⤷ Title: New ‘Win-DDoS’ Attack Turns Windows Servers Into a Global Botnet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 08:43:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #BOTNET #cybersecurity #DDoS #DEF CON #LDAP #SafeBreach #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 08:43:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #BOTNET #cybersecurity #DDoS #DEF CON #LDAP #SafeBreach #windows
Penetration Testing Tools
New 'Win-DDoS' Attack Turns Windows Servers Into a Global Botnet
A new attack technique called "Win-DDoS" can turn thousands of Windows domain controllers into a powerful DDoS botnet without compromising the devices.
⤷ Title: Your Webcam Can Be a Hacker’s Weapon: New ‘BadCam’ Attack Hijacks Lenovo Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 08:41:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #BadUSB #cybersecurity #DEF CON #Eclypsium #firmware #Lenovo #Webcam
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 08:41:52 +0000
════════════════════════
⌗ Tags: #Vulnerability #BadUSB #cybersecurity #DEF CON #Eclypsium #firmware #Lenovo #Webcam
Penetration Testing Tools
Your Webcam Can Be a Hacker's Weapon: New 'BadCam' Attack Hijacks Lenovo Devices
A new "BadCam" attack can turn Lenovo webcams into a BadUSB device, allowing remote hackers to run malicious code and reinfect systems even after a wipe.
⤷ Title: Hackers Leak 9GB of Data from Alleged North Korean Hacker’s Computer
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 13:26:11 +0000
════════════════════════
⌗ Tags: #Security #Hacking News #cyb0rg #Cyber Attack #Cybersecurity #DDoSecrets #def con #Kimsuky #North Korea #Phrack #Saber
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 13:26:11 +0000
════════════════════════
⌗ Tags: #Security #Hacking News #cyb0rg #Cyber Attack #Cybersecurity #DDoSecrets #def con #Kimsuky #North Korea #Phrack #Saber
Hackread
Hackers Leak 9GB of Data from Alleged North Korean Hacker’s Computer
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: BadCam: Critical Flaws in Lenovo Linux Webcams Allow Remote BadUSB Attacks and Persistent Infections
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 00:05:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BadUSB #cybersecurity #DEF CON #Eclypsium #firmware #HID #Lenovo Webcams #Linux #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 00:05:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BadUSB #cybersecurity #DEF CON #Eclypsium #firmware #HID #Lenovo Webcams #Linux #Remote Code Execution
Daily CyberSecurity
BadCam: Critical Flaws in Lenovo Linux Webcams Allow Remote BadUSB Attacks and Persistent Infections
Eclypsium researchers have uncovered a new class of BadUSB attacks, which leverage critical flaws in Linux-based Lenovo webcams to deliver persistent payloads and bypass security.
⤷ Title: our Windows System Is Not Safe: New ‘EPM Poisoning’ Attack Hijacks RPC Protocol
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 02:15:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #DEF CON #EPM Poisoning #RPC #SafeBreach #vulnerability #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 12 Aug 2025 02:15:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #DEF CON #EPM Poisoning #RPC #SafeBreach #vulnerability #windows
Penetration Testing Tools
our Windows System Is Not Safe: New 'EPM Poisoning' Attack Hijacks RPC Protocol
A new "EPM poisoning" attack bypasses Windows security by hijacking the RPC protocol, allowing an unprivileged user to escalate privileges and steal NTLM hashes.
⤷ Title: Beyond the Cookie Jar: Uncovering Privacy Flaws in Google’s New Ad Tech
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 10:02:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #ad tech #cybersecurity #data privacy #DEF CON #google #privacy #privacy sandbox #Vulnerability Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 10:02:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #ad tech #cybersecurity #data privacy #DEF CON #google #privacy #privacy sandbox #Vulnerability Research
Penetration Testing Tools
Beyond the Cookie Jar: Uncovering Privacy Flaws in Google's New Ad Tech
A new book reveals critical vulnerabilities in Google's Privacy Sandbox, showing how its new APIs could be exploited to harvest user data.
⤷ Title: Major Flaw Exposes Password Managers to “One-Click” Data Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 08:54:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #1Password #Browser Extensions #clickjacking #cybersecurity #data breach #DEF CON #LastPass #Password Manager #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 08:54:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #1Password #Browser Extensions #clickjacking #cybersecurity #data breach #DEF CON #LastPass #Password Manager #vulnerability
Penetration Testing Tools
Major Flaw Exposes Password Managers to "One-Click" Data Theft
A new "DOM-based extension clickjacking" vulnerability discovered at DEF CON allows attackers to steal passwords and 2FA codes from popular password managers.
⤷ Title: Microsoft Fixed Entra ID Vulnerability Allowing Global Admin Impersonation
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 21:23:40 +0000
════════════════════════
⌗ Tags: #Security #Azure #Black Hat #Cybersecurity #def con #Entra ID #Microsoft #Vulnerability #Zero Trust
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 21:23:40 +0000
════════════════════════
⌗ Tags: #Security #Azure #Black Hat #Cybersecurity #def con #Entra ID #Microsoft #Vulnerability #Zero Trust
Hackread
Microsoft Fixed Entra ID Vulnerability Allowing Global Admin Impersonation
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: GPO Stealth: Turn Active Directory Into Your C2 With the New GroupPolicyBackdoor Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:59:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #DEF CON 33 #GPO Abuse #GroupPolicyBackdoor #LDAP #privilege escalation #python #red teaming #SMB #Stealth Exploitation #Synacktiv
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:59:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Active Directory #DEF CON 33 #GPO Abuse #GroupPolicyBackdoor #LDAP #privilege escalation #python #red teaming #SMB #Stealth Exploitation #Synacktiv
Penetration Testing Tools
GPO Stealth: Turn Active Directory Into Your C2 With the New GroupPolicyBackdoor Framework
Presented at DEF CON 33, GroupPolicyBackdoor is a Python framework for stealthy GPO manipulation, link poisoning, and AD privilege escalation.
⤷ Title: Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 08:05:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DEF CON 34 #NT AUTHORITY SYSTEM #Plug and Play #privilege escalation #Windows PnP attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 08:05:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #DEF CON 34 #NT AUTHORITY SYSTEM #Plug and Play #privilege escalation #Windows PnP attack
Daily CyberSecurity
Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public
TL;DR Two Accenture researchers showed that plugging a USB device into Windows can hand an attacker SYSTEM. The chain needs no admin rights and no logged-in user. Both the vulnerability details an…