⤷ Title: Supply Chain Attack: Malicious Rust Crates Steal Solana and Ethereum Private Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:32:26 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Crypto Stealer #Ethereum #private keys #Rust #security alert #Solana #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:32:26 +0000
════════════════════════
⌗ Tags: #Malware #Crates.io #Crypto Stealer #Ethereum #private keys #Rust #security alert #Solana #supply chain attack #Typosquatting
Daily CyberSecurity
Supply Chain Attack: Malicious Rust Crates Steal Solana and Ethereum Private Keys
Malicious Rust crates, downloaded 8,400+ times, were found to be typosquatting legitimate libraries to scan source code and steal Solana and Ethereum private keys.
⤷ Title: Cisco Zero-Day CVE-2025-20362 Under Attack: VPN Flaw in ASA/FTD Exposes Restricted Resources
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #CVE_2025_20362 #FTD #Secure Firewall #security update #unauthorized access #vpn #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #cisco #CVE_2025_20362 #FTD #Secure Firewall #security update #unauthorized access #vpn #zero_day
Daily CyberSecurity
Cisco Zero-Day CVE-2025-20362 Under Attack: VPN Flaw in ASA/FTD Exposes Restricted Resources
Cisco patches CVE-2025-20362, a medium-high zero-day vulnerability in ASA/FTD VPN web servers that is being exploited to gain unauthorized access to restricted resources.
⤷ Title: CVE-2025-54831: Apache Airflow Bug Exposes Sensitive Connection Passwords to Read-Only Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:29:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Airflow #Connection Credentials #CVE_2025_54831 #data leak #open_source #security vulnerability #Workflow Management
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:29:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Airflow #Connection Credentials #CVE_2025_54831 #data leak #open_source #security vulnerability #Workflow Management
Daily CyberSecurity
CVE-2025-54831: Apache Airflow Bug Exposes Sensitive Connection Passwords to Read-Only Users
Apache Airflow 3.0.3 has a bug (CVE-2025-54831) exposing sensitive connection details, including passwords, to all users with only READ permissions. Update immediately.
⤷ Title: BRICKSTORM Malware: China-Linked Hackers Stealthily Target US Tech and Legal Firms for 393 Days
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:23:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #backdoor #BRICKSTORM #China_nexus #Espionage #Go malware #SaaS #supply chain attack #UNC5221 #vmware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:23:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #backdoor #BRICKSTORM #China_nexus #Espionage #Go malware #SaaS #supply chain attack #UNC5221 #vmware
Daily CyberSecurity
BRICKSTORM Malware: China-Linked Hackers Stealthily Target US Tech and Legal Firms for 393 Days
GTIG reveals BRICKSTORM, a stealthy Go backdoor linked to China-nexus UNC5221, targeting US legal/SaaS firms to steal IP and establish long-term espionage access.
⤷ Title: GitLab Fixes High-Severity DoS Flaws: Unauthenticated Attackers Could Crash Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_10858 #Denial of Service #dos #gitlab #High Severity #JSON Attack #Patch Now #security update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_10858 #Denial of Service #dos #gitlab #High Severity #JSON Attack #Patch Now #security update
Daily CyberSecurity
GitLab Fixes High-Severity DoS Flaws: Unauthenticated Attackers Could Crash Instances
GitLab urges immediate upgrade to patch versions 18.4.1+ for high-severity DoS flaws that allowed unauthenticated attackers to crash self-managed instances.
⤷ Title: NVIDIA Patches High-Severity Code Injection Flaws in Megatron-LM AI Framework
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:12:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Framework #code_injection #CVE_2025_23348 #LLM #Megatron_LM #nvidia #security update #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:12:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Framework #code_injection #CVE_2025_23348 #LLM #Megatron_LM #nvidia #security update #Vulnerability
Daily CyberSecurity
NVIDIA Patches High-Severity Code Injection Flaws in Megatron-LM AI Framework
NVIDIA released an urgent update for its Megatron-LM LLM framework, patching four high-severity code injection flaws that could allow attackers to compromise AI workflows.
⤷ Title: AI vs. AI: Microsoft Blocks Phishing Attack Using LLM-Generated Obfuscated Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Enhanced Threat #Credential Phishing #cybersecurity #LLM #Microsoft Defender #Microsoft Security Copilot #Obfuscation #SVG
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Enhanced Threat #Credential Phishing #cybersecurity #LLM #Microsoft Defender #Microsoft Security Copilot #Obfuscation #SVG
Daily CyberSecurity
AI vs. AI: Microsoft Blocks Phishing Attack Using LLM-Generated Obfuscated Code
Microsoft blocked a credential phishing campaign that used AI to generate complex, verbose code in an SVG file to obfuscate its payload and evade defenses.
⤷ Title: New Lone None Stealer Malware Hijacks Crypto Wallets via Fake Copyright Takedown Notices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:05:04 +0000
════════════════════════
⌗ Tags: #Malware #Cofense #copyright scam #Cryptocurrency Theft #Lone None Stealer #phishing #PXA Stealer #Stealer malware #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:05:04 +0000
════════════════════════
⌗ Tags: #Malware #Cofense #copyright scam #Cryptocurrency Theft #Lone None Stealer #phishing #PXA Stealer #Stealer malware #Telegram C2
Daily CyberSecurity
New Lone None Stealer Malware Hijacks Crypto Wallets via Fake Copyright Takedown Notices
The Lone None group uses fake copyright notices to deliver a new stealer malware that focuses on crypto theft via clipboard replacement and utilizes Telegram for C2.
⤷ Title: LNK Stomping: Attackers Bypass Windows Security by Stripping the ‘Mark of the Web’
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:00:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AhnLab #CVE_2024_38217 #cyberattack #evasion #LNK Stomping #Mark_of_the_Web #MotW #Windows Security
Daily CyberSecurity
LNK Stomping: Attackers Bypass Windows Security by Stripping the 'Mark of the Web'
A vulnerability dubbed "LNK Stomping" (CVE-2024-38217) is actively used to strip the 'Mark of the Web' from LNK files, bypassing Windows security policies.
⤷ Title: Beyond Burp Suite: Top 8 Underused Tools for Web App Security Testing (2025)
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:31:25 GMT
════════════════════════
⌗ Tags: #pentesting #web_security #penetration_testing #bug_bounty #cybersecurity_tools
════════════════════════
𐀪 Author: Andrei Ivan
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:31:25 GMT
════════════════════════
⌗ Tags: #pentesting #web_security #penetration_testing #bug_bounty #cybersecurity_tools
Medium
Beyond Burp Suite: Top 8 Underused Tools for Web App Security Testing (2025)
Discover powerful alternatives and complementary tools that most security testers overlook but can dramatically improve your bug hunting…
⤷ Title: Stored XSS via PDF Upload in Live chat⚠️
════════════════════════
𐀪 Author: 0verRida
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:21:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #pentesting #bug_bounty_writeup #bug_bounty_tips #bug_bounty
════════════════════════
𐀪 Author: 0verRida
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:21:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #pentesting #bug_bounty_writeup #bug_bounty_tips #bug_bounty
Medium
Stored XSS via PDF Upload in Live chat⚠️
Hello everyone, I’m Firda Nurelia (find me on LinkedIn). Today I’m sharing a critical Stored Cross-Site Scripting (XSS) I found that…
⤷ Title: How a JavaScript Developer Could Prevent Supply-Chain Attacks
════════════════════════
𐀪 Author: Emily Xiong
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 01:44:51 GMT
════════════════════════
⌗ Tags: #npm #javascript #hacking
════════════════════════
𐀪 Author: Emily Xiong
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 01:44:51 GMT
════════════════════════
⌗ Tags: #npm #javascript #hacking
Medium
How a JavaScript Developer Could Prevent Supply-Chain Attacks
Recently, the JavaScript community has been shaken by a series of supplychain attacks. These are not bugs in code we wrote, but malicious…
⤷ Title: Part II — From Orbit to Exploit: Understanding the PWNSAT test case
════════════════════════
𐀪 Author: PWNSAT
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 01:14:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #pwnsat #hacking #satellite #aeroespace
════════════════════════
𐀪 Author: PWNSAT
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 01:14:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #pwnsat #hacking #satellite #aeroespace
Medium
Part II — From Orbit to Exploit: Understanding the PWNSAT test case
Introduction
⤷ Title: From AI Fear to Terms of Service: A Security Professional’s Reality Check
════════════════════════
𐀪 Author: Imanologya
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 01:40:26 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #ai
════════════════════════
𐀪 Author: Imanologya
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 01:40:26 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #ai
Medium
From AI Fear to Terms of Service: A Security Professional’s Reality Check
From AI Fear to Terms of Service: A Security Professional’s Reality Check The cybersecurity community’s relationship with AI has shifted dramatically from existential dread to practical …
⤷ Title: Patch Fatigue vs. Risk Context: Rethinking Vulnerability Remediation Priorities
════════════════════════
𐀪 Author: Sai Krishna Kakarla
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:46:00 GMT
════════════════════════
⌗ Tags: #vulnerability_management #threat_intelligence #cybersecurity #patch_management #risk
════════════════════════
𐀪 Author: Sai Krishna Kakarla
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:46:00 GMT
════════════════════════
⌗ Tags: #vulnerability_management #threat_intelligence #cybersecurity #patch_management #risk
Medium
Patch Fatigue vs. Risk Context: Rethinking Vulnerability Remediation Priorities
In cybersecurity, patching has long been positioned as a simple equation: vulnerabilities are discovered, patches are released, and…
⤷ Title: Part 4: From backyard to battlefield, The Flight Controller.
════════════════════════
𐀪 Author: Pipeline
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:35:09 GMT
════════════════════════
⌗ Tags: #programming #technology #life #cybersecurity #drones
════════════════════════
𐀪 Author: Pipeline
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:35:09 GMT
════════════════════════
⌗ Tags: #programming #technology #life #cybersecurity #drones
Medium
Part 4: From backyard to battlefield, The Flight Controller.
A drone can have a strong body and a powerful energy source, but without a brain, it’s just a shell. The flight controller is that brain…
⤷ Title: Enhancement of Cloudbric WAF+ Completed
════════════════════════
𐀪 Author: Cloudbric
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:32:17 GMT
════════════════════════
⌗ Tags: #waf #cybersecurity #saas #cloudbric
════════════════════════
𐀪 Author: Cloudbric
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:32:17 GMT
════════════════════════
⌗ Tags: #waf #cybersecurity #saas #cloudbric
Medium
Enhancement of Cloudbric WAF+ Completed
Hello, this is Penta Security.
⤷ Title: Cloudbric WAF+ 서비스 고도화 완료
════════════════════════
𐀪 Author: Cloudbric
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:31:17 GMT
════════════════════════
⌗ Tags: #saas #cloudbric #waf #cybersecurity
════════════════════════
𐀪 Author: Cloudbric
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:31:17 GMT
════════════════════════
⌗ Tags: #saas #cloudbric #waf #cybersecurity
Medium
Cloudbric WAF+ 서비스 고도화 완료
안녕하세요. 펜타시큐리티입니다.
⤷ Title: VMware ile FortiGate Lab Kurulumu
════════════════════════
𐀪 Author: Onur Altuğ
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:08:00 GMT
════════════════════════
⌗ Tags: #vmware #network #cybersecurity #firewall #fortinet
════════════════════════
𐀪 Author: Onur Altuğ
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:08:00 GMT
════════════════════════
⌗ Tags: #vmware #network #cybersecurity #firewall #fortinet
Medium
VMware ile FortiGate Lab Kurulumu
NELER VAR
⤷ Title: Critical Flaws in Supermicro BMC Enable Irreversible AI Server Rootkits Below the OS Level
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:59:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Binarly #BMC #CVE_2025_7937 #data center #firmware #rootkit #Supermicro #Supply Chain #UEFI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:59:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Binarly #BMC #CVE_2025_7937 #data center #firmware #rootkit #Supermicro #Supply Chain #UEFI
Penetration Testing Tools
Critical Flaws in Supermicro BMC Enable Irreversible AI Server Rootkits Below the OS Level
Critical Supermicro BMC flaws (CVE-2025-7937/6198) enable malicious, irreversible firmware to be installed, compromising servers at the root-of-trust level.
⤷ Title: Global Cybercrime Crackdown: Interpol Operation HAECHI VI Recovers $439 Million in Stolen Assets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:58:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BEC #cryptocurrency #cybercrime #Financial Crime #I_GRIP #Interpol #Money Laundering #Operation HAECHI VI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 03:58:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BEC #cryptocurrency #cybercrime #Financial Crime #I_GRIP #Interpol #Money Laundering #Operation HAECHI VI
Penetration Testing Tools
Global Cybercrime Crackdown: Interpol Operation HAECHI VI Recovers $439 Million in Stolen Assets
Interpol’s Operation HAECHI VI, involving 40 countries, successfully recovered $439 million from cybercriminals and froze 400 crypto wallets targeting scams like BEC and fraud.