⤷ Title: Matanbuchus 3.0: The Evolved Malware-as-a-Service Evading Detection & Exploiting Microsoft Teams
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 02:03:22 +0000
════════════════════════
⌗ Tags: #Malware #Cobalt Strike #cybersecurity #Evasion #Loader #MaaS #Malware_as_a_Service #Matanbuchus #Microsoft Teams #ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 02:03:22 +0000
════════════════════════
⌗ Tags: #Malware #Cobalt Strike #cybersecurity #Evasion #Loader #MaaS #Malware_as_a_Service #Matanbuchus #Microsoft Teams #ransomware
Penetration Testing Tools
Matanbuchus 3.0: The Evolved Malware-as-a-Service Evading Detection & Exploiting Microsoft Teams
Matanbuchus 3.0, an enhanced MaaS loader, is bypassing defenses with new C2 protocols, obfuscation, and leveraging Microsoft Teams to deploy ransomware and Cobalt Strike.
⤷ Title: Golden dMSA: Critical Windows Server 2025 Flaw Allows Full Active Directory Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 02:01:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #cybersecurity #dMSA #gMSA #Golden dMSA #KDS Root Key #Kerberos #privilege escalation #Windows Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 02:01:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #cybersecurity #dMSA #gMSA #Golden dMSA #KDS Root Key #Kerberos #privilege escalation #Windows Server 2025
Penetration Testing Tools
Golden dMSA: Critical Windows Server 2025 Flaw Allows Full Active Directory Takeover
A critical "Golden dMSA" flaw in Windows Server 2025's dMSAs allows attackers to compromise KDS root keys, enabling full, undetectable takeover of Active Directory.
⤷ Title: Paradox.ai Data Breach: “123456” Password & Nexus Stealer Expose Fortune 500 Clients
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 01:53:59 +0000
════════════════════════
⌗ Tags: #Data Leak #Atlassian #cybersecurity #data breach #McDonald's #McHire #Nexus Stealer #Okta #Paradox.ai #supply chain attack #Weak Password
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 01:53:59 +0000
════════════════════════
⌗ Tags: #Data Leak #Atlassian #cybersecurity #data breach #McDonald's #McHire #Nexus Stealer #Okta #Paradox.ai #supply chain attack #Weak Password
Penetration Testing Tools
Paradox.ai Data Breach: "123456" Password & Nexus Stealer Expose Fortune 500 Clients
A trivial "123456" password and Nexus Stealer malware on a Paradox.ai employee's device exposed data, potentially impacting Fortune 500 clients like Lockheed Martin.
⤷ Title: lockc: Making containers more secure with eBPF and Linux Security Modules
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 00:24:04 +0000
════════════════════════
⌗ Tags: #Open Source Tool #lockc
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 00:24:04 +0000
════════════════════════
⌗ Tags: #Open Source Tool #lockc
Penetration Testing Tools
lockc: Making containers more secure with eBPF and Linux Security Modules
lockc is open source software for providing MAC (Mandatory Access Control) type of security audit for container workloads.
⤷ Title: Pwn2Own Berlin: Critical IonMonkey JIT Bug Exposes Firefox to Memory Corruption
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 02:58:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4919 #cybersecurity #Firefox #IonMonkey #JavaScript Engine #JIT Compiler #Mozilla #Pwn2Own #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 02:58:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_4919 #cybersecurity #Firefox #IonMonkey #JavaScript Engine #JIT Compiler #Mozilla #Pwn2Own #vulnerability
Penetration Testing Tools
Pwn2Own Berlin: Critical IonMonkey JIT Bug Exposes Firefox to Memory Corruption
A critical vulnerability (CVE-2025-4919) in Firefox's IonMonkey JIT compiler, demonstrated at Pwn2Own Berlin, allows out-of-bounds memory access, posing a significant risk.
⤷ Title: Google’s Big Sleep AI Foils Zero-Day Exploit in SQLite Before Attackers Strike
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 01:55:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #Big Sleep #cybersecurity #google #Preemptive Defense #SQLite #Threat Analysis Group #Vulnerability Discovery #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 01:55:06 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #Big Sleep #cybersecurity #google #Preemptive Defense #SQLite #Threat Analysis Group #Vulnerability Discovery #zero_day
Penetration Testing Tools
Google's Big Sleep AI Foils Zero-Day Exploit in SQLite Before Attackers Strike
Google's AI agent, Big Sleep, identified and neutralized a critical SQLite zero-day (CVE-2025-6965) that was actively known to threat actors, preventing its exploitation in the wild.
⤷ Title: Windows Hello for Business Flaw: Biometric Bypass Exposes Enterprise Authentication
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:52:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication #Biometric Security #cybersecurity #Microsoft #privilege escalation #vulnerability #WHfB #Windows Hello for Business
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:52:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication #Biometric Security #cybersecurity #Microsoft #privilege escalation #vulnerability #WHfB #Windows Hello for Business
Penetration Testing Tools
Windows Hello for Business Flaw: Biometric Bypass Exposes Enterprise Authentication
A new study exposes critical architectural flaws in Windows Hello for Business, allowing for biometric bypass and privilege escalation, undermining its passwordless security.
⤷ Title: Beyond Bugs: How Generative AI Ecosystems Can Be Hacked Without Exploits
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:51:03 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Claude AI #cybersecurity #Generative AI #Gmail #MCP #Multi_Component Pipeline #Prompt Injection #Shell Server
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:51:03 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Claude AI #cybersecurity #Generative AI #Gmail #MCP #Multi_Component Pipeline #Prompt Injection #Shell Server
Penetration Testing Tools
Beyond Bugs: How Generative AI Ecosystems Can Be Hacked Without Exploits
A new attack method demonstrates remote code execution on a secure system by exploiting interactions within a generative AI multi-component pipeline, bypassing traditional vulnerabilities.
⤷ Title: Air Serbia Hit by Major Cyberattack: Internal Systems Disrupted, Active Directory Compromised
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:42:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:42:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals
Penetration Testing Tools
Air Serbia Hit by Major Cyberattack: Internal Systems Disrupted, Active Directory Compromised
Air Serbia is battling an ongoing cyberattack that has crippled internal operations, disrupted payroll, and potentially compromised Active Directory. An infostealer is suspected.
⤷ Title: hoaxshell: A Windows reverse shell payload generator and handler
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:04:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #hoaxshell #Windows reverse shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:04:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #hoaxshell #Windows reverse shell
Penetration Testing Tools
hoaxshell: A Windows reverse shell payload generator and handler
hoaxshell is an unconventional Windows reverse shell, currently undetected by Microsoft Defender and other AV solutions
⤷ Title: Abusing Active Directory Certificate Services (Part 2)
════════════════════════
𐀪 Author: Kassie Kimball
════════════════════════
ⴵ Time: Thu, 12 Oct 2023 15:44:18 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
════════════════════════
𐀪 Author: Kassie Kimball
════════════════════════
ⴵ Time: Thu, 12 Oct 2023 15:44:18 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 2) - Black Hills Information Security, Inc.
Misconfigurations in Active Directory Certificate Services (ADCS) can introduce critical vulnerabilities into an Enterprise Active Directory environment, such as paths of escalation from low privileged accounts to domain administrator.
⤷ Title: Abusing Active Directory Certificate Services (Part 1)
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 05 Oct 2023 16:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Thu, 05 Oct 2023 16:00:00 +0000
════════════════════════
⌗ Tags: #Alyssa Snow #Blue Team #External/Internal #How_To #Informational #Red Team #Red Team Tools #Active Directory #exploit
Black Hills Information Security, Inc.
Abusing Active Directory Certificate Services (Part 1) - Black Hills Information Security, Inc.
Active Directory Certificate Services (ADCS) is used for public key infrastructure in an Active Directory environment. ADCS is widely used in enterprise Active Directory environments for managing certificates for systems, users, applications, and more.
⤷ Title: Intigriti Bug Bytes #226 - July 2025 🚀
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
════════════════════════
𐀪 Author: Intigriti
════════════════════════
ⴵ Time: Fri, 18 Jul 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
Intigriti
Intigriti Bug Bytes #226 - July 2025 🚀
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Exploiting Log4Shell (Log4J) in 2025 An indispensable GitHub recon tool (not the one you have in mi...
⤷ Title: Apps Behind Walls: The Story of OS Sandboxes
════════════════════════
𐀪 Author: Natarajan C K
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:31:49 GMT
════════════════════════
⌗ Tags: #systems_thinking #operating_systems #sandbox #bug_bounty #security
════════════════════════
𐀪 Author: Natarajan C K
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:31:49 GMT
════════════════════════
⌗ Tags: #systems_thinking #operating_systems #sandbox #bug_bounty #security
Medium
Apps Behind Walls: The Story of OS Sandboxes
Imagine a group of toddlers playing in a sandbox. The sandbox has raised walls and soft sand inside, keeping the kids entertained — but…
⤷ Title: CTF Day(36)
════════════════════════
𐀪 Author: Ahmed Narmer
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:08:09 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ctf #web_pen_testing #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Ahmed Narmer
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 10:08:09 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #ctf #web_pen_testing #bug_bounty #cybersecurity
Medium
CTF Day(36)
picoCTF Web Exploitation: Java Code Analysis!?!
⤷ Title: “How CVE-2025–4123 Turned Grafana Into a Hacker’s Playground”
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:59:11 GMT
════════════════════════
⌗ Tags: #hacking #technology #bug_bounty #programming #cybersecurity
════════════════════════
𐀪 Author: Aman Sharma
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:59:11 GMT
════════════════════════
⌗ Tags: #hacking #technology #bug_bounty #programming #cybersecurity
Medium
“How CVE-2025–4123 Turned Grafana Into a Hacker’s Playground”
What started as a path traversal led to XSS, SSRF, and full account compromise.
⤷ Title: Payload in the Haystack: Using Wayback & ParamSpider to Find a Forgotten Upload Endpoint
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:56:13 GMT
════════════════════════
⌗ Tags: #infosec #hacking #cybersecurity #money #bug_bounty
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:56:13 GMT
════════════════════════
⌗ Tags: #infosec #hacking #cybersecurity #money #bug_bounty
Medium
🧨 Payload in the Haystack: Using Wayback & ParamSpider to Find a Forgotten Upload Endpoint 📦
Free Link 🎈
⤷ Title: Part 2: Automating Mobile API Discovery Using AI
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:16:16 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #ai #cybersecurity #information_security
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:16:16 GMT
════════════════════════
⌗ Tags: #bug_bounty #infosec #ai #cybersecurity #information_security
Medium
Part 2: Automating Mobile API Discovery Using AI
“Why tap on screens when you can script your recon?”
⤷ Title: I Found a Broken API in a Mobile App — Without Touching the App
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:11:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #mobile_app_development #bug_bounty #information_security #infosec
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 08:11:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #mobile_app_development #bug_bounty #information_security #infosec
Medium
I Found a Broken API in a Mobile App — Without Touching the App
“Sometimes, you don’t need to touch the app to break the backend. You just need to know where to look.”
⤷ Title: API07:2023 — Server-Side Request Forgery (SSRF)
════════════════════════
𐀪 Author: Suhel Kathi
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:29:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_app_security #api_security #ssrf #owasp_top_10
════════════════════════
𐀪 Author: Suhel Kathi
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:29:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_app_security #api_security #ssrf #owasp_top_10
Medium
API07:2023 — Server-Side Request Forgery (SSRF)
“When your server becomes an attacker’s puppet.”
⤷ Title: How to Set Up a Professional Hacking Lab: A Practical Guide for Ethical Hackers and Bug Bounty…
════════════════════════
𐀪 Author: Santhosh Adiga U
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:09:58 GMT
════════════════════════
⌗ Tags: #hacking_tools #bug_bounty #penetration_testing #ethical_hacking #hacking_lab
════════════════════════
𐀪 Author: Santhosh Adiga U
════════════════════════
ⴵ Time: Sat, 19 Jul 2025 07:09:58 GMT
════════════════════════
⌗ Tags: #hacking_tools #bug_bounty #penetration_testing #ethical_hacking #hacking_lab
Medium
How to Set Up a Professional Hacking Lab: A Practical Guide for Ethical Hackers and Bug Bounty Hunters
Secure, anonymous, and fully equipped.