⤷ Title: RVTools Supply Chain Attack: Bumblebee Malware Delivered via Trusted VMware Utility
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 May 2025 00:08:17 +0000
════════════════════════
⌗ Tags: #Malware #Bumblebee loader #cybersecurity #initial access #IT management tools #malware #Malware Distribution #RVTools #supply chain attack #threat analysis #vmware #ZeroDay Labs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 19 May 2025 00:08:17 +0000
════════════════════════
⌗ Tags: #Malware #Bumblebee loader #cybersecurity #initial access #IT management tools #malware #Malware Distribution #RVTools #supply chain attack #threat analysis #vmware #ZeroDay Labs
Daily CyberSecurity
RVTools Supply Chain Attack: Bumblebee Malware Delivered via Trusted VMware Utility
RVTools briefly hijacked in a Bumblebee malware supply chain attack. Learn how attackers used a trusted tool to deliver post-exploitation payloads.
⤷ Title: ArcaneDoor Strikes Cisco Firewalls Again: New DoS Exploit Variant Emerges
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 02:26:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcaneDoor #Cisco #CVE_2025_20333 #cyberattack #Cyberespionage #DoS #firewall #UCCX #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 02:26:16 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcaneDoor #Cisco #CVE_2025_20333 #cyberattack #Cyberespionage #DoS #firewall #UCCX #zeroday
Penetration Testing Tools
ArcaneDoor Strikes Cisco Firewalls Again: New DoS Exploit Variant Emerges
Cisco warns of a new ArcaneDoor attack variant targeting ASA/FTD firewalls for DoS (CVE-2025-20333/20362). Patch immediately, and update UCCX for critical flaws.
⤷ Title: Critical RCE Zero-Days Patched: QNAP Fixes 7 Flaws Exposed at Pwn2Own 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 02:59:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #HBS3 #NAS #Pwn2OwnIreland2025 #QNAP #QTS #QuTShero #RCE #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 02:59:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #HBS3 #NAS #Pwn2OwnIreland2025 #QNAP #QTS #QuTShero #RCE #zeroday
Penetration Testing Tools
Critical RCE Zero-Days Patched: QNAP Fixes 7 Flaws Exposed at Pwn2Own 2025
QNAP released emergency patches for seven critical RCE zero-day flaws in QTS, QuTS hero, and key apps like HBS 3, all demonstrated live at Pwn2Own Ireland 2025.
⤷ Title: Mandiant: Triofox Zero-Day Exploited to Gain SYSTEM Access via Antivirus Feature
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 02:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12480 #Gladinet #HTTPHostHeader #Mandiant #RCE #Triofox #UNC6485 #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 02:59:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12480 #Gladinet #HTTPHostHeader #Mandiant #RCE #Triofox #UNC6485 #zeroday
Penetration Testing Tools
Mandiant: Triofox Zero-Day Exploited to Gain SYSTEM Access via Antivirus Feature
A critical Triofox zero-day (CVE-2025-12480) was exploited by UNC6485. Attackers bypassed auth via Host header, created an admin, and ran code as SYSTEM via the AV check.
⤷ Title: November Patch Tuesday 2025: Microsoft Fixes 63 Flaws, Including an Exploited Windows Zero-Day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 04:34:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_62215 #Microsoft #Office #PatchTuesday #PrivilegeEscalation #RCE #WindowsKernel #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 04:34:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_62215 #Microsoft #Office #PatchTuesday #PrivilegeEscalation #RCE #WindowsKernel #zeroday
Penetration Testing Tools
November Patch Tuesday 2025: Microsoft Fixes 63 Flaws, Including an Exploited Windows Zero-Day
Microsoft fixed 63 flaws on November Patch Tuesday 2025, including a critical Windows kernel zero-day (CVE-2025-62215) actively exploited for privilege escalation.
⤷ Title: Synology Patches BeeStation Zero-Day (CVE-2025-12686) Exposed at Pwn2Own 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 04:13:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #BeeStation #CVE_2025_12686 #NAS #Pwn2OwnIreland2025 #RCE #Synacktiv #Synology #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 04:13:11 +0000
════════════════════════
⌗ Tags: #Vulnerability #BeeStation #CVE_2025_12686 #NAS #Pwn2OwnIreland2025 #RCE #Synacktiv #Synology #zeroday
Penetration Testing Tools
Synology Patches BeeStation Zero-Day (CVE-2025-12686) Exposed at Pwn2Own 2025
Synology patched a critical zero-day (CVE-2025-12686) in BeeStation OS, which allowed RCE. The flaw was demonstrated by Synacktiv researchers at Pwn2Own Ireland 2025.
⤷ Title: Uhale Digital Photo Frames Ship with Root Access and Download Hidden Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:43:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #AndroidTV #DigitalPhotoFrame #malware #RootAccess #SupplyChainAttack #Uhale #WhaleTV #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:43:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #AndroidTV #DigitalPhotoFrame #malware #RootAccess #SupplyChainAttack #Uhale #WhaleTV #zeroday
Penetration Testing Tools
Uhale Digital Photo Frames Ship with Root Access and Download Hidden Malware
Uhale digital photo frames were found to download malware upon startup. Devices ship with root access, SELinux disabled, and 17 flaws (RCE, file upload) from the factory.
⤷ Title: CVE-2025-24893: XWiki Zero-Day Exploited by RondoDox Botnet and Cryptominers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:27:23 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CISA #Cryptominer #CVE_2025_24893 #cybersecurity #RCE #RondoDox #XWiki #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:27:23 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CISA #Cryptominer #CVE_2025_24893 #cybersecurity #RCE #RondoDox #XWiki #zeroday
Penetration Testing Tools
CVE-2025-24893: XWiki Zero-Day Exploited by RondoDox Botnet and Cryptominers
The XWiki zero-day (CVE-2025-24893, CVSS 9.8) is under active exploitation by cryptominers and the RondoDox botnet for DDoS attacks. CISA ordered immediate patching.
⤷ Title: Logitech Discloses Data Exfiltration via Third-Party Zero-Day Vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:18:18 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #cybersecurity #DataBreach #DataExfiltration #Logitech #SEC #ThirdPartySoftware #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 03:18:18 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #cybersecurity #DataBreach #DataExfiltration #Logitech #SEC #ThirdPartySoftware #zeroday
Penetration Testing Tools
Logitech Discloses Data Exfiltration via Third-Party Zero-Day Vulnerability
Logitech disclosed unauthorized data exfiltration to the SEC, caused by a third-party zero-day flaw. The affected data includes some employee and customer information.
⤷ Title: Chrome Emergency Update: Google Patches Actively Exploited V8 Zero-Day (CVE-2025-13223)
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 09:27:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_13223 #GoogleChrome #RCE #SecurityUpdate #ThreatAnalysisGroup #TypeConfusion #V8Engine #zeroday
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 09:27:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_13223 #GoogleChrome #RCE #SecurityUpdate #ThreatAnalysisGroup #TypeConfusion #V8Engine #zeroday
Penetration Testing Tools
Chrome Emergency Update: Google Patches Actively Exploited V8 Zero-Day (CVE-2025-13223)
Google released an emergency update for Chrome to fix a high-severity V8 type confusion zero-day (CVE-2025-13223) that is confirmed to be actively exploited in the wild.
⤷ Title: Firewall Bypass Using SSH Tunneling
════════════════════════
𐀪 Author: ZeroDay-Security-Services
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 16:48:47 GMT
════════════════════════
⌗ Tags: #firewall_security #information_security #zeroday_security_services #cybersecurity #hacking
════════════════════════
𐀪 Author: ZeroDay-Security-Services
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 16:48:47 GMT
════════════════════════
⌗ Tags: #firewall_security #information_security #zeroday_security_services #cybersecurity #hacking
Medium
Firewall Bypass Using SSH Tunneling
Introduction