⤷ Title: Java Deserialization Vulnerability, CVE-2015–7501 . Tony the Tiger: TryHackMe Walkthrough
════════════════════════
𐀪 Author: RosanaFSS
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 21:56:31 GMT
════════════════════════
⌗ Tags: #information_technology #cybersecurity #penetration_testing #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: RosanaFSS
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 21:56:31 GMT
════════════════════════
⌗ Tags: #information_technology #cybersecurity #penetration_testing #tryhackme #tryhackme_walkthrough
Medium
Java Deserialization Vulnerability, CVE-2015–7501 . Tony the Tiger: TryHackMe Walkthrough
Learn how to use a Java Serialisation attack in this boot-to-root. Practice Linux, SHELL=/bin/bash script -q /dev/null, find / -type f…
⤷ Title: CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:17:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_43468 #Microsoft Configuration Manager
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:17:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_43468 #Microsoft Configuration Manager
Daily CyberSecurity
CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code
Discover the technical details and PoC of CVE-2024-43468, a critical vulnerability in Microsoft Configuration Manager. Learn how attackers can exploit SQL injection vulnerabilities.
⤷ Title: CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_21535 #Oracle #Oracle WebLogic Server #WebLogic Server
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_21535 #Oracle #Oracle WebLogic Server #WebLogic Server
Cybersecurity News
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
Learn about the potential risks of the CVE-2025-21535 vulnerability in WebLogic Server. Stay protected from unauthenticated remote attacks that could exploit this critical flaw.
⤷ Title: Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:12:42 +0000
════════════════════════
⌗ Tags: #Malware #AWS #chrome #Chrome Cookies #github #VS Code Marketplace #Zoom’s Meeting SDK
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:12:42 +0000
════════════════════════
⌗ Tags: #Malware #AWS #chrome #Chrome Cookies #github #VS Code Marketplace #Zoom’s Meeting SDK
Cybersecurity News
Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies
Beware of a malicious VS Code extension impersonating the Zoom Workspace tool. Learn how this deceptive extension targets software developers and steals sensitive data.
⤷ Title: CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:09:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_43707 #CVE_2024_43710 #Kibana
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:09:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_43707 #CVE_2024_43710 #Kibana
Daily CyberSecurity
CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information
Take action to secure your Elastic Agent policies. Discover how the high severity vulnerability CVE-2024-43707 could compromise sensitive information in Kibana.
⤷ Title: Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:06:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #AT&T #Comcast Infinity #Credential Harvesting #Docusign #Gravatar #Microsoft #ProtonMail
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:06:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #AT&T #Comcast Infinity #Credential Harvesting #Docusign #Gravatar #Microsoft #ProtonMail
Daily CyberSecurity
Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps
Discover the latest trends in credential harvesting and how attackers are targeting a wider range of cloud applications beyond well-known platforms.
⤷ Title: Donot APT Group Targets Android Devices with Malicious Chat Apps
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:00:56 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #DONOT APT group #OneSignal
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:00:56 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #DONOT APT group #OneSignal
Cybersecurity News
Donot APT Group Targets Android Devices with Malicious Chat Apps
Uncover the alarming Android malware campaign attributed to the Indian APT group DONOT. Learn how this group targets individuals and organizations for strategic intelligence collection.
⤷ Title: 2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:55:26 +0000
════════════════════════
⌗ Tags: #Cyber Security #Adobe Commerce #Check Fraud #CosmicSting #CVE_2024_34102 #Dark Web Market #E_Skimming #Magento #Payment Fraud Report
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:55:26 +0000
════════════════════════
⌗ Tags: #Cyber Security #Adobe Commerce #Check Fraud #CosmicSting #CVE_2024_34102 #Dark Web Market #E_Skimming #Magento #Payment Fraud Report
Cybersecurity News
2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar
Stay informed about the latest payment fraud trends and threats. Learn about the increase in Magecart e-skimmer infections and check fraud in our comprehensive report.
⤷ Title: phpMyAdmin Patches XSS Vulnerabilities in Latest Release
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:50:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_2961 #CVE_2025_24529 #CVE_2025_24530 #phpmyadmin
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:50:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_2961 #CVE_2025_24529 #CVE_2025_24530 #phpmyadmin
Cybersecurity News
phpMyAdmin Patches XSS Vulnerabilities in Latest Release
Learn about the recent XSS vulnerabilities in phpMyAdmin and how the latest release version 5.2.2 provides patches to address these security risks.
⤷ Title: CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:41:53 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CVE_2017_17215 #CVE_2024_7029 #Mirai malware #Murdoc Botnet
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:41:53 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CVE_2017_17215 #CVE_2024_7029 #Mirai malware #Murdoc Botnet
Daily CyberSecurity
CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks
The Qualys Threat Research Unit has unveiled an extensive campaign involving a new variant of the infamous Mirai malware, dubbed the “Murdoc Botnet.” This variant targets AVTECH camera…
👍1
⤷ Title: Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:37:44 +0000
════════════════════════
⌗ Tags: #Malware #Abyss Locker #Abyss Locker ransomware #ESXi Ransomware Attack #SSH tunneling
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:37:44 +0000
════════════════════════
⌗ Tags: #Malware #Abyss Locker #Abyss Locker ransomware #ESXi Ransomware Attack #SSH tunneling
Cybersecurity News
Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi
Stay informed about the latest tactics used in ESXi ransomware attacks. Learn how attackers exploit virtualized infrastructure components to disrupt operations.
⤷ Title: STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:33:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Black Basta ransomware #Carbon Spider #Email Bombing #FIN7 #Microsoft Quick Assist #Sangria Tempest #STAC5143 #STAC5777 #Storm_1811 #Teams #Teams Vishing
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 01:33:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Black Basta ransomware #Carbon Spider #Email Bombing #FIN7 #Microsoft Quick Assist #Sangria Tempest #STAC5143 #STAC5777 #Storm_1811 #Teams #Teams Vishing
Cybersecurity News
STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users
Sophos X-Ops uncovers ransomware campaigns STAC5143 and STAC5777 targeting Microsoft Office 365 and Teams. Learn how these campaigns exploit email bombing and vishing techniques.
⤷ Title: CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 07:23:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_23006 #SMA1000 #SonicWall
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 07:23:45 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_23006 #SMA1000 #SonicWall
Daily CyberSecurity
CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users
SonicWall warns of critical vulnerability CVE-2025-23006 in SMA1000 AMC and CMC. Attackers can exploit this pre-authentication remote command execution flaw.
⤷ Title: CVE-2025-0314: GitLab Releases Patch for XSS Exploit
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 07:13:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_11931 #CVE_2024_6324 #CVE_2025_0314 #gitlab
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 07:13:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_11931 #CVE_2024_6324 #CVE_2025_0314 #gitlab
Daily CyberSecurity
CVE-2025-0314: GitLab Releases Patch for XSS Exploit
GitLab security update: Addressing multiple vulnerabilities, including the high severity cross-site scripting flaw (CVE-2025-0314). Stay protected!
⤷ Title: CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 02:58:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_8190 #CVE_2024_8963 #CVE_2024_9379 #CVE_2024_9380 #Ivanti CSA
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 02:58:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2024_8190 #CVE_2024_8963 #CVE_2024_9379 #CVE_2024_9380 #Ivanti CSA
Daily CyberSecurity
CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory
Stay protected from Ivanti CSA vulnerabilities. Learn about the risks and exploits associated with CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, and CVE-2024-9380.
⤷ Title: CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 02:44:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #cisco #Cisco Meeting Management #CVE_2025_20156 #Meeting Management
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 02:44:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #cisco #Cisco Meeting Management #CVE_2025_20156 #Meeting Management
Cybersecurity News
CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation
Cisco has issued a security advisory addressing a critical privilege escalation vulnerability (CVE-2025-20156) in its Meeting Management software
⤷ Title: 10 Cybersecurity Predictions for 2025
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:27:53 GMT
════════════════════════
⌗ Tags: #infosec #artificial_intelligence #social_engineering #hacking #cybersecurity
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:27:53 GMT
════════════════════════
⌗ Tags: #infosec #artificial_intelligence #social_engineering #hacking #cybersecurity
Medium
10 Cybersecurity Predictions for 2025
Every year I trudge into the analysis and release my #cybersecurity predictions. Here is a quick infographic of the top 10 for 2025. Read…
⤷ Title: Scam Yourself attacks: How social engineering is evolving
════════════════════════
𐀪 Author: Josh Taylor
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:21:52 GMT
════════════════════════
⌗ Tags: #cyber #hacking #cybersecurity #business #security
════════════════════════
𐀪 Author: Josh Taylor
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 02:21:52 GMT
════════════════════════
⌗ Tags: #cyber #hacking #cybersecurity #business #security
Medium
Scam Yourself attacks: How social engineering is evolving
We’ve entered a new era where verification must come before trust, and for good reason. Cyber threats are evolving rapidly, and one of the…
⤷ Title: Cybersecurity Architecture: Server Threat modeling : a Compass model
════════════════════════
𐀪 Author: Ivan Fedorets
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 03:42:00 GMT
════════════════════════
⌗ Tags: #breach_modeling #cybersecurity #security_control #host_based_security #threat_modeling
════════════════════════
𐀪 Author: Ivan Fedorets
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 03:42:00 GMT
════════════════════════
⌗ Tags: #breach_modeling #cybersecurity #security_control #host_based_security #threat_modeling
Medium
Cybersecurity Architecture: Server Threat modeling : a Compass model
An easy to remember visual threat modeling approach for servers
⤷ Title: DNS Misconfigurations and Security Risks
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 03:25:33 GMT
════════════════════════
⌗ Tags: #information_technology #botnet #cybersecurity #dns #misconfiguration
════════════════════════
𐀪 Author: Paritosh
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 03:25:33 GMT
════════════════════════
⌗ Tags: #information_technology #botnet #cybersecurity #dns #misconfiguration
Medium
DNS Misconfigurations and Security Risks
A small misstep can lead to significant consequences. One area where this is especially true is the Domain Name System (DNS). DNS acts as…
⤷ Title: Google Chrome Security alert: 3 billion users must take action now
════════════════════════
𐀪 Author: Borderless CS
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 03:11:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #it_consulting_services
════════════════════════
𐀪 Author: Borderless CS
════════════════════════
ⴵ Time: Fri, 24 Jan 2025 03:11:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #it_consulting_services
Medium
Google Chrome Security alert: 3 billion users must take action now
Google Chrome Security: In today’s fast-paced digital world, your web browser is your gateway to the internet. For over 3 billion users…