⤷ Title: Microsoft Patches Three Zero-Days Including Active Cloud Files UAF to SYSTEM and Copilot RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 01:51:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Cloud Files UAF #GitHub Copilot #Microsoft Patch Tuesday #powershell #rce #SYSTEM Privilege #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 01:51:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Cloud Files UAF #GitHub Copilot #Microsoft Patch Tuesday #powershell #rce #SYSTEM Privilege #zero_day
Daily CyberSecurity
Microsoft Patches Three Zero-Days Including Active Cloud Files UAF to SYSTEM and Copilot RCE
Microsoft patched 72 flaws, including three zero-days. Fixes target a Cloud Files UAF exploited for SYSTEM privileges and an RCE in GitHub Copilot. PowerShell gets a new security prompt.
⤷ Title: Critical Ivanti EPM Flaw (CVE-2025-10573) Risks Admin Session Hijack and Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 01:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Critical Vulnerability #CVE_2025_10573 #Ivanti EPM #rce #Session Hijack #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 01:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Critical Vulnerability #CVE_2025_10573 #Ivanti EPM #rce #Session Hijack #XSS
Daily CyberSecurity
Critical Ivanti EPM Flaw (CVE-2025-10573) Risks Admin Session Hijack and Unauthenticated RCE
Ivanti patched four severe flaws in EPM 2024 SU4. A Critical XSS (9.6) allows admin hijack, and an unauthenticated file write (8.8) risks RCE. Update to 2024 SU4 SR 1 immediately.
⤷ Title: OpenAI ‘Code Red’: Sam Altman Halts Projects to Battle Google and Fix a Sycophancy Crisis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:35:46 +0000
════════════════════════
⌗ Tags: #Technology #AGI #AI Ethics #ChatGPT #Code Red #google #GPT_4o #OpenAI #Sam Altman #Sycophancy #User Engagement
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:35:46 +0000
════════════════════════
⌗ Tags: #Technology #AGI #AI Ethics #ChatGPT #Code Red #google #GPT_4o #OpenAI #Sam Altman #Sycophancy #User Engagement
Daily CyberSecurity
OpenAI 'Code Red': Sam Altman Halts Projects to Battle Google and Fix a Sycophancy Crisis
Sam Altman declares "Code Red," freezing projects like Sora to boost ChatGPT's performance. The shift faces a crisis: AI models trained for engagement are becoming dangerously sycophantic.
⤷ Title: IBM Spends $11 Billion on Confluent to Build Its AI ‘Intelligent Data Platform’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:30:10 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #Apache Kafka #Confluent #Data Streaming #enterprise AI #Generative AI #hybrid cloud #IBM #Tech Investment
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:30:10 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #Apache Kafka #Confluent #Data Streaming #enterprise AI #Generative AI #hybrid cloud #IBM #Tech Investment
Daily CyberSecurity
IBM Spends $11 Billion on Confluent to Build Its AI 'Intelligent Data Platform'
IBM acquires data streaming leader Confluent for $11B to fuel its hybrid cloud and AI strategy. The deal aims to break data silos for next-gen AI workloads. (156 characters)
⤷ Title: GrayBravo MaaS Deploys CastleRAT Backdoor, Hiding C2 with Steam Profile Dead Drop Resolvers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleRAT #ClickFix #Dead Drop Resolver #GrayBravo #hospitality #logistics #MaaS #Steam C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleRAT #ClickFix #Dead Drop Resolver #GrayBravo #hospitality #logistics #MaaS #Steam C2
Daily CyberSecurity
GrayBravo MaaS Deploys CastleRAT Backdoor, Hiding C2 with Steam Profile Dead Drop Resolvers
GrayBravo MaaS uses CastleRAT to target logistics/hospitality. The RAT hides its C2 by using Steam Community profiles as Dead Drop Resolvers, bypassing network monitoring.
⤷ Title: High-Severity Rockwell Flaws Risk Industrial SQLi Data Tampering and Safety Device DoS Requiring Manual Fix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:21:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DataMosaix #Denial of Service #FactoryTalk #GuardLink #Industrial Control #OT Security #Rockwell Automation #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:21:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DataMosaix #Denial of Service #FactoryTalk #GuardLink #Industrial Control #OT Security #Rockwell Automation #sql injection
Daily CyberSecurity
High-Severity Rockwell Flaws Risk Industrial SQLi Data Tampering and Safety Device DoS Requiring Manual Fix
Rockwell patched high-severity flaws: SQLi (CVSS 8.8) in FactoryTalk DataMosaix and a DoS (CVSS 7.5) in GuardLink requiring manual power cycle to fix. Update to prevent industrial downtime and data tampering.
⤷ Title: Itch.io Targeted: Lumma Stealer Deployed Via Fake Updates and Reflective Node.js Loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:16:55 +0000
════════════════════════
⌗ Tags: #Malware #Game Update Lure #information stealer #Itch.io #Lumma Stealer #Nexe #Node.js #reflective loading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:16:55 +0000
════════════════════════
⌗ Tags: #Malware #Game Update Lure #information stealer #Itch.io #Lumma Stealer #Nexe #Node.js #reflective loading
Daily CyberSecurity
Itch.io Targeted: Lumma Stealer Deployed Via Fake Updates and Reflective Node.js Loader
A Lumma Stealer campaign is using fake update lures on Itch.io. The malware uses a Node.js-compiled executable and a reflective loading technique to steal passwords and crypto wallets.
⤷ Title: Critical n8n RCE Flaw (CVE-2025-65964) Allows Remote Code Execution via Git Node Configuration Manipulation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:11:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #core.hooksPath #CVE_2025_65964 #Git Node #n8n #rce #Workflow Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:11:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #core.hooksPath #CVE_2025_65964 #Git Node #n8n #rce #Workflow Automation
Daily CyberSecurity
Critical n8n RCE Flaw (CVE-2025-65964) Allows Remote Code Execution via Git Node Configuration Manipulation
A Critical RCE flaw (CVSS 9.4) in the n8n Git Node allows command execution by manipulating the core.hooksPath setting in workflows. Update to v1.119.2 immediately.
⤷ Title: FrostBeacon Hits Russian B2B: Cobalt Strike Deployed via LNK and Chained Legacy Exploits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:05:59 +0000
════════════════════════
⌗ Tags: #Malware #Cobalt Strike #CVE_2017_0199 #Legacy Exploit #LNK File #Operation FrostBeacon #PowerShell Loader #Russian B2B
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:05:59 +0000
════════════════════════
⌗ Tags: #Malware #Cobalt Strike #CVE_2017_0199 #Legacy Exploit #LNK File #Operation FrostBeacon #PowerShell Loader #Russian B2B
Daily CyberSecurity
FrostBeacon Hits Russian B2B: Cobalt Strike Deployed via LNK and Chained Legacy Exploits
Operation FrostBeacon targets Russian B2B with Cobalt Strike. The dual attack uses LNK files and chained legacy exploits (CVE-2017-0199/11882) to gain persistent, financially motivated access.
⤷ Title: Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_67494 #host header injection #Identity Management #ssrf #XSS #ZITADEL
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:00:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_67494 #host header injection #Identity Management #ssrf #XSS #ZITADEL
Daily CyberSecurity
Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS
ZITADEL patched three high-severity flaws. Critical SSRF (9.3) allows internal breach via x-forward-host; XSS and Host Header Injection risk account hijack. Update to v4.7.1 immediately.
⤷ Title: API8:2023 Security Misconfiguration: Detection, Impact, and Mitigation
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:02:19 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #technology #hacking #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:02:19 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #technology #hacking #bug_bounty
Medium
API8:2023 Security Misconfiguration: Detection, Impact, and Mitigation
Complete guide to API8:2023 vulnerability (Security Misconfiguration): Examples, detection methodology, and essential mitigation.
⤷ Title: How I Exploited Blind SSRF to Own an AWS Environment — My Step-by-Step Red Team Hunt
════════════════════════
𐀪 Author: ZAYN
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 01:38:28 GMT
════════════════════════
⌗ Tags: #pentesting #hacking #penetration_testing #penetration_test #web_penetration_testing
════════════════════════
𐀪 Author: ZAYN
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 01:38:28 GMT
════════════════════════
⌗ Tags: #pentesting #hacking #penetration_testing #penetration_test #web_penetration_testing
Medium
How I Exploited Blind SSRF to Own an AWS Environment — My Step-by-Step Red Team Hunt
It’s 3 AM. My Kali Linux machine glows red in the dark room. Burp Suite traffic lights up both monitors. I’m testing a cloud-hosted API…
⤷ Title: Apache Config vs. .htaccess: The Security Battle You’re Probably Losing
════════════════════════
𐀪 Author: BotsiCat
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:54:48 GMT
════════════════════════
⌗ Tags: #htb_academy #website #hacking #ethical_hacking #web_development
════════════════════════
𐀪 Author: BotsiCat
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:54:48 GMT
════════════════════════
⌗ Tags: #htb_academy #website #hacking #ethical_hacking #web_development
Medium
Apache Config vs. .htaccess: The Security Battle You’re Probably Losing
A simple introduction to Apache .config and .htaccess — and why every site owner should understand the difference.
⤷ Title: Hire a Hacker Pro: The World’s Most Advanced Offensive Cybersecurity Firm
════════════════════════
𐀪 Author: Maxine Patrillo
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:05:54 GMT
════════════════════════
⌗ Tags: #hacker #hacking #hire_a_hacker #cybersecurity #pro_hacker
════════════════════════
𐀪 Author: Maxine Patrillo
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:05:54 GMT
════════════════════════
⌗ Tags: #hacker #hacking #hire_a_hacker #cybersecurity #pro_hacker
Medium
Hire a Hacker Pro: The World’s Most Advanced Offensive Cybersecurity Firm
Black hats never sleep — they’re creeping 24/7, evolving with AI into unstoppable monsters that shred defenses in seconds. In 2025…
⤷ Title: React2Shell(CVE 2025–55182): Command Injection
════════════════════════
𐀪 Author: Abhishek Gupta
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:03:18 GMT
════════════════════════
⌗ Tags: #tryhackme #programming #cybersecurity #reactjs #artificial_intelligence
════════════════════════
𐀪 Author: Abhishek Gupta
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:03:18 GMT
════════════════════════
⌗ Tags: #tryhackme #programming #cybersecurity #reactjs #artificial_intelligence
Medium
React2Shell(CVE 2025–55182): The NextJS Vulnerability that gives RCE
Hi, Myself Abhishek Gupta. I am going to tell you about how you can find this vulnerability and what steps to follow to exploit it.
⤷ Title: OpenAI, Anthropic, Google Unite: Launch Agentic AI Foundation Under Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 03:24:37 +0000
════════════════════════
⌗ Tags: #Technology #AAIF #Agentic AI Foundation #AI Agents #Anthropic #Block #Interoperability #Linux Foundation #MCP Protocol #open_source #OpenAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 03:24:37 +0000
════════════════════════
⌗ Tags: #Technology #AAIF #Agentic AI Foundation #AI Agents #Anthropic #Block #Interoperability #Linux Foundation #MCP Protocol #open_source #OpenAI
Daily CyberSecurity
OpenAI, Anthropic, Google Unite: Launch Agentic AI Foundation Under Linux
Tech giants Anthropic, OpenAI, & Google launch the Agentic AI Foundation under the Linux Foundation, donating the vital MCP protocol for open-source agent development.
⤷ Title: The “Surprise Metric”: Google’s New AI Architecture Outperforms GPT-4 in Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 03:16:05 +0000
════════════════════════
⌗ Tags: #Technology #AI Memory #deep_learning #Google AI #GPT_4 #Long_Context #MIRAS Framework #Neural Networks #Titans Architecture #Transformer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 03:16:05 +0000
════════════════════════
⌗ Tags: #Technology #AI Memory #deep_learning #Google AI #GPT_4 #Long_Context #MIRAS Framework #Neural Networks #Titans Architecture #Transformer
Daily CyberSecurity
The "Surprise Metric": Google's New AI Architecture Outperforms GPT-4 in Memory
Google unveils Titans and MIRAS: AI architectures that “read while remembering” using a "surprise metric." They handle 2M tokens and outperform GPT-4 in memory tasks.
⤷ Title: Seamless Sign-In: Microsoft WebView2 Gets Entra ID for Enterprise Auth
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 03:08:03 +0000
════════════════════════
⌗ Tags: #Technology #authentication #Chromium #enterprise IT #Entra ID #Microsoft #passkey #Web Account Manager #WebView2 #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 03:08:03 +0000
════════════════════════
⌗ Tags: #Technology #authentication #Chromium #enterprise IT #Entra ID #Microsoft #passkey #Web Account Manager #WebView2 #Windows 11
Daily CyberSecurity
Seamless Sign-In: Microsoft WebView2 Gets Entra ID for Enterprise Auth
Microsoft is integrating Entra ID (formerly Azure AD) into WebView2, enabling seamless, modern authentication like passkey and Conditional Access for embedded web apps.
⤷ Title: Apple’s Walls Fall: iOS and Android Interoperability is Finally Here
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:38:33 +0000
════════════════════════
⌗ Tags: #Technology #android #Apple #Competition #Data Migration #DMA #ecosystem #google #Interoperability #ios #Quick Share
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:38:33 +0000
════════════════════════
⌗ Tags: #Technology #android #Apple #Competition #Data Migration #DMA #ecosystem #google #Interoperability #ios #Quick Share
Daily CyberSecurity
Apple's Walls Fall: iOS and Android Interoperability is Finally Here
Regulatory pressure and Google's efforts are dismantling the walls between iOS and Android. Seamless data migration and cross-platform device freedom are now inevitable.
⤷ Title: CISA KEV Alert: WinRAR Zero-Day Used for Malware Injection and Windows UAF RCE Under Active Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:14:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #Cloud Files #CVE_2025_6218 #Directory Traversal #privilege escalation #UAF #WinRAR #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:14:17 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #Cloud Files #CVE_2025_6218 #Directory Traversal #privilege escalation #UAF #WinRAR #zero_day
Daily CyberSecurity
CISA KEV Alert: WinRAR Zero-Day Used for Malware Injection and Windows UAF RCE Under Active Attack
CISA added two actively exploited zero-days to the KEV: a WinRAR directory traversal (CVE-2025-6218) planting malware in Startup folder, and a Windows Cloud Files UAF for SYSTEM privileges.
⤷ Title: Critical Fortinet Flaw Risks Unauthenticated Admin Bypass via FortiCloud SSO SAML Forgery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:01:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59718 #FortiCloud #Fortinet #FortiOS #SAML Forgery #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 02:01:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59718 #FortiCloud #Fortinet #FortiOS #SAML Forgery #SSO Bypass
Daily CyberSecurity
Critical Fortinet Flaw Risks Unauthenticated Admin Bypass via FortiCloud SSO SAML Forgery
Fortinet has issued an urgent security advisory following the discovery of a critical vulnerability affecting its flagship network security products. The flaw, which carries a critical CVSS score …