+54
در 0 کانال‌ها
Get PRO
مه '26
+53
در 0 کانال‌ها
Get PRO
آوریل '26
+11
در 0 کانال‌ها
Get PRO
مارس '26
+19
در 1 کانال‌ها
Get PRO
فوریه '26
+18
در 0 کانال‌ها
Get PRO
ژانویه '26
+49
در 3 کانال‌ها
Get PRO
دسامبر '25
+33
در 0 کانال‌ها
Get PRO
نوامبر '25
+15
در 0 کانال‌ها
Get PRO
اکتبر '25
+25
در 0 کانال‌ها
Get PRO
سپتامبر '25
+49
در 2 کانال‌ها
Get PRO
اوت '25
+125
در 1 کانال‌ها
Get PRO
ژوئیه '25
+122
در 1 کانال‌ها
Get PRO
ژوئن '25
+51
در 0 کانال‌ها
Get PRO
مه '25
+58
در 0 کانال‌ها
Get PRO
آوریل '25
+103
در 1 کانال‌ها
Get PRO
مارس '25
+219
در 0 کانال‌ها
Get PRO
فوریه '25
+879
در 0 کانال‌ها
Get PRO
ژانویه '250
در 2 کانال‌ها
Get PRO
دسامبر '240
در 2 کانال‌ها
Get PRO
نوامبر '24
+10
در 1 کانال‌ها
تاریخ
رشد مشترکین
اشارات
کانال‌ها
23 سپتامبر0
22 سپتامبر+3
21 سپتامبر+1
20 سپتامبر+1
19 سپتامبر+1
18 سپتامبر0
17 سپتامبر0
16 سپتامبر+2
15 سپتامبر0
14 سپتامبر+1
13 سپتامبر0
12 سپتامبر0
11 سپتامبر+1
10 سپتامبر+2
09 سپتامبر+1
08 سپتامبر+1
07 سپتامبر+1
06 سپتامبر+1
05 سپتامبر0
04 سپتامبر+2
03 سپتامبر+6
02 سپتامبر+1
01 سپتامبر0
پست‌های کانال
photo content

2
100 DAYS CHALLENGE - started this thing to build consistency. the challenge is now open, for whoever's willing to show up daily and prove it. so here's the deal: 📅 10 days, first checkpoint -- 3,000 ETB to the winner 📅 25 days (10+15) -- second checkpoint - 5,000 ETB to the winner 📅 55 days (25+30) -- final checkpoint - 10,000 ETB to the winner rule is simple. send your daily update. consistently. no skipping. no excuses. showing up when nobody's watching. this challenge rewards exactly that. who's in? start today! dm me through @anonyguy with consistency, honesty and surely with interesting updates, so you join the challenge and see if you qualify. a little subscriber challenge will be there before release of each prize. if activity is very good, total pot can increase to 25k. let us have a meaningful 100days. Thanks.
468
3
🚨 Five critical flaws in WordPress plugins and themes can lead to site takeover or RCE. The bugs span auth bypass, admin pas
🚨 Five critical flaws in WordPress plugins and themes can lead to site takeover or RCE. The bugs span auth bypass, admin password-reset exposure, privilege escalation, and server-side code execution across GiveWP, Avada, WPMU DEV, TranslatePress, and Pods. Read: https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
465
4
⚠️ Next.js patched two critical flaws that can enable unauthenticated RCE. One affects Windows-hosted apps. The other require
⚠️ Next.js patched two critical flaws that can enable unauthenticated RCE. One affects Windows-hosted apps. The other requires AVIF optimization. No exploitation has been reported. Details: https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html
416
5
‼️ CSS inside webmail can capture passwords and take over accounts. New research demos also show CSS/HTML attack paths across
‼️ CSS inside webmail can capture passwords and take over accounts. New research demos also show CSS/HTML attack paths across Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that can leak tokens, hijack UI actions, or lead to account takeover. See what email CSS can now do: https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html
485
6
⚡ UPDATE - Coldcard-linked theft estimates have jumped from $70 million to $88.6 million. Galaxy Research says two more suspe
⚡ UPDATE - Coldcard-linked theft estimates have jumped from $70 million to $88.6 million. Galaxy Research says two more suspected sweep waves bring the total to 1,367.05 BTC across 4,585 addresses. The activity appears ongoing, and the third wave may involve a different operator. Read: https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
504
7
🛑 Attackers hijacked Adform’s shared tracking script to swap crypto wallet addresses in users’ browsers. The code could rewr
🛑 Attackers hijacked Adform’s shared tracking script to swap crypto wallet addresses in users’ browsers. The code could rewrite addresses copied, pasted, or entered into forms while the page remained open. How the adtech supply-chain attack worked: https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html
453
8
Congratulations to our Talent Center community members on graduating from the Ethiopian Artificial Intelligence Institute! Yo+2
Congratulations to our Talent Center community members on graduating from the Ethiopian Artificial Intelligence Institute! Your hard work, dedication, and commitment have paid off. We are proud of your achievement and wish you continued success as you apply your knowledge and skills to make a positive impact. Congratulations, graduates! !
478
9
1Password Partners with Anthropic to Give Claude Access to Your Credentials 1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values. Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself. Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies. @Cyber_Security_Channel
448
10
بدون متن...
1
11
+3
بدون متن...
469
12
بدون متن...
344
13
بدون متن...
360
14
Today marks a special milestone. Proud to announce that ThreatX has officially graduated from the AI startup center 2026 Star+1
Today marks a special milestone. Proud to announce that ThreatX has officially graduated from the AI startup center 2026 Startup Incubation Program organized by the Ethiopian Artificial Intelligence Institute. This journey has been filled with learning, challenges, innovation, and growth. Thank you to everyone who supported us along the way. This is not the finish line it’s the beginning of an even bigger journey. Here’s to building technology that creates real impact.
725
15
🧩 ThreatXEd Friday Challenge: The Cookie That Trusted Itself You're testing a private portal. Logged in as a regular user, y
🧩 ThreatXEd Friday Challenge: The Cookie That Trusted Itself You're testing a private portal. Logged in as a regular user, you check your cookies and find session_role, holding the value dXNlcg==. You decode it out of curiosity it just says "user". Here's the twist: there's no signature, no server-side lookup happening. The app appears to trust whatever value sits in that cookie directly, and uses it to decide what you're allowed to see. Your turn: 1️⃣ What class of vulnerability is this and why does encoding a value (instead of encrypting or signing it) fail to protect it? 2️⃣ What would you change in the cookie's value, and what would you expect to happen if the server truly has no additional validation? #FridayChallenge #ThreatXEd
388
16
🛑 A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root acce
🛑 A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root access. On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit. Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
337
17
🛠 Ato Root's Corner: netcat No interface. No assumptions. Just a raw connection and that's exactly why it matters. Half the+4
🛠 Ato Root's Corner: netcat No interface. No assumptions. Just a raw connection and that's exactly why it matters. Half the "advanced" tools you use are built on this same logic. Swipe to see how nc grabs banners, opens listeners, and becomes a reverse shell 👉 Ato Root's rule: a tool with no opinions can't lie to you. 💬 You run nc -v target.com 22 and get a banner you didn't expect. First move? #ThreatXEd
441
18
⛽️🔑 One password. No MFA. Fuel shortages across the entire US East Coast. Let's talk about the Colonial Pipeline hack because it's honestly one of the most humbling breaches in cybersecurity history. No fancy zero-day. No genius malware. Just this: An employee's VPN password had leaked online from a totally different, unrelated breach months earlier. That account wasn't even in daily use anymore, but nobody had switched it off. And here's the part that hurts: there was no MFA on it. So a leaked password alone was enough to walk right in. Once inside, attackers dropped ransomware on the company's IT systems. Colonial couldn't be 100% sure the ransomware hadn't also touched their pipeline control systems so out of caution, they shut the whole pipeline down themselves. Result? Fuel shortages, panic buying, and a $4.4 million ransom paid within hours. The real lesson: This wasn't a "sophisticated hacker" story. It was an old account nobody cleaned up + one missing security setting. That's it. That's the whole attack. #ThreatXEd #CyberSecurity
364
19
Half-open, fully sneaky. 🤝⚡️ Swipe to see how -sS interrupts the handshake before it completes — and why an IDS still catche+3
Half-open, fully sneaky. 🤝⚡️ Swipe to see how -sS interrupts the handshake before it completes — and why an IDS still catches it. Quick quiz: you send a SYN, and the target replies with a RST-ACK. Is that port Open, Closed, or Filtered? 🤔 (Hint: SYN-ACK = open, silence = filtered... so what does a RST tell you?) Drop your answer below 👇 no Googling. #ThreatXEd #Nmap #CyberSecurity #EthicalHacking #InfoSec
430
20
🛑 THE $10.69 DOMAIN THAT STOPPED A GLOBAL RANSOMWARE PANDEMIC May 2017. WannaCry rips through hospitals, banks, and governments worldwide — in hours. No phishing email needed. No user clicking anything. It just... spread. On its own. The exploit: EternalBlue — a leaked NSA tool — targeting a flaw in Windows' ancient SMBv1 protocol (Port 445). The worm behavior: Once inside one machine, it silently scanned the local network and the internet for other unpatched systems, and infected them instantly. No human interaction required. The twist: A 22-year-old researcher (MalwareTech) dug into the decompiled binary and found something odd — before encrypting anything, the malware pinged one bizarre, unregistered domain: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com He registered it. Cost: $10.69. The moment that domain went live, WannaCry got a response, assumed it was trapped in a sandbox, and shut itself down. Globally. One connection. One decision. Crisis over. ⚡️ THE THREATXED TAKEAWAY WannaCry didn't spread because it was unstoppable. It spread because organizations left a legacy protocol (SMBv1) exposed to the internet and skipped basic patching. Attack surface reduction isn't advanced theory — it's step one. #ThreatXEd #WannaCry #CyberSecurity #InfoSec
385