⤷ Title: The SSO Trap: How a “Default” Feature is Granting Attackers Admin Access to FortiGate Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:55:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #CVE_2025_59718 #CVE_2025_59719 #Cyberattack 2025 #FortiCloud #Fortinet #FortiOS #network security #SAML #SSO
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:55:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Arctic Wolf #authentication bypass #CVE_2025_59718 #CVE_2025_59719 #Cyberattack 2025 #FortiCloud #Fortinet #FortiOS #network security #SAML #SSO
Penetration Testing Tools
The SSO Trap: How a "Default" Feature is Granting Attackers Admin Access to FortiGate Devices
Arctic Wolf reports the first confirmed intrusions into customer networks in which attackers logged into FortiGate devices via
⤷ Title: Retaliation Strike: 22-Year-Old Arrested After BreachForums Hacks French Ministry of Interior
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:52:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arrest #BreachForums #cyberattack #Cybersecurity 2025 #data breach #French Ministry of the Interior #Hacktivism #Laurent Nuñez #Paris Prosecutor #Police Archives
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:52:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Arrest #BreachForums #cyberattack #Cybersecurity 2025 #data breach #French Ministry of the Interior #Hacktivism #Laurent Nuñez #Paris Prosecutor #Police Archives
Penetration Testing Tools
Retaliation Strike: 22-Year-Old Arrested After BreachForums Hacks French Ministry of Interior
French law enforcement authorities have arrested a 22-year-old man suspected of orchestrating a recent cyberattack against the country’s
⤷ Title: The Play Store Predator: New Cellik Spyware Can Trojanize Any App With One Click
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:49:04 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #App Injection #Cellik #Google Play Store #HyperRat #iVerify #Malware_as_a_Service #mobile security #phishing #Spyware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:49:04 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #App Injection #Cellik #Google Play Store #HyperRat #iVerify #Malware_as_a_Service #mobile security #phishing #Spyware
Penetration Testing Tools
The Play Store Predator: New Cellik Spyware Can Trojanize Any App With One Click
Researchers at iVerify have identified a new Android remote access trojan dubbed Cellik, which blends the capabilities of
⤷ Title: Taming the Wolf: How the 1.8 Million-Strong Kimwolf Botnet Overtook Google Traffic
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:47:16 +0000
════════════════════════
⌗ Tags: #Malware #AISURU #Android TV #BOTNET #DDoS #ENS #EtherHiding #IoT Security #Kimwolf #Proxy_as_a_Service #QiAnXin XLab #Smart Home Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:47:16 +0000
════════════════════════
⌗ Tags: #Malware #AISURU #Android TV #BOTNET #DDoS #ENS #EtherHiding #IoT Security #Kimwolf #Proxy_as_a_Service #QiAnXin XLab #Smart Home Security
Penetration Testing Tools
Taming the Wolf: How the 1.8 Million-Strong Kimwolf Botnet Overtook Google Traffic
The Kimwolf botnet has drawn intense scrutiny after researchers at QiAnXin XLab reported that it had infected more
⤷ Title: Beyond the Shell: Critical React2Shell Exploit Hits Japan to Deploy Stealthy ZnDoor RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:45:54 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #CVE_2025_55182 #Japan Cyber Attacks #malware analysis #Next.js #NTT Security #RCE #React2Shell #threat intelligence #ZnDoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:45:54 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #CVE_2025_55182 #Japan Cyber Attacks #malware analysis #Next.js #NTT Security #RCE #React2Shell #threat intelligence #ZnDoor
Penetration Testing Tools
Beyond the Shell: Critical React2Shell Exploit Hits Japan to Deploy Stealthy ZnDoor RAT
Since early December 2025, SOC teams in Japan have been observing a wave of attacks exploiting React2Shell (CVE-2025-55182)—a
⤷ Title: Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 03:08:18 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #Android Binder #CVE_2025_68260 #Greg Kroah_Hartman #Kernel Crash #Linux Kernel #Mainline Kernel #memory safety #race condition #Rust #Rust_for_Linux
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 03:08:18 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #Android Binder #CVE_2025_68260 #Greg Kroah_Hartman #Kernel Crash #Linux Kernel #Mainline Kernel #memory safety #race condition #Rust #Rust_for_Linux
Daily CyberSecurity
Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel
Linux logs its first Rust CVE (CVE-2025-68260): a race condition in the Android Binder driver causing kernel crashes. Fixed in 6.18.1 and 6.19-rc1.
⤷ Title: Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:30:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2025_68385 #cybersecurity #data visualization #Elastic Stack #Kibana #Patch Update #Session Hijacking #Vega Visualization #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:30:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2025_68385 #cybersecurity #data visualization #Elastic Stack #Kibana #Patch Update #Session Hijacking #Vega Visualization #XSS
Daily CyberSecurity
Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts
Elastic patches a High-severity XSS flaw (CVE-2025-68385) in Kibana. Attackers can weaponize Vega visualizations to hijack sessions. Update now!
⤷ Title: Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 01:50:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #CVE_2025_68161 #Encryption Bypass #Hostname Verification #Java security #Log4j #mitm attack #network_security #Socket Appender #tls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 01:50:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #CVE_2025_68161 #Encryption Bypass #Hostname Verification #Java security #Log4j #mitm attack #network_security #Socket Appender #tls
Daily CyberSecurity
Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption
A new Log4j flaw (CVE-2025-68161) breaks TLS hostname verification, allowing Man-in-the-Middle attacks on log data. Upgrade to v2.25.3 now.
⤷ Title: WatchGuard Under Siege: Critical CVSS 9.3 Zero-Day Exploited in the Wild to Hijack Corporate Firewalls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 01:38:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14733 #Firebox #Fireware OS #IKEv2 #memory corruption #network_security #Remote Code Execution #VPN security #WatchGuard #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 01:38:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14733 #Firebox #Fireware OS #IKEv2 #memory corruption #network_security #Remote Code Execution #VPN security #WatchGuard #zero_day
Daily CyberSecurity
WatchGuard Under Siege: Critical CVSS 9.3 Zero-Day Exploited in the Wild to Hijack Corporate Firewalls
WatchGuard warns of an active CVSS 9.3 zero-day (CVE-2025-14733). Attackers are exploiting IKEv2 VPNs for root RCE. Patch and rotate secrets now!
⤷ Title: Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:50:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cluster Management #Credential Caching #CVE_2025_14269 #DevSecOps #Headlamp #Helm #K8s Security #Kubernetes #Patch Update #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:50:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cluster Management #Credential Caching #CVE_2025_14269 #DevSecOps #Headlamp #Helm #K8s Security #Kubernetes #Patch Update #Vulnerability
Daily CyberSecurity
Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters
A Headlamp flaw allows unauthenticated users to reuse cached credentials to hijack Kubernetes Helm operations. Update to v0.39.0!
⤷ Title: FreeBSD Network Alert: Malicious IPv6 Packets Can Trigger Remote Code Execution via resolvconf (CVE-2025-14558)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:42:10 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2025_14558 #freebsd #IPv6 #Networking Stack #OS Security #rce #resolvconf #Router Advertisement #rtsold #Shell Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:42:10 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2025_14558 #freebsd #IPv6 #Networking Stack #OS Security #rce #resolvconf #Router Advertisement #rtsold #Shell Injection
Daily CyberSecurity
FreeBSD Network Alert: Malicious IPv6 Packets Can Trigger Remote Code Execution via resolvconf (CVE-2025-14558)
A High-severity flaw (CVE-2025-14558) in FreeBSD allows Remote Code Execution via malicious IPv6 router advertisements and unquoted shell inputs.
⤷ Title: Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
Daily CyberSecurity
Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
Roundcube patches two High-severity flaws: an SVG-based XSS and a CSS sanitizer bypass. Protect your inbox—update to v1.6.12 or v1.5.12 now.
⤷ Title: YouTube Ghost Network: The New GachiLoader Malware Hiding in Your Favorite Video Links
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:33:10 +0000
════════════════════════
⌗ Tags: #Malware #Check Point Research #Cracked Software #cybersecurity #GachiLoader #Game Cheats #Infostealer #malware #Node.js Malware #Rhadamanthys #YouTube Ghost Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:33:10 +0000
════════════════════════
⌗ Tags: #Malware #Check Point Research #Cracked Software #cybersecurity #GachiLoader #Game Cheats #Infostealer #malware #Node.js Malware #Rhadamanthys #YouTube Ghost Network
Daily CyberSecurity
YouTube Ghost Network: The New GachiLoader Malware Hiding in Your Favorite Video Links
Check Point Research exposes the YouTube Ghost Network, using GachiLoader to spread Rhadamanthys infostealer through cracked software and game cheats.
⤷ Title: Poisoned Dependencies: How Nethereum.All and 10M+ Fake Downloads Looted .NET Crypto Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET #Blockchain security #Cryptocurrency Theft #Malicious packages #Nethereum.All #NuGet #ReversingLabs #supply chain attack #Typosquatting #Wallet drainer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET #Blockchain security #Cryptocurrency Theft #Malicious packages #Nethereum.All #NuGet #ReversingLabs #supply chain attack #Typosquatting #Wallet drainer
Daily CyberSecurity
Poisoned Dependencies: How Nethereum.All and 10M+ Fake Downloads Looted .NET Crypto Developers
ReversingLabs uncovered Nethereum.All, a malicious NuGet package with 10M+ fake downloads designed to drain crypto wallets and steal API secrets.
⤷ Title: Early-Boot Attack: UEFI Flaw in ASRock, ASUS, & MSI Boards Lets Hackers Bypass OS Security via PCIe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASRock #ASUS #CVE_2025_14304 #DMA Protection #Gigabyte #Hardware Vulnerability #IOMMU #Motherboard Security #MSI #PCIe #UEFI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASRock #ASUS #CVE_2025_14304 #DMA Protection #Gigabyte #Hardware Vulnerability #IOMMU #Motherboard Security #MSI #PCIe #UEFI
Daily CyberSecurity
Early-Boot Attack: UEFI Flaw in ASRock, ASUS, & MSI Boards Lets Hackers Bypass OS Security via PCIe
A critical UEFI flaw in ASRock, ASUS, and MSI motherboards fails to enable IOMMU, allowing pre-boot memory access via PCIe devices.
⤷ Title: Mario’s Deadly Upgrade: RansomHouse Unveils Dual-Key Encryption to Defeat Backups and Recovery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:17:00 +0000
════════════════════════
⌗ Tags: #Malware #Double Extortion #Dual_Key Encryption #Dynamic Chunking #Encryption Upgrade #healthcare security #Jolly Scorpius #Mario Malware #RaaS #RansomHouse #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:17:00 +0000
════════════════════════
⌗ Tags: #Malware #Double Extortion #Dual_Key Encryption #Dynamic Chunking #Encryption Upgrade #healthcare security #Jolly Scorpius #Mario Malware #RaaS #RansomHouse #Unit 42
Daily CyberSecurity
Mario’s Deadly Upgrade: RansomHouse Unveils Dual-Key Encryption to Defeat Backups and Recovery
Jolly Scorpius has upgraded its Mario ransomware with multi-layered, dual-key encryption and dynamic chunking to bypass recovery and lock down data.
⤷ Title: Phantom v3.5 Alert: New Info-Stealer Disguised as Adobe Update Uses SMTP to Loot Digital Lives
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:11:31 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Installer #Credential Theft #crypto wallet #info_stealer #JavaScript malware #K7 Security Labs #malware #Phantom Stealer #powershell #SMTP Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:11:31 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Installer #Credential Theft #crypto wallet #info_stealer #JavaScript malware #K7 Security Labs #malware #Phantom Stealer #powershell #SMTP Exfiltration
Daily CyberSecurity
Phantom v3.5 Alert: New Info-Stealer Disguised as Adobe Update Uses SMTP to Loot Digital Lives
Phantom v3.5 info-stealer targets passwords and crypto via a fake Adobe installer. It uses SMTP to exfiltrate data directly to attackers.
⤷ Title: The Final Cut: Why the Oscars are Leaving ABC for a YouTube-Only Future in 2029
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:08:15 +0000
════════════════════════
⌗ Tags: #Technology #101st Oscars #ABC #Academy Awards #AMPAS #Bill Kramer #Digital Transformation #Google Arts & Culture #Live Events #Oscars #streaming #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:08:15 +0000
════════════════════════
⌗ Tags: #Technology #101st Oscars #ABC #Academy Awards #AMPAS #Bill Kramer #Digital Transformation #Google Arts & Culture #Live Events #Oscars #streaming #youtube
Daily CyberSecurity
The Final Cut: Why the Oscars are Leaving ABC for a YouTube-Only Future in 2029
Starting in 2029, the Oscars move exclusively to YouTube, ending a 50-year run on ABC to reach a global, digital-first audience.
⤷ Title: VPN Betrayal: Popular “Free” Extensions Caught Siphoning 8 Million Users’ Private AI Chats
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:05:33 +0000
════════════════════════
⌗ Tags: #Data Leak #1ClickVPN #AI Privacy #BiScience #Browser Extensions #ChatGPT #Claude #Data Broker #Gemini #KOI Security #Urban Browser Guard #Urban VPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:05:33 +0000
════════════════════════
⌗ Tags: #Data Leak #1ClickVPN #AI Privacy #BiScience #Browser Extensions #ChatGPT #Claude #Data Broker #Gemini #KOI Security #Urban Browser Guard #Urban VPN
Daily CyberSecurity
VPN Betrayal: Popular "Free" Extensions Caught Siphoning 8 Million Users’ Private AI Chats
Security firm KOI warns: Urban VPN extensions are secretly harvesting full AI chat transcripts for data brokers. Uninstall immediately to protect your data.
⤷ Title: Flash Forward: Google’s New Gemini 3 Flash Shatters Efficiency Records and Rival Flagships
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:00:48 +0000
════════════════════════
⌗ Tags: #Technology #AI Arms Race #AI Benchmarks #Generative AI #Google Gemini 3 Flash #Google Search AI Mode #GPT_5.2 #Humanity's Last Exam #machine_learning #MMMU_Pro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:00:48 +0000
════════════════════════
⌗ Tags: #Technology #AI Arms Race #AI Benchmarks #Generative AI #Google Gemini 3 Flash #Google Search AI Mode #GPT_5.2 #Humanity's Last Exam #machine_learning #MMMU_Pro
Daily CyberSecurity
Flash Forward: Google’s New Gemini 3 Flash Shatters Efficiency Records and Rival Flagships
Google’s Gemini 3 Flash defies logic: an ultra-efficient model scoring 81.2% on MMMU-Pro, outperforming OpenAI’s flagship GPT-5.2 in multimodal reasoning.
⤷ Title: Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182)
════════════════════════
𐀪 Author: Frostynxth
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 03:09:41 GMT
════════════════════════
⌗ Tags: #zero_day #cve #bug_bounty #cyberattack #cybesecurity
════════════════════════
𐀪 Author: Frostynxth
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 03:09:41 GMT
════════════════════════
⌗ Tags: #zero_day #cve #bug_bounty #cyberattack #cybesecurity
Medium
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182)
Understanding React2Shell: A Critical Vulnerability in React Server Components (CVE-2025–55182) Introduction In the rapidly evolving landscape of web development, React has established itself as a …