⤷ Title: pamspy: Credentials Dumper for Linux using eBPF
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:38:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:38:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool
Penetration Testing Tools
pamspy: Credentials Dumper for Linux using eBPF
pamspy -- Credentials Dumper for Linux will track a particular userland function inside the PAM (Pluggable Authentication Modules) library
⤷ Title: evilgophish: Combination of evilginx2 and GoPhish
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:32:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #social engineering engagements
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:32:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #social engineering engagements
Penetration Testing Tools
evilgophish: Combination of evilginx2 and GoPhish
This is enticing to us to say the least, but when trying to use it for social engineering engagements, there are some issues off the bat
⤷ Title: Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #RCE #remote code execution #vulnerability #Wiz Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:12:17 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI #cybersecurity #Data Tampering #Inference Server #NVIDIA Triton #RCE #remote code execution #vulnerability #Wiz Research
Penetration Testing Tools
Triple Threat in Triton: Critical Flaws Expose AI Servers to Full Takeover
NVIDIA has patched multiple critical flaws (CVSS 9.8) in its Triton Inference Server. A vulnerability chain allows unauthenticated attackers to gain RCE and seize AI servers.
⤷ Title: CISA Adds Three D-Link Flaws to KEV Catalog: EOL IP Cameras Under Active Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:48:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #cybersecurity #D_Link #end_of_life #EOL #exploitation #IP Camera #network_security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:48:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA KEV #cybersecurity #D_Link #end_of_life #EOL #exploitation #IP Camera #network_security #Vulnerability
Daily CyberSecurity
CISA Adds Three D-Link Flaws to KEV Catalog: EOL IP Cameras Under Active Exploitation
CISA adds three D-Link vulnerabilities (CVE-2020-25078, -25079, -2022-40799) to its KEV Catalog, confirming active exploitation of EOL IP cameras.
⤷ Title: Critical RCE Flaw (CVE-2025-54594) in React Native Bottom Tabs’ GitHub Actions Exposed Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:35:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_54594 #GitHub Actions #rce #React Native Bottom Tabs #Remote Code Execution #Secrets Exfiltration #supply chain attack #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:35:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_54594 #GitHub Actions #rce #React Native Bottom Tabs #Remote Code Execution #Secrets Exfiltration #supply chain attack #Vulnerability
Daily CyberSecurity
Critical RCE Flaw (CVE-2025-54594) in React Native Bottom Tabs' GitHub Actions Exposed Secrets
A critical vulnerability (CVE-2025-54594, CVSS 9.1) in React Native Bottom Tabs’ GitHub Actions allowed RCE and secret exfiltration. The flaw was patched, and no packages were affected.
⤷ Title: From Bing Search to Ransomware in
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:31:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Akira #bing search #Bumblebee #Cybercrime #IT administrators #malware #ransomware #SEO Poisoning #The DFIR Report #Time_to_Ransom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:31:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Akira #bing search #Bumblebee #Cybercrime #IT administrators #malware #ransomware #SEO Poisoning #The DFIR Report #Time_to_Ransom
Daily CyberSecurity
From Bing Search to Ransomware in
The DFIR Report details a destructive attack: Bumblebee malware, delivered via SEO poisoning in Bing search results, led to a full Akira ransomware deployment in under 44 hours.
⤷ Title: Mustang Panda Backdoor Exposed: New ToneShell Malware Masquerades as Chrome to Spy on Gov’t & Military
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:28:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #backdoor #china #chrome #cyber_espionage #cybersecurity #DLL Sideloading #Mustang Panda #threat intelligence #ToneShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:28:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #backdoor #china #chrome #cyber_espionage #cybersecurity #DLL Sideloading #Mustang Panda #threat intelligence #ToneShell
Daily CyberSecurity
Mustang Panda Backdoor Exposed: New ToneShell Malware Masquerades as Chrome to Spy on Gov't & Military
Mustang Panda, a China-aligned APT, is using the ToneShell backdoor to target government and military sectors with phishing and DLL sideloading, masquerading as a legitimate Chrome component.
⤷ Title: Adobe AEM Forms Patch: Critical Flaws (CVE-2025-54253, CVSS 10.0) Allow RCE & Arbitrary File Read, Public PoCs Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:21:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe Experience Manager #AEM #AEM Forms #CVE_2025_54253 #CVE_2025_54254 #cybersecurity #rce #Remote Code Execution #Vulnerability #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:21:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe Experience Manager #AEM #AEM Forms #CVE_2025_54253 #CVE_2025_54254 #cybersecurity #rce #Remote Code Execution #Vulnerability #xxe
Daily CyberSecurity
Adobe AEM Forms Patch: Critical Flaws (CVE-2025-54253, CVSS 10.0) Allow RCE & Arbitrary File Read, Public PoCs Available
Adobe released urgent patches for two critical flaws (CVE-2025-54253, -54254) in AEM Forms on JEE, allowing unauthenticated RCE & file reads, with public PoCs available.
⤷ Title: The Fake Crypto Bot Scam: How Smart Contracts & AI Videos Are Stealing Millions on YouTube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:16:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Generated Video #Arbitrage Bot #crypto scam #cybersecurity #Ethereum #MEV Bot #Smart Contract #Solidity #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:16:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Generated Video #Arbitrage Bot #crypto scam #cybersecurity #Ethereum #MEV Bot #Smart Contract #Solidity #youtube
Daily CyberSecurity
The Fake Crypto Bot Scam: How Smart Contracts & AI Videos Are Stealing Millions on YouTube
SentinelLABS exposes a crypto scam using AI-generated YouTube videos to trick users into deploying malicious smart contracts, siphoning off hundreds of thousands in ETH.
⤷ Title: Critical HFS 2.x Flaw (CVE-2024-23692) Actively Exploited: Legacy File Server Becomes a Ransomware Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:11:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #HFS #Imperva #ransomware #rce #Rejetto HTTP File Server #ssti #Trojan #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:11:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #HFS #Imperva #ransomware #rce #Rejetto HTTP File Server #ssti #Trojan #Vulnerability
Daily CyberSecurity
Critical HFS 2.x Flaw (CVE-2024-23692) Actively Exploited: Legacy File Server Becomes a Ransomware Backdoor
A critical server-side template injection flaw (CVE-2024-23692) in Rejetto HFS 2.x is actively exploited to deploy ransomware and trojans at scale. Update or retire the service immediately.
⤷ Title: High-Severity Flaws in Rockwell Arena Simulation Expose Industrial Systems to Memory Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:06:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arena Simulation #CVE_2025_7025 #CVE_2025_7032 #CVE_2025_7033 #Manufacturing #Memory Abuse #rce #Remote Code Execution #Rockwell Automation #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:06:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arena Simulation #CVE_2025_7025 #CVE_2025_7032 #CVE_2025_7033 #Manufacturing #Memory Abuse #rce #Remote Code Execution #Rockwell Automation #Vulnerability
Daily CyberSecurity
High-Severity Flaws in Rockwell Arena Simulation Expose Industrial Systems to Memory Abuse
Rockwell Automation's Arena Simulation software has three high-severity memory abuse flaws that could allow RCE or data leaks when opening a crafted file. Update immediately.
⤷ Title: The AI Phishing Trap: Zscaler Exposes Fake Brazilian Government Websites Generated by AI to Steal Payments
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:01:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #BlackBox AI #Brazil #cybersecurity #DeepSite AI #phishing #Pix #SEO Poisoning #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:01:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #BlackBox AI #Brazil #cybersecurity #DeepSite AI #phishing #Pix #SEO Poisoning #Zscaler ThreatLabz
Daily CyberSecurity
The AI Phishing Trap: Zscaler Exposes Fake Brazilian Government Websites Generated by AI to Steal Payments
Zscaler reveals an AI-powered phishing campaign targeting Brazilian users. DeepSite AI and BlackBox AI generated fake government websites to steal Pix payments and personal data.
⤷ Title: JavaScript Protocol and XSS: Modern Defence Strategies
════════════════════════
𐀪 Author: Deep Singh
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:54:47 GMT
════════════════════════
⌗ Tags: #application_security #javascript
════════════════════════
𐀪 Author: Deep Singh
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 23:54:47 GMT
════════════════════════
⌗ Tags: #application_security #javascript
Medium
JavaScript Protocol and XSS: Modern Defence Strategies
Cross-site scripting (XSS) vulnerabilities remain the topmost dangerous software weakness of 2024.
⤷ Title: The Ashley Madison Break
════════════════════════
𐀪 Author: Marvion Criddle
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:57:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #business #short_story #dating
════════════════════════
𐀪 Author: Marvion Criddle
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:57:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #business #short_story #dating
Medium
The Ashley Madison Break
What Happens When Privacy Is a Sales Pitch, Not a Standard
⤷ Title: How Scrum Corrupted the Agile Revolution: The Tools of Looters in Tech
════════════════════════
𐀪 Author: Leandro Costa de Oliveira
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:19:40 GMT
════════════════════════
⌗ Tags: #software_development #scrum #agile_methodology #agile #hacking
════════════════════════
𐀪 Author: Leandro Costa de Oliveira
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:19:40 GMT
════════════════════════
⌗ Tags: #software_development #scrum #agile_methodology #agile #hacking
Medium
How Scrum Corrupted the Agile Revolution: The Tools of Looters in Tech
The Agile Manifesto was born as a revolution. In 2001, a group of software professionals came together to challenge the outdated project…
⤷ Title: Passive Reconnaissance: TryHackMe
════════════════════════
𐀪 Author: ShadowPacketRHR
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:18:07 GMT
════════════════════════
⌗ Tags: #passive_reconnaissance #tryhackme #penetration_testing #tryhackme_walkthrough #cybersecurity
════════════════════════
𐀪 Author: ShadowPacketRHR
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:18:07 GMT
════════════════════════
⌗ Tags: #passive_reconnaissance #tryhackme #penetration_testing #tryhackme_walkthrough #cybersecurity
Medium
Passive Reconnaissance: TryHackMe
ShadowPacketRHR
⤷ Title: The Cyber Kill Chain Behind the PXA Stealer Attacks
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:17:17 GMT
════════════════════════
⌗ Tags: #passwords #cybersecurity #information_security #malware #ai
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:17:17 GMT
════════════════════════
⌗ Tags: #passwords #cybersecurity #information_security #malware #ai
Medium
The Cyber Kill Chain Behind the PXA Stealer Attacks
An engaging breakdown of how a stealthy Vietnamese threat group pulled off a global browser heist
⤷ Title: The Browser Is the New Battleground in Cybersecurity
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:10:04 GMT
════════════════════════
⌗ Tags: #google #cybersecurity #browsers #information_security #ai
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:10:04 GMT
════════════════════════
⌗ Tags: #google #cybersecurity #browsers #information_security #ai
Medium
The Browser Is the New Battleground in Cybersecurity
Imagine this: you’re sitting at your desk, coffee in hand, opening up your browser to start the workday. You check your email, log into…
⤷ Title: Gaining Control: How I Learned to Hack Telnet on TryHackMe
════════════════════════
𐀪 Author: JEONGYU NOH
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:33:37 GMT
════════════════════════
⌗ Tags: #network_security #beginner_cybersecurity #tryhackme #cybersecurity #telnet
════════════════════════
𐀪 Author: JEONGYU NOH
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:33:37 GMT
════════════════════════
⌗ Tags: #network_security #beginner_cybersecurity #tryhackme #cybersecurity #telnet
Medium
🎮 Gaining Control: How I Learned to Hack Telnet on TryHackMe
1. 🤔 What Is Telnet and Why Should I Care?
⤷ Title: Automation vs. Accountability: Vibe Coding and the Tea Breach
════════════════════════
𐀪 Author: Eric Vanderburg
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:21:32 GMT
════════════════════════
⌗ Tags: #data_breach #cybersecurity #vibe_coding #vulnerability #ai
════════════════════════
𐀪 Author: Eric Vanderburg
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 00:21:32 GMT
════════════════════════
⌗ Tags: #data_breach #cybersecurity #vibe_coding #vulnerability #ai
Medium
Automation vs. Accountability: Vibe Coding and the Tea Breach
AI wrote the code. Hackers wrote the consequences. That’s the grim reality many organizations are now facing as they rush to embrace…
⤷ Title: Brain Drain in Pakistan: Why Our Best Minds Leave — And How We Can Bring Them Back
════════════════════════
𐀪 Author: Inayat Hussain
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:56:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Inayat Hussain
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 01:56:42 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #ethical_hacking
Medium
🧠 Brain Drain in Pakistan: Why OBest Minds Leave — And How We Can Bring Them Back
By Inayat Hussain Chohan Polymath | Ethical Hacker | Urdu Poet | Building Pakistan’s Future Tech Ecosystem | Founder of Startup Scale →…