πNew WriteupβοΈ
βββββββββββββββ
πDate: Tue, 18 Apr 2023 23:31:21 GMT
βββββββββββββββ
βοΈTitle: Chinese Hackers Turn Googleβs Ethical Hacking Tool into a Security Threat: Cybersecurity Expertsβ¦
βββββββββββββββ
πLink: https://medium.com/p/10865b2fac90
βββββββββββββββ
Tags: #cybercrime #tag #hacking #cybersecurity #news
βββββββββββββββ
πDate: Tue, 18 Apr 2023 23:31:21 GMT
βββββββββββββββ
βοΈTitle: Chinese Hackers Turn Googleβs Ethical Hacking Tool into a Security Threat: Cybersecurity Expertsβ¦
βββββββββββββββ
πLink: https://medium.com/p/10865b2fac90
βββββββββββββββ
Tags: #cybercrime #tag #hacking #cybersecurity #news
Medium
Chinese Hackers Turn Googleβs Ethical Hacking Tool into a Security Threat: Cybersecurity Experts Warn of GC2 Abuse
According to recent reports, Chinese hackers have turned Googleβs ethical hacking tool, Command, and Control (GC2), into a real securityβ¦
β€· Title: TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 05 Feb 2025 01:50:10 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #CleanUpLoader #D3F@ck Loader #Interlock #Rhysida #SocGholish #TA866/Asylum Ambuscade #TAG_124 #traffic distribution system
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 05 Feb 2025 01:50:10 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #CleanUpLoader #D3F@ck Loader #Interlock #Rhysida #SocGholish #TA866/Asylum Ambuscade #TAG_124 #traffic distribution system
Cybersecurity News
TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns
Uncover the TAG-124 traffic distribution system used by cybercriminals to spread malware, phishing pages, and fake browser updates.
β€· Title: MintsLoader Malware: Advanced Evasion Techniques Target Industrial Sector
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 04 May 2025 00:32:09 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #Cybercrime #evasion techniques #malware #MintsLoader #Payload Delivery #TAG_124 #threat analysis
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 04 May 2025 00:32:09 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #Cybercrime #evasion techniques #malware #MintsLoader #Payload Delivery #TAG_124 #threat analysis
Daily CyberSecurity
MintsLoader Malware: Advanced Evasion Techniques Target Industrial Sector
Recorded Future analysis exposes MintsLoader, a stealthy malware loader using advanced evasion to target industrial, legal, and energy sectors.
β€· Title: Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 26 May 2025 00:20:40 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #Government #malware #phishing #russia #TAG_110 #Tajikistan
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 26 May 2025 00:20:40 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT28 #cyber_espionage #cybersecurity #Government #malware #phishing #russia #TAG_110 #Tajikistan
Daily CyberSecurity
Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
Russian-aligned TAG-110 (APT28) is launching a cyber-espionage campaign using macro-enabled Word docs to target Tajikistan's public sector for intelligence.
β€· Title: GrayAlphaβs Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 17 Jun 2025 00:02:46 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 17 Jun 2025 00:02:46 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
Daily CyberSecurity
GrayAlphaβs Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
GrayAlpha, linked to FIN7, escalates tactics with fake browser/7-Zip updates and TAG-124 TDS, spreading NetSupport RAT in a multi-pronged infection campaign.
β€· Title: Pakistan-Aligned APT36 Unleashes DRAT V2: New Delphi RAT Targets Indian Government
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 08 Jul 2025 02:43:31 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #APT36 #ClickFix #Cyberespionage #DRAT V2 #Government #India #phishing #RAT #Remote Access Trojan #SideCopy #TAG_140 #Transparent Tribe
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 08 Jul 2025 02:43:31 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #APT36 #ClickFix #Cyberespionage #DRAT V2 #Government #India #phishing #RAT #Remote Access Trojan #SideCopy #TAG_140 #Transparent Tribe
Penetration Testing Tools
Pakistan-Aligned APT36 Unleashes DRAT V2: New Delphi RAT Targets Indian Government
Pakistan-aligned APT36 (TAG-140) unleashes DRAT V2, a new Delphi-compiled RAT, in a cyber-espionage campaign targeting Indian government entities via ClickFix social engineering.
β€· Title: Reflected XSS in HTML Context with All Standard Tags Blocked Except Custom Ones
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 02 Aug 2025 11:23:24 GMT
ββββββββββββββββββββββββ
β Tags: #tag_filter_bypass #xss_in_html_context #reflected_xss #xss_payload #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 02 Aug 2025 11:23:24 GMT
ββββββββββββββββββββββββ
β Tags: #tag_filter_bypass #xss_in_html_context #reflected_xss #xss_payload #bug_bounty
Medium
Reflected XSS in HTML Context with All Standard Tags Blocked Except Custom Ones
Discover how attackers bypass tag filters using custom HTML elements and event handlers to trigger XSS.
β€· Title: Blind Eagleβs Expanding Cyber Campaigns: Five Clusters Targeting Colombiaβs Government and Beyond
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 29 Aug 2025 04:44:19 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Blind Eagle #Colombia #Cyber Espionage #phishing attacks #RAT malware #Recorded Future #supply chain threats #TAG_144
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 29 Aug 2025 04:44:19 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Blind Eagle #Colombia #Cyber Espionage #phishing attacks #RAT malware #Recorded Future #supply chain threats #TAG_144
Penetration Testing Tools
Blind Eagleβs Expanding Cyber Campaigns: Five Clusters Targeting Colombiaβs Government and Beyond
Recorded Future links Blind Eagle to five attack clusters targeting Colombiaβs government and critical sectors, exposing cyber espionage and data theft risks.
β€· Title: Google Patches Actively Exploited Chrome Zero-Day Flaw (CVE-2025-13223) in Emergency Update
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 17 Nov 2025 23:03:13 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #browser security #chrome #CVE_2025_13223 #cybersecurity #google #patch #Remote Code Execution #tag #Type Confusion #V8 #zero_day
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 17 Nov 2025 23:03:13 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #browser security #chrome #CVE_2025_13223 #cybersecurity #google #patch #Remote Code Execution #tag #Type Confusion #V8 #zero_day
Daily CyberSecurity
Google Patches Actively Exploited Chrome Zero-Day Flaw (CVE-2025-13223) in Emergency Update
Google released an emergency Chrome update (142.0.7444.175) to patch two V8 Type Confusion flaws. One zero-day (CVE-2025-13223) is actively exploited. Update now!
β€· Title: New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 01 Dec 2025 00:19:22 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 01 Dec 2025 00:19:22 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
Daily CyberSecurity
New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
Darktrace exposed TAG-150, a new MaaS operator compromising 469+ US devices in months. The group uses ClickFix to trick victims into running malicious PowerShell that deploys the CastleLoader/CastleRAT backdoor.
β€· Title: CastleLoader PhaaS: GrayBravo Escalates Attacks on Logistics & Booking.com
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 13 Dec 2025 10:28:44 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Booking.com #CastleLoader #cybercrime #GrayBravo #Logistics #Malware_as_a_Service #PhaaS #phishing #Recorded Future #TAG_160
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 13 Dec 2025 10:28:44 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Booking.com #CastleLoader #cybercrime #GrayBravo #Logistics #Malware_as_a_Service #PhaaS #phishing #Recorded Future #TAG_160
Penetration Testing Tools
CastleLoader PhaaS: GrayBravo Escalates Attacks on Logistics & Booking.com
The cybercriminal group GrayBravo, formerly known as TAG-150, continues to evolve at a rapid pace, demonstrating a high
β€· Title: The Mutable Tag Trap: Critical 9.4 CVSS Attack on Xygeni GitHub Action Exposes CI/CD Pipelines
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 12 Mar 2026 04:26:38 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #Vulnerability Report #C2 Backdoor #CI/CD security #CVE_2026_31976 #cybersecurity #DevSecOps #GitHub Actions #infosec #supply chain attack #Tag Poisoning #Xygeni
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 12 Mar 2026 04:26:38 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #Vulnerability Report #C2 Backdoor #CI/CD security #CVE_2026_31976 #cybersecurity #DevSecOps #GitHub Actions #infosec #supply chain attack #Tag Poisoning #Xygeni
Daily CyberSecurity
The Mutable Tag Trap: Critical 9.4 CVSS Attack on Xygeni GitHub Action Exposes CI/CD Pipelines
A critical 9.4 CVSS tag poisoning attack (CVE-2026-31976) hit the xygeni-action GitHub Action, injecting a C2 backdoor into CI/CD pipelines. Update now.
β€· Title: The Tag Trap: How a Single Commit Swap Turned Xygeniβs GitHub Action into a Clandestine Backdoor
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 12 Mar 2026 07:21:26 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #CI/CD Security #DevOps Security #GitHub Actions #GitHub Token Theft #malware #RCE #StepSecurity #supply chain attack #Tag Poisoning #Tech News 2026 #v5 tag #Xygeni
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 12 Mar 2026 07:21:26 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #CI/CD Security #DevOps Security #GitHub Actions #GitHub Token Theft #malware #RCE #StepSecurity #supply chain attack #Tag Poisoning #Tech News 2026 #v5 tag #Xygeni
Penetration Testing Tools
The Tag Trap: How a Single Commit Swap Turned Xygeniβs GitHub Action into a Clandestine Backdoor
An imperceptible edit to a single tag transformed a ubiquitous security auditing instrument into a clandestine backdoor. A
β€1
β€· Title: TAG-182 Threat Cluster Spreads MarkiRAT Malware
ββββββββββββββββββββββββ
πͺ Author: Do Son
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 06 Jul 2026 07:58:54 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Insikt Group #Iran Surveillance #MarkiRAT #Recorded Future #TAG_182
ββββββββββββββββββββββββ
πͺ Author: Do Son
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 06 Jul 2026 07:58:54 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Insikt Group #Iran Surveillance #MarkiRAT #Recorded Future #TAG_182
Daily CyberSecurity
TAG-182 Threat Cluster Spreads MarkiRAT Malware
At a glance: Actor/Group: TAG-182 threat cluster (suspected Iran-nexus) Activity Type: Cyber surveillance and malware distribution Targets/Victims: Iranian citizens and dissidents worldwide Scale:β¦