⤷ Title: CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Malware #ADFS #BRICKSTORM #China APT #CISA #cyber_espionage #DoH #NSA #persistence #vmware
Daily CyberSecurity
CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
CISA/NSA exposed BRICKSTORM, a Chinese state-sponsored backdoor targeting VMware vCenter/ESXi and ADFS servers. The self-restarting malware used DoH and nested TLS for 18 months of persistent espionage.
⤷ Title: High-Severity lz4-java Flaw (CVE-2025-66566) Leaks Uninitialized Memory During Decompression
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Compression #CVE_2025_66566 #Information Disclosure #Java security #lz4_java #Memory Leak #Uninitialized Buffer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Compression #CVE_2025_66566 #Information Disclosure #Java security #lz4_java #Memory Leak #Uninitialized Buffer
Daily CyberSecurity
High-Severity lz4-java Flaw (CVE-2025-66566) Leaks Uninitialized Memory During Decompression
A High-severity flaw (CVE-2025-66566) in lz4-java allows remote attackers to read uninitialized memory (passwords/keys) from recycled buffers during decompression. Update to v1.10.1 immediately.
⤷ Title: Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:22:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #2FA bypass #Account Hijacking #Authentication Bypass #Cal.com #Critical Vulnerability #CVE_2025_66489 #TOTP
Daily CyberSecurity
Critical Cal.com Flaw (CVE-2025-66489, CVSS 9.9) Allows Authentication Bypass by Submitting Fake TOTP Codes
A Critical (CVSS 9.9) Auth Bypass flaw (CVE-2025-66489) in Cal.com allows attackers to bypass password checks and hijack accounts by supplying any value in the TOTP field. Update to v5.9.8.
⤷ Title: High-Severity WatchGuard Flaws Risk VPN DoS and RCE via IKEv2 Memory Corruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_11838 #Denial of Service #Firebox #IKEv2 #VPN security #WatchGuard #Xpath injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_11838 #Denial of Service #Firebox #IKEv2 #VPN security #WatchGuard #Xpath injection
Daily CyberSecurity
High-Severity WatchGuard Flaws Risk VPN DoS and RCE via IKEv2 Memory Corruption
WatchGuard patched five flaws in Fireware OS. CVE-2025-11838 (CVSS 8.7) allows unauthenticated VPN DoS, while CLI Command Injection risks RCE in the management interface. Update immediately to v2025.1.3.
⤷ Title: Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:18:41 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #APT #Espionage #MuddyWater #spear_phishing #Turkey #UDP C2 #UDPGangster
Daily CyberSecurity
Iran-Linked MuddyWater Deploys UDPGangster Backdoor, Using UDP Protocol for Covert C2
FortiGuard exposed UDPGangster, a custom UDP backdoor deployed by MuddyWater APT. The malware evades network defenses and analysis by using UDP for C2 and checking for single-core CPUs/low RAM.
⤷ Title: Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via “smack” iOS Exploit Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #Commercial Surveillance #cyber_espionage #GTIG #Intellexa #iOS Exploit #JSKit #Predator spyware #zero_day
Daily CyberSecurity
Spyware Vendor Intellexa Used 15 Zero-Days Since 2021, Deploying Predator via "smack" iOS Exploit Chain
Google exposed Intellexa (Predator spyware vendor) using 15 zero-days since 2021, including the iOS "smack" exploit chain (JSKit). Google is issuing mass warnings to targeted users globally.
⤷ Title: urllib3 Flaws Risk Client DoS via Unbounded Decompression and Streaming Resource Exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_66418 #Decompression Bomb #Denial of Service #dos #Python #Urllib3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_66418 #Decompression Bomb #Denial of Service #dos #Python #Urllib3
Daily CyberSecurity
urllib3 Flaws Risk Client DoS via Unbounded Decompression and Streaming Resource Exhaustion
A Critical DoS flaw (CVE-2025-66418) in urllib3 allows malicious servers to crash client apps via an unbounded decompression chain. A streaming flaw also risks memory exhaustion. Update to v2.6.0.
⤷ Title: ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #English_Speaking Targets #Foxit PDF reader #Job Scams #malware #Remote Access Trojan #ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #English_Speaking Targets #Foxit PDF reader #Job Scams #malware #Remote Access Trojan #ValleyRAT
Daily CyberSecurity
ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
A new ValleyRAT campaign targets English job seekers. The malware uses DLL sideloading via a trojanized Foxit PDF Reader executable to run a Remote Access Trojan and exfiltrate data.
⤷ Title: Ghost in the WAF: Building “WAF-Whisper” — An Adaptive Evasion Engine
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #software_engineering #python #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #bug_bounty #software_engineering #python #ethical_hacking #cybersecurity
Medium
👻 Ghost in the WAF: Building “WAF-Whisper” — An Adaptive Evasion Engine
“Engineering an Intelligent Python Framework to Defeat Modern Firewalls”
⤷ Title: How Developers Can Quickly Validate Application Security Before Deployment (2025 Guide)
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:47:08 GMT
════════════════════════
⌗ Tags: #app_development #cybersecurity #information_security
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:47:08 GMT
════════════════════════
⌗ Tags: #app_development #cybersecurity #information_security
Medium
How Developers Can Quickly Validate Application Security Before Deployment (2025 Guide)
A Fast, Practical Checklist for Busy Engineers
⤷ Title: The Mandatory Website Security Checklist for Your Business (2025 Edition)
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:42:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #website #information_security
════════════════════════
𐀪 Author: Vulnersight
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:42:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #website #information_security
Medium
The Mandatory Website Security Checklist for Your Business (2025 Edition)
A Practical, Actionable Guide for SMEs in Southeast Asia
⤷ Title: Malspam targeted at Brazilian WhatsApp users
════════════════════════
𐀪 Author: Rafael Batista
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:41:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #whatsapp #brasil #cybercrime #threat_intelligence
════════════════════════
𐀪 Author: Rafael Batista
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:41:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #whatsapp #brasil #cybercrime #threat_intelligence
Medium
Malspam targeted at Brazilian WhatsApp users
📁 THREAT INTELLIGENCE REPORT: “Zip-Lure” Campaign via WhatsApp
⤷ Title: DEFENSE- IN -DEPTH : THAT FOOTBALL, MOVIE AND ADULT SITE WILL RUIN YOUR LIFE
════════════════════════
𐀪 Author: Oyeniyi Oluwatayo James
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:23:03 GMT
════════════════════════
⌗ Tags: #safety #football #ai #technology #cybersecurity
════════════════════════
𐀪 Author: Oyeniyi Oluwatayo James
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:23:03 GMT
════════════════════════
⌗ Tags: #safety #football #ai #technology #cybersecurity
Medium
DEFENSE- IN -DEPTH : THAT FOOTBALL, MOVIE AND ADULT SITE WILL RUIN YOUR LIFE
Football is life, connecting millions from all over the globe in a sport that binds fans in love and rivals in hate, but in the throes of…
⤷ Title: Bypassing PHP Disable Functions with LD_PRELOAD
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:18:12 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #penetration_testing #php #web_security
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:18:12 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #penetration_testing #php #web_security
Medium
Bypassing PHP Disable Functions with LD_PRELOAD
⤷ Title: Basic Pentesting Walkthrough with Python Automation
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:17:57 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #penetration_testing #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:17:57 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #penetration_testing #ethical_hacking #cybersecurity
Medium
Basic Pentesting Walkthrough with Python Automation
This write-up documents solving a “Basic Pentesting” style web application CTF by combining classic enumeration techniques with a bit of…
⤷ Title: ️ Stop the Stalkers: Why Your Digital Life is Up For Sale and How to Reclaim It
You’re Not a…
════════════════════════
𐀪 Author: Kim Brown
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:50:31 GMT
════════════════════════
⌗ Tags: #data_privacy #cybersecurity #data_protection #privacy
You’re Not a…
════════════════════════
𐀪 Author: Kim Brown
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:50:31 GMT
════════════════════════
⌗ Tags: #data_privacy #cybersecurity #data_protection #privacy
Medium
🛡️ Stop the Stalkers: Why Your Digital Life is Up For Sale and How to Reclaim It You’re Not a Product. Stop Letting Data Brokers…
Did you know that thousands of shady companies, known as data brokers, are collecting every detail about your life—from your purchase…
⤷ Title: Rising Android Threat Targeting Mobile Banking Users
════════════════════════
𐀪 Author: Geoffrey Wenger
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #android #mobile #information_technology #information_security
════════════════════════
𐀪 Author: Geoffrey Wenger
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #android #mobile #information_technology #information_security
Medium
Rising Android Threat Targeting Mobile Banking Users
A new strain of Android malware is drawing attention for how easily it can slip into a device and take control of mobile banking activity…
⤷ Title: Virtual Kidnapping Scams Are Evolving Faster Than People Expect
════════════════════════
𐀪 Author: Geoffrey Wenger
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:34:57 GMT
════════════════════════
⌗ Tags: #information_technology #fraud #social_media #scam #cybersecurity
════════════════════════
𐀪 Author: Geoffrey Wenger
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 00:34:57 GMT
════════════════════════
⌗ Tags: #information_technology #fraud #social_media #scam #cybersecurity
Medium
Virtual Kidnapping Scams Are Evolving Faster Than People Expect
Virtual kidnapping scams are rising because criminals know how to use fear, speed, and digital manipulation to overwhelm good judgment…
⤷ Title: The Ultimate Guide to Active Directory LDAP Enumeration Using NetExec
════════════════════════
𐀪 Author: Tareshsharma
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:37:54 GMT
════════════════════════
⌗ Tags: #penetration_testing #ldap_authentication #netexec #active_directory #ldap
════════════════════════
𐀪 Author: Tareshsharma
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:37:54 GMT
════════════════════════
⌗ Tags: #penetration_testing #ldap_authentication #netexec #active_directory #ldap
Medium
The Ultimate Guide to Active Directory LDAP Enumeration Using NetExec
✔️ Computers ✔️ Policies ✔️ Delegations ✔️ Service accounts ✔️ GMSA ✔️ Trusts ✔️ Password policy ✔️ ACLs ✔️ Kerberos settings
⤷ Title: FastAPI + OpenID Connect with PKCE: Secure Mobile & CLI Auth Without SDK Hell
════════════════════════
𐀪 Author: Yamishift
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:32:13 GMT
════════════════════════
⌗ Tags: #fastapi #oauth2 #openid #python #api_security
════════════════════════
𐀪 Author: Yamishift
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 01:32:13 GMT
════════════════════════
⌗ Tags: #fastapi #oauth2 #openid #python #api_security
Medium
FastAPI + OpenID Connect with PKCE: Secure Mobile & CLI Auth Without SDK Hell
Use standards, not black-box SDKs, to give your apps and CLIs clean, secure single sign-on.
⤷ Title: Global Crackdown Dismantles Crypto-Scam Network, Laundering Over €700 Million
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:00:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Asset Seizure #Bitcoin #Call Centers #Crypto Scam #deepfakes #Europol #Financial Crime #International Fraud #Money Laundering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:00:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Asset Seizure #Bitcoin #Call Centers #Crypto Scam #deepfakes #Europol #Financial Crime #International Fraud #Money Laundering
Penetration Testing Tools
Global Crackdown Dismantles Crypto-Scam Network, Laundering Over €700 Million
An international fraud operation has culminated in a sweeping blow against a vast crypto-scam network that laundered more