⤷ Title: Urgent CISA Alert: Ransomware Actors Exploiting SimpleHelp RMM Flaw (CVE-2024-57727)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:47:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #CISA #CVE_2024_57727 #cybersecurity #Double Extortion #Path Traversal #ransomware #Remote Monitoring and Management #SimpleHelp RMM #supply chain attack #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:47:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #CISA #CVE_2024_57727 #cybersecurity #Double Extortion #Path Traversal #ransomware #Remote Monitoring and Management #SimpleHelp RMM #supply chain attack #Vulnerability
Daily CyberSecurity
Urgent CISA Alert: Ransomware Actors Exploiting SimpleHelp RMM Flaw (CVE-2024-57727)
CISA warns of active exploitation of a SimpleHelp RMM flaw (CVE-2024-57727) by ransomware actors, impacting utility billing software providers and their customers.
⤷ Title: Warning: Discontinued Amazon Cloud Cam Has Vulnerability (CVE-2025-6031), Exposing Your Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:25:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Amazon Cloud Cam #CVE_2025_6031 #cybersecurity #end_of_life #EOL #IOT #network_security #Security Camera #Smart Home #SSL Pinning #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:25:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Amazon Cloud Cam #CVE_2025_6031 #cybersecurity #end_of_life #EOL #IOT #network_security #Security Camera #Smart Home #SSL Pinning #Vulnerability
Daily CyberSecurity
Warning: Discontinued Amazon Cloud Cam Has Vulnerability (CVE-2025-6031), Exposing Your Network
A new flaw (CVE-2025-6031) in the discontinued Amazon Cloud Cam allows attackers to intercept network traffic, highlighting risks of unsupported smart home devices.
⤷ Title: Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:08:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #Brute Force #cyberattack #cybersecurity #DigitalOcean #GreyNoise #Login Attempts #Tomcat Manager #Web Security #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 02:08:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #Brute Force #cyberattack #cybersecurity #DigitalOcean #GreyNoise #Login Attempts #Tomcat Manager #Web Security #web server
Daily CyberSecurity
Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces
GreyNoise reports a massive brute-force campaign targeting Apache Tomcat Manager interfaces, with hundreds of malicious IPs attempting to compromise services.
⤷ Title: The Day the Internet Broke: Unpacking the June 12th Global Cloud Meltdown
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 01:42:19 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Failure #cloudflare #Digital Services #Global Disruption #Google Cloud #Internet Outage #June 2025 #Tech Downtime
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 01:42:19 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Failure #cloudflare #Digital Services #Global Disruption #Google Cloud #Internet Outage #June 2025 #Tech Downtime
Daily CyberSecurity
The Day the Internet Broke: Unpacking the June 12th Global Cloud Meltdown
Explore the massive June 12, 2025 global cloud outage that took down Google, Cloudflare, and more. Uncover the ripple effects and lingering questions from this unprecedented digital disruption.
⤷ Title: Critical Path Traversal Vulnerability (CVSS 9.8) Exposes Mitel MiCollab Servers to Unauthorized Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:40:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #critical #cybersecurity #MiCollab #Mitel #Patch Now #Path Traversal #security advisory #unauthenticated access #Unified Communications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:40:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #critical #cybersecurity #MiCollab #Mitel #Patch Now #Path Traversal #security advisory #unauthenticated access #Unified Communications
Daily CyberSecurity
Critical Path Traversal Vulnerability (CVSS 9.8) Exposes Mitel MiCollab Servers to Unauthorized Access
Mitel warns of a critical path traversal flaw (CVSS 9.8) in MiCollab, allowing unauthenticated attackers to access provisioning data and perform admin actions.
⤷ Title: Urgent Bosch Alert: Critical RCE Flaw (CVSS 10.0) Exposes Dispatch & Matrix Software to Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:35:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bosch #Critical Infrastructure #CVE_2025_29902 #CVSS 10.0 #cybersecurity #rce #Remote Code Execution #RTS VLink #security advisory #Telex RDC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:35:25 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bosch #Critical Infrastructure #CVE_2025_29902 #CVSS 10.0 #cybersecurity #rce #Remote Code Execution #RTS VLink #security advisory #Telex RDC
Daily CyberSecurity
Urgent Bosch Alert: Critical RCE Flaw (CVSS 10.0) Exposes Dispatch & Matrix Software to Attack
Bosch warns of a critical RCE flaw (CVSS 10.0, CVE-2025-29902) in Telex RDC Server and RTS VLink, allowing unauthenticated remote code execution. Patch immediately!
⤷ Title: TeamFiltration Weaponized: UNK_SneakyStrike Campaign Targets 80,000+ Microsoft Entra ID Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:30:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #ATO #AWS #cyberattack #cybersecurity #Microsoft 365 #Microsoft Entra ID #OAuth #Password Spraying #Proofpoint #TeamFiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:30:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #ATO #AWS #cyberattack #cybersecurity #Microsoft 365 #Microsoft Entra ID #OAuth #Password Spraying #Proofpoint #TeamFiltration
Daily CyberSecurity
TeamFiltration Weaponized: UNK_SneakyStrike Campaign Targets 80,000+ Microsoft Entra ID Accounts
TeamFiltration is being actively exploited in UNK_SneakyStrike, targeting over 80,000 Microsoft Entra ID accounts with password spraying and data exfiltration.
⤷ Title: Critical CI/CD Cache Poisoning Threatens Supply Chain: Undetectable Code Injection Possible!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:22:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #CI/CD #cloud storage #code_injection #cybersecurity #privilege escalation #Remote Cache #Software Supply Chain #Supply Chain Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:22:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cache Poisoning #CI/CD #cloud storage #code_injection #cybersecurity #privilege escalation #Remote Cache #Software Supply Chain #Supply Chain Security
Daily CyberSecurity
Critical CI/CD Cache Poisoning Threatens Supply Chain: Undetectable Code Injection Possible!
A critical CI/CD flaw in remote caches allows undetectable code injection and privilege escalation via cache poisoning, bypassing all security controls.
⤷ Title: Flaw in PostgreSQL JDBC Driver (CVE-2025-49146) Exposes Database Connections to MITM Attacks!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:18:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49146 #cybersecurity #database security #java #JDBC #Man in the Middle #mitm #pgjdbc #PostgreSQL #SSL/TLS #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:18:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49146 #cybersecurity #database security #java #JDBC #Man in the Middle #mitm #pgjdbc #PostgreSQL #SSL/TLS #Vulnerability
Daily CyberSecurity
Flaw in PostgreSQL JDBC Driver (CVE-2025-49146) Exposes Database Connections to MITM Attacks!
A flaw (CVE-2025-49146) in PostgreSQL JDBC Driver allows MITM attacks even with channel binding enabled. Upgrade to v42.7.7 or use sslMode=verify-full.
⤷ Title: High-Severity Flaw in HashiCorp Nomad (CVE-2025-4922) Allows Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:13:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control List #ACL #CVE_2025_4922 #cybersecurity #HashiCorp Nomad #Nomad #privilege escalation #security patch #Vulnerability #Workload Orchestration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:13:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control List #ACL #CVE_2025_4922 #cybersecurity #HashiCorp Nomad #Nomad #privilege escalation #security patch #Vulnerability #Workload Orchestration
Daily CyberSecurity
High-Severity Flaw in HashiCorp Nomad (CVE-2025-4922) Allows Privilege Escalation
A high-severity flaw (CVE-2025-4922) in HashiCorp Nomad allows privilege escalation via ACL policy lookup. Upgrade to Nomad 1.10.2 (or later) immediately.
⤷ Title: DeepSeek-R1 Chatbot Lure: BrowserVenom Malware Spreads via Google Ads, Hijacking Your Browser Traffic
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:09:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:09:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals
Daily CyberSecurity
DeepSeek-R1 Chatbot Lure: BrowserVenom Malware Spreads via Google Ads, Hijacking Your Browser Traffic
BrowserVenom malware is spreading via fake DeepSeek-R1 Google Ads, installing a proxy implant that hijacks all browser traffic. Beware of fake LLM installers.
⤷ Title: HelloTDS Unmasked: Covert Traffic System Funnels Millions to FakeCaptcha Malware!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:02:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #cybersecurity #FakeCaptcha #Gen Threat Labs #HelloTDS #information stealer #LummaC2 #malware #phishing #social engineering #TDS #Traffic Direction System
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:02:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #cybersecurity #FakeCaptcha #Gen Threat Labs #HelloTDS #information stealer #LummaC2 #malware #phishing #social engineering #TDS #Traffic Direction System
Daily CyberSecurity
HelloTDS Unmasked: Covert Traffic System Funnels Millions to FakeCaptcha Malware!
HelloTDS is a sophisticated traffic direction system delivering millions to FakeCaptcha and other malware via advanced fingerprinting and evasive tactics.
⤷ Title: The Most Underrated 0-Click Account Takeover Using Punycode IDN Attacks
════════════════════════
𐀪 Author: coffinxp
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 08:10:31 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #bug_bounty #hacking #pentesting
════════════════════════
𐀪 Author: coffinxp
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 08:10:31 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #bug_bounty #hacking #pentesting
Medium
The Most Underrated 0-Click Account Takeover Using Punycode IDN Homograph Attacks
Hackers Are Earning 💸$XX,000+ With This Secret Trick — Now It’s Your Turn
⤷ Title: Utilising Context Augmentation in LLMs for Bug Bounty
════════════════════════
𐀪 Author: Spectat0rguy
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:37:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #programming #information_technology #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Spectat0rguy
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:37:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #programming #information_technology #cybersecurity #artificial_intelligence
Medium
Utilising Context Augmentation in LLMs for Bug Bounty
How to improve your recon and reporting using augmented context with large language models
⤷ Title: Web Cache Deception — The Vulnerability Even Developers Don’t See Coming
════════════════════════
𐀪 Author: phoenixcatalan
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:37:03 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #cybersecurity #ethical_hacking #web_security
════════════════════════
𐀪 Author: phoenixcatalan
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:37:03 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty #cybersecurity #ethical_hacking #web_security
Medium
💥 Web Cache Deception — The Vulnerability Even Developers Don’t See Coming
Exploiting path mapping for web cache deception — a subtle yet powerful technique.
⤷ Title: Header Hijinks: How X-Forwarded-For Gave Me Internal Access
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:34:01 GMT
════════════════════════
⌗ Tags: #infosec #money #cybersecurity #bug_bounty #hacking
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:34:01 GMT
════════════════════════
⌗ Tags: #infosec #money #cybersecurity #bug_bounty #hacking
Medium
Header Hijinks: How X-Forwarded-For Gave Me Internal Access 🚧🧠
Hey there!😁
⤷ Title: $7,500 Bounty: Exposed Any User’s Email on HackerOne
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:32:29 GMT
════════════════════════
⌗ Tags: #bug_bounty #tips_and_tricks #technology #penetration_testing #hackerone
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 05:32:29 GMT
════════════════════════
⌗ Tags: #bug_bounty #tips_and_tricks #technology #penetration_testing #hackerone
Medium
$7,500 Bounty: Exposed Any User’s Email on HackerOne
A Subtle Enumeration Bug That Let Attackers Harvest Emails Before Invitations Were Accepted — $7,500 Bounty
⤷ Title: GraphQL in the Wild: Recon to RCE via Introspection, Nested Queries & Batching Attacks
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:14:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #bug_bounty_tips #penetration_testing #technology
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:14:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #bug_bounty_tips #penetration_testing #technology
Medium
GraphQL in the Wild: Recon to RCE via Introspection, Nested Queries & Batching Attacks
How Modern APIs Are Giving Hackers a Query Language for Mayhem
⤷ Title: Cracking JWTs: A Bug Bounty Hunting Guide [Part 7] — The Final P1 Boss
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:13:31 GMT
════════════════════════
⌗ Tags: #jwt_authentication #jwt #cybersecurity #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Aditya Bhatt
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:13:31 GMT
════════════════════════
⌗ Tags: #jwt_authentication #jwt #cybersecurity #bug_bounty #bug_bounty_writeup
Medium
Cracking JWTs: A Bug Bounty Hunting Guide [Part 7] — The Final P1 Boss 🔓
JWT Authentication Bypass via Algorithm Confusion Exploit Without Key Disclosure
⤷ Title: How a Simple RECON Earned Me ₹XX,000
════════════════════════
𐀪 Author: Swarnim Bandekar
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:11:23 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_writeup #hacking #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: Swarnim Bandekar
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 06:11:23 GMT
════════════════════════
⌗ Tags: #infosec #bug_bounty_writeup #hacking #penetration_testing #bug_bounty
Medium
💰 How a Simple RECON Earned Me ₹XX,000
Security bugs aren’t always flashy. Sometimes, you don’t need to pop a shell or find an RCE to make an impact.
Sometimes… all you need is…
Sometimes… all you need is…
⤷ Title: Intigriti Bug Bytes #225 - June 2025 🚀
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 13 Jun 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
Intigriti
Intigriti Bug Bytes #225 - June 2025 🚀
Hello hackers, Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Becoming an Intigriti Pentester Exploiting CORS in 2025 (even when SameSite is set to ‘Strict’) A...