⤷ Title: Data Theft Alert: Salesforce Instances Breached via Third-Party App OAuth Tokens
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 07:39:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AWS keys #cybercrime #cybersecurity #Data Theft #OAuth #Salesforce #Salesloft #UNC6395
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 07:39:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AWS keys #cybercrime #cybersecurity #Data Theft #OAuth #Salesforce #Salesloft #UNC6395
Penetration Testing Tools
Data Theft Alert: Salesforce Instances Breached via Third-Party App OAuth Tokens
A new report reveals a widespread data theft campaign targeting Salesforce instances. Attackers used compromised OAuth tokens from a third-party app to steal data and credentials.
⤷ Title: ShadowCaptcha: A New Malware Campaign Uses Fake CAPTCHAs to Steal Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 07:35:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #cybersecurity #Israel #malware #phishing #ransomware #ShadowCaptcha #Social Engineering #WordPress
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 07:35:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #cybersecurity #Israel #malware #phishing #ransomware #ShadowCaptcha #Social Engineering #WordPress
Penetration Testing Tools
ShadowCaptcha: A New Malware Campaign Uses Fake CAPTCHAs to Steal Data
A new report reveals the ShadowCaptcha campaign, which uses fake CAPTCHA pages and the ClickFix technique to trick users into installing ransomware and infostealers.
⤷ Title: A Deceptive Ad on Facebook Is Spreading Advanced Android Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 00:11:47 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Bitdefender #Brokewell #Crypto theft #cybersecurity #facebook #Malvertising #rat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 00:11:47 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Bitdefender #Brokewell #Crypto theft #cybersecurity #facebook #Malvertising #rat
Daily CyberSecurity
A Deceptive Ad on Facebook Is Spreading Advanced Android Malware
A new report reveals a global malvertising campaign on Facebook spreading an evolved version of Brokewell malware to steal crypto and bypass 2FA.
⤷ Title: BadSuccessor (CVE-2025-53779) Technique Persists Despite Microsoft Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 00:05:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #Akamai #BadSuccessor #CVE_2025_53779 #Domain Admin #privilege escalation #Vulnerability #Windows Server 2025
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 00:05:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #Akamai #BadSuccessor #CVE_2025_53779 #Domain Admin #privilege escalation #Vulnerability #Windows Server 2025
Daily CyberSecurity
BadSuccessor (CVE-2025-53779) Technique Persists Despite Microsoft Patch
A new Active Directory flaw, BadSuccessor, allows low-privileged users to become Domain Admins. Akamai researchers warn that the technique remains a threat even after patching.
⤷ Title: MystRodX: A Stealthy New Backdoor Found Hiding in Networks for Over 20 Months
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 00:00:58 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #DNS tunneling #icmp #malware #Mirai #MystRodX #stealthy #XLab
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 Aug 2025 00:00:58 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #DNS tunneling #icmp #malware #Mirai #MystRodX #stealthy #XLab
Daily CyberSecurity
MystRodX: A Stealthy New Backdoor Found Hiding in Networks for Over 20 Months
A new report reveals MystRodX, a stealthy backdoor that uses passive wake-up triggers and multi-layer encryption to operate undetected in networks for months.
⤷ Title: QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 18:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52856 #CVE_2025_52861 #cybersecurity #improper authentication #NVR #Path Traversal #QNAP #QVR #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 18:15:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_52856 #CVE_2025_52861 #cybersecurity #improper authentication #NVR #Path Traversal #QNAP #QVR #Vulnerability
Daily CyberSecurity
QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3
QNAP has patched a critical improper authentication flaw (CVE-2025-52856) in its QVR firmware with a CVSS score of 9.3, allowing remote attackers to bypass security.
⤷ Title: A Critical Zero-Click WhatsApp Flaw, CVE-2025-55177, Was Exploited in Zero-Day Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 17:58:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #CVE_2025_43300 #CVE_2025_55177 #cybersecurity #rce #Vulnerability #WhatsApp #Zero_Click #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 17:58:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #CVE_2025_43300 #CVE_2025_55177 #cybersecurity #rce #Vulnerability #WhatsApp #Zero_Click #zero_day
Daily CyberSecurity
A Critical Zero-Click WhatsApp Flaw, CVE-2025-55177, Was Exploited in Zero-Day Attacks
A critical zero-click flaw in WhatsApp (CVE-2025-55177), paired with an Apple zero-day, was used in sophisticated attacks. All users must update now.
⤷ Title: Multi Flaws Found in HikCentral, Including a Bypass for Admin Access (CVE-2025-39247)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 09:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #CSV injection #CVSS #cybersecurity #HikCentral #Hikvision #privilege escalation #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 09:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #CSV injection #CVSS #cybersecurity #HikCentral #Hikvision #privilege escalation #Vulnerability
Daily CyberSecurity
Multi Flaws Found in HikCentral, Including a Bypass for Admin Access (CVE-2025-39247)
Hikvision has issued an advisory for three flaws in its HikCentral products. The most severe, with a CVSS of 8.6, allows an unauthenticated user to get admin access.
👍1
⤷ Title: PoC Published: A Format String Bug in ImageMagick Could Allow Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 08:12:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ImageMagick #open_source #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 08:12:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ImageMagick #open_source #rce #Remote Code Execution
Daily CyberSecurity
PoC Published: A Format String Bug in ImageMagick Could Allow Remote Code Execution
ImageMagick has a format string bug (CVE-2025-55298) that can lead to RCE. A PoC is public, and an urgent patch is available for versions 7.1.2-2 and 6.9.13-28.
⤷ Title: Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
Daily CyberSecurity
Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
A new report from AhnLab reveals the Interlock ransomware group is actively attacking businesses and critical infrastructure in North America and Europe with a sophisticated encryption model.
⤷ Title: Beyond Scambaiting: YouTubers Help DOJ Bust a $65 Million Fraud Ring
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:49:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #Elder Fraud #Fraud Scheme #money laundering #scam #scambaiting #Scammer Payback #Trilogy Media #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:49:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #Elder Fraud #Fraud Scheme #money laundering #scam #scambaiting #Scammer Payback #Trilogy Media #youtube
Daily CyberSecurity
Beyond Scambaiting: YouTubers Help DOJ Bust a $65 Million Fraud Ring
The DOJ has indicted 28 members of a Chinese fraud ring for a $65M scheme targeting seniors. Evidence from YouTubers 'Scammer Payback' helped in the takedown.
⤷ Title: Google’s $9 Billion Bet: The New Investment Fueling AI in Virginia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:37:25 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cloud Computing #Data Center #google #investment #Virginia #workforce development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:37:25 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cloud Computing #Data Center #google #investment #Virginia #workforce development
Daily CyberSecurity
Google's $9 Billion Bet: The New Investment Fueling AI in Virginia
Google is investing $9 billion in Virginia by 2026 to expand its cloud and AI infrastructure. The plan includes a new data center and free AI access for college students.
⤷ Title: NVIDIA Refuses to Pay 15% China Revenue Share Without a Law
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:34:00 +0000
════════════════════════
⌗ Tags: #Technology #AI chip #china #Export Controls #geopolitics #nvidia #revenue sharing #US government
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:34:00 +0000
════════════════════════
⌗ Tags: #Technology #AI chip #china #Export Controls #geopolitics #nvidia #revenue sharing #US government
Daily CyberSecurity
NVIDIA Refuses to Pay 15% China Revenue Share Without a Law
NVIDIA's CFO has stated the company will not pay the U.S. government a 15% revenue share on China sales unless the agreement is formally codified into law.
⤷ Title: Cloud Gaming for Everyone: Xbox Opens Its Streaming Service to Game Pass Core and Standard
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:30:53 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Gaming #Game Pass Core #Game Pass Standard #gaming #Microsoft #Xbox Cloud Gaming #Xbox Game Pass #Xbox Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:30:53 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Gaming #Game Pass Core #Game Pass Standard #gaming #Microsoft #Xbox Cloud Gaming #Xbox Game Pass #Xbox Insider
Daily CyberSecurity
Cloud Gaming for Everyone: Xbox Opens Its Streaming Service to Game Pass Core and Standard
Xbox Cloud Gaming is now being tested for Game Pass Core and Standard subscribers. The expansion brings the feature to a wider audience beyond the premium Ultimate tier.
⤷ Title: A New Race for Silicon: Apple Secures Half of TSMC’s 2nm Chip Production
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:20:23 +0000
════════════════════════
⌗ Tags: #Technology #2nm #A20 processor #Apple #chip production #iPhone 18 #Semiconductors #Supply Chain #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:20:23 +0000
════════════════════════
⌗ Tags: #Technology #2nm #A20 processor #Apple #chip production #iPhone 18 #Semiconductors #Supply Chain #TSMC
Daily CyberSecurity
A New Race for Silicon: Apple Secures Half of TSMC's 2nm Chip Production
Apple has reportedly secured nearly half of TSMC's 2nm chip production for the iPhone 18's A20 processor, a move that highlights the fierce competition for cutting-edge silicon.
⤷ Title: PoC Published: Critical Unauthenticated Command Injection Flaw in D-Link Routers (CVSS 9.8), No Patch!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:08:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #cybersecurity #D_Link #EOL #IoT security #router
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:08:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #cybersecurity #D_Link #EOL #IoT security #router
Daily CyberSecurity
PoC Published: Critical Unauthenticated Command Injection Flaw in D-Link Routers (CVSS 9.8), No Patch!
D-Link warns of a critical command injection flaw (CVSS 9.8) in its EOL DIR-series routers. A PoC is public, and since no patch is available, devices must be replaced.
⤷ Title: CRITICAL Zero-Day CVE-2025-57819 in FreePBX Is Under Active Attack (CVSS 10.0)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 02:16:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57819 #cybersecurity #FreePBX #rce #Remote Code Execution #Sangoma #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 02:16:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57819 #cybersecurity #FreePBX #rce #Remote Code Execution #Sangoma #Vulnerability #zero_day
Daily CyberSecurity
CRITICAL Zero-Day CVE-2025-57819 in FreePBX Is Under Active Attack (CVSS 10.0)
A critical zero-day (CVE-2025-57819) in FreePBX with a CVSS 10.0 score is being actively exploited. The flaw allows unauthenticated RCE, and admins must patch immediately.
⤷ Title: CVE-2025-50979: SQL Injection Flaw in NodeBB Forum Software, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_50979 #cybersecurity #Data Breach #forum software #NodeBB #open_source #sql injection #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_50979 #cybersecurity #Data Breach #forum software #NodeBB #open_source #sql injection #Vulnerability
Daily CyberSecurity
CVE-2025-50979: SQL Injection Flaw in NodeBB Forum Software, PoC Available
A critical SQL injection flaw (CVE-2025-50979) in NodeBB allows remote attackers to access sensitive data. Admins are urged to patch immediately.
⤷ Title: Is This a Rebrand? New Sinobi Ransomware Group Shows Code Overlap with Lynx
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:33:02 +0000
════════════════════════
⌗ Tags: #Malware #active directory #cybersecurity #eSentire #Hacking #lynx #ransomware #Ransomware_as_a_Service #Sinobi Group #SonicWall
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:33:02 +0000
════════════════════════
⌗ Tags: #Malware #active directory #cybersecurity #eSentire #Hacking #lynx #ransomware #Ransomware_as_a_Service #Sinobi Group #SonicWall
Daily CyberSecurity
Is This a Rebrand? New Sinobi Ransomware Group Shows Code Overlap with Lynx
A new report links Sinobi Group ransomware to Lynx, a potential rebrand. The group is using strong encryption and targeting compromised SonicWall VPN credentials to gain access.
⤷ Title: Anthropic Report: Criminals Are Weaponizing AI to Automate Cyberattacks at Scale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:30:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #AI misuse #Anthropic #Cybercrime #cybersecurity #Hacking #ransomware #Technology
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:30:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #AI misuse #Anthropic #Cybercrime #cybersecurity #Hacking #ransomware #Technology
Daily CyberSecurity
Anthropic Report: Criminals Are Weaponizing AI to Automate Cyberattacks at Scale
A new Anthropic report reveals how criminals are weaponizing AI systems to automate attacks, create AI-generated ransomware, and secure fraudulent employment.
⤷ Title: Malware-less Ransomware: How Storm-0501 is Pivoting to Cloud-Native Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:24:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #Cloud Security #cybersecurity #Entra ID #Hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:24:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #Cloud Security #cybersecurity #Entra ID #Hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
Daily CyberSecurity
Malware-less Ransomware: How Storm-0501 is Pivoting to Cloud-Native Attacks
A new Microsoft report reveals that the Storm-0501 threat actor is pivoting to cloud-native ransomware, using cloud tools to exfiltrate and destroy data without malware.