⤷ Title: “React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:21:31 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain C2 #Cryptocurrency Theft #CVE_2025_55182 #cyber_espionage #Ethereum #EtherRAT #Node.js #React2Shell #Remote Code Execution
Daily CyberSecurity
“React2Shell” Exploited: New EtherRAT Malware Hunts for Crypto via Node.js
A new, sophisticated malware campaign is sweeping across the internet, leveraging a recently disclosed vulnerability to install cryptocurrency-stealing software on unsuspecting servers. The AhnLab…
⤷ Title: AI-Generated Decoys & XLL Stealth: Inside the New “EchoGather” Cyber Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:18:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #backdoor #CVE_2025_8088 #cyber_espionage #EchoGather #GOFFEE #Intezer #Paper Werewolf #russia #WinRAR #XLL Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:18:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #backdoor #CVE_2025_8088 #cyber_espionage #EchoGather #GOFFEE #Intezer #Paper Werewolf #russia #WinRAR #XLL Malware
Daily CyberSecurity
AI-Generated Decoys & XLL Stealth: Inside the New “EchoGather” Cyber Espionage Campaign
A cyber-espionage group known for hunting Russian organizations has upgraded its arsenal, deploying malicious Excel add-ins to slip past defenses and install a new backdoor. A new report from Inte…
⤷ Title: Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Banking Trojan #Cybercrime #Dropper Malware #Group_IB #mobile security #SMS Stealer #Telegram bot #Uzbekistan #Wonderland Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Banking Trojan #Cybercrime #Dropper Malware #Group_IB #mobile security #SMS Stealer #Telegram bot #Uzbekistan #Wonderland Malware
Daily CyberSecurity
Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
A sophisticated wave of mobile malware is sweeping through Central Asia, marking a dangerous evolution in how cybercriminals target Android users. A new in-depth analysis by Group-IB reveals that …
⤷ Title: Zero-Day Alert: Linksys Auth Bypass Lets Hackers Hijack Routers Without Passwords
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CSIT #CVE_2025_52692 #IoT security #Linksys E9450_SG #Network Safety #router security #Singtel #Telnet #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CSIT #CVE_2025_52692 #IoT security #Linksys E9450_SG #Network Safety #router security #Singtel #Telnet #zero_day
Daily CyberSecurity
Zero-Day Alert: Linksys Auth Bypass Lets Hackers Hijack Routers Without Passwords
A popular Wi-Fi 6 router found in thousands of homes has been blown wide open by security researchers, revealing a critical flaw that allows attackers to bypass login screens and seize full contro…
⤷ Title: The Payroll Trap: New Quishing Campaign Uses Fake CAPTCHAs to Hijack Employee Paychecks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:01:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CAPTCHA Bypass #Credential Theft #Cyfirma #Employee Awareness #mobile security #Payroll Fraud #phishing #QR code phishing #Quishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:01:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CAPTCHA Bypass #Credential Theft #Cyfirma #Employee Awareness #mobile security #Payroll Fraud #phishing #QR code phishing #Quishing #social engineering
Daily CyberSecurity
The Payroll Trap: New Quishing Campaign Uses Fake CAPTCHAs to Hijack Employee Paychecks
A sophisticated new phishing campaign is targeting employees where they are most vulnerable—their paychecks—by leveraging QR codes to bypass corporate security defenses. A new analysis by CYFIRMA …
⤷ Title: Breaking OAuth 2.0: Vulnerabilities & Exploitation Guide
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:45:36 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #penetration_testing #web_security
════════════════════════
𐀪 Author: Fuzzyy Duck
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:45:36 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #bug_bounty #penetration_testing #web_security
Medium
Breaking OAuth 2.0: Vulnerabilities & Exploitation Guide
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…
⤷ Title: Time-Based SQL Injection: Complete Real-World Bug Bounty Guide
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #sql #penetration_testing #technology #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:38:11 GMT
════════════════════════
⌗ Tags: #sql #penetration_testing #technology #bug_bounty #cybersecurity
Medium
Time-Based SQL Injection: Complete Real-World Bug Bounty Guide
How Silent Delays, Burp Repeater, and Patient Testing Turn “Nothing Happening” into a Real Vulnerability
⤷ Title: The Hidden Dangers of Free Wi-Fi – How Hackers Can Steal Your Data Without You Knowing
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:52:29 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #technology #data_science
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:52:29 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #technology #data_science
Medium
The Hidden Dangers of Free Wi-Fi – How Hackers Can Steal Your Data Without You Knowing
Photo by Dreamlike Street on Unsplash
⤷ Title: Why Hackers Break the Law – And How Their Skills Can Actually Do Good.
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:41:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_science #technology #hacking
════════════════════════
𐀪 Author: Salaheddinta
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:41:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_science #technology #hacking
Medium
Why Hackers Break the Law – And How Their Skills Can Actually Do Good.
pixabay.com
⤷ Title: Cyber crime news — ransomware and advanced persistent threat groups
════════════════════════
𐀪 Author: Michael Harms
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability #news #hacking #cybercrime
════════════════════════
𐀪 Author: Michael Harms
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:43:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerability #news #hacking #cybercrime
Medium
Cyber crime news — ransomware and advanced persistent threat groups
Here I want to share some curated cyber crime news, I wasn’t aware that ransomware is still widely in use. Interesting how many crime…
⤷ Title: An ESP32 Script That Monitors My Home Network for Weird Devices
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:25:08 GMT
════════════════════════
⌗ Tags: #nmap #wifihacking #esp32 #hacking #script
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:25:08 GMT
════════════════════════
⌗ Tags: #nmap #wifihacking #esp32 #hacking #script
Medium
An ESP32 Script That Monitors My Home Network for Weird Devices
I’ve always had this paranoid streak. Not the kind where you’re jumping at shadows or tinfoil hats, but the type where a blinking IP on…
⤷ Title: JS Islands: 10 Plays for Less JS, More Speed
════════════════════════
𐀪 Author: Vectorlane
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:32:21 GMT
════════════════════════
⌗ Tags: #javascript #architecture #web_performance #ssrf #frontend_development
════════════════════════
𐀪 Author: Vectorlane
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 01:32:21 GMT
════════════════════════
⌗ Tags: #javascript #architecture #web_performance #ssrf #frontend_development
Medium
JS Islands: 10 Plays for Less JS, More Speed
A practical islands architecture playbook to ship less JavaScript, cut hydration costs, and make pages feel instant — without killing…
⤷ Title: Founding: The Next-Gen Loader Generator for Advanced Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
Information Security News
Founding: The Next-Gen Loader Generator for Advanced Evasion
Founding is a tool that processes shellcode in .bin, .exe, or .dll formats, applying advanced obfuscation or encryption techniques to generate stealthy binaries with sophisticated execution method…
⤷ Title: The Typosquat Trap: Why 90% of Parked Domains Now Redirect to Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:17:29 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #David Bransdon #DNS Security #Gmai[.]com #Infoblox #Malvertising #Parked Domains #Residential IP #Scotaibank #Typosquatting #Zero_Click
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:17:29 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #David Bransdon #DNS Security #Gmai[.]com #Infoblox #Malvertising #Parked Domains #Residential IP #Scotaibank #Typosquatting #Zero_Click
Information Security News
The Typosquat Trap: Why 90% of Parked Domains Now Redirect to Malware
Direct navigation—when a user manually types a website address into the browser—has become markedly more dangerous. Researchers at Infoblox have found that the vast majority of “parked” domains ar…
⤷ Title: The $40M Jackpot: DOJ Charges 54 in Nationwide Ploutus ATM Malware Blitz
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:15:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM malware #Bank Fraud #Cybersecurity 2025 #Diebold Nixdorf #DOJ #FBI #Jackpotting #Jimena Araya #Kalignite #Ploutus #Tren de Aragua
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:15:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM malware #Bank Fraud #Cybersecurity 2025 #Diebold Nixdorf #DOJ #FBI #Jackpotting #Jimena Araya #Kalignite #Ploutus #Tren de Aragua
Information Security News
The $40M Jackpot: DOJ Charges 54 in Nationwide Ploutus ATM Malware Blitz
The U.S. Department of Justice has brought charges against dozens of individuals in connection with a wave of ATM thefts carried out using the Ploutus malware. The department announced that two fe…
⤷ Title: The Raccoon’s End: Nigerian Police Arrest Mastermind Behind RaccoonO365 PhaaS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:14:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BEC #Cybercrime 2025 #FBI #Joshua Ogundipe #Microsoft 365 #Okitipe Samuel #Phishing_as_a_Service #RaccoonO365 #Storm_2246 #Telegram Fraud #U.S. Secret Service
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:14:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BEC #Cybercrime 2025 #FBI #Joshua Ogundipe #Microsoft 365 #Okitipe Samuel #Phishing_as_a_Service #RaccoonO365 #Storm_2246 #Telegram Fraud #U.S. Secret Service
Information Security News
The Raccoon’s End: Nigerian Police Arrest Mastermind Behind RaccoonO365 PhaaS
Nigerian authorities have arrested an individual believed to be one of the developers behind RaccoonO365, a phishing-as-a-service platform that enabled criminals to mass-produce fake Microsoft log…
⤷ Title: Ensuring Space Superiority: Trump’s 2025 Order Reboots the Moon, Mars, and Nuclear Frontier
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:11:57 +0000
════════════════════════
⌗ Tags: #Technology #Artemis Program #Commercial Space #Donald Trump #Golden Dome Defense #Jared Isaacman #Lunar Outpost 2030 #Mars Mission #NASA #Space Force #Space Nuclear Power
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:11:57 +0000
════════════════════════
⌗ Tags: #Technology #Artemis Program #Commercial Space #Donald Trump #Golden Dome Defense #Jared Isaacman #Lunar Outpost 2030 #Mars Mission #NASA #Space Force #Space Nuclear Power
⤷ Title: The Double-Consent Trap: Italy Slaps Apple with $116M Fine Over Privacy Monopoly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:10:42 +0000
════════════════════════
⌗ Tags: #Apple #Technology #AGCM #antitrust #App Store #App Tracking Transparency (ATT) #data privacy #Digital Markets Act #European Commission #GDPR #Italy #Mobile Advertising
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:10:42 +0000
════════════════════════
⌗ Tags: #Apple #Technology #AGCM #antitrust #App Store #App Tracking Transparency (ATT) #data privacy #Digital Markets Act #European Commission #GDPR #Italy #Mobile Advertising
⤷ Title: Offside on the Dark Web: Qilin Ransomware Targets Argentine Giant River Plate
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:07:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #72 Trophies #Argentina Football #Club Atlético River Plate #cyber extortion #Cybersecurity 2025 #Dark Web #data breach #Estadio Monumental #Financial Fraud #Qilin Ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:07:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #72 Trophies #Argentina Football #Club Atlético River Plate #cyber extortion #Cybersecurity 2025 #Dark Web #data breach #Estadio Monumental #Financial Fraud #Qilin Ransomware
Information Security News
Offside on the Dark Web: Qilin Ransomware Targets Argentine Giant River Plate
The Argentine football giant Club Atlético River Plate (CARP) has become a target of extortion by the Qilin ransomware group. The club has appeared on the group’s dark web leak site, where it was …
⤷ Title: The Trusted Trap: How Hackers Weaponize Microsoft’s Own Login Flows to Bypass MFA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:03:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover (ATO) #Conditional Access #Device Code Phishing #Graphish #Microsoft 365 #OAuth 2.0 #Proofpoint #SquarePhish2 #TA2723 #UNK_AcademicFlare
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:03:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover (ATO) #Conditional Access #Device Code Phishing #Graphish #Microsoft 365 #OAuth 2.0 #Proofpoint #SquarePhish2 #TA2723 #UNK_AcademicFlare
Information Security News
The Trusted Trap: How Hackers Weaponize Microsoft’s Own Login Flows to Bypass MFA
Proofpoint is warning of a surge in phishing attacks in which attackers hijack corporate Microsoft 365 accounts not through fake login pages, but via a perfectly legitimate OAuth mechanism—device …
⤷ Title: Thunder & Lightning Return: Iran’s Infy APT Resurfaces with Advanced Foudre Exploits
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:02:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cyber Espionage #DGA #Ehsan8999100 #Foudre #Infy #Iranian APT #Prince of Persia #RSA Signature #Rugissement #SafeBreach #Telegram C2 #Tonnerre
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:02:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cyber Espionage #DGA #Ehsan8999100 #Foudre #Infy #Iranian APT #Prince of Persia #RSA Signature #Rugissement #SafeBreach #Telegram C2 #Tonnerre
Information Security News
Thunder & Lightning Return: Iran’s Infy APT Resurfaces with Advanced Foudre Exploits
After nearly five years of apparent dormancy, the Iranian threat group Infy—also known as Prince of Persia—has resurfaced. Security researchers at SafeBreach have identified a new campaign by this…