⤷ Title: ประจำวันพฤหัสบดีที่ 3 กรกฎาคม 2568
════════════════════════
𐀪 Author: ThaiCERT By NCSA
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:34:16 GMT
════════════════════════
⌗ Tags: #cybersecurity
════════════════════════
𐀪 Author: ThaiCERT By NCSA
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:34:16 GMT
════════════════════════
⌗ Tags: #cybersecurity
Medium
ประจำวันพฤหัสบดีที่ 3 กรกฎาคม 2568
ผู้เชี่ยวชาญเตือนภัยฟิชชิ่งรูปแบบใหม่ผ่าน LLM มิจฉาชีพจ้องใช้ AI มาหลอกลวง
⤷ Title: Attacking ML-based Systems: Understanding the OWASP Top 10 Security Risks
════════════════════════
𐀪 Author: Sheikh Mujtaba
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:19:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #owasp_top_10 #ai_threats #ml_security #machine_learning_secure
════════════════════════
𐀪 Author: Sheikh Mujtaba
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:19:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #owasp_top_10 #ai_threats #ml_security #machine_learning_secure
Medium
Attacking ML-based Systems: Understanding the OWASP Top 10 Security Risks
In today’s world, machine learning (ML) systems are everywhere — from personalizing your online shopping experience to powering…
⤷ Title: Psychological Safety: The Secret Weapon for High-Performing Teams (And What I’ve Learnt Leading…
════════════════════════
𐀪 Author: Lee Barney
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:14:30 GMT
════════════════════════
⌗ Tags: #psychological_safety #leadership_development #business #tech_leader_insights #cybersecurity
════════════════════════
𐀪 Author: Lee Barney
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:14:30 GMT
════════════════════════
⌗ Tags: #psychological_safety #leadership_development #business #tech_leader_insights #cybersecurity
Medium
Psychological Safety: The Secret Weapon for High-Performing Teams (And What I’ve Learnt Leading Them)
Why do some teams perform well under pressure while others fall apart? The answer… it’s not about pay — it’s about mutual respect and…
⤷ Title: How to Effectively and Efficiently Make Every Byte of Your Data Secure
════════════════════════
𐀪 Author: revathi msr
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:57:24 GMT
════════════════════════
⌗ Tags: #zero_trust #data_protection #risk_management #cybersecurity #technology
════════════════════════
𐀪 Author: revathi msr
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:57:24 GMT
════════════════════════
⌗ Tags: #zero_trust #data_protection #risk_management #cybersecurity #technology
Medium
How to Effectively and Efficiently Make Every Byte of Your Data Secure
Think your data is safe? Think again.
In today’s digital landscape, cyberattacks are happening every second, and businesses of all sizes…
In today’s digital landscape, cyberattacks are happening every second, and businesses of all sizes…
⤷ Title: Title: The Hidden Dangers of Free Public Wi-Fi — And How to Stay Safe
════════════════════════
𐀪 Author: Anshika Prajapati
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:48:57 GMT
════════════════════════
⌗ Tags: #entrepreneurship #education #true_crime #freelancing #cybersecurity
════════════════════════
𐀪 Author: Anshika Prajapati
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:48:57 GMT
════════════════════════
⌗ Tags: #entrepreneurship #education #true_crime #freelancing #cybersecurity
Medium
🧠 Title: The Hidden Dangers of Free Public Wi-Fi — And How to Stay Safe
Public Wi-Fi feels like a gift — airports, cafes, colleges, even public parks offer it freely. But behind that free access lies a dangerous trap most users walk right into. One wrong click or…
⤷ Title: From Racetrack to Ransom: NASCAR Faces Down the Medusa Threat
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:32:51 GMT
════════════════════════
⌗ Tags: #medusa_ransomware #data_breach #cybersecurity #nascar #ransomware_attack
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:32:51 GMT
════════════════════════
⌗ Tags: #medusa_ransomware #data_breach #cybersecurity #nascar #ransomware_attack
Medium
From Racetrack to Ransom: NASCAR Faces Down the Medusa Threat
In the fast lane of motorsports, no one expects the real danger to come from behind a keyboard. Yet that’s exactly where NASCAR finds…
⤷ Title: Why AI Is Responsible for the Recent Cyber Theft or Crimes ?
════════════════════════
𐀪 Author: Sardar Ronaq Singh
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:22:53 GMT
════════════════════════
⌗ Tags: #ai #writing #data_science #technology #cybersecurity
════════════════════════
𐀪 Author: Sardar Ronaq Singh
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:22:53 GMT
════════════════════════
⌗ Tags: #ai #writing #data_science #technology #cybersecurity
Medium
Why AI Is Responsible for the Recent Cyber Theft or Crimes ?
Artificial Intelligence (AI), once a futuristic concept, is now deeply embedded in our daily lives—from voice assistants to automated…
⤷ Title: Simple CTF : THM
════════════════════════
𐀪 Author: Proxyminerin
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 02:43:27 GMT
════════════════════════
⌗ Tags: #information_technology #networking #ctf #tryhackme
════════════════════════
𐀪 Author: Proxyminerin
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 02:43:27 GMT
════════════════════════
⌗ Tags: #information_technology #networking #ctf #tryhackme
Medium
Simple CTF : THM
How many services are running under port 1000?
⤷ Title: ️♂️ I Forced You to Log In as Me: OAuth Gone Wrong
════════════════════════
𐀪 Author: ASC Lages
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:16:52 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #oauth #csrf
════════════════════════
𐀪 Author: ASC Lages
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 04:16:52 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #oauth #csrf
Medium
🕵️♂️ I Forced You to Log In as Me: OAuth Gone Wrong
بِسْمِ اللّٰهِ الرَّحْمٰنِ الرَّحِيْمِ
⤷ Title: Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 09:54:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 09:54:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: NimDoor: North Korean APT Uses Nim-Based Malware for Stealthy Web3 & Crypto Attacks on macOS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:54:06 +0000
════════════════════════
⌗ Tags: #Malware #APT #cryptocurrency #Cyberespionage #macos #malware #Nim Programming #NimDoor #North Korea #persistence #SentinelLABS #Social Engineering #Web3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:54:06 +0000
════════════════════════
⌗ Tags: #Malware #APT #cryptocurrency #Cyberespionage #macos #malware #Nim Programming #NimDoor #North Korea #persistence #SentinelLABS #Social Engineering #Web3
Penetration Testing Tools
NimDoor: North Korean APT Uses Nim-Based Malware for Stealthy Web3 & Crypto Attacks on macOS
North Korean APTs are using "NimDoor," a new Nim-based macOS malware, to target Web3/crypto startups via fake Zoom meetings, stealing browser, Keychain, and Telegram data with novel persistence.
⤷ Title: TOAD Attacks Surge: Reverse Phishing Campaigns Trick Victims into Calling Scammers for RAT Delivery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:52:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cisco Talos #cybersecurity #Direct Send #Microsoft 365 #phishing #QR Codes #RAT #Remote Access Trojan #Reverse Phishing #Social Engineering #Telephone_Oriented Attack Delivery #TOAD
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:52:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cisco Talos #cybersecurity #Direct Send #Microsoft 365 #phishing #QR Codes #RAT #Remote Access Trojan #Reverse Phishing #Social Engineering #Telephone_Oriented Attack Delivery #TOAD
Penetration Testing Tools
TOAD Attacks Surge: Reverse Phishing Campaigns Trick Victims into Calling Scammers for RAT Delivery
TOAD reverse phishing attacks are surging, using brand-impersonating emails with QR codes to trick victims into calling scammers who then deploy RATs or steal data.
⤷ Title: Qantas Data Breach: Up to 6 Million Customers’ Personal Info Exposed in Third-Party Contact Centre Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:49:11 +0000
════════════════════════
⌗ Tags: #Data Leak #Airline #Australia #Contact Centre #Customer Data #cyberattack #cybersecurity #data breach #Frequent Flyer #Qantas #Scattered Spider #Third_Party Vendor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:49:11 +0000
════════════════════════
⌗ Tags: #Data Leak #Airline #Australia #Contact Centre #Customer Data #cyberattack #cybersecurity #data breach #Frequent Flyer #Qantas #Scattered Spider #Third_Party Vendor
Penetration Testing Tools
Qantas Data Breach: Up to 6 Million Customers' Personal Info Exposed in Third-Party Contact Centre Attack
Qantas Airways confirms a cyberattack on a third-party contact center platform exposed personal data of up to 6 million customers. No financial data or passwords compromised.
⤷ Title: €460M Crypto Fraud Busted: Europol & Allies Arrest 5, Dismantle Global Money Laundering Ring
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:46:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #cybercrime #Europol #Fraud #Hong Kong #International Operation #Investment Scam #Money Laundering #Online Fraud #Spain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:46:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #cybercrime #Europol #Fraud #Hong Kong #International Operation #Investment Scam #Money Laundering #Online Fraud #Spain
Penetration Testing Tools
€460M Crypto Fraud Busted: Europol & Allies Arrest 5, Dismantle Global Money Laundering Ring
Europol and allies arrested 5 individuals in Spain, dismantling a global crypto investment fraud ring that laundered €460 million from over 5,000 victims worldwide.
⤷ Title: Google Hit with $314M Verdict: Jury Rules Android Secretly Used Cellular Data for Tracking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:41:43 +0000
════════════════════════
⌗ Tags: #Google #Android #Cellular Data #Class Action #data privacy #google #Google Maps #lawsuit #Legal News #Targeted Advertising #Tracking #Verdict
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:41:43 +0000
════════════════════════
⌗ Tags: #Google #Android #Cellular Data #Class Action #data privacy #google #Google Maps #lawsuit #Legal News #Targeted Advertising #Tracking #Verdict
Penetration Testing Tools
Google Hit with $314M Verdict: Jury Rules Android Secretly Used Cellular Data for Tracking
A California jury ordered Google to pay $314M in damages, ruling it secretly used Android users' cellular data for tracking without consent. Google will appeal.
⤷ Title: Critical MCP Inspector Flaw (CVE-2025-49596, CVSS 9.4): Unauthenticated RCE Threatens AI Dev Machines via Browser
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:39:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #0.0.0.0_day #AI Development #AI security #CVE_2025_49596 #cybersecurity #Machine Context Protocol #MCP #MCP Inspector #Oligo Security #RCE #remote code execution #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:39:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #0.0.0.0_day #AI Development #AI security #CVE_2025_49596 #cybersecurity #Machine Context Protocol #MCP #MCP Inspector #Oligo Security #RCE #remote code execution #vulnerability
Penetration Testing Tools
Critical MCP Inspector Flaw (CVE-2025-49596, CVSS 9.4): Unauthenticated RCE Threatens AI Dev Machines via Browser
A critical flaw (CVE-2025-49596, CVSS 9.4) in Anthropic's MCP Inspector allows unauthenticated RCE on AI dev machines via browser interaction. Patch to v0.14.1 immediately!
⤷ Title: FileFix: New Windows Technique Bypasses Mark of the Web for Silent Script Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:36:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #bypass #cybersecurity #FileFix #HTA #HTML Application #Mark of the Web #MoTW #mr.d0x #Social Engineering #vulnerability #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:36:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #bypass #cybersecurity #FileFix #HTA #HTML Application #Mark of the Web #MoTW #mr.d0x #Social Engineering #vulnerability #windows
Penetration Testing Tools
FileFix: New Windows Technique Bypasses Mark of the Web for Silent Script Execution
FileFix is a new Windows technique that allows silent script execution by bypassing Mark of the Web. Attackers trick users into saving and renaming HTML pages to .HTA files.
⤷ Title: Chrome Cookie Encryption Bypassed: “C4 Attack” Exploits Padding Oracle to Steal Cookies
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:31:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #AppBound Encryption #C4 #chrome #cookies #cryptography #cybersecurity #DPAPI #Google Chrome #Padding Oracle Attack #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 06:31:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #AppBound Encryption #C4 #chrome #cookies #cryptography #cybersecurity #DPAPI #Google Chrome #Padding Oracle Attack #vulnerability
Penetration Testing Tools
Chrome Cookie Encryption Bypassed: "C4 Attack" Exploits Padding Oracle to Steal Cookies
Researchers bypassed Chrome's AppBound Cookie Encryption using a Padding Oracle Attack ("C4"), exploiting Windows error logs to decrypt SYSTEM-DPAPI protected cookies.
⤷ Title: Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:14:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Infrastructure #cyberattack #cybersecurity #Exposed Devices #ICS #industrial control systems #Operation Sindoor #OT Security #Power Grid #Vulnerability #zoomeye
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:14:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Infrastructure #cyberattack #cybersecurity #Exposed Devices #ICS #industrial control systems #Operation Sindoor #OT Security #Power Grid #Vulnerability #zoomeye
Daily CyberSecurity
Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure?
Over 143,000 ICS devices in the power sector are publicly exposed to the internet, facing high/critical vulnerabilities. Urgent action is needed to secure global energy infrastructure.
⤷ Title: Urgent: Linux Kernel Flaw Allows Remote Crash, PoC Available!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:03:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Denial of Service #dos #Kernel Crash #Linux Kernel #Network File System #NFS #Null Pointer Dereference #SUNRPC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 03:03:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #Denial of Service #dos #Kernel Crash #Linux Kernel #Network File System #NFS #Null Pointer Dereference #SUNRPC
Daily CyberSecurity
Urgent: Linux Kernel Flaw Allows Remote Crash, PoC Available!
A NFSundown flaw (CVE-2025-38089) in the Linux kernel allows remote attackers to crash NFS servers via a NULL pointer dereference. PoC exploit is public!
⤷ Title: Performing CSRF Exploits Over GraphQL
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 05:00:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #csrf_attack #bug_bounty #graphql_api_security #graphql_csrf_exploit
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Thu, 03 Jul 2025 05:00:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #csrf_attack #bug_bounty #graphql_api_security #graphql_csrf_exploit
Medium
Performing CSRF Exploits Over GraphQL
Exploiting CSRF in GraphQL Endpoints.