⤷ Title: Hack The Box | Devvortex
════════════════════════
𐀪 Author: Luigi Carpio (0xBahalaNa)
════════════════════════
ⴵ Time: Tue, 13 May 2025 23:03:20 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #cybersecurity #information_security #hackthebox_writeup #hackthebox
════════════════════════
𐀪 Author: Luigi Carpio (0xBahalaNa)
════════════════════════
ⴵ Time: Tue, 13 May 2025 23:03:20 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #cybersecurity #information_security #hackthebox_writeup #hackthebox
Medium
Hack The Box | Devvortex
Released 11/25/2023 (Retired)
⤷ Title: meerkat — a scuffed writeup + update
════════════════════════
𐀪 Author: nubb
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:55:49 GMT
════════════════════════
⌗ Tags: #dfir #hackthebox #blue_team #writeup #cybersecurity
════════════════════════
𐀪 Author: nubb
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:55:49 GMT
════════════════════════
⌗ Tags: #dfir #hackthebox #blue_team #writeup #cybersecurity
Medium
meerkat — a scuffed writeup + update
Hello again, Medium. It’s been quite some time since I last appeared on this platform — 10 months of radio silence. During those ten…
⤷ Title: Post India-Pakistan Conflict: India’s Digital Retaliation — Tariffs, Tech, and a Wake-Up Call for…
════════════════════════
𐀪 Author: Everclear International
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:49:47 GMT
════════════════════════
⌗ Tags: #usa #economics #india #technology #cybersecurity
════════════════════════
𐀪 Author: Everclear International
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:49:47 GMT
════════════════════════
⌗ Tags: #usa #economics #india #technology #cybersecurity
Medium
Post India-Pakistan Conflict: India’s Digital Retaliation — Tariffs, Tech, and a Wake-Up Call for the U.S.
By Everclear, Medium Contributor on Geopolitics, Cybersecurity & Emerging Technology
⤷ Title: Ultra-Fast DevSecOps Scanners
════════════════════════
𐀪 Author: AquilaX AI
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #security #devsecops
════════════════════════
𐀪 Author: AquilaX AI
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #security #devsecops
Medium
Ultra-Fast DevSecOps Scanners
Why scan speed matters in modern CI/CD pipelines
⤷ Title: UnderPass (Write-Up) — Hack The Box
════════════════════════
𐀪 Author: Ross Mitchell
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:04 GMT
════════════════════════
⌗ Tags: #htb #penetration_testing #ethical_hacking #hack_the_box_writeup #hack_the_box_walkthrough
════════════════════════
𐀪 Author: Ross Mitchell
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:04 GMT
════════════════════════
⌗ Tags: #htb #penetration_testing #ethical_hacking #hack_the_box_writeup #hack_the_box_walkthrough
Medium
UnderPass (Write-Up) — Hack The Box
UnderPass is a Linux box which contains information disclosure within SNMP utilising default community strings, which can be used to…
⤷ Title: Writing Pentest Reports: TryHackMe Answers with Explanation
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Tue, 13 May 2025 23:12:15 GMT
════════════════════════
⌗ Tags: #pentest_reporting #writing_pentest_reports #tryhackme_writeup #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Tue, 13 May 2025 23:12:15 GMT
════════════════════════
⌗ Tags: #pentest_reporting #writing_pentest_reports #tryhackme_writeup #tryhackme #tryhackme_walkthrough
Medium
Writing Pentest Reports: TryHackMe Answers with Explanation
Learn how to write professional pentesting reports that communicate risk to business stakeholders.
⤷ Title: 3. X86 Assembly Basics
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:32:26 GMT
════════════════════════
⌗ Tags: #miss_robot #static_analysis #tryhackme #dynamic_analysis #malware_analysis
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:32:26 GMT
════════════════════════
⌗ Tags: #miss_robot #static_analysis #tryhackme #dynamic_analysis #malware_analysis
Medium
X86 Assembly Basics
x86 architecture | Malware Analysis
⤷ Title: AIGoat: A deliberately Vulnerable AI Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:30:36 +0000
════════════════════════
⌗ Tags: #Arsenal Lab #Vulnerability Assessment #AIGoat #Vulnerable AI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:30:36 +0000
════════════════════════
⌗ Tags: #Arsenal Lab #Vulnerability Assessment #AIGoat #Vulnerable AI
Penetration Testing Tools
AIGoat: A deliberately Vulnerable AI Infrastructure
AI-Goat is a deliberately vulnerable AI infrastructure hosted on AWS, designed to simulate the OWASP Machine Learning Security Top 10 risks
⤷ Title: dummy: Generator of static files for testing file upload
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec #dummy #testing file upload
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec #dummy #testing file upload
Penetration Testing Tools
dummy: Generator of static files for testing file upload
Generator of static files for testing file upload functionality. When generating a png, as in the screenshot, you can generate a png of a specified size.
⤷ Title: CVSS 10.0 Flaws in Siemens OZW Web Servers Enable Unauthenticated RCE and Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:00:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #building automation #CVE_2025_26389 #CVE_2025_26390 #CVSS 10.0 #cybersecurity #ICS security #OZW672 #OZW772 #Remote Code Execution #Siemens #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:00:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #building automation #CVE_2025_26389 #CVE_2025_26390 #CVSS 10.0 #cybersecurity #ICS security #OZW672 #OZW772 #Remote Code Execution #Siemens #sql injection
Daily CyberSecurity
CVSS 10.0 Flaws in Siemens OZW Web Servers Enable Unauthenticated RCE and Admin Access
CVEs 2025-26389 and 2025-26390 let attackers run code as root or gain admin access on Siemens OZW web servers. Patching is strongly advised.
⤷ Title: Ivanti Neurons for ITSM Hit by CVSS 9.8 Authentication Bypass Flaw Enabling Full Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:55:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #admin access #Authentication Bypass #Critical Vulnerability #CVE_2025_22462 #CVSS 9.8 #Ivanti #Neurons for ITSM #on_prem ITSM #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:55:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #admin access #Authentication Bypass #Critical Vulnerability #CVE_2025_22462 #CVSS 9.8 #Ivanti #Neurons for ITSM #on_prem ITSM #security advisory
Daily CyberSecurity
Ivanti Neurons for ITSM Hit by CVSS 9.8 Authentication Bypass Flaw Enabling Full Admin Access
Ivanti patches CVE-2025-22462, a critical CVSS 9.8 auth bypass flaw in Neurons for ITSM. Risk of full admin access. Patch or restrict IIS access now.
⤷ Title: Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
Daily CyberSecurity
Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
Varnish Cache and Enterprise have a vulnerability allowing HTTP request smuggling. This can lead to cache poisoning and WAF bypass. Upgrade now!
⤷ Title: Zoom Patches High-Severity Flaw (CVE-2025-30663) in Workplace Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:49:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #buffer over_read #CVE_2025_30663 #CVSS 8.8 #cybersecurity #Denial of Service #NULL pointer #privilege escalation #security #security update #update #Workplace Apps #Zoom #Zoom patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:49:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #buffer over_read #CVE_2025_30663 #CVSS 8.8 #cybersecurity #Denial of Service #NULL pointer #privilege escalation #security #security update #update #Workplace Apps #Zoom #Zoom patch
Daily CyberSecurity
Zoom Patches High-Severity Flaw (CVE-2025-30663) in Workplace Apps
Zoom fixes critical CVE-2025-30663 flaw allowing local privilege escalation. Users urged to update Workplace apps and SDKs to version 6.4.0 or newer.
⤷ Title: Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
Daily CyberSecurity
Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
Bitnami Pgpool flaw (CVE-2025-22248) exposes PostgreSQL to unauthenticated access. Update to Pgpool 4.6.0-1 or Helm chart 16.0.0 to fix.
⤷ Title: TA406 Cyber Campaign: North Korea’s Focus on Ukraine Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #geopolitics #intelligence gathering #malware #North Korea #phishing #Proofpoint #TA406 #threat actor #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #geopolitics #intelligence gathering #malware #North Korea #phishing #Proofpoint #TA406 #threat actor #Ukraine
Daily CyberSecurity
TA406 Cyber Campaign: North Korea's Focus on Ukraine Intelligence
North Korean threat actor TA406 intensifies cyber espionage against Ukraine, using phishing and malware to gather political intelligence.
⤷ Title: Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:38:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32469 #CVE_2025_33024 #CVE_2025_33025 #CVSS 9.9 #firmware update #ICS #industrial cybersecurity #OT Security #RUGGEDCOM #Siemens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:38:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32469 #CVE_2025_33024 #CVE_2025_33025 #CVSS 9.9 #firmware update #ICS #industrial cybersecurity #OT Security #RUGGEDCOM #Siemens
Daily CyberSecurity
Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
Siemens RUGGEDCOM devices face CVSS 9.9 command injection flaws. Authenticated users can execute root-level code via web tools. Patch to V2.16.5 now.
⤷ Title: Chihuahua Stealer Unleashed: Obfuscated PowerShell and AES-GCM Encryption Fuel This Advanced Data Theft Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:23:17 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AES_GCM #browser data exfiltration #Chihuahua Stealer #CNG API #crypto wallet theft #cybersecurity #G DATA #Infostealer #PowerShell Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:23:17 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AES_GCM #browser data exfiltration #Chihuahua Stealer #CNG API #crypto wallet theft #cybersecurity #G DATA #Infostealer #PowerShell Malware
Daily CyberSecurity
Chihuahua Stealer Unleashed: Obfuscated PowerShell and AES-GCM Encryption Fuel This Advanced Data Theft Campaign
Chihuahua Stealer uses stealthy PowerShell loaders, CNG AES-GCM encryption, and .NET memory injection to exfiltrate browser and crypto wallet data.
⤷ Title: Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
Daily CyberSecurity
Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
Earth Ammit’s VENOM and TIDRONE campaigns target Taiwan and South Korea’s drone, military, and satellite sectors via stealthy supply chain attacks.
⤷ Title: Critical CVE-2025-4632 Flaw in Samsung MagicINFO Puts Global Signage Networks at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4632 #cybersecurity #Digital Signage #Hacking #MagicINFO #samsung
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4632 #cybersecurity #Digital Signage #Hacking #MagicINFO #samsung
Daily CyberSecurity
Critical CVE-2025-4632 Flaw in Samsung MagicINFO Puts Global Signage Networks at Risk
A critical vulnerability (CVE-2025-4632) in Samsung's MagicINFO Server puts digital signage at risk. Learn how attackers can gain control and what to do
⤷ Title: Swan Vector Espionage Targets Japan & Taiwan with Advanced Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:13:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cobalt Strike #cyber_espionage #DLL Sideloading #Japan #malware #Swan Vector #Taiwan #threat actor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:13:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cobalt Strike #cyber_espionage #DLL Sideloading #Japan #malware #Swan Vector #Taiwan #threat actor
Daily CyberSecurity
Swan Vector Espionage Targets Japan & Taiwan with Advanced Malware
Swan Vector cyber-espionage campaign uses sophisticated malware to target institutions in Japan and Taiwan. Learn how they evade detection and steal data
⤷ Title: 82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:10:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4317 #CVE_2025_4339 #file upload #Remote Code Execution #security patch #site takeover #TheGem #Wordfence #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:10:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4317 #CVE_2025_4339 #file upload #Remote Code Execution #security patch #site takeover #TheGem #Wordfence #wordpress
Daily CyberSecurity
82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover
Two CVEs in TheGem WordPress theme let subscriber-level users upload malicious files and take over sites. Patch to version 5.10.3.1 now.