⤷ Title: Ghidra 12.0 Released: Adds Concolic Execution and File System Mirroring for Reverse Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:38:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Concolic Execution #cybersecurity #Decompiler #Ghidra #NSA #PyGhidra #reverse engineering #RISC_V #Symbolic Links
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:38:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Concolic Execution #cybersecurity #Decompiler #Ghidra #NSA #PyGhidra #reverse engineering #RISC_V #Symbolic Links
Penetration Testing Tools
Ghidra 12.0 Released: Adds Concolic Execution and File System Mirroring for Reverse Engineering
Ghidra, the free reverse-engineering framework developed by the U.S. National Security Agency’s research arm, has reached version 12.0,
⤷ Title: Critical OpenShift GitOps Flaw Risks Cluster Takeover (CVE-2025-13888) via Privilege Escalation to Root
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ArgoCD #Cluster Takeover #CVE_2025_13888 #Kubernetes #Multi_tenancy #OpenShift GitOps #privilege escalation #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ArgoCD #Cluster Takeover #CVE_2025_13888 #Kubernetes #Multi_tenancy #OpenShift GitOps #privilege escalation #rce
Daily CyberSecurity
Critical OpenShift GitOps Flaw Risks Cluster Takeover (CVE-2025-13888) via Privilege Escalation to Root
A critical flaw (CVSS 9.1) in Red Hat OpenShift GitOps lets namespace admins gain root access to the cluster by manipulating ArgoCD CRs. This effectively breaks multi-tenancy. Patch immediately.
⤷ Title: Critical ScreenConnect Flaw (CVE-2025-14265) Risks Config Exposure & Untrusted Extension Installation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:06:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Data #ConnectWise #CVE_2025_14265 #MSP #on_premise #Remote Support #ScreenConnect #Untrusted Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:06:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Configuration Data #ConnectWise #CVE_2025_14265 #MSP #on_premise #Remote Support #ScreenConnect #Untrusted Extensions
Daily CyberSecurity
Critical ScreenConnect Flaw (CVE-2025-14265) Risks Config Exposure & Untrusted Extension Installation
A critical ScreenConnect flaw (CVSS 9.1) allows authorized users to expose config data or force untrusted extension installs. On-premise users must upgrade to v25.8 immediately; cloud users are already patched.
⤷ Title: Enterprise Alert: Windows 10 Update KB5071546 Breaks MSMQ Service with Insufficient Permissions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:29:45 +0000
════════════════════════
⌗ Tags: #Windows #Asynchronous Processing #Enterprise Bug #IIS #KB5071546 #Message Queuing #MSMQ #System.Messaging.MessageQueueException #Windows 10
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:29:45 +0000
════════════════════════
⌗ Tags: #Windows #Asynchronous Processing #Enterprise Bug #IIS #KB5071546 #Message Queuing #MSMQ #System.Messaging.MessageQueueException #Windows 10
Daily CyberSecurity
Enterprise Alert: Windows 10 Update KB5071546 Breaks MSMQ Service with Insufficient Permissions
Installing Windows 10 update KB5071546 causes MSMQ service failure in enterprise systems due to new, missing write permissions, forcing administrators to uninstall the patch.
⤷ Title: EU Compliance: iOS 26.3 Adds Notification Forwarding to Third-Party Wearables, Bypassing Apple Watch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:24:35 +0000
════════════════════════
⌗ Tags: #Technology #Apple Watch #compliance #Digital Markets Act #EU DMA #iOS 26.3 #Notification Forwarding #privacy #Third_Party Wearables
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:24:35 +0000
════════════════════════
⌗ Tags: #Technology #Apple Watch #compliance #Digital Markets Act #EU DMA #iOS 26.3 #Notification Forwarding #privacy #Third_Party Wearables
Daily CyberSecurity
EU Compliance: iOS 26.3 Adds Notification Forwarding to Third-Party Wearables, Bypassing Apple Watch
Apple introduced EU-only Notification Forwarding in iOS 26.3, allowing iPhones to selectively relay notifications to third-party smartwatches to comply with the Digital Markets Act.
⤷ Title: 10 OSINT Tools Every Cybersecurity Professional Should Know (Before Hackers Do) ️♂️
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:21:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #cybersecurity #bug_bounty #osint
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:21:19 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #hacking #cybersecurity #bug_bounty #osint
Medium
10 OSINT Tools Every Cybersecurity Professional Should Know (Before Hackers Do) 🕵️♂️
Cybersecurity isn’t just about firewalls, exploits, or code.
⤷ Title: $200 Bounty: XSS via X-Forwarded-Host Header That Also Triggered an Open Redirect
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:20:36 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #penetration_testing #cybersecurity #web_security
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:20:36 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #penetration_testing #cybersecurity #web_security
Medium
$200 Bounty: XSS via X-Forwarded-Host Header That Also Triggered an Open Redirect
When Blind Trust in HTTP Headers Turned a Secure Website Into an Attack Surface
⤷ Title: Tải Sakura School Simulator Mod Apk (Mở Khóa, Vô Hạn Tiền) v1.046.01
════════════════════════
𐀪 Author: Game4u
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:30:02 GMT
════════════════════════
⌗ Tags: #games #hacking #game4u
════════════════════════
𐀪 Author: Game4u
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:30:02 GMT
════════════════════════
⌗ Tags: #games #hacking #game4u
Medium
Tải Sakura School Simulator Mod Apk (Mở Khóa, Vô Hạn Tiền) v1.046.01
Sakura School Simulator là một trò chơi mô phỏng trường học hấp dẫn, nơi người chơi có thể trải nghiệm cuộc sống học đường với nhiều hoạt…
⤷ Title: Tải FF Advance Server APK (Full Tiền, Kim Cương) v8.9.0g
════════════════════════
𐀪 Author: Bandisharecx
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:21:30 GMT
════════════════════════
⌗ Tags: #hacking #bandishare #games
════════════════════════
𐀪 Author: Bandisharecx
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:21:30 GMT
════════════════════════
⌗ Tags: #hacking #bandishare #games
Medium
Tải FF Advance Server APK (Full Tiền, Kim Cương) v8.9.0g
FF Advance Server APK là một ứng dụng đặc biệt dành cho những người chơi Free Fire muốn trải nghiệm các tính năng mới trước khi chúng được…
⤷ Title: Tải Fishing Master Apk V2.4.196913 Cho Android
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:59:55 GMT
════════════════════════
⌗ Tags: #apkpure #games #hacking
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:59:55 GMT
════════════════════════
⌗ Tags: #apkpure #games #hacking
Medium
Tải Fishing Master Apk V2.4.196913 Cho Android
Fishing Master là một tựa game câu cá hấp dẫn, mang đến cho người chơi trải nghiệm thư giãn và thú vị. Trong game, bạn sẽ hóa thân thành…
⤷ Title: 2025年Q4區塊鏈安全風暴:從國家級駭客到用戶自保,新手入場必讀的生存指南
════════════════════════
𐀪 Author: Crypt0Sophie
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:36:18 GMT
════════════════════════
⌗ Tags: #hacking #smart_contracts #blockchain #cryptocurrency #cryptocurrency_investment
════════════════════════
𐀪 Author: Crypt0Sophie
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:36:18 GMT
════════════════════════
⌗ Tags: #hacking #smart_contracts #blockchain #cryptocurrency #cryptocurrency_investment
Medium
🚨 2025年Q4區塊鏈安全風暴:從國家級駭客到用戶自保,新手入場必讀的生存指南
2025年第四季度,加密貨幣和區塊鏈領域再次被安全事件的陰影籠罩。從震驚全球的巨額比特幣竊案,到持續不斷的平台漏洞攻擊,這些事件不僅造成數十億美元的用戶損失,也再次暴露了在全球監管尚未完全定型階段,區塊鏈世界所面臨的結構性挑戰。
⤷ Title: Why Threat Actors Still Outgun Defensive Teams
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:09:23 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #hacking #cyberattack #cyber_security_awareness
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:09:23 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #hacking #cyberattack #cyber_security_awareness
Medium
Why Threat Actors Still Outgun Defensive Teams
The contemporary cybersecurity landscape is shaped by a persistent tension between offensive and defensive capabilities. It is increasingly…
⤷ Title: RustScan vs Nmap: Which Port Scanner Should You Use in Your Pentesting Workflow?
════════════════════════
𐀪 Author: Sajidur Rahman
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:02:17 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #nmap #cybersecurity #rustscan
════════════════════════
𐀪 Author: Sajidur Rahman
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 03:02:17 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #nmap #cybersecurity #rustscan
Medium
RustScan vs Nmap: Which Port Scanner Should You Use in Your Pentesting Workflow?
Port scanning is one of those boring-but-critical steps in every engagement, and the tools you pick can easily make or break your tempo…
⤷ Title: [Write-up] HackTheBox - Crocodile
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:02:26 GMT
════════════════════════
⌗ Tags: #hack_the_box_walkthrough #hackthebox_writeup #hack_the_box_writeup #hackthebox_walkthrough #hackthebox
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 02:02:26 GMT
════════════════════════
⌗ Tags: #hack_the_box_walkthrough #hackthebox_writeup #hack_the_box_writeup #hackthebox_walkthrough #hackthebox
Medium
[Write-up] HackTheBox - Crocodile
สวัสดีค่ะ วันนี้เราจะมาแชร์วิธีการหา root flag ในกล่อง Crocodile ซึ่งเป็นกล่องใน Starting Point - Tier 1 ของ HackTheBox ค่ะ ถ้าพร้อมแล้ว…
⤷ Title: BugTrace-AI: The Comprehensive AI-Powered Suite for SAST, DAST, and Vulnerability Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:13:15 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BugTrace_AI #DAST #DOM XSS #Generative AI #JWT Auditor #Penetration Testing #SAST #Vulnerability Analysis #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:13:15 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BugTrace_AI #DAST #DOM XSS #Generative AI #JWT Auditor #Penetration Testing #SAST #Vulnerability Analysis #web security
Penetration Testing Tools
BugTrace-AI: The Comprehensive AI-Powered Suite for SAST, DAST, and Vulnerability Research
BugTrace-AI is an AI-powered vulnerability suite for developers and pentesters, offering SAST/DAST, DOM XSS pathfinding, and WAF-bypassing payload generation in one interface.
⤷ Title: Ashen Lepus (WIRTE) Targets Middle East Governments with Stealthy AshTag Malware Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:09:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Ashen Lepus #AshTag #Cyber Espionage #DLL Sideloading #Geofencing #Government Targeting #Hamas #Middle East #Unit 42 #WIRTE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:09:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Ashen Lepus #AshTag #Cyber Espionage #DLL Sideloading #Geofencing #Government Targeting #Hamas #Middle East #Unit 42 #WIRTE
Penetration Testing Tools
Ashen Lepus (WIRTE) Targets Middle East Governments with Stealthy AshTag Malware Toolkit
The Unit 42 team at Palo Alto Networks has documented a prolonged and low-visibility campaign targeting government bodies
⤷ Title: Deep Leak: APT35 Hackers’ Payroll, Kashef Surveillance System, and 2004 Nuclear Spy Document Exposed
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:07:53 +0000
════════════════════════
⌗ Tags: #Data Leak
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:07:53 +0000
════════════════════════
⌗ Tags: #Data Leak
Penetration Testing Tools
Deep Leak: APT35 Hackers' Payroll, Kashef Surveillance System, and 2004 Nuclear Spy Document Exposed
In the autumn of 2025, files began circulating in the public domain that are attributed to the Iranian
⤷ Title: Invisible Surveillance: Tool Exploits WhatsApp/Signal Network Latency to Track User Activity
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:07:04 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #Battery Drain #cybersecurity #Metadata Leak #Network Latency #privacy #Proof of Concept #RTT #Signal #Surveillance #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:07:04 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #Battery Drain #cybersecurity #Metadata Leak #Network Latency #privacy #Proof of Concept #RTT #Signal #Surveillance #WhatsApp
Penetration Testing Tools
Invisible Surveillance: Tool Exploits WhatsApp/Signal Network Latency to Track User Activity
A tool has been released into the public domain that enables covert monitoring of user activity on WhatsApp
⤷ Title: Apple Emergency Patch: Two WebKit Zero-Days Actively Exploited in Targeted iOS Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:00:50 +0000
════════════════════════
⌗ Tags: #Apple #Vulnerability #CVE_2025_14174 #CVE_2025_43529 #Google TAG #iOS 26.2 #targeted attack #use_after_free #Webkit #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 04:00:50 +0000
════════════════════════
⌗ Tags: #Apple #Vulnerability #CVE_2025_14174 #CVE_2025_43529 #Google TAG #iOS 26.2 #targeted attack #use_after_free #Webkit #zero_day
Penetration Testing Tools
Apple Emergency Patch: Two WebKit Zero-Days Actively Exploited in Targeted iOS Attacks
Apple has released out-of-band patches addressing two zero-day vulnerabilities that were already being exploited in real-world attacks. The
⤷ Title: Breaking the Web (Part 7): Security Misconfigurations — When Defaults Become Dangerous
════════════════════════
𐀪 Author: Mohammed Fahad
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 05:42:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #web_application_security
════════════════════════
𐀪 Author: Mohammed Fahad
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 05:42:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #security #pentesting #web_application_security
Medium
Breaking the Web (Part 7): Security Misconfigurations — When Defaults Become Dangerous
Not every breach happens because of complex exploits or zero-days. Some of the most damaging attacks occur simply because something was…
⤷ Title: Becoming a Penetration Tester: Skills, Tools, and the Mindset That Makes the Difference
════════════════════════
𐀪 Author: Ferdi Edogawa
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 05:33:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Ferdi Edogawa
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 05:33:23 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity
Medium
Becoming a Penetration Tester: Skills, Tools, and the Mindset That Makes the Difference
When people hear the term penetration tester, they often think of someone in a dark room typing rapidly, breaking into systems with ease…