⤷ Title: “What If the Hacker Is Already Inside?” — Cybersecurity’s Most Dangerous Assumption
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:51:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #machine_learning #education #ai #life_lessons
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 23:51:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #machine_learning #education #ai #life_lessons
Medium
“What If the Hacker Is Already Inside?” — Cybersecurity’s Most Dangerous Assumption
“They patched everything… but the breach still happened.” I’ve heard that sentence too many times in war rooms across the globe.
⤷ Title: Hack The Box: JinjaCare Writeup
════════════════════════
𐀪 Author: Sahand Babali
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:50:03 GMT
════════════════════════
⌗ Tags: #hackthebox #ctf_writeup #web_app_security #hackthebox_writeup #ctf
════════════════════════
𐀪 Author: Sahand Babali
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:50:03 GMT
════════════════════════
⌗ Tags: #hackthebox #ctf_writeup #web_app_security #hackthebox_writeup #ctf
Medium
Hack The Box: JinjaCare Writeup
Challenge Link: JinjaCare — HTB
⤷ Title: PaperCut NG/MF Vulnerability (CVE-2023-2533) Under Active Exploitation, Allows Remote Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:59:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CSRF #cybersecurity #exploitation #KEV #PaperCut MF #PaperCut NG #Print Management #RCE #remote code execution #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:59:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CSRF #cybersecurity #exploitation #KEV #PaperCut MF #PaperCut NG #Print Management #RCE #remote code execution #vulnerability
Penetration Testing Tools
PaperCut NG/MF Vulnerability (CVE-2023-2533) Under Active Exploitation, Allows Remote Code Execution
CISA issues an urgent alert: PaperCut NG and MF are vulnerable to CVE-2023-2533 (CSRF), allowing remote code execution if an admin clicks a malicious link.
⤷ Title: Tea App’s Second Breach: 1 Million+ Private Messages Exposed, Including Sensitive Discussions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:56:42 +0000
════════════════════════
⌗ Tags: #Data Leak #404 Media #API Vulnerability #cybersecurity #data breach #Dating App #privacy #Private Messages #Sensitive Data #Tea App
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:56:42 +0000
════════════════════════
⌗ Tags: #Data Leak #404 Media #API Vulnerability #cybersecurity #data breach #Dating App #privacy #Private Messages #Sensitive Data #Tea App
Penetration Testing Tools
Tea App's Second Breach: 1 Million+ Private Messages Exposed, Including Sensitive Discussions
The women-only Tea dating app suffers a second, more severe data breach, exposing over 1.1 million private messages, including sensitive discussions on abortions and infidelity.
⤷ Title: Dropbox Passwords Is Shutting Down: Export Your Data by October 28, 2025, or Lose Everything
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:24:09 +0000
════════════════════════
⌗ Tags: #Technology #1Password #cybersecurity #Data Migration #Discontinuation #dropbox #Dropbox Passwords #password manager #Tech News
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:24:09 +0000
════════════════════════
⌗ Tags: #Technology #1Password #cybersecurity #Data Migration #Discontinuation #dropbox #Dropbox Passwords #password manager #Tech News
Daily CyberSecurity
Dropbox Passwords Is Shutting Down: Export Your Data by October 28, 2025, or Lose Everything
Dropbox Passwords will be fully discontinued on October 28, 2025. Users must export all saved data before then, as all information will be permanently deleted.
⤷ Title: OneNote Gains Cell Merging & “Paste Text Only” for Windows, Mac & iPad Insiders
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:19:04 +0000
════════════════════════
⌗ Tags: #Technology #Cell Merging #Insider Preview #Microsoft 365 #note_taking #OneNote #Paste Without Formatting #Productivity #Tech Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:19:04 +0000
════════════════════════
⌗ Tags: #Technology #Cell Merging #Insider Preview #Microsoft 365 #note_taking #OneNote #Paste Without Formatting #Productivity #Tech Update
Daily CyberSecurity
OneNote Gains Cell Merging & "Paste Text Only" for Windows, Mac & iPad Insiders
OneNote Insiders are getting new features: cell merging for tables (Windows, Mac, iPad) and a "paste text only" option (Ctrl+Shift+V) for cleaner note-taking.
⤷ Title: Google NotebookLM Unleashes “Video Overviews”: AI Transforms Documents into Narrated Presentations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:06:09 +0000
════════════════════════
⌗ Tags: #Technology #AI #AI Assistant #Education #Generative AI #google #NotebookLM #Presentations #Research #Video Overviews
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:06:09 +0000
════════════════════════
⌗ Tags: #Technology #AI #AI Assistant #Education #Generative AI #google #NotebookLM #Presentations #Research #Video Overviews
Daily CyberSecurity
Google NotebookLM Unleashes "Video Overviews": AI Transforms Documents into Narrated Presentations
Google NotebookLM introduces "Video Overviews," an AI-powered feature that turns complex documents into narrated, slide-style videos for enhanced visual learning and presentations.
⤷ Title: ChatGPT Launches “Study Mode”: AI Assistant Shifts from Giving Answers to Guiding Learning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:01:12 +0000
════════════════════════
⌗ Tags: #Technology #Academic Integrity #AI #artificial intelligence #ChatGPT #Education #Generative AI #Learning #OpenAI #Study Mode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:01:12 +0000
════════════════════════
⌗ Tags: #Technology #Academic Integrity #AI #artificial intelligence #ChatGPT #Education #Generative AI #Learning #OpenAI #Study Mode
Daily CyberSecurity
ChatGPT Launches "Study Mode": AI Assistant Shifts from Giving Answers to Guiding Learning
OpenAI launches "Study Mode" for ChatGPT, an AI feature designed to guide students through problem-solving with a Socratic method, aiming to foster deeper learning rather than just providing answers.
⤷ Title: Critical BentoML SSRF (CVSS 9.9) Exposes AI Applications to Unauthenticated Network Recon & Cloud Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 01:55:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #BentoML #cybersecurity #machine_learning #python framework #Server_Side Request Forgery #ssrf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 01:55:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #BentoML #cybersecurity #machine_learning #python framework #Server_Side Request Forgery #ssrf
Daily CyberSecurity
Critical BentoML SSRF (CVSS 9.9) Exposes AI Applications to Unauthenticated Network Recon & Cloud Credential Theft
A critical SSRF vulnerability (CVE-2025-54381) in BentoML's file upload handling allows unauthenticated remote attackers to perform internal network reconnaissance and steal cloud metadata credentials from AI applications.
⤷ Title: Global Cyber Authorities Warn of Escalating Threat from Scattered Spider Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 01:46:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ACSC #CCCS #CISA #Cybercrime #DragonForce #fbi #Law Enforcement #MFA Fatigue #NCSC UK #ransomware #RCMP #Scattered Spider #SIM Swapping #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 01:46:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ACSC #CCCS #CISA #Cybercrime #DragonForce #fbi #Law Enforcement #MFA Fatigue #NCSC UK #ransomware #RCMP #Scattered Spider #SIM Swapping #social engineering
Daily CyberSecurity
Global Cyber Authorities Warn of Escalating Threat from Scattered Spider Group
A joint advisory from US, UK, Canada, and Australia warns of Scattered Spider's evolving tactics, now using DragonForce ransomware, spearphishing, SIM swapping, and MFA fatigue to compromise systems.
⤷ Title: Critical Flaw in Wix’s New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Platform #Authentication Bypass #Base44 #cybersecurity #Single Sign_On #SSO #Vulnerability #Wix #Wiz Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Platform #Authentication Bypass #Base44 #cybersecurity #Single Sign_On #SSO #Vulnerability #Wix #Wiz Research
Daily CyberSecurity
Critical Flaw in Wix's New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
Wiz Research uncovered a critical flaw in Wix's new AI platform, Base44, that allowed unauthorized access to private enterprise applications and sensitive data by bypassing SSO.
⤷ Title: Critical RCE Flaw (CVE-2025-5394) in “Alone” WordPress Theme Actively Exploited, Allowing Full Site Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:34:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Alone Theme #Arbitrary File Upload #CVE_2025_5394 #cybersecurity #exploitation #rce #Remote Code Execution #Vulnerability #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:34:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Alone Theme #Arbitrary File Upload #CVE_2025_5394 #cybersecurity #exploitation #rce #Remote Code Execution #Vulnerability #wordpress
Daily CyberSecurity
Critical RCE Flaw (CVE-2025-5394) in "Alone" WordPress Theme Actively Exploited, Allowing Full Site Takeover
A critical RCE flaw (CVE-2025-5394, CVSS 9.8) in the Alone WordPress theme allows unauthenticated attackers to upload arbitrary files and gain full site control. Exploitation is confirmed in the wild.
⤷ Title: Gunra Ransomware Expands to Linux: New Variant Unleashes 100-Thread Encryption & Stealthy Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:30:07 +0000
════════════════════════
⌗ Tags: #Malware #Cross_Platform #Cybercrime #cybersecurity #encryption #Gunra Ransomware #Linux #ransomware #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:30:07 +0000
════════════════════════
⌗ Tags: #Malware #Cross_Platform #Cybercrime #cybersecurity #encryption #Gunra Ransomware #Linux #ransomware #threat intelligence
Daily CyberSecurity
Gunra Ransomware Expands to Linux: New Variant Unleashes 100-Thread Encryption & Stealthy Tactics
Trend Micro reports Gunra ransomware has expanded to Linux, employing 100 parallel encryption threads, partial encryption, and stealthy keystore methods to target global enterprises.
⤷ Title: Seychelles Commercial Bank Hacked: Customer Data Compromised, Suspected Espionage Disguised as Cybercrime
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:22:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Data Leak #cyber_espionage #Cybercrime #dark web #Data Breach #Offshore Banking #Oracle Flexcube #Resecurity #Seychelles Commercial Bank
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:22:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Data Leak #cyber_espionage #Cybercrime #dark web #Data Breach #Offshore Banking #Oracle Flexcube #Resecurity #Seychelles Commercial Bank
Daily CyberSecurity
Seychelles Commercial Bank Hacked: Customer Data Compromised, Suspected Espionage Disguised as Cybercrime
Seychelles Commercial Bank (SCB) suffered a cyberattack exposing 1.4M+ customer PII, including government employee data. Resecurity suspects espionage, not just financial gain, given the low data sale price.
⤷ Title: TP-Link Archer C50 (EOL) Exposed: Hardcoded DES Key Allows Sensitive Config Decryption (CVE-2025-6982)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:22:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer C50 #cybersecurity #DES #encryption #end_of_life #EOL #Hardcoded Key #router #TP_Link #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:22:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer C50 #cybersecurity #DES #encryption #end_of_life #EOL #Hardcoded Key #router #TP_Link #Vulnerability
Daily CyberSecurity
TP-Link Archer C50 (EOL) Exposed: Hardcoded DES Key Allows Sensitive Config Decryption (CVE-2025-6982)
The EOL TP-Link Archer C50 router has a critical hardcoded DES key (CVE-2025-6982), allowing attackers to decrypt sensitive configuration files, including admin credentials and Wi-Fi passwords.
⤷ Title: 0bj3ctivityStealer: Stealthy Info-Stealer Uses Steganography & PowerShell to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:18:04 +0000
════════════════════════
⌗ Tags: #Malware #0bj3ctivityStealer #cybersecurity #data exfiltration #evasion #Infostealer #malware #phishing #powershell #steganography #Trellix
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:18:04 +0000
════════════════════════
⌗ Tags: #Malware #0bj3ctivityStealer #cybersecurity #data exfiltration #evasion #Infostealer #malware #phishing #powershell #steganography #Trellix
Daily CyberSecurity
0bj3ctivityStealer: Stealthy Info-Stealer Uses Steganography & PowerShell to Evade Detection
Trellix uncovers 0bj3ctivityStealer, a sophisticated info-stealer using phishing, custom PowerShell, and steganography to evade detection and exfiltrate sensitive data.
⤷ Title: BeyondTrust Privilege Management for Windows: Two High-Severity Flaws Allow Local Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:17:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BeyondTrust #cybersecurity #endpoint security #privilege escalation #Privilege Management for Windows #Registry Manipulation #Vulnerability #WMIC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:17:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BeyondTrust #cybersecurity #endpoint security #privilege escalation #Privilege Management for Windows #Registry Manipulation #Vulnerability #WMIC
Daily CyberSecurity
BeyondTrust Privilege Management for Windows: Two High-Severity Flaws Allow Local Privilege Escalation
BeyondTrust patches two high-severity LPE flaws (CVE-2025-2297, CVE-2025-6250) in Privilege Management for Windows, allowing local attackers to gain SYSTEM privileges via user profile manipulation and WMIC exploit.
⤷ Title: Raven Stealer: New MaaS Infostealer Plunders Data via Reflective Process Hollowing & Telegram Exfil
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Malware #C++ #cybersecurity #data exfiltration #Delphi #Infostealer #MaaS #Malware_as_a_Service #Process Hollowing #Raven Stealer #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:13:38 +0000
════════════════════════
⌗ Tags: #Malware #C++ #cybersecurity #data exfiltration #Delphi #Infostealer #MaaS #Malware_as_a_Service #Process Hollowing #Raven Stealer #Telegram
Daily CyberSecurity
Raven Stealer: New MaaS Infostealer Plunders Data via Reflective Process Hollowing & Telegram Exfil
A recent in-depth analysis from Cyfirma has shed light on the alarming capabilities of Raven Stealer, a lightweight yet powerful information-stealing malware rapidly gaining traction across the cy…
⤷ Title: ChatGPT Agent Bypasses Cloudflare Turnstile: AI Outsmarts “Human Verification” Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:10:23 +0000
════════════════════════
⌗ Tags: #Technology #AI agent #AI Capabilities #Anti_bot #Bypass #captcha #ChatGPT #Cloudflare Turnstile #cybersecurity #machine_learning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:10:23 +0000
════════════════════════
⌗ Tags: #Technology #AI agent #AI Capabilities #Anti_bot #Bypass #captcha #ChatGPT #Cloudflare Turnstile #cybersecurity #machine_learning
Daily CyberSecurity
ChatGPT Agent Bypasses Cloudflare Turnstile: AI Outsmarts “Human Verification” Systems
Cloudflare’s Turnstile CAPTCHA feature is designed to automate verification and reduce friction caused by traditional image selection or click-based challenges. In theory, this mechanism should se…
⤷ Title: SonicWall Alert: Critical SSL VPN Flaw (CVE-2025-40600) Allows Remote DoS Attack on Firewalls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:07:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_40600 #cybersecurity #Denial of Service #dos #firewall #SonicOS #SonicWall #SSL VPN #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:07:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_40600 #cybersecurity #Denial of Service #dos #firewall #SonicOS #SonicWall #SSL VPN #Vulnerability
Daily CyberSecurity
SonicWall Alert: Critical SSL VPN Flaw (CVE-2025-40600) Allows Remote DoS Attack on Firewalls
SonicWall discloses CVE-2025-40600, a critical format string vulnerability in SonicOS SSL VPN, allowing unauthenticated remote DoS attacks on Gen7 firewalls. Update to 7.3.0-7012 or later.
⤷ Title: Windows 11 Search Gets Visual: New Image Previews Arrive in Local Results
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:06:47 +0000
════════════════════════
⌗ Tags: #Windows #Image Search #Local Index #Search #Tech Update #User Experience #Visual Preview #Windows 11 #Windows Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 00:06:47 +0000
════════════════════════
⌗ Tags: #Windows #Image Search #Local Index #Search #Tech Update #User Experience #Visual Preview #Windows 11 #Windows Insider
Daily CyberSecurity
Windows 11 Search Gets Visual: New Image Previews Arrive in Local Results
Windows 11 Beta and Dev builds now show image search results with visual previews directly in the search box, based on local index data, for a more intuitive experience.