⤷ Title: Best Post-Exploitation Tools for Active Directory Pentesting
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:32:54 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #active_directory_pentest #pentesting #tools
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:32:54 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #active_directory_pentest #pentesting #tools
Medium
Best Post-Exploitation Tools for Active Directory Pentesting
10 + crucial tools for post-exploitation
⤷ Title: Web Security Academy: Websockets— Manipulating WebSocket messages to exploit vulnerabilities
════════════════════════
𐀪 Author: Octavian I.
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:19:08 GMT
════════════════════════
⌗ Tags: #tutorial #websocket #web_security #cybersecurity #hacking
════════════════════════
𐀪 Author: Octavian I.
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 21:19:08 GMT
════════════════════════
⌗ Tags: #tutorial #websocket #web_security #cybersecurity #hacking
Medium
Web Security Academy: Websockets— Manipulating WebSocket messages to exploit vulnerabilities
A simple case of WebSocket message manipulation
⤷ Title: Tryhackme | Advent Of Cyber 2025 | Day 13 | YARA Rules — YARA mean one! | Walkthrough
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:27:28 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme #tryhackme_walkthrough #aoc2025 #tryhackme_writeup
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:27:28 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme #tryhackme_walkthrough #aoc2025 #tryhackme_writeup
Medium
📌🚀Tryhackme | Advent Of Cyber 2025 | Day 13 | YARA Rules — YARA mean one! | Walkthrough🔥👉
Learn how YARA rules can be used to detect anomalies.
⤷ Title: TRYHACKME AOC 2025 Containers — DoorDasher’s Demise Writeup
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:12:39 GMT
════════════════════════
⌗ Tags: #container_security #aoc2025 #tryhackme #tryhackme_walkthrough #tryhackme_writeup
════════════════════════
𐀪 Author: Saiaditya
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:12:39 GMT
════════════════════════
⌗ Tags: #container_security #aoc2025 #tryhackme #tryhackme_walkthrough #tryhackme_writeup
Medium
TRYHACKME AOC 2025 Containers — DoorDasher’s Demise Writeup
Continue your Advent of Cyber journey and learn about container security.
⤷ Title: Hunter by HackSmarter Labs Walkthrough
════════════════════════
𐀪 Author: Muhammad Usman Faridi
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:30:54 GMT
════════════════════════
⌗ Tags: #username_enumeration #ethical_hacking #cybersecurity #access_control #red_team
════════════════════════
𐀪 Author: Muhammad Usman Faridi
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 20:30:54 GMT
════════════════════════
⌗ Tags: #username_enumeration #ethical_hacking #cybersecurity #access_control #red_team
Medium
Hunter by HackSmarter Labs Walkthrough
Lab Overview
⤷ Title: VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:00:31 +0000
════════════════════════
⌗ Tags: #Malware #cmstp.exe #LOLBIN #node_modules #Rust Trojan #steganography #supply chain attack #Typosquatting #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:00:31 +0000
════════════════════════
⌗ Tags: #Malware #cmstp.exe #LOLBIN #node_modules #Rust Trojan #steganography #supply chain attack #Typosquatting #VS Code
Daily CyberSecurity
VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
19 malicious VS Code extensions bypassed detection by hiding a Rust trojan in tampered node_modules and a fake banner.png using steganography. The attack uses cmstp.exe (LOLBIN) for execution.
⤷ Title: How I discovered leaked Snowflake credentials for a Fortune 500 Manufacturing Company using…
════════════════════════
𐀪 Author: Tillson Galloway
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:36:18 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #hacking #cybersecurity
════════════════════════
𐀪 Author: Tillson Galloway
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:36:18 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #hacking #cybersecurity
Medium
How I discovered leaked Snowflake credentials for a Fortune 500 Manufacturing Company using…
In late 2025, I used GitHound to uncover a high severity security issue involving leaked Snowflake tokens and sensitive information on a…
⤷ Title: Local Privilege Escalation via Docker Misconfiguration in Linux Operating Systems
════════════════════════
𐀪 Author: Shady mulla
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:07:27 GMT
════════════════════════
⌗ Tags: #privilege_escalation #penetration_testing #linux #docker #cybersecurity
════════════════════════
𐀪 Author: Shady mulla
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 23:07:27 GMT
════════════════════════
⌗ Tags: #privilege_escalation #penetration_testing #linux #docker #cybersecurity
Medium
Local Privilege Escalation via Docker Misconfiguration in Linux Operating Systems
In my OSCP learning journey, I got hands-on experience with the most common misconfiguration that happens amongst developers related to…
⤷ Title: Attacking ECB Oracles
════════════════════════
𐀪 Author: Jha Divyansh
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:42:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #attacking_ecb_oracles #tryhackme_writeup
════════════════════════
𐀪 Author: Jha Divyansh
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:42:28 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #attacking_ecb_oracles #tryhackme_writeup
Medium
Attacking ECB Oracles
ECB mode is simple but dangerously predictable: identical plaintext blocks always yield identical ciphertext. When exposed through an…
⤷ Title: HTB CTF Write-Up: Dancing
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
Medium
HTB CTF Write-Up: Dancing
Hello, fellow nerds!
⤷ Title: Proving Grounds - Clue
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:41:50 GMT
════════════════════════
⌗ Tags: #provinggrounds #linux #penetration_testing #cybersecurity #hacking
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:41:50 GMT
════════════════════════
⌗ Tags: #provinggrounds #linux #penetration_testing #cybersecurity #hacking
Medium
Proving Grounds - Clue
Summary
⤷ Title: NVIDIA Merlin Flaws Risk AI Pipeline RCE via Unsafe Deserialization in NVTabular & Transformers4Rec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:46:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI/ML #CVE_2025_33214 #Data Tampering #Deserialization #NVIDIA Merlin #NVTabular #rce #Transformers4Rec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:46:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI/ML #CVE_2025_33214 #Data Tampering #Deserialization #NVIDIA Merlin #NVTabular #rce #Transformers4Rec
Daily CyberSecurity
NVIDIA Merlin Flaws Risk AI Pipeline RCE via Unsafe Deserialization in NVTabular & Transformers4Rec
NVIDIA patched High-severity (CVSS 8.8) deserialization flaws in Merlin's NVTabular and Transformers4Rec on Linux. Exploitation risks RCE, DoS, and data tampering in AI recommendation pipelines.
⤷ Title: Unpatched Windows RasMan Flaw Allows Unprivileged Crash, Enabling Local System Privilege Escalation Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:49:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0patch #CVE_2025_59230 #privilege escalation #RasMan #Remote Access Connection Manager #Unpatched Flaw #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:49:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0patch #CVE_2025_59230 #privilege escalation #RasMan #Remote Access Connection Manager #Unpatched Flaw #windows
Daily CyberSecurity
Unpatched Windows RasMan Flaw Allows Unprivileged Crash, Enabling Local System Privilege Escalation Exploit
0patch found an unpatched flaw in Windows RasMan that allows any user to crash the service on demand. This unprivileged crash is the necessary step to exploit the CVE-2025-59230 LPE flaw. Micropatch is available.
⤷ Title: Critical pgAdmin RCE (CVE-2025-13780) Flaw Bypasses Fix, Allowing Server Takeover Via Malicious Database Restore
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13780 #Database Restore #Meta_Command #pgAdmin #PostgreSQL #rce #Remote Code Execution #security bypass #UTF_8 BOM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13780 #Database Restore #Meta_Command #pgAdmin #PostgreSQL #rce #Remote Code Execution #security bypass #UTF_8 BOM
Daily CyberSecurity
Critical pgAdmin RCE (CVE-2025-13780) Flaw Bypasses Fix, Allowing Server Takeover Via Malicious Database Restore
A critical RCE flaw (CVSS 9.1) in pgAdmin bypasses security via a UTF-8 BOM parsing mismatch. It allows attackers to execute root commands during a database restore operation. Update immediately.
⤷ Title: New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
Daily CyberSecurity
New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
NANOREMOTE, a new Windows backdoor, leverages the Google Drive API for covert C2 and data exfiltration using OAuth 2.0 tokens. The malware shares a hard-coded AES key with the FINALDRAFT family, linking it to seasoned espionage actors.
⤷ Title: SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
Daily CyberSecurity
SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
SHADOW-VOID-042 impersonated Trend Micro via fake security advisories to breach defense, energy, and chemical firms. Tactics align with Void Rabisu (ROMCOM), using HR lures and targeted exploits.
⤷ Title: Critical Plesk Flaw (CVE-2025-66430) Risks Full Server Takeover via LPE and Apache Config Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:32:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Configuration Injection #CVE_2025_66430 #Local Privilege Escalation #LPE #Plesk #root access #Web Hosting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:32:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Configuration Injection #CVE_2025_66430 #Local Privilege Escalation #LPE #Plesk #root access #Web Hosting
Daily CyberSecurity
Critical Plesk Flaw (CVE-2025-66430) Risks Full Server Takeover via LPE and Apache Config Injection
A critical LPE flaw (CVSS 9.1) in Plesk's Password-Protected Directories allows Apache configuration injection. Any Plesk user can execute root commands and achieve full server takeover. Update immediately.
⤷ Title: Hamas-Affiliated APT Ashen Lepus Unveils AshTag Malware Suite for Wider Cyber-Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #.NET malware #APT #Ashen Lepus #AshTag #cyber_espionage #Hamas #In_Memory Execution #Rclone #WIRTE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #.NET malware #APT #Ashen Lepus #AshTag #cyber_espionage #Hamas #In_Memory Execution #Rclone #WIRTE
Daily CyberSecurity
Hamas-Affiliated APT Ashen Lepus Unveils AshTag Malware Suite for Wider Cyber-Espionage
Ashen Lepus (Hamas-APT) significantly evolved during the conflict, deploying the AshTag modular .NET malware suite. It uses in-memory execution and Rclone for stealthy cyber-espionage against diplomatic targets in the Middle East.
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.
⤷ Title: Apache StreamPark Flaw Risks Data Decryption & Token Forgery via Hard-Coded Key and AES ECB Mode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES ECB #Apache StreamPark #Cryptographic Flaw #CVE_2025_54947 #Data Decryption #Hard_Coded Key #JWT Forgery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES ECB #Apache StreamPark #Cryptographic Flaw #CVE_2025_54947 #Data Decryption #Hard_Coded Key #JWT Forgery
Daily CyberSecurity
Apache StreamPark Flaw Risks Data Decryption & Token Forgery via Hard-Coded Key and AES ECB Mode
A critical flaw in Apache StreamPark uses a hard-coded encryption key and the insecure AES ECB mode, risking data decryption and JWT authentication token forgery. Update to v2.1.7 immediately.
⤷ Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.