⤷ Title: What is Kerberoasting?
════════════════════════
𐀪 Author: Jason
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 21:32:44 GMT
════════════════════════
⌗ Tags: #kerberoasting #cybersecurity #penetration_testing #ransonware #active_directory_security
════════════════════════
𐀪 Author: Jason
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 21:32:44 GMT
════════════════════════
⌗ Tags: #kerberoasting #cybersecurity #penetration_testing #ransonware #active_directory_security
Medium
What is Kerberoasting?
TL;DR: Kerberoasting is an attack technique used to steal and crack passwords for service accounts in Active Directory. It is quiet, fast…
⤷ Title: Spearphishing Attachments
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 22:32:32 GMT
════════════════════════
⌗ Tags: #malware_analysis #dynamic_analysis #static_analysis #tryhackme #miss_robot
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 22:32:32 GMT
════════════════════════
⌗ Tags: #malware_analysis #dynamic_analysis #static_analysis #tryhackme #miss_robot
Medium
Spearphishing Attachments
Malicious Documents | Part 1
⤷ Title: HTB Bashed Walkthrough
════════════════════════
𐀪 Author: The Cyber Outpost
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 23:02:32 GMT
════════════════════════
⌗ Tags: #php #hackthebox #hackthebox_writeup #hackthebox_walkthrough #cron
════════════════════════
𐀪 Author: The Cyber Outpost
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 23:02:32 GMT
════════════════════════
⌗ Tags: #php #hackthebox #hackthebox_writeup #hackthebox_walkthrough #cron
Medium
HTB Bashed Walkthrough
In this article, we’re going to explore the retired easy box of Blue, following the guided mode.
⤷ Title: xeol: scanner for end-of-life software in container images, filesystems, and SBOMs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:56:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #container images #filesystems #SBOM
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:56:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #container images #filesystems #SBOM
Penetration Testing Tools
xeol: scanner for end-of-life software in container images, filesystems, and SBOMs
xeol is a scanner for end-of-life (EOL) packages in container images, filesystems, and SBOMs
⤷ Title: kntrl: Real-time eBPF Runtime Security for Your CI/CD Pipelines
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:42:11 +0000
════════════════════════
⌗ Tags: #Network Defense #CI/CD #eBPF #GitHub Actions #kernel monitoring #kntrl #OPA #Open Policy Agent #open source #pipeline security #runtime security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:42:11 +0000
════════════════════════
⌗ Tags: #Network Defense #CI/CD #eBPF #GitHub Actions #kernel monitoring #kntrl #OPA #Open Policy Agent #open source #pipeline security #runtime security
Penetration Testing Tools
kntrl: Real-time eBPF Runtime Security for Your CI/CD Pipelines
kntrl is an eBPF-powered runtime agent for real-time detection & prevention of anomalous behavior in CI/CD pipelines, supporting OPA policies & GitHub Actions.
⤷ Title: PoC Reveals Apple Audio Zero-Day Enabling Remote Code Execution via Malicious Media Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:50:14 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #APT #CoreAudio #Cyberespionage #ios #iPadOS #macOS #PoC #proof_of_concept #rce #Remote Code Execution #security patch #tvOS #visionOS #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:50:14 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #APT #CoreAudio #Cyberespionage #ios #iPadOS #macOS #PoC #proof_of_concept #rce #Remote Code Execution #security patch #tvOS #visionOS #zero_day
Daily CyberSecurity
PoC Reveals Apple Audio Zero-Day Enabling Remote Code Execution via Malicious Media Files
Apple patches a CoreAudio flaw exploited in the wild via malicious media files, enabling remote code execution. PoC now on GitHub.
⤷ Title: Critical SSRF Flaw in Esri Portal for ArcGIS Exposes Internal Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:40:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcGIS #critical patch #cybersecurity #data exfiltration #Esri #network_security #Portal for ArcGIS #Remote Code Execution #ssrf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:40:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcGIS #critical patch #cybersecurity #data exfiltration #Esri #network_security #Portal for ArcGIS #Remote Code Execution #ssrf
Daily CyberSecurity
Critical SSRF Flaw in Esri Portal for ArcGIS Exposes Internal Networks
Esri patches a critical SSRF vulnerability in Portal for ArcGIS, allowing unauthenticated remote attackers to bypass protections and access internal services.
⤷ Title: Critical Flaw in Fabio Load Balancer Allows HTTP Header Tampering & Access Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:39:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #access control bypass #cybersecurity #Fabio #HTTP Headers #load balancer #reverse proxy #Server Security #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:39:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #access control bypass #cybersecurity #Fabio #HTTP Headers #load balancer #reverse proxy #Server Security #Web Security
Daily CyberSecurity
Critical Flaw in Fabio Load Balancer Allows HTTP Header Tampering & Access Bypass
A critical flaw in Fabio load balancer allows malicious clients to manipulate or strip HTTP headers, leading to potential access control bypass. Upgrade to 1.6.6.
⤷ Title: Aviation Industry Alert: 50,000+ Azure AD Records Exposed via Misconfigured API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:33:38 +0000
════════════════════════
⌗ Tags: #Data Leak #API vulnerability #aviation #Azure AD #CloudSEK #cybersecurity #Data Breach #Data Exposure #Microsoft Graph #misconfiguration #PII
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:33:38 +0000
════════════════════════
⌗ Tags: #Data Leak #API vulnerability #aviation #Azure AD #CloudSEK #cybersecurity #Data Breach #Data Exposure #Microsoft Graph #misconfiguration #PII
Daily CyberSecurity
Aviation Industry Alert: 50,000+ Azure AD Records Exposed via Misconfigured API
Over 50,000 Microsoft Azure AD user records from the aviation industry were exposed due to a misconfigured, unauthenticated API, revealing sensitive data and posing major risks.
⤷ Title: CISA Alert: Critical Flaws in Consilium Safety CS5000 Fire Panel Could Enable Remote Takeover, No Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:30:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Consilium Safety #Critical Infrastructure #CS5000 #cybersecurity #default account #fire panel #hardcoded credentials #ICS #industrial control systems #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:30:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Consilium Safety #Critical Infrastructure #CS5000 #cybersecurity #default account #fire panel #hardcoded credentials #ICS #industrial control systems #Vulnerability
Daily CyberSecurity
CISA Alert: Critical Flaws in Consilium Safety CS5000 Fire Panel Could Enable Remote Takeover, No Patch
CISA warns of critical flaws (CVE-2025-41438, CVE-2025-46352) in Consilium Safety CS5000 Fire Panels, allowing remote access & disruption. Vendor won't patch.
⤷ Title: Critical Flaws in Veritas DLO Expose Systems to Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:26:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache HTTP Server #apache Tomcat #CISA KEV #cybersecurity #data backup #endpoint protection #rce #Remote Code Execution #Veritas DLO
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:26:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apache HTTP Server #apache Tomcat #CISA KEV #cybersecurity #data backup #endpoint protection #rce #Remote Code Execution #Veritas DLO
Daily CyberSecurity
Critical Flaws in Veritas DLO Expose Systems to Remote Code Execution
Veritas DLO has critical vulnerabilities (CVE-2024-38475, CVE-2025-24813) in bundled Apache components, leading to RCE. Upgrade immediately to prevent exploitation.
⤷ Title: Critical RCE Flaws in MICI NetFax Server Unpatched, Vendor Refuses Fix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:22:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_48045 #CVE_2025_48046 #CVE_2025_48047 #cybersecurity #default credentials #Enterprise Security #MICI NetFax #Rapid7 #rce #Remote Code Execution #unpatched #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:22:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_48045 #CVE_2025_48046 #CVE_2025_48047 #cybersecurity #default credentials #Enterprise Security #MICI NetFax #Rapid7 #rce #Remote Code Execution #unpatched #Vulnerability
Daily CyberSecurity
Critical RCE Flaws in MICI NetFax Server Unpatched, Vendor Refuses Fix
Rapid7 found critical RCE flaws in MICI NetFax (versions < 3.0.1.0) via default credentials & command injection. Vendor refuses to patch, advising no internet exposure.
⤷ Title: PyPI Supply Chain Attack Steals Solana Private Keys via Covert Monkey-Patching
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:19:33 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain #cryptocurrency #cybersecurity #Infostealer #malware #open_source #private keys #PyPI #Python #Socket Security #Solana #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:19:33 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain #cryptocurrency #cybersecurity #Infostealer #malware #open_source #private keys #PyPI #Python #Socket Security #Solana #supply chain attack
Daily CyberSecurity
PyPI Supply Chain Attack Steals Solana Private Keys via Covert Monkey-Patching
A sophisticated PyPI supply chain attack, "cappership," steals Solana private keys by monkey-patching, leveraging transitive dependencies and blockchain exfiltration.
⤷ Title: NetSPI Details Multiple Local Privilege Escalation Vulnerabilities in SonicWall NetExtender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:13:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23009 #CVE_2025_23010 #cybersecurity #LPE #NetExtender #NetSPI #privilege escalation #SonicWall #vpn #Vulnerability #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:13:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23009 #CVE_2025_23010 #cybersecurity #LPE #NetExtender #NetSPI #privilege escalation #SonicWall #vpn #Vulnerability #windows
Daily CyberSecurity
NetSPI Details Multiple Local Privilege Escalation Vulnerabilities in SonicWall NetExtender
High-risk LPE vulnerabilities in SonicWall NetExtender for Windows (CVE-2025-23009, CVE-2025-23010) allow SYSTEM access or DoS. Patch immediately to version 10.3.2.
⤷ Title: Path Traversal at Scale: Study Uncovers 1,756 Vulnerable GitHub Projects and LLM Contamination
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:02:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ChatGPT #code reuse #Copilot #CWE_22 #Cybersecurity Research #github #LLM #Node.js #open_source #Path Traversal #security vulnerability #Supply Chain Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:02:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ChatGPT #code reuse #Copilot #CWE_22 #Cybersecurity Research #github #LLM #Node.js #open_source #Path Traversal #security vulnerability #Supply Chain Security
Daily CyberSecurity
Path Traversal at Scale: Study Uncovers 1,756 Vulnerable GitHub Projects and LLM Contamination
A study reveals widespread path traversal (CWE-22) in open-source projects, exacerbated by LLMs generating insecure code. Automated detection and patching are critical.
⤷ Title: Reconocimiento Web con Katana: Guía Completa para Empezar en Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:02:28 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #bug_bounty #penetration_testing #ethical_hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:02:28 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #bug_bounty #penetration_testing #ethical_hacking
Medium
Reconocimiento Web con Katana: Guía Completa para Empezar en Bug Bounty
Aprende a usar Katana para descubrir rutas y endpoints ocultos. Guía ideal para tus inicios en Bug Bounty.
⤷ Title: What is Security Operations Center (SOC)
════════════════════════
𐀪 Author: Abhinav Pathak
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:47:32 GMT
════════════════════════
⌗ Tags: #security_operation_center #privacy #security #cybersecurity #hacking
════════════════════════
𐀪 Author: Abhinav Pathak
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:47:32 GMT
════════════════════════
⌗ Tags: #security_operation_center #privacy #security #cybersecurity #hacking
Medium
What is Security Operations Center (SOC)
The first thing that immediately comes to mind when considering protection is the protection of our money, our valuable assets, and stuff…
⤷ Title: Attacking Common Applications — Skills Assessment III
════════════════════════
𐀪 Author: Ibrahima Ndong
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:05:18 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #htb #hackthebox #penetration_testing
════════════════════════
𐀪 Author: Ibrahima Ndong
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:05:18 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #htb #hackthebox #penetration_testing
Medium
Attacking Common Applications — Skills Assessment III
What is the hardcoded password for the database connection in the MultimasterAPI.dll file?
⤷ Title: Can a Penetration Test Prevent Ransomware? What Most Companies Miss
════════════════════════
𐀪 Author: Jason
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 21:35:48 GMT
════════════════════════
⌗ Tags: #it_security #active_directory #cybersecurity #penetration_testing #infosec
════════════════════════
𐀪 Author: Jason
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 21:35:48 GMT
════════════════════════
⌗ Tags: #it_security #active_directory #cybersecurity #penetration_testing #infosec
Medium
Can a Penetration Test Prevent Ransomware? What Most Companies Miss
TL;DR:
⤷ Title: Inside the Lab: My Hands-On Guide to Building a Malware Analysis Environment
════════════════════════
𐀪 Author: Ebenezer Hans Mensah
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:31:33 GMT
════════════════════════
⌗ Tags: #flarevm #cybersecurity #malware_analysis #digital_forensics #remnux
════════════════════════
𐀪 Author: Ebenezer Hans Mensah
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:31:33 GMT
════════════════════════
⌗ Tags: #flarevm #cybersecurity #malware_analysis #digital_forensics #remnux
Medium
Inside the Lab: My Hands-On Guide to Building a Malware Analysis Environment
Setting up a malware analysis lab is one of the best ways to learn how malicious software really works without putting your main system at…
⤷ Title: Cybersecurity Lexicon
════════════════════════
𐀪 Author: Dr. Prashant Sawant
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:04:24 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #artificial_intelligence #cybersecurity #information_technology
════════════════════════
𐀪 Author: Dr. Prashant Sawant
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 01:04:24 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #artificial_intelligence #cybersecurity #information_technology
Medium
Cybersecurity Lexicon
A