⤷ Title: High-Severity Duc Disk Tool Flaw (CVE-2025-13654) Risks DoS and Information Leak via Integer Underflow
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:45:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_13654 #Disk Usage #dos #Duc #Information Disclosure #Integer Underflow #Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:45:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_13654 #Disk Usage #dos #Duc #Information Disclosure #Integer Underflow #Linux
Daily CyberSecurity
High-Severity Duc Disk Tool Flaw (CVE-2025-13654) Risks DoS and Information Leak via Integer Underflow
A High-severity flaw (CVE-2025-13654) in the Duc disk usage tool risks DoS and information leaks. An integer underflow in buffer.c allows out-of-bounds memory read. Update to v1.4.6 immediately.
⤷ Title: “SeedSnatcher” Android Malware Targets Crypto Users, Using Overlay Phishing and BIP 39 Validation to Steal Seed Phrases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:40:39 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #BIP 39 #cryptocurrency #Malware_as_a_Service #Overlay Phishing #Seed Phrase #SeedSnatcher #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:40:39 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #BIP 39 #cryptocurrency #Malware_as_a_Service #Overlay Phishing #Seed Phrase #SeedSnatcher #Telegram
Daily CyberSecurity
"SeedSnatcher" Android Malware Targets Crypto Users, Using Overlay Phishing and BIP 39 Validation to Steal Seed Phrases
A dangerous new Android malware called SeedSnatcher targets crypto users with overlay phishing on MetaMask/Trust Wallet. It uses BIP 39 validation to steal seed phrases and supports remote command execution for total device control.
⤷ Title: Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:36:25 +0000
════════════════════════
⌗ Tags: #Cyber Security #Device Code #Fake Conference #M365 #OAuth Phishing #Russian APT #social engineering #UTA0355 #Volexity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:36:25 +0000
════════════════════════
⌗ Tags: #Cyber Security #Device Code #Fake Conference #M365 #OAuth Phishing #Russian APT #social engineering #UTA0355 #Volexity
Daily CyberSecurity
Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support
Volexity exposed Russian APT UTA0355 using fake security conference sites and WhatsApp support to trick victims. The attacks steal Microsoft 365 OAuth and Device Code tokens for persistent access.
⤷ Title: Stealth Supply Chain Attack: Malicious Rust Crate Used Unpinned Dependency for Silent Payload Upgrades
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:33:32 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Credential Theft #Rust #sha_rust #supply chain attack #Typosquatting #Unpinned Dependency
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:33:32 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Credential Theft #Rust #sha_rust #supply chain attack #Typosquatting #Unpinned Dependency
Daily CyberSecurity
Stealth Supply Chain Attack: Malicious Rust Crate Used Unpinned Dependency for Silent Payload Upgrades
A Rust supply chain attack used typosquatting (finch-rust) and an unpinned dependency to silently update the sha-rust payload over two weeks, stealing credentials and private keys from developers.
⤷ Title: CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
Daily CyberSecurity
CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
CISA/NSA exposed BRICKSTORM, a Chinese state-sponsored backdoor targeting VMware vCenter/ESXi and ADFS servers. The self-restarting malware used DoH and nested TLS for 18 months of persistent espionage.
⤷ Title: High-Severity lz4-java Flaw (CVE-2025-66566) Leaks Uninitialized Memory During Decompression
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Compression #CVE_2025_66566 #Information Disclosure #Java security #lz4_java #Memory Leak #Uninitialized Buffer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Compression #CVE_2025_66566 #Information Disclosure #Java security #lz4_java #Memory Leak #Uninitialized Buffer
Daily CyberSecurity
High-Severity lz4-java Flaw (CVE-2025-66566) Leaks Uninitialized Memory During Decompression
A High-severity flaw (CVE-2025-66566) in lz4-java allows remote attackers to read uninitialized memory (passwords/keys) from recycled buffers during decompression. Update to v1.10.1 immediately.
⤷ Title: Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
Daily CyberSecurity
Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
A Critical (CVSS 9.9) Auth Bypass flaw (CVE-2025-66489) in Cal.com allows attackers to bypass password checks and hijack accounts by supplying any value in the TOTP field. Update to v5.9.8.
⤷ Title: High-Severity WatchGuard Flaws Risk VPN DoS and RCE via IKEv2 Memory Corruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_11838 #Denial of Service #Firebox #IKEv2 #VPN security #WatchGuard #Xpath injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_11838 #Denial of Service #Firebox #IKEv2 #VPN security #WatchGuard #Xpath injection
Daily CyberSecurity
High-Severity WatchGuard Flaws Risk VPN DoS and RCE via IKEv2 Memory Corruption
WatchGuard patched five flaws in Fireware OS. CVE-2025-11838 (CVSS 8.7) allows unauthenticated VPN DoS, while CLI Command Injection risks RCE in the management interface. Update immediately to v2025.1.3.
⤷ Title: Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
Daily CyberSecurity
Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
FortiGuard exposed UDPGangster, a custom UDP backdoor deployed by MuddyWater APT. The malware evades network defenses and analysis by using UDP for C2 and checking for single-core CPUs/low RAM.
⤷ Title: Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via “smack” iOS Exploit Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
Daily CyberSecurity
Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via "smack" iOS Exploit Chain
Google exposed Intellexa (Predator spyware vendor) using 15 zero-days since 2021, including the iOS "smack" exploit chain (JSKit). Google is issuing mass warnings to targeted users globally.
⤷ Title: urllib3 Flaws Risk Client DoS via Unbounded Decompression and Streaming Resource Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_66418 #Decompression Bomb #Denial of Service #dos #Python #Urllib3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_66418 #Decompression Bomb #Denial of Service #dos #Python #Urllib3
Daily CyberSecurity
urllib3 Flaws Risk Client DoS via Unbounded Decompression and Streaming Resource Exhaustion
A Critical DoS flaw (CVE-2025-66418) in urllib3 allows malicious servers to crash client apps via an unbounded decompression chain. A streaming flaw also risks memory exhaustion. Update to v2.6.0.
⤷ Title: ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #English_Speaking Targets #Foxit PDF reader #Job Scams #malware #Remote Access Trojan #ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #English_Speaking Targets #Foxit PDF reader #Job Scams #malware #Remote Access Trojan #ValleyRAT
Daily CyberSecurity
ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
A new ValleyRAT campaign targets English job seekers. The malware uses DLL sideloading via a trojanized Foxit PDF Reader executable to run a Remote Access Trojan and exfiltrate data.
⤷ Title: Ghost in the WAF: Building “WAF-Whisper” — An Adaptive Evasion Engine
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #software_engineering #python #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #software_engineering #python #ethical_hacking #cybersecurity
Medium
👻 Ghost in the WAF: Building “WAF-Whisper” — An Adaptive Evasion Engine
“Engineering an Intelligent Python Framework to Defeat Modern Firewalls”
⤷ Title: How Developers Can Quickly Validate Application Security Before Deployment (2025 Guide)
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:47:08 GMT
════════════════════════
⌗ Tags: #app_development #cybersecurity #information_security
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:47:08 GMT
════════════════════════
⌗ Tags: #app_development #cybersecurity #information_security
Medium
How Developers Can Quickly Validate Application Security Before Deployment (2025 Guide)
A Fast, Practical Checklist for Busy Engineers
⤷ Title: The Mandatory Website Security Checklist for Your Business (2025 Edition)
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:42:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #website #information_security
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:42:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #website #information_security
Medium
The Mandatory Website Security Checklist for Your Business (2025 Edition)
A Practical, Actionable Guide for SMEs in Southeast Asia
⤷ Title: Malspam targeted at Brazilian WhatsApp users
════════════════════════
𐀪 Author: Rafael Batista
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:41:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #whatsapp #brasil #cybercrime #threat_intelligence
════════════════════════
𐀪 Author: Rafael Batista
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:41:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #whatsapp #brasil #cybercrime #threat_intelligence
Medium
Malspam targeted at Brazilian WhatsApp users
📁 THREAT INTELLIGENCE REPORT: “Zip-Lure” Campaign via WhatsApp
⤷ Title: DEFENSE- IN -DEPTH : THAT FOOTBALL, MOVIE AND ADULT SITE WILL RUIN YOUR LIFE
════════════════════════
𐀪 Author: Oyeniyi Oluwatayo James
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:23:03 GMT
════════════════════════
⌗ Tags: #safety #football #ai #technology #cybersecurity
════════════════════════
𐀪 Author: Oyeniyi Oluwatayo James
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:23:03 GMT
════════════════════════
⌗ Tags: #safety #football #ai #technology #cybersecurity
Medium
DEFENSE- IN -DEPTH : THAT FOOTBALL, MOVIE AND ADULT SITE WILL RUIN YOUR LIFE
Football is life, connecting millions from all over the globe in a sport that binds fans in love and rivals in hate, but in the throes of…
⤷ Title: Bypassing PHP Disable Functions with LD_PRELOAD
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:18:12 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #penetration_testing #php #web_security
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:18:12 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #penetration_testing #php #web_security
Medium
Bypassing PHP Disable Functions with LD_PRELOAD
⤷ Title: Basic Pentesting Walkthrough with Python Automation
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:17:57 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #penetration_testing #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:17:57 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #penetration_testing #ethical_hacking #cybersecurity
Medium
Basic Pentesting Walkthrough with Python Automation
This write-up documents solving a “Basic Pentesting” style web application CTF by combining classic enumeration techniques with a bit of…
⤷ Title: ️ Stop the Stalkers: Why Your Digital Life is Up For Sale and How to Reclaim It
You’re Not a…
════════════════════════
𐀪 Author: Kim Brown
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:50:31 GMT
════════════════════════
⌗ Tags: #data_privacy #cybersecurity #data_protection #privacy
You’re Not a…
════════════════════════
𐀪 Author: Kim Brown
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:50:31 GMT
════════════════════════
⌗ Tags: #data_privacy #cybersecurity #data_protection #privacy
Medium
🛡️ Stop the Stalkers: Why Your Digital Life is Up For Sale and How to Reclaim It You’re Not a Product. Stop Letting Data Brokers…
Did you know that thousands of shady companies, known as data brokers, are collecting every detail about your life—from your purchase…
⤷ Title: Rising Android Threat Targeting Mobile Banking Users
════════════════════════
𐀪 Author: Geoffrey Wenger
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #android #mobile #information_technology #information_security
════════════════════════
𐀪 Author: Geoffrey Wenger
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #android #mobile #information_technology #information_security
Medium
Rising Android Threat Targeting Mobile Banking Users
A new strain of Android malware is drawing attention for how easily it can slip into a device and take control of mobile banking activity…