⤷ Title: CyberExam Sqlmap for Beginners lab Writeup
════════════════════════
𐀪 Author: FYC
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 19:52:21 GMT
════════════════════════
⌗ Tags: #solutions #hacking #cybersecurity #sqlmap #cyberexam
════════════════════════
𐀪 Author: FYC
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 19:52:21 GMT
════════════════════════
⌗ Tags: #solutions #hacking #cybersecurity #sqlmap #cyberexam
Medium
CyberExam Sqlmap for Beginners lab Writeup
Bu yazıda CyberExam platformunda bulunan Sqlmap for Beginners labının çözümünü inceleyeceğiz.
⤷ Title: We’re Solving Yesterday’s IAM Problems With Tomorrow’s Budget
════════════════════════
𐀪 Author: Steve Anderson
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 21:47:15 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #identity_management
════════════════════════
𐀪 Author: Steve Anderson
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 21:47:15 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #identity_management
Medium
We’re Solving Yesterday’s IAM Problems With Tomorrow’s Budget
Your CFO just approved a seven-figure IAM investment. Congratulations. You’re about to spend a fortune solving problems from 2015.
⤷ Title: Logical 2FA Bypass by Reusing Trusted Device Authentication Flow
════════════════════════
𐀪 Author: Mahmoud Gamal
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 21:55:52 GMT
════════════════════════
⌗ Tags: #writeup #bug_bounty #2fa #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Mahmoud Gamal
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 21:55:52 GMT
════════════════════════
⌗ Tags: #writeup #bug_bounty #2fa #penetration_testing #cybersecurity
Medium
Logical 2FA Bypass by Reusing Trusted Device Authentication Flow
Summary
⤷ Title: Forensics — Registry Furensics | Advent of Cyber 2025 Day 16 | Writeup
════════════════════════
𐀪 Author: Debmalya Mondal⚡
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 20:59:39 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #digital_forensics #tryhackme_walkthrough #tryhackme_writeup #tryhackme
════════════════════════
𐀪 Author: Debmalya Mondal⚡
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 20:59:39 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #digital_forensics #tryhackme_walkthrough #tryhackme_writeup #tryhackme
Medium
Forensics — Registry Furensics | Advent of Cyber 2025 Day 16 | Writeup
Investigating System Activity Through Registry Keys and User Traces
⤷ Title: Symfonos: 2 — Complete Walkthrough (Beginner-Friendly) | NullyBlissful
════════════════════════
𐀪 Author: NullyBlissful
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 20:47:25 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #oscp #vulnhub
════════════════════════
𐀪 Author: NullyBlissful
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 20:47:25 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #oscp #vulnhub
Medium
🌀 Symfonos: 2 — Complete Walkthrough (Beginner-Friendly) | NullyBlissful
“I am not a body. I am not even the mind.”
⤷ Title: SoundCloud Hit by Cyberattack, Breach Affects 20% of its Users
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:35:39 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Security #Cyber Attack #Cybersecurity #data breach #Privacy #ShinyHunters #SoundCloud #VPN
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:35:39 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Security #Cyber Attack #Cybersecurity #data breach #Privacy #ShinyHunters #SoundCloud #VPN
Hackread
SoundCloud Hit by Cyberattack, Breach Affects 20% of its Users
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Top 10 One-Liner Commands for JavaScript Hunting
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:40:48 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #cybersecurity #javascript #penetration_testing
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:40:48 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #cybersecurity #javascript #penetration_testing
Medium
Top 10 One-Liner Commands for JavaScript Hunting
How Simple JS Recon Exposes Hidden APIs, Admin Panels & Real-World Bugs
⤷ Title: Rate Limiting: The API Security Control Everyone Forgets
════════════════════════
𐀪 Author: Adnan taşdemir
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:07:25 GMT
════════════════════════
⌗ Tags: #api_rate_limiting #api_security #rate_limiting
════════════════════════
𐀪 Author: Adnan taşdemir
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 22:07:25 GMT
════════════════════════
⌗ Tags: #api_rate_limiting #api_security #rate_limiting
Medium
Rate Limiting: The API Security Control Everyone Forgets
Rate limiting is one of the simplest security controls in an API. It is also one of the most commonly missing. Many real incidents could…
⤷ Title: Sandworm’s Tactical Pivot: Russian GRU Abandons Zero-Days to Weaponize Misconfigured Edge Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 01:57:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Amazon Threat Intelligence #APT44 #Credential Replay #Critical Infrastructure #Curly COMrades #Edge Device #GRU #misconfiguration #SANDWORM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 01:57:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Amazon Threat Intelligence #APT44 #Credential Replay #Critical Infrastructure #Curly COMrades #Edge Device #GRU #misconfiguration #SANDWORM
Daily CyberSecurity
Sandworm’s Tactical Pivot: Russian GRU Abandons Zero-Days to Weaponize Misconfigured Edge Devices
Sandworm (APT44) has shifted tactics, favoring misconfigured edge devices over complex exploits to breach energy and telecom sectors via credential replay.
⤷ Title: Google Chrome Emergency Update: High-Severity Memory Corruption Flaws Fixed in WebGPU and V8
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 01:47:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #CVE_2025_14765 #google chrome #javascript #memory corruption #patch #use after free #V8 Engine #WebGPU
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 01:47:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #CVE_2025_14765 #google chrome #javascript #memory corruption #patch #use after free #V8 Engine #WebGPU
Daily CyberSecurity
Google Chrome Emergency Update: High-Severity Memory Corruption Flaws Fixed in WebGPU and V8
Google released an urgent Chrome update to patch High-severity flaws in WebGPU and V8. Fixes include a Use-After-Free and Memory Corruption. Update to v143.0.7499.146+ now.
⤷ Title: Fintech Endgame: PayPal Applies for Industrial Bank Charter to Fund SMEs and Support Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:46:59 +0000
════════════════════════
⌗ Tags: #Technology #Alex Chriss #cryptocurrency #FDIC #FinTech #Industrial Bank #Lending #paypal #PYUSD #Small Business #Utah
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:46:59 +0000
════════════════════════
⌗ Tags: #Technology #Alex Chriss #cryptocurrency #FDIC #FinTech #Industrial Bank #Lending #paypal #PYUSD #Small Business #Utah
Daily CyberSecurity
Fintech Endgame: PayPal Applies for Industrial Bank Charter to Fund SMEs and Support Crypto
PayPal seeks an industrial bank charter in Utah to cut reliance on partners, fund small businesses directly, and consolidate its growing cryptocurrency and PYUSD stablecoin operations.
⤷ Title: Security Shift: Google Retires Dark Web Report Service, Citing Inability to Offer Concrete Remedies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:42:30 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #Dark Web Report #Data Breach #google #Google One #Passkeys #password manager #Retirement #Security Checkup
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:42:30 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #Dark Web Report #Data Breach #google #Google One #Passkeys #password manager #Retirement #Security Checkup
Daily CyberSecurity
Security Shift: Google Retires Dark Web Report Service, Citing Inability to Offer Concrete Remedies
Google is retiring its Dark Web Report service in February 2026, stating it only caused anxiety by failing to offer users actionable steps to remedy leaked personal data.
⤷ Title: Critical FreePBX Flaw (CVE-2025-66039) Risks PBX Takeover via Authentication Bypass in ‘webserver’ Auth Mode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:40:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Asterisk #Authentication Bypass #Critical Flaw #CVE_2025_66039 #FreePBX #PBX #VOIP #Webserver Auth
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:40:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Asterisk #Authentication Bypass #Critical Flaw #CVE_2025_66039 #FreePBX #PBX #VOIP #Webserver Auth
Daily CyberSecurity
Critical FreePBX Flaw (CVE-2025-66039) Risks PBX Takeover via Authentication Bypass in 'webserver' Auth Mode
A critical authentication bypass (CVSS 9.3) in FreePBX allows complete PBX takeover when the 'webserver' auth mode is enabled. Attackers can gain an admin session with a crafted HTTP header. Update immediately.
⤷ Title: SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
Daily CyberSecurity
SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
SantaStealer, a new MaaS info-stealer, is being aggressively marketed on the dark web. It's a BluelineStealer rebrand that uses C code and open-source libraries to steal crypto wallets and credentials, despite having amateur anti-analysis features.
⤷ Title: Windows Admin Center Flaw (CVE-2025-64669): How a Simple Folder Permission Opened the Door to SYSTEM Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:31:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_64669 #DLL hijacking #Insecure Permissions #LPE #privilege escalation #TOCTOU #WAC #Windows Admin Center
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:31:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_64669 #DLL hijacking #Insecure Permissions #LPE #privilege escalation #TOCTOU #WAC #Windows Admin Center
Daily CyberSecurity
Windows Admin Center Flaw (CVE-2025-64669): How a Simple Folder Permission Opened the Door to SYSTEM Access
A LPE flaw in Windows Admin Center allows any user to gain SYSTEM privileges. It exploits insecure directory permissions and a TOCTOU flaw to execute a DLL hijacking attack.
⤷ Title: GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:22:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Hijack #Gen Digital #GhostPairing #Linked Devices #phishing #QR Code Scam #User Trust #WhatsApp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:22:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Hijack #Gen Digital #GhostPairing #Linked Devices #phishing #QR Code Scam #User Trust #WhatsApp
Daily CyberSecurity
GhostPairing: New Attack Hijacks WhatsApp via Linked Devices, Tricking Users with Fake Facebook QR Code
Add as a preferredsource on Google A deceptive new cyberattack campaign is turning one of WhatsApp’s most convenient
⤷ Title: Emerging Gentlemen Ransomware Hits 17 Countries with Double Extortion & BYOVD Evasion Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:19:29 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Threats #AhnLab #BYOVD #Cybercrime #Double Extortion #Gentlemen #GPO Manipulation #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:19:29 +0000
════════════════════════
⌗ Tags: #Malware #Advanced Threats #AhnLab #BYOVD #Cybercrime #Double Extortion #Gentlemen #GPO Manipulation #ransomware
Daily CyberSecurity
Emerging Gentlemen Ransomware Hits 17 Countries with Double Extortion & BYOVD Evasion Tactics
The Gentlemen ransomware group rapidly emerged, targeting 17 countries with double extortion. It uses BYOVD and GPO manipulation to bypass security and hit manufacturing, healthcare, and insurance sectors.
⤷ Title: NexusRoute Uncovered: Android RAT Impersonates Indian E-Challan via GitHub for UPI Fraud & Surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:13:59 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #E_Challan #github #Gymkhana Studio #India #mParivahan #NexusRoute #phishing #surveillance #UPI Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:13:59 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #E_Challan #github #Gymkhana Studio #India #mParivahan #NexusRoute #phishing #surveillance #UPI Fraud
Daily CyberSecurity
NexusRoute Uncovered: Android RAT Impersonates Indian E-Challan via GitHub for UPI Fraud & Surveillance
NexusRoute is a sophisticated Android RAT campaign impersonating Indian E-Challan/mParivahan via GitHub phishing. It steals UPI PINs and conducts surveillance using a native-backed and professionally maintained malware framework.
⤷ Title: Hacker Honeypot? BreachForums Reopens via Emails Sent from French Ministry of the Interior Domain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:10:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BreachForums #cyber attack #Cybercrime #data leak #French Ministry of Interior #Hacking Forum #HoneyPot #Indra #phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:10:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BreachForums #cyber attack #Cybercrime #data leak #French Ministry of Interior #Hacking Forum #HoneyPot #Indra #phishing
Daily CyberSecurity
Hacker Honeypot? BreachForums Reopens via Emails Sent from French Ministry of the Interior Domain
Following a data leak, emails from the French Ministry of the Interior's domain invited hackers to the 'new' BreachForums. The community warns it is likely a highly sophisticated honeypot.
⤷ Title: Switching Teams: iOS 26.3 Beta Adds Official “Transfer to Android” Data Migration Option
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:08:53 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Cross_Platform #Data Migration #Digital Markets Act #eSIM #EU Pressure #google #iOS 26.3 #Transfer to Android
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:08:53 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Cross_Platform #Data Migration #Digital Markets Act #eSIM #EU Pressure #google #iOS 26.3 #Transfer to Android
Daily CyberSecurity
Switching Teams: iOS 26.3 Beta Adds Official "Transfer to Android" Data Migration Option
Apple's iOS 26.3 beta now includes an official "Transfer to Android" option, allowing seamless migration of apps, photos, and eSIM, likely driven by EU regulatory pressure.
⤷ Title: Tech Force: US Government Recruits 1,000 Elite AI Engineers with Apple, Microsoft, and NVIDIA Partnership
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:06:02 +0000
════════════════════════
⌗ Tags: #Technology #AI Recruitment #Apple #Data Modernization #Microsoft #nvidia #OpenAI #Public Service #Tech Force #US government #USDS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:06:02 +0000
════════════════════════
⌗ Tags: #Technology #AI Recruitment #Apple #Data Modernization #Microsoft #nvidia #OpenAI #Public Service #Tech Force #US government #USDS
Daily CyberSecurity
Tech Force: US Government Recruits 1,000 Elite AI Engineers with Apple, Microsoft, and NVIDIA Partnership
The Trump administration launches "Tech Force" to recruit 1,000 elite engineers for two-year terms, partnering with tech giants (Apple, NVIDIA) to upgrade federal AI infrastructure.