⤷ Title: Spy Games or Glitch? The Truth Behind Venezuela’s BGP Leak
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:25:48 +0000
════════════════════════
⌗ Tags: #Data Leak #AS8048 #ASPA #BGP Leak #Bryton Herdes #CANTV #cloudflare #Internet Infrastructure #network_security #Route Hijacking #Venezuela
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:25:48 +0000
════════════════════════
⌗ Tags: #Data Leak #AS8048 #ASPA #BGP Leak #Bryton Herdes #CANTV #cloudflare #Internet Infrastructure #network_security #Route Hijacking #Venezuela
Daily CyberSecurity
Spy Games or Glitch? The Truth Behind Venezuela’s BGP Leak
Recently, security analysts had discovered a BGP leak at Venezuela’s state-owned telecommunications company CANTV shortly before the U.S. military operation aimed at apprehending Nicolás Maduro. B…
⤷ Title: “Sophisticated” Zero-Day Demystified: Public Exploit Drop Blows Cover on Critical Apple WebKit Flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:22:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #Google TAG #iOS security #iphone #macOS #WebKit #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:22:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #Google TAG #iOS security #iphone #macOS #WebKit #zero_day
Daily CyberSecurity
“Sophisticated” Zero-Day Demystified: Public Exploit Drop Blows Cover on Critical Apple WebKit Flaw
The “black box” of a highly sophisticated Apple zero-day has just been cracked open. Security researcher jir4vv1t has publicly dissected CVE-2025-43529, a critical WebKit vulnerability…
⤷ Title: One Request to Rule Them All: Critical Trendnet Flaw (CVE-2025-15471) Allows Total Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:17:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_15471 #Firmware Security #IoT Vulnerability #rce #TEW_713RE #Trendnet #Wi_Fi security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:17:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_15471 #Firmware Security #IoT Vulnerability #rce #TEW_713RE #Trendnet #Wi_Fi security
Daily CyberSecurity
One Request to Rule Them All: Critical Trendnet Flaw (CVE-2025-15471) Allows Total Takeover
A critical pre-authentication command injection vulnerability has been uncovered in the Trendnet TEW-713RE Wi-Fi extender, allowing remote attackers to seize full control of the device with a sing…
⤷ Title: “Ghost Tap” Rising: New Wave of Android Malware Turns Phones into Digital Pickpockets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:11:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android Malware #Cybercrime #financial fraud #Ghost Tap #Group_IB #mobile security #NFC Security #Telegram scams
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:11:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android Malware #Cybercrime #financial fraud #Ghost Tap #Group_IB #mobile security #NFC Security #Telegram scams
Daily CyberSecurity
“Ghost Tap” Rising: New Wave of Android Malware Turns Phones into Digital Pickpockets
Your smartphone might be the only accomplice a thief needs to drain your bank account, even if your card never leaves your wallet. A new report from Group-IB reveals a surging underground market f…
⤷ Title: CVE-2025-60262: Critical Misconfiguration in H3C Wireless Gear Hands Control to Hackers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:06:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_60262 #H3C #Network Infrastructure #privilege escalation #root access #vsftpd #Wireless Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:06:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_60262 #H3C #Network Infrastructure #privilege escalation #root access #vsftpd #Wireless Security
Daily CyberSecurity
CVE-2025-60262: Critical Misconfiguration in H3C Wireless Gear Hands Control to Hackers
A glaring configuration oversight in select H3C wireless controllers and access points has opened the door for remote attackers to seize root-level control of the devices. The vulnerability, track…
⤷ Title: Taiwan Faces 2.6 Million Cyberattacks Daily from China
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Critical Infrastructure #Cyber Warfare #Energy Sector Security #Hybrid Warfare #infosec #Mustang Panda #Taiwan NSB
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:01:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT41 #Critical Infrastructure #Cyber Warfare #Energy Sector Security #Hybrid Warfare #infosec #Mustang Panda #Taiwan NSB
Daily CyberSecurity
Taiwan Faces 2.6 Million Cyberattacks Daily from China
Recently, Taiwan’s National Security Bureau (NSB) has released a comprehensive report detailing a massive surge in state-sponsored cyber aggression. The analysis for the year 2025 paints a grim pi…
⤷ Title: Lo-Fi TryHackMe Write UP
════════════════════════
𐀪 Author: cat0x01
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:48:59 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #pentesting #hacking #cybersecurity
════════════════════════
𐀪 Author: cat0x01
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:48:59 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #pentesting #hacking #cybersecurity
Medium
Lo-Fi TryHackMe Write UP
We’re back with another TryHackMe challenge. called LO-FI
⤷ Title: TryHackMe: Willow Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 01:42:11 GMT
════════════════════════
⌗ Tags: #information_security #tryhackme #pentesting #cybersecurity
════════════════════════
𐀪 Author: cbev
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 01:42:11 GMT
════════════════════════
⌗ Tags: #information_security #tryhackme #pentesting #cybersecurity
Medium
TryHackMe: Willow Writeup
This box is ranked medium on THM, it involves us mounting a file share to get access to RSA key pair integers, which we can use to recover…
⤷ Title: From Ghostcat to Root: A Comprehensive Walkthrough of the Thompson Lab
════════════════════════
𐀪 Author: Justin Jude Cabodil
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:43:32 GMT
════════════════════════
⌗ Tags: #tryhackme #ajp #linux
════════════════════════
𐀪 Author: Justin Jude Cabodil
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:43:32 GMT
════════════════════════
⌗ Tags: #tryhackme #ajp #linux
Medium
From Ghostcat to Root: A Comprehensive Walkthrough of the Thompson Lab
In the world of cybersecurity, “Boot2Root” machines serve as the ultimate playground for testing technical depth and creative lateral…
⤷ Title: CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:55:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2009_0556 #CVE_2025_37164 #HPE OneView #Infrastructure Security #KEV Catalog #Microsoft PowerPoint #vulnerability management #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:55:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2009_0556 #CVE_2025_37164 #HPE OneView #Infrastructure Security #KEV Catalog #Microsoft PowerPoint #vulnerability management #zero_day
Daily CyberSecurity
CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with two new entries that span nearly two decades of computing history. Th…
⤷ Title: Public Exploit Released: Critical n8n Flaw CVE-2026-21858 Exposes 100k Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:44:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #CVE_2026_21858 #Cyera #DevSecOps #n8n #Public Exploit #RCE (Remote Code Execution) #Workflow Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:44:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API security #CVE_2026_21858 #Cyera #DevSecOps #n8n #Public Exploit #RCE (Remote Code Execution) #Workflow Automation
Daily CyberSecurity
Public Exploit Released: Critical n8n Flaw CVE-2026-21858 Exposes 100k Servers
The “central nervous system” of automation for thousands of companies has a critical weakness. A new report from Cyera reveals a devastating vulnerability in n8n, the popular workflow …
⤷ Title: “VM Isolation is Not Absolute”: Researchers Unmask Sophisticated ESXi “Maestro” Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:03:02 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CVE_2025_22224 #Huntress #Malware Analysis #Virtualization Security #VM Escape #VMware ESXi #VSOCKpuppet #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:03:02 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CVE_2025_22224 #Huntress #Malware Analysis #Virtualization Security #VM Escape #VMware ESXi #VSOCKpuppet #zero_day
Daily CyberSecurity
“VM Isolation is Not Absolute”: Researchers Unmask Sophisticated ESXi “Maestro” Exploit
In a new report, the Huntress Tactical Response Team details a sophisticated intrusion discovered in December 2025 where threat actors successfully executed a “VM escape”—breaking out …
⤷ Title: GoBruteforcer Returns: How AI Code Snippets Fueled a 50,000-Server Botnet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:45:28 +0000
════════════════════════
⌗ Tags: #Malware #AI_Generated Code #botnet #brute force attack #Check Point Research #Crypto theft #GoBruteforcer #Linux Security #Malware Analysis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:45:28 +0000
════════════════════════
⌗ Tags: #Malware #AI_Generated Code #botnet #brute force attack #Check Point Research #Crypto theft #GoBruteforcer #Linux Security #Malware Analysis
Daily CyberSecurity
GoBruteforcer Returns: How AI Code Snippets Fueled a 50,000-Server Botnet
A sophisticated new variant of the GoBruteforcer botnet is on the loose, and it’s capitalizing on a thoroughly modern problem: the “mass reuse of AI-generated server deployment example…
⤷ Title: CVE-2025-67859: Critical Auth Bypass Discovered in Popular Linux Battery Utility
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:28:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67859 #Denial of Service (DoS) #Linux Security #Polkit #Power Management #privilege escalation #SUSE #TLP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:28:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_67859 #Denial of Service (DoS) #Linux Security #Polkit #Power Management #privilege escalation #SUSE #TLP
Daily CyberSecurity
CVE-2025-67859: Critical Auth Bypass Discovered in Popular Linux Battery Utility
A critical security flaw has been unearthed in TLP, the widely used power management utility for Linux laptops, potentially allowing unauthorized users to bypass authentication checks and tamper w…
⤷ Title: CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:17:34 +0000
════════════════════════
⌗ Tags: #Malware #Active Directory Security #BYOVD (Bring Your Own Vulnerable Driver) #CrazyHunter #healthcare security #Malware Analysis #ransomware #SharpGPOAbuse #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:17:34 +0000
════════════════════════
⌗ Tags: #Malware #Active Directory Security #BYOVD (Bring Your Own Vulnerable Driver) #CrazyHunter #healthcare security #Malware Analysis #ransomware #SharpGPOAbuse #Trellix
Daily CyberSecurity
CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
A new, highly aggressive ransomware strain is cutting a swath through the healthcare sector, leaving hospitals and critical organizations scrambling to protect their data. Security researchers at …
⤷ Title: GitLab Patch: High-Severity XSS & AI Flaws Expose User Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:08:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Application Security #CVE_2025_9222 #DevSecOps #gitlab #GitLab Duo #software update #vulnerability management #XSS (Cross_Site Scripting)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:08:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Application Security #CVE_2025_9222 #DevSecOps #gitlab #GitLab Duo #software update #vulnerability management #XSS (Cross_Site Scripting)
Daily CyberSecurity
GitLab Patch: High-Severity XSS & AI Flaws Expose User Data
GitLab has issued a critical security release for its Community Edition (CE) and Enterprise Edition (EE) platforms, patching a raft of vulnerabilities that range from high-severity Cross-Site Scri…
⤷ Title: Recruiting Google Gemini’s Email Summarizer as a Phishing Aid
════════════════════════
𐀪 Author: Mike Sheward
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:23:09 GMT
════════════════════════
⌗ Tags: #llm #infosec #gemini #ai #bug_bounty
════════════════════════
𐀪 Author: Mike Sheward
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:23:09 GMT
════════════════════════
⌗ Tags: #llm #infosec #gemini #ai #bug_bounty
Medium
Recruiting Google Gemini’s Email Summarizer as a Phishing Aid
Note: I originally disclosed these findings to the Google AI Bug Bounty (or VRP program), but they rejected them as being a non-qualified…
⤷ Title: LangChain Serialization Vulnerabilities: When LLMs Generate Exploits
════════════════════════
𐀪 Author: David Anderson
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:25:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #artificial_intelligence #ai #application_security
════════════════════════
𐀪 Author: David Anderson
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 02:25:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #artificial_intelligence #ai #application_security
Medium
LangChain Serialization Vulnerabilities: When LLMs Generate Exploits
Two critical vulnerabilities were published December 23, 2025 affecting LangChain Python (CVE-2025–68664, CVSS 9.3) and JavaScript…
⤷ Title: Archa CTF 2026 — Mobile (Writeups)
════════════════════════
𐀪 Author: CynPhone
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:38:01 GMT
════════════════════════
⌗ Tags: #mobile_games #hacking #ctf_writeup #mobile_security #ctf
════════════════════════
𐀪 Author: CynPhone
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:38:01 GMT
════════════════════════
⌗ Tags: #mobile_games #hacking #ctf_writeup #mobile_security #ctf
Medium
Archa CTF 2026 — Mobile (Writeups)
สวัสดีครับ ‘โฟน’ นะครับ สำหรับWriteups ในครั้งนี้มาจากการแข่งขัน Archa CTF บอกได้เลยครับว่าโจทย์สนุกทุกข้อ💖…
⤷ Title: Why Spotify’s latest problem could change music forever
════════════════════════
𐀪 Author: Abstract Mind
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:28:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #hacking #security
════════════════════════
𐀪 Author: Abstract Mind
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:28:33 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #hacking #security
Medium
Why Spotify’s latest problem could change music forever
Pirate activist group and shadow library Anna’s Archive claims to have “backed up” the world’s largest music streamer
⤷ Title: Token Leakage in Password Reset Flows
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:15:12 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #pentesting #passwords #cybersecurity
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:15:12 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #pentesting #passwords #cybersecurity
Medium
Token Leakage in Password Reset Flows
A Simple, High‑Impact Bug Bounty Technique