⤷ Title: GreenHorn HTB Walkthrough
════════════════════════
𐀪 Author: Isiaq Bolaji Ibrahim
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 20:34:09 GMT
════════════════════════
⌗ Tags: #htb #htb_writeup #hackthebox_walkthrough #hackthebox #hackthebox_writeup
════════════════════════
𐀪 Author: Isiaq Bolaji Ibrahim
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 20:34:09 GMT
════════════════════════
⌗ Tags: #htb #htb_writeup #hackthebox_walkthrough #hackthebox #hackthebox_writeup
Medium
GreenHorn HTB Walkthrough
Welcome to another Hack The Box walkthrough. The machine we are going to pwn is the GreenHorn machine. Today, we will look at how to pwn…
⤷ Title: ASC Cyber WarGames 2025 Qualifications — (Web)
════════════════════════
𐀪 Author: Abdelrahman Radwan
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 20:04:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #ctf_writeup #jwt #web_security
════════════════════════
𐀪 Author: Abdelrahman Radwan
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 20:04:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #ctf_writeup #jwt #web_security
Medium
ASC Cyber WarGames 2025 Qualifications — (Web)
بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ
⤷ Title: TOTP in the Clear: Proton Authenticator’s Privacy Misstep on iOS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:40:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ios #MFA #Plaintext Logs #Proton Authenticator #Secrets #TOTP #Update #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:40:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ios #MFA #Plaintext Logs #Proton Authenticator #Secrets #TOTP #Update #vulnerability
Penetration Testing Tools
TOTP in the Clear: Proton Authenticator’s Privacy Misstep on iOS
Proton Authenticator for iOS exposed TOTP secrets in plaintext logs, risking 2FA account leaks. A swift patch fixed it—but trust may take longer.
⤷ Title: Critical Command Injection Flaws in Trend Micro Apex One Actively Exploited
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:05:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_54948 #CVE_2025_54987 #cybersecurity #rce #Remote Code Execution #Trend Micro Apex One #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:05:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_54948 #CVE_2025_54987 #cybersecurity #rce #Remote Code Execution #Trend Micro Apex One #Vulnerability
Daily CyberSecurity
Critical Command Injection Flaws in Trend Micro Apex One Actively Exploited
Trend Micro warns of two critical RCE flaws (CVE-2025-54948, -54987) in Apex One (on-prem) actively exploited in the wild. A fix tool is available, but disables remote agent installs.
⤷ Title: How I Discovered a Critical OTP Rate Limiting Vulnerability on a Bug Bounty Program
════════════════════════
𐀪 Author: Lime
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 22:33:29 GMT
════════════════════════
⌗ Tags: #bug_bounty
════════════════════════
𐀪 Author: Lime
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 22:33:29 GMT
════════════════════════
⌗ Tags: #bug_bounty
Medium
How I Discovered a Critical OTP Rate Limiting Vulnerability on a Bug Bounty Program
I’m Lime, a bug bounty hunter and penetration tester. Today I’m sharing a critical vulnerability I discovered on a VDP (Vulnerability…
⤷ Title: Security Logging and Monitoring Failures (OWASP A09): Complete Hacking and Bug Bounty Guide
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:01:41 GMT
════════════════════════
⌗ Tags: #web_development #penetration_testing #ethical_hacking #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:01:41 GMT
════════════════════════
⌗ Tags: #web_development #penetration_testing #ethical_hacking #cybersecurity #bug_bounty
Medium
Security Logging and Monitoring Failures (OWASP A09): Complete Hacking and Bug Bounty Guide
Discover how the lack of logs and alerts facilitates attacks, allows for the erasure of traces, and conceals lateral movement.
⤷ Title: AI Security: What is MCP Security & Why It Matters Now?
════════════════════════
𐀪 Author: Rahul Bhichher
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:55:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #mcp_server #ai_security #model_context_protocol
════════════════════════
𐀪 Author: Rahul Bhichher
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:55:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #mcp_server #ai_security #model_context_protocol
Medium
AI Security: What is MCP Security & Why It Matters Now?
When I first heard about the Model Context Protocol, or MCP, it reminded me of the early days of APIs and cloud services.
⤷ Title: The Ashley Madison Break
════════════════════════
𐀪 Author: Marvion Criddle
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:55:33 GMT
════════════════════════
⌗ Tags: #hacking #short_story #business #dating #cybersecurity
════════════════════════
𐀪 Author: Marvion Criddle
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:55:33 GMT
════════════════════════
⌗ Tags: #hacking #short_story #business #dating #cybersecurity
Medium
The Ashley Madison Break
What Happens When Privacy Is a Sales Pitch, Not a Standard
⤷ Title: The “Layered Instinct” Method: Why Most Cybersecurity Strategies Fail Before the First Alert
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:48:03 GMT
════════════════════════
⌗ Tags: #writing #life #cybersecurity #education #life_lessons
════════════════════════
𐀪 Author: Ahmed Awad ( NullC0d3 )
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:48:03 GMT
════════════════════════
⌗ Tags: #writing #life #cybersecurity #education #life_lessons
Medium
The “Layered Instinct” Method: Why Most Cybersecurity Strategies Fail Before the First Alert
“You patched. You logged. You trained the users. So why did they still breach you?”
⤷ Title: New in the Loop with AI Pentesting
════════════════════════
𐀪 Author: Daniel Knight
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:34:01 GMT
════════════════════════
⌗ Tags: #pentesting #llm #cybersecurity
════════════════════════
𐀪 Author: Daniel Knight
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:34:01 GMT
════════════════════════
⌗ Tags: #pentesting #llm #cybersecurity
Medium
New in the Loop with AI Pentesting
To ensure safety at Vulnetic, there is a major feature we have pushed into the loop, which I will share here. I am hoping this becomes a…
⤷ Title: This One Network Mistake Could Let Hackers Spy on Everything You Do Online
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:17:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #networking #mitm #information_security
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:17:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #ai #networking #mitm #information_security
Medium
This One Network Mistake Could Let Hackers Spy on Everything You Do Online
Man-in-the-Middle Attacks: The Scariest Cyber Threat No One’s Talking About
⤷ Title: Hackviser — Roundcube ≤ 1.6.10
════════════════════════
𐀪 Author: Dogukan İSPİRLİ
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 22:47:18 GMT
════════════════════════
⌗ Tags: #ctf_writeup #vulnerability #cve_2025 #ctf_walkthrough #cybersecurity
════════════════════════
𐀪 Author: Dogukan İSPİRLİ
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 22:47:18 GMT
════════════════════════
⌗ Tags: #ctf_writeup #vulnerability #cve_2025 #ctf_walkthrough #cybersecurity
Medium
Hackviser — Roundcube ≤ 1.6.10
Hackviser platformuna giriş yaparak Laboratuvarlar bölümündeki Yaygın Güvenlik Açıkları bölümüne giriş yapıyoruz ve CVE-2025 olan bölüme…
⤷ Title: Dark Web Websites: What They Are and Why People Visit Them
════════════════════════
𐀪 Author: SafeAeon Inc.
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 22:16:31 GMT
════════════════════════
⌗ Tags: #cybersecurity #dark_web_link #darkwebsites
════════════════════════
𐀪 Author: SafeAeon Inc.
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 22:16:31 GMT
════════════════════════
⌗ Tags: #cybersecurity #dark_web_link #darkwebsites
Medium
Dark Web Websites: What They Are and Why People Visit Them
You’ve probably heard of the dark web a hidden part of the internet that doesn’t show up on Google. But what about dark web websites? Are…
⤷ Title: pamspy: Credentials Dumper for Linux using eBPF
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:38:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:38:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool
Penetration Testing Tools
pamspy: Credentials Dumper for Linux using eBPF
pamspy -- Credentials Dumper for Linux will track a particular userland function inside the PAM (Pluggable Authentication Modules) library
⤷ Title: evilgophish: Combination of evilginx2 and GoPhish
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:32:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #social engineering engagements
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:32:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #social engineering engagements
Penetration Testing Tools
evilgophish: Combination of evilginx2 and GoPhish
This is enticing to us to say the least, but when trying to use it for social engineering engagements, there are some issues off the bat
⤷ Title: Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #RCE #remote code execution #vulnerability #Wiz Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #RCE #remote code execution #vulnerability #Wiz Research
Penetration Testing Tools
Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
NVIDIA has patched multiple critical flaws (CVSS 9.8) in its Triton Inference Server. A vulnerability chain allows unauthenticated attackers to gain RCE and seize AI servers.
⤷ Title: CISA Adds Three D-Link Flaws to KEV Catalog: EOL IP Cameras Under Active Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:48:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #cybersecurity #D_Link #end_of_life #EOL #exploitation #IP Camera #network_security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:48:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #cybersecurity #D_Link #end_of_life #EOL #exploitation #IP Camera #network_security #Vulnerability
Daily CyberSecurity
CISA Adds Three D-Link Flaws to KEV Catalog: EOL IP Cameras Under Active Exploitation
CISA adds three D-Link vulnerabilities (CVE-2020-25078, -25079, -2022-40799) to its KEV Catalog, confirming active exploitation of EOL IP cameras.
⤷ Title: Critical RCE Flaw (CVE-2025-54594) in React Native Bottom Tabs’ GitHub Actions Exposed Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:35:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_54594 #GitHub Actions #rce #React Native Bottom Tabs #Remote Code Execution #Secrets Exfiltration #supply chain attack #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:35:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_54594 #GitHub Actions #rce #React Native Bottom Tabs #Remote Code Execution #Secrets Exfiltration #supply chain attack #Vulnerability
Daily CyberSecurity
Critical RCE Flaw (CVE-2025-54594) in React Native Bottom Tabs' GitHub Actions Exposed Secrets
A critical vulnerability (CVE-2025-54594, CVSS 9.1) in React Native Bottom Tabs’ GitHub Actions allowed RCE and secret exfiltration. The flaw was patched, and no packages were affected.
⤷ Title: From Bing Search to Ransomware in
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:31:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Akira #bing search #Bumblebee #Cybercrime #IT administrators #malware #ransomware #SEO Poisoning #The DFIR Report #Time_to_Ransom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:31:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Akira #bing search #Bumblebee #Cybercrime #IT administrators #malware #ransomware #SEO Poisoning #The DFIR Report #Time_to_Ransom
Daily CyberSecurity
From Bing Search to Ransomware in
The DFIR Report details a destructive attack: Bumblebee malware, delivered via SEO poisoning in Bing search results, led to a full Akira ransomware deployment in under 44 hours.
⤷ Title: Mustang Panda Backdoor Exposed: New ToneShell Malware Masquerades as Chrome to Spy on Gov’t & Military
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:28:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #backdoor #china #chrome #cyber_espionage #cybersecurity #DLL Sideloading #Mustang Panda #threat intelligence #ToneShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:28:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #backdoor #china #chrome #cyber_espionage #cybersecurity #DLL Sideloading #Mustang Panda #threat intelligence #ToneShell
Daily CyberSecurity
Mustang Panda Backdoor Exposed: New ToneShell Malware Masquerades as Chrome to Spy on Gov't & Military
Mustang Panda, a China-aligned APT, is using the ToneShell backdoor to target government and military sectors with phishing and DLL sideloading, masquerading as a legitimate Chrome component.
⤷ Title: Adobe AEM Forms Patch: Critical Flaws (CVE-2025-54253, CVSS 10.0) Allow RCE & Arbitrary File Read, Public PoCs Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:21:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe Experience Manager #AEM #AEM Forms #CVE_2025_54253 #CVE_2025_54254 #cybersecurity #rce #Remote Code Execution #Vulnerability #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:21:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe Experience Manager #AEM #AEM Forms #CVE_2025_54253 #CVE_2025_54254 #cybersecurity #rce #Remote Code Execution #Vulnerability #xxe
Daily CyberSecurity
Adobe AEM Forms Patch: Critical Flaws (CVE-2025-54253, CVSS 10.0) Allow RCE & Arbitrary File Read, Public PoCs Available
Adobe released urgent patches for two critical flaws (CVE-2025-54253, -54254) in AEM Forms on JEE, allowing unauthenticated RCE & file reads, with public PoCs available.