Latest updates for Hackthebox

Fresh curated links around hackthebox are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • HackTheBox. Прохождение Mini Pro Lab Unintended
  • HackTheBox. Прохождение Mini Pro Lab Puppet
  • Reset — прохождение сложной машины от Tryhackme

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

habr.com /1 day ago

HackTheBox. Прохождение Mini Pro Lab Unintended

Компания Unintended недавно перевела свою инфраструктуру на Active Directory. Руководство обеспокоено тем, что устаревшие методы и упущенные из виду ошибки конфигурации могут сдела...

Read source
habr.com /5 days ago

HackTheBox. Прохождение Mini Pro Lab Puppet

Вам поручено провести проверку на проникновение в компанию Puppet Inc. Компания не разрешает передачу данных за пределы внутренней сети, поэтому внутри компании был создан сервер у...

Read source
habr.com /7 hours ago

Reset — прохождение сложной машины от Tryhackme

Годная машина на тему Windows AD, Kerberos. В начале разведки получаем доступ к гостевой шаре. Оттуда достаем файл с паролем, но не знаем от какой учетной записи. Проводим разведку...

Read source
gbhackers.com /1 month ago

Lazarus Lures Developers With Backdoored Coding Tests

North Korea-linked hackers are using AI-assisted malware and backdoored coding challenges to quietly loot millions in cryptocurrency from Web3 developers. Expel assesses with high...

Read source
dev.to /1 month ago

BB Day 14: Command Injection Bug Bounty 2026 — Find OS Injection in Web Apps & APIs That Pay

📰 Originally published on SecurityElites — the canonical, fully-updated version of this article. DAY 14 🎯 BUG BOUNTY COURSE FREE Part of the 60-Day Bug Bounty Master...

Read source
gbhackers.com /1 month ago

Botnet Exposed: Hackers Leave Worker Access and Root Passwords Wide Open

Hackers have left a live Twitter/X credential‑stuffing botnet effectively unlocked, exposing its full command‑and‑control stack, worker fleet, and root passwords to anyone who know...

Read source
thehackernews.com /1 month ago

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege...

Read source
thehackernews.com /1 month ago

Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials

A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private k...

Read source
idev.games /1 month ago

Hacking Is Personal

Hacking Is Personal is an immersive hacking simulation that puts you in the role of a cybercriminal navigating the dangerous world of digital intrusion!...

Read source
gbhackers.com /1 month ago

BPFDoor Variants Hide with Stateless C2 and ICMP Relay Tactics

Seven new BPFDoor variants that push Linux backdoor tradecraft deep into the kernel, making them harder to spot in large telecom networks. These implants use Berkeley Packet Filter...

Read source
gbhackers.com /4 weeks ago

Deep#Door Stealer Targets Passwords, Tokens, SSH Keys, and Wi-Fi Credentials

Deep#Door is a stealthy Python-based Remote Access Trojan (RAT) that uses an obfuscated batch loader to deploy a persistent surveillance and credential-stealing implant on Windows...

Read source
idev.games /2 weeks ago

Account Hacker

Account Hacker: Rogue Login is a dark comedy social media sabotage simulation game...

Read source
dev.to /6 days ago

Inside a Real Production Server Breach

Just a normal day. 23rd May, 2026. Wake up in the morning, pick up my friend from his house, head to the gym. Somewhere between sets, he casually mentions: "One of my client's...

Read source
gbhackers.com /1 month ago

Hackers Exploit Obsidian Plugin to Deploy Cross-Platform Malware

Hackers are abusing Obsidian’s Shell Commands plugin and shared cloud vaults to deliver a new cross‑platform malware chain that ends with the PHANTOMPULSE remote access trojan. Att...

Read source
hackread.com /1 month ago

TeamPCP Hijacks Bitwarden CLI, Uses Dependabot to Deploy Shai-Hulud Malware

GitGuardian uncovers TeamPCP attack on Bitwarden CLI, abusing GitHub Dependabot to spread Shai-Hulud and poison AI coding tools.

Read source
gbhackers.com /1 month ago

Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face

Attackers are rapidly exploiting CVE-2026-39987 in the marimo Python notebook platform to deploy a new NKAbuse backdoor variant hosted on Hugging Face Spaces, turning AI/ML develop...

Read source
gbhackers.com /1 week ago

UAC-0184 Uses Bitsadmin and HTA Files to Deliver Gated Malware

UAC-0184 uses a multi‑stage malware chain that abuses bitsadmin and HTA loaders to reach a heavily obfuscated payload bundle, ultimately hiding behind signed binaries such as VSLau...

Read source
infosecwriteups.com /1 month ago

JADX + MCP: I let the AI read the APK so I don’t have to

Hello Hackers, Hope you guys are doing well and hunting lots of bugs and Dollars!Continue reading on InfoSec Write-ups »

Read source
thehackernews.com /2 days ago

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-...

Read source
dev.to /1 month ago

Kerberoasting Still Works Because You Trust AES Too Much

A domain controller hums in a way most people never hear. Not loud. Not dramatic. Just a steady administrative breath in the background of a network that believes it is orderly. S...

Read source
venturebeat.com /3 weeks ago

Anthropic Skill scanners passed every check. The malicious code rode in on a test file.

Picture this scenario: An Anthropic Skill scanner runs a full analysis of a Skill pulled from ClawHub or skills.sh. Its markdown instructions are clean, and no prompt injection is...

Read source
gbhackers.com /1 week ago

Hackers Exploit F5 BIG-IP to Gain SSH Access and Pivot Into Linux Networks

Threat actors are actively exploiting end-of-life F5 BIG-IP appliances to gain unauthorized SSH access into enterprise networks, using the compromised devices as launchpads for sop...

Read source
gbhackers.com /2 days ago

Hackers Pivot from marimo RCE to Internal Database Using LLM Agent

A newly observed intrusion demonstrates how attackers are replacing static playbooks with AI-driven agents that adapt in real time. The attack began on May 10, 2026, бѓ бѓќбѓ“бѓ”бѓ...

Read source
thehackernews.com /2 weeks ago

âš¡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Hackthebox

feeds.feedburner.com

Recent coverage from public sources
Public source

dev.to

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source

habr.com

Recent coverage from public sources
Public source

medium.com

Recent coverage from public sources
Public source