- 1,033 breaches tracked
- 674 leak passwords
Turn cyber intelligence into practical decisions.
Investigate vulnerabilities, follow source-backed threat signals and move from evidence to action with practical research, detection context and privacy-aware security tools.
- +217 in the last 7 days
- 74 groups active this month
- 18 rated high or critical
- Peak CVSS 10
Updated 22 hours ago
Cyber Weather
A daily reading of the global cyber threat climate.
Critical AI signals are shaping today's risk
The current stream is above normal baseline. ShellCodeX Pulse reviewed 19 published signals from the last 24 hours, with AI as the dominant theme and critical as the highest observed severity.
Activity is easing off; AI should keep receding unless a new disclosure lands.
Signals shaping today
Open PulseFeatured Highlights
Featured articles and tools in one rotating spotlight.
Hunting and Containing Live AWS Access Keys in Production
A public leak lands in your ticketing system: a repo, a build artifact, or a dataset contains an AWS access key. This article shows the exact commands, CloudTrail queries and containmen...
Read Story ▸
Keycloak CVE-2026-18963 Testing & Hunting Guide
A practical, hands-on guide for application security testers and defenders to test, detect and remediate Keycloak CVE-2026-18963. Includes exploit checks, DB and event queries, SIEM hun...
Read Story ▸
Detecting CVE-2026-19478 Exploitation in GitLab GraphQL
When a self‑hosted GitLab project disappears after an unauthenticated GraphQL POST, this guide shows where to look and what rules to run. Includes SIEM queries, Sigma rules and an audit...
Read Story ▸
Leveraging HTTP/2 for Covert Command and Control
Explore how attackers exploit HTTP/2 features for stealthy command and control channels and learn detection strategies.
Read Story ▸
Crafting HTTP Desync Attacks for Web Anomalies
Explore the intricacies of HTTP desync attacks and how they can reveal critical web vulnerabilities. A must-know for penetration testers.
Read Story ▸
Bypassing CSRF Protections with JSONP
Explore how JSONP can be exploited to bypass CSRF protections in web applications. Understand the methods and defensive measures.
Read Story ▸
Exploiting Misconfigured S3 Buckets for Data Exfiltration
Misconfigured S3 buckets pose a significant security risk, often leading to data exfiltration. Discover techniques used by attackers and how to safeguard your data.
Read Story ▸
18 Browser Extensions Every Red Teamer Should Know in 2026
Discover 18 powerful browser extensions every red teamer, penetration tester, and bug bounty hunter should know in 2026. From reconnaissance and proxy management to endpoint discovery,...
Read Story ▸
Analysis of Recent Ransomware Attacks Targeting Critical Infrastructure
Explore the latest ransomware attacks on critical infrastructure, their implications, and strategies for mitigation.
Read Story ▸
Why Threat Actors Still Rely on Simple Mistakes — and Why It Still Works
An analysis of why threat actors continue to exploit simple security mistakes — and how real-world incidents prove that basic errors still lead to major breaches.
Read Story ▸
dismap
Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
Open Tool ▸
shod4nd0rk
A Python tool for managing and searching Shodan dorks, including adding, deleting, and searching dorks with an easy-to-use menu interface.
Open Tool ▸
MailV4l1d8r
A powerful email validation tool for checking disposable and unsafe email addresses using multiple APIs and additional security checks.
Open Tool ▸Technology Pulse
Live signals from the cybersecurity and infrastructure ecosystem.
Articles
An operational playbook to prioritise and remediate CVE-2026-21962 in Oracle WebLogic. Includes triage heuristics, detection queries, WAF rules and timeline SLAs to act fast.
Prioritizing and Remediating CVE-2026-21962 in Oracle WebLogic
An operational playbook to prioritise and remediate CVE-2026-21962 in Oracle WebLogic. Includes triage heuristic...
Read ▸
A public leak lands in your ticketing system: a repo, a build artifact, or a dataset contains an AWS access key. This article shows the exact commands, CloudTrail queries and conta...
Hunting and Containing Live AWS Access Keys in Production
A public leak lands in your ticketing system: a repo, a build artifact, or a dataset contains an AWS access key....
Read ▸
A practical, hands-on guide for application security testers and defenders to test, detect and remediate Keycloak CVE-2026-18963. Includes exploit checks, DB and event queries, SIE...
Keycloak CVE-2026-18963 Testing & Hunting Guide
A practical, hands-on guide for application security testers and defenders to test, detect and remediate Keycloa...
Read ▸
When a self‑hosted GitLab project disappears after an unauthenticated GraphQL POST, this guide shows where to look and what rules to run. Includes SIEM queries, Sigma rules and an...
Detecting CVE-2026-19478 Exploitation in GitLab GraphQL
When a self‑hosted GitLab project disappears after an unauthenticated GraphQL POST, this guide shows where to lo...
Read ▸
If your org runs Zimbra Collaboration Suite with the zimbra-snmp package installed, CVE-2026-73570 lets unauthenticated attackers execute OS commands when SNMP notifications are en...
Hunting and Containing Zimbra CVE-2026-73570 with IDS, SIEM and EDR
If your org runs Zimbra Collaboration Suite with the zimbra-snmp package installed, CVE-2026-73570 lets unauthen...
Read ▸Tools
Curated open-source picks
A not so awesome list of adversary emulation gems for aspiring red/blue/purple teamers
adversaryemulation-gems
A not so awesome list of adversary emulation gems for aspiring red/blue/purple teamers
Open ▸
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
awesome-cybersecurity-blueteam
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue tea...
Open ▸Build, Share, and Grow with the Community.
ShellCodeX is evolving into a practical technology hub for builders and teams. We publish high-signal articles, curate useful tools, and spotlight real community events in one place.