⤷ Title: Black Hat GEO in the LLM Era: Policy, Ethics, and the Fight for Information Integrity
════════════════════════
𐀪 Author: Geolyze
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:27 GMT
════════════════════════
⌗ Tags: #llm #ai #ethical_hacking
════════════════════════
𐀪 Author: Geolyze
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:23:27 GMT
════════════════════════
⌗ Tags: #llm #ai #ethical_hacking
Medium
Black Hat GEO in the LLM Era: Policy, Ethics, and the Fight for Information Integrity
In the early stages of search, ranking algorithms were easily manipulated through tactics such as hidden text, link farms, and keyword…
⤷ Title: What Is API Security and Why Should WE Care?
════════════════════════
𐀪 Author: Hafsah Ashraf
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:51:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #api_security
════════════════════════
𐀪 Author: Hafsah Ashraf
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 00:51:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #api_security
Medium
What Is API Security and Why Should WE Care?
A few months ago, a friend told me about something strange that happened while she was checking her bank account on her phone. The page…
⤷ Title: Understanding Broken Object Level Authorization (BOLA): What It Is, How It Happens, and How to…
════════════════════════
𐀪 Author: Charmaine Mangorima
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 23:54:38 GMT
════════════════════════
⌗ Tags: #api_security #api #owasp_api_security_top_10
════════════════════════
𐀪 Author: Charmaine Mangorima
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 23:54:38 GMT
════════════════════════
⌗ Tags: #api_security #api #owasp_api_security_top_10
Medium
Understanding Broken Object Level Authorization (BOLA): What It Is, How It Happens, and How to…
Introduction
APIs (Application Programming Interfaces) power almost every app you use today, from social media and banking to fitness…
APIs (Application Programming Interfaces) power almost every app you use today, from social media and banking to fitness…
⤷ Title: Farewell, Tabs: Google’s Experimental Disco Browser Generates Web Apps with AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:50:22 +0000
════════════════════════
⌗ Tags: #Technology #AI Browser #artificial intelligence #Chromium #Disco #Gemini 3 #GenTab #google #Google Labs #PWA #Web Browsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:50:22 +0000
════════════════════════
⌗ Tags: #Technology #AI Browser #artificial intelligence #Chromium #Disco #Gemini 3 #GenTab #google #Google Labs #PWA #Web Browsing
Daily CyberSecurity
Farewell, Tabs: Google's Experimental Disco Browser Generates Web Apps with AI
Google Labs unveils Disco, an experimental AI browser powered by Gemini 3. It features GenTab, which can generate interactive Progressive Web Apps (PWAs) from web content.
⤷ Title: React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:38:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_55184 #dos #Infinite Loop #React Server Components #security vulnerability #Source Code Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:38:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_55184 #dos #Infinite Loop #React Server Components #security vulnerability #Source Code Disclosure
Daily CyberSecurity
React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure
New flaws found in React Server Components risk a Server-Crashing DoS (CVSS 7.5) via infinite loop and Source Code Disclosure (CVE-2025-55183). Update to v19.0.3/19.1.4/19.2.3 immediately.
⤷ Title: Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:28:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fineract #Authorization Bypass #Core Banking #CVE_2025_58137 #Financial services #IDOR #Weak Password Policy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:28:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fineract #Authorization Bypass #Core Banking #CVE_2025_58137 #Financial services #IDOR #Weak Password Policy
Daily CyberSecurity
Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access
A flaw in Apache Fineract risks Authorization Bypass via IDOR (CVE-2025-58137) in its self-service API, potentially exposing customer data. Also fixed: Weak Password Policy and Unmasked Server Keys. Update to v1.13.0.
⤷ Title: New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:10:55 +0000
════════════════════════
⌗ Tags: #Malware #01flip #APAC #Cross_Platform #CVE_2019_11580 #LockBit #ransomware #Rust #Sliver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:10:55 +0000
════════════════════════
⌗ Tags: #Malware #01flip #APAC #Cross_Platform #CVE_2019_11580 #LockBit #ransomware #Rust #Sliver
Daily CyberSecurity
New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
New 01flip ransomware (written in Rust) targets APAC critical infra across Windows/Linux. The attackers use Sliver for C2 and older exploits for access. A curious "lockbit" ignore list was found in the code.
⤷ Title: CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 03:00:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58360 #Data Theft #GeoServer #ssrf #XML External Entity #xxe
Daily CyberSecurity
CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
CISA added a critical XXE flaw (CVE-2025-58360) in OSGeo GeoServer to the KEV Catalog. The actively exploited bug allows attackers to read arbitrary files and perform SSRF on internal networks. Patch immediately.
⤷ Title: Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:57:10 +0000
════════════════════════
⌗ Tags: #Malware #Builder Leak #Cybercrime #EDR Bypass #Kernel Rootkit #Modular Backdoor #ValleyRAT #Windows 11 #Winos
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:57:10 +0000
════════════════════════
⌗ Tags: #Malware #Builder Leak #Cybercrime #EDR Bypass #Kernel Rootkit #Modular Backdoor #ValleyRAT #Windows 11 #Winos
Daily CyberSecurity
Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge
A sophisticated cyber weapon previously linked to targeted espionage has gone rogue, flooding the threat landscape after its creation tools were leaked to the public. A new report from Check Point…
⤷ Title: Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:32:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Datadog Labs #Microsoft 365 #Okta #phishing #Salary Review #Session Token Hijack #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:32:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Datadog Labs #Microsoft 365 #Okta #phishing #Salary Review #Session Token Hijack #SSO Bypass
Daily CyberSecurity
Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures
A sophisticated phishing campaign uses salary review lures to target M365/Okta SSO. Attackers proxy the login page to preserve customization and hijack critical session tokens via dynamic redirection.
⤷ Title: CVE-2025-64188 (CVSS 9.8): Critical “Soledad” Theme Flaw Lets Subscribers Take Over WordPress Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:22:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:22:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
CVE-2025-64188 (CVSS 9.8): Critical "Soledad" Theme Flaw Lets Subscribers Take Over WordPress Sites
A Critical (CVSS 9.8) flaw in Soledad WordPress Theme allows Subscribers to escalate privileges and gain full site takeover by exploiting an exposed AJAX action. Update to v8.6.9.1 immediately.
⤷ Title: DiCaprio Movie Torrent Lures Users: Agent Tesla Deployed via Malicious LNK and Subtitle File Code Hiding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:15:04 +0000
════════════════════════
⌗ Tags: #Malware #Agent Tesla #Cybercrime #living_off_the_land #LNK Exploit #LotL #Movie Torrent #powershell #Subtitle File
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:15:04 +0000
════════════════════════
⌗ Tags: #Malware #Agent Tesla #Cybercrime #living_off_the_land #LNK Exploit #LotL #Movie Torrent #powershell #Subtitle File
Daily CyberSecurity
DiCaprio Movie Torrent Lures Users: Agent Tesla Deployed via Malicious LNK and Subtitle File Code Hiding
A movie torrent scam uses a DiCaprio film lure to infect PCs with Agent Tesla RAT. The attack chain uses LNK files and malicious code hidden in a subtitle file to achieve fileless execution via LotL tools.
⤷ Title: GOLD BLADE APT Hits Canadian Firms with BYOVD EDR Killer and Ransomware Delivered Via Fake Resumes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:52:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Canada #corporate espionage #EDR Killer #GOLD BLADE #QWCrypt Ransomware #Recruitment Lure #RedCurl #RedWolf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:52:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Canada #corporate espionage #EDR Killer #GOLD BLADE #QWCrypt Ransomware #Recruitment Lure #RedCurl #RedWolf
Daily CyberSecurity
GOLD BLADE APT Hits Canadian Firms with BYOVD EDR Killer and Ransomware Delivered Via Fake Resumes
GOLD BLADE (RedCurl) targets Canadian firms (80% of attacks) with espionage and QWCrypt ransomware. The group uses fake resumes and a BYOVD EDR killer (Zemana driver) to disable security controls.
⤷ Title: XSS — Merry XSSMas
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:18:19 GMT
════════════════════════
⌗ Tags: #xss_attack #cybersecurity #tryhackme #xss_vulnerability #aoc2025
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:18:19 GMT
════════════════════════
⌗ Tags: #xss_attack #cybersecurity #tryhackme #xss_vulnerability #aoc2025
Medium
XSS — Merry XSSMas
Learn about types of XSS vulnerabilities and how to prevent them.
⤷ Title: [Write-up] HackTheBox - Explosion
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:56:41 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox #hack_the_box_writeup #hack_the_box_walkthrough #hackthebox_walkthrough
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:56:41 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox #hack_the_box_writeup #hack_the_box_walkthrough #hackthebox_walkthrough
Medium
[Write-up] HackTheBox - Explosion
สวัสดีค่ะ วันนี้เราจะมาแชร์วิธีการหา root flag ในกล่อง Explosion ซึ่งเป็นกล่องใน Starting Point - Tier 0 ของ HackTheBox ค่ะ ถ้าพร้อมแล้ว…
⤷ Title: CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 10:31:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 10:31:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SpearSpray: The Stealthy Tool That Bypasses Lockout Policies in Active Directory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:49:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Account Lockout #Active Directory #BloodHound #Cyber Attack Tool #Kerberos #LDAP #password spraying #Red Team #security #SpearSpray
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:49:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Account Lockout #Active Directory #BloodHound #Cyber Attack Tool #Kerberos #LDAP #password spraying #Red Team #security #SpearSpray
Penetration Testing Tools
SpearSpray: The Stealthy Tool That Bypasses Lockout Policies in Active Directory
SpearSpray is an advanced AD password spraying tool using Kerberos and LDAP, featuring jitter and domain policy awareness to bypass account lockouts for stealthy attacks.
⤷ Title: PATCH NOW: Google Issues Emergency Chrome Update for Actively Exploited Zero-Day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:45:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chrome Security #CVE_2025_14372 #cybersecurity #Emergency Update #exploitation #Google Chrome #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:45:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chrome Security #CVE_2025_14372 #cybersecurity #Emergency Update #exploitation #Google Chrome #vulnerability #zero_day
Penetration Testing Tools
PATCH NOW: Google Issues Emergency Chrome Update for Actively Exploited Zero-Day
Google has released an unscheduled Chrome update to patch a zero-day vulnerability already being exploited in active attacks.
⤷ Title: PATCH NOW: Microsoft Fixes 57 Flaws, Including Three Zero-Days Actively Exploited
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #CVE_2025_62221 #cybersecurity #GitHub Copilot #Microsoft #Patch Tuesday #PowerShell #RCE #Windows Security #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #CVE_2025_62221 #cybersecurity #GitHub Copilot #Microsoft #Patch Tuesday #PowerShell #RCE #Windows Security #zero_day
Penetration Testing Tools
PATCH NOW: Microsoft Fixes 57 Flaws, Including Three Zero-Days Actively Exploited
Microsoft has released its December security updates: Patch Tuesday brings fixes for 57 vulnerabilities, including three zero-days (one
⤷ Title: Japan’s Largest Scam: Chinese Duo Used Hijacked Accounts to Manipulate Stock Prices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:42:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese Nationals #Financial Crime #Hijacked Accounts #Japan #Market Manipulation #Matched Orders #phishing #Securities #Stock Fraud #Tokyo Stock Exchange
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:42:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese Nationals #Financial Crime #Hijacked Accounts #Japan #Market Manipulation #Matched Orders #phishing #Securities #Stock Fraud #Tokyo Stock Exchange
Penetration Testing Tools
Japan’s Largest Scam: Chinese Duo Used Hijacked Accounts to Manipulate Stock Prices
The investigation in Japan has detained two Chinese nationals suspected of orchestrating the largest known market-manipulation scheme involving
⤷ Title: ChimeraWire: The Click-Fraud Trojan Disguised as a Human User
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:40:19 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #ChimeraWire #Click Fraud #DLL hijacking #Doctor Web #privilege escalation #SEO Manipulation #trojan #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:40:19 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #ChimeraWire #Click Fraud #DLL hijacking #Doctor Web #privilege escalation #SEO Manipulation #trojan #Windows Security
Penetration Testing Tools
ChimeraWire: The Click-Fraud Trojan Disguised as a Human User
Experts at Doctor Web have identified a new click-fraud trojan, Trojan.ChimeraWire, which disguises itself as the activity of