⤷ Title: BinSync: Revolutionizing Reverse Engineering with Git-Based Decompiler Collaboration
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:53:08 +0000
════════════════════════
⌗ Tags: #Reverse Engineering #BinSync #Collaboration #cybersecurity #Decompiler #Git #malware analysis #open source #REA #reverse engineering #Reverse Engineering Artifacts #Shellphish
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:53:08 +0000
════════════════════════
⌗ Tags: #Reverse Engineering #BinSync #Collaboration #cybersecurity #Decompiler #Git #malware analysis #open source #REA #reverse engineering #Reverse Engineering Artifacts #Shellphish
Penetration Testing Tools
BinSync: Revolutionizing Reverse Engineering with Git-Based Decompiler Collaboration
BinSync is a Git-based decompiler collaboration tool that enables fine-grained reverse engineering, syncing function headers, stack variables, structs, enums, and comments.
⤷ Title: gowitness: website screenshot utility written in Golang
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:06:30 +0000
════════════════════════
⌗ Tags: #OSINT _ Open Source Intelligence #gowitness #website screenshot
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:06:30 +0000
════════════════════════
⌗ Tags: #OSINT _ Open Source Intelligence #gowitness #website screenshot
Penetration Testing Tools
gowitness: website screenshot utility written in Golang
gowitness is a website screenshot utility written in Golang, that uses Chrome Headless to generate screenshots of web interfaces
⤷ Title: High-Severity Flaw Exposes ASUS Armoury Crate to Authentication Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:42:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Armoury Crate #ASUS #Authentication Bypass #cybersecurity #Gaming PC #privilege escalation #race condition #security update #TOCTOU #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:42:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Armoury Crate #ASUS #Authentication Bypass #cybersecurity #Gaming PC #privilege escalation #race condition #security update #TOCTOU #Vulnerability
Daily CyberSecurity
High-Severity Flaw Exposes ASUS Armoury Crate to Authentication Bypass
ASUS warns of a high-severity flaw in Armoury Crate that allows authentication bypass and privilege escalation. Update immediately!
⤷ Title: Team46 (TaxOff) Exploits Google Chrome Zero-Day (CVE-2025-2783) in Sophisticated Phishing Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:40:37 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CVE_2025_2783 #Cyberespionage #google chrome #malware #phishing #Positive Technologies #Sandbox Escape #TaxOff #Team46 #Trinper #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:40:37 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CVE_2025_2783 #Cyberespionage #google chrome #malware #phishing #Positive Technologies #Sandbox Escape #TaxOff #Team46 #Trinper #zero_day
Daily CyberSecurity
Team46 (TaxOff) Exploits Google Chrome Zero-Day (CVE-2025-2783) in Sophisticated Phishing Campaign
Team46 (TaxOff) is exploiting a Google Chrome sandbox escape zero-day (CVE-2025-2783) to deploy the multi-layered Trinper malware via phishing campaigns
⤷ Title: Critical Teleport Flaw (CVSS 9.8): Remote Authentication Bypass Threatens Infrastructure Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:36:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVE_2025_49825 #CVSS 9.8 #cybersecurity #Infrastructure Access #Remote Access #security #Teleport #Zero Trust
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:36:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVE_2025_49825 #CVSS 9.8 #cybersecurity #Infrastructure Access #Remote Access #security #Teleport #Zero Trust
Daily CyberSecurity
Critical Teleport Flaw (CVSS 9.8): Remote Authentication Bypass Threatens Infrastructure Access
Teleport disclosed a critical remote authentication bypass flaw (CVE-2025-49825) affecting self-hosted instances. Upgrade Proxies and agents immediately!
⤷ Title: CVE-2025-49596: Critical RCE Vulnerability in MCP Inspector Exposes AI Developer Environments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:35:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Development #AI security #CVE_2025_49596 #cybersecurity #Machine Context Protocol #MCP #MCP Inspector #Open Standard #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:35:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Development #AI security #CVE_2025_49596 #cybersecurity #Machine Context Protocol #MCP #MCP Inspector #Open Standard #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
CVE-2025-49596: Critical RCE Vulnerability in MCP Inspector Exposes AI Developer Environments
A critical flaw (CVE-2025-49596, CVSS 9.4) in MCP Inspector allows unauthenticated remote code execution, threatening AI application development environments.
⤷ Title: Two sslh Flaws Disclosed: Remote DoS Attacks Possible via Protocol Multiplexer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:31:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_46806 #CVE_2025_46807 #cybersecurity #Denial of Service #https #openvpn #Protocol Multiplexer #Remote DoS #ssh #sslh #SUSE #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:31:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_46806 #CVE_2025_46807 #cybersecurity #Denial of Service #https #openvpn #Protocol Multiplexer #Remote DoS #ssh #sslh #SUSE #Vulnerability
Daily CyberSecurity
Two sslh Flaws Disclosed: Remote DoS Attacks Possible via Protocol Multiplexer
SUSE disclosed flaws in sslh (CVE-2025-46807, CVE-2025-46806) allowing remote DoS attacks via file descriptor exhaustion and unsafe memory access.
⤷ Title: Unauthenticated RCE in BeyondTrust Tools: Chat Feature Opens Door to Server Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:30:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #BeyondTrust #Chat Feature #cybersecurity #PRA #Privileged Remote Access #rce #Remote Code Execution #Remote Support #Server Side Template Injection #ssti
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:30:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #BeyondTrust #Chat Feature #cybersecurity #PRA #Privileged Remote Access #rce #Remote Code Execution #Remote Support #Server Side Template Injection #ssti
Daily CyberSecurity
Unauthenticated RCE in BeyondTrust Tools: Chat Feature Opens Door to Server Takeover
BeyondTrust warns of a high-severity unauthenticated RCE flaw in Remote Support and PRA, exploitable via the built-in chat feature. Patch immediately
⤷ Title: Fileless AsyncRAT Campaign Targets German Users with Stealthy PowerShell Payload
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:28:08 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #ClickFix #CloudSEK #cybersecurity #Fileless Malware #German Users #powershell #rat #Remote Access Trojan #social engineering #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:28:08 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #ClickFix #CloudSEK #cybersecurity #Fileless Malware #German Users #powershell #rat #Remote Access Trojan #social engineering #Windows Defender Bypass
Daily CyberSecurity
Fileless AsyncRAT Campaign Targets German Users with Stealthy PowerShell Payload
A fileless AsyncRAT campaign, dubbed "Clickfix," targets German-speaking users, luring them into executing obfuscated PowerShell payloads via fake verification prompts.
⤷ Title: Water Curse: GitHub Supply Chain Attack Spreads Malware via Fake Tools, Targets Devs & Gamers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:22:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #cybersecurity #Developers #Gamers #github #malware #open_source #Red Team #social engineering #supply chain attack #threat actor #Trend Micro #Water Curse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:22:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #cybersecurity #Developers #Gamers #github #malware #open_source #Red Team #social engineering #supply chain attack #threat actor #Trend Micro #Water Curse
Daily CyberSecurity
Water Curse: GitHub Supply Chain Attack Spreads Malware via Fake Tools, Targets Devs & Gamers
Water Curse is using GitHub to distribute malicious open-source projects, weaponizing 76 accounts with multi-stage malware targeting developers, red teamers, and gamers.
⤷ Title: Apache Tomcat Patches 4 Flaws: DoS, Privilege Bypass, & Installer Risks Addressed
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:19:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2025_48976 #CVE_2025_48988 #CVE_2025_49124 #CVE_2025_49125 #Denial of Service #dos #Installer #java #Privilege Bypass #Vulnerability #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:19:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache Tomcat #CVE_2025_48976 #CVE_2025_48988 #CVE_2025_49124 #CVE_2025_49125 #Denial of Service #dos #Installer #java #Privilege Bypass #Vulnerability #web server
Daily CyberSecurity
Apache Tomcat Patches 4 Flaws: DoS, Privilege Bypass, & Installer Risks Addressed
Apache Tomcat patched four vulnerabilities affecting versions 9.0, 10.1, and 11.0, ranging from DoS to privilege bypass. Update immediately
⤷ Title: Zero-Click to Root: CISA Flags Active Exploits in Apple iOS and TP-Link Routers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:16:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Command Injection #CVE_2023_33538 #CVE_2025_43200 #cybersecurity #iCloud Link #ios #KEV Catalog #rce #Remote Code Execution #spyware #TP_Link #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:16:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Command Injection #CVE_2023_33538 #CVE_2025_43200 #cybersecurity #iCloud Link #ios #KEV Catalog #rce #Remote Code Execution #spyware #TP_Link #Vulnerability #zero_day
Daily CyberSecurity
Zero-Click to Root: CISA Flags Active Exploits in Apple iOS and TP-Link Routers
CISA adds two actively exploited zero-days to KEV: an iOS zero-click flaw used by spyware (CVE-2025-43200) and a command injection in TP-Link routers
⤷ Title: OneLogin AD Connector Flaw Exposes Credentials & Allows Account Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:16:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Impersonation #active directory #AD #AWS #cybersecurity #IAM #Identity and Access Management #OneLogin #S3 bucket #SpecterOps #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:16:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Impersonation #active directory #AD #AWS #cybersecurity #IAM #Identity and Access Management #OneLogin #S3 bucket #SpecterOps #Vulnerability
Daily CyberSecurity
OneLogin AD Connector Flaw Exposes Credentials & Allows Account Impersonation
A critical flaw in OneLogin's AD Connector exposed API keys, allowing attackers to impersonate users across organizations via unclaimed S3 buckets and forged JWT tokens.
⤷ Title: PoCGen: AI Tool Automates Exploit Generation for npm Vulnerabilities with LLMs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:12:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Dynamic Analysis #Exploit Generation #large language model #LLM #npm #PoC #PoCGen #proof_of_concept #Security Research #Static Analysis #University of Stuttgart #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:12:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Dynamic Analysis #Exploit Generation #large language model #LLM #npm #PoC #PoCGen #proof_of_concept #Security Research #Static Analysis #University of Stuttgart #Vulnerability
Daily CyberSecurity
PoCGen: AI Tool Automates Exploit Generation for npm Vulnerabilities with LLMs
PoCGen is a new AI tool using LLMs, static, and dynamic analysis to automate PoC exploit generation for npm vulnerabilities, achieving high success rates at low cost.
⤷ Title: Zyxel Firewalls Under Attack via Critical CVE-2023-28771
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:09:29 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #CVE_2023_28771 #cybersecurity #firewall #GreyNoise #Mirai botnet #rce #Remote Code Execution #UDP Port 500 #Vulnerability #Zyxel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:09:29 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #CVE_2023_28771 #cybersecurity #firewall #GreyNoise #Mirai botnet #rce #Remote Code Execution #UDP Port 500 #Vulnerability #Zyxel
Daily CyberSecurity
Zyxel Firewalls Under Attack via Critical CVE-2023-28771
Zyxel firewalls are under a coordinated attack exploiting critical RCE flaw CVE-2023-28771 (CVSS 9.8) via UDP port 500, likely by Mirai botnets. Patch immediately
⤷ Title: Hackers Leak 7.4 Million Paraguayan Citizen Records, Demand $1 Per Person Ransom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:08:12 +0000
════════════════════════
⌗ Tags: #Data Leak #cyberattack #Cybercrime #dark web #Data Breach #Espionage #Government Hack #Lumma Stealer #national security #Paraguay #PII #ransomware #Resecurity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:08:12 +0000
════════════════════════
⌗ Tags: #Data Leak #cyberattack #Cybercrime #dark web #Data Breach #Espionage #Government Hack #Lumma Stealer #national security #Paraguay #PII #ransomware #Resecurity
Daily CyberSecurity
Hackers Leak 7.4 Million Paraguayan Citizen Records, Demand $1 Per Person Ransom
Hackers leaked 7.4 million Paraguayan citizen records on the dark web, demanding a $7.4M ransom. The breach likely stems from infostealer malware, sparking national security concerns.
⤷ Title: GrayAlpha’s Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:02:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:02:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #7_Zip #Cybercrime #cybersecurity #Fake Browser Updates #FIN7 #GrayAlpha #Insikt Group #NetSupport RAT #powershell #ransomware #Recorded Future #TAG_124 #TDS
Daily CyberSecurity
GrayAlpha’s Expanding Arsenal: FIN7-Aligned Threat Actor Deploys Custom Loaders to Spread NetSupport RAT
GrayAlpha, linked to FIN7, escalates tactics with fake browser/7-Zip updates and TAG-124 TDS, spreading NetSupport RAT in a multi-pronged infection campaign.
⤷ Title: Langflow Under Attacks: CVE-2025-3248 Exploited to Deliver Stealthy Flodrix Botnet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 22:35:52 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI Applications #botnet #CVE_2025_3248 #cybersecurity #ddos #Flodrix #Langflow #open_source #rce #Remote Code Execution #shodan #Trend Micro #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 22:35:52 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI Applications #botnet #CVE_2025_3248 #cybersecurity #ddos #Flodrix #Langflow #open_source #rce #Remote Code Execution #shodan #Trend Micro #Vulnerability
Daily CyberSecurity
Langflow Under Attacks: CVE-2025-3248 Exploited to Deliver Stealthy Flodrix Botnet
A critical RCE flaw (CVE-2025-3248) in Langflow is being actively exploited to deploy the stealthy Flodrix botnet for reconnaissance and diverse DDoS attacks on AI app servers.
⤷ Title: Cómo Usar Subfinder para Bug Bounty: Guía Completa con Ejemplos y Tips Avanzados
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:01:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #penetration_testing #infosec
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:01:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #penetration_testing #infosec
Medium
Cómo Usar Subfinder para Bug Bounty: Guía Completa con Ejemplos y Tips Avanzados
Descubre cómo usar Subfinder para enumerar subdominios en Bug Bounty. Guía práctica, ejemplos, APIs y automatización.
⤷ Title: Reflected XSS Exposed: How a Simple Query Parameter Exposed Informatica’s
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 23:48:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #tips_and_tricks #bug_bounty #technology #hacking
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 23:48:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #tips_and_tricks #bug_bounty #technology #hacking
Medium
Reflected XSS Exposed: How a Simple Query Parameter Exposed Informatica’s
Uncovering a Cross-Site Scripting flaw and how you can spot similar bugs using modern tools
⤷ Title: Fuzzing Hidden HTTP Methods for Admin Access
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 23:48:29 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #penetration_testing #technology #bug_bounty
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 23:48:29 GMT
════════════════════════
⌗ Tags: #hacking #bug_bounty_tips #penetration_testing #technology #bug_bounty
Medium
Fuzzing Hidden HTTP Methods for Admin Access
How overlooked HTTP verbs can unlock sensitive functions and hidden admin panels