⤷ Title: Understanding Digital Consequences: Indonesian Cyber Law
════════════════════════
𐀪 Author: Diva Rizky Alfitrah
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:18:38 GMT
════════════════════════
⌗ Tags: #ethical_hacking #code_ethics
════════════════════════
𐀪 Author: Diva Rizky Alfitrah
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:18:38 GMT
════════════════════════
⌗ Tags: #ethical_hacking #code_ethics
Medium
Understanding Digital Consequences: Indonesian Cyber Law
With the rapid development of technology and digital transformation, every online activity we do now has real legal consequences. The…
⤷ Title: CVE-2025–66478 Explained: The Critical Next.js
════════════════════════
𐀪 Author: Priyen Mehta | Senior Full-Stack Developer
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:32:48 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #web_application_security #react_security #ssrf #nextjs
════════════════════════
𐀪 Author: Priyen Mehta | Senior Full-Stack Developer
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:32:48 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #web_application_security #react_security #ssrf #nextjs
Medium
CVE-2025–66478 Explained: The Critical Next.js & React Server Components Vulnerability You Must Patch Now
On December 6, a critical security flaw — CVE-2025–66478 — was publicly disclosed, impacting both Next.js and React Server Components…
⤷ Title: DllShimmer: The Stealth Tool for Weaponizing DLL Hijacking without Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:18:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Backdooring #cybersecurity #DLL hijacking #DllShimmer #EAT #Export Address Table #Penetration Testing #Proxy DLL #Stealth
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:18:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Backdooring #cybersecurity #DLL hijacking #DllShimmer #EAT #Export Address Table #Penetration Testing #Proxy DLL #Stealth
Penetration Testing Tools
DllShimmer: The Stealth Tool for Weaponizing DLL Hijacking without Detection
DllShimmer weaponizes DLL hijacking by cloning the original DLL's Export Address Table (EAT), enabling stealthy backdooring of functions without detection or reverse engineering.
⤷ Title: Urgent Patch: Notepad++ WinGUp Flaw Allowed Malware to Hijack Updates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:53:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE #cybersecurity #malware #notepad++ #software update #supply chain attack #Traffic Hijacking #Vulnerability #WinGUp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:53:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE #cybersecurity #malware #notepad++ #software update #supply chain attack #Traffic Hijacking #Vulnerability #WinGUp
Daily CyberSecurity
Urgent Patch: Notepad++ WinGUp Flaw Allowed Malware to Hijack Updates
A Notepad++ flaw (now patched in v8.8.9) allowed attackers to hijack the WinGUp update process, serving malware instead of the legitimate executable. Manual update is urged.
⤷ Title: 16-Year Battle Ends: Intel Loses Appeal, Must Pay €237 Million EU Fine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:38:21 +0000
════════════════════════
⌗ Tags: #Technology #AMD #Antitrust #Antitrust Law #court ruling #European Commission #Fine #intel #legal battle #Naked Restrictions #Tech History
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:38:21 +0000
════════════════════════
⌗ Tags: #Technology #AMD #Antitrust #Antitrust Law #court ruling #European Commission #Fine #intel #legal battle #Naked Restrictions #Tech History
Daily CyberSecurity
16-Year Battle Ends: Intel Loses Appeal, Must Pay €237 Million EU Fine
After a 16-year legal battle, Intel loses its appeal against the EU's antitrust ruling. The court upheld the "naked restrictions" finding but reduced the final fine to €237 million.
⤷ Title: Qualcomm Buys Ventana to Double Down on RISC-V and Custom Oryon CPU
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:34:37 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #AI Computing #ARM #CPU Technology #Instruction Set Architecture #Oryon CPU #Qualcomm #RISC_V #Ventana Micro Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:34:37 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #AI Computing #ARM #CPU Technology #Instruction Set Architecture #Oryon CPU #Qualcomm #RISC_V #Ventana Micro Systems
Daily CyberSecurity
Qualcomm Buys Ventana to Double Down on RISC-V and Custom Oryon CPU
Qualcomm acquires Ventana Micro Systems to integrate high-performance RISC-V expertise, bolstering its custom Oryon CPU roadmap and securing freedom from architectural constraints.
⤷ Title: You’re In Control: Instagram Launches “Your Algorithm” Feature for Reels
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:31:50 +0000
════════════════════════
⌗ Tags: #Technology #AI #Feed Control #Instagram #Meta #Personalization #Reels #Social Media #TikTok #User Autonomy #Your Algorithm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:31:50 +0000
════════════════════════
⌗ Tags: #Technology #AI #Feed Control #Instagram #Meta #Personalization #Reels #Social Media #TikTok #User Autonomy #Your Algorithm
Daily CyberSecurity
You're In Control: Instagram Launches "Your Algorithm" Feature for Reels
Instagram launches "Your Algorithm" for Reels, allowing users to see and tune their content preferences with keywords—a move toward TikTok-style personalization.
⤷ Title: EU’s Green Mandate: Parliament Pledges 90% Emissions Cut by 2040
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:27:22 +0000
════════════════════════
⌗ Tags: #Technology #2040 Target #Carbon Credits #climate change #Climate Neutrality #Emissions Reduction #EU #European Parliament #Green Economy #Greenhouse Gas
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:27:22 +0000
════════════════════════
⌗ Tags: #Technology #2040 Target #Carbon Credits #climate change #Climate Neutrality #Emissions Reduction #EU #European Parliament #Green Economy #Greenhouse Gas
Daily CyberSecurity
EU’s Green Mandate: Parliament Pledges 90% Emissions Cut by 2040
The EU reached a provisional agreement for a sweeping 90% reduction in greenhouse gas emissions by 2040, cementing its global lead despite political and industrial resistance.
⤷ Title: Apache Struts 2 DoS Flaw (CVE-2025-66675) Risks Server Crash via File Leak in Multipart Request Processing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts 2 #CVE_2025_64775 #Disk Exhaustion #dos #File Leak #Multipart Request #web application
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Struts 2 #CVE_2025_64775 #Disk Exhaustion #dos #File Leak #Multipart Request #web application
Daily CyberSecurity
Apache Struts 2 DoS Flaw (CVE-2025-66675) Risks Server Crash via File Leak in Multipart Request Processing
An Important DoS flaw (CVE-2025-64775) in Apache Struts 2 risks server crashes. Improper cleanup of multipart request files leads to disk exhaustion. Update to v6.8.0 or v7.1.1 immediately.
⤷ Title: High-Severity Zoom Rooms Flaw Risks Privilege Escalation via Downgrade Protection Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:12:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Conference System #CVE_2025_67460 #Downgrade Protection #Information Disclosure #privilege escalation #Zoom Rooms
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 03:12:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Conference System #CVE_2025_67460 #Downgrade Protection #Information Disclosure #privilege escalation #Zoom Rooms
Daily CyberSecurity
High-Severity Zoom Rooms Flaw Risks Privilege Escalation via Downgrade Protection Bypass
Zoom Rooms patched two flaws: a High-severity (CVSS 7.8) LPE flaw in Windows via downgrade bypass and information disclosure in macOS. Update to v6.6.0 immediately to prevent unauthenticated access.
⤷ Title: Emergency Chrome Update: Google Patches New Zero-Day Under Active Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:58:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #browser security #google chrome #security update #Under Coordination #use after free #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:58:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #browser security #google chrome #security update #Under Coordination #use after free #zero_day
Daily CyberSecurity
Emergency Chrome Update: Google Patches New Zero-Day Under Active Attack
Google has pushed an urgent security update to the Stable Channel for Desktop, racing to patch a high-severity vulnerability that is currently being exploited in the wild. The release, which bring…
⤷ Title: High-Severity Jenkins Flaws Risk Unauthenticated DoS via HTTP CLI and XSS Via Coverage Reports
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:38:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Build Token #CI/CD #Coverage Plugin #CVE_2025_67635 #dos #HTTP CLI #Jenkins #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:38:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Build Token #CI/CD #Coverage Plugin #CVE_2025_67635 #dos #HTTP CLI #Jenkins #XSS
Daily CyberSecurity
High-Severity Jenkins Flaws Risk Unauthenticated DoS via HTTP CLI and XSS Via Coverage Reports
Jenkins patched nine flaws: a High-severity unauthenticated DoS (CVE-2025-67635) via HTTP CLI and XSS via Coverage Plugin. Build tokens are now encrypted. Update to v2.541 immediately.
⤷ Title: Gogs Zero-Day (CVE-2025-8110) Risks RCE for 700+ Servers via Symlink Path Traversal Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:16:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_8110 #Git Service #Gogs #Path Traversal #rce #SUPERSHELL #Symlink #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:16:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_8110 #Git Service #Gogs #Path Traversal #rce #SUPERSHELL #Symlink #zero_day
Daily CyberSecurity
Gogs Zero-Day (CVE-2025-8110) Risks RCE for 700+ Servers via Symlink Path Traversal Bypass
A Gogs zero-day (CVE-2025-8110) bypasses a previous patch, enabling RCE via symlink path traversal. Over 50% of exposed instances are compromised, deploying the Supershell C2. Disable open registration immediately.
⤷ Title: High-Severity GitLab XSS Flaw (CVE-2025-12716) Risks Session Hijack via Malicious Wiki Pages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 01:46:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_12716 #gitlab #HTML Injection #Information Disclosure #Session Hijack #Wiki #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 01:46:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_12716 #gitlab #HTML Injection #Information Disclosure #Session Hijack #Wiki #XSS
Daily CyberSecurity
High-Severity GitLab XSS Flaw (CVE-2025-12716) Risks Session Hijack via Malicious Wiki Pages
A High-severity XSS (CVSS 8.7) flaw in GitLab Wiki allows session hijack via malicious pages, enabling unauthorized actions. Other HTML Injection flaws patched. Self-managed admins must update to v18.6.2.
⤷ Title: Facebook Gets New Look, But Instagram Secretly Uses AI for SEO Bait
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:44:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #404 Media #AI #AI Ethics #App Update #Content Farm #facebook #Instagram #Meta #Redesign #SEO #Social Media
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:44:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #404 Media #AI #AI Ethics #App Update #Content Farm #facebook #Instagram #Meta #Redesign #SEO #Social Media
Daily CyberSecurity
Facebook Gets New Look, But Instagram Secretly Uses AI for SEO Bait
Meta rolls out a transparent Facebook redesign for better navigation. Meanwhile, Instagram is secretly using AI to generate "content-farm" titles in code to boost Google SEO.
⤷ Title: SpaceX IPO: Targeting a $1.5 Trillion Valuation to Fund Space Data Centers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:40:25 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Elon Musk #IPO #Record Breaking #Saudi Aramco #Space Data Centers #SpaceX #Starlink #Starship #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:40:25 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Elon Musk #IPO #Record Breaking #Saudi Aramco #Space Data Centers #SpaceX #Starlink #Starship #valuation
Daily CyberSecurity
SpaceX IPO: Targeting a $1.5 Trillion Valuation to Fund Space Data Centers
SpaceX is planning a record-shattering IPO in 2026/2027 to raise over $30B, targeting a $1.5T valuation. Proceeds will fund Mars ambitions and orbital AI data centers.
⤷ Title: China’s WARP PANDA APT Deploys BRICKSTORM Backdoor to Hijack VMware vCenter/ESXi and Azure Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:36:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BRICKSTORM #China APT #Cloud Espionage #DoH #ESXi #Microsoft Azure #vCenter #vmware #WARP PANDA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:36:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BRICKSTORM #China APT #Cloud Espionage #DoH #ESXi #Microsoft Azure #vCenter #vmware #WARP PANDA
Daily CyberSecurity
China's WARP PANDA APT Deploys BRICKSTORM Backdoor to Hijack VMware vCenter/ESXi and Azure Cloud
China-nexus WARP PANDA APT targets VMware/Azure with BRICKSTORM, a Golang backdoor using DoH for stealth. The group creates "ghost VMs" and conducts session replay attacks for long-term espionage.
⤷ Title: Unpatched TOTOLINK AX1800 Router Flaw Allows Unauthenticated Telnet & Root RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:31:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13184 #rce #root access #Router Flaw #Telnet #TOTOLINK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:31:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13184 #rce #root access #Router Flaw #Telnet #TOTOLINK
Daily CyberSecurity
Unpatched TOTOLINK AX1800 Router Flaw Allows Unauthenticated Telnet & Root RCE
A critical unpatched flaw in the TOTOLINK AX1800 router allows unauthenticated HTTP requests to enable Telnet for root RCE. Admins must block WAN access immediately as there is no official fix.
⤷ Title: FBI/CISA Warn: Pro-Russia Hacktivists Target Critical Infrastructure Via Unsecured VNC HMIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:27:44 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA #Critical Infrastructure #Cyber Army of Russia Reborn #fbi #Hacktivism #HMI #OT Security #vnc
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:27:44 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA #Critical Infrastructure #Cyber Army of Russia Reborn #fbi #Hacktivism #HMI #OT Security #vnc
Daily CyberSecurity
FBI/CISA Warn: Pro-Russia Hacktivists Target Critical Infrastructure Via Unsecured VNC HMIs
FBI/CISA warn pro-Russia hacktivists (CARR, NoName057) are targeting critical infrastructure with unsophisticated attacks. They exploit unsecured VNC connections to manipulate HMIs and cause physical damage.
⤷ Title: Critical CCTV Flaw (CVE-2025-13607) Risks Video Feed Hijack & Credential Theft via Missing Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:22:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CCTV #Credential Theft #Critical Vulnerability #CVE_2025_13607 #D_Link #Missing Authentication #Video Surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:22:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CCTV #Credential Theft #Critical Vulnerability #CVE_2025_13607 #D_Link #Missing Authentication #Video Surveillance
Daily CyberSecurity
Critical CCTV Flaw (CVE-2025-13607) Risks Video Feed Hijack & Credential Theft via Missing Authentication
CISA warned of a Critical (CVSS 9.4) flaw in D-Link DCS-F5614-L1 cameras. Missing Authentication allows attackers to bypass login, steal admin credentials, and hijack video feeds. Patch immediately.
⤷ Title: “React2Shell” Crisis: Critical Vulnerability Triggers Global Cyberattacks by State-Sponsored Groups
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_55182 #Deserialization #Next.js #rce #React Server Components #React2Shell #state_sponsored
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_55182 #Deserialization #Next.js #rce #React Server Components #React2Shell #state_sponsored
Daily CyberSecurity
"React2Shell" Crisis: Critical Vulnerability Triggers Global Cyberattacks by State-Sponsored Groups
A Critical RCE (CVSS 10.0) flaw, React2Shell, in React/Next.js's Flight protocol allows unauthenticated system takeover. North Korean and Chinese state actors are actively exploiting the deserialization bug.