⤷ Title: GPOHound: Offensive GPO dumping and analysis tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:39:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #BloodHound #cybersecurity #GPO #GPOHound #Group Policy Objects #misconfigurations #privilege escalation #Security Tools #SYSVOL
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:39:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #BloodHound #cybersecurity #GPO #GPOHound #Group Policy Objects #misconfigurations #privilege escalation #Security Tools #SYSVOL
Penetration Testing Tools
GPOHound: Offensive GPO dumping and analysis tool
GPOHound analyzes GPOs in Active Directory for misconfigurations and privilege escalation paths, integrating with BloodHound for enhanced security insights.
⤷ Title: Critical Wing FTP Server RCE (CVE-2025-47812) Actively Exploited In The Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:38:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:38:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_47812 #cybersecurity #Exploited in Wild #FTP Server #Huntress #Lua #Null Byte Injection #rce #Remote Code Execution #Vulnerability #Wing FTP Server
Daily CyberSecurity
Critical Wing FTP Server RCE (CVE-2025-47812) Actively Exploited In The Wild
Huntress witnessed active exploitation of a critical RCE flaw (CVE-2025-47812) in Wing FTP Server, allowing root/SYSTEM access via null byte injection and Lua code execution.
⤷ Title: Juniper Security Director Alert: Critical Flaw Allows Unauthenticated Access to Sensitive Resources
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:36:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVSS 9.6 #cybersecurity #Juniper #Missing Authorization #network_security #Security Director
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:36:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CVSS 9.6 #cybersecurity #Juniper #Missing Authorization #network_security #Security Director
Daily CyberSecurity
Juniper Security Director Alert: Critical Flaw Allows Unauthenticated Access to Sensitive Resources
Juniper warns of a critical flaw (CVE-2025-52950, CVSS 9.6) in Security Director 24.4.1, allowing unauthenticated attackers to read or tamper with sensitive resources. Update immediately.
⤷ Title: Laravel Flaw: Leaked APP_KEY Turns Into Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:28:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APP_KEY #cybersecurity #Deserialization #Laravel #php #rce #Remote Code Execution #Synacktiv #Vulnerability #web framework
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:28:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APP_KEY #cybersecurity #Deserialization #Laravel #php #rce #Remote Code Execution #Synacktiv #Vulnerability #web framework
Daily CyberSecurity
Laravel Flaw: Leaked APP_KEY Turns Into Remote Code Execution
Synacktiv reveals Laravel’s APP_KEY vulnerability allows RCE via deserialization attacks when the key is leaked or guessable, risking full application compromise.
⤷ Title: New macOS.ZuRu Variant Uses Trojanized Termius App to Infiltrate Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:22:01 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Khepri #macOS #macOS.ZuRu #malware #Remote Access #SentinelOne #SSH Client #Termius #Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:22:01 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Khepri #macOS #macOS.ZuRu #malware #Remote Access #SentinelOne #SSH Client #Termius #Trojan
Daily CyberSecurity
New macOS.ZuRu Variant Uses Trojanized Termius App to Infiltrate Systems
SentinelOne uncovers a new macOS.ZuRu variant using a trojanized Termius app. It gains persistence via LaunchDaemon and deploys a Khepri C2 beacon for remote control.
⤷ Title: SafePay Ransomware Unleashed: New LockBit 3.0 Variant Hits 200+ MSPs & SMBs Worldwide
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:19:25 +0000
════════════════════════
⌗ Tags: #Malware #Acronis #AES #cybersecurity #LockBit 3.0 #LOCKBIT Black #MSP #ransomware #RDP #RSA #SafePay #smb #UAC bypass #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:19:25 +0000
════════════════════════
⌗ Tags: #Malware #Acronis #AES #cybersecurity #LockBit 3.0 #LOCKBIT Black #MSP #ransomware #RDP #RSA #SafePay #smb #UAC bypass #Windows Defender Bypass
Daily CyberSecurity
SafePay Ransomware Unleashed: New LockBit 3.0 Variant Hits 200+ MSPs & SMBs Worldwide
SafePay, a new centralized ransomware group linked to LockBit 3.0, has hit 200+ MSPs/SMBs via RDP. It bypasses Defender, encrypts files, and exfiltrates data using WinRAR and FileZilla.
⤷ Title: DoNot APT Expands to Europe: Targets Foreign Ministry with LoptikMod Malware via Google Drive Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:11:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT_C_35 #Cyberespionage #cybersecurity #DONOT APT #Europe #Foreign Affairs #Google Drive #LoptikMod #malware #Mint Tempest #Origami Elephant #phishing #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:11:52 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT_C_35 #Cyberespionage #cybersecurity #DONOT APT #Europe #Foreign Affairs #Google Drive #LoptikMod #malware #Mint Tempest #Origami Elephant #phishing #Trellix
Daily CyberSecurity
DoNot APT Expands to Europe: Targets Foreign Ministry with LoptikMod Malware via Google Drive Phishing
DoNot APT (APT-C-35) expands its cyber-espionage to a European foreign affairs ministry, using spear-phishing with Google Drive links to deliver the LoptikMod backdoor.
⤷ Title: Iranian Ransomware “Pay2Key.I2P” Resurfaces on I2P Network, Offering 80% Profit for Targeting Western Enemies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:08:30 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fox Kitten #geopolitics #I2P network #Iranian APT #Mimic Ransomware #Pay2Key.I2P #RaaS #ransomware #Ransomware_as_a_Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:08:30 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fox Kitten #geopolitics #I2P network #Iranian APT #Mimic Ransomware #Pay2Key.I2P #RaaS #ransomware #Ransomware_as_a_Service
Daily CyberSecurity
Iranian Ransomware "Pay2Key.I2P" Resurfaces on I2P Network, Offering 80% Profit for Targeting Western Enemies
Iranian-backed "Pay2Key.I2P" ransomware resurfaced on I2P, offering 80% profit for attacks on Western targets. Linked to Fox Kitten & Mimic, it merges cybercrime with geopolitical motives.
⤷ Title: Helm Flaw (CVE-2025-53547): Local Code Execution via Malicious Chart.yaml & Symlinks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chart.lock #Chart.yaml #CVE_2025_53547 #cybersecurity #Kubernetes #LCE #Local Code Execution #Package manager #Symlinks #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:00:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Chart.lock #Chart.yaml #CVE_2025_53547 #cybersecurity #Kubernetes #LCE #Local Code Execution #Package manager #Symlinks #Vulnerability
Daily CyberSecurity
Helm Flaw (CVE-2025-53547): Local Code Execution via Malicious Chart.yaml & Symlinks
A flaw in Helm (CVE-2025-53547, CVSS 8.5) allows local code execution when updating dependencies via a malicious Chart.yaml and symlinked Chart.lock file
⤷ Title: Cryptographic Failures: La Guía Definitiva para Hacking, Bug Bounty y Seguridad Web
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:01:44 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #bug_bounty #ethical_hacking #penetration_testing
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:01:44 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #bug_bounty #ethical_hacking #penetration_testing
Medium
Cryptographic Failures: La Guía Definitiva para Hacking, Bug Bounty y Seguridad Web
Protege tus Datos. Descubre y Mitiga las Vulnerabilidades Criptográficas Más Críticas.
⤷ Title: Critical IDOR Chain — Edit Any User’s Role, Activate/Deactivate Accounts, and Escalate Privileges
════════════════════════
𐀪 Author: B0d4
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 23:04:49 GMT
════════════════════════
⌗ Tags: #bounty_program #security #idor #web_security #bug_bounty
════════════════════════
𐀪 Author: B0d4
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 23:04:49 GMT
════════════════════════
⌗ Tags: #bounty_program #security #idor #web_security #bug_bounty
Medium
🔓Critical IDOR Chain — Edit Any User’s Role, Activate/Deactivate Accounts, and Escalate Privileges
Summary:
⤷ Title: How to become a “HACKER”
════════════════════════
𐀪 Author: Omar Shraideh
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:44:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #hacking #tech #programming
════════════════════════
𐀪 Author: Omar Shraideh
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:44:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #hacking #tech #programming
Medium
How to become a “HACKER”
Hey, everyone!
I’m Omar Shraideh, and I’ve been in cybersecurity for nearly three years. I didn’t come from a tech family or go to…
I’m Omar Shraideh, and I’ve been in cybersecurity for nearly three years. I didn’t come from a tech family or go to…
⤷ Title: Inside the Adversary’s Mindset: The #1 Skill Missing From Most Cyber Defenders
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:18:02 GMT
════════════════════════
⌗ Tags: #education #cybersecurity #hacking #leadership #learning
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:18:02 GMT
════════════════════════
⌗ Tags: #education #cybersecurity #hacking #leadership #learning
Medium
Inside the Adversary’s Mindset: The #1 Skill Missing From Most Cyber Defenders
“The most dangerous attacker isn’t the one with zero-days — it’s the one who studies you longer than you studied them.”
⤷ Title: McDonald’s Australia Data Breach via AI Chatbot ‘Olivia’: A Cybersecurity Breakdown
════════════════════════
𐀪 Author: Sayan Raha
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:07:21 GMT
════════════════════════
⌗ Tags: #hacker #ai #cyber_security_awareness #hacking #cybersecurity
════════════════════════
𐀪 Author: Sayan Raha
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:07:21 GMT
════════════════════════
⌗ Tags: #hacker #ai #cyber_security_awareness #hacking #cybersecurity
Medium
McDonald’s Australia Data Breach via AI Chatbot ‘Olivia’: A Cybersecurity Breakdown
📌 Introduction: When Hiring Automation Becomes a Vulnerability
⤷ Title: Windows Threat Detection 1: TryHackMe Answers
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:22:15 GMT
════════════════════════
⌗ Tags: #tryhackme #windows_threat_detection #tryhackme_walkthrough #cybersecurity #tryhackme_writeup
════════════════════════
𐀪 Author: Ansul Kotadia
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:22:15 GMT
════════════════════════
⌗ Tags: #tryhackme #windows_threat_detection #tryhackme_walkthrough #cybersecurity #tryhackme_writeup
Medium
Windows Threat Detection 1: TryHackMe Answers
Explore common Initial Access methods on Windows and learn how to detect them.
⤷ Title: PortSwigger Lab: Manipulating the WebSocket handshake to exploit vulnerabilities writeup…
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:57:47 GMT
════════════════════════
⌗ Tags: #portswigger #burpsuite #web_app_security #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:57:47 GMT
════════════════════════
⌗ Tags: #portswigger #burpsuite #web_app_security #cybersecurity #penetration_testing
Medium
PortSwigger Lab: Manipulating the WebSocket handshake to exploit vulnerabilities writeup (Websockets)
This online shop has a live chat feature implemented using WebSockets.
⤷ Title: PortSwigger Lab: Manipulating WebSocket messages to exploit vulnerabilities writeup (Websockets)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:53:48 GMT
════════════════════════
⌗ Tags: #burpsuite #cybersecurity #portswigger #web_application_security #penetration_testing
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:53:48 GMT
════════════════════════
⌗ Tags: #burpsuite #cybersecurity #portswigger #web_application_security #penetration_testing
Medium
PortSwigger Lab: Manipulating WebSocket messages to exploit vulnerabilities writeup (Websockets)
This online shop has a live chat feature implemented using WebSockets.
⤷ Title: I walked into a Fortune 500 HQ … No one stopped me.
════════════════════════
𐀪 Author: JD Brooks
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 23:16:38 GMT
════════════════════════
⌗ Tags: #red_team #social_engineering #cybersecurity #penetration_testing #physical_security
════════════════════════
𐀪 Author: JD Brooks
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 23:16:38 GMT
════════════════════════
⌗ Tags: #red_team #social_engineering #cybersecurity #penetration_testing #physical_security
Medium
I walked into a Fortune 500 HQ … No one stopped me.
The front desk was backed up…couriers, delivery guys, two different clipboards getting passed around. Loud, disorganized. Just the way I…
⤷ Title: Chocolate Factory TryHackMe CTF Çözümü
════════════════════════
𐀪 Author: Beratcamm
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:16:16 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #cybersecurity #privilege_escalation #ctf_writeup
════════════════════════
𐀪 Author: Beratcamm
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 00:16:16 GMT
════════════════════════
⌗ Tags: #tryhackme #ctf #cybersecurity #privilege_escalation #ctf_writeup
Medium
Chocolate Factory TryHackMe CTF Çözümü
Merhaba, bu yazımda TryHackMe’deki Chocolate Factory CTF’inin çözümünü paylaşacağım.
⤷ Title: Ethcode Compromised: Over 6,000 Devs Hit by Malicious VS Code Extension
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 02:57:45 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #cybersecurity #developers #Ethcode #Ethereum #EVM #malware #open source #ReversingLabs #smart contracts #supply chain attack #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 02:57:45 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #cybersecurity #developers #Ethcode #Ethereum #EVM #malware #open source #ReversingLabs #smart contracts #supply chain attack #VS Code
Penetration Testing Tools
Ethcode Compromised: Over 6,000 Devs Hit by Malicious VS Code Extension
A malicious update to the Ethcode VS Code extension compromised over 6,000 developers, highlighting a growing threat in open-source supply chain attacks.
⤷ Title: Windows 11 Beta Build 22631.5696: Critical Fixes for ReFS & Printing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 02:53:46 +0000
════════════════════════
⌗ Tags: #Windows #Beta #bug fix #File System #IPP #KB5062663 #Microsoft #network #printing #ReFS #Update #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 02:53:46 +0000
════════════════════════
⌗ Tags: #Windows #Beta #bug fix #File System #IPP #KB5062663 #Microsoft #network #printing #ReFS #Update #Windows 11
Penetration Testing Tools
Windows 11 Beta Build 22631.5696: Critical Fixes for ReFS & Printing
Windows 11 Beta Build 22631.5696 is out with crucial fixes for ReFS memory exhaustion, printing errors, and network issues. Expect stable release soon!