⤷ Title: PoC Released for Unpatch OnePlus Flaw: Any App Can Read Your SMS Messages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:54:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_10184 #mobile security #OnePlus #OxygenOS #Rapid7 #SMS Leak #SQL injection #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:54:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_10184 #mobile security #OnePlus #OxygenOS #Rapid7 #SMS Leak #SQL injection #zero_day
Penetration Testing Tools
PoC Released for Unpatch OnePlus Flaw: Any App Can Read Your SMS Messages
A critical flaw (CVE-2025-10184) in OnePlus OxygenOS allows any app to read users’ SMS/MMS data without permission. The PoC is public, but a fix is unavailable.Export to Sheets
⤷ Title: Rapid7 Details Cisco ASA Zero-Day Exploit Chain (CVE-2025-20362 & CVE-2025-20333)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #buffer overflow #cisco #CVE_2025_20333 #FTD #Rapid7 #rce #WebVPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #buffer overflow #cisco #CVE_2025_20333 #FTD #Rapid7 #rce #WebVPN
Daily CyberSecurity
Rapid7 Details Cisco ASA Zero-Day Exploit Chain (CVE-2025-20362 & CVE-2025-20333)
Rapid7 exposed the unauthenticated RCE chain in Cisco ASA/FTD. CVE-2025-20362 bypasses auth to reach CVE-2025-20333, a buffer overflow in the WebVPN Lua script. Patch immediately.
⤷ Title: ZERO-DAY ATTACK WARNING: Fortinet FortiWeb Exploit Grants Unauthenticated Admin Access!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 14 Nov 2025 02:53:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #Defused #FortiWeb #Rapid7 #unauthenticated RCE #waf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 14 Nov 2025 02:53:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #Defused #FortiWeb #Rapid7 #unauthenticated RCE #waf
Daily CyberSecurity
ZERO-DAY ATTACK WARNING: Fortinet FortiWeb Exploit Grants Unauthenticated Admin Access!
Cybersecurity firms are sounding the alarm over a critical vulnerability in Fortinet FortiWeb, the company’s Web Application Firewall (WAF) product. The flaw, which has been observed activel…
⤷ Title: Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:14:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13315 #CVE_2025_13316 #IoT security #Media Server #Rapid7 #Twonky Server #Unpatched Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:14:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13315 #CVE_2025_13316 #IoT security #Media Server #Rapid7 #Twonky Server #Unpatched Vulnerability #zero_day
Daily CyberSecurity
Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
Critical alert: Twonky Server suffers unpatched flaws (CVE-2025-13315/16) allowing full takeover. Vendor has no fix; isolate your server immediately.
⤷ Title: SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:37:43 +0000
════════════════════════
⌗ Tags: #Malware #BluelineStealer #C Polymorphic #credentials #dark web #information stealer #MaaS #Rapid7 #SantaStealer
Daily CyberSecurity
SantaStealer Unwrapped: New MaaS Info-Stealer Rebrands Blueline to Steal Crypto and Credentials
SantaStealer, a new MaaS info-stealer, is being aggressively marketed on the dark web. It's a BluelineStealer rebrand that uses C code and open-source libraries to steal crypto wallets and credentials, despite having amateur anti-analysis features.
⤷ Title: Naughty List: SantaStealer Malware Unwrapped—The “New” Holiday Threat is Just Rebranded Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:29:11 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #BluelineStealer #Chrome Security #Cybersecurity 2025 #Data Theft #Infostealer #Malware_as_a_Service #phishing #Rapid7 #SantaStealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:29:11 +0000
════════════════════════
⌗ Tags: #Malware #App_Bound Encryption #BluelineStealer #Chrome Security #Cybersecurity 2025 #Data Theft #Infostealer #Malware_as_a_Service #phishing #Rapid7 #SantaStealer
Penetration Testing Tools
Naughty List: SantaStealer Malware Unwrapped—The "New" Holiday Threat is Just Rebranded Code
In the run-up to the New Year holidays, underground marketplaces often see a surge of freshly minted data-stealing
⤷ Title: The “WorkMail Pivot”: Hackers Abuse AWS WorkMail to Bypass SES Sandbox
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 30 Jan 2026 00:09:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amazon SES #AWS #Cloud Security #CloudTrail Blind Spot #Email Security #phishing infrastructure #Rapid7 #SCP #truffleHog #WorkMail
Daily CyberSecurity
The "WorkMail Pivot": Hackers Abuse AWS WorkMail to Bypass SES Sandbox
Attackers are bypassing AWS SES sandbox limits by pivoting to WorkMail. Rapid7 reveals how this abuse creates a blind spot for defenders.
⤷ Title: PoC Public & Exploited: Critical SolarWinds Help Desk Flaw Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 09:31:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2025_40551 #Exploit in the Wild #metasploit #Patch Alert #proof_of_concept #Rapid7 #Remote Code Execution #SolarWinds #Web Help Desk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 09:31:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2025_40551 #Exploit in the Wild #metasploit #Patch Alert #proof_of_concept #Rapid7 #Remote Code Execution #SolarWinds #Web Help Desk
Daily CyberSecurity
PoC Public & Exploited: Critical SolarWinds Help Desk Flaw Exploited in the Wild
⤷ Title: Supply Chain Poison: Lotus Blossom Hits Notepad++ to Deploy “Chrysalis”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 00:32:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Chrysalis #DLL side_loading #Elise #Lotus Blossom #Malware Analysis #Microsoft Warbird #notepad++ #Rapid7 #Spring Dragon #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 00:32:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Chrysalis #DLL side_loading #Elise #Lotus Blossom #Malware Analysis #Microsoft Warbird #notepad++ #Rapid7 #Spring Dragon #supply chain attack
Daily CyberSecurity
Supply Chain Poison: Lotus Blossom Hits Notepad++ to Deploy "Chrysalis"
Lotus Blossom compromises Notepad++ infrastructure to deploy "Chrysalis" malware. Rapid7 reveals the group using Microsoft Warbird to evade detection.
⤷ Title: Surgical Espionage: The “Chrysalis” Backdoor and the 6-Month Hijack of Notepad++
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:54:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Billbug #Bitdefender Submission Wizard #Chrysalis backdoor #Cyber Espionage #DLL side_loading #Lotus Blossom #Notepad++ #NSIS installer #Rapid7 #supply chain attack #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:54:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Billbug #Bitdefender Submission Wizard #Chrysalis backdoor #Cyber Espionage #DLL side_loading #Lotus Blossom #Notepad++ #NSIS installer #Rapid7 #supply chain attack #Tech News 2026
Penetration Testing Tools
Surgical Espionage: The "Chrysalis" Backdoor and the 6-Month Hijack of Notepad++
Cybersecurity researchers persist in their investigation of a sophisticated incursion targeting the ubiquitous text editor Notepad++, which remained