⤷ Title: Documents & Their Malicious Use
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 22:31:33 GMT
════════════════════════
⌗ Tags: #dynamic_analysis #static_analysis #tryhackme #miss_robot #malware_analysis
════════════════════════
𐀪 Author: Iram Jack
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 22:31:33 GMT
════════════════════════
⌗ Tags: #dynamic_analysis #static_analysis #tryhackme #miss_robot #malware_analysis
Medium
Documents & Their Malicious Use
Malicious Documents | Part 2
⤷ Title: Subdominator: CLI tool for detecting subdomain takeovers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:31:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:31:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment
Penetration Testing Tools
Subdominator: CLI tool for detecting subdomain takeovers
Meet Subdominator, your new favorite CLI tool for detecting subdomain takeovers. It's designed to be fast, accurate, and dependable
⤷ Title: RedRays ABAP Code Analyzer: Open-Source Security Scanner for SAP ABAP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:07:06 +0000
════════════════════════
⌗ Tags: #Code Assessment #ABAP #CI/CD #Code Quality #Code Security #cryptography #Development #Directory Traversal #Hardcoded Credentials #SAP #Static Analysis #vulnerability scanning #XSS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:07:06 +0000
════════════════════════
⌗ Tags: #Code Assessment #ABAP #CI/CD #Code Quality #Code Security #cryptography #Development #Directory Traversal #Hardcoded Credentials #SAP #Static Analysis #vulnerability scanning #XSS
Penetration Testing Tools
RedRays ABAP Code Analyzer: Open-Source Security Scanner for SAP ABAP
The ABAP Code Scanner analyzes ABAP code for XSS, directory traversal, hardcoded credentials, and more. Improve security and quality with customizable scans and detailed reports.
⤷ Title: Splunk Issues Patches for Two Security Flaws: Windows Permission Misconfiguration and Reflected XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 01:57:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #cyberattack #Data Security #security #security advisory #Splunk #Universal Forwarder #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 01:57:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #cyberattack #Data Security #security #security advisory #Splunk #Universal Forwarder #XSS
Daily CyberSecurity
Splunk Issues Patches for Two Security Flaws: Windows Permission Misconfiguration and Reflected XSS
High-severity flaws (CVE-2025-20298 & CVE-2025-20297) impact Splunk Enterprise & Universal Forwarder. Learn how to protect your data.
⤷ Title: Critical 9.8 CVSS Authentication Bypass in HPE StoreOnce Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:52:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVSS #cybersecurity #Data Protection #HPE StoreOnce #hybrid cloud #rce #Remote Code Execution #security update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:52:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVSS #cybersecurity #Data Protection #HPE StoreOnce #hybrid cloud #rce #Remote Code Execution #security update
Daily CyberSecurity
Critical 9.8 CVSS Authentication Bypass in HPE StoreOnce Software
HPE StoreOnce Software has critical vulnerabilities, including a 9.8 CVSS authentication bypass and RCE flaws. Update now to version 4.3.11 or later.
⤷ Title: FiberGateway Router Hacked: Portugal’s 1.6M Homes at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:50:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #DNS hijacking #Exploit #FiberGateway #GR241AG #João Domingos #MEO WiFi #Portugal #rce #router #Vulnerability #wpa2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:50:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #DNS hijacking #Exploit #FiberGateway #GR241AG #João Domingos #MEO WiFi #Portugal #rce #router #Vulnerability #wpa2
Daily CyberSecurity
FiberGateway Router Hacked: Portugal's 1.6M Homes at Risk
A security researcher achieved full control of the FiberGateway GR241AG router, exposing 1.6M Portuguese households to RCE, DNS hijacking, and WPA2 key theft.
⤷ Title: JINX-0132: Cryptojackers Exploit Misconfigured DevOps Environments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:46:19 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Consul #Cryptojacking #cybersecurity #DevOps #Docker API #Gitea #HashiCorp Nomad #JINX_0132 #misconfiguration #Monero #Wiz Threat Research #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:46:19 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Consul #Cryptojacking #cybersecurity #DevOps #Docker API #Gitea #HashiCorp Nomad #JINX_0132 #misconfiguration #Monero #Wiz Threat Research #XMRig
Daily CyberSecurity
JINX-0132: Cryptojackers Exploit Misconfigured DevOps Environments
Wiz uncovers JINX-0132, a cryptojacking campaign exploiting misconfigured Nomad, Consul, Docker, and Gitea in DevOps environments to mine Monero.
⤷ Title: Linux Flaws Expose Sensitive Data via Core Dumps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:42:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apport #CVE_2025_4598 #CVE_2025_5054 #cybersecurity #Data Exposure #Fedora #Linux #password hashes #Qualys #red hat #SUID #systemd_coredump #Ubuntu #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:42:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apport #CVE_2025_4598 #CVE_2025_5054 #cybersecurity #Data Exposure #Fedora #Linux #password hashes #Qualys #red hat #SUID #systemd_coredump #Ubuntu #Vulnerability
Daily CyberSecurity
Linux Flaws Expose Sensitive Data via Core Dumps
Qualys reveals two critical Linux vulnerabilities (CVE-2025-5054, CVE-2025-4598) in Apport & systemd-coredump, risking sensitive data exposure. Patch now!
⤷ Title: Haozi Returns: The Phishing-as-a-Service Platform Making Cybercrime Easy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:40:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Theft #Cybercrime #cybersecurity #dark web #Haozi #Netcraft #PhaaS #phishing #ransomware #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:40:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Theft #Cybercrime #cybersecurity #dark web #Haozi #Netcraft #PhaaS #phishing #ransomware #social engineering
Daily CyberSecurity
Haozi Returns: The Phishing-as-a-Service Platform Making Cybercrime Easy
Haozi, a Chinese Phishing-as-a-Service platform, is back, offering no-code phishing kits and full support. Learn how this service enables easy cybercrime.
⤷ Title: Stealthy npm Supply Chain Attack: Typosquatting Leads to Remote Code Execution and Data Destruction
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:36:38 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #data destruction #malware #npm #npm registry #Remote Code Execution #Socket #supply chain attack #Typosquatting #xlsx_to_json_lh
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:36:38 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #data destruction #malware #npm #npm registry #Remote Code Execution #Socket #supply chain attack #Typosquatting #xlsx_to_json_lh
Daily CyberSecurity
Stealthy npm Supply Chain Attack: Typosquatting Leads to Remote Code Execution and Data Destruction
A new npm supply chain attack, "xlsx-to-json-lh," uses typosquatting to enable remote code execution, silently awaiting a "kill switch" to delete project directories.
⤷ Title: Glitch Platform Abused: Phishing Campaigns Circumvent MFA and Target Credit Unions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:28:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud_hosted Threats #Cybercrime #cybersecurity #Glitch #MFA Bypass #Navy Federal Credit Union #Netskope #OTP #phishing #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:28:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cloud_hosted Threats #Cybercrime #cybersecurity #Glitch #MFA Bypass #Navy Federal Credit Union #Netskope #OTP #phishing #Telegram
Daily CyberSecurity
Glitch Platform Abused: Phishing Campaigns Circumvent MFA and Target Credit Unions
Netskope reveals a surge in phishing on Glitch, abusing the platform to bypass MFA and steal credentials, mainly targeting Navy Federal Credit Union members.
⤷ Title: How to Detect Microsoft 365 Phishing Attacks on Your Business
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:25:48 +0000
════════════════════════
⌗ Tags: #Malware #ANY.RUN #Credential Theft #cybersecurity #Incident Response #MFA Bypass #Microsoft 365 #phishing #sandbox #Security Awareness #Threat Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:25:48 +0000
════════════════════════
⌗ Tags: #Malware #ANY.RUN #Credential Theft #cybersecurity #Incident Response #MFA Bypass #Microsoft 365 #phishing #sandbox #Security Awareness #Threat Detection
Daily CyberSecurity
How to Detect Microsoft 365 Phishing Attacks on Your Business
Learn how interactive sandboxes like ANY.RUN can detect and analyze Microsoft 365 phishing attacks in real-time, preventing silent breaches and data exfiltration.
⤷ Title: Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:22:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #CoinMiner #Cryptocurrency Mining #cyberattack #cybersecurity #Gh0st RAT #Korean Internet Cafes #malware #threat actor #windows
Daily CyberSecurity
Gh0st in the Machine: ASEC Uncovers Cryptomining Campaign Exploiting Korean Internet Cafés
A sophisticated malware campaign targets Korean Internet cafés with Gh0st RAT and CoinMiner, hijacking systems for crypto mining. ASEC urges immediate action.
⤷ Title: Kaspersky Report Reveals Growing Threat from Old Exploits and OS Vulnerabilities in Q1 2025
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:17:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #Cyberattacks #cybersecurity #Exploits #kaspersky #Linux #microsoft office #patch management #Q1 2025 #Vulnerabilities #windows #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:17:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #Cyberattacks #cybersecurity #Exploits #kaspersky #Linux #microsoft office #patch management #Q1 2025 #Vulnerabilities #windows #zero_day
Daily CyberSecurity
Kaspersky Report Reveals Growing Threat from Old Exploits and OS Vulnerabilities in Q1 2025
Kaspersky's Q1 2025 report highlights a surge in attacks on aging systems, unpatched flaws, and mismanaged updates, urging vigilance and prompt action.
⤷ Title: Unmasking BtHoster: The Bulletproof Host Fueling Global Cyberattacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:12:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASNs #BGP Hijacking #Brute Force #BtHoster #bulletproof hosting #Cybercrime #cybersecurity #Intrinsec #malware #scanning #Shell Companies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:12:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASNs #BGP Hijacking #Brute Force #BtHoster #bulletproof hosting #Cybercrime #cybersecurity #Intrinsec #malware #scanning #Shell Companies
Daily CyberSecurity
Unmasking BtHoster: The Bulletproof Host Fueling Global Cyberattacks
Intrinsec exposes BtHoster, a bulletproof hosting provider behind widespread scanning and malware, revealing its network of shell companies and evasion tactics.
⤷ Title: CISA Warns of Critical Unauthenticated Access Vulnerability in Instantel Micromate Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:09:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Critical Vulnerability #CVE_2025_1907 #cybersecurity #ICS #industrial control systems #Instantel Micromate #SCADA #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:09:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Critical Vulnerability #CVE_2025_1907 #cybersecurity #ICS #industrial control systems #Instantel Micromate #SCADA #unauthenticated access
Daily CyberSecurity
CISA Warns of Critical Unauthenticated Access Vulnerability in Instantel Micromate Devices
CISA warns of a critical vulnerability (CVE-2025-1907) in Instantel Micromate devices, allowing unauthenticated remote command execution. Immediate action is advised.
⤷ Title: CISA Adds 5 Actively Exploited Vulnerabilities to KEV Catalog: ASUS Routers, Craft CMS, and ConnectWise Targeted
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASUS routers #CISA #ConnectWise #Craft CMS #Cyber Security #exploitation #KEV Catalog #nation_state #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASUS routers #CISA #ConnectWise #Craft CMS #Cyber Security #exploitation #KEV Catalog #nation_state #Vulnerability #zero_day
Daily CyberSecurity
CISA Adds 5 Actively Exploited Vulnerabilities to KEV Catalog: ASUS Routers, Craft CMS, and ConnectWise Targeted
CISA adds 5 new exploited vulnerabilities to KEV, including flaws in ASUS routers, Craft CMS, and ConnectWise. Urgent patching required!
⤷ Title: Lyrix Ransomware: New Threat Emerges with Advanced Evasion Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:02:40 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cybercrime #cybersecurity #Cyfirma #data destruction #encryption #Lyrix Ransomware #malware #ransomware #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:02:40 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cybercrime #cybersecurity #Cyfirma #data destruction #encryption #Lyrix Ransomware #malware #ransomware #windows
Daily CyberSecurity
Lyrix Ransomware: New Threat Emerges with Advanced Evasion Tactics
A new ransomware strain, Lyrix, targets Windows systems with strong encryption, anti-analysis, and data destruction techniques. Learn how to protect your data.
⤷ Title: Web Reconnaissance with Katana: A Complete Guide to Getting Started with Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:02:40 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #infosec #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:02:40 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #infosec #bug_bounty #cybersecurity
Medium
Web Reconnaissance with Katana: A Complete Guide to Getting Started with Bug Bounty
Learn how to use Katana to discover hidden routes and endpoints. This is the perfect guide for beginners in Bug Bounty.
⤷ Title: Why Theory Matters in Hacking (And How I Bricked a Lab System by “Being Practical”
════════════════════════
𐀪 Author: Alex Grande
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:19:52 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #hacking #self_improvement #learning
════════════════════════
𐀪 Author: Alex Grande
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 00:19:52 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #hacking #self_improvement #learning
Medium
Why Theory Matters in Hacking (And How I Bricked a Lab System by “Being Practical”
It’s a mistake. A big, stupid, unforgettable mistake….
⤷ Title: AI progress: why ‘miniaturization’ of LLM models will lead to a cybersecurity nightmare
════════════════════════
𐀪 Author: Andrea Isoni
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 01:50:16 GMT
════════════════════════
⌗ Tags: #technology #ai #artificial_intelligence #innovation #cybersecurity
════════════════════════
𐀪 Author: Andrea Isoni
════════════════════════
ⴵ Time: Tue, 03 Jun 2025 01:50:16 GMT
════════════════════════
⌗ Tags: #technology #ai #artificial_intelligence #innovation #cybersecurity
Medium
AI progress: why ‘miniaturization’ of LLM models will lead to a cybersecurity nightmare
At the moment LLMs are becoming increasingly more powerful everyday. Even hallucinations (errors) are diminishing at a good pace and…