⤷ Title: Best Recon Method to Find JavaScript Vulnerabilities
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:38:15 GMT
════════════════════════
⌗ Tags: #javascript #tech #bug_bounty #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:38:15 GMT
════════════════════════
⌗ Tags: #javascript #tech #bug_bounty #penetration_testing #cybersecurity
Medium
Best Recon Method to Find JavaScript Vulnerabilities
From One-Liner Commands to Real-World Vulnerabilities That Pay
⤷ Title: Malware Analysis Report: “SecretPictures” USB Worm & Info-Stealer
════════════════════════
𐀪 Author: Rahaliashraf
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:56:38 GMT
════════════════════════
⌗ Tags: #hacking #malware #hackthebox #cybersecurity #malware_analysis
════════════════════════
𐀪 Author: Rahaliashraf
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:56:38 GMT
════════════════════════
⌗ Tags: #hacking #malware #hackthebox #cybersecurity #malware_analysis
Medium
Malware Analysis Report: “SecretPictures” USB Worm & Info-Stealer
HackTheBox: SecretPictures
⤷ Title: Android Attacks Google Confirms No Fix For 30% Of All Phones
════════════════════════
𐀪 Author: Moni
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:13:04 GMT
════════════════════════
⌗ Tags: #hacking #data #self_improvement #google #writing
════════════════════════
𐀪 Author: Moni
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:13:04 GMT
════════════════════════
⌗ Tags: #hacking #data #self_improvement #google #writing
Medium
Android Attacks Google Confirms No Fix For 30% Of All Phones
Take this seriously. Google kicked off Dangerous December with a warning that Android is now under attack. Two vulnerabilities have been…
⤷ Title: When an Unusual Open Port Leads to Full Compromise: Lessons from an NFS Lab
════════════════════════
𐀪 Author: Vivektumma27
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:28:19 GMT
════════════════════════
⌗ Tags: #privilege_escalation #ethical_hacking #linux_security #nfs_server #cybersecurity
════════════════════════
𐀪 Author: Vivektumma27
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:28:19 GMT
════════════════════════
⌗ Tags: #privilege_escalation #ethical_hacking #linux_security #nfs_server #cybersecurity
Medium
When an Unusual Open Port Leads to Full Compromise: Lessons from an NFS Lab
TL;DR In this lab, I identified an uncommon open port tied to network file sharing, investigated exposed RPC services, and discovered a…
⤷ Title: Understanding OWASP API Security Top 10 With Live Breach Examples — A Practical Guide
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:38:27 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #owasp_top_10 #api_security #web_development
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:38:27 GMT
════════════════════════
⌗ Tags: #api #cybersecurity #owasp_top_10 #api_security #web_development
Medium
Understanding OWASP API Security Top 10 With Live Breach Examples — A Practical Guide
Understanding OWASP API Security Top 10 With Live Breach Examples — A Practical Guide
⤷ Title: Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:08:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #Cybersecurity 2025 #Entra ID #Golden SAML #Identity Security #Pentesting #SAML #SAMLSmith #Silver SAML #XML Forgery
Information Security News
Forging the Keys: Inside SAMLSmith, the C# Framework for Golden & Silver SAML Attacks
SAMLSmith is a C# tool for generating custom SAML responses and implementing Silver SAML and Golden SAML attacks. It provides comprehensive functionality for security researchers and penetration t…
⤷ Title: The End of Crashes: Mullvad’s New GotaTun Rust Engine Slashes VPN Failures by 97%
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:43:09 +0000
════════════════════════
⌗ Tags: #Technology #Android #BoringTun #DAITA #GotaTun #Memory Safety #Mullvad VPN #Multihop #open source #Rust #VPN Performance #WireGuard
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:43:09 +0000
════════════════════════
⌗ Tags: #Technology #Android #BoringTun #DAITA #GotaTun #Memory Safety #Mullvad VPN #Multihop #open source #Rust #VPN Performance #WireGuard
⤷ Title: Automation Crisis: Critical 9.9 CVSS Flaw Exposes 103K n8n Instances to Full Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:40:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Censys #CVE_2025_68613 #Cybersecurity 2025 #DevOps Security #n8n #Node.js #Patch Alert #RCE #remote code execution #Sandbox Escape #Workflow Automation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:40:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Censys #CVE_2025_68613 #Cybersecurity 2025 #DevOps Security #n8n #Node.js #Patch Alert #RCE #remote code execution #Sandbox Escape #Workflow Automation
Information Security News
Automation Crisis: Critical 9.9 CVSS Flaw Exposes 103K n8n Instances to Full Takeover
A critical vulnerability in the globally used workflow automation platform n8n allows attackers to execute arbitrary code remotely. Tracked as CVE-2025-68613, the flaw carries an exceptionally hig…
⤷ Title: The Ad Trap Closed: DOJ Seizes Global Control Hub Behind $28M Bank Fraud
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:39:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bank Account Takeover #Cybercrime 2025 #DOJ #Estonia #FBI #Georgia #Google Ads #IC3 #phishing #Search Engine Fraud #web3adspanels
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:39:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bank Account Takeover #Cybercrime 2025 #DOJ #Estonia #FBI #Georgia #Google Ads #IC3 #phishing #Search Engine Fraud #web3adspanels
Information Security News
The Ad Trap Closed: DOJ Seizes Global Control Hub Behind $28M Bank Fraud
U.S. law enforcement authorities have announced the seizure of a domain used in a large-scale scheme to steal bank accounts. According to the U.S. Department of Justice, the site—web3adspanels[.]o…
⤷ Title: The Admin’s Shadow: How Hackers Turned the Nezha Monitoring Tool into a Stealth RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:38:40 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #Evasion #Nezha #NT AUTHORITY\SYSTEM #Ontinue #open source #post_exploitation #Qualys #RAT #RMM Abuse #Root Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:38:40 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security 2025 #Evasion #Nezha #NT AUTHORITY\SYSTEM #Ontinue #open source #post_exploitation #Qualys #RAT #RMM Abuse #Root Access
Information Security News
The Admin’s Shadow: How Hackers Turned the Nezha Monitoring Tool into a Stealth RAT
Threat actors have begun repurposing a legitimate server monitoring tool as a ready-made platform for remotely controlling systems that have already been compromised. According to the Ontinue Cybe…
⤷ Title: The Silent Sync: How the “lotusbail” npm Package Hijacks WhatsApp Accounts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:36:24 +0000
════════════════════════
⌗ Tags: #Malware #Baileys library #Cybersecurity 2025 #JavaScript #Koi Security #lotusbail #malware #npm #Session Hijacking #supply chain attack #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:36:24 +0000
════════════════════════
⌗ Tags: #Malware #Baileys library #Cybersecurity 2025 #JavaScript #Koi Security #lotusbail #malware #npm #Session Hijacking #supply chain attack #WhatsApp
Information Security News
The Silent Sync: How the “lotusbail” npm Package Hijacks WhatsApp Accounts
A malicious package named lotusbail has been uncovered in the npm repository, masquerading as a library for working with WhatsApp Web while quietly siphoning conversations and granting attackers p…
⤷ Title: Spotify Cracks Down After Anna’s Archive Publishes Massive Music Dataset
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:33:00 +0000
════════════════════════
⌗ Tags: #Data Leak #Anna’s Archive #copyright #data scraping #digital libraries #music piracy #Spotify #stream_ripping
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:33:00 +0000
════════════════════════
⌗ Tags: #Data Leak #Anna’s Archive #copyright #data scraping #digital libraries #music piracy #Spotify #stream_ripping
Information Security News
Spotify Cracks Down After Anna’s Archive Publishes Massive Music Dataset
Spotify has blocked a number of accounts after the Anna’s Archive team publicly released a dataset collected from the streaming platform. According to the group, the trove comprises 86 million aud…
⤷ Title: Agent Under Fire: OpenAI Hardens ChatGPT Atlas Against “Invisible” Resignation Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:30:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Adversarial Training #AI security #Browser Agent #ChatGPT Atlas #Cyber Security 2025 #OpenAI #Prompt Injection #red teaming #Reinforcement Learning
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:30:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #Adversarial Training #AI security #Browser Agent #ChatGPT Atlas #Cyber Security 2025 #OpenAI #Prompt Injection #red teaming #Reinforcement Learning
Information Security News
Agent Under Fire: OpenAI Hardens ChatGPT Atlas Against “Invisible” Resignation Attacks
OpenAI has released a security update for ChatGPT Atlas, a browser equipped with a built-in “agent mode” that can browse the web and act within it almost like a human—clicking, typing, and carryin…
⤷ Title: Linux Kernel 6.19 Slashes Latency & Boosts Legacy AMD GPUs by 30%
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:11:16 +0000
════════════════════════
⌗ Tags: #Linux #AMDGPU #GCN 1.0 #GCN 1.1 #GPU Drivers #Linux Kernel 6.19 #Mesa RADV #open_source #Radeon HD 7950 #Retro Gaming #Valve #Vulkan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 03:11:16 +0000
════════════════════════
⌗ Tags: #Linux #AMDGPU #GCN 1.0 #GCN 1.1 #GPU Drivers #Linux Kernel 6.19 #Mesa RADV #open_source #Radeon HD 7950 #Retro Gaming #Valve #Vulkan
Daily CyberSecurity
Linux Kernel 6.19 Slashes Latency & Boosts Legacy AMD GPUs by 30%
In 2011, AMD introduced its Graphics Core Next 1.0 architecture, codenamed Southern Islands, debuting with the now-iconic Radeon HD 7970. Within this design, AMD pioneered asynchronous compute eng…
⤷ Title: Racing the Zombie: PoC Released for Linux Kernel POSIX Timer Vulnerability (CVE-2025-38352)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:52:30 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #Android security #ARM 32_bit #CVE_2025_38352 #KASAN #kernel_exploitation #Linux Kernel #POSIX CPU Timers #proof_of_concept #race condition #Use_After_Free (UAF)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:52:30 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #Android security #ARM 32_bit #CVE_2025_38352 #KASAN #kernel_exploitation #Linux Kernel #POSIX CPU Timers #proof_of_concept #race condition #Use_After_Free (UAF)
Daily CyberSecurity
Racing the Zombie: PoC Released for Linux Kernel POSIX Timer Vulnerability (CVE-2025-38352)
A vulnerability in the Linux kernel’s implementation of POSIX CPU timers has drawn attention following the release of a working proof-of-concept exploit. The flaw, tracked as CVE-2025-38352, is a …
⤷ Title: Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:47:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #ATO #Bing Ads #DOJ #fbi #Financial Crime #Google Ads #Malvertising #Northern District of Georgia #Search Engine Fraud #web3adspanels.org
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:47:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #ATO #Bing Ads #DOJ #fbi #Financial Crime #Google Ads #Malvertising #Northern District of Georgia #Search Engine Fraud #web3adspanels.org
Daily CyberSecurity
Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme
A sprawling cybercrime operation that weaponized trusted search engines to drain millions from American bank accounts has been dismantled by federal authorities. The Department of Justice (DOJ) an…
⤷ Title: The Hard-Coded Backdoor: Critical 9.8 Severity NVIDIA Flaws Grant Total Control of AI Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:37:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2025_33222 #CVE_2025_33223 #CVE_2025_33224 #Hard_coded Credentials #Isaac Launchable #nvidia #privilege escalation #Remote Code Execution #Robotics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 01:37:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2025_33222 #CVE_2025_33223 #CVE_2025_33224 #Hard_coded Credentials #Isaac Launchable #nvidia #privilege escalation #Remote Code Execution #Robotics
Daily CyberSecurity
The Hard-Coded Backdoor: Critical 9.8 Severity NVIDIA Flaws Grant Total Control of AI Systems
NVIDIA has issued an urgent security update for its Isaac Launchable software, patching a trio of critical vulnerabilities that could allow attackers to seize total control of affected systems. Th…
⤷ Title: Critical Network Collapse: 9.8 Severity Net-SNMP Buffer Overflow Threatens Global Monitoring Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:40:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_68615 #Denial of Service #Infrastructure Security #Net_SNMP #network monitoring #Patch Alert #Remote Code Execution #snmptrapd #Zero Day Initiative
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:40:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_68615 #Denial of Service #Infrastructure Security #Net_SNMP #network monitoring #Patch Alert #Remote Code Execution #snmptrapd #Zero Day Initiative
Daily CyberSecurity
Critical Network Collapse: 9.8 Severity Net-SNMP Buffer Overflow Threatens Global Monitoring Systems
A critical security vulnerability has been found in Net-SNMP, the ubiquitous software suite used globally for network monitoring and management. Tracked as CVE-2025-68615, the flaw carries a near-…
⤷ Title: “Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT37 #Artemis Campaign #cyber_espionage #Genians Security Center #HWP Malware #North Korea #pCloud #Reaper #Ricochet Chollima #social engineering #Yandex Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT37 #Artemis Campaign #cyber_espionage #Genians Security Center #HWP Malware #North Korea #pCloud #Reaper #Ricochet Chollima #social engineering #Yandex Cloud
Daily CyberSecurity
“Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets
A notorious threat group is auditioning victims for a new cyber-espionage campaign, masquerading as television production staff to slip malware past defenses. A new report from Genians Security Ce…
⤷ Title: The Notarized Nightmare: New MacSync Stealer Bypasses Gatekeeper to Hijack Mac Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:28:59 +0000
════════════════════════
⌗ Tags: #Malware #Apple Notarization #Code Signing #Cyber Security #Gatekeeper Bypass #Infostealer #Jamf Threat Labs #macOS Malware #MacSync Stealer #swift #ZK_Call Messenger
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:28:59 +0000
════════════════════════
⌗ Tags: #Malware #Apple Notarization #Code Signing #Cyber Security #Gatekeeper Bypass #Infostealer #Jamf Threat Labs #macOS Malware #MacSync Stealer #swift #ZK_Call Messenger
Daily CyberSecurity
The Notarized Nightmare: New MacSync Stealer Bypasses Gatekeeper to Hijack Mac Devices
The cat-and-mouse game between Apple’s security protocols and malware authors has taken a stealthy turn. A new report from Jamf Threat Labs reveals that the increasingly active MacSync Steal…
⤷ Title: “Operation IconCat”: Hackers Masquerade as Security Giants to Target Israeli Firms
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:23:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Check Point #cyber_espionage #Icon Spoofing #Israel #Operation IconCat #PYTRIC #RUSTRIC #SentinelOne #Seqrite Labs #UNG0801 #Western Asia #wiper malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:23:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Check Point #cyber_espionage #Icon Spoofing #Israel #Operation IconCat #PYTRIC #RUSTRIC #SentinelOne #Seqrite Labs #UNG0801 #Western Asia #wiper malware
Daily CyberSecurity
“Operation IconCat”: Hackers Masquerade as Security Giants to Target Israeli Firms
A new and deceptive cyber-espionage campaign is targeting Israeli organizations by disguising malicious implants as trusted antivirus software updates. A new report from SEQRITE Labs’ APT Team det…