⤷ Title: Windows RasMan Zero-Day: New DoS Flaw Crashes Service, Unofficial Fix Available
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:45:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #0patch #ACROS Security #CVE_2025_59230 #Denial of Service #DoS #Micropatch #privilege escalation #RasMan #windows #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:45:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #0patch #ACROS Security #CVE_2025_59230 #Denial of Service #DoS #Micropatch #privilege escalation #RasMan #windows #zero_day
Penetration Testing Tools
Windows RasMan Zero-Day: New DoS Flaw Crashes Service, Unofficial Fix Available
A newly discovered flaw in the Windows Remote Access Connection Manager (RasMan) service allows the operating system to
⤷ Title: NANOREMOTE Trojan Uses Google Drive as Covert C2 for Chinese Espionage Campaigns
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:44:18 +0000
════════════════════════
⌗ Tags: #Malware #C2 #Chinese Espionage #cloud security #FINALDRAFT #Google Drive API #NANOREMOTE #REF7707 #Windows Trojan #WMLOADER
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:44:18 +0000
════════════════════════
⌗ Tags: #Malware #C2 #Chinese Espionage #cloud security #FINALDRAFT #Google Drive API #NANOREMOTE #REF7707 #Windows Trojan #WMLOADER
Penetration Testing Tools
NANOREMOTE Trojan Uses Google Drive as Covert C2 for Chinese Espionage Campaigns
A new multifunctional Windows trojan dubbed NANOREMOTE leverages a cloud-based file storage service as a covert command-and-control hub,
⤷ Title: Total Takeover: Droidlock Android Malware Locks Phones, Records Screen, and Bypasses Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:42:21 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android malware #Device Admin #Droidlock #mobile security #phishing #ransomware #Screen Capture #Zimperium
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:42:21 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android malware #Device Admin #Droidlock #mobile security #phishing #ransomware #Screen Capture #Zimperium
Penetration Testing Tools
Total Takeover: Droidlock Android Malware Locks Phones, Records Screen, and Bypasses Security
A new Android malware known as Droidlock turns an infected smartphone into a device fully controlled by attackers.
⤷ Title: ConsentFix Attack: New Phishing Bypasses MFA to Hijack Microsoft Accounts via OAuth Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:34:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure CLI #ClickFix #cloud security #ConsentFix #MFA Bypass #Microsoft Account Takeover #OAuth 2.0 #phishing #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:34:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure CLI #ClickFix #cloud security #ConsentFix #MFA Bypass #Microsoft Account Takeover #OAuth 2.0 #phishing #Social Engineering
Penetration Testing Tools
ConsentFix Attack: New Phishing Bypasses MFA to Hijack Microsoft Accounts via OAuth Code
A new technique dubbed “ConsentFix” expands upon the already known ClickFix social engineering attack, enabling the hijacking of
⤷ Title: The End of d_genocide(): Linux Kernel Removes Controversial Function Name in 6.19 Refactor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:32:03 +0000
════════════════════════
⌗ Tags: #Linux #Al Viro #d_genocide #dcache #Inclusive Language #Linux 6.19 #Linux Kernel #open source #Terminology
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:32:03 +0000
════════════════════════
⌗ Tags: #Linux #Al Viro #d_genocide #dcache #Inclusive Language #Linux 6.19 #Linux Kernel #open source #Terminology
Penetration Testing Tools
The End of d_genocide(): Linux Kernel Removes Controversial Function Name in 6.19 Refactor
In the source code of the forthcoming Linux 6.19 kernel, a function with a controversial name has been
⤷ Title: The HTTPS Lockdown: Chrome & CAs Retire 11 Legacy Domain Validation Methods by 2028
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:27:51 +0000
════════════════════════
⌗ Tags: #Technology #ACME #CA/Browser Forum #Certificate Authority #Chrome Root Program #DCV #Domain Validation #HTTPS #Security Standard #TLS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:27:51 +0000
════════════════════════
⌗ Tags: #Technology #ACME #CA/Browser Forum #Certificate Authority #Chrome Root Program #DCV #Domain Validation #HTTPS #Security Standard #TLS
Penetration Testing Tools
The HTTPS Lockdown: Chrome & CAs Retire 11 Legacy Domain Validation Methods by 2028
The HTTPS certificate ecosystem is beginning a phased retreat from weaker methods of domain ownership verification. The Chrome
⤷ Title: PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #AES #CentreStack #CVE_2025_30406 #cybersecurity #Gladinet #Hardcoded Key #Huntress #RCE #Triofox #ViewState Deserialization
Penetration Testing Tools
PATCH NOW: Critical Gladinet RCE Flaw Exploits Hardcoded Crypto to Steal Keys
Gladinet is facing fresh trouble once again: vulnerabilities have been uncovered in its CentreStack and Triofox products stemming
⤷ Title: Notepad++ Fixes WinGUp Vulnerability Exploited to Deliver Reconnaissance Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #AutoUpdater.exe #Code Execution #cybersecurity #Notepad++ #reconnaissance #software update #supply chain attack #WinGUp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:25:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #AutoUpdater.exe #Code Execution #cybersecurity #Notepad++ #reconnaissance #software update #supply chain attack #WinGUp
Penetration Testing Tools
Notepad++ Fixes WinGUp Vulnerability Exploited to Deliver Reconnaissance Malware
Notepad++ has released version 8.8.9 to remediate a weakness in its WinGUp (GUP.exe) update mechanism. Researchers and users
⤷ Title: MITRE ATT&CK Evaluation 2025, Scattered Spider Mustang Panda
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:21:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cloud security #Cybersecurity Evaluation #EDR #MITRE ATT&CK #Mustang Panda #ransomware #Scattered Spider #SoC #Threat Hunting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:21:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cloud security #Cybersecurity Evaluation #EDR #MITRE ATT&CK #Mustang Panda #ransomware #Scattered Spider #SoC #Threat Hunting
Penetration Testing Tools
MITRE ATT&CK Evaluation 2025, Scattered Spider Mustang Panda
One of the cybersecurity industry’s most frequently cited “benchmarks” has once again made the rounds in slide decks
⤷ Title: Unmasking Mythic: Kaspersky Reveals How to Detect the Stealthy Open-Source Post-Exploitation Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:18:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #C2 framework #Cobalt Strike #kaspersky #Mythic #Network Detection #open source #post_exploitation #Suricata #UUID
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:18:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #C2 framework #Cobalt Strike #kaspersky #Mythic #Network Detection #open source #post_exploitation #Suricata #UUID
Penetration Testing Tools
Unmasking Mythic: Kaspersky Reveals How to Detect the Stealthy Open-Source Post-Exploitation Framework
Researchers at Kaspersky Lab have published an in-depth study on how to detect the presence of Mythic within
⤷ Title: ARTEMIS AI Places 2nd in Live Pentest, Outperforming 9 of 10 Human Security Experts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:16:21 +0000
════════════════════════
⌗ Tags: #Information Security #AI Agent #ARTEMIS #Autonomous Hacking #Cost_Effectiveness #cybersecurity #Pentesting #RCE #Stanford #Vulnerability Triage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 07:16:21 +0000
════════════════════════
⌗ Tags: #Information Security #AI Agent #ARTEMIS #Autonomous Hacking #Cost_Effectiveness #cybersecurity #Pentesting #RCE #Stanford #Vulnerability Triage
Penetration Testing Tools
ARTEMIS AI Places 2nd in Live Pentest, Outperforming 9 of 10 Human Security Experts
Researchers from Stanford and their collaborators conducted an unconventional experiment: they compared how ten seasoned professional penetration testers
⤷ Title: Advanced Search Techniques for Exposed Information — By Reju Kole
════════════════════════
𐀪 Author: Reju Kole
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:42:46 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #google #google_dorking #cybersecurity
════════════════════════
𐀪 Author: Reju Kole
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:42:46 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #google #google_dorking #cybersecurity
Medium
Advanced Search Techniques for Exposed Information — By Reju Kole
When Private Information Becomes Public on Google.
⤷ Title: How I Check for Subdomain Takeovers Part 1
════════════════════════
𐀪 Author: Red
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:41:12 GMT
════════════════════════
⌗ Tags: #linux #security #website #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Red
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:41:12 GMT
════════════════════════
⌗ Tags: #linux #security #website #cybersecurity #bug_bounty
Medium
How I Check for Subdomain Takeovers Part 1
Subdomain takeovers is a high risk vulnerability that negatively impacts businesses, but if found, can result in big rewards for a bug…
⤷ Title: When AI Gossips: How I Eavesdropped on a Federated Learning System
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:40:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #money #bug_bounty_tips #cybersecurity #hacking
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:40:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #money #bug_bounty_tips #cybersecurity #hacking
Medium
When AI Gossips: How I Eavesdropped on a Federated Learning System
You know that feeling when you’re at a party, and you can piece together everyone’s drama just by listening to random conversation…
⤷ Title: Reflected XSS in OAuth Callback Endpoint
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:34:56 GMT
════════════════════════
⌗ Tags: #infosec #xss_attack #reflected_xss #bug_bounty #javascript
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:34:56 GMT
════════════════════════
⌗ Tags: #infosec #xss_attack #reflected_xss #bug_bounty #javascript
Medium
Reflected XSS in OAuth Callback Endpoint
Free Article Link: Click for free!
⤷ Title: How I Turned a 403 Error into a $200 API Key Leak Bounty
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:34:18 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: JEETPAL
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:34:18 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Medium
How I Turned a 403 Error into a $200 API Key Leak Bounty
Hello everyone,
⤷ Title: Top 3 tools for Bug Bounty/Pentesting (2025)
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:32:45 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:32:45 GMT
════════════════════════
⌗ Tags: #credentials #bug_bounty #cybersecurity #pentesting #leaked
Medium
Top 3 tools for Bug Bounty/Pentesting (2025)
There are lots of web app security tools. Some of them are very well known, like BurpSuite, Nmap, Nuclei, ffuf, etc, whilst others, even…
⤷ Title: Your Smart Speaker is Dumber Than You Think: How I Made Alexa’s Sister Spill the Tea
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:30:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec #bug_bounty_tips #hacking
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:30:36 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec #bug_bounty_tips #hacking
Medium
Your Smart Speaker is Dumber Than You Think: How I Made Alexa’s Sister Spill the Tea
Free Link 🎈
⤷ Title: How I Tricked an AI Into Spilling Its Secrets (And Made a Pretty Penny)
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:27:14 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #hacking #bug_bounty #money
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:27:14 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #hacking #bug_bounty #money
Medium
How I Tricked an AI Into Spilling Its Secrets (And Made a Pretty Penny)
Free Link🎈
⤷ Title: Deepfake Deception: How I Hacked Biometric Authentication with $ and a YouTube Video
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:23:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #infosec #hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:23:39 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #infosec #hacking #cybersecurity #bug_bounty
Medium
Deepfake Deception: How I Hacked Biometric Authentication with $ and a YouTube Video 🤖
Free Link 🎈
⤷ Title: How to Pick the Right Bug Bounty Target
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:23:17 GMT
════════════════════════
⌗ Tags: #programming #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:23:17 GMT
════════════════════════
⌗ Tags: #programming #cybersecurity #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Medium
How to Pick the Right Bug Bounty Target
With the thousands of Bug Bounty Programs currently hosted on Intigriti, HackerOne, Bugcrowd and other platforms, it is very easy to get…