⤷ Title: Popular Selenium Library WebDriverManager Hit by Critical XXE Bug (CVE-2025-4641, CVSS 9.3)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:40:03 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4641 #CVSS 9.3 #Java security #Selenium #ssrf #WebDriverManager #XML parsing #XXE Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:40:03 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4641 #CVSS 9.3 #Java security #Selenium #ssrf #WebDriverManager #XML parsing #XXE Vulnerability
Daily CyberSecurity
Popular Selenium Library WebDriverManager Hit by Critical XXE Bug (CVE-2025-4641, CVSS 9.3)
CVE-2025-4641: XXE flaw in popular WebDriverManager library (CVSS 9.3) exposes test systems to file leaks and SSRF. Patch to 6.0.2 now.
⤷ Title: TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:33:00 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #backdoor #COM hijacking #IPFS C2 #malware loader #Morpheus ransomware #TransferLoader #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:33:00 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #backdoor #COM hijacking #IPFS C2 #malware loader #Morpheus ransomware #TransferLoader #Zscaler ThreatLabz
Daily CyberSecurity
TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision
Zscaler reveals TransferLoader: a stealthy malware using IPFS and obfuscation to drop ransomware and backdoors. A new threat in the wild since 2025.
⤷ Title: Pgpool-II Hit by Critical CVE-2025-46801: CVSS 9.8 Risk Lets Attackers Bypass Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:30:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVE_2025_46801 #CVSS 9.8 #database security #Pgpool_II #PostgreSQL middleware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:30:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVE_2025_46801 #CVSS 9.8 #database security #Pgpool_II #PostgreSQL middleware
Daily CyberSecurity
Pgpool-II Hit by Critical CVE-2025-46801: CVSS 9.8 Risk Lets Attackers Bypass Authentication
CVE-2025-46801 in Pgpool-II scores 9.8 CVSS—flaw lets attackers log in as any user. Patch now to prevent database tampering and access.
⤷ Title: Jenkins Plugin Flaws Expose Critical Risks: CVE-2025-47889 Hits 9.8 CVSS with Auth Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:24:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CI/CD security #CVE_2025_47884 #CVE_2025_47885 #CVE_2025_47889 #Jenkins vulnerabilities #OpenID Connect #plugin security #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:24:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CI/CD security #CVE_2025_47884 #CVE_2025_47885 #CVE_2025_47889 #Jenkins vulnerabilities #OpenID Connect #plugin security #XSS
Daily CyberSecurity
Jenkins Plugin Flaws Expose Critical Risks: CVE-2025-47889 Hits 9.8 CVSS with Auth Bypass
Jenkins plugins hit by CVE-2025-47884 (CVSS 9.1) and more—flaws enable impersonation, XSS, and authentication bypass. Patch now to secure pipelines.
⤷ Title: Inside North Korea’s Cyber Mafia: How Hidden IT Workers Fuel Global Espionage and Crypto Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:16:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #AI cyber ops #DPRK cybercrime #DTEX report #hidden IT workers #North Korean APTs #Research Center 227 #TraderTraitor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:16:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #AI cyber ops #DPRK cybercrime #DTEX report #hidden IT workers #North Korean APTs #Research Center 227 #TraderTraitor
Daily CyberSecurity
Inside North Korea’s Cyber Mafia: How Hidden IT Workers Fuel Global Espionage and Crypto Theft
DTEX reveals how North Korea's hidden IT workforce and cyber syndicate drive global espionage, crypto theft, and AI-powered attacks.
⤷ Title: Critical NAS Risk: I-O DATA Flaw with 9.8 CVSS Allows Remote Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:13:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32002 #CVE_2025_32738 #firmware #HDL_T Series #I_O DATA #NAS #security #update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:13:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_32002 #CVE_2025_32738 #firmware #HDL_T Series #I_O DATA #NAS #security #update
Daily CyberSecurity
Critical NAS Risk: I-O DATA Flaw with 9.8 CVSS Allows Remote Command Execution
Urgent security alert! I-O DATA NAS devices vulnerable. A critical 9.8 CVSS flaw (CVE-2025-32002) enables remote command execution. Update firmware now!
⤷ Title: Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:09:41 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #APT28 #CVE_2023_43770 #cyber_espionage #Cyberespionage #Fancy Bear #Operation RoundPress #russia #security #Sednit #SpyPress #Ukraine #webmail #webmail attacks #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:09:41 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #APT28 #CVE_2023_43770 #cyber_espionage #Cyberespionage #Fancy Bear #Operation RoundPress #russia #security #Sednit #SpyPress #Ukraine #webmail #webmail attacks #XSS
Daily CyberSecurity
Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers
Russia-linked APT28 (Sednit/Fancy Bear) targets vulnerable webmail with XSS in Operation RoundPress, stealing data from global entities.
⤷ Title: Patch Now: SonicWall SMA1000 Flaw (CVE-2025-40595) Enables Stealth SSRF Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_40595 #patch #security #SMA1000 #SonicWall #ssrf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_40595 #patch #security #SMA1000 #SonicWall #ssrf
Daily CyberSecurity
Patch Now: SonicWall SMA1000 Flaw (CVE-2025-40595) Enables Stealth SSRF Attacks
SonicWall fixes CVE-2025-40595, a high-severity SSRF flaw in SMA1000 appliances. Patch now to block remote encoded URL exploitation.
⤷ Title: High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 May 2025 08:52:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #a_blog cms #CMS vulnerability #CVE_2025_36560 #CVSS 9.2 #JPCERT #Path Traversal #ssrf #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 15 May 2025 08:52:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #a_blog cms #CMS vulnerability #CVE_2025_36560 #CVSS 9.2 #JPCERT #Path Traversal #ssrf #XSS
Daily CyberSecurity
High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale
JPCERT reports critical flaws in a-blog cms, including CVE-2025-36560 (CVSS 9.2). Attackers could hijack sessions and access sensitive data.
⤷ Title: Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
════════════════════════
𐀪 Author: Sonny
════════════════════════
ⴵ Time: Thu, 15 May 2025 14:51:12 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Sonny
════════════════════════
ⴵ Time: Thu, 15 May 2025 14:51:12 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
Keeping your ears to the ground and eyes wide open for the latest vulnerability news at watchTowr is a given. Despite rummaging through enterprise code looking for 0days on a daily basis, our interest was piqued this week when news of fresh vulnerabilities…
⤷ Title: Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 2: Copilot
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 14 May 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Craig Vincent #How_To #Informational #AI #artifical intelligence #Copilot #penetration testing #Pentesting
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 14 May 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Craig Vincent #How_To #Informational #AI #artifical intelligence #Copilot #penetration testing #Pentesting
Black Hills Information Security, Inc.
Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 2: Copilot - Black Hills Information Security, Inc.
A common use case for LLMs is rapid software development. One of the first ways I used AI in my penetration testing methodology was for payload generation.
⤷ Title: Part-2️♂️Bug Bounty Secrets They Don’t Tell You: Tricks From 100+ Reported Bugs
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:05:52 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #hacking #secrets #bug_bounty
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:05:52 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #hacking #secrets #bug_bounty
Medium
Part-2🕵️♂️Bug Bounty Secrets They Don’t Tell You: Tricks From 100+ Reported Bugs
✨Free Article Link
⤷ Title: $500 Bounty: Race Condition in Hacker101 CTF Group Join
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:02:36 GMT
════════════════════════
⌗ Tags: #report #technology #bug_bounty #penetration_testing #hacking
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:02:36 GMT
════════════════════════
⌗ Tags: #report #technology #bug_bounty #penetration_testing #hacking
Medium
$500 Bounty: Race Condition in Hacker101 CTF Group Join
$500 for discovering a timing flaw in Hacker101’s invite system that let users join the same team multiple times
⤷ Title: Secret to find bugs in five minutes. Juicy reality.
════════════════════════
𐀪 Author: Rabia Riaz
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:02:02 GMT
════════════════════════
⌗ Tags: #easy_bugs #bug_bounty_writeup #bug_bounty_tips #bug_bounty #bug_in_5_minutes
════════════════════════
𐀪 Author: Rabia Riaz
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:02:02 GMT
════════════════════════
⌗ Tags: #easy_bugs #bug_bounty_writeup #bug_bounty_tips #bug_bounty #bug_in_5_minutes
Medium
Secret to find bugs in five minutes. Juicy reality.
Want to find bugs in 5-minutes? Let me help you real quick.
⤷ Title: NoSQL Injection Detection — A hands-on Exploitation Walkthrough
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:00:16 GMT
════════════════════════
⌗ Tags: #nosql_injection #nosql #sql_injection #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
ⴵ Time: Fri, 16 May 2025 05:00:16 GMT
════════════════════════
⌗ Tags: #nosql_injection #nosql #sql_injection #cybersecurity #bug_bounty
Medium
NoSQL Injection Detection — A hands-on Exploitation Walkthrough with Burp 🔍
Unleashing logic-flipping payloads in the neon-lit alleys of NoSQL One Injection at a Time.
⤷ Title: How a Simple Logic Flaw Led to a $3,250 Bounty
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 16 May 2025 04:59:05 GMT
════════════════════════
⌗ Tags: #report #technology #cybersecurity #bug_bounty #penetration_testing
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 16 May 2025 04:59:05 GMT
════════════════════════
⌗ Tags: #report #technology #cybersecurity #bug_bounty #penetration_testing
Medium
How a Simple Logic Flaw Led to a $3,250 Bounty
Claiming Unclaimed Restaurants on Zomato via OTP Manipulation
⤷ Title: From 0 to $$$: Finding Rate Limit Bypasses Like a Pro
════════════════════════
𐀪 Author: BugBounty University
════════════════════════
ⴵ Time: Fri, 16 May 2025 04:58:05 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #infosec #penetration_testing #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: BugBounty University
════════════════════════
ⴵ Time: Fri, 16 May 2025 04:58:05 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #infosec #penetration_testing #cybersecurity #bug_bounty
Medium
From 0 to $$$: Finding Rate Limit Bypasses Like a Pro
A beginner-friendly guide to finding rate limit bugs with real techniques, testing steps, and real-world impact.
⤷ Title: Top Tools That Helped Me Earn $500 in 30 Days
════════════════════════
𐀪 Author: It4chis3c
════════════════════════
ⴵ Time: Fri, 16 May 2025 04:57:24 GMT
════════════════════════
⌗ Tags: #bug_bounty #recon #secrets #hacking #information_security
════════════════════════
𐀪 Author: It4chis3c
════════════════════════
ⴵ Time: Fri, 16 May 2025 04:57:24 GMT
════════════════════════
⌗ Tags: #bug_bounty #recon #secrets #hacking #information_security
Medium
Top Tools That Helped Me Earn $500 in 30 Days
How I used these tools & commands to find bugs fast
⤷ Title: Blog Title: Not Your File: How Misconfigured MIME Types Let Me Upload Evil Scripts
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Thu, 15 May 2025 05:01:29 GMT
════════════════════════
⌗ Tags: #hacking #infosec #money #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Thu, 15 May 2025 05:01:29 GMT
════════════════════════
⌗ Tags: #hacking #infosec #money #bug_bounty #cybersecurity
Medium
📝 Blog Title: Not Your File: How Misconfigured MIME Types Let Me Upload Evil Scripts 📁😈
Hey there!😁
⤷ Title: ☕Best Tool for Analyzing Java Files (90% of Hackers Don’t Know This)
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Thu, 15 May 2025 05:00:35 GMT
════════════════════════
⌗ Tags: #java #bug_bounty #infosec #hacking #cybersecurity
════════════════════════
𐀪 Author: Abhijeet Kumawat
════════════════════════
ⴵ Time: Thu, 15 May 2025 05:00:35 GMT
════════════════════════
⌗ Tags: #java #bug_bounty #infosec #hacking #cybersecurity
Medium
☕Best Tool for Analyzing Java Files (90% of Hackers Don’t Know This)
Free Article Link
⤷ Title: Hacking With No Tools: How to Break Web Apps Using Just Your Browser ️♂️
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Thu, 15 May 2025 04:55:56 GMT
════════════════════════
⌗ Tags: #infosec #hacking #cybersecurity #bug_bounty #tech
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Thu, 15 May 2025 04:55:56 GMT
════════════════════════
⌗ Tags: #infosec #hacking #cybersecurity #bug_bounty #tech
Medium
Hacking With No Tools: How to Break Web Apps Using Just Your Browser 🕵️♂️
Hacking With No Tools: How to Break Web Apps Using Just Your Browser 🕵️♂️