⤷ Title: 5-Year Threat: Malicious NuGet Package Used Homoglyphs and Typosquatting to Steal Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:45:36 +0000
════════════════════════
⌗ Tags: #Malware #.NET #Crypto Stealer #Fody #Homoglyph #NuGet #Stratis #supply chain attack #Tracer.Fody.NLog #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:45:36 +0000
════════════════════════
⌗ Tags: #Malware #.NET #Crypto Stealer #Fody #Homoglyph #NuGet #Stratis #supply chain attack #Tracer.Fody.NLog #Typosquatting
Daily CyberSecurity
5-Year Threat: Malicious NuGet Package Used Homoglyphs and Typosquatting to Steal Crypto Wallets
A malicious NuGet package (Tracer.Fody.NLog) stole crypto wallet data for 5 years using homoglyphs and typosquatting to evade detection. The .NET supply chain attack linked to a Russian C2 server.
⤷ Title: macOS LPE Flaw Resurfaces: .localized Directory Exploited to Hijack Installers and Gain Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:40:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.localized #CVE_2025_24099 #Installer Hijack #Local Privilege Escalation #LPE #macOS #root access #Third_Party Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:40:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.localized #CVE_2025_24099 #Installer Hijack #Local Privilege Escalation #LPE #macOS #root access #Third_Party Software
Daily CyberSecurity
macOS LPE Flaw Resurfaces: .localized Directory Exploited to Hijack Installers and Gain Root Access
A macOS LPE flaw resurfaces after 7 years, allowing unprivileged users to hijack third-party installers and gain root access. The exploit leverages the hidden .localized directory to confuse the installation path.
⤷ Title: Frogblight Android Banking Trojan Targets Turkey via Fake E-Gov Smishing and WebView
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:32:19 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #Coper #Frogblight #MaaS #smishing #spyware #Turkey #WebView
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:32:19 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #Coper #Frogblight #MaaS #smishing #spyware #Turkey #WebView
Daily CyberSecurity
Frogblight Android Banking Trojan Targets Turkey via Fake E-Gov Smishing and WebView
Frogblight, a new Android banking Trojan, is targeting Turkey via smishing with fake e-government apps. It uses WebView to steal credentials and is linked to the Coper MaaS family. It is being actively developed.
⤷ Title: Phantom Stealer Targets Russian Finance with ISO Phishing, Deploying Keyloggers and Crypto-Wallet Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:27:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Financial Sector #information stealer #ISO File #Keylogger #Phantom Stealer #phishing #russia #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:27:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Financial Sector #information stealer #ISO File #Keylogger #Phantom Stealer #phishing #russia #social engineering
Daily CyberSecurity
Phantom Stealer Targets Russian Finance with ISO Phishing, Deploying Keyloggers and Crypto-Wallet Theft
Operation MoneyMount-ISO targets Russian financial institutions with a Phantom Stealer info-stealer hidden in an ISO file. The malware steals crypto wallets, browser data, and uses a keylogger. It has a SelfDestruct function for evasion.
⤷ Title: PyStoreRAT Uncovered: Fileless RAT Hides in Fake GitHub Repos to Launch Invisible Attacks on Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:22:06 +0000
════════════════════════
⌗ Tags: #Malware #CrowdStrike Evasion #fileless #github #HTA #PyStoreRAT #rat #Remote Access Trojan #Rhadamanthys #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:22:06 +0000
════════════════════════
⌗ Tags: #Malware #CrowdStrike Evasion #fileless #github #HTA #PyStoreRAT #rat #Remote Access Trojan #Rhadamanthys #Supply Chain
Daily CyberSecurity
PyStoreRAT Uncovered: Fileless RAT Hides in Fake GitHub Repos to Launch Invisible Attacks on Developers
PyStoreRAT, a new fileless RAT, is spreading via fake GitHub repositories targeting developers. It executes as a JS implant via mshta.exe and includes explicit evasion logic against CrowdStrike.
⤷ Title: BlackForce PhaaS Weaponizes React and Stateful Sessions to Bypass MFA & Steal Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackForce #Credential Theft #Man_in_the_Browser #MFA Bypass #PhaaS #Phishing_as_a_Service #React #SessionStorage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackForce #Credential Theft #Man_in_the_Browser #MFA Bypass #PhaaS #Phishing_as_a_Service #React #SessionStorage
Daily CyberSecurity
BlackForce PhaaS Weaponizes React and Stateful Sessions to Bypass MFA & Steal Credentials
BlackForce, a new PhaaS kit, is being sold for €300, using React/React Router to disguise its code. It utilizes stateful sessions and MitB to bypass MFA in real time. Update to V5 shows rapid evolution.
⤷ Title: From Cisco Student Rivalry to Global Hackers: Salt Typhoon Breaches 80+ Telecos for Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #CALEA #Cisco Network Academy #Geopolitical Espionage #Qiu Daibing #Salt Typhoon #Telecommunications #Yuyang
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #CALEA #Cisco Network Academy #Geopolitical Espionage #Qiu Daibing #Salt Typhoon #Telecommunications #Yuyang
Daily CyberSecurity
From Cisco Student Rivalry to Global Hackers: Salt Typhoon Breaches 80+ Telecos for Intelligence
Salt Typhoon operators, former Cisco Academy students, breached 80+ telecos and CALEA systems to harvest calls from high-profile targets. The report highlights the risk of corporate tech training in geopolitics.
⤷ Title: SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
Daily CyberSecurity
SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
SpaceX is interviewing investment banks for a potential 2026 IPO after its valuation nearly doubled to $800 billion in a secondary sale, fueled by Starlink's growth.
⤷ Title: Data Disaster: Claude AI Executes rm -rf ~/ and Wipes Developer’s Mac Home Directory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:03:41 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding Assistant #Claude AI #Containerization #Data Loss #Developer Workflow #docker #Home Directory #rm _rf #security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:03:41 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding Assistant #Claude AI #Containerization #Data Loss #Developer Workflow #docker #Home Directory #rm _rf #security
Daily CyberSecurity
Data Disaster: Claude AI Executes rm -rf ~/ and Wipes Developer's Mac Home Directory
A developer's Mac home directory was wiped after Claude AI executed an unconstrained rm -rf ~/ command. Experts urge using Docker to contain AI coding tools for safety.
⤷ Title: Intel Nears SambaNova Acquisition at $1.6B Fire-Sale Price, Down from $5B Valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:00:46 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #AI chip #Generative AI #Habana Labs #intel #M&A #nvidia #RDU #SambaNova #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:00:46 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #AI chip #Generative AI #Habana Labs #intel #M&A #nvidia #RDU #SambaNova #valuation
Daily CyberSecurity
Intel Nears SambaNova Acquisition at $1.6B Fire-Sale Price, Down from $5B Valuation
Intel is reportedly nearing a deal to buy AI chip startup SambaNova for around $1.6B, a sharp drop from its $5B valuation, for strategic boost to its inference capabilities.
⤷ Title: API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:02:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #technology #hacking #api
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:02:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #technology #hacking #api
Medium
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.
⤷ Title: O Gato de Schrödinger — Pwn Challenge
════════════════════════
𐀪 Author: FireUAI
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:02:32 GMT
════════════════════════
⌗ Tags: #capture_the_flag #ctf_writeup #hacking
════════════════════════
𐀪 Author: FireUAI
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:02:32 GMT
════════════════════════
⌗ Tags: #capture_the_flag #ctf_writeup #hacking
Medium
O Gato de Schrödinger — Pwn Challenge
Autor: Denner Lopes
⤷ Title: Geely Launches World’s Largest Safety Center in Ningbo, Targeting Zero Fatalities & Zero Data Leaks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:59:46 +0000
════════════════════════
⌗ Tags: #Information Security #Automotive Safety #Comprehensive Safety 2.0 #Crash Test #Cyberattack Resilience #EV Safety #Geely #Lynk & Co #Ningbo #Zero Fatalities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:59:46 +0000
════════════════════════
⌗ Tags: #Information Security #Automotive Safety #Comprehensive Safety 2.0 #Crash Test #Cyberattack Resilience #EV Safety #Geely #Lynk & Co #Ningbo #Zero Fatalities
Penetration Testing Tools
Geely Launches World's Largest Safety Center in Ningbo, Targeting Zero Fatalities & Zero Data Leaks
Ningbo is a major port city on China’s eastern seaboard, a key industrial hub of Zhejiang Province and
⤷ Title: New Security Default: CERT-FR Urges Users to Fully Disable Wi-Fi When Not Active
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:58:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CERT_FR #cybersecurity #Digital Hygiene #Evil Twin #iOS Settings #NCSC #Public Wi_Fi #Smartphone Security #Wi_Fi Attack Surface
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:58:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CERT_FR #cybersecurity #Digital Hygiene #Evil Twin #iOS Settings #NCSC #Public Wi_Fi #Smartphone Security #Wi_Fi Attack Surface
Penetration Testing Tools
New Security Default: CERT-FR Urges Users to Fully Disable Wi-Fi When Not Active
If it already felt as though smartphone security advice had devolved into an endless catalogue of prohibitions, here
⤷ Title: Supply Chain Alert: MangaGamer Higurashi USB Installers Compromised with Possible Floxif Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:56:39 +0000
════════════════════════
⌗ Tags: #Malware #Customer Alert #Floxif #Gaming Security #Higurashi #malware #MangaGamer #supply chain attack #USB Drive #Windows Installer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:56:39 +0000
════════════════════════
⌗ Tags: #Malware #Customer Alert #Floxif #Gaming Security #Higurashi #malware #MangaGamer #supply chain attack #USB Drive #Windows Installer
Penetration Testing Tools
Supply Chain Alert: MangaGamer Higurashi USB Installers Compromised with Possible Floxif Malware
MangaGamer has issued a warning about a potential supply-chain attack: in the latest print run of the physical
⤷ Title: Quality Control: GNOME Extensions Catalog Rejects Submissions with Unvetted AI-Generated Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:54:04 +0000
════════════════════════
⌗ Tags: #Linux #AI_Generated Code #Code Quality #developers #EGO #extensions #GNOME Shell #JavaScript #Moderation #Review Process
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:54:04 +0000
════════════════════════
⌗ Tags: #Linux #AI_Generated Code #Code Quality #developers #EGO #extensions #GNOME Shell #JavaScript #Moderation #Review Process
Penetration Testing Tools
Quality Control: GNOME Extensions Catalog Rejects Submissions with Unvetted AI-Generated Code
The GNOME Shell Extensions team has decided to tighten moderation rules in the EGO catalog in response to
⤷ Title: Unpatched RasMan Zero-Day Allows Local System Takeover via DoS Crash and RPC Spoofing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:50:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #0patch #CVE_2025_59230 #DoS #Local System #privilege escalation #RasMan #RPC Spoofing #Windows Vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:50:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #0patch #CVE_2025_59230 #DoS #Local System #privilege escalation #RasMan #RPC Spoofing #Windows Vulnerability #zero_day
Penetration Testing Tools
Unpatched RasMan Zero-Day Allows Local System Takeover via DoS Crash and RPC Spoofing
The 0patch team has reported that while analyzing CVE-2025-59230 in the Windows Remote Access Connection Manager (RasMan)—a flaw
⤷ Title: US Draft Cyber Strategy Plans to Enlist Private Firms for Offensive Cyber Operations
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:44:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cyber Command #National Cyber Director #National Security #Offensive Cyber #Policy #Private Sector #ransomware #US Cyber Strategy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:44:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cyber Command #National Cyber Director #National Security #Offensive Cyber #Policy #Private Sector #ransomware #US Cyber Strategy
Penetration Testing Tools
US Draft Cyber Strategy Plans to Enlist Private Firms for Offensive Cyber Operations
The administration of U.S. President Donald Trump is preparing to enlist private companies in the conduct of offensive
⤷ Title: Covert Channels: Stillepost Turns Chromium Browser into Stealth Application-Layer Proxy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:41:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Application Proxy #C2 Evasion #Chromium #CORS #DevTools Protocol #Edge #network security #PoC #Stillepost
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:41:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Application Proxy #C2 Evasion #Chromium #CORS #DevTools Protocol #Edge #network security #PoC #Stillepost
Penetration Testing Tools
Covert Channels: Stillepost Turns Chromium Browser into Stealth Application-Layer Proxy
A project called stillepost demonstrates an unusual technique that turns an ordinary Chromium-based browser into an application-layer proxy
⤷ Title: Ghidra 12.0 Released: Adds Concolic Execution and File System Mirroring for Reverse Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:38:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Concolic Execution #cybersecurity #Decompiler #Ghidra #NSA #PyGhidra #reverse engineering #RISC_V #Symbolic Links
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:38:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Concolic Execution #cybersecurity #Decompiler #Ghidra #NSA #PyGhidra #reverse engineering #RISC_V #Symbolic Links
Penetration Testing Tools
Ghidra 12.0 Released: Adds Concolic Execution and File System Mirroring for Reverse Engineering
Ghidra, the free reverse-engineering framework developed by the U.S. National Security Agency’s research arm, has reached version 12.0,
⤷ Title: Critical OpenShift GitOps Flaw Risks Cluster Takeover (CVE-2025-13888) via Privilege Escalation to Root
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ArgoCD #Cluster Takeover #CVE_2025_13888 #Kubernetes #Multi_tenancy #OpenShift GitOps #privilege escalation #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ArgoCD #Cluster Takeover #CVE_2025_13888 #Kubernetes #Multi_tenancy #OpenShift GitOps #privilege escalation #rce
Daily CyberSecurity
Critical OpenShift GitOps Flaw Risks Cluster Takeover (CVE-2025-13888) via Privilege Escalation to Root
A critical flaw (CVSS 9.1) in Red Hat OpenShift GitOps lets namespace admins gain root access to the cluster by manipulating ArgoCD CRs. This effectively breaks multi-tenancy. Patch immediately.