⤷ Title: How I Forged a Facebook JWT to Impersonate Any User on Wit.ai (No Secret Verification)
════════════════════════
𐀪 Author: Ramzy Bouyahya
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 22:50:27 GMT
════════════════════════
⌗ Tags: #facebook_bug_bounty #facebook #meta_bug_bounty #wit #bug_bounty_writeup
════════════════════════
𐀪 Author: Ramzy Bouyahya
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 22:50:27 GMT
════════════════════════
⌗ Tags: #facebook_bug_bounty #facebook #meta_bug_bounty #wit #bug_bounty_writeup
Medium
How I Forged a Facebook JWT to Impersonate Any User on Wit.ai (No Secret Verification)
During a routine test of Wit.ai’s Facebook login integration, I discovered a critical vulnerability where the backend fails to verify the…
⤷ Title: FrogPost: postMessage Security Testing Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:07:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Chrome extension #cybersecurity #DOM_based XSS #FrogPost #Fuzzing #Iframes #postMessage #security testing #Vulnerability Analysis #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:07:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Chrome extension #cybersecurity #DOM_based XSS #FrogPost #Fuzzing #Iframes #postMessage #security testing #Vulnerability Analysis #web security
Penetration Testing Tools
FrogPost: postMessage Security Testing Tool
FrogPost is a powerful Chrome extension for security researchers, enabling live monitoring, analysis, and fuzzing of postMessage communications to find iframe vulnerabilities.
⤷ Title: Proofpoint Exposes TA829 & UNK_GreenSec’s Dual-Nature Campaigns
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:52:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Cybercriminal Overlap #Espionage #Morpheus ransomware #Proofpoint #RomCom #Russian APT #TA829 #threat intelligence #TransferLoader #UNK_GreenSec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:52:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Cybercriminal Overlap #Espionage #Morpheus ransomware #Proofpoint #RomCom #Russian APT #TA829 #threat intelligence #TransferLoader #UNK_GreenSec
Daily CyberSecurity
Proofpoint Exposes TA829 & UNK_GreenSec's Dual-Nature Campaigns
Proofpoint reveals two Russian threat clusters (TA829 & UNK_GreenSec) blending financial cybercrime with state-aligned espionage, using RomCom and TransferLoader malware.
⤷ Title: Critical RCE in MCP Inspector Exposes AI Devs to Web-Based Exploits (CVE-2025-49596)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0.0.0.0_day #AI Development #AI security #CVE_2025_49596 #cybersecurity #Machine Context Protocol #MCP #MCP Inspector #Oligo Security #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:36:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #0.0.0.0_day #AI Development #AI security #CVE_2025_49596 #cybersecurity #Machine Context Protocol #MCP #MCP Inspector #Oligo Security #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Critical RCE in MCP Inspector Exposes AI Devs to Web-Based Exploits (CVE-2025-49596)
⤷ Title: From Code to Crypto Theft: DOJ Charges Four North Koreans for Infiltrating U.S. Companies and Laundering $900K in Virtual Currency
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:20:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:20:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
Daily CyberSecurity
From Code to Crypto Theft: DOJ Charges Four North Koreans for Infiltrating U.S. Companies and Laundering $900K in Virtual Currency
The DOJ dismantled a North Korean scheme exploiting remote IT jobs at 100+ U.S. firms, using stolen identities and laundering millions to fund DPRK weapons programs.
⤷ Title: North Korea’s AI-Powered Cybercrime: Deepfakes & Fake Personas Infiltrate 300+ US Companies via Remote IT Jobs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:13:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #artificial intelligence #Cybercrime #cybersecurity #deepfake #identity theft #Jasper Sleet #Microsoft Threat Intelligence #North Korea #Remote IT Workers #Sanctions Evasion #Storm_0287
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:13:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #artificial intelligence #Cybercrime #cybersecurity #deepfake #identity theft #Jasper Sleet #Microsoft Threat Intelligence #North Korea #Remote IT Workers #Sanctions Evasion #Storm_0287
Daily CyberSecurity
North Korea's AI-Powered Cybercrime: Deepfakes & Fake Personas Infiltrate 300+ US Companies via Remote IT Jobs
Microsoft exposes North Korea’s Jasper Sleet (Storm-0287) using AI-enhanced deepfakes and fake personas to secure remote IT jobs at 300+ US firms, funding the DPRK regime and stealing data.
⤷ Title: DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:53:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:53:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
Daily CyberSecurity
DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
The DOJ dismantled a North Korean scheme exploiting remote IT jobs at 100+ U.S. firms, using stolen identities and laundering millions to fund DPRK weapons programs.
⤷ Title: Blind Eagle (APT-C-36): Financially Motivated Cybercrime Meets Open-Access Infrastructure in LATAM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:44:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #APT_C_36 #AsyncRAT #Blind Eagle #Colombia #Cybercrime #Exposed C2 #Latin America #phishing #rat #Remcos #Remote Access Trojan #Trustwave #VBS Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:44:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #APT_C_36 #AsyncRAT #Blind Eagle #Colombia #Cybercrime #Exposed C2 #Latin America #phishing #rat #Remcos #Remote Access Trojan #Trustwave #VBS Malware
Daily CyberSecurity
Blind Eagle (APT-C-36): Financially Motivated Cybercrime Meets Open-Access Infrastructure in LATAM
Trustwave exposes Blind Eagle (APT-C-36) leveraging exposed infrastructure and VBS malware in phishing campaigns, targeting Colombian banks with blatant disregard for concealment.
⤷ Title: Google Patches Actively Exploited Chrome Zero-Day: CVE-2025-6554
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:34:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #chrome #CVE_2025_6554 #cybersecurity #Exploited in Wild #google chrome #JavaScript Engine #rce #Remote Code Execution #Type Confusion #V8 #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:34:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #chrome #CVE_2025_6554 #cybersecurity #Exploited in Wild #google chrome #JavaScript Engine #rce #Remote Code Execution #Type Confusion #V8 #Vulnerability #zero_day
Daily CyberSecurity
Google Patches Actively Exploited Chrome Zero-Day: CVE-2025-6554
Google has urgently patched a high-severity zero-day (CVE-2025-6554) in Chrome's V8 JavaScript engine. This type confusion flaw is actively exploited in the wild, risking RCE.
⤷ Title: gf: Tu Aliado Indispensable para el Reconocimiento y Detección de Vulnerabilidades en Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:01:29 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #ethical_hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:01:29 GMT
════════════════════════
⌗ Tags: #infosec #penetration_testing #ethical_hacking #cybersecurity #bug_bounty
Medium
gf: Tu Aliado Indispensable para el Reconocimiento y Detección de Vulnerabilidades en Bug Bounty
Descubre gf y sus patrones para filtrar datos sensibles, detectar vulnerabilidades y optimizar tu reconocimiento en pentesting y bug bounty.
⤷ Title: Flash USDT Explained – For Educational Purposes Only
════════════════════════
𐀪 Author: Picaga
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:10:07 GMT
════════════════════════
⌗ Tags: #cryptocurrency #defi #programming #cybersecurity #web3
════════════════════════
𐀪 Author: Picaga
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:10:07 GMT
════════════════════════
⌗ Tags: #cryptocurrency #defi #programming #cybersecurity #web3
Medium
Flash USDT Explained – For Educational Purposes Only
Flash USDT is a term used to describe fake USDT wallet reflections that don’t involve real blockchain transactions. These can be created…
⤷ Title: AI Slop will Fuel the Next Wave of Social Engineering Cybercrime Attacks
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:07:30 GMT
════════════════════════
⌗ Tags: #genai #cybercrime #social_engineering #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:07:30 GMT
════════════════════════
⌗ Tags: #genai #cybercrime #social_engineering #cybersecurity #artificial_intelligence
Medium
AI Slop will Fuel the Next Wave of Social Engineering Cybercrime Attacks
Simple Math:
⤷ Title: What if TikTok were a geopolitical tool?
════════════════════════
𐀪 Author: Alex M. S.
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:04:31 GMT
════════════════════════
⌗ Tags: #techpolitics #tik_tok #cybersecurity #geopolitics #technology
════════════════════════
𐀪 Author: Alex M. S.
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:04:31 GMT
════════════════════════
⌗ Tags: #techpolitics #tik_tok #cybersecurity #geopolitics #technology
Medium
What if TikTok were a geopolitical tool?
TikTok, controlled by China, is a geopolitical tool shaping data, public opinion, and digital power on a global scale.
⤷ Title: What Is Flash USDT? Know Before You’re Tricked
════════════════════════
𐀪 Author: Picaga
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:04:30 GMT
════════════════════════
⌗ Tags: #cryptocurrency #blockchain #bitcoin #cybersecurity #web3
════════════════════════
𐀪 Author: Picaga
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:04:30 GMT
════════════════════════
⌗ Tags: #cryptocurrency #blockchain #bitcoin #cybersecurity #web3
Medium
What Is Flash USDT? Know Before You’re Tricked
Flash USDT is a simulated version of USDT that appears in a wallet but does not exist on the blockchain. It’s often used in fraudulent…
⤷ Title: Flash USDT – Digital Illusions You Should Understand
════════════════════════
𐀪 Author: Hefixi
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:47:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #blockchain #cryptocurrency #bitcoin #software_development
════════════════════════
𐀪 Author: Hefixi
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:47:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #blockchain #cryptocurrency #bitcoin #software_development
Medium
Flash USDT – Digital Illusions You Should Understand
Not all USDT transfers are what they seem. Flash USDT can mimic legitimate wallet activity but doesn't leave a real trace on the…
⤷ Title: Flash USDT: What You See Isn’t Always What You Get
════════════════════════
𐀪 Author: Hefixi
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:42:43 GMT
════════════════════════
⌗ Tags: #bitcoin #programming #cryptocurrency #cybersecurity #ethereum
════════════════════════
𐀪 Author: Hefixi
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:42:43 GMT
════════════════════════
⌗ Tags: #bitcoin #programming #cryptocurrency #cybersecurity #ethereum
Medium
Flash USDT: What You See Isn’t Always What You Get
Flash USDT is a growing term in the crypto space, often referring to wallet balances that appear real but aren't backed by actual…
⤷ Title: FortiGate Virtual and Cloud-Native Next-Generation Firewalls
════════════════════════
𐀪 Author: Juara IT Solutions
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:31:02 GMT
════════════════════════
⌗ Tags: #cloud_security #network_security #fortinet #fortigate #cybersecurity
════════════════════════
𐀪 Author: Juara IT Solutions
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:31:02 GMT
════════════════════════
⌗ Tags: #cloud_security #network_security #fortinet #fortigate #cybersecurity
Medium
FortiGate Virtual and Cloud-Native Next-Generation Firewalls
As businesses continue to accelerate digital transformation, the need for flexible and scalable cybersecurity solutions has never been more…
⤷ Title: Security Auditing Terms Explained — Like You’re Playing Chess with Hackers
════════════════════════
𐀪 Author: Mujtaba Shaikeldin
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:17:57 GMT
════════════════════════
⌗ Tags: #security_auditing #cybersecurity #grc
════════════════════════
𐀪 Author: Mujtaba Shaikeldin
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:17:57 GMT
════════════════════════
⌗ Tags: #security_auditing #cybersecurity #grc
Medium
Security Auditing Terms Explained — Like You’re Playing Chess with Hackers
When I first opened up the Essential Terminology module in my security auditing course (part of my prep for eJPT), I’ll be honest — it…
⤷ Title: VulnNet-Roasted (PT1-Recommended Room)
════════════════════════
𐀪 Author: MR-X.Security
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:15:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #active_directory #cybersecurity #tryhackme #security
════════════════════════
𐀪 Author: MR-X.Security
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 23:15:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #active_directory #cybersecurity #tryhackme #security
Medium
VulnNet-Roasted (PT1-Recommended Room)
Enumeration :-
⤷ Title: Securing Go APIs: Authentication and Rate Limiting Patterns
════════════════════════
𐀪 Author: Hassanein Sharaf Al Dein
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 07:52:40 GMT
════════════════════════
⌗ Tags: #golang #api_security #web_development #backend #cybersecurity
════════════════════════
𐀪 Author: Hassanein Sharaf Al Dein
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 07:52:40 GMT
════════════════════════
⌗ Tags: #golang #api_security #web_development #backend #cybersecurity
Medium
Securing Go APIs: Authentication and Rate Limiting Patterns
Implement production-grade security in Go APIs with authentication and rate limiting patterns
⤷ Title: Critical Sudo Flaw (CVE-2025-32463, CVSS 9.3): Root Privilege Escalation & Host Bypass, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 02:51:46 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2025_32462 #CVE_2025_32463 #local exploit #PoC #privilege escalation #root access #sudo #SysAdmin #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 02:51:46 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability Report #CVE_2025_32462 #CVE_2025_32463 #local exploit #PoC #privilege escalation #root access #sudo #SysAdmin #Vulnerability
Daily CyberSecurity
Critical Sudo Flaw (CVE-2025-32463, CVSS 9.3): Root Privilege Escalation & Host Bypass, PoC Available
Two Sudo flaws (CVE-2025-32463 & CVE-2025-32462) allow local users full root via PoC. Critical privilege escalation vulnerabilities revealed by Stratascale CRU.