⤷ Title: Trace IP Information using Office Docs
════════════════════════
𐀪 Author: Saqlain Naqvi
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:20:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #word_document #ip #hacking #tracking
════════════════════════
𐀪 Author: Saqlain Naqvi
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:20:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #word_document #ip #hacking #tracking
Medium
Trace IP Information using Office Docs
Let’s dive into a fascinating topic: tracking someone’s IP using files. We’ll break down the concept first before delving into a…
⤷ Title: Como Automatizei uma simples verificação de Segurança Web com um Script Python
════════════════════════
𐀪 Author: Jonathan M.
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:06:35 GMT
════════════════════════
⌗ Tags: #infosecurity #python #hacking #web_development #security
════════════════════════
𐀪 Author: Jonathan M.
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:06:35 GMT
════════════════════════
⌗ Tags: #infosecurity #python #hacking #web_development #security
Medium
Como Automatizei uma simples verificação de Segurança Web com um Script Python
De horas de cliques em abas a um único comando no terminal. Uma história sobre a automação da validação de CSP, HSTS e certificados SSL.
⤷ Title: Dalfox: Escáner de XSS Inteligente para Bug Bounty y Pentesting
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:01:47 GMT
════════════════════════
⌗ Tags: #xss_attack #cybersecurity #technology #bug_bounty #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:01:47 GMT
════════════════════════
⌗ Tags: #xss_attack #cybersecurity #technology #bug_bounty #hacking
Medium
Dalfox: Escáner de XSS Inteligente para Bug Bounty y Pentesting
Descubre cómo Dalfox automatiza la detección de vulnerabilidades XSS y se convierte en una pieza clave de tu flujo de trabajo profesional.
⤷ Title: Androgoat Android App WriteUp
════════════════════════
𐀪 Author: Recep Emir
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:54:41 GMT
════════════════════════
⌗ Tags: #mobile #cybersecurity #red_team
════════════════════════
𐀪 Author: Recep Emir
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:54:41 GMT
════════════════════════
⌗ Tags: #mobile #cybersecurity #red_team
Medium
Androgoat Android App WriteUp
Challenge : Network Intercepting
⤷ Title: Understanding Zero-Day Vulnerabilities: The Invisible Threat
════════════════════════
𐀪 Author: Houssam LASFAR
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:36:47 GMT
════════════════════════
⌗ Tags: #vulnerability #software_engineering #technology #malware #cybersecurity
════════════════════════
𐀪 Author: Houssam LASFAR
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:36:47 GMT
════════════════════════
⌗ Tags: #vulnerability #software_engineering #technology #malware #cybersecurity
Medium
Understanding Zero-Day Vulnerabilities: The Invisible Threat
Understanding Zero-Day Vulnerabilities: The Invisible Threat Zero-day vulnerabilities, often called 0-days, represent flaws in software or hardware that remain unknown to the vendor or developer and …
⤷ Title: Netflix’s God-Tier Product Placement: A Masterclass in Defending Against AI Threats
════════════════════════
𐀪 Author: Scott Huang
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:31:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Scott Huang
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:31:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence
Medium
Netflix’s God-Tier Product Placement: A Masterclass in Defending Against AI Threats
In recent years, one of the most famous examples of product placement is Netflix’s Stranger Things. It didn’t just recreate the 1980s; it…
⤷ Title: How a German environmental forum post could have saved Volkswagen from the biggest corporate…
════════════════════════
𐀪 Author: Rishisec
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:11:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint
════════════════════════
𐀪 Author: Rishisec
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 23:11:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint
Medium
How a German environmental forum post could have saved Volkswagen from the biggest corporate…
The post was buried on page 3 of an obscure environmental research forum. Written in technical German by a graduate student analyzing…
⤷ Title: How One Bad Password Killed a 158-Year-Old Company Overnight
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:47:06 GMT
════════════════════════
⌗ Tags: #passwords #information_security #malware #cybersecurity #ai
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:47:06 GMT
════════════════════════
⌗ Tags: #passwords #information_security #malware #cybersecurity #ai
Medium
How One Bad Password Killed a 158-Year-Old Company Overnight
In June 2025, KNP Logistics Group, a UK transport giant with 500 trucks and 158 years of history, collapsed.
⤷ Title: Expressway Hachthebox Walkthrough
════════════════════════
𐀪 Author: Ahmed Ghazal
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:45:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox_writeup #hackthebox_walkthrough #hackthebox_challenge
════════════════════════
𐀪 Author: Ahmed Ghazal
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 22:45:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #hackthebox_writeup #hackthebox_walkthrough #hackthebox_challenge
Medium
Expressway Hachthebox Walkthrough
Expressway Hachthebox Walkthrough Hi there, this is a step by step writeup to solve Expressway on Hackthebox Season 9 The attack vector involved a multi-stage process beginning with the exploitation …
⤷ Title: CRITICAL Cisco Zero-Day (CVE-2025-20333, CVSS 9.9) Under Active Attack: VPN Flaw Allows Root RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:44:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #critical #CVE_2025_20333 #FTD #Patch Now #rce #VPN vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:44:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #critical #CVE_2025_20333 #FTD #Patch Now #rce #VPN vulnerability #zero_day
Daily CyberSecurity
CRITICAL Cisco Zero-Day (CVE-2025-20333, CVSS 9.9) Under Active Attack: VPN Flaw Allows Root RCE
Cisco patches a Critical 9.9 zero-day (CVE-2025-20333) in ASA/FTD VPN web servers. Authenticated attackers can exploit the flaw for root-level Remote Code Execution.
⤷ Title: Cisco Warns of Critical RCE Flaw (CVE-2025-20363) Affecting Firewall and Router Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:38:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #Critical Vulnerability #CVE_2025_20363 #FTD #IOS XE #network_security #rce #Secure Firewall
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:38:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #Critical Vulnerability #CVE_2025_20363 #FTD #IOS XE #network_security #rce #Secure Firewall
Daily CyberSecurity
Cisco Warns of Critical RCE Flaw (CVE-2025-20363) Affecting Firewall and Router Software
Cisco disclosed a Critical RCE flaw in its Firewall ASA/FTD, IOS, IOS XE, and IOS XR web services. Unauthenticated attackers can gain root access.
⤷ Title: Supply Chain Attack: Malicious Rust Crates Steal Solana and Ethereum Private Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:32:26 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Crypto Stealer #Ethereum #private keys #Rust #security alert #Solana #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:32:26 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Crypto Stealer #Ethereum #private keys #Rust #security alert #Solana #supply chain attack #Typosquatting
Daily CyberSecurity
Supply Chain Attack: Malicious Rust Crates Steal Solana and Ethereum Private Keys
Malicious Rust crates, downloaded 8,400+ times, were found to be typosquatting legitimate libraries to scan source code and steal Solana and Ethereum private keys.
⤷ Title: Cisco Zero-Day CVE-2025-20362 Under Attack: VPN Flaw in ASA/FTD Exposes Restricted Resources
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #CVE_2025_20362 #FTD #Secure Firewall #security update #unauthorized access #vpn #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #CVE_2025_20362 #FTD #Secure Firewall #security update #unauthorized access #vpn #zero_day
Daily CyberSecurity
Cisco Zero-Day CVE-2025-20362 Under Attack: VPN Flaw in ASA/FTD Exposes Restricted Resources
Cisco patches CVE-2025-20362, a medium-high zero-day vulnerability in ASA/FTD VPN web servers that is being exploited to gain unauthorized access to restricted resources.
⤷ Title: CVE-2025-54831: Apache Airflow Bug Exposes Sensitive Connection Passwords to Read-Only Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:29:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Airflow #Connection Credentials #CVE_2025_54831 #data leak #open_source #security vulnerability #Workflow Management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:29:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Airflow #Connection Credentials #CVE_2025_54831 #data leak #open_source #security vulnerability #Workflow Management
Daily CyberSecurity
CVE-2025-54831: Apache Airflow Bug Exposes Sensitive Connection Passwords to Read-Only Users
Apache Airflow 3.0.3 has a bug (CVE-2025-54831) exposing sensitive connection details, including passwords, to all users with only READ permissions. Update immediately.
⤷ Title: BRICKSTORM Malware: China-Linked Hackers Stealthily Target US Tech and Legal Firms for 393 Days
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:23:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #backdoor #BRICKSTORM #China_nexus #Espionage #Go malware #SaaS #supply chain attack #UNC5221 #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:23:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #backdoor #BRICKSTORM #China_nexus #Espionage #Go malware #SaaS #supply chain attack #UNC5221 #vmware
Daily CyberSecurity
BRICKSTORM Malware: China-Linked Hackers Stealthily Target US Tech and Legal Firms for 393 Days
GTIG reveals BRICKSTORM, a stealthy Go backdoor linked to China-nexus UNC5221, targeting US legal/SaaS firms to steal IP and establish long-term espionage access.
⤷ Title: GitLab Fixes High-Severity DoS Flaws: Unauthenticated Attackers Could Crash Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_10858 #Denial of Service #dos #gitlab #High Severity #JSON Attack #Patch Now #security update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_10858 #Denial of Service #dos #gitlab #High Severity #JSON Attack #Patch Now #security update
Daily CyberSecurity
GitLab Fixes High-Severity DoS Flaws: Unauthenticated Attackers Could Crash Instances
GitLab urges immediate upgrade to patch versions 18.4.1+ for high-severity DoS flaws that allowed unauthenticated attackers to crash self-managed instances.
⤷ Title: NVIDIA Patches High-Severity Code Injection Flaws in Megatron-LM AI Framework
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:12:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Framework #code_injection #CVE_2025_23348 #LLM #Megatron_LM #nvidia #security update #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:12:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Framework #code_injection #CVE_2025_23348 #LLM #Megatron_LM #nvidia #security update #Vulnerability
Daily CyberSecurity
NVIDIA Patches High-Severity Code Injection Flaws in Megatron-LM AI Framework
NVIDIA released an urgent update for its Megatron-LM LLM framework, patching four high-severity code injection flaws that could allow attackers to compromise AI workflows.
⤷ Title: AI vs. AI: Microsoft Blocks Phishing Attack Using LLM-Generated Obfuscated Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Enhanced Threat #Credential Phishing #cybersecurity #LLM #Microsoft Defender #Microsoft Security Copilot #Obfuscation #SVG
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Enhanced Threat #Credential Phishing #cybersecurity #LLM #Microsoft Defender #Microsoft Security Copilot #Obfuscation #SVG
Daily CyberSecurity
AI vs. AI: Microsoft Blocks Phishing Attack Using LLM-Generated Obfuscated Code
Microsoft blocked a credential phishing campaign that used AI to generate complex, verbose code in an SVG file to obfuscate its payload and evade defenses.
⤷ Title: New Lone None Stealer Malware Hijacks Crypto Wallets via Fake Copyright Takedown Notices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:05:04 +0000
════════════════════════
⌗ Tags: #Malware #Cofense #copyright scam #Cryptocurrency Theft #Lone None Stealer #phishing #PXA Stealer #Stealer malware #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:05:04 +0000
════════════════════════
⌗ Tags: #Malware #Cofense #copyright scam #Cryptocurrency Theft #Lone None Stealer #phishing #PXA Stealer #Stealer malware #Telegram C2
Daily CyberSecurity
New Lone None Stealer Malware Hijacks Crypto Wallets via Fake Copyright Takedown Notices
The Lone None group uses fake copyright notices to deliver a new stealer malware that focuses on crypto theft via clipboard replacement and utilizes Telegram for C2.
⤷ Title: LNK Stomping: Attackers Bypass Windows Security by Stripping the ‘Mark of the Web’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
Daily CyberSecurity
LNK Stomping: Attackers Bypass Windows Security by Stripping the 'Mark of the Web'
A vulnerability dubbed "LNK Stomping" (CVE-2024-38217) is actively used to strip the 'Mark of the Web' from LNK files, bypassing Windows security policies.
⤷ Title: Beyond Burp Suite: Top 8 Underused Tools for Web App Security Testing (2025)
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:31:25 GMT
════════════════════════
⌗ Tags: #pentesting #web_security #penetration_testing #bug_bounty #cybersecurity_tools
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:31:25 GMT
════════════════════════
⌗ Tags: #pentesting #web_security #penetration_testing #bug_bounty #cybersecurity_tools
Medium
Beyond Burp Suite: Top 8 Underused Tools for Web App Security Testing (2025)
Discover powerful alternatives and complementary tools that most security testers overlook but can dramatically improve your bug hunting…