⤷ Title: New Android Banking Malware Targets Indian Banks: Steals Credentials, Intercepts OTPs via Fake Apps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:01:18 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Credential Theft #cybersecurity #Financial Fraud #firebase #India #OTP Interception #phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:01:18 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Credential Theft #cybersecurity #Financial Fraud #firebase #India #OTP Interception #phishing
Penetration Testing Tools
New Android Banking Malware Targets Indian Banks: Steals Credentials, Intercepts OTPs via Fake Apps
CYFIRMA warns of a new Android malware campaign disguised as banking apps, aggressively targeting Indian bank customers to steal credentials, intercept OTPs, and perform unauthorized transactions.
⤷ Title: ropr: blazing fast multithreaded ROP Gadget finder
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:27 +0000
════════════════════════
⌗ Tags: #Open Source Tool #ROP Gadget finder #ropr
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:27 +0000
════════════════════════
⌗ Tags: #Open Source Tool #ROP Gadget finder #ropr
Penetration Testing Tools
ropr: blazing fast multithreaded ROP Gadget finder
ropr is a blazing fast multithreaded ROP Gadget finder. These gadgets may be used for binary exploitation and to subvert vulnerable executables.
⤷ Title: CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:17 +0000
════════════════════════
⌗ Tags: #Malware #CastleLoader #ClickFix #cybersecurity #Github #Infostealer #Loader #malware #phishing #RAT #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:17 +0000
════════════════════════
⌗ Tags: #Malware #CastleLoader #ClickFix #cybersecurity #Github #Infostealer #Loader #malware #phishing #RAT #threat intelligence
Penetration Testing Tools
CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
CastleLoader, a sophisticated malware loader, is actively exploiting ClickFix phishing and fake GitHub repos to distribute infostealers and RATs, with a 29% infection rate.
⤷ Title: TerraformGoat: “Vulnerable by Design” multi cloud deployment tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:26:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #TerraformGoat #Vulnerable by Design
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:26:56 +0000
════════════════════════
⌗ Tags: #Open Source Tool #TerraformGoat #Vulnerable by Design
Penetration Testing Tools
TerraformGoat: "Vulnerable by Design" multi cloud deployment tool
TerraformGoat is HuoCorp research lab's "Vulnerable by Design" multi cloud deployment tool. supported cloud vendors include AWS, Azure, Google
⤷ Title: Critical Command Injection (CVE-2025-54416) in tj-actions/branch-names GitHub Action Exposes 5,000+ Repos
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:50:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #Command Injection #CVE_2025_54416 #cybersecurity #GitHub Actions #rce #Remote Code Execution #supply chain attack #tj_actions/branch_names #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:50:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #Command Injection #CVE_2025_54416 #cybersecurity #GitHub Actions #rce #Remote Code Execution #supply chain attack #tj_actions/branch_names #Vulnerability
Daily CyberSecurity
Critical Command Injection (CVE-2025-54416) in tj-actions/branch-names GitHub Action Exposes 5,000+ Repos
A critical command injection flaw (CVE-2025-54416) in tj-actions/branch-names GitHub Action allows arbitrary code execution in workflows, affecting over 5,000 public repositories.
⤷ Title: The Homograph Illusion: Phishing Attacks Exploit Lookalike Characters to Bypass Defenses – AI Amplifies the Threat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Content Filtering #Credential Theft #cybersecurity #Homograph Attack #phishing #social engineering #Unicode #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Content Filtering #Credential Theft #cybersecurity #Homograph Attack #phishing #social engineering #Unicode #Unit 42
Daily CyberSecurity
The Homograph Illusion: Phishing Attacks Exploit Lookalike Characters to Bypass Defenses – AI Amplifies the Threat
Unit 42 reveals homograph phishing attacks exploiting visually similar characters to bypass defenses and deceive users. AI is amplifying this threat, making malicious emails highly convincing.
⤷ Title: Fire Ant: Stealthy Cyber-Espionage Campaign Targets VMware ESXi & vCenter, Evades Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:36:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cyber_espionage #cybersecurity #ESXi #Fire Ant #Network Appliances #UNC3886 #vCenter #virtualization #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:36:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cyber_espionage #cybersecurity #ESXi #Fire Ant #Network Appliances #UNC3886 #vCenter #virtualization #vmware
Daily CyberSecurity
Fire Ant: Stealthy Cyber-Espionage Campaign Targets VMware ESXi & vCenter, Evades Detection
Sygnia uncovers "Fire Ant," a sophisticated cyber-espionage campaign exploiting VMware ESXi and vCenter since early 2025, using advanced techniques to evade detection and maintain persistent access.
⤷ Title: RCE, SSRF & Data Exposure: Salesforce Patches 8 Serious Flaws in Tableau Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Data Exposure #rce #Remote Code Execution #Salesforce #sql injection #ssrf #Tableau Server #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Data Exposure #rce #Remote Code Execution #Salesforce #sql injection #ssrf #Tableau Server #Vulnerability
Daily CyberSecurity
RCE, SSRF & Data Exposure: Salesforce Patches 8 Serious Flaws in Tableau Server
Salesforce patched eight critical flaws in Tableau Server, including RCE, database exposure, and SSRF vulnerabilities, urging users to update immediately.
⤷ Title: Cyber Stealer: New Infostealer-Botnet Hybrid Offers Full Digital Plunder as a Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:30:08 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Credential Theft #cryptocurrency #Cyber Stealer #cybersecurity #ddos #Infostealer #MaaS #Malware_as_a_Service #Remote Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:30:08 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Credential Theft #cryptocurrency #Cyber Stealer #cybersecurity #ddos #Infostealer #MaaS #Malware_as_a_Service #Remote Access
Daily CyberSecurity
Cyber Stealer: New Infostealer-Botnet Hybrid Offers Full Digital Plunder as a Service
eSentire unveils Cyber Stealer, a new infostealer-botnet hybrid offered as a service, fusing data theft, remote control, crypto mining, and DDoS attacks into one scalable toolkit.
⤷ Title: SHUYAL: New Stealthy Infostealer Plunders Browser Credentials, System Data, & Screenshots to Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #evasion #Hybrid_Analysis #Infostealer #malware #SHUYAL #spyware #Telegram exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:27:12 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #evasion #Hybrid_Analysis #Infostealer #malware #SHUYAL #spyware #Telegram exfiltration
Daily CyberSecurity
SHUYAL: New Stealthy Infostealer Plunders Browser Credentials, System Data, & Screenshots to Telegram
Hybrid Analysis reveals SHUYAL, a new stealthy infostealer that harvests browser credentials, system data, and screenshots, exfiltrating it all via a Telegram bot.
⤷ Title: Chaos Ransomware: New RaaS Group (Likely Former BlackSuit) Unleashes Vishing & Double Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:21:19 +0000
════════════════════════
⌗ Tags: #Malware #BlackSuit #Chaos Ransomware #Cybercrime #cybersecurity #Double Extortion #Microsoft Quick Assist #RaaS #Royal #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:21:19 +0000
════════════════════════
⌗ Tags: #Malware #BlackSuit #Chaos Ransomware #Cybercrime #cybersecurity #Double Extortion #Microsoft Quick Assist #RaaS #Royal #Vishing
Daily CyberSecurity
Chaos Ransomware: New RaaS Group (Likely Former BlackSuit) Unleashes Vishing & Double Extortion
Cisco Talos reveals "Chaos," a new RaaS operation likely formed by former BlackSuit members, using vishing and Quick Assist to conduct big-game hunting and double extortion campaigns.
⤷ Title: CERT Warns of Privilege Escalation Vulnerability in Lakeside SysTrack (CVE-2025-6241)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:18:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #cybersecurity #DLL hijacking #Endpoint Monitoring #Lakeside Software #LPE #privilege escalation #SysTrack #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:18:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #cybersecurity #DLL hijacking #Endpoint Monitoring #Lakeside Software #LPE #privilege escalation #SysTrack #Vulnerability
Daily CyberSecurity
CERT Warns of Privilege Escalation Vulnerability in Lakeside SysTrack (CVE-2025-6241)
A critical privilege escalation flaw (CVE-2025-6241) in Lakeside Software's SysTrack allows low-privileged local users to gain SYSTEM access via DLL hijacking. Patch immediately.
⤷ Title: Critical Node-SAML Flaw (CVE-2025-54369) Exposes SAML 2.0 to Authentication Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:13:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_54369 #cybersecurity #Node_SAML #SAML #SAML 2.0 #Single Sign_On #SSO #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:13:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_54369 #cybersecurity #Node_SAML #SAML #SAML 2.0 #Single Sign_On #SSO #Vulnerability
Daily CyberSecurity
Critical Node-SAML Flaw (CVE-2025-54369) Exposes SAML 2.0 to Authentication Bypass
A critical flaw (CVE-2025-54369) in Node-SAML allows attackers to bypass SAML 2.0 authentication by manipulating unsigned assertion data. Update to v5.1.0 immediately!
⤷ Title: Singapore’s Critical Infrastructure Under Attack by China-Linked UNC3886 APT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:11:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #china #Critical Infrastructure #cyber_espionage #cyberattack #OT Security #singapore #UNC3886 #Zero_Day Exploits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:11:13 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #china #Critical Infrastructure #cyber_espionage #cyberattack #OT Security #singapore #UNC3886 #Zero_Day Exploits
Daily CyberSecurity
Singapore's Critical Infrastructure Under Attack by China-Linked UNC3886 APT
OT-ISAC warns that China-linked APT group UNC3886 is actively targeting Singapore's critical infrastructure, exploiting zero-day vulnerabilities for stealthy, long-term access.
⤷ Title: Russian-Aligned Hive0156 Escalates Remcos RAT Attacks on Ukrainian Government & Military
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:10:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyberattack #cybersecurity #Hive0156 #IBM X_Force #Remcos RAT #Remote Access Trojan #russia #spear_phishing #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:10:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyberattack #cybersecurity #Hive0156 #IBM X_Force #Remcos RAT #Remote Access Trojan #russia #spear_phishing #Ukraine
Daily CyberSecurity
Russian-Aligned Hive0156 Escalates Remcos RAT Attacks on Ukrainian Government & Military
IBM X-Force warns that Russian-aligned Hive0156 is intensifying spear-phishing campaigns against Ukrainian government and military, delivering Remcos RAT via LNK/PowerShell files.
⤷ Title: Windows 11 News Feed Gets AI Overhaul: Microsoft Replaces MSN with “Copilot Discover”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:09:10 +0000
════════════════════════
⌗ Tags: #Windows #advertising #AI #Copilot Discover #Microsoft #MSN #News Feed #Personalization #Widgets Panel #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:09:10 +0000
════════════════════════
⌗ Tags: #Windows #advertising #AI #Copilot Discover #Microsoft #MSN #News Feed #Personalization #Widgets Panel #Windows 11
Daily CyberSecurity
Windows 11 News Feed Gets AI Overhaul: Microsoft Replaces MSN with "Copilot Discover"
Microsoft is replacing its MSN News feed in Windows 11's widgets panel with "Copilot Discover," an AI-driven experience offering personalized content and smoother interactions.
⤷ Title: Apple Overhauls App Store Age Ratings with New Granular Tiers for Enhanced Parental Controls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Technology #Age Ratings #App Store Connect #Apple App Store #Developers #Family Safety #ios #iPadOS #macOS #Parental Controls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:06:12 +0000
════════════════════════
⌗ Tags: #Technology #Age Ratings #App Store Connect #Apple App Store #Developers #Family Safety #ios #iPadOS #macOS #Parental Controls
Daily CyberSecurity
Apple Overhauls App Store Age Ratings with New Granular Tiers for Enhanced Parental Controls
Apple introduces more granular age ratings for the App Store, enhancing family safety tools and requiring developers to complete new content questionnaires by Jan 2026.
⤷ Title: Intel CEO Hints at Exiting Advanced Chip Manufacturing Amid Cost Cuts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:03:55 +0000
════════════════════════
⌗ Tags: #Technology #14A #18A #Chip Manufacturing #Cost Cuts #Foundry #intel #samsung #Semiconductors #Tech Industry #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:03:55 +0000
════════════════════════
⌗ Tags: #Technology #14A #18A #Chip Manufacturing #Cost Cuts #Foundry #intel #samsung #Semiconductors #Tech Industry #TSMC
Daily CyberSecurity
Intel CEO Hints at Exiting Advanced Chip Manufacturing Amid Cost Cuts
Intel's new CEO indicates the company may exit advanced chip manufacturing (14A/18A) if external demand falters, highlighting struggles to compete with TSMC and ongoing cost-cutting efforts.
⤷ Title: Google Unveils “Opal”: A New AI Tool for Building Mini Web Apps with Natural Language
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Technology #AI App Builder #AI Tools #Generative AI #Google Labs #Google Opal #No_Code #Productivity #web development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Technology #AI App Builder #AI Tools #Generative AI #Google Labs #Google Opal #No_Code #Productivity #web development
Daily CyberSecurity
Google Unveils "Opal": A New AI Tool for Building Mini Web Apps with Natural Language
Google introduces "Opal" in Google Labs, an experimental AI service allowing users to build web applications using natural language prompts, simplifying app creation for non-technical users.
⤷ Title: My JS Recon Stack: How I Mine JavaScript for Tokens, Endpoints, and Vulnerabilities
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:37 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #ai #information_security #bug_bounty
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:37 GMT
════════════════════════
⌗ Tags: #infosec #cybersecurity #ai #information_security #bug_bounty
Medium
My JS Recon Stack: How I Mine JavaScript for Tokens, Endpoints, and Vulnerabilities
“Give me your JavaScript, and I’ll give you your bug bounty.”
⤷ Title: I Used usedJS to Find 100+ Vulnerabilities — Here’s How
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #infosec #information_security #bug_bounty
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:40:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #infosec #information_security #bug_bounty
Medium
I Used usedJS to Find 100+ Vulnerabilities — Here’s How
“The JavaScript files told me everything — I just had to listen.”