⤷ Title: A Critical Zero-Click WhatsApp Flaw, CVE-2025-55177, Was Exploited in Zero-Day Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 17:58:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #CVE_2025_43300 #CVE_2025_55177 #cybersecurity #rce #Vulnerability #WhatsApp #Zero_Click #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 17:58:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apple #CVE_2025_43300 #CVE_2025_55177 #cybersecurity #rce #Vulnerability #WhatsApp #Zero_Click #zero_day
Daily CyberSecurity
A Critical Zero-Click WhatsApp Flaw, CVE-2025-55177, Was Exploited in Zero-Day Attacks
A critical zero-click flaw in WhatsApp (CVE-2025-55177), paired with an Apple zero-day, was used in sophisticated attacks. All users must update now.
⤷ Title: Multi Flaws Found in HikCentral, Including a Bypass for Admin Access (CVE-2025-39247)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 09:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #CSV injection #CVSS #cybersecurity #HikCentral #Hikvision #privilege escalation #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 09:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #access control bypass #CSV injection #CVSS #cybersecurity #HikCentral #Hikvision #privilege escalation #Vulnerability
Daily CyberSecurity
Multi Flaws Found in HikCentral, Including a Bypass for Admin Access (CVE-2025-39247)
Hikvision has issued an advisory for three flaws in its HikCentral products. The most severe, with a CVSS of 8.6, allows an unauthenticated user to get admin access.
👍1
⤷ Title: PoC Published: A Format String Bug in ImageMagick Could Allow Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 08:12:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ImageMagick #open_source #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 08:12:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ImageMagick #open_source #rce #Remote Code Execution
Daily CyberSecurity
PoC Published: A Format String Bug in ImageMagick Could Allow Remote Code Execution
ImageMagick has a format string bug (CVE-2025-55298) that can lead to RCE. A PoC is public, and an urgent patch is available for versions 7.1.2-2 and 6.9.13-28.
⤷ Title: Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:58:49 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_GCM #AhnLab #Critical Infrastructure #Cybercrime #cybersecurity #Double Extortion #Interlock ransomware #ransomware
Daily CyberSecurity
Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
A new report from AhnLab reveals the Interlock ransomware group is actively attacking businesses and critical infrastructure in North America and Europe with a sophisticated encryption model.
⤷ Title: Beyond Scambaiting: YouTubers Help DOJ Bust a $65 Million Fraud Ring
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:49:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #Elder Fraud #Fraud Scheme #money laundering #scam #scambaiting #Scammer Payback #Trilogy Media #youtube
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 07:49:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #Elder Fraud #Fraud Scheme #money laundering #scam #scambaiting #Scammer Payback #Trilogy Media #youtube
Daily CyberSecurity
Beyond Scambaiting: YouTubers Help DOJ Bust a $65 Million Fraud Ring
The DOJ has indicted 28 members of a Chinese fraud ring for a $65M scheme targeting seniors. Evidence from YouTubers 'Scammer Payback' helped in the takedown.
⤷ Title: Google’s $9 Billion Bet: The New Investment Fueling AI in Virginia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:37:25 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cloud Computing #Data Center #google #investment #Virginia #workforce development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:37:25 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cloud Computing #Data Center #google #investment #Virginia #workforce development
Daily CyberSecurity
Google's $9 Billion Bet: The New Investment Fueling AI in Virginia
Google is investing $9 billion in Virginia by 2026 to expand its cloud and AI infrastructure. The plan includes a new data center and free AI access for college students.
⤷ Title: NVIDIA Refuses to Pay 15% China Revenue Share Without a Law
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:34:00 +0000
════════════════════════
⌗ Tags: #Technology #AI chip #china #Export Controls #geopolitics #nvidia #revenue sharing #US government
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:34:00 +0000
════════════════════════
⌗ Tags: #Technology #AI chip #china #Export Controls #geopolitics #nvidia #revenue sharing #US government
Daily CyberSecurity
NVIDIA Refuses to Pay 15% China Revenue Share Without a Law
NVIDIA's CFO has stated the company will not pay the U.S. government a 15% revenue share on China sales unless the agreement is formally codified into law.
⤷ Title: Cloud Gaming for Everyone: Xbox Opens Its Streaming Service to Game Pass Core and Standard
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:30:53 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Gaming #Game Pass Core #Game Pass Standard #gaming #Microsoft #Xbox Cloud Gaming #Xbox Game Pass #Xbox Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:30:53 +0000
════════════════════════
⌗ Tags: #Technology #Cloud Gaming #Game Pass Core #Game Pass Standard #gaming #Microsoft #Xbox Cloud Gaming #Xbox Game Pass #Xbox Insider
Daily CyberSecurity
Cloud Gaming for Everyone: Xbox Opens Its Streaming Service to Game Pass Core and Standard
Xbox Cloud Gaming is now being tested for Game Pass Core and Standard subscribers. The expansion brings the feature to a wider audience beyond the premium Ultimate tier.
⤷ Title: A New Race for Silicon: Apple Secures Half of TSMC’s 2nm Chip Production
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:20:23 +0000
════════════════════════
⌗ Tags: #Technology #2nm #A20 processor #Apple #chip production #iPhone 18 #Semiconductors #Supply Chain #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:20:23 +0000
════════════════════════
⌗ Tags: #Technology #2nm #A20 processor #Apple #chip production #iPhone 18 #Semiconductors #Supply Chain #TSMC
Daily CyberSecurity
A New Race for Silicon: Apple Secures Half of TSMC's 2nm Chip Production
Apple has reportedly secured nearly half of TSMC's 2nm chip production for the iPhone 18's A20 processor, a move that highlights the fierce competition for cutting-edge silicon.
⤷ Title: PoC Published: Critical Unauthenticated Command Injection Flaw in D-Link Routers (CVSS 9.8), No Patch!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:08:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #cybersecurity #D_Link #EOL #IoT security #router
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 03:08:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #cybersecurity #D_Link #EOL #IoT security #router
Daily CyberSecurity
PoC Published: Critical Unauthenticated Command Injection Flaw in D-Link Routers (CVSS 9.8), No Patch!
D-Link warns of a critical command injection flaw (CVSS 9.8) in its EOL DIR-series routers. A PoC is public, and since no patch is available, devices must be replaced.
⤷ Title: CRITICAL Zero-Day CVE-2025-57819 in FreePBX Is Under Active Attack (CVSS 10.0)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 02:16:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57819 #cybersecurity #FreePBX #rce #Remote Code Execution #Sangoma #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 02:16:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57819 #cybersecurity #FreePBX #rce #Remote Code Execution #Sangoma #Vulnerability #zero_day
Daily CyberSecurity
CRITICAL Zero-Day CVE-2025-57819 in FreePBX Is Under Active Attack (CVSS 10.0)
A critical zero-day (CVE-2025-57819) in FreePBX with a CVSS 10.0 score is being actively exploited. The flaw allows unauthenticated RCE, and admins must patch immediately.
⤷ Title: CVE-2025-50979: SQL Injection Flaw in NodeBB Forum Software, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_50979 #cybersecurity #Data Breach #forum software #NodeBB #open_source #sql injection #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:35:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_50979 #cybersecurity #Data Breach #forum software #NodeBB #open_source #sql injection #Vulnerability
Daily CyberSecurity
CVE-2025-50979: SQL Injection Flaw in NodeBB Forum Software, PoC Available
A critical SQL injection flaw (CVE-2025-50979) in NodeBB allows remote attackers to access sensitive data. Admins are urged to patch immediately.
⤷ Title: Is This a Rebrand? New Sinobi Ransomware Group Shows Code Overlap with Lynx
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:33:02 +0000
════════════════════════
⌗ Tags: #Malware #active directory #cybersecurity #eSentire #Hacking #lynx #ransomware #Ransomware_as_a_Service #Sinobi Group #SonicWall
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:33:02 +0000
════════════════════════
⌗ Tags: #Malware #active directory #cybersecurity #eSentire #Hacking #lynx #ransomware #Ransomware_as_a_Service #Sinobi Group #SonicWall
Daily CyberSecurity
Is This a Rebrand? New Sinobi Ransomware Group Shows Code Overlap with Lynx
A new report links Sinobi Group ransomware to Lynx, a potential rebrand. The group is using strong encryption and targeting compromised SonicWall VPN credentials to gain access.
⤷ Title: Anthropic Report: Criminals Are Weaponizing AI to Automate Cyberattacks at Scale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:30:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #AI misuse #Anthropic #Cybercrime #cybersecurity #Hacking #ransomware #Technology
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:30:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #AI misuse #Anthropic #Cybercrime #cybersecurity #Hacking #ransomware #Technology
Daily CyberSecurity
Anthropic Report: Criminals Are Weaponizing AI to Automate Cyberattacks at Scale
A new Anthropic report reveals how criminals are weaponizing AI systems to automate attacks, create AI-generated ransomware, and secure fraudulent employment.
⤷ Title: Malware-less Ransomware: How Storm-0501 is Pivoting to Cloud-Native Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:24:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #Cloud Security #cybersecurity #Entra ID #Hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:24:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #Cloud Security #cybersecurity #Entra ID #Hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
Daily CyberSecurity
Malware-less Ransomware: How Storm-0501 is Pivoting to Cloud-Native Attacks
A new Microsoft report reveals that the Storm-0501 threat actor is pivoting to cloud-native ransomware, using cloud tools to exfiltrate and destroy data without malware.
⤷ Title: A Deceptive AI Lure Is Hiding ScreenConnect & XWorm RAT to Hijack Your PC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #AI #cybersecurity #Hacking #malware #ScreenConnect #social engineering #Trustwave #XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:20:42 +0000
════════════════════════
⌗ Tags: #Malware #AI #cybersecurity #Hacking #malware #ScreenConnect #social engineering #Trustwave #XWorm RAT
Daily CyberSecurity
A Deceptive AI Lure Is Hiding ScreenConnect & XWorm RAT to Hijack Your PC
A new campaign is using fake AI-themed content to trick users into downloading a malicious ScreenConnect installer that secretly delivers the XWorm Remote Access Trojan.
⤷ Title: Cache Me If You Can (Sitecore Experience Platform Cache Poisoning to RCE)
════════════════════════
𐀪 Author: Piotr Bazydlo (@chudyPB)
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 10:00:41 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Piotr Bazydlo (@chudyPB)
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 10:00:41 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
Cache Me If You Can (Sitecore Experience Platform Cache Poisoning to RCE)
What is the main purpose of a Content Management System (CMS)?
We have to accept that when we ask such existential and philosophical questions, we’re also admitting that we have no idea and that there probably isn’t an easy answer (this is our excuse, and…
We have to accept that when we ask such existential and philosophical questions, we’re also admitting that we have no idea and that there probably isn’t an easy answer (this is our excuse, and…
⤷ Title: The One Where We Just Steal The Vulnerabilities (CrushFTP CVE-2025-54309)
════════════════════════
𐀪 Author: Sonny
════════════════════════
ⴵ Time: Wed, 27 Aug 2025 04:51:44 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Sonny
════════════════════════
ⴵ Time: Wed, 27 Aug 2025 04:51:44 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
The One Where We Just Steal The Vulnerabilities (CrushFTP CVE-2025-54309)
On July 18, 2025, users of CrushFTP woke up to an announcement:
As we’ve all experienced in 2025, 2025 has been the year of vendors burying their heads in the sand with regard to in-the-wild exploitation, even in the face of impressively indisputable evidence…
As we’ve all experienced in 2025, 2025 has been the year of vendors burying their heads in the sand with regard to in-the-wild exploitation, even in the face of impressively indisputable evidence…
⤷ Title: Commonly Abused Administrative Utilities: A Hidden Risk to Enterprise Security
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 27 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Dale Hobbs #General InfoSec Tips & Tricks #Informational #InfoSec 101 #CMD #PowerShell #RDP
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 27 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Dale Hobbs #General InfoSec Tips & Tricks #Informational #InfoSec 101 #CMD #PowerShell #RDP
Black Hills Information Security, Inc.
Commonly Abused Administrative Utilities: A Hidden Risk to Enterprise Security - Black Hills Information Security, Inc.
Organizations tend to focus a significant amount of their efforts on external threats, such as phishing and ransomware, but they often overlook one of the most dangerous attack vectors on their internal networks.
⤷ Title: Blind XSS via Clipboard Paste Handling: A Detailed Guide
════════════════════════
𐀪 Author: coffinxp
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 12:37:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #xss_attack #technology #penetration_testing
════════════════════════
𐀪 Author: coffinxp
════════════════════════
ⴵ Time: Mon, 25 Aug 2025 12:37:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #xss_attack #technology #penetration_testing
Medium
Blind XSS via Clipboard Paste Handling: A Detailed Guide
Discover how attackers abuse clipboard paste handling to trigger Blind XSS from setup to exploitation
⤷ Title: August CTF challenge: Exploiting SSRF via NextJS Middleware
════════════════════════
𐀪 Author: blackbird-eu
════════════════════════
ⴵ Time: Wed, 27 Aug 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Hacking Tools
════════════════════════
𐀪 Author: blackbird-eu
════════════════════════
ⴵ Time: Wed, 27 Aug 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Hacking Tools
Intigriti
August CTF Challenge: Exploiting SSRFs in Next.js Middleware
Learn how to solve Intigriti's 0825 CTF challenge by exploiting an SSRF in Next.js Middleware and leveraging it into a remote code execution. Read the article now!