⤷ Title: dAWShund: New Tool Suite to Visualize & Secure AWS IAM Permissions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:22:35 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AWS #BloodHound #cloud security #cybersecurity #enumeration #IAM #Identity and Access Management #JSON #permissions #Policy Evaluation #security tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:22:35 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AWS #BloodHound #cloud security #cybersecurity #enumeration #IAM #Identity and Access Management #JSON #permissions #Policy Evaluation #security tool
Penetration Testing Tools
dAWShund: New Tool Suite to Visualize & Secure AWS IAM Permissions
dAWShund is a new tool suite to enumerate, evaluate, and visualize AWS IAM policies and resource access conditions, helping security teams manage and secure cloud permissions.
⤷ Title: CVSS 9.8 RCE in Netflix Conductor Exposes Servers to Full Remote Shell – PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:29:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #JavaScript Injection #Microservices Security #Nashorn Engine #Netflix Conductor #PoC Exploit #rce #Remote Code Execution #Workflow Automation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:29:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #JavaScript Injection #Microservices Security #Nashorn Engine #Netflix Conductor #PoC Exploit #rce #Remote Code Execution #Workflow Automation
Daily CyberSecurity
CVSS 9.8 RCE in Netflix Conductor Exposes Servers to Full Remote Shell – PoC Available
Critical CVSS 9.8 RCE in Netflix Conductor lets attackers gain remote shell via JavaScript injection. Exploit PoC available. Patch now!
⤷ Title: Multi DataEase Flaws: RCE & Bypass Vulnerabilities Threaten BI Platform via JDBC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:24:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BI #Business Intelligence #CVE_2025_49003 #CVE_2025_53004 #CVE_2025_53005 #CVE_2025_53006 #cybersecurity #DataEase #H2 #JDBC #PostgreSQL #rce #Redshift #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:24:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BI #Business Intelligence #CVE_2025_49003 #CVE_2025_53004 #CVE_2025_53005 #CVE_2025_53006 #cybersecurity #DataEase #H2 #JDBC #PostgreSQL #rce #Redshift #Remote Code Execution #Vulnerability
Daily CyberSecurity
Multi DataEase Flaws: RCE & Bypass Vulnerabilities Threaten BI Platform via JDBC
DataEase has critical flaws in database connection handling, allowing remote RCE and JDBC parameter bypasses for H2, Redshift, and PostgreSQL. Update to v2.10.11 now!
⤷ Title: Graylog Flaw (CVE-2025-53106, CVSS 8.8): Privilege Escalation Via API Token Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:19:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Token #CVE_2025_53106 #CVSS 8.8 #cybersecurity #Graylog #privilege escalation #Security Information and Event Management #SIEM #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:19:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Token #CVE_2025_53106 #CVSS 8.8 #cybersecurity #Graylog #privilege escalation #Security Information and Event Management #SIEM #Vulnerability
Daily CyberSecurity
Graylog Flaw (CVE-2025-53106, CVSS 8.8): Privilege Escalation Via API Token Abuse
A flaw (CVE-2025-53106) in Graylog allows authenticated users to escalate privileges via API token abuse. Update to 6.2.4 or 6.3.0-rc.2 immediately.
⤷ Title: Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #Cross_Site Scripting #CVE_2025_52895 #CVE_2025_52896 #CVE_2025_52898 #cybersecurity #ERPNext #Frappe Framework #sql injection #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #Cross_Site Scripting #CVE_2025_52895 #CVE_2025_52896 #CVE_2025_52898 #cybersecurity #ERPNext #Frappe Framework #sql injection #Vulnerability #XSS
Daily CyberSecurity
Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection
Three flaws in Frappe Framework allow account takeover via password reset token leaks, XSS via file upload, and SQL injection. Update self-hosted ERPNext immediately!
⤷ Title: Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:06:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #freelance deception #GitHub abuse #Infostealer #Intrinsec #malware campaigns #Pakistani Freelancers #phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:06:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #freelance deception #GitHub abuse #Infostealer #Intrinsec #malware campaigns #Pakistani Freelancers #phishing
Daily CyberSecurity
Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware
A report exposes Pakistani freelancers building websites distributing cracked software with stealer malware, leveraging a pay-per-install model and geopolitical loopholes.
⤷ Title: Pilz IndustrialPI 4 Alert: Critical Flaws (CVE-2025-41656 CVSS 10.0 RCE, CVE-2025-41648 Auth Bypass) Expose Industrial PCs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #cybersecurity #ICS #Industrial PC #IndustrialPI 4 #Node_RED #Pilz #rce #Remote Code Execution #SCADA #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #cybersecurity #ICS #Industrial PC #IndustrialPI 4 #Node_RED #Pilz #rce #Remote Code Execution #SCADA #Vulnerability
Daily CyberSecurity
Pilz IndustrialPI 4 Alert: Critical Flaws (CVE-2025-41656 CVSS 10.0 RCE, CVE-2025-41648 Auth Bypass) Expose Industrial PCs
CERT@VDE and Pilz disclose critical flaws in IndustrialPI 4: unauthenticated remote bypass (CVSS 9.6) and RCE (CVSS 10.0) via exposed Node-RED. Update or mitigate immediately.
⤷ Title: Hack The System — Bug Bounty CTF: Sattrack
════════════════════════
𐀪 Author: D4LTON
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:22:51 GMT
════════════════════════
⌗ Tags: #ctf #htb #bug_bounty #web #hack_the_system
════════════════════════
𐀪 Author: D4LTON
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:22:51 GMT
════════════════════════
⌗ Tags: #ctf #htb #bug_bounty #web #hack_the_system
Medium
Hack The System — Bug Bounty CTF: Sattrack
Difficulte : meduim
⤷ Title: NEWS UPDATE — July 1, 2025 | 6:45 PM UTC
Hacker “0-P” Claims Responsibility for Iranian Satellite…
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:29 GMT
════════════════════════
⌗ Tags: #hacking #satellite_technology #cybersecurity
Hacker “0-P” Claims Responsibility for Iranian Satellite…
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:29 GMT
════════════════════════
⌗ Tags: #hacking #satellite_technology #cybersecurity
Medium
Who is 0-P?
(Washington, D.C.) — Just two days after two Iranian satellites were knocked offline in a coordinated cyberattack, a notorious hacker…
⤷ Title: How a 141-Year-Old British Giant, Marks & Spencer, Was Brought Down by a Social Engineering-Driven…
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:57 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #cyberattack #hacking
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:57 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #cyberattack #hacking
Medium
How a 141-Year-Old British Giant, Marks & Spencer, Was Brought Down by a Social Engineering-Driven Ransomware Attack
In late April 2025, Marks & Spencer (M&S), the iconic British retailer with a 141-year legacy, fell victim to a large-scale ransomware…
⤷ Title: BREAKING NEWS — July 1, 2025 Iranian Satellites Reportedly Hacked in Sophisticated Cyberattack
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:53:34 GMT
════════════════════════
⌗ Tags: #hacking #fbi_investigation #cybersecurity
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:53:34 GMT
════════════════════════
⌗ Tags: #hacking #fbi_investigation #cybersecurity
Medium
BREAKING NEWS — July 1, 2025 Iranian Satellites Reportedly Hacked in Sophisticated Cyberattack
Tehran, Iran (Reuters-like) — In what appears to be one of the most sophisticated cyberattacks on Iranian aerospace infrastructure to date…
⤷ Title: “Cybersecurity isn’t just technology—it’s awareness, instinct, and action.”
════════════════════════
𐀪 Author: Rodkeshia "Keshia" Clifton
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:14:57 GMT
════════════════════════
⌗ Tags: #infosec #phishing #cybersecurity #cyber_security_awareness #tech
════════════════════════
𐀪 Author: Rodkeshia "Keshia" Clifton
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:14:57 GMT
════════════════════════
⌗ Tags: #infosec #phishing #cybersecurity #cyber_security_awareness #tech
Medium
“Cybersecurity isn’t just technology—it’s awareness, instinct, and action.”
The Phish That Almost Got Away: A Cybersecurity Wake-Up Call
⤷ Title: Agentic Threat Modeling with Local LLM (Mistral + LangChain)
════════════════════════
𐀪 Author: Oluwadare Bankole
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_detection #threat_hunting #threat_modeling #ai
════════════════════════
𐀪 Author: Oluwadare Bankole
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_detection #threat_hunting #threat_modeling #ai
Medium
Agentic Threat Modeling with Local LLM (Mistral + LangChain)
Set up a local agentic AI threat modeling environment
⤷ Title: How LockBit “Revolutionized” the Ransomware Ecosystem with Its Business Model and Product Strategy…
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:10:06 GMT
════════════════════════
⌗ Tags: #ransomware #cybersecurity #cyberattack #cybercrime #ransomware_attack
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:10:06 GMT
════════════════════════
⌗ Tags: #ransomware #cybersecurity #cyberattack #cybercrime #ransomware_attack
Medium
How LockBit “Revolutionized” the Ransomware Ecosystem with Its Business Model and Product Strategy — Just Like an Innovative Startup
The story of LockBit — a name that once instilled fear in IT departments worldwide — has taken a dramatic turn. Once considered the apex…
⤷ Title: Why Threat Actors Target the Energy Sector
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #infrastructure #cyberattack #cybercrime #energy
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #infrastructure #cyberattack #cybercrime #energy
Medium
Why Threat Actors Target the Energy Sector
Cyberattacks Targeting the Energy Sector
⤷ Title: “OneClik” Malware Weaponizes Microsoft ClickOnce to Hijack Energy Sector
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:02:52 GMT
════════════════════════
⌗ Tags: #microsoft #news #aws #cybersecurity #malware
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:02:52 GMT
════════════════════════
⌗ Tags: #microsoft #news #aws #cybersecurity #malware
Medium
🚨 “OneClik” Malware Weaponizes Microsoft ClickOnce to Hijack Energy Sector
Stealth attacks deploy Go backdoors via AWS/fake sites—zero admin rights, zero alerts, zero detection.
⤷ Title: I will construct AWS resume for cybersecurity, devops cloud engineer
════════════════════════
𐀪 Author: Excellentpeace
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:32 GMT
════════════════════════
⌗ Tags: #cloud_devops_engineer #aws_resume #cloudarchitects #cybersecurity
════════════════════════
𐀪 Author: Excellentpeace
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:32 GMT
════════════════════════
⌗ Tags: #cloud_devops_engineer #aws_resume #cloudarchitects #cybersecurity
Medium
I will construct AWS resume for cybersecurity, devops cloud engineer
HELLO AWESOME BUYER
⤷ Title: The Evolving Role of WAFs: On-Premises vs. Cloud-Based Deployment
════════════════════════
𐀪 Author: Infosecjourney.tech
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:47:09 GMT
════════════════════════
⌗ Tags: #zero_trust #cybersecurity #cloud_security #web_application_firewall
════════════════════════
𐀪 Author: Infosecjourney.tech
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:47:09 GMT
════════════════════════
⌗ Tags: #zero_trust #cybersecurity #cloud_security #web_application_firewall
Medium
The Evolving Role of WAFs: On-Premises vs. Cloud-Based Deployment
Web Application Firewalls (WAFs) have become a cornerstone of modern network and perimeter security. Not only are they a best practice for…
⤷ Title: Compromise Splunk for AWS Privilege Escalation(AWS-Red team lab)
════════════════════════
𐀪 Author: n00
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:26:31 GMT
════════════════════════
⌗ Tags: #seim #aws #ethical_hacking #splunk #cloud_security
════════════════════════
𐀪 Author: n00
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:26:31 GMT
════════════════════════
⌗ Tags: #seim #aws #ethical_hacking #splunk #cloud_security
Medium
Compromise Splunk for AWS Privilege Escalation(AWS-Red team lab)
Video: Coming
⤷ Title: CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:56:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #File Transfer #FTP Server #Lua Injection #Null Byte #rce #Remote Code Execution #unauthenticated #Vulnerability #Wing FTP Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:56:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #File Transfer #FTP Server #Lua Injection #Null Byte #rce #Remote Code Execution #unauthenticated #Vulnerability #Wing FTP Server
Daily CyberSecurity
CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases
A critical RCE flaw (CVE-2025-47812, CVSS 10.0) in Wing FTP Server allows unauthenticated attackers to execute arbitrary Lua code via NULL byte injection, compromising the server
⤷ Title: CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:32:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #plugin #rce #Remote Code Execution #site takeover #Vulnerability #Wordfence #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:32:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #plugin #rce #Remote Code Execution #site takeover #Vulnerability #Wordfence #wordpress
Daily CyberSecurity
CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
A critical flaw (CVE-2025-6463, CVSS 8.8) in Forminator WordPress plugin allows unauthenticated arbitrary file deletion, leading to site takeover.