⤷ Title: Hackers Abuse “Device Codes” to Bypass Security and Seize Microsoft 365 Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #cybersecurity #Device Authorization #MFA Bypass #Microsoft 365 #OAuth 2.0 #phishing #Proofpoint #social engineering #Token Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #cybersecurity #Device Authorization #MFA Bypass #Microsoft 365 #OAuth 2.0 #phishing #Proofpoint #social engineering #Token Theft
Daily CyberSecurity
Hackers Abuse "Device Codes" to Bypass Security and Seize Microsoft 365 Accounts
Proofpoint warns of a surge in device code phishing where attackers abuse Microsoft 365 OAuth flows to hijack accounts and bypass MFA.
⤷ Title: The Silent Hijacker: New Cellik Android RAT Turns Legitimate Google Play Apps into Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:24 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #APK Builder #Cellik #Credential Theft #Google Play Store #iVerify #Malware_as_a_Service #mobile security #Remote Access Trojan #spyware #vnc
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:50:24 +0000
════════════════════════
⌗ Tags: #Malware #Android RAT #APK Builder #Cellik #Credential Theft #Google Play Store #iVerify #Malware_as_a_Service #mobile security #Remote Access Trojan #spyware #vnc
Daily CyberSecurity
The Silent Hijacker: New Cellik Android RAT Turns Legitimate Google Play Apps into Surveillance Tools
iVerify exposes Cellik, a $150/mo Android RAT that wraps malicious code inside Play Store apps to grant attackers total device control.
⤷ Title: Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:43:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67896 #Exim #Heap Buffer Overflow #Mail Transfer Agent #memory corruption #NIST #Ratelimit ACL #SMTP Security #sql injection #SQLite
Daily CyberSecurity
Exim’s Poisoned Record: How a Failed Patch and SQL Injection Lead to Critical Heap Overflows
NIST warns of a critical Exim 4.99 flaw. A failed SQLi patch allows attackers to poison SQLite records and trigger a 1.5MB heap buffer overflow.
⤷ Title: “ClickFix” Trap: Fake Human Verification Leads to Qilin Ransomware Infection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:40:50 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Fortinet #Human Verification #info_stealer #NetSupport RAT #Qilin Ransomware #social engineering #Sophos CTU #StealC V2 #VPN Breach
Daily CyberSecurity
"ClickFix" Trap: Fake Human Verification Leads to Qilin Ransomware Infection
Sophos CTU reveals how the ClickFix tactic led to a Qilin ransomware attack via NetSupport RAT and StealC V2 using stolen VPN credentials.
⤷ Title: TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #AuraStealer #Cyber Security #Data Theft #Gen Digital #Infostealer #powershell #Scam_Yourself #social engineering #TikTok Malware #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:37:11 +0000
════════════════════════
⌗ Tags: #Malware #AuraStealer #Cyber Security #Data Theft #Gen Digital #Infostealer #powershell #Scam_Yourself #social engineering #TikTok Malware #Windows malware
Daily CyberSecurity
TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
Gen Digital uncovers AuraStealer, a new infostealer using TikTok "Scam-Yourself" tactics to trick users into infecting their own Windows PCs.
⤷ Title: The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:33:47 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Service #Android security #Belarus #Journalists #KGB #Physical Access #Reporters Without Borders #ResidentBat #spyware #surveillance
Daily CyberSecurity
The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
RSF uncovers ResidentBat, a Belarusian KGB spyware physically installed during interrogations to hijack encrypted messages and monitor journalists.
⤷ Title: Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Acronis #BlueNoroff #cyber_espionage #DPRK #Hunt.io #Infrastructure Mapping #Kimsuky #Lazarus Group #North Korea #threat intelligence
Daily CyberSecurity
Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
A joint Hunt.io and Acronis report exposes the shared infrastructure behind Lazarus and Kimsuky, revealing the unified web of North Korean hacking.
⤷ Title: Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:22:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache NiFi #Asana Integration #CVE_2025_66524 #cybersecurity #Data Flow #Deserialization #GetAsanaObject #Java security #JSON Serialization #Patch Update
Daily CyberSecurity
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
Apache NiFi patches a High-severity flaw (CVE-2025-66524) in the GetAsanaObject processor. Unfiltered deserialization risks system compromise. Update now!
⤷ Title: North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:18:02 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #DocSwap #DPRK #ENKI Research #Kimsuky #mobile security #North Korea #QR Code Scam #rat #smishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:18:02 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #DocSwap #DPRK #ENKI Research #Kimsuky #mobile security #North Korea #QR Code Scam #rat #smishing
Daily CyberSecurity
North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
Kimsuky is deploying a new DOCSWAP RAT via QR codes and smishing. The DPRK-linked malware turns phones into surveillance tools for data theft.
⤷ Title: “Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #APT_C_36 #BlindEagle #Caminho #Colombia #DCRat #Government Cyberattack #malware #phishing #steganography #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #APT_C_36 #BlindEagle #Caminho #Colombia #DCRat #Government Cyberattack #malware #phishing #steganography #Zscaler ThreatLabz
Daily CyberSecurity
"Caminho" to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
⤷ Title: The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
Daily CyberSecurity
The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
BlueDelta (APT28) is targeting UKR.NET users with a sophisticated phishing campaign using ngrok and Mocky to bypass security and steal 2FA codes.
⤷ Title: AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
Daily CyberSecurity
AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
A High-severity flaw (CVE-2025-63387) in Dify v1.9.1 allows unauthenticated users to access sensitive system configurations via an unprotected API.
⤷ Title: Attackers Don’t Follow the Kill Chain. You Shouldn’t Either.
════════════════════════
𐀪 Author: Val Vask
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:59:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #cyber_kill_chain #red_team
════════════════════════
𐀪 Author: Val Vask
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:59:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #cyber_kill_chain #red_team
Medium
Attackers Don’t Follow the Kill Chain. You Shouldn’t Either.
Defenders have organized attack strategy around the linear kill chain for years: a clean, predictable progression from reconnaissance to…
⤷ Title: Advent of Cyber 2025 Day 7 — Network Discovery “San-ta Clause”
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:08:47 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #hacking_with_netcat #tryhackme #network_discovery_tool #netcat
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:08:47 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #hacking_with_netcat #tryhackme #network_discovery_tool #netcat
Medium
Advent of Cyber 2025 Day 7 — Network Discovery “San-ta Clause”
As of right now, preparations for Christmas are delayed! HopSec has breached the QA environment and locked out the elves. They need back…
⤷ Title: TryHackMe | Tempest | Challenge Walkthrough
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #blue_team
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #blue_team
Medium
TryHackMe | Tempest | Challenge Walkthrough
An Endpoint Forensic Investigation Challenge Using SysmonView, EvtxECmd, Brim, & CyberChef.
⤷ Title: Unlock the Secrets of Ethical Hacking: How to Safeguard Your Future in Cybersecurity
════════════════════════
𐀪 Author: Negro Med
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:20 GMT
════════════════════════
⌗ Tags: #data_science #ethical_hacking #cybersecurity #programming #python
════════════════════════
𐀪 Author: Negro Med
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:20 GMT
════════════════════════
⌗ Tags: #data_science #ethical_hacking #cybersecurity #programming #python
Medium
Unlock the Secrets of Ethical Hacking: How to Safeguard Your Future in Cybersecurity
The Future of Cybersecurity Begins with You
⤷ Title: The Octopus Trap: Iranian Hackers Breach Naftali Bennett’s Telegram in Bold Cyber Strike
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:30:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Benjamin Netanyahu #Cyber Espionage #data leak #Election 2026 #Handala #Iran #Israeli Politics #Naftali Bennett #Operation Octopus #Shin Bet #Telegram Hack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:30:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Benjamin Netanyahu #Cyber Espionage #data leak #Election 2026 #Handala #Iran #Israeli Politics #Naftali Bennett #Operation Octopus #Shin Bet #Telegram Hack
Penetration Testing Tools
The Octopus Trap: Iranian Hackers Breach Naftali Bennett’s Telegram in Bold Cyber Strike
Former Israeli Prime Minister Naftali Bennett has acknowledged that his Telegram account was accessed without authorization, even though
⤷ Title: 21,000 SIMs Discovered: CBI Dismantles Massive “Phishing Factory” in Operation Chakra-V
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:29:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CBI #Cyber Security India #Digital Arrest #Financial Scams #KYC Violation #Lord Mahavira Services #NCR #Operation Chakra_V #phishing #SIM Box #SMS Fraud
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:29:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CBI #Cyber Security India #Digital Arrest #Financial Scams #KYC Violation #Lord Mahavira Services #NCR #Operation Chakra_V #phishing #SIM Box #SMS Fraud
Penetration Testing Tools
21,000 SIMs Discovered: CBI Dismantles Massive "Phishing Factory" in Operation Chakra-V
India’s Central Bureau of Investigation (CBI) has announced the arrest of three individuals suspected of orchestrating a large-scale
⤷ Title: Operation Magic Cat: Google Sues to Dismantle the Chinese “Darcula” Phishing Empire
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:28:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Google #Credit Card Fraud #Cyber Lawsuit #Darcula #google #Google Messages #Magic Cat #Phishing Toolkit #Phishing_as_a_Service #Smishing #Yucheng Chang
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:28:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Google #Credit Card Fraud #Cyber Lawsuit #Darcula #google #Google Messages #Magic Cat #Phishing Toolkit #Phishing_as_a_Service #Smishing #Yucheng Chang
Penetration Testing Tools
Operation Magic Cat: Google Sues to Dismantle the Chinese "Darcula" Phishing Empire
Google has filed a lawsuit against a Chinese-speaking group it describes as a central driver behind a massive
⤷ Title: Hacking “Analytical Amnesia”: How the ATHF Framework Gives AI a Memory for Threat Hunting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:26:08 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #ATHF #Cybersecurity 2026 #Infosec Memory #LOCK Template #MITRE ATT&CK #open source #python #Threat Hunting #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:26:08 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #ATHF #Cybersecurity 2026 #Infosec Memory #LOCK Template #MITRE ATT&CK #open source #python #Threat Hunting #threat intelligence
Penetration Testing Tools
Hacking "Analytical Amnesia": How the ATHF Framework Gives AI a Memory for Threat Hunting
Stop losing context: The Agentic Threat Hunting Framework (ATHF) uses the LOCK template to build a permanent memory layer for AI-driven security teams.
⤷ Title: The Intimacy Breach: TikTok Sued for Unlawfully Tracking Users on Grindr
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:21:32 +0000
════════════════════════
⌗ Tags: #Data Leak #AppsFlyer #Article 9 #Austrian DPA #Data Access Request #data privacy #GDPR #Grindr #Max Schrems #noyb #Off_App Tracking #Sensitive Data #TikTok
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:21:32 +0000
════════════════════════
⌗ Tags: #Data Leak #AppsFlyer #Article 9 #Austrian DPA #Data Access Request #data privacy #GDPR #Grindr #Max Schrems #noyb #Off_App Tracking #Sensitive Data #TikTok
Penetration Testing Tools
The Intimacy Breach: TikTok Sued for Unlawfully Tracking Users on Grindr
The popular video platform TikTok has found itself at the center of a new scandal involving alleged violations