⤷ Title: Musk’s megaphone: France investigates X for undermining democracy
════════════════════════
𐀪 Author: Enrique Dans
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 21:55:39 GMT
════════════════════════
⌗ Tags: #france #xs #social_media #elon_musk #manipulation
════════════════════════
𐀪 Author: Enrique Dans
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 21:55:39 GMT
════════════════════════
⌗ Tags: #france #xs #social_media #elon_musk #manipulation
Medium
Musk’s megaphone: France investigates X for undermining democracy
The Paris Prosecutor’s Office has opened a criminal investigation into Elon Musk’s X social network for “algorithmic manipulation aimed at…
⤷ Title: السلام عليكم
اليوم جايب لكم رايت أب جديد، بسيط ومفيد إن شاء الله.
════════════════════════
𐀪 Author: Ibrahimsyamgame
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 21:13:39 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup
اليوم جايب لكم رايت أب جديد، بسيط ومفيد إن شاء الله.
════════════════════════
𐀪 Author: Ibrahimsyamgame
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 21:13:39 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup
Medium
السلام عليكم اليوم جايب لكم رايت أب جديد، بسيط ومفيد إن شاء الله.
الثغرة تم تصنيفها خطيرة (High)، مع إني بصراحة توقعتها متوسطة، بس الظاهر الموقع يهتم مرّة بأي شي له علاقة بالمستخدمين وخصوصيتهم، فعشان كذا…
⤷ Title: Coercer: automatically coerce a Windows server to authenticate on an arbitrary machine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:48:09 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Coercer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:48:09 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Coercer
Penetration Testing Tools
Coercer: automatically coerce a Windows server to authenticate on an arbitrary machine
Coercer is a python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods.
⤷ Title: Piracy’s Hidden Cost: FMovies Linked to Massive Infostealer Campaign Compromising 1 Million+ Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:14:51 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #data breach #FMovies #Hudson Rock #Infostealer #malware #Microsoft #Piracy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:14:51 +0000
════════════════════════
⌗ Tags: #Malware #cybercrime #cybersecurity #data breach #FMovies #Hudson Rock #Infostealer #malware #Microsoft #Piracy
Penetration Testing Tools
Piracy's Hidden Cost: FMovies Linked to Massive Infostealer Campaign Compromising 1 Million+ Devices
Microsoft reveals a link between the defunct FMovies and a massive infostealer campaign that compromised over 1 million devices, stealing credentials and financial data.
⤷ Title: Arch Linux Users Beware: Malicious AUR Packages Deployed CHAOS RAT Trojan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:11:02 +0000
════════════════════════
⌗ Tags: #Malware #Arch Linux #AUR #CHAOS RAT #cybersecurity #danikpapas #Linux Security #malware #Remote Access Trojan #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:11:02 +0000
════════════════════════
⌗ Tags: #Malware #Arch Linux #AUR #CHAOS RAT #cybersecurity #danikpapas #Linux Security #malware #Remote Access Trojan #supply chain attack
Penetration Testing Tools
Arch Linux Users Beware: Malicious AUR Packages Deployed CHAOS RAT Trojan
Three malicious packages disguised as browser updates in the Arch User Repository (AUR) deployed the CHAOS RAT trojan, compromising Linux systems.
⤷ Title: Free Decryption Tool Released for Phobos and 8Base Ransomware: End of the Line for These Notorious Threats
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:07:27 +0000
════════════════════════
⌗ Tags: #Malware #8Base #cybercrime #cybersecurity #Decryption Tool #Europol #Japanese Police #NoMoreRansom #Phobos #ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:07:27 +0000
════════════════════════
⌗ Tags: #Malware #8Base #cybercrime #cybersecurity #Decryption Tool #Europol #Japanese Police #NoMoreRansom #Phobos #ransomware
Penetration Testing Tools
Free Decryption Tool Released for Phobos and 8Base Ransomware: End of the Line for These Notorious Threats
Japanese police have released a free decryption tool for Phobos and 8Base ransomware victims, offering hope for data recovery after a major international crackdown.
⤷ Title: Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now!
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:52:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Access Point #Aruba Instant On #CVE_2025_37103 #cybersecurity #Hardcoded Credentials #HPE #network security #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:52:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Access Point #Aruba Instant On #CVE_2025_37103 #cybersecurity #Hardcoded Credentials #HPE #network security #vulnerability
Penetration Testing Tools
Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now!
HPE warns of a critical vulnerability (CVE-2025-37103, CVSS 9.8) in Aruba Instant On APs with hardcoded credentials, allowing unauthenticated full administrative access. Update immediately!
⤷ Title: npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:39:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Eslint #malware #npm #phishing #PoC #Prettier #remote code execution #supply chain attack #Synckit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:39:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Eslint #malware #npm #phishing #PoC #Prettier #remote code execution #supply chain attack #Synckit
Penetration Testing Tools
npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages
A phishing campaign stole npm maintainer tokens, leading to trojanized versions of eslint-config-prettier, synckit, and other packages, enabling remote code execution on Windows systems.
⤷ Title: Critical Flaw (CVE-2025-24936, CVSS 9.0) in Nokia WaveSuite NOC Expose Telecom Networks to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:46:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_24936 #CVE_2025_24938 #cybersecurity #enterprise #Network Operations #Nokia WaveSuite NOC #rce #telecom #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:46:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_24936 #CVE_2025_24938 #cybersecurity #enterprise #Network Operations #Nokia WaveSuite NOC #rce #telecom #Vulnerability
Daily CyberSecurity
Critical Flaw (CVE-2025-24936, CVSS 9.0) in Nokia WaveSuite NOC Expose Telecom Networks to RCE
Nokia's WaveSuite NOC platform has two severe command injection vulnerabilities (CVE-2025-24938, CVE-2025-24936) allowing remote code execution, even with low privileges.
⤷ Title: Greedy Sponge Reemerges: New AllaKore RAT Variant and SystemBC Target Mexico’s Financial Sector
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:44:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AllaKore RAT #Cybercrime #financial fraud #Greedy Sponge #malware #Mexico #Remote Access Trojan #spear_phishing #SystemBC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:44:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AllaKore RAT #Cybercrime #financial fraud #Greedy Sponge #malware #Mexico #Remote Access Trojan #spear_phishing #SystemBC
Daily CyberSecurity
Greedy Sponge Reemerges: New AllaKore RAT Variant and SystemBC Target Mexico's Financial Sector
Greedy Sponge, a financially motivated group, is back with an upgraded AllaKore RAT and SystemBC, targeting Mexican organizations for banking credentials and financial fraud.
⤷ Title: Android Malware Strikes: Fake Facebook & TikTok Apps Impersonate Brands for Traffic Monetization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:40:17 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #apk #brand impersonation #cybersecurity #facebook #phishing #TikTok #Traffic Monetization #Trustwave
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:40:17 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #apk #brand impersonation #cybersecurity #facebook #phishing #TikTok #Traffic Monetization #Trustwave
Daily CyberSecurity
Android Malware Strikes: Fake Facebook & TikTok Apps Impersonate Brands for Traffic Monetization
Trustwave uncovers an Android malware cluster using fake Facebook & TikTok apps to lure victims via brand impersonation, abusing permissions for data collection and traffic monetization.
⤷ Title: NailaoLocker Ransomware: Chinese SM2 Crypto and Built-in Decryptor Raise Questions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:35:12 +0000
════════════════════════
⌗ Tags: #Malware #cryptography #cybersecurity #DLL side_loading #encryption #FortiGuard Labs #malware #NailaoLocker #ransomware #SM2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:35:12 +0000
════════════════════════
⌗ Tags: #Malware #cryptography #cybersecurity #DLL side_loading #encryption #FortiGuard Labs #malware #NailaoLocker #ransomware #SM2
Daily CyberSecurity
NailaoLocker Ransomware: Chinese SM2 Crypto and Built-in Decryptor Raise Questions
FortiGuard Labs unveils NailaoLocker, a new ransomware using Chinese SM2 encryption and a built-in, non-functional decryptor, suggesting a prototype or decoy.
⤷ Title: Important wolfSSL Update: Critical Apple Trust Store Bypass & Predictable Randomness Flaws Patched
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:30:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #cryptography #CVE_2025_7394 #CVE_2025_7395 #cybersecurity #embedded systems #IOT #ssl #tls #Vulnerability #wolfSSL
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:30:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #cryptography #CVE_2025_7394 #CVE_2025_7395 #cybersecurity #embedded systems #IOT #ssl #tls #Vulnerability #wolfSSL
Daily CyberSecurity
Important wolfSSL Update: Critical Apple Trust Store Bypass & Predictable Randomness Flaws Patched
wolfSSL 5.8.2 patches four vulnerabilities, including a critical Apple trust store bypass (CVE-2025-7395) and predictable randomness after fork(), impacting secure communications.
⤷ Title: From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
Daily CyberSecurity
From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
JPCERT/CC details a sophisticated, ongoing malware campaign exploiting Ivanti Connect Secure (CVE-2025-0282, -22457) using MDifyLoader, Cobalt Strike, vshell, and Fscan for stealthy persistent access.
⤷ Title: SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
Daily CyberSecurity
SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
AhnLab uncovers SVF Bot, a Python-based DDoS botnet abusing Discord as its C&C channel to target misconfigured Linux servers and launch HTTP/UDP floods.
⤷ Title: DeedRAT Backdoor: Chinese APT Targets Southeast Asian Governments via Vulnerable AV Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Chinese APT #cyberattack #cybersecurity #DeedRAT #DLL Sideloading #Government #malware #Southeast Asia #VIPRE Antivirus
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Chinese APT #cyberattack #cybersecurity #DeedRAT #DLL Sideloading #Government #malware #Southeast Asia #VIPRE Antivirus
Daily CyberSecurity
DeedRAT Backdoor: Chinese APT Targets Southeast Asian Governments via Vulnerable AV Software
LAB52 uncovers a sophisticated phishing campaign delivering DeedRAT, a modular backdoor by Chinese APTs, targeting Southeast Asian governments via vulnerable AV software.
⤷ Title: Ghost Crypt & PureRAT: New Stealthy Malware Targets Accounting Firm via “Process Hypnosis”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:15:34 +0000
════════════════════════
⌗ Tags: #Malware #Accounting Firm #Crypter #cybersecurity #evasion #Ghost Crypt #malware #Process Hypnosis #PureRAT #rat #Remote Access Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:15:34 +0000
════════════════════════
⌗ Tags: #Malware #Accounting Firm #Crypter #cybersecurity #evasion #Ghost Crypt #malware #Process Hypnosis #PureRAT #rat #Remote Access Trojan
Daily CyberSecurity
Ghost Crypt & PureRAT: New Stealthy Malware Targets Accounting Firm via "Process Hypnosis"
eSentire uncovered a sophisticated attack on a US accounting firm, deploying PureRAT via the new Ghost Crypt crypter and a stealthy "Process Hypnosis" injection technique.
⤷ Title: Apache Jena Flaws (CVE-2025-49656 and CVE-2025-50151) Expose Semantic Web Apps to File System Compromise
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:11:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jena #CVE_2025_49656 #CVE_2025_50151 #cybersecurity #file system #Fuseki #Java Framework #Semantic Web #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:11:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jena #CVE_2025_49656 #CVE_2025_50151 #cybersecurity #file system #Fuseki #Java Framework #Semantic Web #Vulnerability
Daily CyberSecurity
Apache Jena Flaws (CVE-2025-49656 and CVE-2025-50151) Expose Semantic Web Apps to File System Compromise
Apache Jena versions up to 5.4.0 are vulnerable (CVE-2025-49656, -50151), allowing admin users to compromise the server file system and manipulate configurations.
⤷ Title: APT41 Unleashes Full Arsenal in Rare African Cyberespionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:06:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Africa #APT41 #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #lateral movement #threat group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:06:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Africa #APT41 #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #lateral movement #threat group
Daily CyberSecurity
APT41 Unleashes Full Arsenal in Rare African Cyberespionage Campaign
Kaspersky uncovers a sophisticated APT41 cyberespionage campaign targeting African government IT, showcasing the Chinese group's full TTPs, including Impacket and Cobalt Strike.
⤷ Title: LARVA-208: New Web3 Phishing Campaign Leverages Fake AI Platforms & Job Lures to Steal Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Platforms #cryptocurrency #cybersecurity #Fickle Stealer #Job Scams #LARVA_208 #phishing #social engineering #Web3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Platforms #cryptocurrency #cybersecurity #Fickle Stealer #Job Scams #LARVA_208 #phishing #social engineering #Web3
Daily CyberSecurity
LARVA-208: New Web3 Phishing Campaign Leverages Fake AI Platforms & Job Lures to Steal Crypto
LARVA-208 is targeting Web3 developers with fake AI platforms (like Norlax AI) and job lures to deploy Fickle Stealer malware, aiming to steal crypto and sensitive data.
⤷ Title: Security Misconfiguration (OWASP A05): Guía de Hacking y Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:01:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #ethical_hacking #penetration_testing #web_development
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:01:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #ethical_hacking #penetration_testing #web_development
Medium
Security Misconfiguration(OWASP A05): Guía de Hacking y Bug Bounty
Descubre cómo las Security Misconfiguration exponen sistemas y datos. ¡Explota y protege con esta guía!