⤷ Title: Zero Tust: When “Never Trust, Always Verify” Breaks Down
════════════════════════
𐀪 Author: Postmodern Cybersecurity
════════════════════════
ⴵ Time: Wed, 21 May 2025 23:11:42 GMT
════════════════════════
⌗ Tags: #security #zta #zero_trust #cybersecurity
════════════════════════
𐀪 Author: Postmodern Cybersecurity
════════════════════════
ⴵ Time: Wed, 21 May 2025 23:11:42 GMT
════════════════════════
⌗ Tags: #security #zta #zero_trust #cybersecurity
Medium
Zero Tust: When “Never Trust, Always Verify” Breaks Down
Zero Trust, the security model promising to solve all our problems by assuming everyone is a potential threat, may not be as effective as…
⤷ Title: ️ Home SOC Lab — Project-Z v1.0
════════════════════════
𐀪 Author: 0xZetss
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:51:20 GMT
════════════════════════
⌗ Tags: #blue_team #soc #homelab #cybersecurity #purple_team
════════════════════════
𐀪 Author: 0xZetss
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:51:20 GMT
════════════════════════
⌗ Tags: #blue_team #soc #homelab #cybersecurity #purple_team
Medium
🛡️ Home SOC Lab — Project-Z v1.0
From Blueprint to Detection: Building My Own Blue/Purple Team Lab By Ziad Okka (0xZetss)
⤷ Title: Ripple’s xrpl.js npm Package Was Backdoored: Here’s How Private Keys Were Stolen
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:40:36 GMT
════════════════════════
⌗ Tags: #cybercrime #ai #information_security #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:40:36 GMT
════════════════════════
⌗ Tags: #cybercrime #ai #information_security #cybersecurity #cyber_security_awareness
Medium
Ripple’s xrpl.js npm Package Was Backdoored: Here’s How Private Keys Were Stolen
The open-source ecosystem was hit with another wake-up call — and this time, the target was one of the most widely used libraries in the…
⤷ Title: Free VPNs : When “Free” comes at a hidden cost
════════════════════════
𐀪 Author: Larbi OUIYZME
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:39:07 GMT
════════════════════════
⌗ Tags: #privacy #encryption #privacy_protection #vpn #cybersecurity
════════════════════════
𐀪 Author: Larbi OUIYZME
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:39:07 GMT
════════════════════════
⌗ Tags: #privacy #encryption #privacy_protection #vpn #cybersecurity
Medium
Free VPNs : When “Free” comes at a hidden cost
In an era where the risk of sensitive data breaches is ever-present, using a VPN (Virtual Private Network) has become a common practice to…
⤷ Title: Cyber Chat: Page Glave
════════════════════════
𐀪 Author: Ryan G. Cox
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:36:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #detection_engineering #information_security #blue_team #career_change
════════════════════════
𐀪 Author: Ryan G. Cox
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:36:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #detection_engineering #information_security #blue_team #career_change
Medium
Cyber Chat: Page Glave
Pivoting careers. Panther + Scanner is the optimal stack. Day-to-day as a Detection Engineer. And more…
⤷ Title: Hijacking ssh client to get passwords of other server
════════════════════════
𐀪 Author: gerald amasi
════════════════════════
ⴵ Time: Wed, 21 May 2025 23:11:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #red_teaming #hijack #hijacking #ssh
════════════════════════
𐀪 Author: gerald amasi
════════════════════════
ⴵ Time: Wed, 21 May 2025 23:11:26 GMT
════════════════════════
⌗ Tags: #penetration_testing #red_teaming #hijack #hijacking #ssh
Medium
Hijacking ssh client to get passwords of other server
A simple scenario to this is when you have somehow gained access to the server, and you wan’t to pivot in the network further but no more…
⤷ Title: MalBuster’s Challenge ️♀️
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:31:23 GMT
════════════════════════
⌗ Tags: #dynamic_analysis #malware_analysis #static_analysis #tryhackme #miss_robot
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Wed, 21 May 2025 22:31:23 GMT
════════════════════════
⌗ Tags: #dynamic_analysis #malware_analysis #static_analysis #tryhackme #miss_robot
Medium
MalBuster’s Challenge 🕵️♀️
Basic Static Analysis | Part 3
⤷ Title: SQL INJECTION LEADING TO DDOS ATTACK IN PRIVATE CONQUER SERVER WEBSITE
════════════════════════
𐀪 Author: Alkaptonurea
════════════════════════
ⴵ Time: Wed, 21 May 2025 23:50:54 GMT
════════════════════════
⌗ Tags: #conquer #ddos_attack #penetration_testing #xss_vulnerability #sql_injection
════════════════════════
𐀪 Author: Alkaptonurea
════════════════════════
ⴵ Time: Wed, 21 May 2025 23:50:54 GMT
════════════════════════
⌗ Tags: #conquer #ddos_attack #penetration_testing #xss_vulnerability #sql_injection
Medium
SQL injection leading to Stored XSS leading to DDOS attack in game website
BUG INFO :
⤷ Title: MSFTRecon: Unauthenticated Recon Tool for Microsoft 365 & Azure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:55:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Azure #cybersecurity #enumeration #Microsoft 365 #MSFTRecon #reconnaissance #Red Team
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:55:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Azure #cybersecurity #enumeration #Microsoft 365 #MSFTRecon #reconnaissance #Red Team
Penetration Testing Tools
MSFTRecon: Unauthenticated Recon Tool for Microsoft 365 & Azure
MSFTRecon is a powerful tool for red teamers to map Microsoft 365 and Azure infrastructure without authentication, identifying misconfigurations.
⤷ Title: YATAS: AWS security, hardening, configurations, logging auditing tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:29:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #AWS hardening
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:29:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #AWS hardening
Penetration Testing Tools
YATAS: AWS security, hardening, configurations, logging auditing tool
Yet Another Testing & Auditing Solution is a simple and easy to use tool to audit your infrastructure for misconfiguration or potential security issues.
⤷ Title: Grafana Zero-Day? Emergency Patch Released ‘One Day Ahead of Schedule’ for XSS Flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 01:46:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4123 #cybersecurity #emergency patch #Grafana #security #XSS #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 01:46:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4123 #cybersecurity #emergency patch #Grafana #security #XSS #zero_day
Daily CyberSecurity
Grafana Zero-Day? Emergency Patch Released 'One Day Ahead of Schedule' for XSS Flaw
Grafana rushed an emergency patch for CVE-2025-4123, a high-severity XSS flaw that was made public. Upgrade now to prevent unauthorized access.
⤷ Title: GitLab Patches High-Severity Flaws: DoS and 2FA Bypass Fixed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 01:33:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #2FA bypass #authentication #cybersecurity #dos #gitlab #security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 01:33:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #2FA bypass #authentication #cybersecurity #dos #gitlab #security
Daily CyberSecurity
GitLab Patches High-Severity Flaws: DoS and 2FA Bypass Fixed
GitLab released urgent updates (18.0.1+) fixing high-severity flaws, including a DoS vulnerability (CVE-2025-0993) and a 2FA bypass (CVE-2024-12093).
⤷ Title: Docker Containers Under Attack: New Self-Replicating Dero Cryptominer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:36:14 +0000
════════════════════════
⌗ Tags: #Malware #container security #cryptomining #cybersecurity #Dero #docker #malware #worm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:36:14 +0000
════════════════════════
⌗ Tags: #Malware #container security #cryptomining #cybersecurity #Dero #docker #malware #worm
Daily CyberSecurity
Docker Containers Under Attack: New Self-Replicating Dero Cryptominer
A new self-replicating Dero cryptominer is infecting exposed Docker containers, spreading as a worm without needing a C2 server.
⤷ Title: NIST Proposes New Metric to Predict “Likely Exploited” Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:30:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #EPSS #KEV #LEV #NIST #patch prioritization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:30:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #EPSS #KEV #LEV #NIST #patch prioritization
Daily CyberSecurity
NIST Proposes New Metric to Predict "Likely Exploited" Vulnerabilities
NIST introduces the Likely Exploited Vulnerability (LEV) metric, a new way to estimate which CVEs have likely been exploited in the wild.
⤷ Title: Langroid Flaws (CVSS 9.8) Expose LLM Apps to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:20:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_46724 #CVE_2025_46725 #CVSS #cybersecurity #Langroid #LLM #Python #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:20:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_46724 #CVE_2025_46725 #CVSS #cybersecurity #Langroid #LLM #Python #rce #Remote Code Execution
Daily CyberSecurity
Langroid Flaws (CVSS 9.8) Expose LLM Apps to RCE
Critical vulnerabilities (CVSS 9.8) in the Langroid Python framework allow remote code execution in LLM applications. Update to version 0.53.15 now!
⤷ Title: Beyond Detection: PyBitmessage Protocol Used for Covert Monero Mining Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:16:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #CoinMiner #evasion #malware #Monero #p2p #powershell #PyBitmessage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:16:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #CoinMiner #evasion #malware #Monero #p2p #powershell #PyBitmessage
Daily CyberSecurity
Beyond Detection: PyBitmessage Protocol Used for Covert Monero Mining Campaign
Threat actors are using the PyBitmessage protocol as a stealthy C2 channel to hide a Monero coinminer and backdoor, evading detection.
⤷ Title: Critical Flaws in AI Browse Agents: Exposed to Credential Theft and Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:12:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #agent hijacking #AI Agents #Credential Theft #CVE_2025_47241 #cybersecurity #domain bypass #LLM #Prompt injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:12:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #agent hijacking #AI Agents #Credential Theft #CVE_2025_47241 #cybersecurity #domain bypass #LLM #Prompt injection
Daily CyberSecurity
Critical Flaws in AI Browse Agents: Exposed to Credential Theft and Hijacking
Learn about critical vulnerabilities in LLM-powered Browse agents like Browser Use, allowing domain bypass and prompt injection for data theft.
⤷ Title: Industrial Alert: AutomationDirect MB-Gateway Flaw Rated CVSS 10, No Software Fix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:09:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #AutomationDirect #CISA #Critical Infrastructure #CVE_2025_36535 #industrial cybersecurity #MB_Gateway #Remote Access #unauthenticated
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:09:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #AutomationDirect #CISA #Critical Infrastructure #CVE_2025_36535 #industrial cybersecurity #MB_Gateway #Remote Access #unauthenticated
Daily CyberSecurity
Industrial Alert: AutomationDirect MB-Gateway Flaw Rated CVSS 10, No Software Fix
AutomationDirect's MB-Gateway has a critical (CVSS 10) flaw allowing unauthenticated remote access and RCE. Hardware limits prevent a software fix; replacement is recommended.
⤷ Title: Beyond Ads: Malvertising Campaign Leverages Google APIs to Redirect Shoppers to Fake Payments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:00:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #e_commerce #Fraud #Google API #JSONP #Malvertising #phishing #retail security #script injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:00:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #e_commerce #Fraud #Google API #JSONP #Malvertising #phishing #retail security #script injection
Daily CyberSecurity
Beyond Ads: Malvertising Campaign Leverages Google APIs to Redirect Shoppers to Fake Payments
Attackers exploit JSONP flaws in Google APIs to inject malicious scripts into e-commerce sites, silently redirecting users to fake payment pages.
⤷ Title: Weighing Our Chances
════════════════════════
𐀪 Author: Nature's Wild Berry
════════════════════════
ⴵ Time: Thu, 22 May 2025 01:32:25 GMT
════════════════════════
⌗ Tags: #acai #sugar_free #co_packer #natural_sweetener #hacking
════════════════════════
𐀪 Author: Nature's Wild Berry
════════════════════════
ⴵ Time: Thu, 22 May 2025 01:32:25 GMT
════════════════════════
⌗ Tags: #acai #sugar_free #co_packer #natural_sweetener #hacking
Medium
Weighing Our Chances
Now that we had a product I was finally proud of, the new mission was clear: find a co-packer willing to work with a completely unknown…
⤷ Title: Getting Locked Out of My House Was the Best Hacking Lesson of My Life
════════════════════════
𐀪 Author: Alex Grande
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:46:26 GMT
════════════════════════
⌗ Tags: #hacking #life_lessons #creativity #motivation #life
════════════════════════
𐀪 Author: Alex Grande
════════════════════════
ⴵ Time: Thu, 22 May 2025 00:46:26 GMT
════════════════════════
⌗ Tags: #hacking #life_lessons #creativity #motivation #life
Medium
Getting Locked Out of My House Was the Best Hacking Lesson of My Life
No Hacking Course Could Teach Me (My Front Door Did)