⤷ Title: How to Secure a Vibe-Coded Website or App
════════════════════════
𐀪 Author: Yasir Khan
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:16:35 GMT
════════════════════════
⌗ Tags: #security #coding #hacking #vibe_coding #authentication
════════════════════════
𐀪 Author: Yasir Khan
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:16:35 GMT
════════════════════════
⌗ Tags: #security #coding #hacking #vibe_coding #authentication
Medium
🚀 Why Security Is a Must
Cool vibe-coded app are great. But without security, your app won’t survive
⤷ Title: SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357 Exploitation
════════════════════════
𐀪 Author: Raynard Waits
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:41:54 GMT
════════════════════════
⌗ Tags: #lets_defend #cybersecurity #security_analysts #writeup #soc_analyst_training
════════════════════════
𐀪 Author: Raynard Waits
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:41:54 GMT
════════════════════════
⌗ Tags: #lets_defend #cybersecurity #security_analysts #writeup #soc_analyst_training
Medium
SOC227 — Microsoft SharePoint Server Elevation of Privilege — Possible CVE-2023–29357 Exploitation
Let’s jump in and take a look!
⤷ Title: Shaping Alignment without Fear and the Hidden Cost of Negation
════════════════════════
𐀪 Author: Danielle Breegle
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:56:39 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #ai_security #machine_learning #red_team
════════════════════════
𐀪 Author: Danielle Breegle
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:56:39 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #ai_security #machine_learning #red_team
Medium
Shaping Alignment without Fear and the Hidden Cost of Negation
If you wanted to teach a system, would you suppress all risk or would you build paths where misalignment is incoherent to internal logic?
⤷ Title: Fortinet Zero Trust Network Access: A Comprehensive Guide
════════════════════════
𐀪 Author: Juara IT Solutions
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:47:06 GMT
════════════════════════
⌗ Tags: #fortinet #zero_trust_security #cybersecurity #zero_trust_network_access #ztna
════════════════════════
𐀪 Author: Juara IT Solutions
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:47:06 GMT
════════════════════════
⌗ Tags: #fortinet #zero_trust_security #cybersecurity #zero_trust_network_access #ztna
Medium
Fortinet Zero Trust Network Access: A Comprehensive Guide
As cybersecurity threats continue to evolve, traditional perimeter-based security models are proving inadequate. Organizations need…
⤷ Title: Why Every Beginner Pentester Should Build Their Own Lab (Before Getting Certified)
════════════════════════
𐀪 Author: Corey Jones
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:37:52 GMT
════════════════════════
⌗ Tags: #it #homelab #cybersecurity #penetration_testing #pentesting
════════════════════════
𐀪 Author: Corey Jones
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:37:52 GMT
════════════════════════
⌗ Tags: #it #homelab #cybersecurity #penetration_testing #pentesting
Medium
Why Every Beginner Pentester Should Build Their Own Lab (Before Getting Certified)
Let me be straight with you: certifications are cool, but they don’t teach you how to think like a hacker. They teach you how to pass a…
⤷ Title: XLMRat Lab Analysis
════════════════════════
𐀪 Author: Omer Bawazir
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:34:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberdefender #soc_analyst #network_forensics #incident_response
════════════════════════
𐀪 Author: Omer Bawazir
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:34:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberdefender #soc_analyst #network_forensics #incident_response
Medium
XLMRat Lab Analysis
🕵️ CyberDefender — Network Forensics
⤷ Title: From Swords to Words: The new weapons piercing enterprise’s armor
════════════════════════
𐀪 Author: Emre Tezisci
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:28:12 GMT
════════════════════════
⌗ Tags: #ai_security #cybersecurity #zero_trust #technology #ai
════════════════════════
𐀪 Author: Emre Tezisci
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 23:28:12 GMT
════════════════════════
⌗ Tags: #ai_security #cybersecurity #zero_trust #technology #ai
Medium
From Swords to Words: The new weapons piercing enterprise’s armor
Words are the new weapons. Attackers are now hacking AI with language, not code, turning our most powerful tools against us.
⤷ Title: Protocols and Servers — TryHackMe
════════════════════════
𐀪 Author: sercan timocin
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:29:06 GMT
════════════════════════
⌗ Tags: #security #protocol #tryhackme #penetration_testing #network_security
════════════════════════
𐀪 Author: sercan timocin
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 00:29:06 GMT
════════════════════════
⌗ Tags: #security #protocol #tryhackme #penetration_testing #network_security
Medium
Protocols and Servers — TryHackMe
Task 1: Introduction
⤷ Title: Batavia Spyware Unmasked: Covert Campaign Hits Russian Industrial & Scientific Orgs via Phishing Emails
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:51:32 +0000
════════════════════════
⌗ Tags: #Malware #Batavia #C++ #Cyber Espionage #Delphi #Industrial Sector #Kaspersky Lab #phishing #Russia #Scientific Organizations #Spyware #UAC bypass #VBScript
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:51:32 +0000
════════════════════════
⌗ Tags: #Malware #Batavia #C++ #Cyber Espionage #Delphi #Industrial Sector #Kaspersky Lab #phishing #Russia #Scientific Organizations #Spyware #UAC bypass #VBScript
Penetration Testing Tools
Batavia Spyware Unmasked: Covert Campaign Hits Russian Industrial & Scientific Orgs via Phishing Emails
Kaspersky uncovers Batavia, a new spyware hitting Russian industrial/scientific orgs since July 2024. It uses VBS scripts, WebView.exe, and javav.exe to steal data and maintain persistence.
⤷ Title: RingReaper: New Linux Tool Leverages io_uring Kernel Feature to Bypass EDR & Stealthily Control Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:49:03 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #EDR Bypass #io_uring #Kernel Feature #Linux #Offensive Security #Penetration Testing #Remote Access Agent #RingReaper #System Calls
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:49:03 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #EDR Bypass #io_uring #Kernel Feature #Linux #Offensive Security #Penetration Testing #Remote Access Agent #RingReaper #System Calls
Penetration Testing Tools
RingReaper: New Linux Tool Leverages io_uring Kernel Feature to Bypass EDR & Stealthily Control Systems
RingReaper is a new remote access agent that exploits the Linux kernel's io_uring feature to stealthily bypass EDR solutions and control compromised systems with minimal detection.
⤷ Title: NightEagle APT Unleashed: Zero-Day Exchange Exploit Targets China’s Strategic Industries with Fileless Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:46:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #APT_Q_95 #China #Chisel #Cyberespionage #cybersecurity #Exchange Zero_Day #Fileless Malware #Microsoft Exchange #NightEagle #QiAnXin
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:46:17 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #APT_Q_95 #China #Chisel #Cyberespionage #cybersecurity #Exchange Zero_Day #Fileless Malware #Microsoft Exchange #NightEagle #QiAnXin
Penetration Testing Tools
NightEagle APT Unleashed: Zero-Day Exchange Exploit Targets China's Strategic Industries with Fileless Malware
NightEagle APT (APT-Q-95) is exploiting an unknown Exchange zero-day to target China's strategic industries, using fileless malware and exfiltrating machineKey for remote email access.
⤷ Title: Pakistan-Aligned APT36 Unleashes DRAT V2: New Delphi RAT Targets Indian Government
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:43:31 +0000
════════════════════════
⌗ Tags: #Malware #APT36 #ClickFix #Cyberespionage #DRAT V2 #Government #India #phishing #RAT #Remote Access Trojan #SideCopy #TAG_140 #Transparent Tribe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:43:31 +0000
════════════════════════
⌗ Tags: #Malware #APT36 #ClickFix #Cyberespionage #DRAT V2 #Government #India #phishing #RAT #Remote Access Trojan #SideCopy #TAG_140 #Transparent Tribe
Penetration Testing Tools
Pakistan-Aligned APT36 Unleashes DRAT V2: New Delphi RAT Targets Indian Government
Pakistan-aligned APT36 (TAG-140) unleashes DRAT V2, a new Delphi-compiled RAT, in a cyber-espionage campaign targeting Indian government entities via ClickFix social engineering.
⤷ Title: Critical macOS SMBClient Flaws Allow Remote Code Execution & Kernel Crashes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:33:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_24235 #CVE_2025_24269 #cybersecurity #Heap Overflow #kernel #macos #RCE #remote code execution #SMB #SMBClient #use_after_free #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:33:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_24235 #CVE_2025_24269 #cybersecurity #Heap Overflow #kernel #macos #RCE #remote code execution #SMB #SMBClient #use_after_free #vulnerability
Penetration Testing Tools
Critical macOS SMBClient Flaws Allow Remote Code Execution & Kernel Crashes
Critical flaws in macOS SMBClient (CVE-2025-24269, CVSS 9.8) allow RCE via kernel heap overflow and process termination, impacting a broad user base. Apple has patched them.
⤷ Title: Spain’s .es Domain Surges 19x in Cybercrime Use: Now Third Most Popular for Phishing & RATs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:31:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.es Domain #Cloudflare #Cofense #cybercrime #cybersecurity #malware #phishing #RAT #Remote Access Trojan #Spain #TLD Abuse
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:31:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.es Domain #Cloudflare #Cofense #cybercrime #cybersecurity #malware #phishing #RAT #Remote Access Trojan #Spain #TLD Abuse
Penetration Testing Tools
Spain's .es Domain Surges 19x in Cybercrime Use: Now Third Most Popular for Phishing & RATs
Spain's .es domain surged 19x in cybercrime use, becoming the 3rd most popular TLD for phishing & RATs. Attackers use random subdomains hosted on Cloudflare to bypass detection.
⤷ Title: Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:24:42 +0000
════════════════════════
⌗ Tags: #Malware #Cryptojacking #cryptomining #cybersecurity #HoneyPot #Java Debug Wire Protocol #JDWP #malware #RCE #remote code execution #TeamCity #Wiz Research Team
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:24:42 +0000
════════════════════════
⌗ Tags: #Malware #Cryptojacking #cryptomining #cybersecurity #HoneyPot #Java Debug Wire Protocol #JDWP #malware #RCE #remote code execution #TeamCity #Wiz Research Team
Penetration Testing Tools
Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
Wiz Research Team uncovers rapid exploitation of exposed JDWP interfaces, deploying XMRig cryptominers in TeamCity and other Java environments within hours of exposure.
⤷ Title: iOS 26 Beta 3 Unleashed: Apple Refines “Liquid Glass” UI, Boosting Readability in Music, Safari & More
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:58:01 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Beta 3 #Bug Fixes #Design #iOS 26 #Liquid Glass #Music App #readability #Safari #Tech News #UI #User Interface
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:58:01 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Beta 3 #Bug Fixes #Design #iOS 26 #Liquid Glass #Music App #readability #Safari #Tech News #UI #User Interface
Daily CyberSecurity
iOS 26 Beta 3 Unleashed: Apple Refines "Liquid Glass" UI, Boosting Readability in Music, Safari & More
iOS 26 Beta 3 refines the "Liquid Glass" UI, addressing readability issues by adjusting menu transparency in apps like Music and Safari, with a Public Beta expected soon.
⤷ Title: Galaxy Z Fold7 & Flip7 Leaked: Samsung’s Thinnest Foldables Yet Unveiling July 9 at Unpacked
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:58:54 +0000
════════════════════════
⌗ Tags: #Technology #Flex G #Foldable Smartphone #Galaxy Unpacked #Galaxy Z Flip7 #Galaxy Z Fold7 #Lightweight #Punch_Hole Display #Roland Quandt #samsung #Tech News #Thinnest
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:58:54 +0000
════════════════════════
⌗ Tags: #Technology #Flex G #Foldable Smartphone #Galaxy Unpacked #Galaxy Z Flip7 #Galaxy Z Fold7 #Lightweight #Punch_Hole Display #Roland Quandt #samsung #Tech News #Thinnest
Daily CyberSecurity
Galaxy Z Fold7 & Flip7 Leaked: Samsung's Thinnest Foldables Yet Unveiling July 9 at Unpacked
Samsung's Galaxy Z Fold7 (4.2mm unfolded, 216g) and Flip7 (4.1-inch outer punch-hole) are leaked as its thinnest, lightest foldables yet, set to debut July 9 at Unpacked 2025.
⤷ Title: Apple Appeals €500M EU DMA Fine: Challenges “Unprecedented” Ruling on App Store Policies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:54:59 +0000
════════════════════════
⌗ Tags: #Technology #Antitrust #App Store #Appeal #Apple #Developer Policy #Digital Markets Act #DMA #EU #European Union #Fine #General Court #Tech Regulation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:54:59 +0000
════════════════════════
⌗ Tags: #Technology #Antitrust #App Store #Appeal #Apple #Developer Policy #Digital Markets Act #DMA #EU #European Union #Fine #General Court #Tech Regulation
Daily CyberSecurity
Apple Appeals €500M EU DMA Fine: Challenges "Unprecedented" Ruling on App Store Policies
Apple is appealing the EU's €500M DMA fine, calling the ruling "unprecedented." The company has revised App Store policies but will argue its case in court.
⤷ Title: Galaxy S25 Edge Breaks Sales Records in Europe, Outselling All Previous Plus Models
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:49:38 +0000
════════════════════════
⌗ Tags: #Technology #Counterpoint #Flagship #Galaxy S Plus #Galaxy S25 Edge #mobile technology #Sales #samsung #Smartphone #Tech News #Western Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:49:38 +0000
════════════════════════
⌗ Tags: #Technology #Counterpoint #Flagship #Galaxy S Plus #Galaxy S25 Edge #mobile technology #Sales #samsung #Smartphone #Tech News #Western Europe
Daily CyberSecurity
Galaxy S25 Edge Breaks Sales Records in Europe, Outselling All Previous Plus Models
Samsung's new Galaxy S25 Edge has outsold all previous Plus-series models in Western Europe in its first week, potentially reshaping Samsung's flagship strategy.
⤷ Title: MongoDB Flaws Allow Privilege Escalation & DoS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:42:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #$mergeCursors #cybersecurity #database #Denial of Service #dos #mongodb #mongos #nosql #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 01:42:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #$mergeCursors #cybersecurity #database #Denial of Service #dos #mongodb #mongos #nosql #privilege escalation
Daily CyberSecurity
MongoDB Flaws Allow Privilege Escalation & DoS
MongoDB has patched two flaws: CVE-2025-6713 (CVSS 7.7) allows privilege escalation via $mergeCursors, and CVE-2025-6714 (CVSS 7.5) causes mongos DoS.
⤷ Title: Broken Access Control: When Good Bug Only Get “Informative”
════════════════════════
𐀪 Author: Zeta
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:49:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #privilege_escalation #penetration_testing #hacking #bug_bounty
════════════════════════
𐀪 Author: Zeta
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 02:49:11 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #privilege_escalation #penetration_testing #hacking #bug_bounty
Medium
Broken Access Control: When Good Bug Only Get “Informative”
Disclaimer: This article is purely for educational purposes. All bugs have been reported through responsible disclosure.