⤷ Title: Microsoft BFS Flaws Expose Windows to Privilege Escalation – PoC Code Released
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:50:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #AppContainer #cybersecurity #Exploit #Microsoft BFS #PoC #privilege escalation #race condition #use after free #UWP #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:50:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #AppContainer #cybersecurity #Exploit #Microsoft BFS #PoC #privilege escalation #race condition #use after free #UWP #windows
Daily CyberSecurity
Microsoft BFS Flaws Expose Windows to Privilege Escalation – PoC Code Released
Critical flaws in Microsoft's Brokering File System (BFS), including race conditions and UAF bugs, expose Windows to privilege escalation. PoC code available. Patch now!
⤷ Title: From Cheats to Compromise: Blitz Malware Exploits Gamers via Backdoored Standoff 2 Cheats
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:48:28 +0000
════════════════════════
⌗ Tags: #Malware #Blitz malware #Cryptojacking #Cybercrime #cybersecurity #gaming cheats #Hugging Face #Infostealer #Standoff 2 #Telegram #Unit 42 #Windows malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:48:28 +0000
════════════════════════
⌗ Tags: #Malware #Blitz malware #Cryptojacking #Cybercrime #cybersecurity #gaming cheats #Hugging Face #Infostealer #Standoff 2 #Telegram #Unit 42 #Windows malware
Daily CyberSecurity
From Cheats to Compromise: Blitz Malware Exploits Gamers via Backdoored Standoff 2 Cheats
Blitz malware infects gamers via backdoored Standoff 2 cheats, stealing data and cryptojacking. It uses Hugging Face for C2 and targets Windows users globally.
⤷ Title: QNAP Fixes SQL Injection and Certificate Validation Flaws in Qsync Central and File Station 5
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:43:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #data compromise #File Station 5 #network storage #QNAP #Qsync Central #Remote Code Execution #security update #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:43:36 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #data compromise #File Station 5 #network storage #QNAP #Qsync Central #Remote Code Execution #security update #sql injection
Daily CyberSecurity
QNAP Fixes SQL Injection and Certificate Validation Flaws in Qsync Central and File Station 5
QNAP releases urgent patches for high-severity flaws in Qsync Central and File Station 5, enabling RCE and data compromise. Update immediately!
⤷ Title: Critical CVSS 10.0 Flaws in B. Braun OnlineSuite Threaten Healthcare Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:39:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #B. Braun #CVE_2025_3322 #cybersecurity #healthcare #IT security #medical devices #OnlineSuite AP 3.0 #patient safety #rce #Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:39:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #B. Braun #CVE_2025_3322 #cybersecurity #healthcare #IT security #medical devices #OnlineSuite AP 3.0 #patient safety #rce #Vulnerabilities
Daily CyberSecurity
Critical CVSS 10.0 Flaws in B. Braun OnlineSuite Threaten Healthcare Infrastructure
B. Braun's OnlineSuite AP 3.0 faces severe vulnerabilities, including a CVSS 10.0 RCE, risking hospital IT and data. Immediate patching is crucial.
⤷ Title: UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
Daily CyberSecurity
UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
CERT Polska warns of a critical Roundcube XSS flaw (CVE-2024-42009) exploited by UNC1151 in spear phishing, stealing credentials and compromising Polish organizations.
⤷ Title: DuplexSpy RAT: New C# Malware Toolkit Emerges on GitHub
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:30:48 +0000
════════════════════════
⌗ Tags: #Malware #C++ #Cybercrime #cybersecurity #Cyfirma #DuplexSpy #github #Infostealer #malware #rat #Remote Access Trojan #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:30:48 +0000
════════════════════════
⌗ Tags: #Malware #C++ #Cybercrime #cybersecurity #Cyfirma #DuplexSpy #github #Infostealer #malware #rat #Remote Access Trojan #threat intelligence
Daily CyberSecurity
DuplexSpy RAT: New C# Malware Toolkit Emerges on GitHub
CYFIRMA uncovers DuplexSpy, a powerful C# RAT on GitHub with surveillance, persistence, and anti-analysis features, posing a significant cybercrime threat.
⤷ Title: Destructive npm Packages Disguised as Utilities Trigger Remote System Wipes on Demand
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:27:46 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #data wiping #Developer Tools #express_api_sync #malware #npm #Socket Security #supply chain attack #system_health_sync_api
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:27:46 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #data wiping #Developer Tools #express_api_sync #malware #npm #Socket Security #supply chain attack #system_health_sync_api
Daily CyberSecurity
Destructive npm Packages Disguised as Utilities Trigger Remote System Wipes on Demand
Two malicious npm packages, express-api-sync and system-health-sync-api, act as remote-controlled time bombs, wiping entire directories with a single POST request.
⤷ Title: Android’s Secret Tracking: Meta & Yandex Abused Localhost for User Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:21:39 +0000
════════════════════════
⌗ Tags: #Data Leak #android #cross_context tracking #cybersecurity #facebook #Instagram #localhost #Meta #Meta Pixel #privacy #tracking #WebRTC #Yandex
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:21:39 +0000
════════════════════════
⌗ Tags: #Data Leak #android #cross_context tracking #cybersecurity #facebook #Instagram #localhost #Meta #Meta Pixel #privacy #tracking #WebRTC #Yandex
Daily CyberSecurity
Android’s Secret Tracking: Meta & Yandex Abused Localhost for User Data
A new disclosure by researchers from IMDEA Networks, Radboud University, and KU Leuven has revealed a novel cross-context tracking technique that affects billions of Android users worldwide. The m…
⤷ Title: Go Fixes Three Security Flaws: Update Your Apps Now!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:16:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #crypto/x509 #CVE #cybersecurity #go #Golang #net/http #OS #security vulnerability #software update #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:16:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #crypto/x509 #CVE #cybersecurity #go #Golang #net/http #OS #security vulnerability #software update #web development
Daily CyberSecurity
Go Fixes Three Security Flaws: Update Your Apps Now!
Go 1.24.4 and 1.23.10 fix flaws in net/http, os, and crypto/x509, addressing data leaks, file inconsistencies, and certificate validation bypasses. Update now!
⤷ Title: FormBook Returns: Exploiting CVE-2017-0199 via Malicious Excel Attachments in New Phishing Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2017_0199 #cybersecurity #Excel #Exploit #Formbook #FortiGuard #Infostealer #malware #microsoft office #phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #CVE_2017_0199 #cybersecurity #Excel #Exploit #Formbook #FortiGuard #Infostealer #malware #microsoft office #phishing
Daily CyberSecurity
FormBook Returns: Exploiting CVE-2017-0199 via Malicious Excel Attachments in New Phishing Campaign
An old Microsoft Office vulnerability (CVE-2017-0199) is being exploited in a new phishing campaign to deploy the FormBook infostealer malware. Update now!
⤷ Title: EnigmaCyberSecurity: Brazil-Focused Banking Malware Campaign Uses RATs and Malicious Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:07:04 +0000
════════════════════════
⌗ Tags: #Malware #banking trojans #Browser Extension Malware #EnigmaCyberSecurity #Financial Credential Theft #Latin America Cybercrime #Mesh Agent #Phishing Campaign #rat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:07:04 +0000
════════════════════════
⌗ Tags: #Malware #banking trojans #Browser Extension Malware #EnigmaCyberSecurity #Financial Credential Theft #Latin America Cybercrime #Mesh Agent #Phishing Campaign #rat
Daily CyberSecurity
EnigmaCyberSecurity: Brazil-Focused Banking Malware Campaign Uses RATs and Malicious Extensions
"EnigmaCyberSecurity" is a new multi-stage cybercrime campaign hitting Brazil and beyond, using phishing, malicious extensions, and RATs to steal banking data.
⤷ Title: CVE-2025-4318 (CVSS 9.5): AWS Amplify RCE Flaw Exposed with PoC – CI/CD Pipelines at Risk
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:02:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS Amplify #CI/CD security #CVE_2025_4318 #JavaScript Exploits #Node.js #PoC Exploit #Remote Code Execution #Web Development Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:02:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AWS Amplify #CI/CD security #CVE_2025_4318 #JavaScript Exploits #Node.js #PoC Exploit #Remote Code Execution #Web Development Security
Daily CyberSecurity
CVE-2025-4318 (CVSS 9.5): AWS Amplify RCE Flaw Exposed with PoC – CI/CD Pipelines at Risk
CVE-2025-4318 (CVSS 9.5) hits AWS Amplify Codegen UI with PoC exploit. RCE flaw puts CI/CD pipelines and developer environments at high risk.
⤷ Title: Finally , Got Certified with EJpt Certification
════════════════════════
𐀪 Author: Mr Horbio
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:33:51 GMT
════════════════════════
⌗ Tags: #hacker #cybersecurity #ejpt #bug_bounty #ethical_hacking
════════════════════════
𐀪 Author: Mr Horbio
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:33:51 GMT
════════════════════════
⌗ Tags: #hacker #cybersecurity #ejpt #bug_bounty #ethical_hacking
Medium
Finally , Got Certified with EJpt Certification
This is tells about my story and how to complete my preparation for ejpt exam.
⤷ Title: Behind the Shop: How a Simple SQLi in the Products Page Gave Me Full Access
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:32:45 GMT
════════════════════════
⌗ Tags: #sql #hacking #developer #bug_bounty #sql_injection
════════════════════════
𐀪 Author: Waleed Osama
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:32:45 GMT
════════════════════════
⌗ Tags: #sql #hacking #developer #bug_bounty #sql_injection
Medium
Behind the Shop: How a Simple SQLi in the Products Page Gave Me Full Access
Quick Overview
⤷ Title: Kurby DC — Easy Windows
════════════════════════
𐀪 Author: neo mask
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:05:59 GMT
════════════════════════
⌗ Tags: #writeup #hacking
════════════════════════
𐀪 Author: neo mask
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:05:59 GMT
════════════════════════
⌗ Tags: #writeup #hacking
Medium
Kurby DC — Easy Windows
Description: Unravel Active Directory secrets in Kurby DC! Face fun and engaging tasks designed to test their skills in navigating complex…
⤷ Title: HackTheBox - Nibbles
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Sun, 08 Jun 2025 23:48:49 GMT
════════════════════════
⌗ Tags: #linux #penetration_testing #hacking #cybersecurity #hackthebox
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Sun, 08 Jun 2025 23:48:49 GMT
════════════════════════
⌗ Tags: #linux #penetration_testing #hacking #cybersecurity #hackthebox
Medium
HackTheBox - Nibbles
Summary
⤷ Title: Documentation: Hardening Linux Remote Tools — SSH
════════════════════════
𐀪 Author: IndoHajk
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:34:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #ssh
════════════════════════
𐀪 Author: IndoHajk
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:34:47 GMT
════════════════════════
⌗ Tags: #cybersecurity #ssh
Medium
Documentation: Hardening Linux Remote Tools — SSH
Apa itu SSH?
⤷ Title: Why Traditional Security Frameworks Are Failing Against AI Threats (And What Actually Works)
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:04:55 GMT
════════════════════════
⌗ Tags: #threat_modeling #artificial_intelligence #cyber_security_solutions #ai_security #cybersecurity
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:04:55 GMT
════════════════════════
⌗ Tags: #threat_modeling #artificial_intelligence #cyber_security_solutions #ai_security #cybersecurity
Medium
Why Traditional Security Frameworks Are Failing Against AI Threats (And What Actually Works)
Last month, I was reviewing a client’s machine learning pipeline when something unsettling caught my attention. Their fraud detection model had been performing beautifully for eight months – until it…
⤷ Title: Dari Aplikasi ke Kabel: Mengurai Cara Kerja 7 Lapis OSI Model
════════════════════════
𐀪 Author: Muhammad Akhtar Khawarizmi
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:04:55 GMT
════════════════════════
⌗ Tags: #networking #technology #cybersecurity #information_technology #computer_science
════════════════════════
𐀪 Author: Muhammad Akhtar Khawarizmi
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:04:55 GMT
════════════════════════
⌗ Tags: #networking #technology #cybersecurity #information_technology #computer_science
Medium
Dari Aplikasi ke Kabel: Mengurai Cara Kerja 7 Lapis OSI Model
Pernahkah kamu berpikir tentang bagaimana sebuah proses digital bekerja? Saat kita mengirim email, memesan ojek online, atau memposting…
⤷ Title: CTF Writeup — TJCTF 2025 — guess-my-number
════════════════════════
𐀪 Author: embossdotar
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:00:30 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #ctf #ctf_walkthrough #ctf_writeup
════════════════════════
𐀪 Author: embossdotar
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:00:30 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyber_security_awareness #ctf #ctf_walkthrough #ctf_writeup
Medium
CTF Writeup — TJCTF 2025 — guess-my-number
Capture The Flag. CTF Writeup. TJCTF 2025 challenge
⤷ Title: Quantum-Safe Cryptography: Preparing for the Next Security Revolution
════════════════════════
𐀪 Author: Prit
════════════════════════
ⴵ Time: Sun, 08 Jun 2025 23:49:31 GMT
════════════════════════
⌗ Tags: #cybersecurity #quantum_computing #encryption
════════════════════════
𐀪 Author: Prit
════════════════════════
ⴵ Time: Sun, 08 Jun 2025 23:49:31 GMT
════════════════════════
⌗ Tags: #cybersecurity #quantum_computing #encryption
Medium
Quantum-Safe Cryptography: Preparing for the Next Security Revolution
Ever heard the term “quantum computing” and thought, “Yeah, that’s something for scientists, not me”? I used to feel the same way — until…