⤷ Title: NVIDIA Merlin Flaws Risk AI Pipeline RCE via Unsafe Deserialization in NVTabular & Transformers4Rec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:46:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI/ML #CVE_2025_33214 #Data Tampering #Deserialization #NVIDIA Merlin #NVTabular #rce #Transformers4Rec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:46:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI/ML #CVE_2025_33214 #Data Tampering #Deserialization #NVIDIA Merlin #NVTabular #rce #Transformers4Rec
Daily CyberSecurity
NVIDIA Merlin Flaws Risk AI Pipeline RCE via Unsafe Deserialization in NVTabular & Transformers4Rec
NVIDIA patched High-severity (CVSS 8.8) deserialization flaws in Merlin's NVTabular and Transformers4Rec on Linux. Exploitation risks RCE, DoS, and data tampering in AI recommendation pipelines.
⤷ Title: Unpatched Windows RasMan Flaw Allows Unprivileged Crash, Enabling Local System Privilege Escalation Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:49:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0patch #CVE_2025_59230 #privilege escalation #RasMan #Remote Access Connection Manager #Unpatched Flaw #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:49:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0patch #CVE_2025_59230 #privilege escalation #RasMan #Remote Access Connection Manager #Unpatched Flaw #windows
Daily CyberSecurity
Unpatched Windows RasMan Flaw Allows Unprivileged Crash, Enabling Local System Privilege Escalation Exploit
0patch found an unpatched flaw in Windows RasMan that allows any user to crash the service on demand. This unprivileged crash is the necessary step to exploit the CVE-2025-59230 LPE flaw. Micropatch is available.
⤷ Title: Critical pgAdmin RCE (CVE-2025-13780) Flaw Bypasses Fix, Allowing Server Takeover Via Malicious Database Restore
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13780 #Database Restore #Meta_Command #pgAdmin #PostgreSQL #rce #Remote Code Execution #security bypass #UTF_8 BOM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13780 #Database Restore #Meta_Command #pgAdmin #PostgreSQL #rce #Remote Code Execution #security bypass #UTF_8 BOM
Daily CyberSecurity
Critical pgAdmin RCE (CVE-2025-13780) Flaw Bypasses Fix, Allowing Server Takeover Via Malicious Database Restore
A critical RCE flaw (CVSS 9.1) in pgAdmin bypasses security via a UTF-8 BOM parsing mismatch. It allows attackers to execute root commands during a database restore operation. Update immediately.
⤷ Title: New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #Espionage #FINALDRAFT #Google Drive #NANOREMOTE #OAuth 2.0 #REF7707 #WMLOADER
Daily CyberSecurity
New NANOREMOTE Backdoor Uses Google Drive API for Covert C2 and Links to FINALDRAFT Espionage Group
NANOREMOTE, a new Windows backdoor, leverages the Google Drive API for covert C2 and data exfiltration using OAuth 2.0 tokens. The malware shares a hard-coded AES key with the FINALDRAFT family, linking it to seasoned espionage actors.
⤷ Title: SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
Daily CyberSecurity
SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
SHADOW-VOID-042 impersonated Trend Micro via fake security advisories to breach defense, energy, and chemical firms. Tactics align with Void Rabisu (ROMCOM), using HR lures and targeted exploits.
⤷ Title: Critical Plesk Flaw (CVE-2025-66430) Risks Full Server Takeover via LPE and Apache Config Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:32:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Configuration Injection #CVE_2025_66430 #Local Privilege Escalation #LPE #Plesk #root access #Web Hosting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:32:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Configuration Injection #CVE_2025_66430 #Local Privilege Escalation #LPE #Plesk #root access #Web Hosting
Daily CyberSecurity
Critical Plesk Flaw (CVE-2025-66430) Risks Full Server Takeover via LPE and Apache Config Injection
A critical LPE flaw (CVSS 9.1) in Plesk's Password-Protected Directories allows Apache configuration injection. Any Plesk user can execute root commands and achieve full server takeover. Update immediately.
⤷ Title: Hamas-Affiliated APT Ashen Lepus Unveils AshTag Malware Suite for Wider Cyber-Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #.NET malware #APT #Ashen Lepus #AshTag #cyber_espionage #Hamas #In_Memory Execution #Rclone #WIRTE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #.NET malware #APT #Ashen Lepus #AshTag #cyber_espionage #Hamas #In_Memory Execution #Rclone #WIRTE
Daily CyberSecurity
Hamas-Affiliated APT Ashen Lepus Unveils AshTag Malware Suite for Wider Cyber-Espionage
Ashen Lepus (Hamas-APT) significantly evolved during the conflict, deploying the AshTag modular .NET malware suite. It uses in-memory execution and Rclone for stealthy cyber-espionage against diplomatic targets in the Middle East.
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.
⤷ Title: Apache StreamPark Flaw Risks Data Decryption & Token Forgery via Hard-Coded Key and AES ECB Mode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES ECB #Apache StreamPark #Cryptographic Flaw #CVE_2025_54947 #Data Decryption #Hard_Coded Key #JWT Forgery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AES ECB #Apache StreamPark #Cryptographic Flaw #CVE_2025_54947 #Data Decryption #Hard_Coded Key #JWT Forgery
Daily CyberSecurity
Apache StreamPark Flaw Risks Data Decryption & Token Forgery via Hard-Coded Key and AES ECB Mode
A critical flaw in Apache StreamPark uses a hard-coded encryption key and the insecure AES ECB mode, risking data decryption and JWT authentication token forgery. Update to v2.1.7 immediately.
⤷ Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:11:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.
⤷ Title: ImageMagick Flaw Risks Arbitrary Memory Disclosure via PSX TIM File Integer Overflow on 32-bit Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:05:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #32_bit #Arbitrary Memory Disclosure #CVE_2025_66628 #ImageMagick #integer overflow #open_source #PSX TIM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:05:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #32_bit #Arbitrary Memory Disclosure #CVE_2025_66628 #ImageMagick #integer overflow #open_source #PSX TIM
Daily CyberSecurity
ImageMagick Flaw Risks Arbitrary Memory Disclosure via PSX TIM File Integer Overflow on 32-bit Systems
A High-severity (CVSS 7.5) flaw in ImageMagick's PSX TIM parser allows Arbitrary Memory Disclosure on 32-bit systems via an integer overflow. Patch immediately to v7.1.2-10.
⤷ Title: CloudSEK Hiring CTF December 2025- Round 2 -WriteUP
════════════════════════
𐀪 Author: Adithyanpezheri
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 03:35:05 GMT
════════════════════════
⌗ Tags: #hacking #cloudsek #ctf_writeup #hackathons #ctf
════════════════════════
𐀪 Author: Adithyanpezheri
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 03:35:05 GMT
════════════════════════
⌗ Tags: #hacking #cloudsek #ctf_writeup #hackathons #ctf
Medium
CloudSEK Hiring CTF December 2025- Round 2 -WriteUP
CHALLENGE-1
⤷ Title: Evolution of Composite Cyber Threats: 2025 Analysis and 2026 Key Response Strategies
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:01:34 GMT
════════════════════════
⌗ Tags: #hacking #threat_intelligence #cybersecurity #cyberattack #infosec
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:01:34 GMT
════════════════════════
⌗ Tags: #hacking #threat_intelligence #cybersecurity #cyberattack #infosec
Medium
Evolution of Composite Cyber Threats: 2025 Analysis and 2026 Key Response Strategies
This article explains how AI-driven attacks reshaped cyber threats in 2025 and what to expect in 2026.
⤷ Title: Google, I’m Sorry. I Think I Broke It.
════════════════════════
𐀪 Author: YUZU
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:58:31 GMT
════════════════════════
⌗ Tags: #hacking #google_gemini #artificial_intelligence #large_language_models #generative_ai_tools
════════════════════════
𐀪 Author: YUZU
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 01:58:31 GMT
════════════════════════
⌗ Tags: #hacking #google_gemini #artificial_intelligence #large_language_models #generative_ai_tools
Medium
Google, I’m Sorry. I Think I Broke It.
Confessions of a $20/month user who accidentally unlocked a $300 feature.
⤷ Title: Python Basics
════════════════════════
𐀪 Author: Md Amjad
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 03:22:51 GMT
════════════════════════
⌗ Tags: #python_for_pentesting #basic_python #python_programming #tryhackme
════════════════════════
𐀪 Author: Md Amjad
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 03:22:51 GMT
════════════════════════
⌗ Tags: #python_for_pentesting #basic_python #python_programming #tryhackme
Medium
Python Basics
Using a web-based code editor, learn the basics of Python and put your knowledge into practice by eventually coding a short Bitcoin…
⤷ Title: TryHackMe Advent of Cyber 2024 — Day 6 Walkthrough: Malware Sandboxing
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 03:00:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #malware_analysis #blue_team
════════════════════════
𐀪 Author: Pongsathorn Parivutthipong
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 03:00:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme #malware_analysis #blue_team
Medium
TryHackMe Advent of Cyber 2024 — Day 6 Walkthrough: Malware Sandboxing
Investigating suspicious executables with static and dynamic analysis tools in the town of Wareville.
⤷ Title: TryHackMe: Include Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:51:23 GMT
════════════════════════
⌗ Tags: #tryhackme #information_security #cybersecurity #pentesting
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:51:23 GMT
════════════════════════
⌗ Tags: #tryhackme #information_security #cybersecurity #pentesting
Medium
TryHackMe: Include Writeup
This box is ranked medium-difficulty on THM, it involves us escalating privileges on a web application, SSRF on an internal API to read…
⤷ Title: [Write-up] HackTheBox - Appointment
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:02:16 GMT
════════════════════════
⌗ Tags: #hack_the_box_walkthrough #hackthebox_walkthrough #hackthebox_writeup #hack_the_box_writeup #hackthebox
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 02:02:16 GMT
════════════════════════
⌗ Tags: #hack_the_box_walkthrough #hackthebox_walkthrough #hackthebox_writeup #hack_the_box_writeup #hackthebox
Medium
[Write-up] HackTheBox - Appointment
สวัสดีค่ะ วันนี้เราจะมาแชร์วิธีการหา root flag ในกล่อง Appointment ซึ่งเป็นกล่องใน Starting Point - Tier 1 ของ HackTheBox ค่ะ ถ้าพร้อมแล้ว…
⤷ Title: Windows 11 Gaming Guide: Microsoft’s Recommended PC Specs for 1080p to 4K
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 04:34:49 +0000
════════════════════════
⌗ Tags: #Windows #AMD Radeon #CPU #DirectStorage #Gaming PC #GPU #Hardware Specs #NVIDIA RTX #NVMe SSD #PC Gaming #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 04:34:49 +0000
════════════════════════
⌗ Tags: #Windows #AMD Radeon #CPU #DirectStorage #Gaming PC #GPU #Hardware Specs #NVIDIA RTX #NVMe SSD #PC Gaming #Windows 11
Daily CyberSecurity
Windows 11 Gaming Guide: Microsoft’s Recommended PC Specs for 1080p to 4K
Microsoft published a guide outlining recommended Windows 11 gaming PC specs from entry-level 1080p to high-end 4K, emphasizing NVMe SSDs for DirectStorage.
⤷ Title: Reader Freedom: Amazon Returns DRM Control to Publishers for EPUB/PDF Downloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 04:25:09 +0000
════════════════════════
⌗ Tags: #Technology #Amazon #copyright #Digital Rights Management #DRM #ebook #EPUB #KDP #Kindle #Pdf #publishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 04:25:09 +0000
════════════════════════
⌗ Tags: #Technology #Amazon #copyright #Digital Rights Management #DRM #ebook #EPUB #KDP #Kindle #Pdf #publishing
Daily CyberSecurity
Reader Freedom: Amazon Returns DRM Control to Publishers for EPUB/PDF Downloads
Amazon shifts DRM control to publishers/authors starting Jan 2026. Readers can download unencrypted EPUB/PDF files if the publisher consents, boosting reader choice.
⤷ Title: Catching Apple: Google Overhauls Health Connect to Track Alcohol & Medical Symptoms
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 04:16:14 +0000
════════════════════════
⌗ Tags: #Android #Alcohol Intake #android #Apple Health #Fitness Tracking #google #Health Connect #Health Data Hub #Medical Symptoms #privacy #software update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 04:16:14 +0000
════════════════════════
⌗ Tags: #Android #Alcohol Intake #android #Apple Health #Fitness Tracking #google #Health Connect #Health Data Hub #Medical Symptoms #privacy #software update
Daily CyberSecurity
Catching Apple: Google Overhauls Health Connect to Track Alcohol & Medical Symptoms
Google is overhauling Health Connect with new tracking for alcohol and medical symptoms to challenge Apple Health. The redesign improves privacy via group permission management.