⤷ Title: Ultra-Fast DevSecOps Scanners
════════════════════════
𐀪 Author: AquilaX AI
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #security #devsecops
════════════════════════
𐀪 Author: AquilaX AI
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #security #devsecops
Medium
Ultra-Fast DevSecOps Scanners
Why scan speed matters in modern CI/CD pipelines
⤷ Title: UnderPass (Write-Up) — Hack The Box
════════════════════════
𐀪 Author: Ross Mitchell
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:04 GMT
════════════════════════
⌗ Tags: #htb #penetration_testing #ethical_hacking #hack_the_box_writeup #hack_the_box_walkthrough
════════════════════════
𐀪 Author: Ross Mitchell
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:40:04 GMT
════════════════════════
⌗ Tags: #htb #penetration_testing #ethical_hacking #hack_the_box_writeup #hack_the_box_walkthrough
Medium
UnderPass (Write-Up) — Hack The Box
UnderPass is a Linux box which contains information disclosure within SNMP utilising default community strings, which can be used to…
⤷ Title: Writing Pentest Reports: TryHackMe Answers with Explanation
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Tue, 13 May 2025 23:12:15 GMT
════════════════════════
⌗ Tags: #pentest_reporting #writing_pentest_reports #tryhackme_writeup #tryhackme #tryhackme_walkthrough
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Tue, 13 May 2025 23:12:15 GMT
════════════════════════
⌗ Tags: #pentest_reporting #writing_pentest_reports #tryhackme_writeup #tryhackme #tryhackme_walkthrough
Medium
Writing Pentest Reports: TryHackMe Answers with Explanation
Learn how to write professional pentesting reports that communicate risk to business stakeholders.
⤷ Title: 3. X86 Assembly Basics
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:32:26 GMT
════════════════════════
⌗ Tags: #miss_robot #static_analysis #tryhackme #dynamic_analysis #malware_analysis
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Tue, 13 May 2025 22:32:26 GMT
════════════════════════
⌗ Tags: #miss_robot #static_analysis #tryhackme #dynamic_analysis #malware_analysis
Medium
X86 Assembly Basics
x86 architecture | Malware Analysis
⤷ Title: AIGoat: A deliberately Vulnerable AI Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:30:36 +0000
════════════════════════
⌗ Tags: #Arsenal Lab #Vulnerability Assessment #AIGoat #Vulnerable AI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:30:36 +0000
════════════════════════
⌗ Tags: #Arsenal Lab #Vulnerability Assessment #AIGoat #Vulnerable AI
Penetration Testing Tools
AIGoat: A deliberately Vulnerable AI Infrastructure
AI-Goat is a deliberately vulnerable AI infrastructure hosted on AWS, designed to simulate the OWASP Machine Learning Security Top 10 risks
⤷ Title: dummy: Generator of static files for testing file upload
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec #dummy #testing file upload
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec #dummy #testing file upload
Penetration Testing Tools
dummy: Generator of static files for testing file upload
Generator of static files for testing file upload functionality. When generating a png, as in the screenshot, you can generate a png of a specified size.
⤷ Title: CVSS 10.0 Flaws in Siemens OZW Web Servers Enable Unauthenticated RCE and Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:00:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #building automation #CVE_2025_26389 #CVE_2025_26390 #CVSS 10.0 #cybersecurity #ICS security #OZW672 #OZW772 #Remote Code Execution #Siemens #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:00:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #building automation #CVE_2025_26389 #CVE_2025_26390 #CVSS 10.0 #cybersecurity #ICS security #OZW672 #OZW772 #Remote Code Execution #Siemens #sql injection
Daily CyberSecurity
CVSS 10.0 Flaws in Siemens OZW Web Servers Enable Unauthenticated RCE and Admin Access
CVEs 2025-26389 and 2025-26390 let attackers run code as root or gain admin access on Siemens OZW web servers. Patching is strongly advised.
⤷ Title: Ivanti Neurons for ITSM Hit by CVSS 9.8 Authentication Bypass Flaw Enabling Full Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:55:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #admin access #Authentication Bypass #Critical Vulnerability #CVE_2025_22462 #CVSS 9.8 #Ivanti #Neurons for ITSM #on_prem ITSM #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:55:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #admin access #Authentication Bypass #Critical Vulnerability #CVE_2025_22462 #CVSS 9.8 #Ivanti #Neurons for ITSM #on_prem ITSM #security advisory
Daily CyberSecurity
Ivanti Neurons for ITSM Hit by CVSS 9.8 Authentication Bypass Flaw Enabling Full Admin Access
Ivanti patches CVE-2025-22462, a critical CVSS 9.8 auth bypass flaw in Neurons for ITSM. Risk of full admin access. Patch or restrict IIS access now.
⤷ Title: Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
Daily CyberSecurity
Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
Varnish Cache and Enterprise have a vulnerability allowing HTTP request smuggling. This can lead to cache poisoning and WAF bypass. Upgrade now!
⤷ Title: Zoom Patches High-Severity Flaw (CVE-2025-30663) in Workplace Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:49:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #buffer over_read #CVE_2025_30663 #CVSS 8.8 #cybersecurity #Denial of Service #NULL pointer #privilege escalation #security #security update #update #Workplace Apps #Zoom #Zoom patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:49:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #buffer over_read #CVE_2025_30663 #CVSS 8.8 #cybersecurity #Denial of Service #NULL pointer #privilege escalation #security #security update #update #Workplace Apps #Zoom #Zoom patch
Daily CyberSecurity
Zoom Patches High-Severity Flaw (CVE-2025-30663) in Workplace Apps
Zoom fixes critical CVE-2025-30663 flaw allowing local privilege escalation. Users urged to update Workplace apps and SDKs to version 6.4.0 or newer.
⤷ Title: Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
Daily CyberSecurity
Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
Bitnami Pgpool flaw (CVE-2025-22248) exposes PostgreSQL to unauthenticated access. Update to Pgpool 4.6.0-1 or Helm chart 16.0.0 to fix.
⤷ Title: TA406 Cyber Campaign: North Korea’s Focus on Ukraine Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #geopolitics #intelligence gathering #malware #North Korea #phishing #Proofpoint #TA406 #threat actor #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #geopolitics #intelligence gathering #malware #North Korea #phishing #Proofpoint #TA406 #threat actor #Ukraine
Daily CyberSecurity
TA406 Cyber Campaign: North Korea's Focus on Ukraine Intelligence
North Korean threat actor TA406 intensifies cyber espionage against Ukraine, using phishing and malware to gather political intelligence.
⤷ Title: Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:38:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32469 #CVE_2025_33024 #CVE_2025_33025 #CVSS 9.9 #firmware update #ICS #industrial cybersecurity #OT Security #RUGGEDCOM #Siemens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:38:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32469 #CVE_2025_33024 #CVE_2025_33025 #CVSS 9.9 #firmware update #ICS #industrial cybersecurity #OT Security #RUGGEDCOM #Siemens
Daily CyberSecurity
Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
Siemens RUGGEDCOM devices face CVSS 9.9 command injection flaws. Authenticated users can execute root-level code via web tools. Patch to V2.16.5 now.
⤷ Title: Chihuahua Stealer Unleashed: Obfuscated PowerShell and AES-GCM Encryption Fuel This Advanced Data Theft Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:23:17 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AES_GCM #browser data exfiltration #Chihuahua Stealer #CNG API #crypto wallet theft #cybersecurity #G DATA #Infostealer #PowerShell Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:23:17 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AES_GCM #browser data exfiltration #Chihuahua Stealer #CNG API #crypto wallet theft #cybersecurity #G DATA #Infostealer #PowerShell Malware
Daily CyberSecurity
Chihuahua Stealer Unleashed: Obfuscated PowerShell and AES-GCM Encryption Fuel This Advanced Data Theft Campaign
Chihuahua Stealer uses stealthy PowerShell loaders, CNG AES-GCM encryption, and .NET memory injection to exfiltrate browser and crypto wallet data.
⤷ Title: Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
Daily CyberSecurity
Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
Earth Ammit’s VENOM and TIDRONE campaigns target Taiwan and South Korea’s drone, military, and satellite sectors via stealthy supply chain attacks.
⤷ Title: Critical CVE-2025-4632 Flaw in Samsung MagicINFO Puts Global Signage Networks at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4632 #cybersecurity #Digital Signage #Hacking #MagicINFO #samsung
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4632 #cybersecurity #Digital Signage #Hacking #MagicINFO #samsung
Daily CyberSecurity
Critical CVE-2025-4632 Flaw in Samsung MagicINFO Puts Global Signage Networks at Risk
A critical vulnerability (CVE-2025-4632) in Samsung's MagicINFO Server puts digital signage at risk. Learn how attackers can gain control and what to do
⤷ Title: Swan Vector Espionage Targets Japan & Taiwan with Advanced Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:13:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cobalt Strike #cyber_espionage #DLL Sideloading #Japan #malware #Swan Vector #Taiwan #threat actor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:13:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cobalt Strike #cyber_espionage #DLL Sideloading #Japan #malware #Swan Vector #Taiwan #threat actor
Daily CyberSecurity
Swan Vector Espionage Targets Japan & Taiwan with Advanced Malware
Swan Vector cyber-espionage campaign uses sophisticated malware to target institutions in Japan and Taiwan. Learn how they evade detection and steal data
⤷ Title: 82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:10:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4317 #CVE_2025_4339 #file upload #Remote Code Execution #security patch #site takeover #TheGem #Wordfence #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:10:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4317 #CVE_2025_4339 #file upload #Remote Code Execution #security patch #site takeover #TheGem #Wordfence #wordpress
Daily CyberSecurity
82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover
Two CVEs in TheGem WordPress theme let subscriber-level users upload malicious files and take over sites. Patch to version 5.10.3.1 now.
⤷ Title: Horabot Malware Targets Latin America with Sophisticated Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:02:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AutoIt #Credential Theft #Fortinet #Horabot #Latin America #malware #Outlook COM #phishing #powershell #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:02:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AutoIt #Credential Theft #Fortinet #Horabot #Latin America #malware #Outlook COM #phishing #powershell #VBScript
Daily CyberSecurity
Horabot Malware Targets Latin America with Sophisticated Phishing
Horabot malware targets Latin America with fake invoices, hijacking Outlook to spread phishing emails and steal data via stealthy scripting.
⤷ Title: Basic AWS IAM Enumeration Using Pacu
════════════════════════
𐀪 Author: innervision
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:13:40 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #aws #cloud_security #penetration_testing
════════════════════════
𐀪 Author: innervision
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:13:40 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #aws #cloud_security #penetration_testing
Medium
Basic AWS IAM Enumeration Using Pacu
A small article that compliments the Introduction to AWS pentesting course by Tyler Ramsbey.
⤷ Title: Domain analysis tools for OSINT Investigators
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:26 GMT
════════════════════════
⌗ Tags: #hacking #osint #cybersecurity #programming #investigation
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:26 GMT
════════════════════════
⌗ Tags: #hacking #osint #cybersecurity #programming #investigation
Medium
Domain analysis tools for OSINT Investigators
Analyze your target domain completely using these tools