⤷ Title: Zero-Day CLFS Vulnerability (CVE-2025-29824) Exploited in Ransomware Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 10:51:51 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Balloonfly #CLFS #CVE_2025_29824 #cybersecurity #Exploit #Microsoft #Play Ransomware #privilege escalation #ransomware #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 10:51:51 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Balloonfly #CLFS #CVE_2025_29824 #cybersecurity #Exploit #Microsoft #Play Ransomware #privilege escalation #ransomware #zero_day
Daily CyberSecurity
Zero-Day CLFS Vulnerability (CVE-2025-29824) Exploited in Ransomware Attacks
A zero-day privilege escalation vulnerability (CVE-2025-29824) in Microsoft CLFS was exploited by Balloonfly (Play ransomware) before the official patch.
⤷ Title: CISA Warns of Unsophisticated Cyber Actors Targeting U.S. Critical Infrastructure OT Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 07:33:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Critical Infrastructure #Cyber Hygiene #industrial control systems #OT Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 07:33:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Critical Infrastructure #Cyber Hygiene #industrial control systems #OT Security
Daily CyberSecurity
CISA Warns of Unsophisticated Cyber Actors Targeting U.S. Critical Infrastructure OT Systems
CISA warns that basic cyber attacks are targeting ICS/SCADA systems in the U.S. energy and transportation sectors due to poor cyber hygiene and exposed assets.
⤷ Title: Microsoft Unveils Enhanced Windows AI Features for “Copilot+ PC”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:41:59 +0000
════════════════════════
⌗ Tags: #Technology #AI #artificial intelligence #Click to Do #Copilot+ PC #Microsoft #Snapdragon #software update #windows #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:41:59 +0000
════════════════════════
⌗ Tags: #Technology #AI #artificial intelligence #Click to Do #Copilot+ PC #Microsoft #Snapdragon #software update #windows #Windows 11
Daily CyberSecurity
Microsoft Unveils Enhanced Windows AI Features for "Copilot+ PC"
Microsoft announces new AI-powered features for "Copilot+ PC," including natural language settings search and the "Click to Do" function, enhancing Windows 11.
⤷ Title: CVE-2025-25014 (CVSS 9.1): Prototype Pollution in Kibana Opens Door to Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:50:01 +0000
════════════════════════
⌗ Tags: #Penetration Testing #Arbitrary Code Execution #CVE_2025_25014 #Elastic #Kibana #Prototype Pollution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:50:01 +0000
════════════════════════
⌗ Tags: #Penetration Testing #Arbitrary Code Execution #CVE_2025_25014 #Elastic #Kibana #Prototype Pollution #Vulnerability
Daily CyberSecurity
CVE-2025-25014 (CVSS 9.1): Prototype Pollution in Kibana Opens Door to Code Execution
A critical vulnerability in Kibana (CVE-2025-25014) enables arbitrary code execution via prototype pollution. Elastic urges users to patch immediately.
⤷ Title: Botnet Exploits Old GeoVision IoT Devices via CVE-2024-6047 & CVE-2024-11120
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:46:08 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #botnet #CVE_2024_11120 #CVE_2024_6047 #IoT security #Vulnerability Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:46:08 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #botnet #CVE_2024_11120 #CVE_2024_6047 #IoT security #Vulnerability Exploitation
Daily CyberSecurity
Botnet Exploits Old GeoVision IoT Devices via CVE-2024-6047 & CVE-2024-11120
Akamai uncovers active exploitation of retired GeoVision IoT devices via CVE-2024-6047 and CVE-2024-11120 using Mirai-based botnet LZRD.
⤷ Title: CVE-2025-46728: cpp-httplib Vulnerability Exposes Servers to Denial of Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:40:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #C++ vulnerability #cpp_httplib #CVE_2025_46728 #Denial of Service #HTTP chunked encoding #memory exhaustion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:40:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #C++ vulnerability #cpp_httplib #CVE_2025_46728 #Denial of Service #HTTP chunked encoding #memory exhaustion
Daily CyberSecurity
CVE-2025-46728: cpp-httplib Vulnerability Exposes Servers to Denial of Service
CVE-2025-46728 in cpp-httplib allows memory exhaustion via chunked requests. Patch to v0.20.1 to prevent denial-of-service attacks.
⤷ Title: CVE-2025-47241: Critical Whitelist Bypass in Browser Use Exposes Internal Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:35:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agents #ARIMLABS #browser automation #Browser Use #CVE_2025_47241 #internal service exposure #whitelist bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:35:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agents #ARIMLABS #browser automation #Browser Use #CVE_2025_47241 #internal service exposure #whitelist bypass
Daily CyberSecurity
CVE-2025-47241: Critical Whitelist Bypass in Browser Use Exposes Internal Services
CVE-2025-47241 in Browser Use lets attackers bypass whitelists via crafted URLs. Upgrade to v0.1.45 to secure AI-driven browser automation.
⤷ Title: CoGUI Phishing Kit: Advanced Evasion Tactics Target Japan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:27:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CoGUI #Credential Phishing #cyberattack #Email Security #Japan #phishing campaigns #Phishing Kit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:27:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CoGUI #Credential Phishing #cyberattack #Email Security #Japan #phishing campaigns #Phishing Kit
Daily CyberSecurity
CoGUI Phishing Kit: Advanced Evasion Tactics Target Japan
The CoGUI phishing kit uses advanced evasion to target Japan with high-volume campaigns impersonating Amazon, PayPay, and more.
⤷ Title: CVE-2025-24977: Critical RCE Flaw in OpenCTI Platform Exposes Infrastructure to Root-Level Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:24:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_24977 #Cyber Threat Intelligence #OpenCTI #Remote Code Execution #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:24:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_24977 #Cyber Threat Intelligence #OpenCTI #Remote Code Execution #security advisory
Daily CyberSecurity
CVE-2025-24977: Critical RCE Flaw in OpenCTI Platform Exposes Infrastructure to Root-Level Attacks
OpenCTI flaw CVE-2025-24977 allows RCE and secret exposure via webhooks. Patch to v6.4.11 to protect Docker/Kubernetes deployments.
⤷ Title: Scattered Spider (UNC3944) Resurfaces with Ties to DragonForce and RansomHub in Retail Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:22:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DragonForce #Mandiant #RansomHub #ransomware #retail cyberattack #Scattered Spider #social engineering #UNC3944
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:22:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DragonForce #Mandiant #RansomHub #ransomware #retail cyberattack #Scattered Spider #social engineering #UNC3944
Daily CyberSecurity
Scattered Spider (UNC3944) Resurfaces with Ties to DragonForce and RansomHub in Retail Attacks
UNC3944 resurfaces as Scattered Spider, linked to DragonForce and RansomHub in new retail attacks. Mandiant warns of social engineering escalation.
⤷ Title: Gunra Ransomware: New Threat Analysis Reveals Evasion Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:20:29 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Threat #cybersecurity #Cyfirma #data exfiltration #Gunra Ransomware #Malware Analysis #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:20:29 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Threat #cybersecurity #Cyfirma #data exfiltration #Gunra Ransomware #Malware Analysis #ransomware
Daily CyberSecurity
Gunra Ransomware: New Threat Analysis Reveals Evasion Tactics
CYFIRMA's analysis details Gunra Ransomware's sophisticated techniques, including evasion and data exfiltration, impacting global industries.
⤷ Title: Critical AWS Amplify Studio Flaw Allows Code Execution – Update Now!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:15:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #Amplify Studio #AWS Amplify #Code Execution #CVE_2025_4318 #javascript #security #update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:15:48 +0000
════════════════════════
⌗ Tags: #Vulnerability #Amplify Studio #AWS Amplify #Code Execution #CVE_2025_4318 #javascript #security #update
Daily CyberSecurity
Critical AWS Amplify Studio Flaw Allows Code Execution - Update Now!
Critical security vulnerability (CVE-2025-4318) in AWS Amplify Studio allows arbitrary code execution. Upgrade to version 2.20.3 immediately!
⤷ Title: Panda Shop Smishing Syndicate: China-Backed Cybercrime-as-a-Service Hits Millions Globally
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:10:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android RCS #Apple iMessage #carding #China cybercrime #cybercrime_as_a_service #Panda Shop #PII theft #Resecurity #smishing #Telegram fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:10:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android RCS #Apple iMessage #carding #China cybercrime #cybercrime_as_a_service #Panda Shop #PII theft #Resecurity #smishing #Telegram fraud
Daily CyberSecurity
Panda Shop Smishing Syndicate: China-Backed Cybercrime-as-a-Service Hits Millions Globally
Resecurity exposes Panda Shop smishing kit linked to Chinese cybercrime, targeting millions via iMessage and RCS with carding and data theft.
⤷ Title: Critical Open Source Library ‘easyjson’ Linked to Russian VK Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:02:16 +0000
════════════════════════
⌗ Tags: #Cyber Security #easyjson #Hunted Labs #Open Source Security #Russian cyber threat #Software Supply Chain #VK Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 07 May 2025 00:02:16 +0000
════════════════════════
⌗ Tags: #Cyber Security #easyjson #Hunted Labs #Open Source Security #Russian cyber threat #Software Supply Chain #VK Group
Daily CyberSecurity
Critical Open Source Library 'easyjson' Linked to Russian VK Group
Research reveals the widely used open source library 'easyjson' is controlled by developers linked to Russia's VK Group, raising security concerns.
⤷ Title: SysOwned, Your Friendly Support Ticket - SysAid On-Premise Pre-Auth RCE Chain (CVE-2025-2775 And Friends)
════════════════════════
𐀪 Author: Sina Kheirkhah (@SinSinology)
════════════════════════
ⴵ Time: Wed, 07 May 2025 09:38:35 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Sina Kheirkhah (@SinSinology)
════════════════════════
ⴵ Time: Wed, 07 May 2025 09:38:35 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
SysOwned, Your Friendly Support Ticket - SysAid On-Premise Pre-Auth RCE Chain (CVE-2025-2775 And Friends)
It’s… another week, and another vendor who is apparently experienced with ransomware gangs but yet struggles with email.
In what we've seen others term "the watchTowr treatment", we are once again (surprise, surprise) disclosing vulnerability research that…
In what we've seen others term "the watchTowr treatment", we are once again (surprise, surprise) disclosing vulnerability research that…
⤷ Title: How to setup a Monthly Free VPS for Bug Hunting
════════════════════════
𐀪 Author: Mostafa Alrefai
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:50:19 GMT
════════════════════════
⌗ Tags: #bug_bounty #github #cybersecurity #penetration_testing #hacking
════════════════════════
𐀪 Author: Mostafa Alrefai
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:50:19 GMT
════════════════════════
⌗ Tags: #bug_bounty #github #cybersecurity #penetration_testing #hacking
Medium
How to setup a Monthly Free VPS for Bug Hunting
In this article, I explained how to setup and use (GitHub CodeSpaces) for bug hunting
⤷ Title: Revisiting the Past, Hacking the Future
════════════════════════
𐀪 Author: SIDDHANT SHUKLA
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:48:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #programming #hacking #technology
════════════════════════
𐀪 Author: SIDDHANT SHUKLA
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:48:54 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #programming #hacking #technology
Medium
Revisiting the Past, Hacking the Future
From Invalid Reports to Real Vulnerabilities: The Path to Growth in Hacking
⤷ Title: Hacking the Frontend Logic: Exploiting JavaScript Business Flaws
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:45:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #infosec #programming #bug_bounty
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:45:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #infosec #programming #bug_bounty
Medium
Hacking the Frontend Logic: Exploiting JavaScript Business Flaws 💼
Hacking the Frontend Logic: Exploiting JavaScript Business Flaws 💼
⤷ Title: A Must-Have Tool for Bug Hunters: Find Open Redirect Vulnerabilities on Linux
════════════════════════
𐀪 Author: Elie Attieh
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:43:51 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #bug_bounty #pentesting #ethical_hacking
════════════════════════
𐀪 Author: Elie Attieh
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:43:51 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #bug_bounty #pentesting #ethical_hacking
Medium
A Must-Have Tool for Bug Hunters: Find Open Redirect Vulnerabilities on Linux
Automate open redirection detection, save hours of manual testing, and level up your bug bounty recon game.
⤷ Title: Exploiting a Referer Header for Open Redirect
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:43:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #open_redirect #infosec #rewards #bug_bounty
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:43:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #open_redirect #infosec #rewards #bug_bounty
Medium
Exploiting a Referer Header for Open Redirect
Today, I’m excited to share how I found an open redirect vulnerability by manipulating the Referer header on a bug bounty program. In this article, I’ll walk you through: An open redirect happens…
⤷ Title: 2FA Bypass: A Case of Insecure Implementation
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:42:57 GMT
════════════════════════
⌗ Tags: #2fa_authentication #ethical_hacking #bug_bounty #penetration_testing #infosec
════════════════════════
𐀪 Author: Ehtesham Ul Haq
════════════════════════
ⴵ Time: Wed, 07 May 2025 06:42:57 GMT
════════════════════════
⌗ Tags: #2fa_authentication #ethical_hacking #bug_bounty #penetration_testing #infosec
Medium
2FA Bypass: A Case of Insecure Implementation
Two-factor authentication (2FA) is widely seen as one of the best ways to secure user accounts. Whether it’s through SMS codes, authenticator apps, or hardware tokens, 2FA is meant to protect users…