⤷ Title: TryHackMe: LazyAdmin [Write-up / Walkthrough]
════════════════════════
𐀪 Author: SIGKILLers
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 21:26:05 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #lazy_admin #writeup #tryhackme
════════════════════════
𐀪 Author: SIGKILLers
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 21:26:05 GMT
════════════════════════
⌗ Tags: #ctf #cybersecurity #lazy_admin #writeup #tryhackme
Medium
TryHackMe: LazyAdmin [Write-up / Walkthrough]
LazyAdmin is a beginner-friendly CTF room on TryHackMe that teaches fundamental enumeration and privilege escalation techniques.
⤷ Title: Securely storing credentials in Terraform with ‘Ephemeral Blocks’ and ‘Write-Only’ attributes
════════════════════════
𐀪 Author: ISHII (石井)
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 21:23:52 GMT
════════════════════════
⌗ Tags: #devops #terraform #infrastructure_as_code #infrastructure #cybersecurity
════════════════════════
𐀪 Author: ISHII (石井)
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 21:23:52 GMT
════════════════════════
⌗ Tags: #devops #terraform #infrastructure_as_code #infrastructure #cybersecurity
Medium
Securely storing credentials in Terraform with ‘Ephemeral Blocks’ and ‘Write-Only’ attributes
Infrastructure as Code (IaC) has changed how we manage cloud resources. But it also brought new security challenges. A big one is how to…
⤷ Title: Monetizing Stolen Data in the Name of Threat Intelligence – The Case of Farnsworth Intelligence
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 21:23:01 GMT
════════════════════════
⌗ Tags: #cyberattack #hacks #cybercrime #crime #cybersecurity
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 21:23:01 GMT
════════════════════════
⌗ Tags: #cyberattack #hacks #cybercrime #crime #cybersecurity
Medium
Monetizing Stolen Data in the Name of Threat Intelligence – The Case of Farnsworth Intelligence
In July 2025, cybersecurity journalists uncovered a startling development: a U.S. startup is openly selling personal data pilfered by malware, effectively repackaging hackers’ stolen loot as a…
⤷ Title: ALLSIGNS2PWNAGE WALKTHROUGH : TRYHACKME
════════════════════════
𐀪 Author: rizzziom
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 22:31:48 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #penetration_testing #ctf_writeup #ctf
════════════════════════
𐀪 Author: rizzziom
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 22:31:48 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #penetration_testing #ctf_writeup #ctf
Medium
ALLSIGNS2PWNAGE WALKTHROUGH : TRYHACKME
TryHackMe AllSigns2Pwnage CTF challenge writeup.
⤷ Title: npm Supply Chain Attack Exposes Devs to “Scavenger” Malware Via Phished Accounts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:52:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Developer Security #Eslint #JavaScript #malware #npm #phishing #Scavenger #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:52:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Developer Security #Eslint #JavaScript #malware #npm #phishing #Scavenger #supply chain attack
Penetration Testing Tools
npm Supply Chain Attack Exposes Devs to "Scavenger" Malware Via Phished Accounts
A phishing attack compromised an npm maintainer's account, leading to the injection of "Scavenger" malware into popular packages like eslint-config-prettier, posing a severe supply chain threat.
⤷ Title: #StopRansomware: CISA & FBI Warn of Interlock Ransomware Surging, Hits US Healthcare Giants
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:49:56 +0000
════════════════════════
⌗ Tags: #Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:49:56 +0000
════════════════════════
⌗ Tags: #Malware
Penetration Testing Tools
#StopRansomware: CISA & FBI Warn of Interlock Ransomware Surging, Hits US Healthcare Giants
CISA and FBI warn of Interlock ransomware's surge, targeting US healthcare and critical infrastructure with double extortion, drive-by downloads, and new FileFix social engineering.
⤷ Title: Google’s AI Now Calls Businesses for You: A New Era of Search Automation or Digital Noise?
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:41:21 +0000
════════════════════════
⌗ Tags: #Google #AI #AI_powered Calling #Automation #Convenience #Duplex #Generative AI #Google Search #Local Businesses #privacy #Project Astra
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:41:21 +0000
════════════════════════
⌗ Tags: #Google #AI #AI_powered Calling #Automation #Convenience #Duplex #Generative AI #Google Search #Local Businesses #privacy #Project Astra
Penetration Testing Tools
Google's AI Now Calls Businesses for You: A New Era of Search Automation or Digital Noise?
Google unveils AI-powered calling for local businesses, letting users delegate calls for pricing and availability. This controversial feature is now rolling out in the US, with premium tiers getting higher quotas.
⤷ Title: Lumma Stealer Resurfaces After Takedown: New Stealth Tactics Target Users Via Fake Cracks, CAPTCHAs & GitHub
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:34:19 +0000
════════════════════════
⌗ Tags: #Malware #Cracked Software #cybersecurity #Github #Infostealer #Lumma Stealer #malware #phishing #Resurgence #Takedown #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:34:19 +0000
════════════════════════
⌗ Tags: #Malware #Cracked Software #cybersecurity #Github #Infostealer #Lumma Stealer #malware #phishing #Resurgence #Takedown #threat intelligence
Penetration Testing Tools
Lumma Stealer Resurfaces After Takedown: New Stealth Tactics Target Users Via Fake Cracks, CAPTCHAs & GitHub
Weeks after a major takedown, Lumma Stealer has resurfaced with new stealth tactics, exploiting cracked software, fake CAPTCHAs, and GitHub to resume its credential-stealing operations.
⤷ Title: China Alleges Widespread Foreign Backdoors in Software, Hardware, and Subsea Espionage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:23:33 +0000
════════════════════════
⌗ Tags: #Cyber Security #backdoors #China #cybersecurity #Espionage #Foreign Intelligence #hardware #Maritime Security #National Security #Software #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:23:33 +0000
════════════════════════
⌗ Tags: #Cyber Security #backdoors #China #cybersecurity #Espionage #Foreign Intelligence #hardware #Maritime Security #National Security #Software #Supply Chain
Penetration Testing Tools
China Alleges Widespread Foreign Backdoors in Software, Hardware, and Subsea Espionage
China's Ministry of State Security warns of deliberate backdoors in foreign software/hardware and alleged subsea espionage devices, urging a shift to domestic tech and heightened public vigilance.
⤷ Title: VulnLab: web vulnerability lab project
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:08:32 +0000
════════════════════════
⌗ Tags: #Open Source Tool #VulnLab #web vulnerability lab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:08:32 +0000
════════════════════════
⌗ Tags: #Open Source Tool #VulnLab #web vulnerability lab
Penetration Testing Tools
VulnLab: web vulnerability lab project
VulnLab is a web vulnerability lab project developed by Yavuzlar. Vulnerabilities: SQL Injection, Cross Site Scripting (XSS), more...
⤷ Title: Coyote Banking Trojan Exploits Microsoft UI Automation for Stealthy Credential Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 23:43:52 +0000
════════════════════════
⌗ Tags: #Malware #Akamai #banking trojan #Coyote #cybersecurity #Evasion #Financial Fraud #malware #UI Automation #UIA #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 23:43:52 +0000
════════════════════════
⌗ Tags: #Malware #Akamai #banking trojan #Coyote #cybersecurity #Evasion #Financial Fraud #malware #UI Automation #UIA #Windows Security
Penetration Testing Tools
Coyote Banking Trojan Exploits Microsoft UI Automation for Stealthy Credential Theft
Akamai confirms Coyote, a Latin America-focused banking trojan, is the first malware to exploit Microsoft's UI Automation (UIA) framework in the wild for credential theft.
⤷ Title: Greedy Sponge Targets Mexico: New AllaKore RAT & SystemBC Campaign Evades Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 23:30:30 +0000
════════════════════════
⌗ Tags: #Malware #AllaKore RAT #cybercrime #Financial Fraud #Greedy Sponge #malware #Mexico #Remote Access Trojan #Stealth #SystemBC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 23:30:30 +0000
════════════════════════
⌗ Tags: #Malware #AllaKore RAT #cybercrime #Financial Fraud #Greedy Sponge #malware #Mexico #Remote Access Trojan #Stealth #SystemBC
Penetration Testing Tools
Greedy Sponge Targets Mexico: New AllaKore RAT & SystemBC Campaign Evades Detection
The Greedy Sponge group is persistently targeting Mexican organizations with a modified AllaKore RAT and SystemBC, using advanced geofiltering and stealth tactics to commit financial fraud.
⤷ Title: mx-takeover: detects misconfigured MX records
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 23:05:44 +0000
════════════════════════
⌗ Tags: #Open Source Tool #detects misconfigured MX records #mx_takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 23:05:44 +0000
════════════════════════
⌗ Tags: #Open Source Tool #detects misconfigured MX records #mx_takeover
Penetration Testing Tools
mx-takeover: detects misconfigured MX records
mx-takeover focuses DNS MX records and detects misconfigured MX records. It currently support three technique.
⤷ Title: Toptal GitHub Organization Compromised: Malicious npm Packages Steal Tokens & Wipe Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:39:28 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #github #javascript #malware #npm #supply chain attack #System Destruction #Token Theft #Toptal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:39:28 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #github #javascript #malware #npm #supply chain attack #System Destruction #Token Theft #Toptal
Daily CyberSecurity
Toptal GitHub Organization Compromised: Malicious npm Packages Steal Tokens & Wipe Systems
Socket discovered 10 malicious npm packages from Toptal's GitHub, exfiltrating GitHub tokens and wiping systems. The compromise vector is under investigation.
⤷ Title: Operation GhostChat & PhantomPrayers: China-Linked APTs Target Tibetan Community with Stealthy Spyware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:32:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #china #cyber_espionage #Dalai Lama #DLL Sideloading #Ghost RAT #PhantomNet #TibCERT #Tibetan Community #Zscaler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:32:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #china #cyber_espionage #Dalai Lama #DLL Sideloading #Ghost RAT #PhantomNet #TibCERT #Tibetan Community #Zscaler
Daily CyberSecurity
Operation GhostChat & PhantomPrayers: China-Linked APTs Target Tibetan Community with Stealthy Spyware
Zscaler uncovers two China-linked APT campaigns, "GhostChat" and "PhantomPrayers," targeting the Tibetan community with sophisticated spyware via fake apps and DLL sideloading.
⤷ Title: Critical Axios Flaw (CVE-2025-54371) in Form-Data Dependency Exposes Millions to HTTP Manipulation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:28:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2025_54371 #cybersecurity #Form_Data #HTTP Parameter Pollution #javascript #Multipart Form_Data #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:28:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Axios #CVE_2025_54371 #cybersecurity #Form_Data #HTTP Parameter Pollution #javascript #Multipart Form_Data #Vulnerability
Daily CyberSecurity
Critical Axios Flaw (CVE-2025-54371) in Form-Data Dependency Exposes Millions to HTTP Manipulation
A critical flaw (CVE-2025-54371, CVSS 7.5) in the form-data package, used by Axios 1.10.0, allows attackers to predict multipart boundaries, risking HTTP parameter pollution and injection. Update to 1.11.0 now!
⤷ Title: Dropping Elephant Targets Türkiye’s Missile Industry with Stealthy Conference Lures & VLC DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:22:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #cyber_espionage #Defense Industry #DLL Sideloading #Dropping Elephant #Missile Systems #social engineering #Türkiye #VLC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:22:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #cyber_espionage #Defense Industry #DLL Sideloading #Dropping Elephant #Missile Systems #social engineering #Türkiye #VLC
Daily CyberSecurity
Dropping Elephant Targets Türkiye's Missile Industry with Stealthy Conference Lures & VLC DLL Sideloading
Dropping Elephant is targeting Türkiye's defense industry, particularly missile manufacturers, with weaponized conference lures, VLC DLL sideloading, and custom shellcode for intelligence exfiltration.
⤷ Title: 400,000 WordPress Sites at Risk: CVE-2025-24000 in Post SMTP Plugin Allows Full Site Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:18:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:18:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
400,000 WordPress Sites at Risk: CVE-2025-24000 in Post SMTP Plugin Allows Full Site Takeover
A broken access control vulnerability (CVE-2025-24000) in Post SMTP WordPress plugin allows low-privileged users to take over administrator accounts and full sites.
⤷ Title: 4 Open-Source Packages Infect 56,000+ Downloads with Stealthy Spyware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:12:36 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Keylogger #npm #open_source #PyPI #spyware #supply chain attack #surveillance #Webcam Hijack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:12:36 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Keylogger #npm #open_source #PyPI #spyware #supply chain attack #surveillance #Webcam Hijack
Daily CyberSecurity
4 Open-Source Packages Infect 56,000+ Downloads with Stealthy Spyware
Four open-source packages on npm and PyPI (56k+ downloads) are secretly deploying sophisticated spyware, performing webcam surveillance, keylogging, and credential theft.
⤷ Title: Soco404: New Stealthy Cryptojacking Campaign Exploits Cloud Misconfigurations and PostgreSQL to Mine Crypto
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Cryptojacking #Cybercrime #Linux #malware #PostgreSQL #Soco404 #Stealth #windows #Wiz Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:06:21 +0000
════════════════════════
⌗ Tags: #Malware #Cloud Security #Cryptojacking #Cybercrime #Linux #malware #PostgreSQL #Soco404 #Stealth #windows #Wiz Research
Daily CyberSecurity
Soco404: New Stealthy Cryptojacking Campaign Exploits Cloud Misconfigurations and PostgreSQL to Mine Crypto
Wiz Research uncovers Soco404, an evolving cryptojacking operation exploiting cloud misconfigurations and PostgreSQL to stealthily mine cryptocurrency across Linux and Windows.
⤷ Title: High-Severity SQL Injection (CVE-2025-52914) in Mitel MiCollab Allows Data Access, Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52914 #cybersecurity #MiCollab #Mitel MiCollab #sql injection #Unified Communications #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 25 Jul 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52914 #cybersecurity #MiCollab #Mitel MiCollab #sql injection #Unified Communications #Vulnerability
Daily CyberSecurity
High-Severity SQL Injection (CVE-2025-52914) in Mitel MiCollab Allows Data Access, Command Execution
Mitel issued patches for a high-severity SQL injection flaw (CVE-2025-52914) in MiCollab, allowing authenticated attackers to access user provisioning data and execute arbitrary database commands.