⤷ Title: CVSS 10.0 Flaws in Siemens OZW Web Servers Enable Unauthenticated RCE and Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:00:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #building automation #CVE_2025_26389 #CVE_2025_26390 #CVSS 10.0 #cybersecurity #ICS security #OZW672 #OZW772 #Remote Code Execution #Siemens #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:00:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #building automation #CVE_2025_26389 #CVE_2025_26390 #CVSS 10.0 #cybersecurity #ICS security #OZW672 #OZW772 #Remote Code Execution #Siemens #sql injection
Daily CyberSecurity
CVSS 10.0 Flaws in Siemens OZW Web Servers Enable Unauthenticated RCE and Admin Access
CVEs 2025-26389 and 2025-26390 let attackers run code as root or gain admin access on Siemens OZW web servers. Patching is strongly advised.
⤷ Title: Ivanti Neurons for ITSM Hit by CVSS 9.8 Authentication Bypass Flaw Enabling Full Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:55:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #admin access #Authentication Bypass #Critical Vulnerability #CVE_2025_22462 #CVSS 9.8 #Ivanti #Neurons for ITSM #on_prem ITSM #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:55:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #admin access #Authentication Bypass #Critical Vulnerability #CVE_2025_22462 #CVSS 9.8 #Ivanti #Neurons for ITSM #on_prem ITSM #security advisory
Daily CyberSecurity
Ivanti Neurons for ITSM Hit by CVSS 9.8 Authentication Bypass Flaw Enabling Full Admin Access
Ivanti patches CVE-2025-22462, a critical CVSS 9.8 auth bypass flaw in Neurons for ITSM. Risk of full admin access. Patch or restrict IIS access now.
⤷ Title: Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:50:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
Daily CyberSecurity
Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
Varnish Cache and Enterprise have a vulnerability allowing HTTP request smuggling. This can lead to cache poisoning and WAF bypass. Upgrade now!
⤷ Title: Zoom Patches High-Severity Flaw (CVE-2025-30663) in Workplace Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:49:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #buffer over_read #CVE_2025_30663 #CVSS 8.8 #cybersecurity #Denial of Service #NULL pointer #privilege escalation #security #security update #update #Workplace Apps #Zoom #Zoom patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:49:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #buffer over_read #CVE_2025_30663 #CVSS 8.8 #cybersecurity #Denial of Service #NULL pointer #privilege escalation #security #security update #update #Workplace Apps #Zoom #Zoom patch
Daily CyberSecurity
Zoom Patches High-Severity Flaw (CVE-2025-30663) in Workplace Apps
Zoom fixes critical CVE-2025-30663 flaw allowing local privilege escalation. Users urged to update Workplace apps and SDKs to version 6.4.0 or newer.
⤷ Title: Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
Daily CyberSecurity
Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
Bitnami Pgpool flaw (CVE-2025-22248) exposes PostgreSQL to unauthenticated access. Update to Pgpool 4.6.0-1 or Helm chart 16.0.0 to fix.
⤷ Title: TA406 Cyber Campaign: North Korea’s Focus on Ukraine Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #geopolitics #intelligence gathering #malware #North Korea #phishing #Proofpoint #TA406 #threat actor #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #geopolitics #intelligence gathering #malware #North Korea #phishing #Proofpoint #TA406 #threat actor #Ukraine
Daily CyberSecurity
TA406 Cyber Campaign: North Korea's Focus on Ukraine Intelligence
North Korean threat actor TA406 intensifies cyber espionage against Ukraine, using phishing and malware to gather political intelligence.
⤷ Title: Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:38:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32469 #CVE_2025_33024 #CVE_2025_33025 #CVSS 9.9 #firmware update #ICS #industrial cybersecurity #OT Security #RUGGEDCOM #Siemens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:38:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32469 #CVE_2025_33024 #CVE_2025_33025 #CVSS 9.9 #firmware update #ICS #industrial cybersecurity #OT Security #RUGGEDCOM #Siemens
Daily CyberSecurity
Siemens RUGGEDCOM Flaws Scored CVSS 9.9: Command Injection Bugs Threaten Industrial Networks
Siemens RUGGEDCOM devices face CVSS 9.9 command injection flaws. Authenticated users can execute root-level code via web tools. Patch to V2.16.5 now.
⤷ Title: Chihuahua Stealer Unleashed: Obfuscated PowerShell and AES-GCM Encryption Fuel This Advanced Data Theft Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:23:17 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AES_GCM #browser data exfiltration #Chihuahua Stealer #CNG API #crypto wallet theft #cybersecurity #G DATA #Infostealer #PowerShell Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:23:17 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #AES_GCM #browser data exfiltration #Chihuahua Stealer #CNG API #crypto wallet theft #cybersecurity #G DATA #Infostealer #PowerShell Malware
Daily CyberSecurity
Chihuahua Stealer Unleashed: Obfuscated PowerShell and AES-GCM Encryption Fuel This Advanced Data Theft Campaign
Chihuahua Stealer uses stealthy PowerShell loaders, CNG AES-GCM encryption, and .NET memory injection to exfiltrate browser and crypto wallet data.
⤷ Title: Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
Daily CyberSecurity
Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
Earth Ammit’s VENOM and TIDRONE campaigns target Taiwan and South Korea’s drone, military, and satellite sectors via stealthy supply chain attacks.
⤷ Title: Critical CVE-2025-4632 Flaw in Samsung MagicINFO Puts Global Signage Networks at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4632 #cybersecurity #Digital Signage #Hacking #MagicINFO #samsung
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:17:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4632 #cybersecurity #Digital Signage #Hacking #MagicINFO #samsung
Daily CyberSecurity
Critical CVE-2025-4632 Flaw in Samsung MagicINFO Puts Global Signage Networks at Risk
A critical vulnerability (CVE-2025-4632) in Samsung's MagicINFO Server puts digital signage at risk. Learn how attackers can gain control and what to do
⤷ Title: Swan Vector Espionage Targets Japan & Taiwan with Advanced Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:13:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cobalt Strike #cyber_espionage #DLL Sideloading #Japan #malware #Swan Vector #Taiwan #threat actor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:13:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cobalt Strike #cyber_espionage #DLL Sideloading #Japan #malware #Swan Vector #Taiwan #threat actor
Daily CyberSecurity
Swan Vector Espionage Targets Japan & Taiwan with Advanced Malware
Swan Vector cyber-espionage campaign uses sophisticated malware to target institutions in Japan and Taiwan. Learn how they evade detection and steal data
⤷ Title: 82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:10:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4317 #CVE_2025_4339 #file upload #Remote Code Execution #security patch #site takeover #TheGem #Wordfence #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:10:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4317 #CVE_2025_4339 #file upload #Remote Code Execution #security patch #site takeover #TheGem #Wordfence #wordpress
Daily CyberSecurity
82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover
Two CVEs in TheGem WordPress theme let subscriber-level users upload malicious files and take over sites. Patch to version 5.10.3.1 now.
⤷ Title: Horabot Malware Targets Latin America with Sophisticated Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:02:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AutoIt #Credential Theft #Fortinet #Horabot #Latin America #malware #Outlook COM #phishing #powershell #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:02:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AutoIt #Credential Theft #Fortinet #Horabot #Latin America #malware #Outlook COM #phishing #powershell #VBScript
Daily CyberSecurity
Horabot Malware Targets Latin America with Sophisticated Phishing
Horabot malware targets Latin America with fake invoices, hijacking Outlook to spread phishing emails and steal data via stealthy scripting.
⤷ Title: Basic AWS IAM Enumeration Using Pacu
════════════════════════
𐀪 Author: innervision
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:13:40 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #aws #cloud_security #penetration_testing
════════════════════════
𐀪 Author: innervision
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:13:40 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #aws #cloud_security #penetration_testing
Medium
Basic AWS IAM Enumeration Using Pacu
A small article that compliments the Introduction to AWS pentesting course by Tyler Ramsbey.
⤷ Title: Domain analysis tools for OSINT Investigators
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:26 GMT
════════════════════════
⌗ Tags: #hacking #osint #cybersecurity #programming #investigation
════════════════════════
𐀪 Author: loyalonlytoday
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:42:26 GMT
════════════════════════
⌗ Tags: #hacking #osint #cybersecurity #programming #investigation
Medium
Domain analysis tools for OSINT Investigators
Analyze your target domain completely using these tools
⤷ Title: Usable Encryption. Two-word PUNCHLINE?
════════════════════════
𐀪 Author: Senjaputrasndr
════════════════════════
ⴵ Time: Wed, 14 May 2025 02:00:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #usability #encryption #usable_encryption
════════════════════════
𐀪 Author: Senjaputrasndr
════════════════════════
ⴵ Time: Wed, 14 May 2025 02:00:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #usability #encryption #usable_encryption
Medium
Usable Encryption. Two-word PUNCHLINE?
You know why Usable Encryption sounds like Two-Word Pubchline? Let me explain in simpliest way
⤷ Title: Agentic AI in the Hands of Cybercriminals: A Growing Concern for Wall Street
════════════════════════
𐀪 Author: Wale Adedeji
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:57:12 GMT
════════════════════════
⌗ Tags: #artificial_inteligence #risk_management #cybersecurity_awareness #cybersecurity #ai_agents_army
════════════════════════
𐀪 Author: Wale Adedeji
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:57:12 GMT
════════════════════════
⌗ Tags: #artificial_inteligence #risk_management #cybersecurity_awareness #cybersecurity #ai_agents_army
Medium
Agentic AI in the Hands of Cybercriminals: A Growing Concern for Wall Street
Wall Street thrives on speed, data, and an intricate web of digital transactions. It’s a high-stakes environment where fortunes are made and lost in microseconds. For years, financial institutions…
⤷ Title: Incident Analysis: Malicious Activity on Host 12.183.1.55!
════════════════════════
𐀪 Author: Jonathan M.
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:42:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #wireshark
════════════════════════
𐀪 Author: Jonathan M.
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:42:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #wireshark
Medium
🚨Incident Analysis: Malicious Activity on Host 12.183.1.55!
Introduction
⤷ Title: Top 8 Best Vulnerability Scanning Tools (2025 Guide)
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:38:22 GMT
════════════════════════
⌗ Tags: #openexploit #technology #cybersecurity #programming #software_engineering
════════════════════════
𐀪 Author: Pawan Jaiswal
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:38:22 GMT
════════════════════════
⌗ Tags: #openexploit #technology #cybersecurity #programming #software_engineering
Medium
Top 8 Best Vulnerability Scanning Tools (2025 Guide)
If you have a small website, do IT for a company, or simply an inquisitive security enthusiast, one thing is certain — you must scan for…
⤷ Title: MITM HTTPS Payload with Python
════════════════════════
𐀪 Author: Aris Haryanto
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:35:58 GMT
════════════════════════
⌗ Tags: #https #artificial_intelligence #cybersecurity #mitm #python
════════════════════════
𐀪 Author: Aris Haryanto
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:35:58 GMT
════════════════════════
⌗ Tags: #https #artificial_intelligence #cybersecurity #mitm #python
Medium
MITM HTTPS Payload with Python
A lightweight MITM tool for monitoring encrypted traffic and detecting threats powered by AI and built in Python
⤷ Title: The Red Teaming: 30-Day Challenge[30]
════════════════════════
𐀪 Author: Bl@ckC!pH3r
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:16:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #career_advice #careers
════════════════════════
𐀪 Author: Bl@ckC!pH3r
════════════════════════
ⴵ Time: Wed, 14 May 2025 01:16:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #career_advice #careers
Medium
The Red Teaming: 30-Day Challenge[30]
Day 30: Building Your Career in Red Teaming