⤷ Title: TryHackMe Advent of Cyber 2025 (Day 21) : Malware Analysis — Malhare.exe
════════════════════════
𐀪 Author: Hibullahi AbdulAzeez
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 19:56:37 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #malware_analysis #aoc2025 #advent_of_cyber_2025
════════════════════════
𐀪 Author: Hibullahi AbdulAzeez
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 19:56:37 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #malware_analysis #aoc2025 #advent_of_cyber_2025
Medium
TryHackMe Advent of Cyber 2025 (Day 21) : Malware Analysis — Malhare.exe
Static Analysis of HTA Malware: From Surveys to Security Failures
⤷ Title: Steganography 101: Hiding secret in plain sights using STEGHIDE
════════════════════════
𐀪 Author: Madhu Sudhan
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 21:43:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #image_steganography #kali_linux #steganography
════════════════════════
𐀪 Author: Madhu Sudhan
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 21:43:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #image_steganography #kali_linux #steganography
Medium
Steganography 101: Hiding secret in plain sights using STEGHIDE
1. Introduction:
⤷ Title: Why Cybersecurity Beginners Fail (3 Common Mistakes)
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 21:15:10 GMT
════════════════════════
⌗ Tags: #carrer #common_mistakes #cybersecurity #ethical_hacking #tech_skills
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 21:15:10 GMT
════════════════════════
⌗ Tags: #carrer #common_mistakes #cybersecurity #ethical_hacking #tech_skills
Medium
Why Cybersecurity Beginners Fail (3 Common Mistakes)
The Brutal Truth I Wish Someone Had Told Me Years Ago
⤷ Title: Finishing the year 2025, My Cybersecurity Journey
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 20:27:51 GMT
════════════════════════
⌗ Tags: #tcm_security #comptia #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Aaronashley
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 20:27:51 GMT
════════════════════════
⌗ Tags: #tcm_security #comptia #ethical_hacking #cybersecurity
Medium
Finishing the year 2025, My Cybersecurity Journey
The start of The Husky Hacker.
⤷ Title: VibeHackAI: Human‑Led Multi-Agent AI Penetration Testing Team
════════════════════════
𐀪 Author: Kyo
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 23:58:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ai #ai_agent #open_source
════════════════════════
𐀪 Author: Kyo
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 23:58:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #ai #ai_agent #open_source
Medium
VibeHackAI: Human‑Led Multi-Agent AI Penetration Testing Team
Have you ever imagined being the leader of a team made up only of members with over IQ140?
⤷ Title: Advent of Cyber 2025 Day 21 — Malware Analysis Bonus Challenge
════════════════════════
𐀪 Author: Matt Swann
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 23:39:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #reverse_engineering #malware_analysis #advent_of_cyber_2025 #tryhackme
════════════════════════
𐀪 Author: Matt Swann
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 23:39:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #reverse_engineering #malware_analysis #advent_of_cyber_2025 #tryhackme
Medium
Advent of Cyber 2025 Day 21 — Malware Analysis Bonus Challenge
This write up is for the bonus challenge at the end of Day 21 — “Malware Analysis — Malhare.exe” which, when completed, provides a key for…
⤷ Title: When You Post, You Become the Target
════════════════════════
𐀪 Author: Sam Galope
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 23:04:48 GMT
════════════════════════
⌗ Tags: #osint #ethical_hacking #cybersecurity #information_security #osint_investigation
════════════════════════
𐀪 Author: Sam Galope
════════════════════════
ⴵ Time: Sun, 21 Dec 2025 23:04:48 GMT
════════════════════════
⌗ Tags: #osint #ethical_hacking #cybersecurity #information_security #osint_investigation
Medium
When You Post, You Become the Target
A real-world lesson in public OSINT from a Philippine scandal
⤷ Title: Vectored Overloading: New “Ghost Network” Hijacks YouTube to Deploy Stealthy GachiLoader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:00:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Check Point Research #GachiLoader #Infostealer #Kidkadi #Malware_as_a_Service #Node.js Malware #PE Injection #Rhadamanthys #Vectored Overloading #YouTube Ghost Network
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:00:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Check Point Research #GachiLoader #Infostealer #Kidkadi #Malware_as_a_Service #Node.js Malware #PE Injection #Rhadamanthys #Vectored Overloading #YouTube Ghost Network
Penetration Testing Tools
Vectored Overloading: New "Ghost Network" Hijacks YouTube to Deploy Stealthy GachiLoader
Check Point researchers have uncovered a new campaign known as the so-called YouTube Ghost Network—a web of hijacked
⤷ Title: Router Risk: New FreeBSD Flaw Exploits IPv6 to Grant Remote Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 01:58:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_14558 #FreeBSD #IPv6 #network security #OS Command Injection #Patch Alert #RCE #resolvconf #Router Advertisement #rtsold
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 01:58:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_14558 #FreeBSD #IPv6 #network security #OS Command Injection #Patch Alert #RCE #resolvconf #Router Advertisement #rtsold
Penetration Testing Tools
Router Risk: New FreeBSD Flaw Exploits IPv6 to Grant Remote Code Execution
A newly discovered vulnerability in FreeBSD components responsible for IPv6 configuration allows an attacker on the same local
⤷ Title: The Two-Day Tax: How Much of Your Life Is Being Stolen by Online Ads?
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 01:56:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2025 Report #ad blocker #AdGuard #Cyber Security #data privacy #Data Savings #FBI Recommendations #Google Trackers #Page Load Speed #web performance
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 01:56:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2025 Report #ad blocker #AdGuard #Cyber Security #data privacy #Data Savings #FBI Recommendations #Google Trackers #Page Load Speed #web performance
Penetration Testing Tools
The Two-Day Tax: How Much of Your Life Is Being Stolen by Online Ads?
Have you ever considered how much of your personal time is quietly consumed by those “universally beloved” online
⤷ Title: Ghost in the Machine: The $6B “Doublespeed” Leak Exposes the AI Warehouse Hijacking TikTok
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 01:55:49 +0000
════════════════════════
⌗ Tags: #Data Leak #a16z #AI Influencers #Algorithmic Manipulation #Andreessen Horowitz #Doublespeed #Generative AI #Kira Hacker #Smartphone Farm #Social Media Fraud #TikTok
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 01:55:49 +0000
════════════════════════
⌗ Tags: #Data Leak #a16z #AI Influencers #Algorithmic Manipulation #Andreessen Horowitz #Doublespeed #Generative AI #Kira Hacker #Smartphone Farm #Social Media Fraud #TikTok
Penetration Testing Tools
Ghost in the Machine: The $6B "Doublespeed" Leak Exposes the AI Warehouse Hijacking TikTok
In an industry where artificial intelligence increasingly sets the rules of the game, one startup has found itself
⤷ Title: n8n Under Fire: Critical CVSS 10.0 RCE Vulnerability Grants Total Server Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:55:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_68613 #Cyber Security #DevOps #Expression Injection #infosec #n8n #Patch Update #rce #Remote Code Execution #Workflow Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:55:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_68613 #Cyber Security #DevOps #Expression Injection #infosec #n8n #Patch Update #rce #Remote Code Execution #Workflow Automation
Daily CyberSecurity
n8n Under Fire: Critical CVSS 10.0 RCE Vulnerability Grants Total Server Access
n8n warns of a CVSS 10.0 RCE (CVE-2025-68613) in its expression system. Attackers can seize total server control. Upgrade to v1.122.0 immediately.
⤷ Title: Hackers Abuse “Device Codes” to Bypass Security and Seize Microsoft 365 Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #cybersecurity #Device Authorization #MFA Bypass #Microsoft 365 #OAuth 2.0 #phishing #Proofpoint #social engineering #Token Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #cybersecurity #Device Authorization #MFA Bypass #Microsoft 365 #OAuth 2.0 #phishing #Proofpoint #social engineering #Token Theft
Daily CyberSecurity
Hackers Abuse "Device Codes" to Bypass Security and Seize Microsoft 365 Accounts
Proofpoint warns of a surge in device code phishing where attackers abuse Microsoft 365 OAuth flows to hijack accounts and bypass MFA.
⤷ Title: The Silent Hijacker: New Cellik Android RAT Turns Legitimate Google Play Apps into Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:24 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #APK Builder #Cellik #Credential Theft #Google Play Store #iVerify #Malware_as_a_Service #mobile security #Remote Access Trojan #spyware #vnc
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:24 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #APK Builder #Cellik #Credential Theft #Google Play Store #iVerify #Malware_as_a_Service #mobile security #Remote Access Trojan #spyware #vnc
Daily CyberSecurity
The Silent Hijacker: New Cellik Android RAT Turns Legitimate Google Play Apps into Surveillance Tools
iVerify exposes Cellik, a $150/mo Android RAT that wraps malicious code inside Play Store apps to grant attackers total device control.
⤷ Title: Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
Daily CyberSecurity
Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
NIST warns of a critical Exim 4.99 flaw. A failed SQLi patch allows attackers to poison SQLite records and trigger a 1.5MB heap buffer overflow.
⤷ Title: “ClickFix” Trap: Fake Human Verification Leads to Qilin Ransomware Infection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
Daily CyberSecurity
"ClickFix" Trap: Fake Human Verification Leads to Qilin Ransomware Infection
Sophos CTU reveals how the ClickFix tactic led to a Qilin ransomware attack via NetSupport RAT and StealC V2 using stolen VPN credentials.
⤷ Title: TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #AuraStealer #Cyber Security #Data Theft #Gen Digital #Infostealer #powershell #Scam_Yourself #social engineering #TikTok Malware #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #AuraStealer #Cyber Security #Data Theft #Gen Digital #Infostealer #powershell #Scam_Yourself #social engineering #TikTok Malware #Windows malware
Daily CyberSecurity
TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
Gen Digital uncovers AuraStealer, a new infostealer using TikTok "Scam-Yourself" tactics to trick users into infecting their own Windows PCs.
⤷ Title: The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
Daily CyberSecurity
The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
RSF uncovers ResidentBat, a Belarusian KGB spyware physically installed during interrogations to hijack encrypted messages and monitor journalists.
⤷ Title: Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
Daily CyberSecurity
Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
A joint Hunt.io and Acronis report exposes the shared infrastructure behind Lazarus and Kimsuky, revealing the unified web of North Korean hacking.
⤷ Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Daily CyberSecurity
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
Apache NiFi patches a High-severity flaw (CVE-2025-66524) in the GetAsanaObject processor. Unfiltered deserialization risks system compromise. Update now!
⤷ Title: North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:18:02 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #DocSwap #DPRK #ENKI Research #Kimsuky #mobile security #North Korea #QR Code Scam #rat #smishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:18:02 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #DocSwap #DPRK #ENKI Research #Kimsuky #mobile security #North Korea #QR Code Scam #rat #smishing
Daily CyberSecurity
North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
Kimsuky is deploying a new DOCSWAP RAT via QR codes and smishing. The DPRK-linked malware turns phones into surveillance tools for data theft.