⤷ Title: Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 10:27:08 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #ClickFix #Cyber Attack #Cybersecurity #Fraud #Lazarus #Maltrail #North Korea #Scam #security #SentinelLABS #Validin #VirusTotal
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 10:27:08 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #ClickFix #Cyber Attack #Cybersecurity #Fraud #Lazarus #Maltrail #North Korea #Scam #security #SentinelLABS #Validin #VirusTotal
Hackread
Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: A “Catastrophic” Flaw in Burger King’s Parent Company Exposed
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:34:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Burger King #cybersecurity #hacking #Popeyes #RBI #security vulnerability #Tim Hortons
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:34:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Burger King #cybersecurity #hacking #Popeyes #RBI #security vulnerability #Tim Hortons
Penetration Testing Tools
A "Catastrophic" Flaw in Burger King's Parent Company Exposed
A new report reveals critical vulnerabilities in the systems of RBI, the parent company of Burger King and Popeyes, exposing employee accounts and systems.
⤷ Title: Critical SAP S/4HANA Flaw Exposes Systems to Full Compromise
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:32:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_42957 #cybersecurity #remote code execution #S/4HANA #SAP #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:32:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_42957 #cybersecurity #remote code execution #S/4HANA #SAP #vulnerability
Penetration Testing Tools
Critical SAP S/4HANA Flaw Exposes Systems to Full Compromise
A critical vulnerability (CVE-2025-42957) in SAP S/4HANA with a CVSS score of 9.9 allows attackers with minimal privileges to execute arbitrary code.
⤷ Title: Apple Issues Urgent Patch for Zero-Click Image Flaw
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:30:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #CVE_2025_43300 #ios #macos #security update #Zero_Click #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:30:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #Apple #CVE_2025_43300 #ios #macos #security update #Zero_Click #zero_day
Penetration Testing Tools
Apple Issues Urgent Patch for Zero-Click Image Flaw
Apple has issued an urgent, unscheduled patch for a zero-click vulnerability (CVE-2025-43300) in its ImageIO framework that was being actively exploited in targeted attacks.
⤷ Title: CSS Injection Can Now Steal Data with Just One Line of Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:25:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chromium #CSS injection #cybersecurity #Data Exfiltration #hacking #PortSwigger #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:25:56 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chromium #CSS injection #cybersecurity #Data Exfiltration #hacking #PortSwigger #web security
Penetration Testing Tools
CSS Injection Can Now Steal Data with Just One Line of Code
A new technique allows attackers to steal data directly from HTML attributes using just a single line of inline CSS, without relying on external style sheets.
⤷ Title: Thermoptic: The New HTTP Proxy That Makes Your Traffic Vanish
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:23:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #anti_bot #Cloudflare #cybersecurity #fingerprinting #HTTP proxy #Technology #Thermoptic
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:23:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #anti_bot #Cloudflare #cybersecurity #fingerprinting #HTTP proxy #Technology #Thermoptic
Penetration Testing Tools
Thermoptic: The New HTTP Proxy That Makes Your Traffic Vanish
A new HTTP proxy called Thermoptic disguises network requests as authentic Chrome traffic, enabling users to bypass advanced blocking systems.
⤷ Title: Anatomy of a Cyberattack: Inside the Campaign Against Kazakhstan’s Energy Sector
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:21:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #cyberattack #cybersecurity #Energy Sector #KazMunaiGas #NoisyBear #phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:21:47 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #cyberattack #cybersecurity #Energy Sector #KazMunaiGas #NoisyBear #phishing
Penetration Testing Tools
Anatomy of a Cyberattack: Inside the Campaign Against Kazakhstan's Energy Sector
A new report details a sophisticated cyberattack against Kazakhstan's national oil and gas company, revealing the tactics and tools used by a new threat group, NoisyBear.
⤷ Title: Why the FTC’s Accusations Against Gmail’s Spam Filter Are Misguided
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:20:50 +0000
════════════════════════
⌗ Tags: #Google #cybersecurity #FTC #Gmail #google #political bias #spam filter #Tech Regulation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:20:50 +0000
════════════════════════
⌗ Tags: #Google #cybersecurity #FTC #Gmail #google #political bias #spam filter #Tech Regulation
Penetration Testing Tools
Why the FTC's Accusations Against Gmail's Spam Filter Are Misguided
The FTC is investigating Gmail for alleged political bias. But experts say the real reason for filtered emails is the Republican platform’s aggressive mailing practices.
⤷ Title: XChat’s Encrypted Messages Are Not as Secure as They Seem
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:18:01 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #E2EE #end_to_end encryption #privacy #Signal #XChat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:18:01 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #E2EE #end_to_end encryption #privacy #Signal #XChat
Penetration Testing Tools
XChat's Encrypted Messages Are Not as Secure as They Seem
X has launched an end-to-end encrypted chat service, but cryptographers warn it has critical flaws, including server-stored keys and no forward secrecy.
⤷ Title: GhostAction: The Supply Chain Attack That Stole 3,325 GitHub Secrets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:13:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CI/CD #cybersecurity #GhostAction #Github #hacking #Secrets #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:13:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CI/CD #cybersecurity #GhostAction #Github #hacking #Secrets #supply chain attack
Penetration Testing Tools
GhostAction: The Supply Chain Attack That Stole 3,325 GitHub Secrets
A new report details GhostAction, a major supply chain attack that injected malicious code into GitHub repositories, stealing thousands of secrets.
⤷ Title: Wealthsimple Confirms Data Breach, Cites Third-Party Vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:11:43 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity #data breach #fintech #privacy #third_party risk #Wealthsimple
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:11:43 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity #data breach #fintech #privacy #third_party risk #Wealthsimple
Penetration Testing Tools
Wealthsimple Confirms Data Breach, Cites Third-Party Vulnerability
Wealthsimple confirms a security incident affecting less than 1% of its clients due to a third-party software compromise. No funds or passwords were lost.
⤷ Title: NightshadeC2 Botnet Is Using “UAC Prompt Bombing” to Bypass Defenses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:09:34 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #eSentire #hacking #malware #NightshadeC2 #uac
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 04:09:34 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #eSentire #hacking #malware #NightshadeC2 #uac
Penetration Testing Tools
NightshadeC2 Botnet Is Using "UAC Prompt Bombing" to Bypass Defenses
A new botnet called NightshadeC2 uses "UAC Prompt Bombing" to force users to approve malicious actions, bypassing Windows Defender and analysis sandboxes.
⤷ Title: Havoc: modern and malleable post-exploitation command and control framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 07:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #HavocFramework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 07:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #HavocFramework
Penetration Testing Tools
Havoc: modern and malleable post-exploitation command and control framework
Havoc is a modern and malleable post-exploitation command and control framework. It handles the listeners, teamserver authentication and payload generation
⤷ Title: CastleRAT: The New MaaS Threat Expanding the Cybercrime Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:35:29 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #cybercrime #cybersecurity #MaaS #malware #Remote Access Trojan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:35:29 +0000
════════════════════════
⌗ Tags: #Malware #CastleRAT #cybercrime #cybersecurity #MaaS #malware #Remote Access Trojan
Penetration Testing Tools
CastleRAT: The New MaaS Threat Expanding the Cybercrime Toolkit
A new remote access trojan, CastleRAT, has been discovered. It's part of a growing MaaS ecosystem and is being used to distribute stealers and other malware.
⤷ Title: EU Fines Google $3.5B for Abusing Its Ad Tech Monopoly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:33:31 +0000
════════════════════════
⌗ Tags: #Google #ad tech #antitrust #digital advertising #European Commission #fine #google #monopoly
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:33:31 +0000
════════════════════════
⌗ Tags: #Google #ad tech #antitrust #digital advertising #European Commission #fine #google #monopoly
Penetration Testing Tools
EU Fines Google $3.5B for Abusing Its Ad Tech Monopoly
The EU has fined Google €2.95B for favoring its own ad tech services, a practice that distorted competition and harmed rivals, advertisers, and publishers.
⤷ Title: Hackers Threaten Google: Fire Our Trackers or We’ll Leak Your Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:30:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #cybersecurity #Extortion #google #hacking #Scattered LapSus Hunters
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:30:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #cybersecurity #Extortion #google #hacking #Scattered LapSus Hunters
Penetration Testing Tools
Hackers Threaten Google: Fire Our Trackers or We'll Leak Your Data
A hacker group is threatening to leak Google's databases unless the company fires two of its security staff and ceases its investigations.
⤷ Title: The Fall of XSS.is: A Cybercrime Forum Fractured by Toha’s Arrest
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:28:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #cybersecurity #Dark Web #forum #ransomware #Toha #XSS.is
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 04:28:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #cybersecurity #Dark Web #forum #ransomware #Toha #XSS.is
Penetration Testing Tools
The Fall of XSS.is: A Cybercrime Forum Fractured by Toha's Arrest
The arrest of XSS.is administrator "Toha" has thrown the cybercrime underground into turmoil. A new report details the forum's downfall and its fractured community.
⤷ Title: CVE-2025-40795 (CVSS 9.8): Critical Flaw in Siemens SIVaaS Exposes Network Share Without Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 15:12:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_40804 #data leak #Industrial Security #Remote Access #Siemens #SIVaaS #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 15:12:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_40804 #data leak #Industrial Security #Remote Access #Siemens #SIVaaS #Vulnerability
Daily CyberSecurity
CVE-2025-40795 (CVSS 9.8): Critical Flaw in Siemens SIVaaS Exposes Network Share Without Authentication
Siemens has disclosed a critical flaw in its SIVaaS platform. A network share is exposed without authentication, allowing unauthenticated attackers to access or alter sensitive data.
⤷ Title: Ivanti Patches Two High-Severity RCE Flaws in Endpoint Manager
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 14:55:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_9712 #CVE_2025_9872 #cybersecurity #filename validation #Ivanti #Ivanti EPM #rce #Remote Code Execution #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 14:55:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_9712 #CVE_2025_9872 #cybersecurity #filename validation #Ivanti #Ivanti EPM #rce #Remote Code Execution #Vulnerability
Daily CyberSecurity
Ivanti Patches Two High-Severity RCE Flaws in Endpoint Manager
Ivanti has released a security update for Endpoint Manager, patching two high-severity RCE flaws (CVSS 8.8) that could allow unauthenticated attackers to execute code.
⤷ Title: Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure
════════════════════════
𐀪 Author: cybernewswire
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 13:00:17 +0000
════════════════════════
⌗ Tags: #Press Release
════════════════════════
𐀪 Author: cybernewswire
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 13:00:17 +0000
════════════════════════
⌗ Tags: #Press Release
Daily CyberSecurity
Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure
Frankfurt am Main, Germany, 9th September 2025, CyberNewsWire
⤷ Title: Signal Solves Its Biggest Flaw with a New Privacy-Focused Cloud Backup
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 10:13:05 +0000
════════════════════════
⌗ Tags: #Technology #cloud backup #encryption #messaging app #privacy #security #Signal #subscription #zero_knowledge
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Sep 2025 10:13:05 +0000
════════════════════════
⌗ Tags: #Technology #cloud backup #encryption #messaging app #privacy #security #Signal #subscription #zero_knowledge
Daily CyberSecurity
Signal Solves Its Biggest Flaw with a New Privacy-Focused Cloud Backup