⤷ Title: Write Up Lab: Visible error-based SQL injection
════════════════════════
𐀪 Author: Velskynotfound
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:02:23 GMT
════════════════════════
⌗ Tags: #sql_injection #writeup #portswigger #web_security #portswigger_lab
════════════════════════
𐀪 Author: Velskynotfound
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:02:23 GMT
════════════════════════
⌗ Tags: #sql_injection #writeup #portswigger #web_security #portswigger_lab
Medium
Write Up Lab: Visible error-based SQL injection
Halo para pembaca, bagaimana kabar kalian? saya harap kalian dalam keadaan yang baik dan sehat. Sebab pada artikel kali ini, saya akan…
⤷ Title: Cavalry Werewolf APT Targets Russian Agencies with FoalShell and Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:55:55 +0000
════════════════════════
⌗ Tags: #Malware #APT #BI.ZONE #Cavalry Werewolf #cyber_espionage #FoalShell #phishing #russia #StallionRAT #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:55:55 +0000
════════════════════════
⌗ Tags: #Malware #APT #BI.ZONE #Cavalry Werewolf #cyber_espionage #FoalShell #phishing #russia #StallionRAT #Telegram C2
Daily CyberSecurity
Cavalry Werewolf APT Targets Russian Agencies with FoalShell and Telegram C2
The Cavalry Werewolf APT is using FoalShell reverse shells and StallionRAT backdoors, controlled via Telegram, to target Russian state agencies and energy/mining firms.
⤷ Title: Confucius APT Evolves: Espionage Group Shifts from WooperStealer to Advanced Python Backdoor AnonDoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:48:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anondoor #APT #Confucius Group #cyber_espionage #DLL Sideloading #Pakistan #Python RAT #Wooperstealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:48:46 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anondoor #APT #Confucius Group #cyber_espionage #DLL Sideloading #Pakistan #Python RAT #Wooperstealer
Daily CyberSecurity
Confucius APT Evolves: Espionage Group Shifts from WooperStealer to Advanced Python Backdoor AnonDoor
The Confucius APT group is evolving, abandoning WooperStealer for the sophisticated AnonDoor Python backdoor to maintain stealthy, long-term espionage in South Asia.
⤷ Title: UAT-8099: Chinese Group Uses BadIIS Malware on Compromised Servers for SEO Fraud and Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:42:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BadIIS #Cisco Talos #Cobalt Strike #Credential Theft #Cybercrime #IIS #SEO Fraud #UAT_8099
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:42:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BadIIS #Cisco Talos #Cobalt Strike #Credential Theft #Cybercrime #IIS #SEO Fraud #UAT_8099
Daily CyberSecurity
UAT-8099: Chinese Group Uses BadIIS Malware on Compromised Servers for SEO Fraud and Credential Theft
Cisco Talos exposed UAT-8099, a Chinese group compromising IIS servers for SEO fraud, using BadIIS malware and Cobalt Strike to steal credentials and manipulate search rankings.
⤷ Title: WARMCOOKIE Resurfaces After Takedown: New Variant Adds Stealth Handlers, Uses Expired C2 Certificates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:05:16 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #cybersecurity #Elastic Security Labs #MaaS #malware #Operation Endgame #persistence #WarmCookie
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:05:16 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #C2 #cybersecurity #Elastic Security Labs #MaaS #malware #Operation Endgame #persistence #WarmCookie
Daily CyberSecurity
WARMCOOKIE Resurfaces After Takedown: New Variant Adds Stealth Handlers, Uses Expired C2 Certificates
WARMCOOKIE has resurfaced post-Operation Endgame with new execution handlers, a MaaS model, and evasive techniques like disguised scheduled tasks using company names.
⤷ Title: Researcher Details Zero-Day Linux/Android Kernel Flaw (CVE-2025-38352)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:01:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #android #CVE_2025_38352 #Kernel Security #Linux Kernel #POSIX Timer #privilege escalation #race condition #TOCTOU
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:01:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #android #CVE_2025_38352 #Kernel Security #Linux Kernel #POSIX Timer #privilege escalation #race condition #TOCTOU
Daily CyberSecurity
Researcher Details Zero-Day Linux/Android Kernel Flaw (CVE-2025-38352)
A High-severity TOCTOU race condition (CVE-2025-38352) in the Linux/Android POSIX CPU Timer subsystem can lead to kernel crashes and privilege escalation.
⤷ Title: Starting Over at 22: My 100 Days Back Into Cybersecurity
════════════════════════
𐀪 Author: Andrej Glavnik
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:00:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #blog #freelancing #hacking
════════════════════════
𐀪 Author: Andrej Glavnik
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:00:58 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #blog #freelancing #hacking
Medium
Starting Over at 22: My 100 Days Back Into Cybersecurity
Prologue: Boot Sequence Initiated
⤷ Title: Findomain: Herramienta Fundamental para la Enumeración Pasiva de Subdominios
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:02:07 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #technology #hacking #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:02:07 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #technology #hacking #bug_bounty
Medium
Findomain: Herramienta Fundamental para la Enumeración Pasiva de Subdominios
Descubre Findomain, una herramienta clave en el bug bounty para el reconocimiento rápido y pasivo de subdominios.
⤷ Title: The Truth About Cybersecurity: Myths vs. Reality
════════════════════════
𐀪 Author: Cyber Security Research
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:52:57 GMT
════════════════════════
⌗ Tags: #infosec #security #cyber_sec #myths #reality
════════════════════════
𐀪 Author: Cyber Security Research
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:52:57 GMT
════════════════════════
⌗ Tags: #infosec #security #cyber_sec #myths #reality
Medium
The Truth About Cybersecurity: Myths vs. Reality
Cybersecurity is often misunderstood, with pervasive myths hindering effective defense strategies. This article debunks common…
⤷ Title: Navigating the Complexities of Cybersecurity Compliance
════════════════════════
𐀪 Author: Cyber Security Research
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:47:31 GMT
════════════════════════
⌗ Tags: #infosec #cyber_sec #risk #compliance #reg
════════════════════════
𐀪 Author: Cyber Security Research
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:47:31 GMT
════════════════════════
⌗ Tags: #infosec #cyber_sec #risk #compliance #reg
Medium
Navigating the Complexities of Cybersecurity Compliance
Master cybersecurity compliance complexities, covering frameworks like GDPR, HIPAA, and CMMC. Implement robust data protection, automate…
⤷ Title: Brick by Brick: Why I’m Choosing to Document My Cybersecurity Journey
════════════════════════
𐀪 Author: Boluwatife shopeju
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:54:15 GMT
════════════════════════
⌗ Tags: #information_technology #beginners_guide #cybersecurity #technology #cybersecurity_journey
════════════════════════
𐀪 Author: Boluwatife shopeju
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:54:15 GMT
════════════════════════
⌗ Tags: #information_technology #beginners_guide #cybersecurity #technology #cybersecurity_journey
Medium
Brick by Brick: Why I’m Choosing to Document My Cybersecurity Journey
I almost didn’t choose cybersecurity.
⤷ Title: Hack the Box — Shoppy — WriteUp
════════════════════════
𐀪 Author: Emre A.
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:28:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #linux_priv_esc #hackthebox_writeup #penetration_testing
════════════════════════
𐀪 Author: Emre A.
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:28:37 GMT
════════════════════════
⌗ Tags: #cybersecurity #linux_priv_esc #hackthebox_writeup #penetration_testing
Medium
Hack the Box — Shoppy — WriteUp
About Shoppy
⤷ Title: Summary of “Evaluating the Effectiveness and Robustness of Visual Similarity-based Phishing…
════════════════════════
𐀪 Author: Shadman Hossain
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:28:13 GMT
════════════════════════
⌗ Tags: #llm #phishing #phishing_awareness #ai #cybersecurity
════════════════════════
𐀪 Author: Shadman Hossain
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:28:13 GMT
════════════════════════
⌗ Tags: #llm #phishing #phishing_awareness #ai #cybersecurity
Medium
Summary of “Evaluating the Effectiveness and Robustness of Visual Similarity-based Phishing Detection Models”
ACM Reference Format:
⤷ Title: Dropbox Passwords Is Shutting Down: What Users Need to Know | VBM
════════════════════════
𐀪 Author: Marcus Spencer
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:12:55 GMT
════════════════════════
⌗ Tags: #android #technology #cybersecurity #security #ios
════════════════════════
𐀪 Author: Marcus Spencer
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 01:12:55 GMT
════════════════════════
⌗ Tags: #android #technology #cybersecurity #security #ios
⤷ Title: Comprehensive Report on Bias in Large Language Models (LLMs)
════════════════════════
𐀪 Author: Emile J Fagerstrom IV #Bofaf #t3 #1CallWest
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:14:03 GMT
════════════════════════
⌗ Tags: #machine_learning #artificial_intelligence #data_science #programming #cybersecurity
════════════════════════
𐀪 Author: Emile J Fagerstrom IV #Bofaf #t3 #1CallWest
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 00:14:03 GMT
════════════════════════
⌗ Tags: #machine_learning #artificial_intelligence #data_science #programming #cybersecurity
Medium
Comprehensive Report on Bias in Large Language Models (LLMs)
By Emile J Fagerstrom IV #1CallWest #Bofaf #t3
⤷ Title: Red Hat Confirms Breach After Hackers Steal 570GB of Client Network Blueprints and Auth Tokens from GitLab
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 04:00:07 +0000
════════════════════════
⌗ Tags: #Data Leak #Authentication Tokens #CERs #Crimson Collective #Customer Data #cybercrime #GitHub Breach #Red Hat
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 04:00:07 +0000
════════════════════════
⌗ Tags: #Data Leak #Authentication Tokens #CERs #Crimson Collective #Customer Data #cybercrime #GitHub Breach #Red Hat
Penetration Testing Tools
Red Hat Confirms Breach After Hackers Steal 570GB of Client Network Blueprints and Auth Tokens from GitLab
Red Hat confirmed a breach of its consulting division's GitLab after the Crimson Collective claimed to steal 570GB of data, including client network blueprints and auth tokens.
⤷ Title: CERT-UA Warns: New Espionage Campaign Distributes CABINETRAT Backdoor via Signal Messenger XLL Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:56:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anti_Analysis #Backdoor #CABINETRAT #CERT_UA #Cyber Espionage #Signal #UAC_0245 #Ukraine #XLL
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:56:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Anti_Analysis #Backdoor #CABINETRAT #CERT_UA #Cyber Espionage #Signal #UAC_0245 #Ukraine #XLL
Penetration Testing Tools
CERT-UA Warns: New Espionage Campaign Distributes CABINETRAT Backdoor via Signal Messenger XLL Files
CERT-UA uncovered a campaign (UAC-0245) using Signal to deliver malicious XLL files and inject the full-featured CABINETRAT backdoor. The malware evades sandboxes by checking system specs.
⤷ Title: Eufy Paid Users $2 Per Video of Staged Thefts to Train AI Security Cameras
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:54:20 +0000
════════════════════════
⌗ Tags: #Data Leak #AI training #Anker #data collection #Eufy #privacy #Security Camera #Video Data #Video Donation Program
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:54:20 +0000
════════════════════════
⌗ Tags: #Data Leak #AI training #Anker #data collection #Eufy #privacy #Security Camera #Video Data #Video Donation Program
Penetration Testing Tools
Eufy Paid Users $2 Per Video of Staged Thefts to Train AI Security Cameras
Eufy, the maker of Anker security cameras, ran a controversial program that paid users $2 per video of staged thefts to gather training data for its AI algorithms.
⤷ Title: Exploited Routers: Flaw in Milesight Industrial Devices Used for Mass Smishing in Europe
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:50:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CVE_2023_43261 #cybersecurity #Milesight #router #SEKOIA #Smishing #SMS API #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:50:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CVE_2023_43261 #cybersecurity #Milesight #router #SEKOIA #Smishing #SMS API #vulnerability
Penetration Testing Tools
Exploited Routers: Flaw in Milesight Industrial Devices Used for Mass Smishing in Europe
A critical flaw in Milesight industrial routers is being exploited to launch mass smishing campaigns across Europe, exposing 572 devices and using SMS APIs to send phishing links.
⤷ Title: Chrome 141 Stable Released: Fixes High-Severity WebGPU and Video Heap Overflow Flaws
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:48:22 +0000
════════════════════════
⌗ Tags: #Google #Vulnerability #Chrome 141 #Code Execution #CVE_2025_11205 #Google Chrome #Heap Overflow #security update #V8 engine #WebGPU
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:48:22 +0000
════════════════════════
⌗ Tags: #Google #Vulnerability #Chrome 141 #Code Execution #CVE_2025_11205 #Google Chrome #Heap Overflow #security update #V8 engine #WebGPU
Penetration Testing Tools
Chrome 141 Stable Released: Fixes High-Severity WebGPU and Video Heap Overflow Flaws
Google promoted Chrome 141 to Stable, patching 21 flaws, including two High-severity Heap Overflows in WebGPU (CVE-2025-11205) and Video, which could lead to RCE.
⤷ Title: Meta Denies Microphone Spying, Confirms AI Chat Data Will Now Be Used for Targeted Ads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:46:07 +0000
════════════════════════
⌗ Tags: #Data Leak #Adam Mosseri #AI Chatbot #Conspiracy Theory #Instagram #Meta #microphone #privacy #Targeted Ads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:46:07 +0000
════════════════════════
⌗ Tags: #Data Leak #Adam Mosseri #AI Chatbot #Conspiracy Theory #Instagram #Meta #microphone #privacy #Targeted Ads
Penetration Testing Tools
Meta Denies Microphone Spying, Confirms AI Chat Data Will Now Be Used for Targeted Ads
Instagram head Adam Mosseri debunked the microphone myth but confirmed Meta will use user interactions with its AI chatbot to create hyper-targeted ads starting Dec. 16.