⤷ Title: The VPN Stand-off: Denmark Backtracks on Controversial VPN Ban Amid Authoritarian Concerns
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:27:42 +0000
════════════════════════
⌗ Tags: #Technology #Chat Control #copyright law #Denmark #Digital Privacy #EU Regulation #Geoblocking #Jakob Engel_Schmidt #Net Neutrality #Online Piracy #VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:27:42 +0000
════════════════════════
⌗ Tags: #Technology #Chat Control #copyright law #Denmark #Digital Privacy #EU Regulation #Geoblocking #Jakob Engel_Schmidt #Net Neutrality #Online Piracy #VPN
Penetration Testing Tools
The VPN Stand-off: Denmark Backtracks on Controversial VPN Ban Amid Authoritarian Concerns
The Danish government has opened a public consultation on amendments to copyright and broadcasting laws that would make
⤷ Title: The Developer Win: GitHub Postpones Self-Hosted Runner Fee After Massive Community Outcry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:19:25 +0000
════════════════════════
⌗ Tags: #Technology #CI/CD #Developer Backlash #DevOps #GitHub Actions #GitHub Changelog #GitHub Pricing #Microsoft #Platform Fee #Self_Hosted Runners #Tech News 2025
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:19:25 +0000
════════════════════════
⌗ Tags: #Technology #CI/CD #Developer Backlash #DevOps #GitHub Actions #GitHub Changelog #GitHub Pricing #Microsoft #Platform Fee #Self_Hosted Runners #Tech News 2025
Daily CyberSecurity
The Developer Win: GitHub Postpones Self-Hosted Runner Fee After Massive Community Outcry
GitHub walks back its plan to charge $0.002/min for self-hosted runners, postponing the fee indefinitely following intense backlash from the community.
⤷ Title: CVE-2025-37164 (CVSS 10.0): Unauthenticated HPE OneView RCE Grants Total Control Over Data Centers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:59:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_37164 #CVSS 10.0 #Data Center #HPE #HPE Synergy #hybrid cloud #Infrastructure Management #OneView #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:59:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_37164 #CVSS 10.0 #Data Center #HPE #HPE Synergy #hybrid cloud #Infrastructure Management #OneView #rce #Remote Code Execution
Daily CyberSecurity
CVE-2025-37164 (CVSS 10.0): Unauthenticated HPE OneView RCE Grants Total Control Over Data Centers
HPE issued an urgent alert for a CVSS 10.0 RCE in OneView. Attackers can seize unauthenticated control of data centers. Upgrade to v11.00+ now.
⤷ Title: CISA Alert: Chinese Hackers Weaponize CVSS 10 Cisco Zero-Day & SonicWall Exploit Chains
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:41:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASUS Live Update #Chinese APT #CISA KEV #Cisco Secure Email Gateway #CVE_2025_20393 #Cyber Security #Root RCE #SonicWall SMA1000 #UAT_9686 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:41:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASUS Live Update #Chinese APT #CISA KEV #Cisco Secure Email Gateway #CVE_2025_20393 #Cyber Security #Root RCE #SonicWall SMA1000 #UAT_9686 #zero_day
Daily CyberSecurity
CISA Alert: Chinese Hackers Weaponize CVSS 10 Cisco Zero-Day & SonicWall Exploit Chains
CISA adds a CVSS 10 Cisco zero-day and SonicWall exploit chains to its KEV catalog, warning of active exploitation by Chinese APTs and supply chain attacks.
⤷ Title: Cisco Zero-Day Siege: Chinese Group UAT-9686 Deploys ‘Aqua’ Malware via CVSS 10 Root Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 01:52:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AquaShell #Chinese APT #cisco #Cisco Talos #CVE_2025_20393 #root access #Secure Email Gateway #Spam Quarantine #UAT_9686 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 01:52:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AquaShell #Chinese APT #cisco #Cisco Talos #CVE_2025_20393 #root access #Secure Email Gateway #Spam Quarantine #UAT_9686 #zero_day
Daily CyberSecurity
Cisco Zero-Day Siege: Chinese Group UAT-9686 Deploys 'Aqua' Malware via CVSS 10 Root Exploit
Cisco warns of a CVSS 10 zero-day (CVE-2025-20393) exploited by Chinese APT UAT-9686 to backdoor Secure Email Gateways with the Aqua malware suite.
⤷ Title: Zero-Day Warning: Hackers Chain SonicWall SMA1000 Flaws for Unauthenticated Root RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 01:43:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23006 #CVE_2025_40602 #Patch Update #privilege escalation #rce #Remote Code Execution #root access #Secure Access Gateway #SMA1000 #SonicWall
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 01:43:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23006 #CVE_2025_40602 #Patch Update #privilege escalation #rce #Remote Code Execution #root access #Secure Access Gateway #SMA1000 #SonicWall
Daily CyberSecurity
Zero-Day Warning: Hackers Chain SonicWall SMA1000 Flaws for Unauthenticated Root RCE
SonicWall warns of zero-day attacks chaining CVE-2025-40602 and CVE-2025-23006 to gain unauthenticated root access on SMA1000 appliances. Patch now!
⤷ Title: Academic Ambush: How the Forum Troll APT Hijacks Scholars’ Systems via Fake Plagiarism Reports
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:44:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Academic Espionage #APT #COM hijacking #Forum Troll #kaspersky #malware #phishing #Russian Research #social engineering #Tuoni Framework
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:44:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Academic Espionage #APT #COM hijacking #Forum Troll #kaspersky #malware #phishing #Russian Research #social engineering #Tuoni Framework
Daily CyberSecurity
Academic Ambush: How the Forum Troll APT Hijacks Scholars' Systems via Fake Plagiarism Reports
The Forum Troll APT is targeting Russian scholars with highly personalized phishing lures and the Tuoni framework disguised as plagiarism reports.
⤷ Title: Locked Out of the Cloud: Hackers Use AWS Termination Protection to Hijack ECS for Unstoppable Crypto Mining
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon ECS #Amazon GuardDuty #AWS #AWS Lambda #Cloud Security #Cryptojacking #EC2 #IAM Security #persistence #Termination Protection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon ECS #Amazon GuardDuty #AWS #AWS Lambda #Cloud Security #Cryptojacking #EC2 #IAM Security #persistence #Termination Protection
Daily CyberSecurity
Locked Out of the Cloud: Hackers Use AWS Termination Protection to Hijack ECS for Unstoppable Crypto Mining
Hackers are weaponizing AWS termination protection to lock defenders out while they mine crypto on hijacked ECS/EC2 resources using a malicious Docker image.
⤷ Title: Blurred Deception: Russian APT Targets Transnistria and NATO with High-Pressure Phishing Lures
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:37:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Credential Harvesting #CSS Blur #HTML Malware #NATO #phishing #Russian APT #social engineering #StrikeReady Labs #Transnistria
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:37:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Credential Harvesting #CSS Blur #HTML Malware #NATO #phishing #Russian APT #social engineering #StrikeReady Labs #Transnistria
Daily CyberSecurity
Blurred Deception: Russian APT Targets Transnistria and NATO with High-Pressure Phishing Lures
A Russian APT is targeting Transnistria and NATO entities using blurred HTML attachments to harvest credentials. The 2025 campaign mimics official presidential decrees.
⤷ Title: “Better Auth” Framework Alert: The Double-Slash Trick That Bypasses Security Controls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:33:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #Better Auth #CVSS 8.6 #javascript #Path Normalization #Proxy Security #Rate Limit Evasion #rou3 #TypeScript #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:33:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #Better Auth #CVSS 8.6 #javascript #Path Normalization #Proxy Security #Rate Limit Evasion #rou3 #TypeScript #Web Security
Daily CyberSecurity
"Better Auth" Framework Alert: The Double-Slash Trick That Bypasses Security Controls
A normalization flaw in Better Auth's router allows attackers to bypass access controls and rate limits using simple double-slash URLs.
⤷ Title: Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
Daily CyberSecurity
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
Ink Dragon is weaponizing government servers in Europe using a relay-centric mesh. By hijacking IIS servers, they mask C2 traffic across global networks.
⤷ Title: CVE-2025-46295 (CVSS 9.8): Critical Apache Commons Text Flaw Risks Total Server Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:22:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Commons Text #CVE_2025_46295 #FileMaker Server #Java security #Patch Update #rce #Remote Code Execution #String Interpolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:22:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Commons Text #CVE_2025_46295 #FileMaker Server #Java security #Patch Update #rce #Remote Code Execution #String Interpolation
Daily CyberSecurity
CVE-2025-46295 (CVSS 9.8): Critical Apache Commons Text Flaw Risks Total Server Takeover
A critical RCE flaw (CVSS 9.8) in Apache Commons Text mirrors Log4Shell, allowing server takeover. FileMaker Server users must update to v22.0.4 now.
⤷ Title: RTO Challan Scam: How a Fake Traffic Ticket and a Malicious VPN Can Drain Your Bank Account
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aadhaar Theft #Android Malware #Banking Trojan #identity theft #India #Mobile Fraud #RTO Challan #UPI Fraud #VPN Tunneling #WhatsApp Scam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aadhaar Theft #Android Malware #Banking Trojan #identity theft #India #Mobile Fraud #RTO Challan #UPI Fraud #VPN Tunneling #WhatsApp Scam
Daily CyberSecurity
RTO Challan Scam: How a Fake Traffic Ticket and a Malicious VPN Can Drain Your Bank Account
RTO Challan malware hijacks Android devices in India using a fake traffic ticket lure, a malicious VPN, and SMS interception to steal UPI PINs and Aadhaar data.
⤷ Title: Node.js Alert: systeminformation Flaw Risks Windows RCE for 16M+ Monthly Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:12:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_68154 #cybersecurity #Node.js #npm #powershell #rce #systeminformation #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:12:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_68154 #cybersecurity #Node.js #npm #powershell #rce #systeminformation #windows
Daily CyberSecurity
Node.js Alert: systeminformation Flaw Risks Windows RCE for 16M+ Monthly Users
A critical OS Command Injection (CVE-2025-68154) in the systeminformation Node.js library risks RCE on Windows. Affects 16M+ users. Upgrade to v5.27.14.
⤷ Title: The $10B Pivot: OpenAI in Talks for Massive Amazon Funding—But There’s a Silicon Catch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:10:52 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Amazon #AWS #Cloud Computing #Inferentia #Microsoft #nvidia #OpenAI #Sam Altman #Silicon War #Trainium #Venture Capital
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:10:52 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Amazon #AWS #Cloud Computing #Inferentia #Microsoft #nvidia #OpenAI #Sam Altman #Silicon War #Trainium #Venture Capital
Daily CyberSecurity
The $10B Pivot: OpenAI in Talks for Massive Amazon Funding—But There’s a Silicon Catch
OpenAI eyes a $10B+ investment from Amazon, but the deal requires a major shift: switching from NVIDIA GPUs to Amazon’s custom Trainium AI chips.
⤷ Title: The Internet Rewired: Cloudflare 2025 Review Unveils the AI Bot War and a 19% Traffic Surge
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:08:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2025 Year in Review #AI Bots #Cloudflare Radar #cybersecurity #DDoS attacks #Googlebot #Internet Outages #Matthew Prince #Post_Quantum Cryptography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:08:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2025 Year in Review #AI Bots #Cloudflare Radar #cybersecurity #DDoS attacks #Googlebot #Internet Outages #Matthew Prince #Post_Quantum Cryptography
Daily CyberSecurity
The Internet Rewired: Cloudflare 2025 Review Unveils the AI Bot War and a 19% Traffic Surge
Cloudflare’s 2025 report reveals a 19% traffic spike, Googlebot’s dominance in the "AI bot war," and the rise of post-quantum encryption for 52% of users.
⤷ Title: Self-Hosting No Longer Free: GitHub Introduces New $0.002/Min Platform Fee for Actions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:06:45 +0000
════════════════════════
⌗ Tags: #Technology #Blacksmith #CI/CD Automation #CI/CD Pricing #Cloud Infrastructure #DevOps #GitHub Actions #GitHub Hosted Runners #Platform Fee #Self_Hosted Runners
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:06:45 +0000
════════════════════════
⌗ Tags: #Technology #Blacksmith #CI/CD Automation #CI/CD Pricing #Cloud Infrastructure #DevOps #GitHub Actions #GitHub Hosted Runners #Platform Fee #Self_Hosted Runners
Daily CyberSecurity
Self-Hosting No Longer Free: GitHub Introduces New $0.002/Min Platform Fee for Actions
Starting March 1, 2026, GitHub will charge $0.002/min for self-hosted runners, ending the "free control plane" era for private repositories.
⤷ Title: Mozilla’s New Chapter: CEO Anthony Enzor-DeMeo to Transform Firefox into an AI-Powered Powerhouse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:02:14 +0000
════════════════════════
⌗ Tags: #Technology #AI Browser #Anthony Enzor_DeMeo #ChatGPT #Claude #firefox #Google Search Deal #mozilla #open web #privacy #Tech Leadership
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:02:14 +0000
════════════════════════
⌗ Tags: #Technology #AI Browser #Anthony Enzor_DeMeo #ChatGPT #Claude #firefox #Google Search Deal #mozilla #open web #privacy #Tech Leadership
Daily CyberSecurity
Mozilla’s New Chapter: CEO Anthony Enzor-DeMeo to Transform Firefox into an AI-Powered Powerhouse
New CEO Anthony Enzor-DeMeo announces Firefox’s evolution into an "AI browser," offering users a choice of models like ChatGPT and Claude by 2026.
⤷ Title: The 45-Day Era Begins: Let’s Encrypt Unveils Generation Y Hierarchy and IP-Based TLS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:00:49 +0000
════════════════════════
⌗ Tags: #Technology #45_Day Lifespan #ACME #Certificate Authority #cybersecurity #Generation Y #IP Address SSL #ISRG #Let's Encrypt #SSL Security #TLS Certificates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:00:49 +0000
════════════════════════
⌗ Tags: #Technology #45_Day Lifespan #ACME #Certificate Authority #cybersecurity #Generation Y #IP Address SSL #ISRG #Let's Encrypt #SSL Security #TLS Certificates
Daily CyberSecurity
The 45-Day Era Begins: Let’s Encrypt Unveils Generation Y Hierarchy and IP-Based TLS
Let’s Encrypt moves to Generation Y roots, launches IP address certificates, and sets a path for 45-day lifetimes by 2028. Is your automation ready?
⤷ Title: Weekly Threat Intelligence Report 15 Dec 2025
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:22:41 GMT
════════════════════════
⌗ Tags: #threat_intelligence #infosec #hacking #cyberattack #cybersecurity
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:22:41 GMT
════════════════════════
⌗ Tags: #threat_intelligence #infosec #hacking #cyberattack #cybersecurity
Medium
Weekly Threat Intelligence Report 15 Dec 2025
This document summarizes key cyber threats identified between December 8and December 14, 2025, including related threat events
⤷ Title: [Write-up] HackTheBox - Bike
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:02:20 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #hack_the_box_walkthrough #hack_the_box_writeup #hackthebox #hackthebox_writeup
════════════════════════
𐀪 Author: Mattana Olarikded
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 02:02:20 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #hack_the_box_walkthrough #hack_the_box_writeup #hackthebox #hackthebox_writeup
Medium
[Write-up] HackTheBox - Bike
สวัสดีค่ะ วันนี้เราจะมาแชร์วิธีการหา root flag ในกล่อง Bike ซึ่งเป็นกล่องใน Starting Point - Tier 1 ของ HackTheBox ค่ะ ถ้าพร้อมแล้ว เราก็กด…