⤷ Title: ️ The Day I Found a phpinfo() Page Exposed in Production — And Why It Was Worth More Than $200
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:05:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #hacking #bug_bounty_tips #bugs
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:05:55 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_writeup #hacking #bug_bounty_tips #bugs
Medium
🛠️ The Day I Found a phpinfo() Page Exposed in Production — And Why It Was Worth More Than $200
There are days in bug bounty hunting when you stumble across something tiny — almost too simple — and yet it reminds you exactly why web…
⤷ Title: When I Found a docker-compose.yml
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:08:56 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_writeup #bug_bounty_tips #hackerone #hacking
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:08:56 GMT
════════════════════════
⌗ Tags: #bug_hunting #bug_bounty_writeup #bug_bounty_tips #hackerone #hacking
Medium
🐳 When I Found a docker-compose.yml File Exposed in Production — And It Contained Live Database Credentials
Some bug bounty stories start with clever payloads, boundary-pushing exploits, or hours of reverse engineering.
⤷ Title: Your Workspace Can Betray You — If You Let It
════════════════════════
𐀪 Author: Sam Galope
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:07:55 GMT
════════════════════════
⌗ Tags: #infosec #opsec #cyber_security_awareness #osint #operational_security
════════════════════════
𐀪 Author: Sam Galope
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:07:55 GMT
════════════════════════
⌗ Tags: #infosec #opsec #cyber_security_awareness #osint #operational_security
Medium
Your Workspace Can Betray You — If You Let It
Spatial awareness is a core OSINT skill most overlook.
⤷ Title: HTB Challenge — Puppet Master
════════════════════════
𐀪 Author: Fardeen A.
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 23:44:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #daily_blog #mindset #hackthebox #challenge
════════════════════════
𐀪 Author: Fardeen A.
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 23:44:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #daily_blog #mindset #hackthebox #challenge
Medium
HTB Challenge — Puppet Master
Hello, and thank you if you’re one of the few tech savvy, interested in HackTheBox reading this. This is one of the series that I’ve…
⤷ Title: Public Wi-Fi is a Trap. Here’s How to Secure It for $0.
════════════════════════
𐀪 Author: Muneeb | Budget Tech Buddy
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 23:02:15 GMT
════════════════════════
⌗ Tags: #technology #privacy #cybersecurity #lifehacks #remote_working
════════════════════════
𐀪 Author: Muneeb | Budget Tech Buddy
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 23:02:15 GMT
════════════════════════
⌗ Tags: #technology #privacy #cybersecurity #lifehacks #remote_working
Medium
Public Wi-Fi is a Trap. Here’s How to Secure It for $0.
That free coffee shop Wi-Fi isn’t just slow — it’s a hacker’s playground. Here is your survival guide to locking down your connection…
⤷ Title: Blockchain Risks: What Project Managers and Tech Strategists Need to Know as Stablecoins Outpace…
════════════════════════
𐀪 Author: CCL Montante
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:55:07 GMT
════════════════════════
⌗ Tags: #tech_strategy #project_management #cybersecurity #blockchain
════════════════════════
𐀪 Author: CCL Montante
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:55:07 GMT
════════════════════════
⌗ Tags: #tech_strategy #project_management #cybersecurity #blockchain
Medium
Blockchain Risks: What Project Managers and Tech Strategists Need to Know as Stablecoins Outpace…
In 2026, blockchain is no longer a niche innovation quietly maturing in the background of digital finance. It has become both a global…
⤷ Title: How can you send secure message across the internet?
════════════════════════
𐀪 Author: Jan Skopal
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:33:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #rsa_algorithm #rsa #cyber_security_awareness
════════════════════════
𐀪 Author: Jan Skopal
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:33:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #rsa_algorithm #rsa #cyber_security_awareness
Medium
How can you send secure message across the internet?
Think of it like a magic mailbox. Anyone can drop a letter in, but only you have the key to open it. The mailbox actually has two keys…
⤷ Title: TryHackMe Advent of Cyber 2025 (Day 7): Network Discovery — Scan-ta Clause
════════════════════════
𐀪 Author: Hibullahi AbdulAzeez
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:07:17 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme #aoc2025
════════════════════════
𐀪 Author: Hibullahi AbdulAzeez
════════════════════════
ⴵ Time: Sun, 07 Dec 2025 22:07:17 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme #aoc2025
Medium
TryHackMe Advent of Cyber 2025 (Day 7): Network Discovery — Scan-ta Clause
Complete Walkthrough & Learning Guide
⤷ Title: PoC Available: Bluetooth Flaw Risks DoS Crash on Smart Cars and Wear OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:50:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android Automotive #BlueShrimp #Bluetooth #CVE_2025_48593 #Denial of Service #UAF #Wear OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:50:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android Automotive #BlueShrimp #Bluetooth #CVE_2025_48593 #Denial of Service #UAF #Wear OS
Daily CyberSecurity
PoC Available: Bluetooth Flaw Risks DoS Crash on Smart Cars and Wear OS
The BlueShrimp exploit targets a Bluetooth UAF flaw (CVE-2025-48593, CVSS 8.0) that can crash the service on Android Automotive and Wear OS. Phones are safe, but PoC is public. Patch immediately.
⤷ Title: High-Severity Duc Disk Tool Flaw (CVE-2025-13654) Risks DoS and Information Leak via Integer Underflow
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:45:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_13654 #Disk Usage #dos #Duc #Information Disclosure #Integer Underflow #Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:45:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_13654 #Disk Usage #dos #Duc #Information Disclosure #Integer Underflow #Linux
Daily CyberSecurity
High-Severity Duc Disk Tool Flaw (CVE-2025-13654) Risks DoS and Information Leak via Integer Underflow
A High-severity flaw (CVE-2025-13654) in the Duc disk usage tool risks DoS and information leaks. An integer underflow in buffer.c allows out-of-bounds memory read. Update to v1.4.6 immediately.
⤷ Title: “SeedSnatcher” Android Malware Targets Crypto Users, Using Overlay Phishing and BIP 39 Validation to Steal Seed Phrases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:40:39 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #BIP 39 #cryptocurrency #Malware_as_a_Service #Overlay Phishing #Seed Phrase #SeedSnatcher #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:40:39 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #BIP 39 #cryptocurrency #Malware_as_a_Service #Overlay Phishing #Seed Phrase #SeedSnatcher #Telegram
Daily CyberSecurity
"SeedSnatcher" Android Malware Targets Crypto Users, Using Overlay Phishing and BIP 39 Validation to Steal Seed Phrases
A dangerous new Android malware called SeedSnatcher targets crypto users with overlay phishing on MetaMask/Trust Wallet. It uses BIP 39 validation to steal seed phrases and supports remote command execution for total device control.
⤷ Title: Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:36:25 +0000
════════════════════════
⌗ Tags: #Cyber Security #Device Code #Fake Conference #M365 #OAuth Phishing #Russian APT #social engineering #UTA0355 #Volexity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:36:25 +0000
════════════════════════
⌗ Tags: #Cyber Security #Device Code #Fake Conference #M365 #OAuth Phishing #Russian APT #social engineering #UTA0355 #Volexity
Daily CyberSecurity
Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support
Volexity exposed Russian APT UTA0355 using fake security conference sites and WhatsApp support to trick victims. The attacks steal Microsoft 365 OAuth and Device Code tokens for persistent access.
⤷ Title: Stealth Supply Chain Attack: Malicious Rust Crate Used Unpinned Dependency for Silent Payload Upgrades
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:33:32 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Credential Theft #Rust #sha_rust #supply chain attack #Typosquatting #Unpinned Dependency
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:33:32 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Credential Theft #Rust #sha_rust #supply chain attack #Typosquatting #Unpinned Dependency
Daily CyberSecurity
Stealth Supply Chain Attack: Malicious Rust Crate Used Unpinned Dependency for Silent Payload Upgrades
A Rust supply chain attack used typosquatting (finch-rust) and an unpinned dependency to silently update the sha-rust payload over two weeks, stealing credentials and private keys from developers.
⤷ Title: CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
Daily CyberSecurity
CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
CISA/NSA exposed BRICKSTORM, a Chinese state-sponsored backdoor targeting VMware vCenter/ESXi and ADFS servers. The self-restarting malware used DoH and nested TLS for 18 months of persistent espionage.
⤷ Title: High-Severity lz4-java Flaw (CVE-2025-66566) Leaks Uninitialized Memory During Decompression
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Compression #CVE_2025_66566 #Information Disclosure #Java security #lz4_java #Memory Leak #Uninitialized Buffer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Compression #CVE_2025_66566 #Information Disclosure #Java security #lz4_java #Memory Leak #Uninitialized Buffer
Daily CyberSecurity
High-Severity lz4-java Flaw (CVE-2025-66566) Leaks Uninitialized Memory During Decompression
A High-severity flaw (CVE-2025-66566) in lz4-java allows remote attackers to read uninitialized memory (passwords/keys) from recycled buffers during decompression. Update to v1.10.1 immediately.
⤷ Title: Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
Daily CyberSecurity
Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
A Critical (CVSS 9.9) Auth Bypass flaw (CVE-2025-66489) in Cal.com allows attackers to bypass password checks and hijack accounts by supplying any value in the TOTP field. Update to v5.9.8.
⤷ Title: High-Severity WatchGuard Flaws Risk VPN DoS and RCE via IKEv2 Memory Corruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_11838 #Denial of Service #Firebox #IKEv2 #VPN security #WatchGuard #Xpath injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_11838 #Denial of Service #Firebox #IKEv2 #VPN security #WatchGuard #Xpath injection
Daily CyberSecurity
High-Severity WatchGuard Flaws Risk VPN DoS and RCE via IKEv2 Memory Corruption
WatchGuard patched five flaws in Fireware OS. CVE-2025-11838 (CVSS 8.7) allows unauthenticated VPN DoS, while CLI Command Injection risks RCE in the management interface. Update immediately to v2025.1.3.
⤷ Title: Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
Daily CyberSecurity
Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
FortiGuard exposed UDPGangster, a custom UDP backdoor deployed by MuddyWater APT. The malware evades network defenses and analysis by using UDP for C2 and checking for single-core CPUs/low RAM.
⤷ Title: Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via “smack” iOS Exploit Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
Daily CyberSecurity
Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via "smack" iOS Exploit Chain
Google exposed Intellexa (Predator spyware vendor) using 15 zero-days since 2021, including the iOS "smack" exploit chain (JSKit). Google is issuing mass warnings to targeted users globally.
⤷ Title: urllib3 Flaws Risk Client DoS via Unbounded Decompression and Streaming Resource Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_66418 #Decompression Bomb #Denial of Service #dos #Python #Urllib3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_66418 #Decompression Bomb #Denial of Service #dos #Python #Urllib3
Daily CyberSecurity
urllib3 Flaws Risk Client DoS via Unbounded Decompression and Streaming Resource Exhaustion
A Critical DoS flaw (CVE-2025-66418) in urllib3 allows malicious servers to crash client apps via an unbounded decompression chain. A streaming flaw also risks memory exhaustion. Update to v2.6.0.
⤷ Title: ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #English_Speaking Targets #Foxit PDF reader #Job Scams #malware #Remote Access Trojan #ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #English_Speaking Targets #Foxit PDF reader #Job Scams #malware #Remote Access Trojan #ValleyRAT
Daily CyberSecurity
ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
A new ValleyRAT campaign targets English job seekers. The malware uses DLL sideloading via a trojanized Foxit PDF Reader executable to run a Remote Access Trojan and exfiltrate data.