⤷ Title: JS#SMUGGLER Malware Evades EDR Using “Junk Code” JavaScript and Fileless PowerShell to Deploy NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:14:50 +0000
════════════════════════
⌗ Tags: #Malware #fileless #HTA #JS#SMUGGLER #Junk Code Obfuscation #LOLBins #NetSupport RAT #powershell #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:14:50 +0000
════════════════════════
⌗ Tags: #Malware #fileless #HTA #JS#SMUGGLER #Junk Code Obfuscation #LOLBins #NetSupport RAT #powershell #Supply Chain
Daily CyberSecurity
JS#SMUGGLER Malware Evades EDR Using "Junk Code" JavaScript and Fileless PowerShell to Deploy NetSupport RAT
The JS#SMUGGLER campaign uses "Junk Code" JavaScript and fileless PowerShell executed via mshta.exe to bypass EDR. This multi-stage attack silently installs the NetSupport RAT.
⤷ Title: Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:10:46 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #Clipboard Hijacking #rat #rc4 #Remote Access Trojan #Screen Capture #Steam C2 #UAC bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:10:46 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #Clipboard Hijacking #rat #rc4 #Remote Access Trojan #Screen Capture #Steam C2 #UAC bypass
Daily CyberSecurity
Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
A new C-compiled RAT, CastleRAT, uses Steam Community pages to hide its C2. The malware deploys advanced features like UAC Bypass, screen capture, and clipboard hijacking for espionage.
⤷ Title: LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
Daily CyberSecurity
LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
Despite takedown, LockBit 5.0 resurges as a cross-platform threat. The new variant blinds Windows Event Tracing (ETW), uses Invisible Mode for stealth encryption, and overwrites free disk space.
⤷ Title: AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:03:54 +0000
════════════════════════
⌗ Tags: #Windows #AI Actions #Context Menu #File Explorer #Microsoft Copilot #UI Clutter #User Feedback #Windows 11 #Windows Build 26220
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:03:54 +0000
════════════════════════
⌗ Tags: #Windows #AI Actions #Context Menu #File Explorer #Microsoft Copilot #UI Clutter #User Feedback #Windows 11 #Windows Build 26220
Daily CyberSecurity
AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu
Responding to user complaints, Windows 11 Build 26220 adds a setting to disable AI actions in the File Explorer context menu, reducing significant UI clutter.
⤷ Title: Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Technology #AI services #Antitrust #Apple Contract #Behavioral Remedy #Bing #Default Search #DuckDuckGo #google #Judge Amit Mehta #monopoly
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:00:17 +0000
════════════════════════
⌗ Tags: #Technology #AI services #Antitrust #Apple Contract #Behavioral Remedy #Bing #Default Search #DuckDuckGo #google #Judge Amit Mehta #monopoly
Daily CyberSecurity
Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term
⤷ Title: Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:51:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty #programming #cybersecurity
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:51:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #technology #bug_bounty #programming #cybersecurity
Medium
Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works
The Exact Recon → Bug → Report Flow That Still Pays in 2025
⤷ Title: API8:2023 Security Misconfiguration: Detección, Impacto y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:02:12 GMT
════════════════════════
⌗ Tags: #hacking #api #bug_bounty #cybersecurity #technology
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:02:12 GMT
════════════════════════
⌗ Tags: #hacking #api #bug_bounty #cybersecurity #technology
Medium
API8:2023 Security Misconfiguration: Detección, Impacto y Mitigación
Guía completa sobre la vulnerabilidad API8:2023 (Security Misconfiguration): Ejemplos, metodología de detección y mitigación esencial.
⤷ Title: Subdomain Takeover in 2025 — New Methods + Tools
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:41:31 GMT
════════════════════════
⌗ Tags: #hacking #tech #cybersecurity #ai #programming
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:41:31 GMT
════════════════════════
⌗ Tags: #hacking #tech #cybersecurity #ai #programming
Medium
Subdomain Takeover in 2025 🌐 — New Methods + Tools
Hi Vipul from The Hacker’s Log here 👋 Today we’re diving into one of the most powerful bug bounty techniques that still works beautifully
⤷ Title: Eleven Devices That Help You Read Environments Like A System
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:57:38 GMT
════════════════════════
⌗ Tags: #hacking #devops #tools #electronics #cybersecurity
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:57:38 GMT
════════════════════════
⌗ Tags: #hacking #devops #tools #electronics #cybersecurity
Medium
Eleven Devices That Help You Read Environments Like A System
There is a point in your life as an operator, builder, or diagnostician where you stop “looking at a place” and start “reading it.” The…
⤷ Title: Terrorism and crime research tools for OSINT investigators
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:51:10 GMT
════════════════════════
⌗ Tags: #osint #osint_investigation #tools #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 01:51:10 GMT
════════════════════════
⌗ Tags: #osint #osint_investigation #tools #cybersecurity #ethical_hacking
Medium
Terrorism and crime research tools for OSINT investigators
These will be helpful in your journey
⤷ Title: Stealthy Spies: MuddyWater Deploys UDPGangster to Evade Network Defenses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:54:01 +0000
════════════════════════
⌗ Tags: #Malware #APT #Azerbaijan #cyber attack #Cyber Espionage #Fortinet #Israel #malware #MuddyWater #phishing #Turkey #UDPGangster
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:54:01 +0000
════════════════════════
⌗ Tags: #Malware #APT #Azerbaijan #cyber attack #Cyber Espionage #Fortinet #Israel #malware #MuddyWater #phishing #Turkey #UDPGangster
Penetration Testing Tools
Stealthy Spies: MuddyWater Deploys UDPGangster to Evade Network Defenses
The Iranian threat group MuddyWater has intensified its cyber-espionage operations with the deployment of a new malicious program
⤷ Title: CISA’s Stark Mobile Security Warning: Stop Using Personal VPNs Now?
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:53:01 +0000
════════════════════════
⌗ Tags: #Information Security #Android #CISA #Cyber Attack Surface #cybersecurity #Data Protection #iphone #mobile security #privacy #Surveillance #VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:53:01 +0000
════════════════════════
⌗ Tags: #Information Security #Android #CISA #Cyber Attack Surface #cybersecurity #Data Protection #iphone #mobile security #privacy #Surveillance #VPN
Penetration Testing Tools
CISA's Stark Mobile Security Warning: Stop Using Personal VPNs Now?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in its newly issued mobile communications guidelines, has delivered a
⤷ Title: Portugal Grants Legal Protection to Ethical Hackers for Vulnerability Disclosure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:50:13 +0000
════════════════════════
⌗ Tags: #Information Security #bug bounty #CNCS #Cybersecurity Law #ethical hacking #Legal Protection #Portugal #Responsible Disclosure #Vulnerability Disclosure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:50:13 +0000
════════════════════════
⌗ Tags: #Information Security #bug bounty #CNCS #Cybersecurity Law #ethical hacking #Legal Protection #Portugal #Responsible Disclosure #Vulnerability Disclosure
Penetration Testing Tools
Portugal Grants Legal Protection to Ethical Hackers for Vulnerability Disclosure
Portugal has expanded its legal framework in the realm of digital security, formally establishing protections for good-faith specialists
⤷ Title: Tiny Core Linux 16.2: Fully Functional Graphical OS Fits in Just 23 MB
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:49:21 +0000
════════════════════════
⌗ Tags: #Linux #BusyBox #embedded systems #FLTK/FLWM #Linux 16.2 #Minimalist OS #obsolete hardware #RAM_based #Tiny Core Linux
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:49:21 +0000
════════════════════════
⌗ Tags: #Linux #BusyBox #embedded systems #FLTK/FLWM #Linux 16.2 #Minimalist OS #obsolete hardware #RAM_based #Tiny Core Linux
Penetration Testing Tools
Tiny Core Linux 16.2: Fully Functional Graphical OS Fits in Just 23 MB
The new release of Tiny Core Linux illustrates just how far the philosophy of minimalism can be taken
⤷ Title: Upbit Solana Hack: 100 Billion Tokens Stolen, Exchange Delay Avoids Penalties
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:46:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BONK #Crypto Exchange #Financial Supervisory Service #Regulatory Gap #Solana #Solana Exploit #Token Hack #Upbit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:46:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BONK #Crypto Exchange #Financial Supervisory Service #Regulatory Gap #Solana #Solana Exploit #Token Hack #Upbit
Penetration Testing Tools
Upbit Solana Hack: 100 Billion Tokens Stolen, Exchange Delay Avoids Penalties
Hackers siphoned more than 100 billion tokens from Upbit in just 54 minutes, exploiting a flaw in Solana
⤷ Title: Sauron: Fast Active Directory Tool Maps Credential Privileges and Nested Groups in Seconds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:42:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD Enumeration #Credential Context #cybersecurity #Group Policy #LDAP #post_exploitation #Red Team Tool #Sauron
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:42:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #AD Enumeration #Credential Context #cybersecurity #Group Policy #LDAP #post_exploitation #Red Team Tool #Sauron
Penetration Testing Tools
Sauron: Fast Active Directory Tool Maps Credential Privileges and Nested Groups in Seconds
Sauron is a fast AD tool for post-exploitation. It provides instant context on new credentials, resolving nested groups, OUs, GPO inheritance, and account metadata via LDAP.
⤷ Title: Google Titans & MIRAS: New Architecture for 2M+ Token Long-Term AI Memory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:34:26 +0000
════════════════════════
⌗ Tags: #Google #AI Architecture #Associative Memory #Google Research #Long_Context #MIRAS #RNN #Surprise Metric #Titans #Transformer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:34:26 +0000
════════════════════════
⌗ Tags: #Google #AI Architecture #Associative Memory #Google Research #Long_Context #MIRAS #RNN #Surprise Metric #Titans #Transformer
Penetration Testing Tools
Google Titans & MIRAS: New Architecture for 2M+ Token Long-Term AI Memory
Google has unveiled a new architecture for processing long sequences, Titans, along with a theoretical framework, MIRAS, which
⤷ Title: Zero-JS Clickjacking: SVG Filters Exploit iFrames to Steal Cross-Origin Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:32:53 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chromium #clickjacking #Cross_Origin #feBlend #Firefox #iFrame #Lira Rebane #SVG Filter #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:32:53 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chromium #clickjacking #Cross_Origin #feBlend #Firefox #iFrame #Lira Rebane #SVG Filter #web security
⤷ Title: Apple & Google Issue New Spyware Alerts, Targeting Intellexa Zero-Day Victims
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:28:46 +0000
════════════════════════
⌗ Tags: #Malware #Apple #google #Intellexa #Spyware Alerts #State_Linked Attacks #Surveillance Tech #Threat Analysis Group #Zero_Day Exploitation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:28:46 +0000
════════════════════════
⌗ Tags: #Malware #Apple #google #Intellexa #Spyware Alerts #State_Linked Attacks #Surveillance Tech #Threat Analysis Group #Zero_Day Exploitation
Penetration Testing Tools
Apple & Google Issue New Spyware Alerts, Targeting Intellexa Zero-Day Victims
The world’s largest technology companies have begun issuing notifications to users who may have been targeted by state-linked
⤷ Title: Cloudflare Outage Caused by Frantic Patching of Critical React2Shell (CVE-2025-55182) Flaw
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:27:51 +0000
════════════════════════
⌗ Tags: #Technology #Vulnerability #Chinese APT #Cloudflare #CVE_2025_55182 #Deserialization Flaw #Emergency Patch #Internet Fragility #Outage #React2Shell #WAF Configuration
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:27:51 +0000
════════════════════════
⌗ Tags: #Technology #Vulnerability #Chinese APT #Cloudflare #CVE_2025_55182 #Deserialization Flaw #Emergency Patch #Internet Fragility #Outage #React2Shell #WAF Configuration
Penetration Testing Tools
Cloudflare Outage Caused by Frantic Patching of Critical React2Shell (CVE-2025-55182) Flaw
Cloudflare’s global infrastructure has suffered a second major outage in less than a month — and it has
⤷ Title: FBI Warns: Deepfake Kidnapping Scams Use AI to Fabricate Image ‘Proof’ for Extortion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:19:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Fraud #Deepfake Scam #FBI Warning #Image Manipulation #Kidnapping Extortion #Missing Persons #Social Engineering #WormGPT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:19:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Fraud #Deepfake Scam #FBI Warning #Image Manipulation #Kidnapping Extortion #Missing Persons #Social Engineering #WormGPT
Penetration Testing Tools
FBI Warns: Deepfake Kidnapping Scams Use AI to Fabricate Image 'Proof' for Extortion
Malefactors are increasingly exploiting photographs and video clips sourced from open platforms, presenting them as “evidence” of an