⤷ Title: THM Cyber Kill Chain — WALKTHROUGH
════════════════════════
𐀪 Author: Kagiso Makubjana
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:27:21 GMT
════════════════════════
⌗ Tags: #soc_1_certification #tryhackme_walkthrough #tryhackme
════════════════════════
𐀪 Author: Kagiso Makubjana
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:27:21 GMT
════════════════════════
⌗ Tags: #soc_1_certification #tryhackme_walkthrough #tryhackme
Medium
THM Cyber Kill Chain — WALKTHROUGH
Task 1 Introduction
⤷ Title: CVE-2024-52284: SUSE Fleet Vulnerability Exposes Sensitive Helm Values in Plain Text
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 03:04:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2024_52284 #cybersecurity #Fleet #GitOps #Kubernetes #Rancher #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 03:04:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2024_52284 #cybersecurity #Fleet #GitOps #Kubernetes #Rancher #Vulnerability
Daily CyberSecurity
CVE-2024-52284: SUSE Fleet Vulnerability Exposes Sensitive Helm Values in Plain Text
A new high-severity vulnerability in SUSE Rancher's Fleet engine (CVE-2024-52284) exposes sensitive Helm chart credentials in plain text.
⤷ Title: CVE-2025-57803: Critical Flaw in ImageMagick Could Lead to Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:43:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57803 #cybersecurity #heap corruption #ImageMagick #Remote Code Execution #security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:43:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_57803 #cybersecurity #heap corruption #ImageMagick #Remote Code Execution #security #Vulnerability
Daily CyberSecurity
CVE-2025-57803: Critical Flaw in ImageMagick Could Lead to Remote Code Execution
A critical vulnerability in ImageMagick's BMP encoder (CVE-2025-57803) could allow remote code execution. Update your 32-bit builds immediately.
⤷ Title: South Korea Fines SK Telecom $96.5M Over Massive Data Breach
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:14:36 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity #Data Breach #Fine #privacy #SK Telecom #south korea #Telecommunications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:14:36 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity #Data Breach #Fine #privacy #SK Telecom #south korea #Telecommunications
Daily CyberSecurity
South Korea Fines SK Telecom $96.5M Over Massive Data Breach
SK Telecom was fined a record-breaking $96.5 million after a massive data breach exposed the personal data of 27 million users.
⤷ Title: Elon Musk’s xAI Sues Ex-Engineer Over Stolen Grok AI Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:09:53 +0000
════════════════════════
⌗ Tags: #Data Leak #AI #cybersecurity #Elon Musk #Grok #Lawsuit #OpenAI #trade secret #xAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:09:53 +0000
════════════════════════
⌗ Tags: #Data Leak #AI #cybersecurity #Elon Musk #Grok #Lawsuit #OpenAI #trade secret #xAI
Daily CyberSecurity
Elon Musk's xAI Sues Ex-Engineer Over Stolen Grok AI Secrets
xAI is suing a former engineer for allegedly stealing its AI chatbot's codebase and trade secrets before joining OpenAI. The company claims the secrets are worth billions.
⤷ Title: Is Gmail’s Spam Filter Politically Biased? The FTC Investigates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:04:53 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #FTC #gmail #google #political bias #spam filter #Tech Regulation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:04:53 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #FTC #gmail #google #political bias #spam filter #Tech Regulation
Daily CyberSecurity
Is Gmail's Spam Filter Politically Biased? The FTC Investigates
The FTC is investigating whether Gmail's spam filters unfairly target Republican emails. This isn't the first time the company has faced such accusations.
⤷ Title: Microsoft Urges OEMs to Fix Windows 11 USB-C Problems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:00:22 +0000
════════════════════════
⌗ Tags: #Windows #hardware #Microsoft #OEM #Tech News #Technology #USB_C #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 02:00:22 +0000
════════════════════════
⌗ Tags: #Windows #hardware #Microsoft #OEM #Tech News #Technology #USB_C #Windows 11
Daily CyberSecurity
Microsoft Urges OEMs to Fix Windows 11 USB-C Problems
Microsoft is urging PC makers to properly implement USB-C support in Windows 11. Learn why your notifications may not be working and how OEMs can fix it.
⤷ Title: Grok’s New Code Model Is Here to Revolutionize Development
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 01:55:01 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #Developer Tools #Grok #machine_learning #Python #Rust #xAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 01:55:01 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #Developer Tools #Grok #machine_learning #Python #Rust #xAI
Daily CyberSecurity
Grok's New Code Model Is Here to Revolutionize Development
xAI has launched grok-code-fast-1, a new AI coding model optimized for speed and efficiency. Learn how it plans to challenge Microsoft and OpenAI.
⤷ Title: Another Ryzen 9000 CPU Burnout: What’s Really Going On?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 01:51:26 +0000
════════════════════════
⌗ Tags: #Technology #AMD #CPU #GMP #hardware failure #processor #Ryzen #Tech News
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 01:51:26 +0000
════════════════════════
⌗ Tags: #Technology #AMD #CPU #GMP #hardware failure #processor #Ryzen #Tech News
Daily CyberSecurity
Another Ryzen 9000 CPU Burnout: What's Really Going On?
A new report from a specialized developer reveals two Ryzen 9950X CPUs have failed under extreme computational load, sparking a new AMD investigation.
⤷ Title: Why Meta Is Turning to Its Rivals to Win the AI Race
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 01:45:41 +0000
════════════════════════
⌗ Tags: #Technology #AI Strategy #big tech #Generative AI #Google Gemini #Llama #Meta AI #OpenAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 01:45:41 +0000
════════════════════════
⌗ Tags: #Technology #AI Strategy #big tech #Generative AI #Google Gemini #Llama #Meta AI #OpenAI
Daily CyberSecurity
Why Meta Is Turning to Its Rivals to Win the AI Race
Meta is exploring a temporary partnership with rivals like Google and OpenAI to power its AI chatbot, a move that signals a new 'all-of-the-above' strategy.
⤷ Title: Malicious npm Package Masquerades as Nodemailer, Drains Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:41:02 +0000
════════════════════════
⌗ Tags: #Malware #Atomic Wallet #crypto drainer #cybersecurity #Developer Tools #nodejs_smtp #nodemailer #npm #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:41:02 +0000
════════════════════════
⌗ Tags: #Malware #Atomic Wallet #crypto drainer #cybersecurity #Developer Tools #nodejs_smtp #nodemailer #npm #supply chain attack
Daily CyberSecurity
Malicious npm Package Masquerades as Nodemailer, Drains Crypto Wallets
A malicious npm package impersonates the popular nodemailer library to inject code into crypto wallets on developers' PCs and steal funds from outgoing transactions.
⤷ Title: Beyond Defense: New Report Exposes How Russian Cyber Firms Aid the Kremlin’s War
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:39:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #CNA #Cyber Warfare #cybersecurity #kaspersky #Kremlin #national security #Positive Technologies #russia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:39:05 +0000
════════════════════════
⌗ Tags: #Cyber Security #CNA #Cyber Warfare #cybersecurity #kaspersky #Kremlin #national security #Positive Technologies #russia
Daily CyberSecurity
Beyond Defense: New Report Exposes How Russian Cyber Firms Aid the Kremlin's War
A new CNA report reveals how private Russian cybersecurity firms, including Kaspersky and Positive Technologies, are deeply entwined with the Kremlin's cyber operations.
⤷ Title: CVE-2025-8077 (CVSS 9.8): CRITICAL Flaw in NeuVector Exposes Kubernetes Clusters to Full Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:33:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container security #CVSS 9.8 #cybersecurity #Kubernetes #NeuVector #open_source #SUSE #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:33:44 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container security #CVSS 9.8 #cybersecurity #Kubernetes #NeuVector #open_source #SUSE #Vulnerability
Daily CyberSecurity
CVE-2025-8077 (CVSS 9.8): CRITICAL Flaw in NeuVector Exposes Kubernetes Clusters to Full Takeover
A critical flaw in NeuVector (CVE-2025-8077) allows attackers to bypass authentication with a hardcoded password, exposing Kubernetes clusters to full compromise.
⤷ Title: Deepfakes and Deception: North Korean IT Workers Infiltrating Companies to Fund Regime
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:31:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Deepfakes #Fraud #hiring scams #Lazarus Group #North Korean IT workers #Remote Work #Sanctions Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:31:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Deepfakes #Fraud #hiring scams #Lazarus Group #North Korean IT workers #Remote Work #Sanctions Evasion
Daily CyberSecurity
Deepfakes and Deception: North Korean IT Workers Infiltrating Companies to Fund Regime
North Korean IT workers are using deepfakes and fake identities to secure remote jobs, funding their regime’s weapons programs while posing a major security threat.
⤷ Title: Unraveling a Phishing Spree That Abuses Email Marketing and Cloud Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:28:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cloud services #Credential Theft #cybersecurity #Malvertising #phishing #social engineering #Trustwave #URL redirectors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:28:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cloud services #Credential Theft #cybersecurity #Malvertising #phishing #social engineering #Trustwave #URL redirectors
Daily CyberSecurity
Unraveling a Phishing Spree That Abuses Email Marketing and Cloud Services
A new report reveals a rise in phishing campaigns that abuse email marketing platforms and cloud services to evade detection and steal credentials from victims.
⤷ Title: CVE-2024-58259: DoS Flaw in Rancher Manager Allows Unauthenticated Attackers to Crash Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:23:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Container Management #CVE_2024_58259 #cybersecurity #Denial of Service #dos #Rancher #SUSE #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:23:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Container Management #CVE_2024_58259 #cybersecurity #Denial of Service #dos #Rancher #SUSE #Vulnerability
Daily CyberSecurity
CVE-2024-58259: DoS Flaw in Rancher Manager Allows Unauthenticated Attackers to Crash Servers
A high-severity DoS flaw (CVE-2024-58259) in Rancher Manager allows attackers to crash servers by sending oversized API requests. Admins are urged to patch immediately.
⤷ Title: TAOTH Campaign: Hijacked Software Updates Are Spreading Malware Across Asia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #cybersecurity #malware #phishing #Sogou Zhuyin #supply chain attack #TAOTH #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyber_espionage #cybersecurity #malware #phishing #Sogou Zhuyin #supply chain attack #TAOTH #Trend Micro
Daily CyberSecurity
TAOTH Campaign: Hijacked Software Updates Are Spreading Malware Across Asia
A new report reveals the TAOTH cyber-espionage campaign, which hijacks software updates and uses spear-phishing to deliver malware to high-value targets in Asia.
⤷ Title: Fraudulent Scholarship Apps: A New Malware Campaign Targets Students in Bangladesh
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:15:38 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Bangladesh #Cyble #financial fraud #mobile security #phishing #SikkahBot #smishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:15:38 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Bangladesh #Cyble #financial fraud #mobile security #phishing #SikkahBot #smishing
Daily CyberSecurity
Fraudulent Scholarship Apps: A New Malware Campaign Targets Students in Bangladesh
SikkahBot, a new Android malware, is impersonating scholarship apps to steal financial data and automate transactions from students in Bangladesh.
⤷ Title: A Dangerous Loophole in the VS Code Marketplace Is Allowing Malicious Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:10:49 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #cybersecurity #Developers #malware #marketplace #ransomware #ReversingLabs #supply chain attack #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:10:49 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #cybersecurity #Developers #malware #marketplace #ransomware #ReversingLabs #supply chain attack #VS Code
Daily CyberSecurity
A Dangerous Loophole in the VS Code Marketplace Is Allowing Malicious Extensions
A loophole in the VS Code Marketplace allows attackers to reuse names of removed extensions to spread malware, a flaw that creates a new supply chain attack vector.
⤷ Title: Silver Fox APT Exploits Microsoft-Signed Driver to Deploy ValleyRAT Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:04:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #BYOVD #Check Point Research #cybersecurity #Microsoft #Silver Fox #ValleyRAT #vulnerable driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:04:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #BYOVD #Check Point Research #cybersecurity #Microsoft #Silver Fox #ValleyRAT #vulnerable driver
Daily CyberSecurity
Silver Fox APT Exploits Microsoft-Signed Driver to Deploy ValleyRAT Backdoor
A new report reveals the Silver Fox APT group is abusing a Microsoft-signed vulnerable driver to disable endpoint security and deploy the ValleyRAT backdoor.
⤷ Title: PoC Exploit Released for Nagios XI RCE Flaw Allows Attackers to Hijack Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #IT monitoring #Nagios XI #Path Traversal #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #IT monitoring #Nagios XI #Path Traversal #rce #Remote Code Execution
Daily CyberSecurity
PoC Exploit Released for Nagios XI RCE Flaw Allows Attackers to Hijack Servers
A critical RCE flaw (CVE-2024-13986) in Nagios XI allows an authenticated attacker to upload and execute a malicious PHP shell, taking control of the server.