⤷ Title: Critical Flaws in Phoenix Contact EV Charging Controllers Expose Infrastructure to Remote Code Execution and Unauthorized Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:00:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #Charging Controller #CHARX SEC_3xxx #cybersecurity #Electric Vehicle #EV #Phoenix Contact #privilege escalation #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 00:00:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CERT@VDE #Charging Controller #CHARX SEC_3xxx #cybersecurity #Electric Vehicle #EV #Phoenix Contact #privilege escalation #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Critical Flaws in Phoenix Contact EV Charging Controllers Expose Infrastructure to Remote Code Execution and Unauthorized Access
Phoenix Contact warns of critical flaws (CVE-2025-25270 CVSS 9.8 RCE, CVE-2025-25268 Auth Bypass, CVE-2025-25271 OCPP Reconfig, CVE-2025-25269 LPE) in CHARX SEC-3xxx EV controllers.
⤷ Title: Phoenix: A New Rowhammer Attack Bypasses DDR5 Protections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 09:11:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #COMSEC #CVE_2025_6202 #cybersecurity #DDR5 #google #Phoenix #Rowhammer #SK Hynix #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 09:11:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #COMSEC #CVE_2025_6202 #cybersecurity #DDR5 #google #Phoenix #Rowhammer #SK Hynix #vulnerability
Penetration Testing Tools
Phoenix: A New Rowhammer Attack Bypasses DDR5 Protections
A new Rowhammer variant, Phoenix, can bypass protections on SK Hynix DDR5 memory modules, leading to privilege escalation and data exfiltration.
⤷ Title: Phoenix (CVE-2025-6202): A New Rowhammer Attack Bypasses DDR5 Protections
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_6202 #cybersecurity #DDR5 #ETH Zurich #memory corruption #Phoenix #privilege escalation #Rowhammer #SK Hynix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_6202 #cybersecurity #DDR5 #ETH Zurich #memory corruption #Phoenix #privilege escalation #Rowhammer #SK Hynix
Daily CyberSecurity
Phoenix (CVE-2025-6202): A New Rowhammer Attack Bypasses DDR5 Protections
A new Rowhammer attack, "Phoenix," bypasses DDR5 protections on all tested SK Hynix devices, enabling memory corruption and privilege escalation.
⤷ Title: MuddyWater APT Shifts Tactics to Custom Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Sep 2025 00:22:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #BugSleep #Fooder #Group_IB #Iran #MuddyWater #Phoenix #state_sponsored #StealthCache #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Sep 2025 00:22:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #BugSleep #Fooder #Group_IB #Iran #MuddyWater #Phoenix #state_sponsored #StealthCache #threat intelligence
Daily CyberSecurity
MuddyWater APT Shifts Tactics to Custom Malware
Group-IB reports on MuddyWater, an Iranian APT, shifting tactics from RMM tools to custom malware and spearphishing, using new backdoors like Phoenix.
⤷ Title: Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:20:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:20:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
Daily CyberSecurity
Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
Group-IB exposed MuddyWater using NordVPN to send phishing emails that deliver the Phoenix v4 backdoor. The malware steals credentials via a custom Chromium stealer disguised as a calculator.
⤷ Title: High-Value Targets: MuddyWater APT Used Compromised VPN Mailbox in Stealth Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 26 Oct 2025 09:57:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Cyber Espionage #Middle East #MuddyWater #phishing #Phoenix Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 26 Oct 2025 09:57:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Cyber Espionage #Middle East #MuddyWater #phishing #Phoenix Backdoor
Penetration Testing Tools
High-Value Targets: MuddyWater APT Used Compromised VPN Mailbox in Stealth Campaign
Iran-linked MuddyWater APT targeted 100+ government entities, using a compromised NordVPN mailbox and Phoenix v4 backdoor for stealthy espionage.
⤷ Title: Unmasking the Phoenix System’s Rogue BTS Smishing Empire
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:29:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Group_IB #infosec #Live_Phishing #MFA Bypass #Mouse System #OTP Interception #Phishing_as_a_Service #Phoenix System #Rogue BTS #smishing #Telegram fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:29:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Group_IB #infosec #Live_Phishing #MFA Bypass #Mouse System #OTP Interception #Phishing_as_a_Service #Phoenix System #Rogue BTS #smishing #Telegram fraud
Daily CyberSecurity
Unmasking the Phoenix System’s Rogue BTS Smishing Empire
Group-IB unmasks the Phoenix System: a PhaaS platform using rogue cell towers and live-dashboards to bypass MFA across 2,500+ domains. Read the full report.
⤷ Title: Phoenix Invicta Extension Malware Strips CSP Headers to Bypass Manifest V3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:08:50 +0000
════════════════════════
⌗ Tags: #Malware #7AI Threat Intelligence #browser extension malware #Content Security Policy Stripping #JavaScript Backdoor #lottingem.com #Manifest V3 Bypass #MyColorPick #Phoenix Invicta #Search Engine Ad Fraud #statsdata.online
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 08:08:50 +0000
════════════════════════
⌗ Tags: #Malware #7AI Threat Intelligence #browser extension malware #Content Security Policy Stripping #JavaScript Backdoor #lottingem.com #Manifest V3 Bypass #MyColorPick #Phoenix Invicta #Search Engine Ad Fraud #statsdata.online
Penetration Testing Tools
Phoenix Invicta Extension Malware Strips CSP Headers to Bypass Manifest V3
Popular browser extensions have historically been perceived as benign, utilitarian artifacts—innocuous implements such as color droppers, ad-blockers, or