⤷ Title: ASP.NET Vulnerability Lets Hackers Hijack Servers, Inject Malicious Code
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 07 Feb 2025 21:35:43 +0000
════════════════════════
⌗ Tags: #Security #Microsoft #ASP.NET #Cybersecurity #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 07 Feb 2025 21:35:43 +0000
════════════════════════
⌗ Tags: #Security #Microsoft #ASP.NET #Cybersecurity #Vulnerability
Hackread
ASP.NET Vulnerability Lets Hackers Hijack Servers, Inject Malicious Code
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
⤷ Title: Russian APT UNC6293 Exploits Google Application-Specific Passwords to Hack Critics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 00:28:22 +0000
════════════════════════
⌗ Tags: #Cyber Security #Application_Specific Passwords #APT29 #ASP #Cyberespionage #Google Accounts #Google Threat Intelligence #phishing #Russian APT #social engineering #state_sponsored #UNC6293
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Jun 2025 00:28:22 +0000
════════════════════════
⌗ Tags: #Cyber Security #Application_Specific Passwords #APT29 #ASP #Cyberespionage #Google Accounts #Google Threat Intelligence #phishing #Russian APT #social engineering #state_sponsored #UNC6293
Daily CyberSecurity
Russian APT UNC6293 Exploits Google Application-Specific Passwords to Hack Critics
A Russian state-sponsored APT, UNC6293 (likely APT29), is exploiting Google Application-Specific Passwords in a sophisticated phishing campaign targeting critics of Russia
⤷ Title: Gold Melody’s Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
Daily CyberSecurity
Gold Melody's Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
Unit 42 reveals "Gold Melody" uses leaked ASP.NET Machine Keys to achieve in-memory RCE via View State deserialization and privilege escalation via GodPotato, compromising web servers.
⤷ Title: Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
Penetration Testing Tools
Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
Gold Melody (Prophet Spider) is exploiting leaked ASP.NET machine keys to launch stealthy, memory-only attacks on global corporate systems.
⤷ Title: .NET 10 (Preview 7): Microsoft Unveils WebSocket Streaming and Passkey Support
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 23:25:12 +0000
════════════════════════
⌗ Tags: #Microsoft #.NET 10 #.NET MAUI #ASP.NET Core #C# 14 #developer tools #Passkeys #WebSockets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 17 Aug 2025 23:25:12 +0000
════════════════════════
⌗ Tags: #Microsoft #.NET 10 #.NET MAUI #ASP.NET Core #C# 14 #developer tools #Passkeys #WebSockets
Penetration Testing Tools
.NET 10 (Preview 7): Microsoft Unveils WebSocket Streaming and Passkey Support
Microsoft's new .NET 10 Preview 7 brings a WebSocket streaming API, improved passkey authentication, and faster MAUI builds with a new XAML source generator.
⤷ Title: Critical HTTP Smuggling Flaw Patched in Microsoft ASP.NET Core Kestrel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 03:57:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASP.NET #cybersecurity #HTTP Smuggling #Microsoft #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 03:57:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #ASP.NET #cybersecurity #HTTP Smuggling #Microsoft #vulnerability
Penetration Testing Tools
Critical HTTP Smuggling Flaw Patched in Microsoft ASP.NET Core Kestrel
Microsoft patched a critical HTTP Request Smuggling flaw (CVE-2025-55315) in ASP.NET Core Kestrel that could lead to data exfiltration and session hijacking.
⤷ Title: Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
Daily CyberSecurity
Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
Elastic exposed Chinese threat actors exploiting public ASP.NET machine keys to deploy TOLLBOOTH IIS backdoor and HIDDENDRIVER kernel rootkit. The malware performs stealthy SEO cloaking.
⤷ Title: Critical .NET Flaw (CVE-2025-55315) in QNAP: NAS Backup Utility Vulnerable to Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 04:16:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASP.NET #cybersecurity #http_request_smuggling #Microsoft #NetBak #QNAP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 04:16:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASP.NET #cybersecurity #http_request_smuggling #Microsoft #NetBak #QNAP
Daily CyberSecurity
Critical .NET Flaw (CVE-2025-55315) in QNAP: NAS Backup Utility Vulnerable to Credential Theft
QNAP warns its NetBak PC Agent users to patch a critical ASP.NET Core flaw (CVSS 9.8) that allows attackers to hijack credentials via HTTP request smuggling.
⤷ Title: Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:27:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT41 #ASP.NET #Check Point Research #cyber_espionage #Earth Alux #IIS Listener #Ink Dragon #Microsoft Graph API #Relay Network #ShadowPad
Daily CyberSecurity
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes
Ink Dragon is weaponizing government servers in Europe using a relay-centric mesh. By hijacking IIS servers, they mask C2 traffic across global networks.
⤷ Title: Malicious NuGet Packages Weaponize ASP.NET Identity for Production Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 00:13:36 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Security #C2 Server #Identity and Access Management #infosec #Malware Dropper #NCryptYo #NuGet Attack #Socket Threat Research #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 00:13:36 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Security #C2 Server #Identity and Access Management #infosec #Malware Dropper #NCryptYo #NuGet Attack #Socket Threat Research #supply chain attack #Typosquatting
Daily CyberSecurity
Malicious NuGet Packages Weaponize ASP.NET Identity for Production Backdoors
Socket researchers uncover a NuGet supply chain attack using "NCryptYo" to hijack ASP.NET apps. Attackers inject backdoors into production authorization layers.
⤷ Title: Emergency .NET Update: Critical Data Protection Flaw Allows Authentication Forgery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 02:21:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET 10 #ASP.NET Core #Authentication Bypass #CVE_2026_40372 #Data Protection #infosec #Key Rotation #Linux Security #macOS #Microsoft #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 02:21:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET 10 #ASP.NET Core #Authentication Bypass #CVE_2026_40372 #Data Protection #infosec #Key Rotation #Linux Security #macOS #Microsoft #privilege escalation
Daily CyberSecurity
Emergency .NET Update: Critical Data Protection Flaw Allows Authentication Forgery
Microsoft's OOB update for .NET 10 (CVE-2026-40372) hits Linux/macOS users. Authentication is at risk. Stop the bypass and rotate your keys today.