⤷ Title: [Write-up] HackTheBox - Explosion
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:56:41 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox #hack_the_box_writeup #hack_the_box_walkthrough #hackthebox_walkthrough
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 02:56:41 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #hackthebox #hack_the_box_writeup #hack_the_box_walkthrough #hackthebox_walkthrough
Medium
[Write-up] HackTheBox - Explosion
สวัสดีค่ะ วันนี้เราจะมาแชร์วิธีการหา root flag ในกล่อง Explosion ซึ่งเป็นกล่องใน Starting Point - Tier 0 ของ HackTheBox ค่ะ ถ้าพร้อมแล้ว…
⤷ Title: CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 10:31:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 10:31:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SpearSpray: The Stealthy Tool That Bypasses Lockout Policies in Active Directory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:49:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Account Lockout #Active Directory #BloodHound #Cyber Attack Tool #Kerberos #LDAP #password spraying #Red Team #security #SpearSpray
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:49:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Account Lockout #Active Directory #BloodHound #Cyber Attack Tool #Kerberos #LDAP #password spraying #Red Team #security #SpearSpray
Penetration Testing Tools
SpearSpray: The Stealthy Tool That Bypasses Lockout Policies in Active Directory
SpearSpray is an advanced AD password spraying tool using Kerberos and LDAP, featuring jitter and domain policy awareness to bypass account lockouts for stealthy attacks.
⤷ Title: PATCH NOW: Google Issues Emergency Chrome Update for Actively Exploited Zero-Day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:45:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chrome Security #CVE_2025_14372 #cybersecurity #Emergency Update #exploitation #Google Chrome #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:45:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chrome Security #CVE_2025_14372 #cybersecurity #Emergency Update #exploitation #Google Chrome #vulnerability #zero_day
Penetration Testing Tools
PATCH NOW: Google Issues Emergency Chrome Update for Actively Exploited Zero-Day
Google has released an unscheduled Chrome update to patch a zero-day vulnerability already being exploited in active attacks.
⤷ Title: PATCH NOW: Microsoft Fixes 57 Flaws, Including Three Zero-Days Actively Exploited
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #CVE_2025_62221 #cybersecurity #GitHub Copilot #Microsoft #Patch Tuesday #PowerShell #RCE #Windows Security #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:44:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #CVE_2025_62221 #cybersecurity #GitHub Copilot #Microsoft #Patch Tuesday #PowerShell #RCE #Windows Security #zero_day
Penetration Testing Tools
PATCH NOW: Microsoft Fixes 57 Flaws, Including Three Zero-Days Actively Exploited
Microsoft has released its December security updates: Patch Tuesday brings fixes for 57 vulnerabilities, including three zero-days (one
⤷ Title: Japan’s Largest Scam: Chinese Duo Used Hijacked Accounts to Manipulate Stock Prices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:42:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese Nationals #Financial Crime #Hijacked Accounts #Japan #Market Manipulation #Matched Orders #phishing #Securities #Stock Fraud #Tokyo Stock Exchange
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:42:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese Nationals #Financial Crime #Hijacked Accounts #Japan #Market Manipulation #Matched Orders #phishing #Securities #Stock Fraud #Tokyo Stock Exchange
Penetration Testing Tools
Japan’s Largest Scam: Chinese Duo Used Hijacked Accounts to Manipulate Stock Prices
The investigation in Japan has detained two Chinese nationals suspected of orchestrating the largest known market-manipulation scheme involving
⤷ Title: ChimeraWire: The Click-Fraud Trojan Disguised as a Human User
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:40:19 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #ChimeraWire #Click Fraud #DLL hijacking #Doctor Web #privilege escalation #SEO Manipulation #trojan #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:40:19 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #ChimeraWire #Click Fraud #DLL hijacking #Doctor Web #privilege escalation #SEO Manipulation #trojan #Windows Security
Penetration Testing Tools
ChimeraWire: The Click-Fraud Trojan Disguised as a Human User
Experts at Doctor Web have identified a new click-fraud trojan, Trojan.ChimeraWire, which disguises itself as the activity of
⤷ Title: Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:38:43 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #EDR #Initial Access Broker #PowerShell #ransomware #ReliaQuest #SentinelOne #Storm_0249 #supply chain attack
Penetration Testing Tools
Invisible Ransomware: Storm-0249 Weaponizes SentinelOne EDR in Stealth Attacks
The financially motivated group Storm-0249, long known as a broker of initial access for ransomware operators, has markedly
⤷ Title: React2Shell Exploit: Botnets Target 150K+ Devices Daily with Node.js Flaw
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:37:14 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #BOTNET #BusyBox #Cryptominer #CVE_2025_55182 #cybersecurity #IoT #Mirai #Node.js #React2Shell #remote command execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:37:14 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #BOTNET #BusyBox #Cryptominer #CVE_2025_55182 #cybersecurity #IoT #Mirai #Node.js #React2Shell #remote command execution
Penetration Testing Tools
React2Shell Exploit: Botnets Target 150K+ Devices Daily with Node.js Flaw
A newly discovered vulnerability in Node.js, designated CVE-2025-55182 and informally dubbed React2Shell, has become a favored weapon of
⤷ Title: Khashoggi’s Widow Files French Complaint Over Pegasus Spyware Infection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:36:37 +0000
════════════════════════
⌗ Tags: #Malware #Citizen Lab #French Prosecutor #Hanan Elatr Khashoggi #Jamal Khashoggi #NSO Group #Pegasus #Saudi Arabia #Spyware #Surveillance #UAE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:36:37 +0000
════════════════════════
⌗ Tags: #Malware #Citizen Lab #French Prosecutor #Hanan Elatr Khashoggi #Jamal Khashoggi #NSO Group #Pegasus #Saudi Arabia #Spyware #Surveillance #UAE
Penetration Testing Tools
Khashoggi's Widow Files French Complaint Over Pegasus Spyware Infection
The widow of Saudi dissident journalist Jamal Khashoggi has filed a complaint with the French prosecutor’s office, alleging
⤷ Title: Digital War Crimes: ICC Drafts Policy to Judge Cyber-Enabled Genocide and Aggression
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:34:37 +0000
════════════════════════
⌗ Tags: #Information Security #AI #Cybercrimes #Digital Evidence #Genocide #ICC #International Criminal Court #International Law #Rome Statute #Tallinn Manual #War Crimes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:34:37 +0000
════════════════════════
⌗ Tags: #Information Security #AI #Cybercrimes #Digital Evidence #Genocide #ICC #International Criminal Court #International Law #Rome Statute #Tallinn Manual #War Crimes
Penetration Testing Tools
Digital War Crimes: ICC Drafts Policy to Judge Cyber-Enabled Genocide and Aggression
The International Criminal Court has released a draft policy aimed at confronting crimes committed through digital technologies. The
⤷ Title: OpenAI Fights Back: GPT-5.2 Unveiled to Rival Google’s Gemini 3 Pro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:21:11 +0000
════════════════════════
⌗ Tags: #Technology #AGI #AI Benchmark #artificial intelligence #Gemini 3 Pro #GPT_5.2 #LMArena #OpenAI #Red Alert #Sam Altman #Superintelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:21:11 +0000
════════════════════════
⌗ Tags: #Technology #AGI #AI Benchmark #artificial intelligence #Gemini 3 Pro #GPT_5.2 #LMArena #OpenAI #Red Alert #Sam Altman #Superintelligence
Daily CyberSecurity
OpenAI Fights Back: GPT-5.2 Unveiled to Rival Google's Gemini 3 Pro
OpenAI launches GPT-5.2 ("Red Alert") to reclaim the top spot from Gemini 3 Pro. The model achieves perfect math scores and promises unparalleled reliability for enterprise tasks.
⤷ Title: The IP Wall Falls: Disney Invests $1B in OpenAI to License 200+ Characters for AI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:16:24 +0000
════════════════════════
⌗ Tags: #Technology #Bob Iger #Character Licensing #ChatGPT #Disney+ #investment #IP Protection #Marvel #OpenAI #Sam Altman #Sora #Star Wars
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:16:24 +0000
════════════════════════
⌗ Tags: #Technology #Bob Iger #Character Licensing #ChatGPT #Disney+ #investment #IP Protection #Marvel #OpenAI #Sam Altman #Sora #Star Wars
Daily CyberSecurity
The IP Wall Falls: Disney Invests $1B in OpenAI to License 200+ Characters for AI
Disney invests $1B in OpenAI and licenses 200+ characters (Mickey, Iron Man, Vader) for Sora and ChatGPT Images—a major pivot to defining the rules of AI-generated content.
⤷ Title: The AI Super-App Rises: Photoshop & Adobe Express Integrate into ChatGPT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:13:26 +0000
════════════════════════
⌗ Tags: #Technology #Acrobat #Adobe #Adobe Express #AI Integration #Canva #ChatGPT #Creative Workflow #MCP Protocol #OpenAI #Photoshop #Super App
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:13:26 +0000
════════════════════════
⌗ Tags: #Technology #Acrobat #Adobe #Adobe Express #AI Integration #Canva #ChatGPT #Creative Workflow #MCP Protocol #OpenAI #Photoshop #Super App
Daily CyberSecurity
The AI Super-App Rises: Photoshop & Adobe Express Integrate into ChatGPT
OpenAI integrates Photoshop, Acrobat, and Adobe Express into ChatGPT via MCP. The move creates an "AI super-app," enabling 800M users to edit images and PDFs directly in chat.
⤷ Title: The “USB-C of AI” is Here: Google Launches Managed Servers for MCP Protocol
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:09:37 +0000
════════════════════════
⌗ Tags: #Technology #AAIF #Agentic AI #Anthropic #BigQuery #Gemini 3 #google #google maps #Kubernetes #MCP Protocol #Tool Use
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:09:37 +0000
════════════════════════
⌗ Tags: #Technology #AAIF #Agentic AI #Anthropic #BigQuery #Gemini 3 #google #google maps #Kubernetes #MCP Protocol #Tool Use
Daily CyberSecurity
The "USB-C of AI" is Here: Google Launches Managed Servers for MCP Protocol
Google rapidly adopts the MCP protocol, launching managed servers for AI agents. This enables seamless, autonomous tool use across Google Maps, BigQuery, and GKE infrastructure.
⤷ Title: YouTube TV’s New Subscription Bundles: Is Streaming Becoming Cable All Over Again?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:04:22 +0000
════════════════════════
⌗ Tags: #Technology #cable alternatives #cord_cutting #Sports Streaming #streaming services #Subscription Plans #YouTube TV
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:04:22 +0000
════════════════════════
⌗ Tags: #Technology #cable alternatives #cord_cutting #Sports Streaming #streaming services #Subscription Plans #YouTube TV
Daily CyberSecurity
YouTube TV’s New Subscription Bundles: Is Streaming Becoming Cable All Over Again?
Streaming television appears to be retracing the path once taken by traditional cable. YouTube TV has announced that it will introduce a new subscription model, “YouTube TV Plans,” in early 2026. …
⤷ Title: Social Media & Messaging: Where Privacy Goes to Die
════════════════════════
𐀪 Author: Raghunandan J
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:32:17 GMT
════════════════════════
⌗ Tags: #social_media #social_media_addiction #application_security
════════════════════════
𐀪 Author: Raghunandan J
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:32:17 GMT
════════════════════════
⌗ Tags: #social_media #social_media_addiction #application_security
Medium
Social Media & Messaging: Where Privacy Goes to Die
If mobile apps were high school stereotypes, social media would be the popular kid everyone gossips about, but secretly rolls their eyes…
⤷ Title: How React Got Hacked: The Supply‑Chain Attack Nobody Saw Coming
════════════════════════
𐀪 Author: The Silent Genius
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 05:47:11 GMT
════════════════════════
⌗ Tags: #hacking #react_js_tutorials #software_development #reactjs #mern_stack
════════════════════════
𐀪 Author: The Silent Genius
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 05:47:11 GMT
════════════════════════
⌗ Tags: #hacking #react_js_tutorials #software_development #reactjs #mern_stack
Medium
How React Got Hacked: The Supply‑Chain Attack Nobody Saw Coming
Most of us trust popular tools like React without thinking twice. It’s everywhere — from small personal projects to huge apps used by…
⤷ Title: Understanding the Kill Chain: From Reconnaissance to Exploitation
════════════════════════
𐀪 Author: ZAYN
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 05:10:12 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #hacking #penetration_test #web_penetration_testing
════════════════════════
𐀪 Author: ZAYN
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 05:10:12 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #hacking #penetration_test #web_penetration_testing
Medium
Understanding the Kill Chain: From Reconnaissance to Exploitation
Every attack follows a pattern.
⤷ Title: How Hackers Actually Hack Instagram Accounts and How You Can Stop Them
════════════════════════
𐀪 Author: Noorul Ameen
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 05:13:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #instagram_hack #viral_topic #cyber_awareness #infosec
════════════════════════
𐀪 Author: Noorul Ameen
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 05:13:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #instagram_hack #viral_topic #cyber_awareness #infosec
Medium
How Hackers Actually Hack Instagram Accounts and How You Can Stop Them
Instagram hacking is no longer about “technical genius.”
Today, most attacks succeed because of psychology, trust, urgency and…
Today, most attacks succeed because of psychology, trust, urgency and…
⤷ Title: REACT2SHELL EXPLOITATION
════════════════════════
𐀪 Author: Rakesh Krishnan
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:48:59 GMT
════════════════════════
⌗ Tags: #infosec #security #react2shell #cybersecurity #exploitation
════════════════════════
𐀪 Author: Rakesh Krishnan
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 04:48:59 GMT
════════════════════════
⌗ Tags: #infosec #security #react2shell #cybersecurity #exploitation
Medium
REACT2SHELL EXPLOITATION
NOTE: This is not a technical break-down of React2Shell Vulnerability, as it’s already been covered by Trend Micro. This is currently…
❤1