⤷ Title: “Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #APT_C_36 #BlindEagle #Caminho #Colombia #DCRat #Government Cyberattack #malware #phishing #steganography #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #APT_C_36 #BlindEagle #Caminho #Colombia #DCRat #Government Cyberattack #malware #phishing #steganography #Zscaler ThreatLabz
Daily CyberSecurity
"Caminho" to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
⤷ Title: The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
Daily CyberSecurity
The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
BlueDelta (APT28) is targeting UKR.NET users with a sophisticated phishing campaign using ngrok and Mocky to bypass security and steal 2FA codes.
⤷ Title: AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
Daily CyberSecurity
AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
A High-severity flaw (CVE-2025-63387) in Dify v1.9.1 allows unauthenticated users to access sensitive system configurations via an unprotected API.
⤷ Title: Attackers Don’t Follow the Kill Chain. You Shouldn’t Either.
════════════════════════
𐀪 Author: Val Vask
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:59:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #cyber_kill_chain #red_team
════════════════════════
𐀪 Author: Val Vask
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:59:02 GMT
════════════════════════
⌗ Tags: #penetration_testing #cyber_kill_chain #red_team
Medium
Attackers Don’t Follow the Kill Chain. You Shouldn’t Either.
Defenders have organized attack strategy around the linear kill chain for years: a clean, predictable progression from reconnaissance to…
⤷ Title: Advent of Cyber 2025 Day 7 — Network Discovery “San-ta Clause”
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:08:47 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #hacking_with_netcat #tryhackme #network_discovery_tool #netcat
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:08:47 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #hacking_with_netcat #tryhackme #network_discovery_tool #netcat
Medium
Advent of Cyber 2025 Day 7 — Network Discovery “San-ta Clause”
As of right now, preparations for Christmas are delayed! HopSec has breached the QA environment and locked out the elves. They need back…
⤷ Title: TryHackMe | Tempest | Challenge Walkthrough
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #blue_team
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup #tryhackme_walkthrough #tryhackme #blue_team
Medium
TryHackMe | Tempest | Challenge Walkthrough
An Endpoint Forensic Investigation Challenge Using SysmonView, EvtxECmd, Brim, & CyberChef.
⤷ Title: Unlock the Secrets of Ethical Hacking: How to Safeguard Your Future in Cybersecurity
════════════════════════
𐀪 Author: Negro Med
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:20 GMT
════════════════════════
⌗ Tags: #data_science #ethical_hacking #cybersecurity #programming #python
════════════════════════
𐀪 Author: Negro Med
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:02:20 GMT
════════════════════════
⌗ Tags: #data_science #ethical_hacking #cybersecurity #programming #python
Medium
Unlock the Secrets of Ethical Hacking: How to Safeguard Your Future in Cybersecurity
The Future of Cybersecurity Begins with You
⤷ Title: The Octopus Trap: Iranian Hackers Breach Naftali Bennett’s Telegram in Bold Cyber Strike
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:30:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Benjamin Netanyahu #Cyber Espionage #data leak #Election 2026 #Handala #Iran #Israeli Politics #Naftali Bennett #Operation Octopus #Shin Bet #Telegram Hack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:30:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Benjamin Netanyahu #Cyber Espionage #data leak #Election 2026 #Handala #Iran #Israeli Politics #Naftali Bennett #Operation Octopus #Shin Bet #Telegram Hack
Penetration Testing Tools
The Octopus Trap: Iranian Hackers Breach Naftali Bennett’s Telegram in Bold Cyber Strike
Former Israeli Prime Minister Naftali Bennett has acknowledged that his Telegram account was accessed without authorization, even though
⤷ Title: 21,000 SIMs Discovered: CBI Dismantles Massive “Phishing Factory” in Operation Chakra-V
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:29:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CBI #Cyber Security India #Digital Arrest #Financial Scams #KYC Violation #Lord Mahavira Services #NCR #Operation Chakra_V #phishing #SIM Box #SMS Fraud
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:29:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CBI #Cyber Security India #Digital Arrest #Financial Scams #KYC Violation #Lord Mahavira Services #NCR #Operation Chakra_V #phishing #SIM Box #SMS Fraud
Penetration Testing Tools
21,000 SIMs Discovered: CBI Dismantles Massive "Phishing Factory" in Operation Chakra-V
India’s Central Bureau of Investigation (CBI) has announced the arrest of three individuals suspected of orchestrating a large-scale
⤷ Title: Operation Magic Cat: Google Sues to Dismantle the Chinese “Darcula” Phishing Empire
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:28:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Google #Credit Card Fraud #Cyber Lawsuit #Darcula #google #Google Messages #Magic Cat #Phishing Toolkit #Phishing_as_a_Service #Smishing #Yucheng Chang
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:28:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Google #Credit Card Fraud #Cyber Lawsuit #Darcula #google #Google Messages #Magic Cat #Phishing Toolkit #Phishing_as_a_Service #Smishing #Yucheng Chang
Penetration Testing Tools
Operation Magic Cat: Google Sues to Dismantle the Chinese "Darcula" Phishing Empire
Google has filed a lawsuit against a Chinese-speaking group it describes as a central driver behind a massive
⤷ Title: Hacking “Analytical Amnesia”: How the ATHF Framework Gives AI a Memory for Threat Hunting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:26:08 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #ATHF #Cybersecurity 2026 #Infosec Memory #LOCK Template #MITRE ATT&CK #open source #python #Threat Hunting #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:26:08 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AI Agents #ATHF #Cybersecurity 2026 #Infosec Memory #LOCK Template #MITRE ATT&CK #open source #python #Threat Hunting #threat intelligence
Penetration Testing Tools
Hacking "Analytical Amnesia": How the ATHF Framework Gives AI a Memory for Threat Hunting
Stop losing context: The Agentic Threat Hunting Framework (ATHF) uses the LOCK template to build a permanent memory layer for AI-driven security teams.
⤷ Title: The Intimacy Breach: TikTok Sued for Unlawfully Tracking Users on Grindr
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:21:32 +0000
════════════════════════
⌗ Tags: #Data Leak #AppsFlyer #Article 9 #Austrian DPA #Data Access Request #data privacy #GDPR #Grindr #Max Schrems #noyb #Off_App Tracking #Sensitive Data #TikTok
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:21:32 +0000
════════════════════════
⌗ Tags: #Data Leak #AppsFlyer #Article 9 #Austrian DPA #Data Access Request #data privacy #GDPR #Grindr #Max Schrems #noyb #Off_App Tracking #Sensitive Data #TikTok
Penetration Testing Tools
The Intimacy Breach: TikTok Sued for Unlawfully Tracking Users on Grindr
The popular video platform TikTok has found itself at the center of a new scandal involving alleged violations
⤷ Title: The $2 Billion Heist: North Korea Smashes Crypto Theft Records in 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:20:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2025 Crypto Report #Bybit Hack #Chainalysis #cryptocurrency #Cyber Espionage #DeFi #Ethereum #Lazarus Group #Money Laundering #North Korea #Tron
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:20:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2025 Crypto Report #Bybit Hack #Chainalysis #cryptocurrency #Cyber Espionage #DeFi #Ethereum #Lazarus Group #Money Laundering #North Korea #Tron
Penetration Testing Tools
The $2 Billion Heist: North Korea Smashes Crypto Theft Records in 2025
In 2025, hackers linked to North Korea stole a record-breaking two billion dollars in cryptocurrency—51% more than the
⤷ Title: The Pitch-Black Bot: DIG AI Emerges as the Dark Web’s Uncensored Malware Engine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:18:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime 2025 #Dark Web #DIG AI #Fraud GPT Alternative #Malicious AI #Malware Development #Pitch #Resecurity #Synthetic Content #Tor Network
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:18:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime 2025 #Dark Web #DIG AI #Fraud GPT Alternative #Malicious AI #Malware Development #Pitch #Resecurity #Synthetic Content #Tor Network
Penetration Testing Tools
The Pitch-Black Bot: DIG AI Emerges as the Dark Web’s Uncensored Malware Engine
A new tool has surfaced on the dark web, quickly drawing the attention of security professionals—and not for
⤷ Title: Perimeter Breach: Critical Zero-Day CVE-2025-14733 Exploited to Hijack WatchGuard Firewalls
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:17:10 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA KEV #CVE_2025_14733 #Firebox #Fireware OS #iked #IKEv2 VPN #network security #Patch Management #RCE #WatchGuard #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:17:10 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA KEV #CVE_2025_14733 #Firebox #Fireware OS #iked #IKEv2 VPN #network security #Patch Management #RCE #WatchGuard #zero_day
Penetration Testing Tools
Perimeter Breach: Critical Zero-Day CVE-2025-14733 Exploited to Hijack WatchGuard Firewalls
WatchGuard has warned customers of a critical vulnerability in its Firebox firewalls that is already being actively exploited
⤷ Title: Critical UEFI Flaw Bypasses All Early-Boot Protections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #BIOS Update #CVE_2025_11901 #CVE_2025_14302 #DMA Attack #Hardware Root of Trust #IOMMU #Motherboard Security #Riot Games #UEFI #Vanguard
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 03:15:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #BIOS Update #CVE_2025_11901 #CVE_2025_14302 #DMA Attack #Hardware Root of Trust #IOMMU #Motherboard Security #Riot Games #UEFI #Vanguard
Penetration Testing Tools
Critical UEFI Flaw Bypasses All Early-Boot Protections
Researchers have uncovered a vulnerability in the UEFI firmware implementations used on motherboards from several major manufacturers, including
⤷ Title: The Single-Step Sniper: Bypassing EDR Hooks with TrapFlagForSyscalling
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:34:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EDR Bypass #EFLAGS #Malware Development #NtAllocateVirtualMemory #red teaming #Single_Step Exception #Syscall Tampering #Trap Flag #User_land Hooking #VEH
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:34:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EDR Bypass #EFLAGS #Malware Development #NtAllocateVirtualMemory #red teaming #Single_Step Exception #Syscall Tampering #Trap Flag #User_land Hooking #VEH
Penetration Testing Tools
The Single-Step Sniper: Bypassing EDR Hooks with TrapFlagForSyscalling
Master TrapFlagForSyscalling: Use the CPU’s Trap Flag and VEH to hijack whitelisted syscalls and bypass EDR user-land hooks with stealth.
⤷ Title: The Extortion Deficit: Ransomware Payments Plunge by 33% as Victims Refuse to Pay
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:06:41 +0000
════════════════════════
⌗ Tags: #Malware #AML Act 2020 #BlackCat #Cybersecurity 2024 #Financial Crime #FinCEN #Healthcare Data #LockBit #Manufacturing Security #ransomware #U.S. Treasury
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:06:41 +0000
════════════════════════
⌗ Tags: #Malware #AML Act 2020 #BlackCat #Cybersecurity 2024 #Financial Crime #FinCEN #Healthcare Data #LockBit #Manufacturing Security #ransomware #U.S. Treasury
Penetration Testing Tools
The Extortion Deficit: Ransomware Payments Plunge by 33% as Victims Refuse to Pay
The U.S. Treasury is cautiously suggesting that the ransomware market may be beginning to cool. In a new
⤷ Title: Shared Shadows: Hunt.io Uncovers the Unified Staging Grounds of Lazarus and Kimsuky
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:05:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Badcall #BLINDINGCAN #Cyber Espionage #DPRK #Fast Reverse Proxy (FRP) #HttpTroy #Hunt.io #Kimsuky #Lazarus Group #Malware Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:05:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis TRU #Badcall #BLINDINGCAN #Cyber Espionage #DPRK #Fast Reverse Proxy (FRP) #HttpTroy #Hunt.io #Kimsuky #Lazarus Group #Malware Infrastructure
Penetration Testing Tools
Shared Shadows: Hunt.io Uncovers the Unified Staging Grounds of Lazarus and Kimsuky
Groups operating in the interests of the DPRK continue to aggressively expand their infrastructure for cyber espionage, financial
⤷ Title: The Accounting of Intrusion: How the “Episode 4” Leak Exposed APT35’s Bureaucratic Machine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:05:12 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT35 #Charming Kitten #Cryptomus #Cyber Espionage #cyber warfare #DomainTools #Infrastructure Management #Iran #IRGC #Moses Staff #Nariman Gharib
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:05:12 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT35 #Charming Kitten #Cryptomus #Cyber Espionage #cyber warfare #DomainTools #Infrastructure Management #Iran #IRGC #Moses Staff #Nariman Gharib
Penetration Testing Tools
The Accounting of Intrusion: How the "Episode 4" Leak Exposed APT35’s Bureaucratic Machine
The leak of a fourth episode linked to the APT35 hacking group—also known as Charming Kitten—dramatically reshapes perceptions
⤷ Title: Onions & Audit Trails: How the Tor Project is Decoupling from Government Funding
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:02:00 +0000
════════════════════════
⌗ Tags: #Technology #Arti #Censorship Circumvention #Financial Audit #open source #privacy #Rust #Tails #Tor Project #Transparency Report #U.S. State Department
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 02:02:00 +0000
════════════════════════
⌗ Tags: #Technology #Arti #Censorship Circumvention #Financial Audit #open source #privacy #Rust #Tails #Tor Project #Transparency Report #U.S. State Department
Penetration Testing Tools
Onions & Audit Trails: How the Tor Project is Decoupling from Government Funding
The Tor Project has published its Form 990 tax filings and an independent audit of its financial statements