⤷ Title: OpenSSL Patches Three Flaws: Timing Side-Channel RCE Risk and Memory Corruption Affect All Versions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 02:02:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptography #CVE_2025_9230 #Denial of Service #openssl #rce #security advisory #Timing Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 02:02:46 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cryptography #CVE_2025_9230 #Denial of Service #openssl #rce #security advisory #Timing Attack
Daily CyberSecurity
OpenSSL Patches Three Flaws: Timing Side-Channel RCE Risk and Memory Corruption Affect All Versions
OpenSSL patches three flaws, including CVE-2025-9230 (RCE/DoS risk) and a SM2 timing side-channel (CVE-2025-9231) that could allow private key recovery on ARM64.
⤷ Title: QNAP Fixes High-Severity Flaws: NetBak Replicator RCE and SQL Injection in Qsync Central
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 00:08:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57714 #DLL hijacking #NAS #NetBak Replicator #QNAP #Qsync Central #security advisory #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 00:08:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57714 #DLL hijacking #NAS #NetBak Replicator #QNAP #Qsync Central #security advisory #sql injection
Daily CyberSecurity
QNAP Fixes High-Severity Flaws: NetBak Replicator RCE and SQL Injection in Qsync Central
QNAP patches NetBak Replicator and Qsync Central. Flaws include a DLL hijacking risk and critical SQL Injection that allows remote attackers to execute code.
⤷ Title: Critical Flaw CVE-2025-59159 (CVSS 9.7) in SillyTavern Allows Full Remote Control of Local AI Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59159 #DNS Rebinding #LLM #Remote Access #security advisory #SillyTavern #WebUI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59159 #DNS Rebinding #LLM #Remote Access #security advisory #SillyTavern #WebUI
Daily CyberSecurity
Critical Flaw CVE-2025-59159 (CVSS 9.7) in SillyTavern Allows Full Remote Control of Local AI Instances
A Critical (CVSS 9.7) DNS rebinding flaw (CVE-2025-59159) in the SillyTavern LLM interface allows remote attackers to seize full control of local AI instances and steal API keys.
⤷ Title: Critical Nagios Flaw CVE-2025-44823 (CVSS 9.9) Leaks Plaintext Admin API Keys, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 03:57:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Key Leak #Critical Vulnerability #CVE_2025_44823 #Elasticsearch #Nagios Log Server #privilege escalation #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 03:57:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Key Leak #Critical Vulnerability #CVE_2025_44823 #Elasticsearch #Nagios Log Server #privilege escalation #security advisory
Daily CyberSecurity
Critical Nagios Flaw CVE-2025-44823 (CVSS 9.9) Leaks Plaintext Admin API Keys, PoC Available
A Critical (CVSS 9.9) flaw (CVE-2025-44823) in Nagios Log Server allows any authenticated user to retrieve plaintext administrative API keys, leading to full system compromise. Update now.
⤷ Title: New Cache Smuggling Phishing Attack Delivers Malware via Browser Cache
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:51:57 +0000
════════════════════════
⌗ Tags: #Malware #Cache Smuggling #ClickFix #FileFix #Fortinet Lure #Malware Evasion #PowerShell #Security Advisory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:51:57 +0000
════════════════════════
⌗ Tags: #Malware #Cache Smuggling #ClickFix #FileFix #Fortinet Lure #Malware Evasion #PowerShell #Security Advisory
Penetration Testing Tools
New Cache Smuggling Phishing Attack Delivers Malware via Browser Cache
A new phishing variant uses cache smuggling to hide a malicious ZIP in the browser cache. The FileFix lure then executes PowerShell to install malware without any downloads.
⤷ Title: Oracle Warns of Unauthenticated Vulnerability in E-Business Suite (CVE-2025-61884)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:11:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_61884 #E_Business Suite #ERP #Oracle #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 02:11:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_61884 #E_Business Suite #ERP #Oracle #security advisory
Daily CyberSecurity
Oracle Warns of Unauthenticated Vulnerability in E-Business Suite (CVE-2025-61884)
Oracle issued an emergency alert for a critical flaw (CVE-2025-61884) in E-Business Suite. The bug allows unauthenticated remote access to sensitive EBS resources.
⤷ Title: F5 Networks Breached by Nation-State Actor, BIG-IP Source Code and Undisclosed Vulnerabilities Stolen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 03:38:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #BIG_IP #CISA Emergency Directive #F5 Networks #Nation_State APT #security advisory #Source Code Leak #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 03:38:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #BIG_IP #CISA Emergency Directive #F5 Networks #Nation_State APT #security advisory #Source Code Leak #Supply Chain
Daily CyberSecurity
F5 Networks Breached by Nation-State Actor, BIG-IP Source Code and Undisclosed Vulnerabilities Stolen
F5 disclosed a breach by a "highly sophisticated nation-state" that stole BIG-IP source code and internal vuln info. CISA issued an Emergency Directive mandating immediate patching of 44 flaws.
⤷ Title: Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:51:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2025_41253 #security advisory #SpEL injection #Spring Cloud Gateway #Spring Framework #WebSocket
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:51:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2025_41253 #security advisory #SpEL injection #Spring Cloud Gateway #Spring Framework #WebSocket
Daily CyberSecurity
Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
Spring fixed two flaws: CVE-2025-41253 allows SpEL injection in Cloud Gateway to expose secrets, and CVE-2025-41254 allows STOMP CSRF to send unauthorized WebSocket messages. Update immediately.
⤷ Title: Hacktivist Warning: Canadian Critical Infrastructure Breached, Control Parameters Altered
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:13:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Canada #Critical Infrastructure #cybersecurity #Hacktivism #ICS #Remote Access #SCADA #Security Advisory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:13:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Canada #Critical Infrastructure #cybersecurity #Hacktivism #ICS #Remote Access #SCADA #Security Advisory
Penetration Testing Tools
Hacktivist Warning: Canadian Critical Infrastructure Breached, Control Parameters Altered
Hacktivists infiltrated Canadian water, oil, and agriculture systems, altering control parameters. Officials warn exposed industrial control systems are easy targets.
⤷ Title: Critical Warning: QNAP Patches Seven Zero-Days Exploited at Pwn2Own 2025
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 08 Nov 2025 02:54:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #HBS 3 #Malware Remover #NAS #Pwn2Own #QNAP #QTS #QuTS hero #security advisory #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 08 Nov 2025 02:54:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #HBS 3 #Malware Remover #NAS #Pwn2Own #QNAP #QTS #QuTS hero #security advisory #zero_day
Daily CyberSecurity
Critical Warning: QNAP Patches Seven Zero-Days Exploited at Pwn2Own 2025
QNAP patched 7 zero-day flaws in QTS/QuTS hero and apps (HBS 3, Malware Remover) after being hacked by researchers at Pwn2Own Ireland 2025. Update urgently.