⤷ Title: University CTF 2025: Tinsel Trouble experience (and writeups)
════════════════════════
𐀪 Author: Maksim Hayder
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 23:23:45 GMT
════════════════════════
⌗ Tags: #ctf_writeup #hackthebox #ctf #hackthebox_writeup #htb_writeup
════════════════════════
𐀪 Author: Maksim Hayder
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 23:23:45 GMT
════════════════════════
⌗ Tags: #ctf_writeup #hackthebox #ctf #hackthebox_writeup #htb_writeup
Medium
University CTF 2025: Tinsel Trouble experience (and writeups)
The University CTF 2025: Tinsel Trouble, mainly for University students/teams event lasted from December 19th-21st 2025.
⤷ Title: Hack The Box University CTF 2025: Tinsel Trouble - Coding Challenges
════════════════════════
𐀪 Author: Juan Pablo Morales
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 20:19:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #coding #hackthebox_writeup #hackthebox #ctf_writeup
════════════════════════
𐀪 Author: Juan Pablo Morales
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 20:19:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #coding #hackthebox_writeup #hackthebox #ctf_writeup
Medium
Hack The Box University CTF 2025: Tinsel Trouble
Hello everyone! 👋
⤷ Title: Building Your First Hacking Lab: A Step-by-Step Guide to VirtualBox and Kali Linux
════════════════════════
𐀪 Author: Tonia Taiwo
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 22:45:01 GMT
════════════════════════
⌗ Tags: #free_cyber_security #cybersecurity #ethical_hacking #cybersecurity_awareness #cybersecurity_training
════════════════════════
𐀪 Author: Tonia Taiwo
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 22:45:01 GMT
════════════════════════
⌗ Tags: #free_cyber_security #cybersecurity #ethical_hacking #cybersecurity_awareness #cybersecurity_training
Medium
Building Your First Hacking Lab: A Step-by-Step Guide to VirtualBox and Kali Linux
Your journey into cybersecurity starts with a safe place to break things.
⤷ Title: Anna’s Archive Claims 300TB Spotify Mirror, Forcing an Investigation Into a Massive Music Data Leak
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:53:52 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Training Data #Anna’s Archive #copyright #data leak #DRM Bypass #Music Piracy #Spotify #Streaming Platforms
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:53:52 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Training Data #Anna’s Archive #copyright #data leak #DRM Bypass #Music Piracy #Spotify #Streaming Platforms
Daily CyberSecurity
Anna’s Archive Claims 300TB Spotify Mirror, Forcing an Investigation Into a Massive Music Data Leak
The shadow library Anna’s Archive has claimed that it has carried out a large-scale “mirror” of Spotify’s music catalog and intends to distribute it via torrents totaling roughly 300 terabytes. Sp…
⤷ Title: Critical Unauthenticated MongoDB Flaw Leaks Sensitive Data via zlib Compression
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:50:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14847 #database security #Heap Leak #Information Disclosure #Memory Leak #mongodb #NoSQL Security #Patch Alert #unauthenticated exploit #zlib
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:50:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_14847 #database security #Heap Leak #Information Disclosure #Memory Leak #mongodb #NoSQL Security #Patch Alert #unauthenticated exploit #zlib
Daily CyberSecurity
Critical Unauthenticated MongoDB Flaw Leaks Sensitive Data via zlib Compression
A critical vulnerability was disclosed in MongoDB, one of the world’s most popular NoSQL database platforms. The security flaw, tracked as CVE-2025-14847, allows attackers to siphon sensitiv…
⤷ Title: The 3-Million Email Siege: Inside Scripted Sparrow’s Global Industrialized BEC Machine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:46:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Automated Cyberattacks #BEC #business email compromise #Email Security #Executive Impersonation #Finance Fraud #Fortra FIRE #phishing #Scripted Sparrow #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:46:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Automated Cyberattacks #BEC #business email compromise #Email Security #Executive Impersonation #Finance Fraud #Fortra FIRE #phishing #Scripted Sparrow #social engineering
Daily CyberSecurity
The 3-Million Email Siege: Inside Scripted Sparrow’s Global Industrialized BEC Machine
A massive, globally distributed cybercriminal collective is aggressively targeting corporate finance departments with a highly automated Business Email Compromise (BEC) campaign. A new report by F…
⤷ Title: A Desperate Cartel: Inside the Unlikely Alliance of Qilin, DragonForce, and a Fading LockBit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #Cybercrime Cartel #data extortion #DragonForce #LockBit #Operation Cronos #Qilin #RaaS #ransomware #Yarix Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cyber_espionage #Cybercrime Cartel #data extortion #DragonForce #LockBit #Operation Cronos #Qilin #RaaS #ransomware #Yarix Intelligence
Daily CyberSecurity
A Desperate Cartel: Inside the Unlikely Alliance of Qilin, DragonForce, and a Fading LockBit
In a digital underworld increasingly fractured by law enforcement takedowns and eroding trust, three of the most notorious ransomware groups have allegedly joined forces. A new report by the Yarix…
⤷ Title: Iranian “Prince of Persia” APT Resurfaces with Telegram-Controlled Stealth Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:38:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #cyber_espionage #DGA #Foudre v34 #Infy #Iranian APT #Malware_as_a_Service #Prince of Persia #SafeBreach #Telegram C2 #Tonnerre v50
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:38:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #cyber_espionage #DGA #Foudre v34 #Infy #Iranian APT #Malware_as_a_Service #Prince of Persia #SafeBreach #Telegram C2 #Tonnerre v50
Daily CyberSecurity
Iranian “Prince of Persia” APT Resurfaces with Telegram-Controlled Stealth Malware
After years of radio silence that led many to believe they had disbanded, one of Iran’s most persistent state-sponsored threat groups has resurfaced with a revamped arsenal. A new investigat…
⤷ Title: “Purchase Order” Deception: Sophisticated Loader Targets Manufacturing Giants in Italy, Finland, and Saudi Arabia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:32:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyble #Government Cyberattacks #Malware_as_a_Service #Manufacturing Security #PureLog Stealer #Remcos RAT #steganography #TaskScheduler #UAC bypass #Unified Commodity Loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:32:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyble #Government Cyberattacks #Malware_as_a_Service #Manufacturing Security #PureLog Stealer #Remcos RAT #steganography #TaskScheduler #UAC bypass #Unified Commodity Loader
Daily CyberSecurity
“Purchase Order” Deception: Sophisticated Loader Targets Manufacturing Giants in Italy, Finland, and Saudi Arabia
A highly sophisticated cyber-espionage campaign is indiscriminately targeting the manufacturing and government sectors across Europe and the Middle East, using a “Swiss Army Knife” sty…
⤷ Title: Identity Theft in M-Files: High-Severity Flaw Lets Insiders Hijack User Accounts and Access Sensitive Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:26:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13008 #CVE_2025_14267 #cybersecurity #Document Management #identity theft #Information Disclosure #M_Files #M_Files Server #Patch Update #Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:26:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13008 #CVE_2025_14267 #cybersecurity #Document Management #identity theft #Information Disclosure #M_Files #M_Files Server #Patch Update #Session Hijacking
Daily CyberSecurity
Identity Theft in M-Files: High-Severity Flaw Lets Insiders Hijack User Accounts and Access Sensitive Data
M-Files, the intelligent information management platform used by enterprises to organize their documents, has issued a security advisory addressing two distinct vulnerabilities. The most critical …
⤷ Title: “React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
Daily CyberSecurity
“React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
A new, sophisticated malware campaign is sweeping across the internet, leveraging a recently disclosed vulnerability to install cryptocurrency-stealing software on unsuspecting servers. The AhnLab…
⤷ Title: AI-Generated Decoys & XLL Stealth: Inside the New “EchoGather” Cyber Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:18:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #backdoor #CVE_2025_8088 #cyber_espionage #EchoGather #GOFFEE #Intezer #Paper Werewolf #russia #WinRAR #XLL Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:18:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #backdoor #CVE_2025_8088 #cyber_espionage #EchoGather #GOFFEE #Intezer #Paper Werewolf #russia #WinRAR #XLL Malware
Daily CyberSecurity
AI-Generated Decoys & XLL Stealth: Inside the New “EchoGather” Cyber Espionage Campaign
A cyber-espionage group known for hunting Russian organizations has upgraded its arsenal, deploying malicious Excel add-ins to slip past defenses and install a new backdoor. A new report from Inte…
⤷ Title: Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Banking Trojan #Cybercrime #Dropper Malware #Group_IB #mobile security #SMS Stealer #Telegram bot #Uzbekistan #Wonderland Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Banking Trojan #Cybercrime #Dropper Malware #Group_IB #mobile security #SMS Stealer #Telegram bot #Uzbekistan #Wonderland Malware
Daily CyberSecurity
Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
A sophisticated wave of mobile malware is sweeping through Central Asia, marking a dangerous evolution in how cybercriminals target Android users. A new in-depth analysis by Group-IB reveals that …
⤷ Title: Zero-Day Alert: Linksys Auth Bypass Lets Hackers Hijack Routers Without Passwords
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CSIT #CVE_2025_52692 #IoT security #Linksys E9450_SG #Network Safety #router security #Singtel #Telnet #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CSIT #CVE_2025_52692 #IoT security #Linksys E9450_SG #Network Safety #router security #Singtel #Telnet #zero_day
Daily CyberSecurity
Zero-Day Alert: Linksys Auth Bypass Lets Hackers Hijack Routers Without Passwords
A popular Wi-Fi 6 router found in thousands of homes has been blown wide open by security researchers, revealing a critical flaw that allows attackers to bypass login screens and seize full contro…
⤷ Title: The Payroll Trap: New Quishing Campaign Uses Fake CAPTCHAs to Hijack Employee Paychecks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:01:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CAPTCHA Bypass #Credential Theft #Cyfirma #Employee Awareness #mobile security #Payroll Fraud #phishing #QR code phishing #Quishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:01:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CAPTCHA Bypass #Credential Theft #Cyfirma #Employee Awareness #mobile security #Payroll Fraud #phishing #QR code phishing #Quishing #social engineering
Daily CyberSecurity
The Payroll Trap: New Quishing Campaign Uses Fake CAPTCHAs to Hijack Employee Paychecks
A sophisticated new phishing campaign is targeting employees where they are most vulnerable—their paychecks—by leveraging QR codes to bypass corporate security defenses. A new analysis by CYFIRMA …
⤷ Title: Breaking OAuth 2.0: Vulnerabilities & Exploitation Guide
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:45:36 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #penetration_testing #web_security
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:45:36 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #penetration_testing #web_security
Medium
Breaking OAuth 2.0: Vulnerabilities & Exploitation Guide
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…
⤷ Title: Time-Based SQL Injection: Complete Real-World Bug Bounty Guide
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #sql #penetration_testing #technology #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #sql #penetration_testing #technology #bug_bounty #cybersecurity
Medium
Time-Based SQL Injection: Complete Real-World Bug Bounty Guide
How Silent Delays, Burp Repeater, and Patient Testing Turn “Nothing Happening” into a Real Vulnerability
⤷ Title: The Hidden Dangers of Free Wi-Fi – How Hackers Can Steal Your Data Without You Knowing
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:52:29 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #technology #data_science
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:52:29 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #technology #data_science
Medium
The Hidden Dangers of Free Wi-Fi – How Hackers Can Steal Your Data Without You Knowing
Photo by Dreamlike Street on Unsplash
⤷ Title: Why Hackers Break the Law – And How Their Skills Can Actually Do Good.
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:41:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_science #technology #hacking
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:41:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_science #technology #hacking
Medium
Why Hackers Break the Law – And How Their Skills Can Actually Do Good.
pixabay.com
⤷ Title: Cyber crime news — ransomware and advanced persistent threat groups
════════════════════════
𐀪 Author: Michael Harms
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability #news #hacking #cybercrime
════════════════════════
𐀪 Author: Michael Harms
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability #news #hacking #cybercrime
Medium
Cyber crime news — ransomware and advanced persistent threat groups
Here I want to share some curated cyber crime news, I wasn’t aware that ransomware is still widely in use. Interesting how many crime…
⤷ Title: An ESP32 Script That Monitors My Home Network for Weird Devices
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:25:08 GMT
════════════════════════
⌗ Tags: #nmap #wifihacking #esp32 #hacking #script
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:25:08 GMT
════════════════════════
⌗ Tags: #nmap #wifihacking #esp32 #hacking #script
Medium
An ESP32 Script That Monitors My Home Network for Weird Devices
I’ve always had this paranoid streak. Not the kind where you’re jumping at shadows or tinfoil hats, but the type where a blinking IP on…