⤷ Title: Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now!
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:52:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Access Point #Aruba Instant On #CVE_2025_37103 #cybersecurity #Hardcoded Credentials #HPE #network security #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:52:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Access Point #Aruba Instant On #CVE_2025_37103 #cybersecurity #Hardcoded Credentials #HPE #network security #vulnerability
Penetration Testing Tools
Critical Flaw (CVE-2025-37103) in Aruba Instant On APs: Hardcoded Credentials Allow Full Admin Takeover – Patch Now!
HPE warns of a critical vulnerability (CVE-2025-37103, CVSS 9.8) in Aruba Instant On APs with hardcoded credentials, allowing unauthenticated full administrative access. Update immediately!
⤷ Title: npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:39:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Eslint #malware #npm #phishing #PoC #Prettier #remote code execution #supply chain attack #Synckit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:39:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Eslint #malware #npm #phishing #PoC #Prettier #remote code execution #supply chain attack #Synckit
Penetration Testing Tools
npm Supply Chain Attack Exploited in the Wild – Phishing Steals Maintainer Tokens, Injects Malware into Popular Packages
A phishing campaign stole npm maintainer tokens, leading to trojanized versions of eslint-config-prettier, synckit, and other packages, enabling remote code execution on Windows systems.
⤷ Title: Critical Flaw (CVE-2025-24936, CVSS 9.0) in Nokia WaveSuite NOC Expose Telecom Networks to RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:46:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_24936 #CVE_2025_24938 #cybersecurity #enterprise #Network Operations #Nokia WaveSuite NOC #rce #telecom #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:46:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_24936 #CVE_2025_24938 #cybersecurity #enterprise #Network Operations #Nokia WaveSuite NOC #rce #telecom #Vulnerability
Daily CyberSecurity
Critical Flaw (CVE-2025-24936, CVSS 9.0) in Nokia WaveSuite NOC Expose Telecom Networks to RCE
Nokia's WaveSuite NOC platform has two severe command injection vulnerabilities (CVE-2025-24938, CVE-2025-24936) allowing remote code execution, even with low privileges.
⤷ Title: Greedy Sponge Reemerges: New AllaKore RAT Variant and SystemBC Target Mexico’s Financial Sector
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:44:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AllaKore RAT #Cybercrime #financial fraud #Greedy Sponge #malware #Mexico #Remote Access Trojan #spear_phishing #SystemBC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:44:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AllaKore RAT #Cybercrime #financial fraud #Greedy Sponge #malware #Mexico #Remote Access Trojan #spear_phishing #SystemBC
Daily CyberSecurity
Greedy Sponge Reemerges: New AllaKore RAT Variant and SystemBC Target Mexico's Financial Sector
Greedy Sponge, a financially motivated group, is back with an upgraded AllaKore RAT and SystemBC, targeting Mexican organizations for banking credentials and financial fraud.
⤷ Title: Android Malware Strikes: Fake Facebook & TikTok Apps Impersonate Brands for Traffic Monetization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:40:17 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #apk #brand impersonation #cybersecurity #facebook #phishing #TikTok #Traffic Monetization #Trustwave
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:40:17 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #apk #brand impersonation #cybersecurity #facebook #phishing #TikTok #Traffic Monetization #Trustwave
Daily CyberSecurity
Android Malware Strikes: Fake Facebook & TikTok Apps Impersonate Brands for Traffic Monetization
Trustwave uncovers an Android malware cluster using fake Facebook & TikTok apps to lure victims via brand impersonation, abusing permissions for data collection and traffic monetization.
⤷ Title: NailaoLocker Ransomware: Chinese SM2 Crypto and Built-in Decryptor Raise Questions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:35:12 +0000
════════════════════════
⌗ Tags: #Malware #cryptography #cybersecurity #DLL side_loading #encryption #FortiGuard Labs #malware #NailaoLocker #ransomware #SM2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:35:12 +0000
════════════════════════
⌗ Tags: #Malware #cryptography #cybersecurity #DLL side_loading #encryption #FortiGuard Labs #malware #NailaoLocker #ransomware #SM2
Daily CyberSecurity
NailaoLocker Ransomware: Chinese SM2 Crypto and Built-in Decryptor Raise Questions
FortiGuard Labs unveils NailaoLocker, a new ransomware using Chinese SM2 encryption and a built-in, non-functional decryptor, suggesting a prototype or decoy.
⤷ Title: Important wolfSSL Update: Critical Apple Trust Store Bypass & Predictable Randomness Flaws Patched
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:30:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #cryptography #CVE_2025_7394 #CVE_2025_7395 #cybersecurity #embedded systems #IOT #ssl #tls #Vulnerability #wolfSSL
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:30:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #cryptography #CVE_2025_7394 #CVE_2025_7395 #cybersecurity #embedded systems #IOT #ssl #tls #Vulnerability #wolfSSL
Daily CyberSecurity
Important wolfSSL Update: Critical Apple Trust Store Bypass & Predictable Randomness Flaws Patched
wolfSSL 5.8.2 patches four vulnerabilities, including a critical Apple trust store bypass (CVE-2025-7395) and predictable randomness after fork(), impacting secure communications.
⤷ Title: From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cobalt Strike #cyberattack #Fscan #Ivanti Connect Secure #JPCERT/CC #malware #MDifyLoader #VShell #Vulnerability
Daily CyberSecurity
From MDifyLoader to Fscan: JPCERT Uncovers Deep Exploitation of Ivanti VPN Flaws in Advanced Malware Campaign
JPCERT/CC details a sophisticated, ongoing malware campaign exploiting Ivanti Connect Secure (CVE-2025-0282, -22457) using MDifyLoader, Cobalt Strike, vshell, and Fscan for stealthy persistent access.
⤷ Title: SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:21 +0000
════════════════════════
⌗ Tags: #Malware #AhnLab #botnet #C2 #Command and Control #cybersecurity #ddos #Discord #Linux #Python #SVF Bot
Daily CyberSecurity
SVF Botnet: New Python DDoS Threat Leverages Discord for Stealthy C&C on Linux Servers
AhnLab uncovers SVF Bot, a Python-based DDoS botnet abusing Discord as its C&C channel to target misconfigured Linux servers and launch HTTP/UDP floods.
⤷ Title: DeedRAT Backdoor: Chinese APT Targets Southeast Asian Governments via Vulnerable AV Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Chinese APT #cyberattack #cybersecurity #DeedRAT #DLL Sideloading #Government #malware #Southeast Asia #VIPRE Antivirus
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #Chinese APT #cyberattack #cybersecurity #DeedRAT #DLL Sideloading #Government #malware #Southeast Asia #VIPRE Antivirus
Daily CyberSecurity
DeedRAT Backdoor: Chinese APT Targets Southeast Asian Governments via Vulnerable AV Software
LAB52 uncovers a sophisticated phishing campaign delivering DeedRAT, a modular backdoor by Chinese APTs, targeting Southeast Asian governments via vulnerable AV software.
⤷ Title: Ghost Crypt & PureRAT: New Stealthy Malware Targets Accounting Firm via “Process Hypnosis”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:15:34 +0000
════════════════════════
⌗ Tags: #Malware #Accounting Firm #Crypter #cybersecurity #evasion #Ghost Crypt #malware #Process Hypnosis #PureRAT #rat #Remote Access Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:15:34 +0000
════════════════════════
⌗ Tags: #Malware #Accounting Firm #Crypter #cybersecurity #evasion #Ghost Crypt #malware #Process Hypnosis #PureRAT #rat #Remote Access Trojan
Daily CyberSecurity
Ghost Crypt & PureRAT: New Stealthy Malware Targets Accounting Firm via "Process Hypnosis"
eSentire uncovered a sophisticated attack on a US accounting firm, deploying PureRAT via the new Ghost Crypt crypter and a stealthy "Process Hypnosis" injection technique.
⤷ Title: Apache Jena Flaws (CVE-2025-49656 and CVE-2025-50151) Expose Semantic Web Apps to File System Compromise
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:11:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jena #CVE_2025_49656 #CVE_2025_50151 #cybersecurity #file system #Fuseki #Java Framework #Semantic Web #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:11:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Jena #CVE_2025_49656 #CVE_2025_50151 #cybersecurity #file system #Fuseki #Java Framework #Semantic Web #Vulnerability
Daily CyberSecurity
Apache Jena Flaws (CVE-2025-49656 and CVE-2025-50151) Expose Semantic Web Apps to File System Compromise
Apache Jena versions up to 5.4.0 are vulnerable (CVE-2025-49656, -50151), allowing admin users to compromise the server file system and manipulate configurations.
⤷ Title: APT41 Unleashes Full Arsenal in Rare African Cyberespionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:06:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Africa #APT41 #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #lateral movement #threat group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:06:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Africa #APT41 #Cobalt Strike #Cyberespionage #Government IT #Impacket #kaspersky #lateral movement #threat group
Daily CyberSecurity
APT41 Unleashes Full Arsenal in Rare African Cyberespionage Campaign
Kaspersky uncovers a sophisticated APT41 cyberespionage campaign targeting African government IT, showcasing the Chinese group's full TTPs, including Impacket and Cobalt Strike.
⤷ Title: LARVA-208: New Web3 Phishing Campaign Leverages Fake AI Platforms & Job Lures to Steal Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Platforms #cryptocurrency #cybersecurity #Fickle Stealer #Job Scams #LARVA_208 #phishing #social engineering #Web3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Platforms #cryptocurrency #cybersecurity #Fickle Stealer #Job Scams #LARVA_208 #phishing #social engineering #Web3
Daily CyberSecurity
LARVA-208: New Web3 Phishing Campaign Leverages Fake AI Platforms & Job Lures to Steal Crypto
LARVA-208 is targeting Web3 developers with fake AI platforms (like Norlax AI) and job lures to deploy Fickle Stealer malware, aiming to steal crypto and sensitive data.
⤷ Title: Security Misconfiguration (OWASP A05): Guía de Hacking y Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:01:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #ethical_hacking #penetration_testing #web_development
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:01:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #ethical_hacking #penetration_testing #web_development
Medium
Security Misconfiguration(OWASP A05): Guía de Hacking y Bug Bounty
Descubre cómo las Security Misconfiguration exponen sistemas y datos. ¡Explota y protege con esta guía!
⤷ Title: I Found 127 Hidden Bugs in JavaScript Files Here’s How
════════════════════════
𐀪 Author: Ibtissam hammadi
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:51:03 GMT
════════════════════════
⌗ Tags: #infosec #technology #javascript #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Ibtissam hammadi
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:51:03 GMT
════════════════════════
⌗ Tags: #infosec #technology #javascript #bug_bounty #cybersecurity
Medium
I Found 127 Hidden Bugs in JavaScript Files Here’s How
The One JavaScript Trick That Exposed 127 Vulnerabilities Instantly
⤷ Title: DefenseArk #ThreatIntelThursday | Smurf Attacks
════════════════════════
𐀪 Author: Kalpitha S
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:31:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #threat_intelligence #smurfs #hacking
════════════════════════
𐀪 Author: Kalpitha S
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:31:55 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #threat_intelligence #smurfs #hacking
Medium
DefenseArk #ThreatIntelThursday | Smurf Attacks
This article was originally published on Oct 28, 2021, writted by Ted Udelson
⤷ Title: CoinDCX Hack: 44 Million Dollars Lost. How Safeguard Helps Protect Your Crypto
════════════════════════
𐀪 Author: Safeguard Capital
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:08 GMT
════════════════════════
⌗ Tags: #hacking #india #bitcoin #cryptocurrency
════════════════════════
𐀪 Author: Safeguard Capital
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:27:08 GMT
════════════════════════
⌗ Tags: #hacking #india #bitcoin #cryptocurrency
Medium
CoinDCX Hack: 44 Million Dollars Lost. How Safeguard Helps Protect Your Crypto
One of India’s largest crypto exchanges, CoinDCX, has suffered a serious security breach. Over 44 million dollars in crypto assets were…
⤷ Title: Writeup — Evil File reader (Web) — BDSec CTF 2025
════════════════════════
𐀪 Author: TIOURSI YASSER
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:39:30 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ctf_writeup #ctf
════════════════════════
𐀪 Author: TIOURSI YASSER
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 23:39:30 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #ctf_writeup #ctf
Medium
Writeup — Evil File reader (Web) — BDSec CTF 2025
Challenge Overview
⤷ Title: Most Cookies CTFs Write-up
════════════════════════
𐀪 Author: -_ENIGMA_-
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 22:57:38 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #hacking #ctf #flask #picoctf
════════════════════════
𐀪 Author: -_ENIGMA_-
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 22:57:38 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #hacking #ctf #flask #picoctf
Medium
Most Cookies CTFs Write-up
بسم الله الرحمن الرحيم
والصلاة والسلام على نبينا المجاهد الشهيد
والصلاة والسلام على نبينا المجاهد الشهيد
⤷ Title: The Invisible Weakness: Unmasking IoT Vulnerabilities in a Connected World
════════════════════════
𐀪 Author: Md Shafiqul Baten Sumon
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:33:31 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #zero_trust #mirai_botnet #iot
════════════════════════
𐀪 Author: Md Shafiqul Baten Sumon
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 00:33:31 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #zero_trust #mirai_botnet #iot
Medium
The Invisible Weakness: Unmasking IoT Vulnerabilities in a Connected World
By Md Shafiqul Baten Sumon