⤷ Title: Working with System Commands Using the subprocess Module — Python in Cybersecurity
════════════════════════
𐀪 Author: Mohammed Gabic
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:31:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #devsecops #cybersecurity #incident_response
════════════════════════
𐀪 Author: Mohammed Gabic
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:31:41 GMT
════════════════════════
⌗ Tags: #penetration_testing #ethical_hacking #devsecops #cybersecurity #incident_response
Medium
Working with System Commands Using the subprocess Module — Python in Cybersecurity
Running system commands in Python lets you automate terminal-based tasks like pinging a server, scanning ports with Nmap, checking network…
⤷ Title: Build Practical Python Scripts for Cybersecurity
════════════════════════
𐀪 Author: Mohammed Gabic
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:25:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking #devsecops #ethical_hacking_training #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Mohammed Gabic
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:25:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking #devsecops #ethical_hacking_training #penetration_testing #cybersecurity
Medium
Build Practical Python Scripts for Cybersecurity
Build Practical Python Scripts for Cybersecurity
⤷ Title: Error Handling with Python in Cybersecurity Making Your Scripts More Reliable and Secure
════════════════════════
𐀪 Author: Mohammed Gabic
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:17:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #kali_linux #ethical_hacking #python_programming #penetration_testing
════════════════════════
𐀪 Author: Mohammed Gabic
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:17:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #kali_linux #ethical_hacking #python_programming #penetration_testing
Medium
Error Handling with Python in Cybersecurity Making Your Scripts More Reliable and Secure
Why You Need Error Handling in Cybersecurity
⤷ Title: TryHackMe — Web App PenTest: NoSQL Injection
════════════════════════
𐀪 Author: Huy Phu
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:56:30 GMT
════════════════════════
⌗ Tags: #tryhackme #nosql_injection #web_security #web_app_pentesting
════════════════════════
𐀪 Author: Huy Phu
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:56:30 GMT
════════════════════════
⌗ Tags: #tryhackme #nosql_injection #web_security #web_app_pentesting
Medium
TryHackMe — Web App PenTest: NoSQL Injection
Learning Objectives
⤷ Title: TryHackMe — Web App Pentest: Advanced SQL Injection
════════════════════════
𐀪 Author: Huy Phu
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:38:33 GMT
════════════════════════
⌗ Tags: #sql_injection #tryhackme
════════════════════════
𐀪 Author: Huy Phu
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 21:38:33 GMT
════════════════════════
⌗ Tags: #sql_injection #tryhackme
Medium
TryHackMe — Web App Pentest: Advanced SQL Injection
Learning Objectives
⤷ Title: Koske Malware: AI-Generated Cryptojacker Hides in Panda Images, Targets Linux Servers with Rootkit Stealth
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 01:00:02 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cryptojacking #cybersecurity #JupyterLab #Koske Malware #Linux #Polyglot Files #rootkit #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 01:00:02 +0000
════════════════════════
⌗ Tags: #Malware #AI Malware #Cryptojacking #cybersecurity #JupyterLab #Koske Malware #Linux #Polyglot Files #rootkit #threat intelligence
Penetration Testing Tools
Koske Malware: AI-Generated Cryptojacker Hides in Panda Images, Targets Linux Servers with Rootkit Stealth
AquaSec uncovers Koske, a new cryptojacking malware potentially AI-generated, hiding in innocent-looking images to silently infect Linux servers and evade detection with rootkit stealth.
⤷ Title: Operation Checkmate: BlackSuit Ransomware Sites Seized, But Is “Chaos” Their Next Rebrand?
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:46:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackSuit #Chaos #cybercrime #cybersecurity #Law Enforcement #Operation Checkmate #Quantum #ransomware #Royal #Takedown
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:46:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackSuit #Chaos #cybercrime #cybersecurity #Law Enforcement #Operation Checkmate #Quantum #ransomware #Royal #Takedown
Penetration Testing Tools
Operation Checkmate: BlackSuit Ransomware Sites Seized, But Is "Chaos" Their Next Rebrand?
An international law enforcement operation, "Operation Checkmate," has seized BlackSuit ransomware's dark web sites. However, intelligence suggests the prolific group may rebrand as "Chaos."
⤷ Title: SharePoint Under Siege: China-Linked Storm-2603 Unleashes Warlock Ransomware After Zero-Day Exploitation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:33:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China #cybersecurity #exploitation #LockBit #ransomware #SharePoint #Storm_2603 #Warlock #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:33:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China #cybersecurity #exploitation #LockBit #ransomware #SharePoint #Storm_2603 #Warlock #zero_day
Penetration Testing Tools
SharePoint Under Siege: China-Linked Storm-2603 Unleashes Warlock Ransomware After Zero-Day Exploitation
Microsoft confirms China-linked Storm-2603 is exploiting SharePoint zero-days (CVE-2025-49706, -49704) to deploy Warlock ransomware on unpatched on-premises servers.
⤷ Title: New Android Banking Malware Targets Indian Banks: Steals Credentials, Intercepts OTPs via Fake Apps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:01:18 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Credential Theft #cybersecurity #Financial Fraud #firebase #India #OTP Interception #phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:01:18 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Credential Theft #cybersecurity #Financial Fraud #firebase #India #OTP Interception #phishing
Penetration Testing Tools
New Android Banking Malware Targets Indian Banks: Steals Credentials, Intercepts OTPs via Fake Apps
CYFIRMA warns of a new Android malware campaign disguised as banking apps, aggressively targeting Indian bank customers to steal credentials, intercept OTPs, and perform unauthorized transactions.
⤷ Title: ropr: blazing fast multithreaded ROP Gadget finder
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:27 +0000
════════════════════════
⌗ Tags: #Open Source Tool #ROP Gadget finder #ropr
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:27 +0000
════════════════════════
⌗ Tags: #Open Source Tool #ROP Gadget finder #ropr
Penetration Testing Tools
ropr: blazing fast multithreaded ROP Gadget finder
ropr is a blazing fast multithreaded ROP Gadget finder. These gadgets may be used for binary exploitation and to subvert vulnerable executables.
⤷ Title: CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:17 +0000
════════════════════════
⌗ Tags: #Malware #CastleLoader #ClickFix #cybersecurity #Github #Infostealer #Loader #malware #phishing #RAT #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:17 +0000
════════════════════════
⌗ Tags: #Malware #CastleLoader #ClickFix #cybersecurity #Github #Infostealer #Loader #malware #phishing #RAT #threat intelligence
Penetration Testing Tools
CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
CastleLoader, a sophisticated malware loader, is actively exploiting ClickFix phishing and fake GitHub repos to distribute infostealers and RATs, with a 29% infection rate.
⤷ Title: TerraformGoat: “Vulnerable by Design” multi cloud deployment tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:26:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #TerraformGoat #Vulnerable by Design
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:26:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #TerraformGoat #Vulnerable by Design
Penetration Testing Tools
TerraformGoat: "Vulnerable by Design" multi cloud deployment tool
TerraformGoat is HuoCorp research lab's "Vulnerable by Design" multi cloud deployment tool. supported cloud vendors include AWS, Azure, Google
⤷ Title: Critical Command Injection (CVE-2025-54416) in tj-actions/branch-names GitHub Action Exposes 5,000+ Repos
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:50:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #Command Injection #CVE_2025_54416 #cybersecurity #GitHub Actions #rce #Remote Code Execution #supply chain attack #tj_actions/branch_names #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:50:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #Command Injection #CVE_2025_54416 #cybersecurity #GitHub Actions #rce #Remote Code Execution #supply chain attack #tj_actions/branch_names #Vulnerability
Daily CyberSecurity
Critical Command Injection (CVE-2025-54416) in tj-actions/branch-names GitHub Action Exposes 5,000+ Repos
A critical command injection flaw (CVE-2025-54416) in tj-actions/branch-names GitHub Action allows arbitrary code execution in workflows, affecting over 5,000 public repositories.
⤷ Title: The Homograph Illusion: Phishing Attacks Exploit Lookalike Characters to Bypass Defenses – AI Amplifies the Threat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Content Filtering #Credential Theft #cybersecurity #Homograph Attack #phishing #social engineering #Unicode #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Content Filtering #Credential Theft #cybersecurity #Homograph Attack #phishing #social engineering #Unicode #Unit 42
Daily CyberSecurity
The Homograph Illusion: Phishing Attacks Exploit Lookalike Characters to Bypass Defenses – AI Amplifies the Threat
Unit 42 reveals homograph phishing attacks exploiting visually similar characters to bypass defenses and deceive users. AI is amplifying this threat, making malicious emails highly convincing.
⤷ Title: Fire Ant: Stealthy Cyber-Espionage Campaign Targets VMware ESXi & vCenter, Evades Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:36:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cyber_espionage #cybersecurity #ESXi #Fire Ant #Network Appliances #UNC3886 #vCenter #virtualization #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:36:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cyber_espionage #cybersecurity #ESXi #Fire Ant #Network Appliances #UNC3886 #vCenter #virtualization #vmware
Daily CyberSecurity
Fire Ant: Stealthy Cyber-Espionage Campaign Targets VMware ESXi & vCenter, Evades Detection
Sygnia uncovers "Fire Ant," a sophisticated cyber-espionage campaign exploiting VMware ESXi and vCenter since early 2025, using advanced techniques to evade detection and maintain persistent access.
⤷ Title: RCE, SSRF & Data Exposure: Salesforce Patches 8 Serious Flaws in Tableau Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Data Exposure #rce #Remote Code Execution #Salesforce #sql injection #ssrf #Tableau Server #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Data Exposure #rce #Remote Code Execution #Salesforce #sql injection #ssrf #Tableau Server #Vulnerability
Daily CyberSecurity
RCE, SSRF & Data Exposure: Salesforce Patches 8 Serious Flaws in Tableau Server
Salesforce patched eight critical flaws in Tableau Server, including RCE, database exposure, and SSRF vulnerabilities, urging users to update immediately.
⤷ Title: Cyber Stealer: New Infostealer-Botnet Hybrid Offers Full Digital Plunder as a Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:30:08 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Credential Theft #cryptocurrency #Cyber Stealer #cybersecurity #ddos #Infostealer #MaaS #Malware_as_a_Service #Remote Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:30:08 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Credential Theft #cryptocurrency #Cyber Stealer #cybersecurity #ddos #Infostealer #MaaS #Malware_as_a_Service #Remote Access
Daily CyberSecurity
Cyber Stealer: New Infostealer-Botnet Hybrid Offers Full Digital Plunder as a Service
eSentire unveils Cyber Stealer, a new infostealer-botnet hybrid offered as a service, fusing data theft, remote control, crypto mining, and DDoS attacks into one scalable toolkit.
⤷ Title: SHUYAL: New Stealthy Infostealer Plunders Browser Credentials, System Data, & Screenshots to Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #evasion #Hybrid_Analysis #Infostealer #malware #SHUYAL #spyware #Telegram exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #evasion #Hybrid_Analysis #Infostealer #malware #SHUYAL #spyware #Telegram exfiltration
Daily CyberSecurity
SHUYAL: New Stealthy Infostealer Plunders Browser Credentials, System Data, & Screenshots to Telegram
Hybrid Analysis reveals SHUYAL, a new stealthy infostealer that harvests browser credentials, system data, and screenshots, exfiltrating it all via a Telegram bot.
⤷ Title: Chaos Ransomware: New RaaS Group (Likely Former BlackSuit) Unleashes Vishing & Double Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:21:19 +0000
════════════════════════
⌗ Tags: #Malware #BlackSuit #Chaos Ransomware #Cybercrime #cybersecurity #Double Extortion #Microsoft Quick Assist #RaaS #Royal #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:21:19 +0000
════════════════════════
⌗ Tags: #Malware #BlackSuit #Chaos Ransomware #Cybercrime #cybersecurity #Double Extortion #Microsoft Quick Assist #RaaS #Royal #Vishing
Daily CyberSecurity
Chaos Ransomware: New RaaS Group (Likely Former BlackSuit) Unleashes Vishing & Double Extortion
Cisco Talos reveals "Chaos," a new RaaS operation likely formed by former BlackSuit members, using vishing and Quick Assist to conduct big-game hunting and double extortion campaigns.
⤷ Title: CERT Warns of Privilege Escalation Vulnerability in Lakeside SysTrack (CVE-2025-6241)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:18:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #cybersecurity #DLL hijacking #Endpoint Monitoring #Lakeside Software #LPE #privilege escalation #SysTrack #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:18:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #cybersecurity #DLL hijacking #Endpoint Monitoring #Lakeside Software #LPE #privilege escalation #SysTrack #Vulnerability
Daily CyberSecurity
CERT Warns of Privilege Escalation Vulnerability in Lakeside SysTrack (CVE-2025-6241)
A critical privilege escalation flaw (CVE-2025-6241) in Lakeside Software's SysTrack allows low-privileged local users to gain SYSTEM access via DLL hijacking. Patch immediately.
⤷ Title: Critical Node-SAML Flaw (CVE-2025-54369) Exposes SAML 2.0 to Authentication Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:13:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_54369 #cybersecurity #Node_SAML #SAML #SAML 2.0 #Single Sign_On #SSO #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:13:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_54369 #cybersecurity #Node_SAML #SAML #SAML 2.0 #Single Sign_On #SSO #Vulnerability
Daily CyberSecurity
Critical Node-SAML Flaw (CVE-2025-54369) Exposes SAML 2.0 to Authentication Bypass
A critical flaw (CVE-2025-54369) in Node-SAML allows attackers to bypass SAML 2.0 authentication by manipulating unsigned assertion data. Update to v5.1.0 immediately!