⤷ Title: NATS Server Vulnerability: Missing Access Controls in JetStream API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:46:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Access Control #API security #CVE_2025_30215 #JetStream #NATS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:46:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Access Control #API security #CVE_2025_30215 #JetStream #NATS
Daily CyberSecurity
NATS Server Vulnerability: Missing Access Controls in JetStream API
A security vulnerability (CVE-2025-30215) in NATS Server allows unauthorized actions on JetStream assets due to missing access controls.
⤷ Title: Critical SSRF Vulnerability Patched in LNbits Lightning Wallet Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:40:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitcoin #Cryptocurrency Security #CVE_2025_32013 #cybersecurity #Lightning Network #LNbits #LNURL #Server_Side Request Forgery #ssrf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:40:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitcoin #Cryptocurrency Security #CVE_2025_32013 #cybersecurity #Lightning Network #LNbits #LNURL #Server_Side Request Forgery #ssrf
Daily CyberSecurity
Critical SSRF Vulnerability Patched in LNbits Lightning Wallet Server
A critical SSRF vulnerability (CVE-2025-32013) has been patched in LNbits, the Lightning Network wallet server. Learn how attackers could exploit LNURL authentication to access internal services and how to protect your systems.
⤷ Title: Spyware Alert: BADBAZAAR and MOONSHINE Target Civil Society and Ethnic Groups
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:34:43 +0000
════════════════════════
⌗ Tags: #Malware #BADBAZAAR #China APTs #mobile security #MOONSHINE #NCSC UK #spyware #Taiwanese #targeted surveillance #Tibetan #Uyghur
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:34:43 +0000
════════════════════════
⌗ Tags: #Malware #BADBAZAAR #China APTs #mobile security #MOONSHINE #NCSC UK #spyware #Taiwanese #targeted surveillance #Tibetan #Uyghur
Daily CyberSecurity
Spyware Alert: BADBAZAAR and MOONSHINE Target Civil Society and Ethnic Groups
The NCSC UK warns of BADBAZAAR and MOONSHINE spyware targeting Uyghur, Tibetan, and Taiwanese individuals. These sophisticated trojans collect sensitive data via fake apps. Learn how to protect your devices.
⤷ Title: High-Severity XXE Vulnerability Found in NAKIVO Backup & Replication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:21:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #Backup and Recovery #CVE_2025_32406 #cybersecurity #Data Protection #NAKIVO #XXE Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:21:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #Backup and Recovery #CVE_2025_32406 #cybersecurity #Data Protection #NAKIVO #XXE Vulnerability
Daily CyberSecurity
High-Severity XXE Vulnerability Found in NAKIVO Backup & Replication
A high-severity XXE vulnerability (CVE-2025-32406) has been discovered in NAKIVO Backup & Replication, allowing potential unauthorized access to sensitive data. Users are urged to upgrade to the latest version.
⤷ Title: “Pick Your Poison” Phishing Attack: Credentials or Malware?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:18:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Cofense #Credential Phishing #cybersecurity #Email Security #Files.fm #malware #phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:18:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Cofense #Credential Phishing #cybersecurity #Email Security #Files.fm #malware #phishing
Daily CyberSecurity
"Pick Your Poison" Phishing Attack: Credentials or Malware?
A new "Pick Your Poison" phishing campaign tricks users into choosing between having their credentials stolen or infecting their systems with malware. Cofense analysis reveals how this double-edged attack uses files.fm to deliver malicious payloads.
⤷ Title: Evolving Cybercrime: Inside the Russian-Speaking Underground
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber_physical crime #Cybercrime #Cybercriminal underground #phishing #ransomware #Russian cybercrime #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber_physical crime #Cybercrime #Cybercriminal underground #phishing #ransomware #Russian cybercrime #Web3 security
Daily CyberSecurity
Evolving Cybercrime: Inside the Russian-Speaking Underground
A Trend Micro report explores the evolving tactics of the Russian-speaking cybercriminal underground, including phishing innovations, Web3 scams, the role of ransomware, and the convergence of cyber and physical crime
⤷ Title: Tool Poisoning Attacks: Critical Vulnerability Discovered in Model Context Protocol (MCP)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:05:27 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agents #AI security #AI vulnerability #artificial intelligence #cybersecurity #Invariant Labs #MCP (Model Context Protocol) #Tool Poisoning Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:05:27 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agents #AI security #AI vulnerability #artificial intelligence #cybersecurity #Invariant Labs #MCP (Model Context Protocol) #Tool Poisoning Attack
Daily CyberSecurity
Tool Poisoning Attacks: Critical Vulnerability Discovered in Model Context Protocol (MCP)
Invariant Labs reveals a critical vulnerability in the Model Context Protocol (MCP) enabling Tool Poisoning Attacks. Learn how this threat can lead to data exfiltration and AI hijacking
⤷ Title: A must-use tool for subdomain enumeration.
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:42:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #ethical_hacking #tips #bug_bounty_tips
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:42:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #ethical_hacking #tips #bug_bounty_tips
Medium
A must-use tool for subdomain enumeration.
One of the most underrated tools for subdomain finding.
⤷ Title: How I Found a WordPress Database Setup via Shodan (HackerOne)
════════════════════════
𐀪 Author: Enterlectury
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:33:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #web_security #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Enterlectury
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:33:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #web_security #bug_bounty_writeup #bug_bounty
Medium
How I Found a WordPress Database Setup via Shodan (HackerOne)
Hey everyone, My name is Aditya, also known as Enterlectury. I’m a BCA student, and in my free time, I work on improving my bug hunting…
⤷ Title: CyberSecurity Career Launchpad
════════════════════════
𐀪 Author: Mohamedashmar
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:59:41 GMT
════════════════════════
⌗ Tags: #careers #career_advice #information_technology #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Mohamedashmar
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:59:41 GMT
════════════════════════
⌗ Tags: #careers #career_advice #information_technology #cybersecurity #cyber_security_awareness
Medium
CyberSecurity Career Launchpad
Understand CyberSecurity domains:
⤷ Title: An Industry Interview Study of Software Signing for Supply Chain Security
════════════════════════
𐀪 Author: James Davis
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:48:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #science #software_development #security #software_engineering
════════════════════════
𐀪 Author: James Davis
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:48:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #science #software_development #security #software_engineering
Medium
An Industry Interview Study of Software Signing for Supply Chain Security
This is a brief for the research paper “An Industry Interview Study of Software Signing for Supply Chain Security”, at USENIX Security…
⤷ Title: Exploring the Dark Web: Myths vs. Reality
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:47:26 GMT
════════════════════════
⌗ Tags: #software_engineering #cybersecurity #openexploit #programming #technology
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:47:26 GMT
════════════════════════
⌗ Tags: #software_engineering #cybersecurity #openexploit #programming #technology
Medium
Exploring the Dark Web: Myths vs. Reality
When one hears the phrase “dark web”, it usually evokes visions of illicit transactions, hoodie-wearing hackers, and clandestine…
⤷ Title: WhiteRabbitNeo Takes on RSAC 2025
════════════════════════
𐀪 Author: WhiteRabbitNeo
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:34:17 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #rsa_conference #artificial_intelligence #ai
════════════════════════
𐀪 Author: WhiteRabbitNeo
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:34:17 GMT
════════════════════════
⌗ Tags: #devsecops #cybersecurity #rsa_conference #artificial_intelligence #ai
Medium
WhiteRabbitNeo Takes on RSAC 2025
WhiteRabbitNeo is going to RSAC! Come meet our team at one of the many events we are hosting both inside and outside the Moscone Center
⤷ Title: Understanding Keystore vs Truststore
════════════════════════
𐀪 Author: Mahabir Mohapatra
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:09:12 GMT
════════════════════════
⌗ Tags: #tls_certificate #ssl #ssl_certificate #tls #cybersecurity
════════════════════════
𐀪 Author: Mahabir Mohapatra
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:09:12 GMT
════════════════════════
⌗ Tags: #tls_certificate #ssl #ssl_certificate #tls #cybersecurity
Medium
Understanding Keystore vs Truststore
🛡️ Truststore
⤷ Title: Create Your Own Network Exploitation Multitool: A Step-by-Step Guide (Part 2)
════════════════════════
𐀪 Author: Agneya Tharun
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:44:37 GMT
════════════════════════
⌗ Tags: #networking #security #cybersecurity #penetration_testing #android
════════════════════════
𐀪 Author: Agneya Tharun
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:44:37 GMT
════════════════════════
⌗ Tags: #networking #security #cybersecurity #penetration_testing #android
Medium
Create Your Own Network Exploitation Multitool: A Step-by-Step Guide (Part 2)
This guide will focus on developing a tool that can interfere with devices on a network — specifically intercepting data. This part (Part…
⤷ Title: NHL Teams Up with Palo Alto Networks to Boost Cybersecurity
════════════════════════
𐀪 Author: SafetyDetectives Research Team
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:44:26 GMT
════════════════════════
⌗ Tags: #nhl #cybersecurity #security
════════════════════════
𐀪 Author: SafetyDetectives Research Team
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:44:26 GMT
════════════════════════
⌗ Tags: #nhl #cybersecurity #security
Medium
NHL Teams Up with Palo Alto Networks to Boost Cybersecurity
The NHL has signed a new multi-year partnership with cybersecurity company Palo Alto Networks to enhance protection across the league…
⤷ Title: Oracle Discloses Second Hack
════════════════════════
𐀪 Author: SafetyDetectives Research Team
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:44:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #oracle #data_breach
════════════════════════
𐀪 Author: SafetyDetectives Research Team
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:44:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #oracle #data_breach
Medium
Oracle Discloses Second Hack
Oracle has suffered its second reported security breach in a month, with a hacker accessing a legacy system and stealing outdated client…
⤷ Title: Mastering SOC Alert Tuning and False Positive Reduction
════════════════════════
𐀪 Author: Bl@ckC!pH3r
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:36:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #soc
════════════════════════
𐀪 Author: Bl@ckC!pH3r
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:36:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #soc
Medium
Mastering SOC Alert Tuning and False Positive Reduction
Photo by CDC on Unsplash
⤷ Title: Introduction: The Hidden Cost of Skipping Security Testing
════════════════════════
𐀪 Author: Gil Vidals
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:43:11 GMT
════════════════════════
⌗ Tags: #hipaa_compliance #penetration_testing #pentest
════════════════════════
𐀪 Author: Gil Vidals
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 01:43:11 GMT
════════════════════════
⌗ Tags: #hipaa_compliance #penetration_testing #pentest
Medium
Penetration Testing for HIPAA Compliance: How to Prepare and Why It Matters
Healthcare data breaches continue to rise in frequency and severity. According to IBM’s 2023 Cost of a Data Breach report, the average…
⤷ Title: Host & Network Penetration Testing: Network-Based Attacks CTF 1
════════════════════════
𐀪 Author: Oluwaseun Adebayo
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:53:59 GMT
════════════════════════
⌗ Tags: #penetration_testing #ctf_writeup #wireshark #ine
════════════════════════
𐀪 Author: Oluwaseun Adebayo
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:53:59 GMT
════════════════════════
⌗ Tags: #penetration_testing #ctf_writeup #wireshark #ine
Medium
Host & Network Penetration Testing: Network-Based Attacks CTF 1
Host & Network Penetration Testing: Network-Based Attacks CTF 1
⤷ Title: Compromised Windows Analysis: TryHackMe Answers
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:36:54 GMT
════════════════════════
⌗ Tags: #windows #tryhackme #windows_forensics #windows_analysis_thm #tryhackme_writeup
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 00:36:54 GMT
════════════════════════
⌗ Tags: #windows #tryhackme #windows_forensics #windows_analysis_thm #tryhackme_writeup
Medium
Compromised Windows Analysis: TryHackMe Answers
Task 1: Introduction