⤷ Title: Insecure Deserialization — Overview
════════════════════════
𐀪 Author: Yassin Khadrawy
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 21:30:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #insecure_deserialization #pentesting #cybersecurity #insecurity
════════════════════════
𐀪 Author: Yassin Khadrawy
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 21:30:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #insecure_deserialization #pentesting #cybersecurity #insecurity
Medium
Insecure Deserialization — Overview
Serialization and deserialization are common operations in modern web applications. But when misused, they open the door to one of the…
⤷ Title: Basics Commands of Kali-Linux for Ethical Hacking (PART-1)
════════════════════════
𐀪 Author: Akhil Thakur
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 20:10:07 GMT
════════════════════════
⌗ Tags: #kali_linux #programming #ethical_hacking #basics #easy
════════════════════════
𐀪 Author: Akhil Thakur
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 20:10:07 GMT
════════════════════════
⌗ Tags: #kali_linux #programming #ethical_hacking #basics #easy
Medium
Basics Commands of Kali-Linux for Ethical Hacking (PART-1)
Learn how to use basic commands in Kali-Linux that will help in ethical hacking
⤷ Title: The Day I Found a Public Laravel Log Viewer — And Why It Could Have Exposed an Entire Hospital…
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 22:20:11 GMT
════════════════════════
⌗ Tags: #hacking #hacker_news #bug_bounty #bug_bounty_tips #hackerone
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 22:20:11 GMT
════════════════════════
⌗ Tags: #hacking #hacker_news #bug_bounty #bug_bounty_tips #hackerone
Medium
📜 The Day I Found a Public Laravel Log Viewer — And Why It Could Have Exposed an Entire Hospital System
Bug bounty hunting isn’t always about breaking into systems or crafting clever payloads. Sometimes, it’s about discovering something…
⤷ Title: When One Slash Broke the Rules — Finding an Open Redirect on a Major Marketplace
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 22:19:51 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #bug_bounty #bug_hunting #hackerone
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 22:19:51 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #bug_bounty #bug_hunting #hackerone
Medium
🎯 When One Slash Broke the Rules — Finding an Open Redirect on a Major Marketplace
Some bugs are loud and dramatic. Others slip in quietly, hiding in tiny assumptions — like how a website handles its URLs.
⤷ Title: My CPTS Exam Experience (Part 2): The Midpoint, The 12 Flags, and All the Mistakes I Made
════════════════════════
𐀪 Author: Kentucky Mathitis
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 23:12:13 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #hackthebox #pentesting #learning_to_code
════════════════════════
𐀪 Author: Kentucky Mathitis
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 23:12:13 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #hackthebox #pentesting #learning_to_code
Medium
My CPTS Exam Experience (Part 2): The Midpoint, The 12 Flags, and All the Mistakes I Made
How I pushed myself to six flags by Day 3, hit dead ends, wasted over 12 hours, restarted environments, and eventually reached all 12 flags…
⤷ Title: XSS TO SSRF INTO THE NEXT JS THAT VULNERABLE TO REACT2SHELL NEW CVE-2025–66478
════════════════════════
𐀪 Author: Ahmed Ibrahim
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 22:11:26 GMT
════════════════════════
⌗ Tags: #xss_attack #ssrf #react2shell
════════════════════════
𐀪 Author: Ahmed Ibrahim
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 22:11:26 GMT
════════════════════════
⌗ Tags: #xss_attack #ssrf #react2shell
Medium
XSS TO SSRF INTO THE NEXT JS THAT VULNERABLE TO REACT2SHELL NEW CVE-2025–66478
This is the challenge where I achieved second blood: XSS → SSRF → RCE
⤷ Title: Samsung Foundry Hits 60% 4nm Yield, Secures $100M AI Chip Order from Tsavorite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:50:35 +0000
════════════════════════
⌗ Tags: #Technology #4nm Yield #AI chip #Exynos 2600 #Foundry Wars #OPU Chip #Samsung Foundry #semiconductor #Tsavorite #TSMC Rivalry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:50:35 +0000
════════════════════════
⌗ Tags: #Technology #4nm Yield #AI chip #Exynos 2600 #Foundry Wars #OPU Chip #Samsung Foundry #semiconductor #Tsavorite #TSMC Rivalry
Daily CyberSecurity
Samsung Foundry Hits 60% 4nm Yield, Secures $100M AI Chip Order from Tsavorite
Samsung Foundry reached 60-70% 4nm yield, securing a $100M order for OPU chips from US AI startup Tsavorite, signaling recovery in high-end chip production.
⤷ Title: Ad Code Found in ChatGPT Android Build, OpenAI Denies Current Advertising Tests
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:47:52 +0000
════════════════════════
⌗ Tags: #Technology #advertising #Android Build #ChatGPT #Nick Turley #OpenAI #Revenue Model #Search Ads #Speculation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:47:52 +0000
════════════════════════
⌗ Tags: #Technology #advertising #Android Build #ChatGPT #Nick Turley #OpenAI #Revenue Model #Search Ads #Speculation
Daily CyberSecurity
Ad Code Found in ChatGPT Android Build, OpenAI Denies Current Advertising Tests
Code for "search ads" was found in a ChatGPT Android build. OpenAI officially denied current testing, but high operational costs keep advertising speculation alive.
⤷ Title: AI Uncovers GhostPenguin: Undetectable Linux Backdoor Used RC5-Encrypted UDP for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:50:48 +0000
════════════════════════
⌗ Tags: #Malware #AI_Driven Detection #GhostPenguin #Linux Backdoor #RC5 Encryption #Threat Hunting #UDP C2 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:50:48 +0000
════════════════════════
⌗ Tags: #Malware #AI_Driven Detection #GhostPenguin #Linux Backdoor #RC5 Encryption #Threat Hunting #UDP C2 #zero_day
Daily CyberSecurity
AI Uncovers GhostPenguin: Undetectable Linux Backdoor Used RC5-Encrypted UDP for Covert C2
A previously undetectable Linux backdoor called GhostPenguin was exposed by AI-driven threat hunting. The C++ malware uses RC5-encrypted UDP for stealthy, multi-threaded C2 operations.
⤷ Title: Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Malware #DLL Doppelganger #EDR Killer #Kernel Abuse #PEB Manipulation #ransomware #Shanya Crypter #Sophos #VX Crypt
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Malware #DLL Doppelganger #EDR Killer #Kernel Abuse #PEB Manipulation #ransomware #Shanya Crypter #Sophos #VX Crypt
Daily CyberSecurity
Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR
The Shanya Crypter (VX Crypt) is a new PaaS used by Akira/Medusa to bypass EDR. It deploys a kernel driver attack to kill security products and uses PEB manipulation for stealth.
⤷ Title: Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:36:29 +0000
════════════════════════
⌗ Tags: #Malware #Beima PHP Webshell #botnet #Cybercrime Freelancing #Education Sites #rce #Undetectable #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:36:29 +0000
════════════════════════
⌗ Tags: #Malware #Beima PHP Webshell #botnet #Cybercrime Freelancing #Education Sites #rce #Undetectable #webshell
Daily CyberSecurity
Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
A college student is selling access to 5,200+ gov/edu sites via the undetectable Beima PHP Webshell. The custom backdoor allows full RCE and fuels a growing cybercrime freelancing marketplace.
⤷ Title: Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:32:24 +0000
════════════════════════
⌗ Tags: #Malware #AES_CFB #backdoor #data exfiltration #dpaste #Go Package #Go Typosquatting #security #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:32:24 +0000
════════════════════════
⌗ Tags: #Malware #AES_CFB #backdoor #data exfiltration #dpaste #Go Package #Go Typosquatting #security #Supply Chain
Daily CyberSecurity
Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected
A malicious Go package typosquat (bpoorman/uuid) operated for four years, using a hidden Valid function to silently encrypt and exfiltrate sensitive data to dpaste.com.
⤷ Title: Silver Fox APT Uses Cyrillic False Flag in Teams SEO Poisoning to Deploy ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:27:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyrillic #False Flag #Microsoft Teams #SEO Poisoning #Silver Fox #Typosquatting #ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:27:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyrillic #False Flag #Microsoft Teams #SEO Poisoning #Silver Fox #Typosquatting #ValleyRAT
Daily CyberSecurity
Silver Fox APT Uses Cyrillic False Flag in Teams SEO Poisoning to Deploy ValleyRAT
Chinese APT Silver Fox is using a Cyrillic false flag in an SEO poisoning campaign impersonating Microsoft Teams. The attack installs ValleyRAT for espionage and financial fraud.
⤷ Title: Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Spyware #ClayRat #dropbox #Keylogger #Lockscreen Bypass #MediaProjection API #Self_Defense
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Spyware #ClayRat #dropbox #Keylogger #Lockscreen Bypass #MediaProjection API #Self_Defense
Daily CyberSecurity
Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys
Evolved ClayRat spyware uses Accessibility Services to install a keylogger and lockscreen bypass. It leverages self-defense (blocking uninstallation) and screen recording for comprehensive surveillance.
⤷ Title: New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:19:40 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #apk0day #banking malware #FvncBot #H.264 #HVNC #mBank #WebSocket C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:19:40 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #apk0day #banking malware #FvncBot #H.264 #HVNC #mBank #WebSocket C2
Daily CyberSecurity
New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming
A unique Android banking trojan, FvncBot, targets mBank (Poland) customers. It uses HVNC and H.264 to stream screens and performs web-inject attacks via FCM/WebSocket C2.
⤷ Title: JS#SMUGGLER Malware Evades EDR Using “Junk Code” JavaScript and Fileless PowerShell to Deploy NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:14:50 +0000
════════════════════════
⌗ Tags: #Malware #fileless #HTA #JS#SMUGGLER #Junk Code Obfuscation #LOLBins #NetSupport RAT #powershell #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:14:50 +0000
════════════════════════
⌗ Tags: #Malware #fileless #HTA #JS#SMUGGLER #Junk Code Obfuscation #LOLBins #NetSupport RAT #powershell #Supply Chain
Daily CyberSecurity
JS#SMUGGLER Malware Evades EDR Using "Junk Code" JavaScript and Fileless PowerShell to Deploy NetSupport RAT
The JS#SMUGGLER campaign uses "Junk Code" JavaScript and fileless PowerShell executed via mshta.exe to bypass EDR. This multi-stage attack silently installs the NetSupport RAT.
⤷ Title: Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:10:46 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #Clipboard Hijacking #rat #rc4 #Remote Access Trojan #Screen Capture #Steam C2 #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:10:46 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #Clipboard Hijacking #rat #rc4 #Remote Access Trojan #Screen Capture #Steam C2 #UAC bypass
Daily CyberSecurity
Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
A new C-compiled RAT, CastleRAT, uses Steam Community pages to hide its C2. The malware deploys advanced features like UAC Bypass, screen capture, and clipboard hijacking for espionage.
⤷ Title: LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
Daily CyberSecurity
LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
Despite takedown, LockBit 5.0 resurges as a cross-platform threat. The new variant blinds Windows Event Tracing (ETW), uses Invisible Mode for stealth encryption, and overwrites free disk space.
⤷ Title: AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:03:54 +0000
════════════════════════
⌗ Tags: #Windows #AI Actions #Context Menu #File Explorer #Microsoft Copilot #UI Clutter #User Feedback #Windows 11 #Windows Build 26220
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:03:54 +0000
════════════════════════
⌗ Tags: #Windows #AI Actions #Context Menu #File Explorer #Microsoft Copilot #UI Clutter #User Feedback #Windows 11 #Windows Build 26220
Daily CyberSecurity
AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu
Responding to user complaints, Windows 11 Build 26220 adds a setting to disable AI actions in the File Explorer context menu, reducing significant UI clutter.
⤷ Title: Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Technology #AI services #Antitrust #Apple Contract #Behavioral Remedy #Bing #Default Search #DuckDuckGo #google #Judge Amit Mehta #monopoly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Technology #AI services #Antitrust #Apple Contract #Behavioral Remedy #Bing #Default Search #DuckDuckGo #google #Judge Amit Mehta #monopoly
Daily CyberSecurity
Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term
⤷ Title: Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:51:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty #programming #cybersecurity
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:51:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty #programming #cybersecurity
Medium
Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works
The Exact Recon → Bug → Report Flow That Still Pays in 2025