⤷ Title: ⌚All Xiaomi watches hacked (Cross Tenant IDOR)
════════════════════════
𐀪 Author: Hohky
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:37:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #bug_bounty_writeup #bug_bounty_tips
════════════════════════
𐀪 Author: Hohky
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:37:40 GMT
════════════════════════
⌗ Tags: #bug_bounty #hacking #bug_bounty_writeup #bug_bounty_tips
Medium
⌚All Xiaomi watches hacked (Cross Tenant IDOR)
The IoT is part of everyone’s daily life! So why not explore it? 🤨
⤷ Title: Epidemics we cannot see
════════════════════════
𐀪 Author: Progsky
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:56:39 GMT
════════════════════════
⌗ Tags: #virus #hacking #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Progsky
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:56:39 GMT
════════════════════════
⌗ Tags: #virus #hacking #cybersecurity #ethical_hacking
Medium
Epidemics we cannot see
Epidemics we cannot see Ordinary users are never concerned about their security; they don’t download patches or update their antivirus software, and they respond to all security warnings with a …
⤷ Title: Beyond Naïve Filters: Chaining Guardrails for LLM Prompt Injection
════════════════════════
𐀪 Author: Pratip Dasgupta
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:29:29 GMT
════════════════════════
⌗ Tags: #defensive_security #prompt_injection #cybersecurity #llm_safety #ai_security
════════════════════════
𐀪 Author: Pratip Dasgupta
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:29:29 GMT
════════════════════════
⌗ Tags: #defensive_security #prompt_injection #cybersecurity #llm_safety #ai_security
Medium
Beyond Naïve Filters: Chaining Guardrails for LLM Prompt Injection
Next step of my LLM safety experiments — moving from simple regex filters to chained guardrails
⤷ Title: DP-Diffusion-TS: Interpretable Time Series Generation with Differential Privacy
════════════════════════
𐀪 Author: David Zagardo
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:22:18 GMT
════════════════════════
⌗ Tags: #ai #data_privacy #cybersecurity #machine_learning #privacy
════════════════════════
𐀪 Author: David Zagardo
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:22:18 GMT
════════════════════════
⌗ Tags: #ai #data_privacy #cybersecurity #machine_learning #privacy
Medium
DP-Diffusion-TS: Interpretable Time Series Generation with Differential Privacy
Generate synthetic time series with formal privacy guarantees: DP-Diffusion-TS combines AI with differential privacy for safe data sharing
⤷ Title: Quantum-Ready Security: Why Your Passwords Need Post-Quantum Protection Today
════════════════════════
𐀪 Author: Bervice
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:17:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #post_quantum #bervice #digital_trust #quantum_computing
════════════════════════
𐀪 Author: Bervice
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:17:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #post_quantum #bervice #digital_trust #quantum_computing
Medium
Quantum-Ready Security: Why Your Passwords Need Post-Quantum Protection Today
Introduction: The Coming Quantum Threat
⤷ Title: Cloudflare Blocks Largest-Ever DDoS Attack at 7.3 Tbps
════════════════════════
𐀪 Author: Raviteja Mureboina
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:13:01 GMT
════════════════════════
⌗ Tags: #ddos #cybersecurity #cloudflare #cyberattack #cybersecurity_news
════════════════════════
𐀪 Author: Raviteja Mureboina
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:13:01 GMT
════════════════════════
⌗ Tags: #ddos #cybersecurity #cloudflare #cyberattack #cybersecurity_news
Medium
Cloudflare Blocks Largest-Ever DDoS Attack at 7.3 Tbps
In May 2025, Cloudflare successfully blocked the largest distributed denial of service (DDoS) attack ever recorded, peaking at a staggering…
⤷ Title: Building an AI-Powered WAF: When Machine Learning Meets Web Security
════════════════════════
𐀪 Author: Yevhenii Zhuk
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:00:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #waf #ai #web
════════════════════════
𐀪 Author: Yevhenii Zhuk
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 23:00:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #waf #ai #web
Medium
Building an AI-Powered WAF: When Machine Learning Meets Web Security
The cybersecurity landscape is evolving rapidly. Traditional Web Application Firewalls, with their static rules and regex patterns…
⤷ Title: Real-time Cryptographic Agility:
The Existential Mandate for the Post-Quantum Era
════════════════════════
𐀪 Author: Peter Lablans
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:51:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #cryptography #post_quantum_cryptography #quantum_computing
The Existential Mandate for the Post-Quantum Era
════════════════════════
𐀪 Author: Peter Lablans
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:51:39 GMT
════════════════════════
⌗ Tags: #cybersecurity #cryptography #post_quantum_cryptography #quantum_computing
Medium
Real-time Cryptographic Agility: The Existential Mandate for the Post-Quantum Era
Introduction
⤷ Title: Monday Cyber Brief — September 29 2025
════════════════════════
𐀪 Author: Keaton @ File Under Risk
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:48:37 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #espionage #ransomware #information_security
════════════════════════
𐀪 Author: Keaton @ File Under Risk
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:48:37 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #espionage #ransomware #information_security
Medium
Monday Cyber Brief — September 29 2025
Exploitation of critical vulnerabilities, espionage campaigns, and ransomware group operations
⤷ Title: How a Simple Python Bind Shell Works
════════════════════════
𐀪 Author: Taulan Zauzanov
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:44:31 GMT
════════════════════════
⌗ Tags: #programming #penetration_testing #pentesting #cybersecurity #information_security
════════════════════════
𐀪 Author: Taulan Zauzanov
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:44:31 GMT
════════════════════════
⌗ Tags: #programming #penetration_testing #pentesting #cybersecurity #information_security
Medium
How a Simple Python Bind Shell Works
For Educational Purposes Only. Use only on hosts/networks you own or have permission to test.
⤷ Title: The Human Factor in Vulnerability Management: Analyst Fatigue, Bias, and Decision Errors
════════════════════════
𐀪 Author: Sai Krishna Kakarla
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:33:44 GMT
════════════════════════
⌗ Tags: #vulnerability_management #human_factors #behavioral_science #risk_management #cybersecurity
════════════════════════
𐀪 Author: Sai Krishna Kakarla
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 22:33:44 GMT
════════════════════════
⌗ Tags: #vulnerability_management #human_factors #behavioral_science #risk_management #cybersecurity
Medium
The Human Factor in Vulnerability Management: Analyst Fatigue, Bias, and Decision Errors
“The strongest defense isn’t faster patching — it’s smarter, supported humans making better decisions.”
⤷ Title: Critical RCE Flaw in Apache Fory’s Python Module (CVE-2025-61622)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:55:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fory #CVE_2025_61622 #cybersecurity #Deserialization #Pyfory #Python #rce #Remote Code Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:55:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Fory #CVE_2025_61622 #cybersecurity #Deserialization #Pyfory #Python #rce #Remote Code Execution
Daily CyberSecurity
Critical RCE Flaw in Apache Fory’s Python Module (CVE-2025-61622)
Apache Fory has a critical RCE vulnerability (CVE-2025-61622) in its pyfory module. An attacker can exploit an unguarded pickle fallback to execute arbitrary code.
⤷ Title: CVE-2025-58384 (CVSS 10): Critical RCE Flaw Found in Watchdoc Print Management Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:49:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_58384 #cybersecurity #Doxense #Print Management #rce #Remote Code Execution #Watchdoc
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:49:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_58384 #cybersecurity #Doxense #Print Management #rce #Remote Code Execution #Watchdoc
Daily CyberSecurity
CVE-2025-58384 (CVSS 10): Critical RCE Flaw Found in Watchdoc Print Management Software
A critical RCE flaw (CVSS 10) in Doxense's Watchdoc print management solution allows unauthenticated attackers to execute code and take control of the print server.
⤷ Title: Broadcom Patches VMware Flaws: Privilege Escalation and Info Disclosure Vulnerabilities Affect VMware Tools and Aria Operations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:42:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Aria Operations #Broadcom #CVE_2025_41244 #cybersecurity #Information Disclosure #privilege escalation #vmware #VMware Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 01:42:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Aria Operations #Broadcom #CVE_2025_41244 #cybersecurity #Information Disclosure #privilege escalation #vmware #VMware Tools
Daily CyberSecurity
Broadcom Patches VMware Flaws: Privilege Escalation and Info Disclosure Vulnerabilities Affect VMware Tools and Aria Operations
Broadcom has patched three flaws in VMware Aria Operations and VMware Tools. The vulnerabilities include privilege escalation and information disclosure.
⤷ Title: Under the Hood of a Kernel Crash: PoC Exposes Race Condition in Qualcomm’s Driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:25:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android security #GPU Driver #kernel vulnerability #KGSL #PoC #Qualcomm #race condition #use after free
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:25:46 +0000
════════════════════════
⌗ Tags: #Vulnerability #Android security #GPU Driver #kernel vulnerability #KGSL #PoC #Qualcomm #race condition #use after free
Daily CyberSecurity
Under the Hood of a Kernel Crash: PoC Exposes Race Condition in Qualcomm's Driver
A new PoC reveals a race condition in Qualcomm's KGSL GPU driver (CVE-2024-38399). Two threads can access the same list simultaneously, leading to a Use-After-Free vulnerability.
⤷ Title: Ongoing APT35 Phishing Campaign Uncovered: Iranian Group Impersonates Video Conferencing Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:20:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT35 #CTI #cybersecurity #Iran #Middle East #Mint Sandstorm #phishing #Stormshield
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:20:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT35 #CTI #cybersecurity #Iran #Middle East #Mint Sandstorm #phishing #Stormshield
Daily CyberSecurity
Ongoing APT35 Phishing Campaign Uncovered: Iranian Group Impersonates Video Conferencing Services
Stormshield CTI uncovers ongoing APT35 phishing infrastructure impersonating video conferencing services to target organizations in Israel and other regions.
⤷ Title: NCSC Exposes Advanced Bootkit: RayInitiator and LINE VIPER Malware Found on Cisco ASA Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ArcaneDoor #Bootkit #Cisco ASA #cybersecurity #LINE VIPER #malware #NCSC #RayInitiator #shellcode loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:15:24 +0000
════════════════════════
⌗ Tags: #Malware #ArcaneDoor #Bootkit #Cisco ASA #cybersecurity #LINE VIPER #malware #NCSC #RayInitiator #shellcode loader
Daily CyberSecurity
NCSC Exposes Advanced Bootkit: RayInitiator and LINE VIPER Malware Found on Cisco ASA Devices
NCSC exposes RayInitiator, a bootkit for Cisco ASA 5500-X devices without Secure Boot, which deploys the LINE VIPER shellcode loader for persistent and stealthy attacks.
⤷ Title: Rent-a-Domain: Report Details How APTs and Cybercriminals Abuse DDNS Services for Malicious Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:10:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #C2 #Cybercrime #DDNS #Dynamic DNS #malware #phishing #Silent Push #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:10:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #C2 #Cybercrime #DDNS #Dynamic DNS #malware #phishing #Silent Push #threat intelligence
Daily CyberSecurity
Rent-a-Domain: Report Details How APTs and Cybercriminals Abuse DDNS Services for Malicious Infrastructure
Silent Push details how cybercriminals and APTs are misusing DDNS services for stealthy C2 servers, phishing, and malware delivery. Dozens of high-profile groups are involved.
⤷ Title: Acreed: The New Infostealer Using BNB Smart Chain and Steam Profiles for Stealthy C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:05:58 +0000
════════════════════════
⌗ Tags: #Malware #Acreed #Binance Smart Chain #cryptocurrency #Cybercrime #Infostealer #Lumma #malware #Steam #Vidar
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:05:58 +0000
════════════════════════
⌗ Tags: #Malware #Acreed #Binance Smart Chain #cryptocurrency #Cybercrime #Infostealer #Lumma #malware #Steam #Vidar
Daily CyberSecurity
Acreed: The New Infostealer Using BNB Smart Chain and Steam Profiles for Stealthy C2
The new infostealer Acreed is rapidly gaining market share post-Lumma takedown. It uses BNB Smart Chain and Steam profiles for C2, with a focus on crypto theft.
⤷ Title: Olymp Loader: New Assembly-Based MaaS Is a Turnkey Solution for Low-Tier Cybercriminals
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:01:23 +0000
════════════════════════
⌗ Tags: #Malware #Assembly #Crypter #Cybercrime #FUD #MaaS #malware #Olymp Loader #Outpost24
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:01:23 +0000
════════════════════════
⌗ Tags: #Malware #Assembly #Crypter #Cybercrime #FUD #MaaS #malware #Olymp Loader #Outpost24
Daily CyberSecurity
Olymp Loader: New Assembly-Based MaaS Is a Turnkey Solution for Low-Tier Cybercriminals
Olymp Loader, a new assembly-based MaaS, has emerged in underground markets. It's a turnkey solution for cybercriminals, with stealth and persistence features.
⤷ Title: Kicking off Cybersecurity Awareness Month 2025: Researcher spotlights and enhanced incentives
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
The GitHub Blog
Kicking off Cybersecurity Awareness Month 2025: Researcher spotlights and enhanced incentives
For this year’s Cybersecurity Awareness Month, GitHub’s Bug Bounty team is offering some additional incentives to security researchers!