⤷ Title: Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #Cross_Site Scripting #CVE_2025_52895 #CVE_2025_52896 #CVE_2025_52898 #cybersecurity #ERPNext #Frappe Framework #sql injection #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Account Takeover #Cross_Site Scripting #CVE_2025_52895 #CVE_2025_52896 #CVE_2025_52898 #cybersecurity #ERPNext #Frappe Framework #sql injection #Vulnerability #XSS
Daily CyberSecurity
Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection
Three flaws in Frappe Framework allow account takeover via password reset token leaks, XSS via file upload, and SQL injection. Update self-hosted ERPNext immediately!
⤷ Title: Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:06:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #freelance deception #GitHub abuse #Infostealer #Intrinsec #malware campaigns #Pakistani Freelancers #phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:06:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #freelance deception #GitHub abuse #Infostealer #Intrinsec #malware campaigns #Pakistani Freelancers #phishing
Daily CyberSecurity
Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware
A report exposes Pakistani freelancers building websites distributing cracked software with stealer malware, leveraging a pay-per-install model and geopolitical loopholes.
⤷ Title: Pilz IndustrialPI 4 Alert: Critical Flaws (CVE-2025-41656 CVSS 10.0 RCE, CVE-2025-41648 Auth Bypass) Expose Industrial PCs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #cybersecurity #ICS #Industrial PC #IndustrialPI 4 #Node_RED #Pilz #rce #Remote Code Execution #SCADA #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #cybersecurity #ICS #Industrial PC #IndustrialPI 4 #Node_RED #Pilz #rce #Remote Code Execution #SCADA #Vulnerability
Daily CyberSecurity
Pilz IndustrialPI 4 Alert: Critical Flaws (CVE-2025-41656 CVSS 10.0 RCE, CVE-2025-41648 Auth Bypass) Expose Industrial PCs
CERT@VDE and Pilz disclose critical flaws in IndustrialPI 4: unauthenticated remote bypass (CVSS 9.6) and RCE (CVSS 10.0) via exposed Node-RED. Update or mitigate immediately.
⤷ Title: Hack The System — Bug Bounty CTF: Sattrack
════════════════════════
𐀪 Author: D4LTON
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:22:51 GMT
════════════════════════
⌗ Tags: #ctf #htb #bug_bounty #web #hack_the_system
════════════════════════
𐀪 Author: D4LTON
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:22:51 GMT
════════════════════════
⌗ Tags: #ctf #htb #bug_bounty #web #hack_the_system
Medium
Hack The System — Bug Bounty CTF: Sattrack
Difficulte : meduim
⤷ Title: NEWS UPDATE — July 1, 2025 | 6:45 PM UTC
Hacker “0-P” Claims Responsibility for Iranian Satellite…
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:29 GMT
════════════════════════
⌗ Tags: #hacking #satellite_technology #cybersecurity
Hacker “0-P” Claims Responsibility for Iranian Satellite…
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:29 GMT
════════════════════════
⌗ Tags: #hacking #satellite_technology #cybersecurity
Medium
Who is 0-P?
(Washington, D.C.) — Just two days after two Iranian satellites were knocked offline in a coordinated cyberattack, a notorious hacker…
⤷ Title: How a 141-Year-Old British Giant, Marks & Spencer, Was Brought Down by a Social Engineering-Driven…
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:57 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #cyberattack #hacking
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:57 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #cyberattack #hacking
Medium
How a 141-Year-Old British Giant, Marks & Spencer, Was Brought Down by a Social Engineering-Driven Ransomware Attack
In late April 2025, Marks & Spencer (M&S), the iconic British retailer with a 141-year legacy, fell victim to a large-scale ransomware…
⤷ Title: BREAKING NEWS — July 1, 2025 Iranian Satellites Reportedly Hacked in Sophisticated Cyberattack
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:53:34 GMT
════════════════════════
⌗ Tags: #hacking #fbi_investigation #cybersecurity
════════════════════════
𐀪 Author: Cybersec News
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:53:34 GMT
════════════════════════
⌗ Tags: #hacking #fbi_investigation #cybersecurity
Medium
BREAKING NEWS — July 1, 2025 Iranian Satellites Reportedly Hacked in Sophisticated Cyberattack
Tehran, Iran (Reuters-like) — In what appears to be one of the most sophisticated cyberattacks on Iranian aerospace infrastructure to date…
⤷ Title: “Cybersecurity isn’t just technology—it’s awareness, instinct, and action.”
════════════════════════
𐀪 Author: Rodkeshia "Keshia" Clifton
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:14:57 GMT
════════════════════════
⌗ Tags: #infosec #phishing #cybersecurity #cyber_security_awareness #tech
════════════════════════
𐀪 Author: Rodkeshia "Keshia" Clifton
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:14:57 GMT
════════════════════════
⌗ Tags: #infosec #phishing #cybersecurity #cyber_security_awareness #tech
Medium
“Cybersecurity isn’t just technology—it’s awareness, instinct, and action.”
The Phish That Almost Got Away: A Cybersecurity Wake-Up Call
⤷ Title: Agentic Threat Modeling with Local LLM (Mistral + LangChain)
════════════════════════
𐀪 Author: Oluwadare Bankole
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_detection #threat_hunting #threat_modeling #ai
════════════════════════
𐀪 Author: Oluwadare Bankole
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:47:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #threat_detection #threat_hunting #threat_modeling #ai
Medium
Agentic Threat Modeling with Local LLM (Mistral + LangChain)
Set up a local agentic AI threat modeling environment
⤷ Title: How LockBit “Revolutionized” the Ransomware Ecosystem with Its Business Model and Product Strategy…
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:10:06 GMT
════════════════════════
⌗ Tags: #ransomware #cybersecurity #cyberattack #cybercrime #ransomware_attack
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:10:06 GMT
════════════════════════
⌗ Tags: #ransomware #cybersecurity #cyberattack #cybercrime #ransomware_attack
Medium
How LockBit “Revolutionized” the Ransomware Ecosystem with Its Business Model and Product Strategy — Just Like an Innovative Startup
The story of LockBit — a name that once instilled fear in IT departments worldwide — has taken a dramatic turn. Once considered the apex…
⤷ Title: Why Threat Actors Target the Energy Sector
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #infrastructure #cyberattack #cybercrime #energy
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:04:00 GMT
════════════════════════
⌗ Tags: #cybersecurity #infrastructure #cyberattack #cybercrime #energy
Medium
Why Threat Actors Target the Energy Sector
Cyberattacks Targeting the Energy Sector
⤷ Title: “OneClik” Malware Weaponizes Microsoft ClickOnce to Hijack Energy Sector
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:02:52 GMT
════════════════════════
⌗ Tags: #microsoft #news #aws #cybersecurity #malware
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:02:52 GMT
════════════════════════
⌗ Tags: #microsoft #news #aws #cybersecurity #malware
Medium
🚨 “OneClik” Malware Weaponizes Microsoft ClickOnce to Hijack Energy Sector
Stealth attacks deploy Go backdoors via AWS/fake sites—zero admin rights, zero alerts, zero detection.
⤷ Title: I will construct AWS resume for cybersecurity, devops cloud engineer
════════════════════════
𐀪 Author: Excellentpeace
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:32 GMT
════════════════════════
⌗ Tags: #cloud_devops_engineer #aws_resume #cloudarchitects #cybersecurity
════════════════════════
𐀪 Author: Excellentpeace
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:55:32 GMT
════════════════════════
⌗ Tags: #cloud_devops_engineer #aws_resume #cloudarchitects #cybersecurity
Medium
I will construct AWS resume for cybersecurity, devops cloud engineer
HELLO AWESOME BUYER
⤷ Title: The Evolving Role of WAFs: On-Premises vs. Cloud-Based Deployment
════════════════════════
𐀪 Author: Infosecjourney.tech
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:47:09 GMT
════════════════════════
⌗ Tags: #zero_trust #cybersecurity #cloud_security #web_application_firewall
════════════════════════
𐀪 Author: Infosecjourney.tech
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 23:47:09 GMT
════════════════════════
⌗ Tags: #zero_trust #cybersecurity #cloud_security #web_application_firewall
Medium
The Evolving Role of WAFs: On-Premises vs. Cloud-Based Deployment
Web Application Firewalls (WAFs) have become a cornerstone of modern network and perimeter security. Not only are they a best practice for…
⤷ Title: Compromise Splunk for AWS Privilege Escalation(AWS-Red team lab)
════════════════════════
𐀪 Author: n00
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:26:31 GMT
════════════════════════
⌗ Tags: #seim #aws #ethical_hacking #splunk #cloud_security
════════════════════════
𐀪 Author: n00
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 00:26:31 GMT
════════════════════════
⌗ Tags: #seim #aws #ethical_hacking #splunk #cloud_security
Medium
Compromise Splunk for AWS Privilege Escalation(AWS-Red team lab)
Video: Coming
⤷ Title: CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:56:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #File Transfer #FTP Server #Lua Injection #Null Byte #rce #Remote Code Execution #unauthenticated #Vulnerability #Wing FTP Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:56:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #File Transfer #FTP Server #Lua Injection #Null Byte #rce #Remote Code Execution #unauthenticated #Vulnerability #Wing FTP Server
Daily CyberSecurity
CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases
A critical RCE flaw (CVE-2025-47812, CVSS 10.0) in Wing FTP Server allows unauthenticated attackers to execute arbitrary Lua code via NULL byte injection, compromising the server
⤷ Title: CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:32:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #plugin #rce #Remote Code Execution #site takeover #Vulnerability #Wordfence #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:32:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #plugin #rce #Remote Code Execution #site takeover #Vulnerability #Wordfence #wordpress
Daily CyberSecurity
CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
A critical flaw (CVE-2025-6463, CVSS 8.8) in Forminator WordPress plugin allows unauthenticated arbitrary file deletion, leading to site takeover.
⤷ Title: Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:20:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Data Theft #DCPCU #Fraud #mobile security #phishing #Rogue Cell Tower #smishing #SMS Blaster #UK Police
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:20:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Data Theft #DCPCU #Fraud #mobile security #phishing #Rogue Cell Tower #smishing #SMS Blaster #UK Police
Daily CyberSecurity
Chinese Student Jailed for Smishing: Operated Covert "SMS Blaster" in Car for Mass Phishing
A Chinese student was jailed in London for running a smishing campaign with an "SMS Blaster" hidden in his car, spoofing texts to steal data.
⤷ Title: ANSSI Exposes “Houken”: China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:08:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #ANSSI #APT #china #Cyberespionage #cybersecurity #Houken #initial access broker #Ivanti CSA #Linux Rootkit #MSS #UNC5174 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:08:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #ANSSI #APT #china #Cyberespionage #cybersecurity #Houken #initial access broker #Ivanti CSA #Linux Rootkit #MSS #UNC5174 #zero_day
Daily CyberSecurity
ANSSI Exposes "Houken": China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits
ANSSI exposes "Houken," a China-linked APT exploiting Ivanti CSA zero-days (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) and deploying Linux rootkits for cyber-espionage against strategic sectors.
⤷ Title: OFAC Sanctions Russian “Bulletproof Host” Aeza Group: Linked to Ransomware, Infostealers & Darknet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:57:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aeza Group #BPH #bulletproof hosting #Cybercrime #cybersecurity #Darknet #Infostealer #OFAC #ransomware #russia #sanctions #Treasury Department
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:57:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aeza Group #BPH #bulletproof hosting #Cybercrime #cybersecurity #Darknet #Infostealer #OFAC #ransomware #russia #sanctions #Treasury Department
Daily CyberSecurity
OFAC Sanctions Russian "Bulletproof Host" Aeza Group: Linked to Ransomware, Infostealers & Darknet
OFAC sanctioned Russia's Aeza Group, a bulletproof hosting provider, and its executives for enabling ransomware, infostealers (Meduza, Lumma), and darknet drug trafficking operations globally.
⤷ Title: DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:46:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:46:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
Daily CyberSecurity
DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
The DOJ dismantled a North Korean scheme exploiting remote IT jobs at 100+ U.S. firms, using stolen identities and laundering millions to fund DPRK weapons programs.