⤷ Title: Red Teaming at Scale: GHARF Automates the Attack Lifecycle via CI/CD
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:08:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Automation #CAI/CAD #CI/CD Security #DevSecOps #GHARF #GitHub Actions #InfoSec 2026 #Offensive Security #Pentesting #red teaming
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:08:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Automation #CAI/CAD #CI/CD Security #DevSecOps #GHARF #GitHub Actions #InfoSec 2026 #Offensive Security #Pentesting #red teaming
Penetration Testing Tools
Red Teaming at Scale: GHARF Automates the Attack Lifecycle via CI/CD
Discover GHARF, the framework bringing CI/CD to Red Teaming. Learn how CAI/CAD automates attack cycles for rapid, high-fidelity security exercises.
⤷ Title: The Browser Puppeteer: New Vishing Kits Hijack Sessions in Real-Time
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:03:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #FIDO2 #InfoSec 2026 #MFA Bypass #Okta #Okta FastPass #Phishing_as_a_Service #Session Orchestration #ShinyHunters #Social Engineering #Vishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:03:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #FIDO2 #InfoSec 2026 #MFA Bypass #Okta #Okta FastPass #Phishing_as_a_Service #Session Orchestration #ShinyHunters #Social Engineering #Vishing
Penetration Testing Tools
The Browser Puppeteer: New Vishing Kits Hijack Sessions in Real-Time
Social engineering offensives are undergoing a sophisticated metamorphosis—adversaries now amalgamate telephonic directives with dynamic phishing kits that facilitate
⤷ Title: The Industrialized Scam: How Sinch and Microsoft Teams Power the Global Fraud Trade
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:01:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Callback Scheme #Demurrage Report #InfoSec 2026 #Inteliquent #KYC #Microsoft Teams #Sinch #Telecom Security #Tom Walker #VoIP Fraud
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:01:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Callback Scheme #Demurrage Report #InfoSec 2026 #Inteliquent #KYC #Microsoft Teams #Sinch #Telecom Security #Tom Walker #VoIP Fraud
Penetration Testing Tools
The Industrialized Scam: How Sinch and Microsoft Teams Power the Global Fraud Trade
When the facade of a PayPal, Microsoft, or banking “support” number graces a smartphone screen, few perceive the
⤷ Title: The ERP Breach: North Korea’s Andariel Group Strikes Europe with New Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:00:03 +0000
════════════════════════
⌗ Tags: #Malware #Andariel #BYOVD #ERP Hack #GopherRAT #InfoSec 2026 #JelusRAT #North Korea #StarshellRAT #supply chain attack #TigerRAT #WithSecure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 08:00:03 +0000
════════════════════════
⌗ Tags: #Malware #Andariel #BYOVD #ERP Hack #GopherRAT #InfoSec 2026 #JelusRAT #North Korea #StarshellRAT #supply chain attack #TigerRAT #WithSecure
Penetration Testing Tools
The ERP Breach: North Korea’s Andariel Group Strikes Europe with New Malware
The North Korean-aligned cyber-espionage syndicate Andariel has reasserted its presence through a sophisticated offensive targeting entities across Europe
⤷ Title: MFA Under Siege: Microsoft Unveils Stealthy AiTM Attacks Striking the Energy Sector
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:58:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #BEC #Energy Sector #InfoSec 2026 #MFA Bypass #Microsoft #Microsoft Defender #phishing #Session Hijacking #SharePoint
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:58:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #BEC #Energy Sector #InfoSec 2026 #MFA Bypass #Microsoft #Microsoft Defender #phishing #Session Hijacking #SharePoint
Penetration Testing Tools
MFA Under Siege: Microsoft Unveils Stealthy AiTM Attacks Striking the Energy Sector
Microsoft has disclosed a sophisticated sequence of multi-stage incursions leveraging Adversary-in-the-Middle (AiTM) session hijacking in tandem with Business
⤷ Title: The Developer’s Trap: EmEditor Supply Chain Attack Drains Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:57:05 +0000
════════════════════════
⌗ Tags: #Malware #Developer Security #EmEditor #Emurasoft #Google Drive Caching #InfoSec 2026 #Infostealer #PowerShell #supply chain attack #Trend Micro #Watering Hole
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:57:05 +0000
════════════════════════
⌗ Tags: #Malware #Developer Security #EmEditor #Emurasoft #Google Drive Caching #InfoSec 2026 #Infostealer #PowerShell #supply chain attack #Trend Micro #Watering Hole
Penetration Testing Tools
The Developer’s Trap: EmEditor Supply Chain Attack Drains Credentials
In late December 2025, the architects of the renowned text editor EmEditor issued a formal advisory regarding the
⤷ Title: The Year the Web Faltered: Cloudflare’s 2025 Report Unveils a Fragile Digital World
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:52:42 +0000
════════════════════════
⌗ Tags: #Technology #Cloudflare Radar #Digital Blackout #InfoSec 2026 #Infrastructure Security #Internet Outage #Network Resilience #Submarine Cables #Tanzania Election #WACS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:52:42 +0000
════════════════════════
⌗ Tags: #Technology #Cloudflare Radar #Digital Blackout #InfoSec 2026 #Infrastructure Security #Internet Outage #Network Resilience #Submarine Cables #Tanzania Election #WACS
Penetration Testing Tools
The Year the Web Faltered: Cloudflare’s 2025 Report Unveils a Fragile Digital World
The internet appears as a steadfast and nearly imperceptible presence in our daily lives, until the abrupt moment
⤷ Title: Office Under Siege: Microsoft Rushes Emergency Fix for Active Zero-Day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:51:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2026_21509 #Cyber Security #InfoSec 2026 #Microsoft 365 #Microsoft Office #OLE Bypass #Patch Management #Social Engineering #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:51:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2026_21509 #Cyber Security #InfoSec 2026 #Microsoft 365 #Microsoft Office #OLE Bypass #Patch Management #Social Engineering #zero_day
Penetration Testing Tools
Office Under Siege: Microsoft Rushes Emergency Fix for Active Zero-Day
Microsoft has issued an urgent, out-of-band security update for Microsoft Office to mitigate a high-stakes zero-day vulnerability that
⤷ Title: VPNs & Fake Updates: Google Dismantles Massive IPIDEA Proxy Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 31 Jan 2026 00:32:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android security #botnet #Galleon VPN #Google Threat Intelligence #IPIDEA #Malicious SDK #Proxy Hijacking #Radish VPN #residential proxy #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 31 Jan 2026 00:32:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android security #botnet #Galleon VPN #Google Threat Intelligence #IPIDEA #Malicious SDK #Proxy Hijacking #Radish VPN #residential proxy #Windows malware
Daily CyberSecurity
VPNs & Fake Updates: Google Dismantles Massive IPIDEA Proxy Network
Google disrupts IPIDEA proxy network. Fake VPNs and hijacked apps turned millions of devices into unwitting exit nodes. Play Protect is removing them.
⤷ Title: From User to SYSTEM: PoC Released for Zabbix Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 02:52:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #Patch Alert #PoC #privilege escalation #SYSTEM privileges #Windows Security #Zabbix #Zabbix Agent
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 02:52:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #Patch Alert #PoC #privilege escalation #SYSTEM privileges #Windows Security #Zabbix #Zabbix Agent
Daily CyberSecurity
From User to SYSTEM: PoC Released for Zabbix Privilege Escalation
Exploit code released for Zabbix flaw CVE-2025-27237. Low-level users can gain SYSTEM privileges on Windows via OpenSSL config. Update now.
⤷ Title: “Update” to Nightmare: eScan Antivirus Hacked to Distribute Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 02:15:55 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Compromise #cyber attack #eScan #infosec #malware #Manual Patch #MicroWorld Technologies #Morphisec #Reload.exe #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 02:15:55 +0000
════════════════════════
⌗ Tags: #Malware #Antivirus Compromise #cyber attack #eScan #infosec #malware #Manual Patch #MicroWorld Technologies #Morphisec #Reload.exe #supply chain attack
Daily CyberSecurity
"Update" to Nightmare: eScan Antivirus Hacked to Distribute Malware
Critical supply chain attack hits eScan antivirus. Hackers hijacked updates to install malware and disable the AV. Manual patch required.
⤷ Title: Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:59:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #building automation #CISA #Critical Vulnerability #CVE_2025_26385 #ICS security #Johnson Controls #Metasys #Smart Building #sql injection #TCP 1433
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:59:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #building automation #CISA #Critical Vulnerability #CVE_2025_26385 #ICS security #Johnson Controls #Metasys #Smart Building #sql injection #TCP 1433
Daily CyberSecurity
Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
CISA warns of CVSS 10 flaw CVE-2025-26385 in Johnson Controls Metasys. Remote SQL execution possible. Patch now or close TCP port 1433.
⤷ Title: Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:52:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #exploited in the wild #Ivanti EPMM #MDM #mobile security #MobileIron Core #rce #Remote Code Execution #unauthenticated RCE #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 01:52:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_1281 #CVE_2026_1340 #exploited in the wild #Ivanti EPMM #MDM #mobile security #MobileIron Core #rce #Remote Code Execution #unauthenticated RCE #zero_day
Daily CyberSecurity
Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack
Ivanti confirms critical EPMM RCE flaws (CVE-2026-1281) are exploited in the wild. Unauthenticated attackers can compromise MDM. Patch immediately.
⤷ Title: Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:27:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admission Controller #cloud_native #CVE_2026_22039 #CVE_2026_23881 #DevSecOps #dos #K8s #Kubernetes Security #Kyverno #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:27:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admission Controller #cloud_native #CVE_2026_22039 #CVE_2026_23881 #DevSecOps #dos #K8s #Kubernetes Security #Kyverno #privilege escalation
Daily CyberSecurity
Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
Critical Kyverno flaw CVE-2026-22039 (CVSS 10) allows policy creators to gain cluster admin rights. Update to v1.16.3 to fix privilege escalation & DoS.
⤷ Title: “SessionReaper” Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:21:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #API vulnerability #CVE_2025_54236 #e_commerce security #Magento #Oasis Security #root access #Session Hijacking #SessionReaper #Web Shells
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:21:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #API vulnerability #CVE_2025_54236 #e_commerce security #Magento #Oasis Security #root access #Session Hijacking #SessionReaper #Web Shells
Daily CyberSecurity
"SessionReaper" Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites
"SessionReaper" (CVE-2025-54236) targets Magento stores. Attackers use zombie tokens to gain root access. 200+ sites compromised. Patch now.
⤷ Title: Scam Alert: “Amazon Ads Blocker” Extension Hijacks Creator Commissions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:16:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #10xprofit_20 #adware #Affiliate Hijacking #Affiliate Marketing #Amazon Ads Blocker #Chrome extension #Creator Revenue #google chrome #Malicious Extension #Socket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:16:51 +0000
════════════════════════
⌗ Tags: #Cybercriminals #10xprofit_20 #adware #Affiliate Hijacking #Affiliate Marketing #Amazon Ads Blocker #Chrome extension #Creator Revenue #google chrome #Malicious Extension #Socket Security
Daily CyberSecurity
Scam Alert: "Amazon Ads Blocker" Extension Hijacks Creator Commissions
"Amazon Ads Blocker" extension exposed for stealing creator revenue. It hijacks affiliate links to divert commissions to the developer. Uninstall it now.
⤷ Title: Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:13:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2025_33217 #CVE_2025_33220 #GPU Driver #Linux Security #nvidia #privilege escalation #use after free #vGPU #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:13:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Execution #CVE_2025_33217 #CVE_2025_33220 #GPU Driver #Linux Security #nvidia #privilege escalation #use after free #vGPU #Windows Security
Daily CyberSecurity
Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws
NVIDIA patches high-severity flaws (CVE-2025-33217) in GPU drivers & vGPU software. Flaws allow code execution. Update Windows/Linux drivers now.
⤷ Title: The “WorkMail Pivot”: Hackers Abuse AWS WorkMail to Bypass SES Sandbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
Daily CyberSecurity
The "WorkMail Pivot": Hackers Abuse AWS WorkMail to Bypass SES Sandbox
Attackers are bypassing AWS SES sandbox limits by pivoting to WorkMail. Rapid7 reveals how this abuse creates a blind spot for defenders.
⤷ Title: The Great Recalibration: Amazon Cuts 16,000 More Roles in Massive Shift to AI-First Future
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:06:37 +0000
════════════════════════
⌗ Tags: #Technology #Amazon #Amazon Jobs #artificial intelligence #Beth Galetti #Corporate Restructuring #Future of Work #Generative AI #Layoffs 2026 #Tech News #Workforce Reduction
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:06:37 +0000
════════════════════════
⌗ Tags: #Technology #Amazon #Amazon Jobs #artificial intelligence #Beth Galetti #Corporate Restructuring #Future of Work #Generative AI #Layoffs 2026 #Tech News #Workforce Reduction
Daily CyberSecurity
The Great Recalibration: Amazon Cuts 16,000 More Roles in Massive Shift to AI-First Future
Amazon confirms 16,000 new layoffs in Jan 2026, completing a 30,000-person cut. Discover how the titan is swapping managers for Generative AI tech.
⤷ Title: The AI Squeeze: NVIDIA Overtakes Apple as TSMC’s Top Revenue Source
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:03:27 +0000
════════════════════════
⌗ Tags: #Technology #A19 chip #AI Infrastructure #Apple #Blackwell GPU #CoWoS #data centers #Jensen Huang #nvidia #Semiconductor News 2026 #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:03:27 +0000
════════════════════════
⌗ Tags: #Technology #A19 chip #AI Infrastructure #Apple #Blackwell GPU #CoWoS #data centers #Jensen Huang #nvidia #Semiconductor News 2026 #TSMC
Daily CyberSecurity
The AI Squeeze: NVIDIA Overtakes Apple as TSMC’s Top Revenue Source
NVIDIA replaces Apple as TSMC's largest customer in Jan 2026. Discover how the $33B AI chip boom is rewriting the rules of the silicon industry.
⤷ Title: The Fake Region Block: YouTube’s Cryptic New War on Ad-Blockers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:00:05 +0000
════════════════════════
⌗ Tags: #Technology #Ad Blocker #AdGuard #Anti_Adblock 2026 #google #Reddit Workaround #Tech Frustration #uBlock Origin #Video Unavailable #XHR Filtering #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:00:05 +0000
════════════════════════
⌗ Tags: #Technology #Ad Blocker #AdGuard #Anti_Adblock 2026 #google #Reddit Workaround #Tech Frustration #uBlock Origin #Video Unavailable #XHR Filtering #youtube
Daily CyberSecurity
The Fake Region Block: YouTube’s Cryptic New War on Ad-Blockers
YouTube is faking regional blocks to break ad-blockers in Jan 2026! Discover the "technical frustration" strategy behind the new "unavailable" errors.