⤷ Title: Gold Melody’s Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
Daily CyberSecurity
Gold Melody's Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
Unit 42 reveals "Gold Melody" uses leaked ASP.NET Machine Keys to achieve in-memory RCE via View State deserialization and privilege escalation via GodPotato, compromising web servers.
⤷ Title: Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Jul 2025 03:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET #cyberattack #cybersecurity #Gold Melody #IIS #machine keys #memory_only attack #Prophet Spider #UNC961 #ViewState
Penetration Testing Tools
Gold Melody Unleashed: New Stealthy Attacks Exploit Leaked ASP.NET Keys
Gold Melody (Prophet Spider) is exploiting leaked ASP.NET machine keys to launch stealthy, memory-only attacks on global corporate systems.
⤷ Title: GOLD BLADE Unleashes RedLoader with Novel Attack Chain: LNK Files + WebDAV + DLL Sideloading Evades Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 00:15:51 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #evasion #GOLD BLADE #LNK File #malware #RedLoader #Sophos #threat actor #WebDAV
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 00:15:51 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #DLL Sideloading #evasion #GOLD BLADE #LNK File #malware #RedLoader #Sophos #threat actor #WebDAV
Daily CyberSecurity
GOLD BLADE Unleashes RedLoader with Novel Attack Chain: LNK Files + WebDAV + DLL Sideloading Evades Detection
Sophos uncovers a new infection chain for GOLD BLADE's RedLoader malware, combining LNK files, WebDAV, and DLL sideloading to bypass defenses and deploy payloads stealthily.
⤷ Title: From Locks on Doors to Locks on Data: How Security Has Evolved With Us
════════════════════════
𐀪 Author: Haider Ali
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 21:11:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #money #illumination #security #gold
════════════════════════
𐀪 Author: Haider Ali
════════════════════════
ⴵ Time: Sat, 06 Sep 2025 21:11:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #money #illumination #security #gold
Medium
From Locks on Doors to Locks on Data: How Security Has Evolved With Us
Tracing the Journey of Security from Physical Protections to the Digital Age
⤷ Title: GOLD SALEM: A New Ransomware Group Is Exploiting SharePoint Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:11:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #CVE_2024_51324 #Cybercrime #EDR evasion #GOLD SALEM #ransomware #Sharepoint #Sophos #Warlock Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:11:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #CVE_2024_51324 #Cybercrime #EDR evasion #GOLD SALEM #ransomware #Sharepoint #Sophos #Warlock Group
Daily CyberSecurity
GOLD SALEM: A New Ransomware Group Is Exploiting SharePoint Flaws
Sophos uncovers GOLD SALEM, a new ransomware group exploiting SharePoint flaws. The group uses EDR evasion and legitimate tools to attack global targets.
⤷ Title: Announcing Creek Testnet’s Bug Bounty Program
════════════════════════
𐀪 Author: Creek Finance
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 14:24:05 GMT
════════════════════════
⌗ Tags: #incentivized_testnet #bug_bounty #sui_network #gold #testnet_airdrop
════════════════════════
𐀪 Author: Creek Finance
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 14:24:05 GMT
════════════════════════
⌗ Tags: #incentivized_testnet #bug_bounty #sui_network #gold #testnet_airdrop
Medium
Announcing Creek Testnet’s Bug Bounty Program
The Creek Testnet Bug Bounty Program incentivizes security researchers to identify vulnerabilities that may impact the protocol’s core…
⤷ Title: GOLD BLADE APT Hits Canadian Firms with BYOVD EDR Killer and Ransomware Delivered Via Fake Resumes
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:52:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Canada #corporate espionage #EDR Killer #GOLD BLADE #QWCrypt Ransomware #Recruitment Lure #RedCurl #RedWolf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 12 Dec 2025 01:52:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Canada #corporate espionage #EDR Killer #GOLD BLADE #QWCrypt Ransomware #Recruitment Lure #RedCurl #RedWolf
Daily CyberSecurity
GOLD BLADE APT Hits Canadian Firms with BYOVD EDR Killer and Ransomware Delivered Via Fake Resumes
GOLD BLADE (RedCurl) targets Canadian firms (80% of attacks) with espionage and QWCrypt ransomware. The group uses fake resumes and a BYOVD EDR killer (Zemana driver) to disable security controls.
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.
⤷ Title: Shadows in the Server: How the Warlock Group Weaponized a “Forgotten” VM to Breach SmarterTools
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #CVE_2026_23760 #CVE_2026_24423 #Gold Salem #ransomware #SentinelOne #SmarterMail #SmarterTools #Storm_2603 #Tech News 2026 #Warlock Group #zero_day exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #CVE_2026_23760 #CVE_2026_24423 #Gold Salem #ransomware #SentinelOne #SmarterMail #SmarterTools #Storm_2603 #Tech News 2026 #Warlock Group #zero_day exploit
Penetration Testing Tools
Shadows in the Server: How the Warlock Group Weaponized a "Forgotten" VM to Breach SmarterTools
SmarterTools has disclosed a comprehensive retrospective regarding a recent infiltration of its infrastructure, meticulously delineating the adversaries’ entry
⤷ Title: The Phantom Hypervisor: How Payouts King Uses QEMU to Hide Ransomware Inside Virtual Machines
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 08:01:37 +0000
════════════════════════
⌗ Tags: #Malware #3AM Ransomware #Alpine Linux #CitrixBleed 2 #Cyber Security #EDR evasion #GOLD ENCOUNTER #Payouts King #QEMU #ransomware #Sophos #Virtualization Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 08:01:37 +0000
════════════════════════
⌗ Tags: #Malware #3AM Ransomware #Alpine Linux #CitrixBleed 2 #Cyber Security #EDR evasion #GOLD ENCOUNTER #Payouts King #QEMU #ransomware #Sophos #Virtualization Security
Penetration Testing Tools
The Phantom Hypervisor: How Payouts King Uses QEMU to Hide Ransomware Inside Virtual Machines
Ransomware syndicates are increasingly adopting the clandestine practice of concealing their malicious artifacts not merely adjacent to the
⤷ Title: White House Launches GOLD EAGLE Initiative to Speed Vulnerability Patching
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 03:39:32 +0000
════════════════════════
⌗ Tags: #Technology #AI cybersecurity #CISA #Critical Infrastructure #EO 14409 #GOLD EAGLE #Trump Administration #vulnerability coordination #White House
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 03:39:32 +0000
════════════════════════
⌗ Tags: #Technology #AI cybersecurity #CISA #Critical Infrastructure #EO 14409 #GOLD EAGLE #Trump Administration #vulnerability coordination #White House
Daily CyberSecurity
White House Launches GOLD EAGLE Initiative to Speed Vulnerability Patching
The White House has launched the GOLD EAGLE initiative, a new clearinghouse for cybersecurity vulnerability coordination. It aims to help government and industry find and patch flaws faster. The a…
⤷ Title: Interlock Ransomware Abuses Volatility3 for Credential Theft
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:20:55 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #GOLD EMBRACE #Interlock ransomware #living off the land #Sophos #Volatility3
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:20:55 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #GOLD EMBRACE #Interlock ransomware #living off the land #Sophos #Volatility3
Daily CyberSecurity
Interlock Ransomware Abuses Volatility3 for Credential Theft
At a Glance Attribute Detail Malware family Interlock ransomware (double extortion) Threat actor Interlock, tracked by Sophos as GOLD EMBRACE (confirmed) Target / victims Critical infrastructure, …