⤷ Title: VS Code ETHcode Extension Hacked: Just 2 Lines of Code Led to Supply Chain Compromise Via GitHub PR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:46:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #ETHcode #Ethereum #Extension #github #malware #Pull Request #ReversingLabs #supply chain attack #Typosquatting #visual studio code #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:46:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #ETHcode #Ethereum #Extension #github #malware #Pull Request #ReversingLabs #supply chain attack #Typosquatting #visual studio code #VS Code
Daily CyberSecurity
VS Code ETHcode Extension Hacked: Just 2 Lines of Code Led to Supply Chain Compromise Via GitHub PR
ReversingLabs exposes a supply chain compromise of the VS Code ETHcode extension via two lines of malicious code in a GitHub PR, leading to malware deployment.
⤷ Title: Critical Flaws Found in Siemens SINEC NMS: Privilege Escalation and Remote Code Execution Risks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:36:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cybersecurity #ICS #industrial control systems #Network Management #Path Traversal #rce #Remote Code Execution #SCADA #Siemens #SINEC NMS #sql injection #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:36:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #cybersecurity #ICS #industrial control systems #Network Management #Path Traversal #rce #Remote Code Execution #SCADA #Siemens #SINEC NMS #sql injection #Vulnerability
Daily CyberSecurity
Critical Flaws Found in Siemens SINEC NMS: Privilege Escalation and Remote Code Execution Risks
Siemens warns of critical flaws (CVE-2025-40736 CVSS 9.8 Auth Bypass, SQLi, Path Traversal) in SINEC NMS, allowing unauthenticated remote root access and RCE.
⤷ Title: Citrix Warns of Privilege Escalation Vulnerability in Windows Virtual Delivery Agent (CVE-2025-6759)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:31:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Citrix #Citrix DaaS #Citrix Virtual Apps and Desktops #CVAD #CVE_2025_6759 #cybersecurity #privilege escalation #SYSTEM privileges #VDA #Virtual Delivery Agent #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:31:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Citrix #Citrix DaaS #Citrix Virtual Apps and Desktops #CVAD #CVE_2025_6759 #cybersecurity #privilege escalation #SYSTEM privileges #VDA #Virtual Delivery Agent #Vulnerability
Daily CyberSecurity
Citrix Warns of Privilege Escalation Vulnerability in Windows Virtual Delivery Agent (CVE-2025-6759)
Citrix warns of a high-severity local privilege escalation flaw (CVE-2025-6759, CVSSv4 7.3) in Windows VDA, allowing low-privileged users to gain SYSTEM access.
⤷ Title: Apache Tomcat Patches Trio of Denial-of-Service Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:29:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #APR #Denial of Service #dos #file upload #HTTP/2 #Multipart #web server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:29:02 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache Tomcat #APR #Denial of Service #dos #file upload #HTTP/2 #Multipart #web server
Daily CyberSecurity
Apache Tomcat Patches Trio of Denial-of-Service Flaws
Apache Tomcat 9.0.107 patches three critical DoS flaws (CVE-2025-52434, CVE-2025-52520, CVE-2025-53506) that can disrupt web services via HTTP/2, file uploads, and excessive streams.
⤷ Title: OmegaPro Founders Charged: DOJ Unseals Indictment for $650M Global Crypto Ponzi Scheme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:25:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Fraud #cryptocurrency #Cybercrime #Department of Justice #DOJ #Juan Carlos Reynoso #Michael Shannon Sims #MLM #money laundering #Multi_Level Marketing #OmegaPro #Ponzi scheme #Wire Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:25:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Fraud #cryptocurrency #Cybercrime #Department of Justice #DOJ #Juan Carlos Reynoso #Michael Shannon Sims #MLM #money laundering #Multi_Level Marketing #OmegaPro #Ponzi scheme #Wire Fraud
Daily CyberSecurity
OmegaPro Founders Charged: DOJ Unseals Indictment for $650M Global Crypto Ponzi Scheme
The DOJ unsealed an indictment against OmegaPro founders for a $650M global crypto Ponzi scheme. They face charges for defrauding investors with fake forex trading promises.
⤷ Title: Microsoft’s July 2025 Patch Tuesday: 140 Flaws Fixed, Including Zero-Day, RCEs & AMD CPU Threats
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:21:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #CPU Vulnerabilities #CVE_2025_47981 #CVE_2025_49719 #CVE_2025_49735 #cybersecurity #Elevation of Privilege #Hyper_V #Information Disclosure #Microsoft #office #Patch Tuesday #rce #sql server #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:21:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #CPU Vulnerabilities #CVE_2025_47981 #CVE_2025_49719 #CVE_2025_49735 #cybersecurity #Elevation of Privilege #Hyper_V #Information Disclosure #Microsoft #office #Patch Tuesday #rce #sql server #zero_day
Daily CyberSecurity
Microsoft’s July 2025 Patch Tuesday: 140 Flaws Fixed, Including Zero-Day, RCEs & AMD CPU Threats
Microsoft's July 2025 Patch Tuesday fixes 140 flaws, including a SQL Server zero-day (CVE-2025-49719), multiple RCEs, critical Office/Word bugs, and AMD CPU-level threats.
⤷ Title: Philippines Hit by Surge in Chinese Cybercrime: NFC & Smishing Attacks Steal Millions from Mobile Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:17:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese hackers #Cybercrime #cybersecurity #Financial Sector #GCash #GoTyme #Maya #Mobile Wallets #NFC Fraud #Philippines #Resecurity #smishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:17:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chinese hackers #Cybercrime #cybersecurity #Financial Sector #GCash #GoTyme #Maya #Mobile Wallets #NFC Fraud #Philippines #Resecurity #smishing
Daily CyberSecurity
Philippines Hit by Surge in Chinese Cybercrime: NFC & Smishing Attacks Steal Millions from Mobile Wallets
Chinese cybercriminals are escalating attacks on the Philippine financial sector, exploiting NFC technology and smishing to steal from mobile wallets, with a 230% surge in dark web activity.
⤷ Title: Fortinet Fixes Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257, CVSS 9.6)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:14:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_25257 #cybersecurity #FortiWeb #rce #Remote Code Execution #sql injection #unauthenticated #Vulnerability #waf #Web Application Firewall
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:14:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_25257 #cybersecurity #FortiWeb #rce #Remote Code Execution #sql injection #unauthenticated #Vulnerability #waf #Web Application Firewall
Daily CyberSecurity
Fortinet Fixes Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257, CVSS 9.6)
Fortinet released a critical patch for FortiWeb (CVE-2025-25257, CVSS 9.6). This unauthenticated SQL injection flaw allows remote code execution; update immediately!
⤷ Title: Chinese State-Sponsored Hacker Xu Zewei Arrested in Italy for COVID-19 Research & Exchange Server Hacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:11:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #china #COVID_19 Research #Cyberespionage #DOJ #fbi #HAFNIUM #Microsoft Exchange #MSS #Xu Zewei #zero_day #Zhang Yu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:11:47 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #china #COVID_19 Research #Cyberespionage #DOJ #fbi #HAFNIUM #Microsoft Exchange #MSS #Xu Zewei #zero_day #Zhang Yu
Daily CyberSecurity
Chinese State-Sponsored Hacker Xu Zewei Arrested in Italy for COVID-19 Research & Exchange Server Hacks
Chinese national Xu Zewei, linked to HAFNIUM, arrested in Italy for cyberespionage. He targeted US COVID-19 research & exploited Exchange zero-days, compromising 60,000+ US entities for China's MSS.
⤷ Title: Anatsa Resurfaces: Banking Trojan Targets North America via Google Play
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #Anatsa #android #Banking Trojan #Credential Theft #Cybercrime #Google Play Store #Keylogging #malware #North America #Overlay Attacks #Remote Control Fraud #ThreatFabric
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:07:00 +0000
════════════════════════
⌗ Tags: #Malware #Anatsa #android #Banking Trojan #Credential Theft #Cybercrime #Google Play Store #Keylogging #malware #North America #Overlay Attacks #Remote Control Fraud #ThreatFabric
Daily CyberSecurity
Anatsa Resurfaces: Banking Trojan Targets North America via Google Play
Anatsa, an advanced Android banking trojan, is targeting North America via Google Play. It steals credentials and conducts remote fraud through disguised apps and overlay attacks.
⤷ Title: Critical Flaws in Phoenix Contact EV Charging Controllers Expose Infrastructure to Remote Code Execution and Unauthorized Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:00:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #Charging Controller #CHARX SEC_3xxx #cybersecurity #Electric Vehicle #EV #Phoenix Contact #privilege escalation #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:00:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #Charging Controller #CHARX SEC_3xxx #cybersecurity #Electric Vehicle #EV #Phoenix Contact #privilege escalation #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Critical Flaws in Phoenix Contact EV Charging Controllers Expose Infrastructure to Remote Code Execution and Unauthorized Access
Phoenix Contact warns of critical flaws (CVE-2025-25270 CVSS 9.8 RCE, CVE-2025-25268 Auth Bypass, CVE-2025-25271 OCPP Reconfig, CVE-2025-25269 LPE) in CHARX SEC-3xxx EV controllers.
⤷ Title: Google’s New Android Advanced Protection Supercharges Chrome Security for High-Risk Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 23:38:01 +0000
════════════════════════
⌗ Tags: #Android #Advanced Protection Program #android #APP #chrome #cybersecurity #google #HTTPS_Only Mode #javascript #mobile security #privacy #Site Isolation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 23:38:01 +0000
════════════════════════
⌗ Tags: #Android #Advanced Protection Program #android #APP #chrome #cybersecurity #google #HTTPS_Only Mode #javascript #mobile security #privacy #Site Isolation
Daily CyberSecurity
Google’s New Android Advanced Protection Supercharges Chrome Security for High-Risk Users
Google's Advanced Protection Program now offers device-level security for Android, bringing HTTPS-Only Mode, full Site Isolation, and disabled JS optimizers to Chrome for high-risk users.
⤷ Title: Start with VDPs Before Aiming for Private Bug Bounty Programs
════════════════════════
𐀪 Author: 127.0.0.1
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:02:19 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability #money #private #vdp
════════════════════════
𐀪 Author: 127.0.0.1
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:02:19 GMT
════════════════════════
⌗ Tags: #bug_bounty #vulnerability #money #private #vdp
Medium
Start with VDPs Before Aiming for Private Bug Bounty Programs
Loophole how I get more private programs + $$$$
⤷ Title: FortiOS CVE-2025–24477 Exposes Systems to Code Execution
════════════════════════
𐀪 Author: Darshan
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:43:28 GMT
════════════════════════
⌗ Tags: #ai #technology #fortinet #cybersecurity #tech
════════════════════════
𐀪 Author: Darshan
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:43:28 GMT
════════════════════════
⌗ Tags: #ai #technology #fortinet #cybersecurity #tech
Medium
FortiOS CVE-2025–24477 Exposes Systems to Code Execution
Fortinet has revealed a notable security flaw in its FortiOS operating system, identified as CVE-2025–24477, which highlights how even…
⤷ Title: ประจำวันพุธที่ 9 กรกฎาคม 2568
════════════════════════
𐀪 Author: ThaiCERT By NCSA
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:36:16 GMT
════════════════════════
⌗ Tags: #cybersecurity
════════════════════════
𐀪 Author: ThaiCERT By NCSA
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 02:36:16 GMT
════════════════════════
⌗ Tags: #cybersecurity
Medium
ประจำวันพุธที่ 9 กรกฎาคม 2568
ระวังภัย SEO Poisoning แฮกเกอร์หลอกติดตั้งมัลแวร์ กลุ่ม SMB ตกเป็นเหยื่อแล้ว 8,500 ราย
⤷ Title: The Hidden Dangers of AI-Generated Code
════════════════════════
𐀪 Author: Sophia Perez
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:54:31 GMT
════════════════════════
⌗ Tags: #coding #ai #cybersecurity #devops
════════════════════════
𐀪 Author: Sophia Perez
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:54:31 GMT
════════════════════════
⌗ Tags: #coding #ai #cybersecurity #devops
Medium
The Hidden Dangers of AI-Generated Code
AI-powered coding tools like GitHub Copilot and ChatGPT are transforming the way software is written. They enable faster development and…
⤷ Title: Miscellaneous Series 5 — Level up a Script Kiddie v8 skills Part 1
════════════════════════
𐀪 Author: INTfinity Consulting
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:39:17 GMT
════════════════════════
⌗ Tags: #binary_exploitation #cybersecurity #browsers
════════════════════════
𐀪 Author: INTfinity Consulting
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:39:17 GMT
════════════════════════
⌗ Tags: #binary_exploitation #cybersecurity #browsers
Medium
Miscellaneous Series 5 — Level up a Script Kiddie v8 skills Part 1
Going through the first four levels of pwn.college v8 exploitation challenge
⤷ Title: Soul Cyber Tech Brief
════════════════════════
𐀪 Author: Ameer R. Weston-Lee / Soul Cyber
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:30:04 GMT
════════════════════════
⌗ Tags: #noir #privacy #network #cybersecurity #technology
════════════════════════
𐀪 Author: Ameer R. Weston-Lee / Soul Cyber
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 01:30:04 GMT
════════════════════════
⌗ Tags: #noir #privacy #network #cybersecurity #technology
Medium
Soul Cyber Tech Brief
Bitchat: A Resilient, Private Messaging System Without the Internet
⤷ Title: Signed Drivers Fueling Kernel Attacks: 620+ Malicious Drivers & 80+ Compromised Certs Target Windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 03:03:59 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Digital Signatures #EV Certificates #Group_IB #kernel #malware #ransomware #Signed Drivers #WHCP #windows #Windows Hardware Compatibility Program
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 03:03:59 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Digital Signatures #EV Certificates #Group_IB #kernel #malware #ransomware #Signed Drivers #WHCP #windows #Windows Hardware Compatibility Program
Penetration Testing Tools
Signed Drivers Fueling Kernel Attacks: 620+ Malicious Drivers & 80+ Compromised Certs Target Windows
Group-IB exposes 620+ malicious digitally signed drivers and 80+ compromised certificates since 2020, fueling stealthy Windows kernel attacks and bypassing security defenses.
⤷ Title: Ransomware War Ignites: DragonForce & RansomHub Clash Threatens Businesses with Re-Extortion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 03:01:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Affiliate Marketing #Cyber Conflict #cybercrime #cybersecurity #DragonForce #Extortion #RaaS #RansomHub #ransomware #Ransomware_as_a_Service
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 03:01:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Affiliate Marketing #Cyber Conflict #cybercrime #cybersecurity #DragonForce #Extortion #RaaS #RansomHub #ransomware #Ransomware_as_a_Service
Penetration Testing Tools
Ransomware War Ignites: DragonForce & RansomHub Clash Threatens Businesses with Re-Extortion
A war between DragonForce and RansomHub ransomware groups threatens businesses with re-extortion. DragonForce's cartel model and RansomHub's alleged takedown mark escalating tensions.
⤷ Title: Part 3: The Custom Gate — Building a Custom Authentication Scheme
════════════════════════
𐀪 Author: Rohit Mittel
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 04:32:57 GMT
════════════════════════
⌗ Tags: #custom_authentication #authentication #2_factor_authentication #application_security #oracle_apex
════════════════════════
𐀪 Author: Rohit Mittel
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 04:32:57 GMT
════════════════════════
⌗ Tags: #custom_authentication #authentication #2_factor_authentication #application_security #oracle_apex
Medium
customPart 3: The Custom Gate — Building a Custom Authentication Scheme
Welcome back, Gatekeeper.