⤷ Title: Wafw00f: Desvelando el Escudo Oculto de las Aplicaciones Web
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:02:09 GMT
════════════════════════
⌗ Tags: #hacking #waf_bypass #technology #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:02:09 GMT
════════════════════════
⌗ Tags: #hacking #waf_bypass #technology #bug_bounty #cybersecurity
Medium
Wafw00f: Desvelando el Escudo Oculto de las Aplicaciones Web
Descubre por qué WafW00f es esencial para identificar Web Application Firewalls, planear bypasses específicos y optimizar tu estrategia.
⤷ Title: Tuesday Morning Threat Report: Oct 7, 2025
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:30:36 GMT
════════════════════════
⌗ Tags: #hacking #gemini #bitcoin #cybersecurity
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:30:36 GMT
════════════════════════
⌗ Tags: #hacking #gemini #bitcoin #cybersecurity
Medium
Tuesday Morning Threat Report: Oct 7, 2025
Google patches Gemini vulnerabilities exposing personal data, while the U.K. records its largest-ever Bitcoin seizure following an arrest
⤷ Title: Security in CI/CD Pipelines
════════════════════════
𐀪 Author: Cyberoptic Security
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:43:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #ci_cd_pipeline
════════════════════════
𐀪 Author: Cyberoptic Security
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:43:24 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_development #ci_cd_pipeline
Medium
Security in CI/CD Pipelines
This guide covers the essential security checks every small team should use. Most of these tools are free or cheap, and they run…
⤷ Title: How Cybersecurity OEMs Can Turn Risk into Revenue
════════════════════════
𐀪 Author: Dr. Deep Pandey
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:59:14 GMT
════════════════════════
⌗ Tags: #cloudcsf #auditsecintel #cybersecurity #pciai #ciso2ai
════════════════════════
𐀪 Author: Dr. Deep Pandey
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:59:14 GMT
════════════════════════
⌗ Tags: #cloudcsf #auditsecintel #cybersecurity #pciai #ciso2ai
Medium
How Cybersecurity OEMs Can Turn Risk into Revenue
How Cybersecurity OEMs Can Turn Risk into Revenue
⤷ Title: HackTheBox Windows Events and Hunting Evil Part 2: Leveling Up with Sysmon
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:34:36 GMT
════════════════════════
⌗ Tags: #technology #women_in_tech #tech #hackthebox #cybersecurity
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:34:36 GMT
════════════════════════
⌗ Tags: #technology #women_in_tech #tech #hackthebox #cybersecurity
Medium
HackTheBox Windows Events and Hunting Evil Part 2: Leveling Up with Sysmon
Welcome back to Part 2 of our “Finding Evil” journey! If Windows Event Logs were a detective’s notebook, then Sysmon is like giving that…
👍1
⤷ Title: FSF Unveils LibrePhone Project to Bring Complete Computing Freedom to Mobile Devices
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:59:16 +0000
════════════════════════
⌗ Tags: #Technology #AI Ethics #Digital Rights #Free Software Foundation #FSF #GNU #LibrePhone #Mobile Freedom #open source
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:59:16 +0000
════════════════════════
⌗ Tags: #Technology #AI Ethics #Digital Rights #Free Software Foundation #FSF #GNU #LibrePhone #Mobile Freedom #open source
Penetration Testing Tools
FSF Unveils LibrePhone Project to Bring Complete Computing Freedom to Mobile Devices
The FSF celebrated its 40th anniversary by launching the LibrePhone project, an ambitious initiative to create a fully open and free-software mobile computing ecosystem.
⤷ Title: US Army NGC2 Prototype Had “Critical Deficiencies” in Zero Trust Security Before Ivy Sting Trials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:56:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #Anduril #cybersecurity #Defense #Kiwuli Memo #NGC2 #Palantir #US Army #Zero Trust
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:56:41 +0000
════════════════════════
⌗ Tags: #Vulnerability #Anduril #cybersecurity #Defense #Kiwuli Memo #NGC2 #Palantir #US Army #Zero Trust
Penetration Testing Tools
US Army NGC2 Prototype Had "Critical Deficiencies" in Zero Trust Security Before Ivy Sting Trials
A leaked memo revealed the US Army's NGC2 system had "critical deficiencies," including no RBAC and unverified cloud components, violating Zero Trust principles before testing.
⤷ Title: Discord Data Breach: Hackers Steal User IDs and Government ID Images from Third-Party Contractor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:54:51 +0000
════════════════════════
⌗ Tags: #Data Leak #data breach #Discord #Extortion #Government ID #PII #third_party risk #Trust & Safety
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:54:51 +0000
════════════════════════
⌗ Tags: #Data Leak #data breach #Discord #Extortion #Government ID #PII #third_party risk #Trust & Safety
Penetration Testing Tools
Discord Data Breach: Hackers Steal User IDs and Government ID Images from Third-Party Contractor
Discord confirmed a breach at a third-party contractor exposed PII, limited payment details, and a small number of government ID images submitted for age verification.
⤷ Title: Hacker Alliance Demands $989M Ransom, Threatens to Leak 1 Billion Salesforce Records
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:53:05 +0000
════════════════════════
⌗ Tags: #Data Leak #Data Extortion #Data Leak Site #ransomware #Salesforce #Scattered LapSus Hunters #Scattered Spider #ShinyHunters
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:53:05 +0000
════════════════════════
⌗ Tags: #Data Leak #Data Extortion #Data Leak Site #ransomware #Salesforce #Scattered LapSus Hunters #Scattered Spider #ShinyHunters
Penetration Testing Tools
Hacker Alliance Demands $989M Ransom, Threatens to Leak 1 Billion Salesforce Records
A hacker alliance launched a leak site demanding $989.45M ransom to withhold 1 billion records stolen from Salesforce customers via OAuth token abuse and vishing.
⤷ Title: Zimbra Zero-Day (CVE-2025-27915) Actively Exploited to Steal Credentials via Malicious Calendar Invites
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:46:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Theft #CVE_2025_27915 #Cyber Espionage #ICS File #StrikeReady #XSS #zero_day #Zimbra
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:46:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Theft #CVE_2025_27915 #Cyber Espionage #ICS File #StrikeReady #XSS #zero_day #Zimbra
Penetration Testing Tools
Zimbra Zero-Day (CVE-2025-27915) Actively Exploited to Steal Credentials via Malicious Calendar Invites
A ZCS zero-day (CVE-2025-27915, CVSS 7.8) was actively exploited since Jan. 2025. Attackers used malicious calendar .ICS files to inject XSS and steal Zimbra webmail credentials.
⤷ Title: Oracle EBS Zero-Day CVE-2025-61882 (CVSS 9.8) Being Actively Exploited by Clop Ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:45:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #Clop #Critical #CVE_2025_61882 #Oracle EBS #ransomware #RCE #Unauthenticated #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:45:04 +0000
════════════════════════
⌗ Tags: #Vulnerability #Clop #Critical #CVE_2025_61882 #Oracle EBS #ransomware #RCE #Unauthenticated #zero_day
Penetration Testing Tools
Oracle EBS Zero-Day CVE-2025-61882 (CVSS 9.8) Being Actively Exploited by Clop Ransomware
A Critical (CVSS 9.8) zero-day RCE flaw (CVE-2025-61882) in Oracle E-Business Suite's BI Publisher component is being actively exploited by the Clop group for data theft.
⤷ Title: CometJacking Attack Hijacks Perplexity’s AI Browser to Steal Gmail and Calendar Data with One Click
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:43:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI browser #CometJacking #cybersecurity #Data Exfiltration #LayerX #Perplexity Comet #Prompt Injection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:43:09 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI browser #CometJacking #cybersecurity #Data Exfiltration #LayerX #Perplexity Comet #Prompt Injection
Penetration Testing Tools
CometJacking Attack Hijacks Perplexity's AI Browser to Steal Gmail and Calendar Data with One Click
LayerX disclosed CometJacking, a critical flaw that exploits a single crafted link to silently hijack Perplexity Comet’s AI agent, stealing Gmail and Calendar data.
⤷ Title: Confucius APT Targets Pakistan with WooperStealer and New Python-Based Anondoor Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Anondoor #APT #Confucius Group #Cyber Espionage #DLL Sideloading #Fortinet #Pakistan #WooperStealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:40:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Anondoor #APT #Confucius Group #Cyber Espionage #DLL Sideloading #Fortinet #Pakistan #WooperStealer
Penetration Testing Tools
Confucius APT Targets Pakistan with WooperStealer and New Python-Based Anondoor Backdoor
The Confucius APT is actively targeting Pakistani entities with the Anondoor Python backdoor and WooperStealer, using DLL sideloading and sophisticated phishing to ensure long-term espionage.
⤷ Title: Critical Unity Flaw CVE-2025-59489 Exposes Games Built Since 2017 to Local Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:39:35 +0000
════════════════════════
⌗ Tags: #Vulnerability #Code Execution #CVE_2025_59489 #Game Engine #Local File Inclusion #RCE #Unity #Unity Runtime
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:39:35 +0000
════════════════════════
⌗ Tags: #Vulnerability #Code Execution #CVE_2025_59489 #Game Engine #Local File Inclusion #RCE #Unity #Unity Runtime
Penetration Testing Tools
Critical Unity Flaw CVE-2025-59489 Exposes Games Built Since 2017 to Local Code Execution
A critical Unity bug (CVE-2025-59489) exposes games built since Unity 2017.1 to local code execution via argument injection. Developers must recompile and republish their titles.
⤷ Title: Detour Dog: Stealthy DNS Malware Campaign Hijacks 30,000+ Websites to Deliver Strela Stealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:34:34 +0000
════════════════════════
⌗ Tags: #Malware #Command and Control #Detour Dog #DNS TXT #Infoblox #malware #StarFish #Strela Stealer #Web Compromise
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:34:34 +0000
════════════════════════
⌗ Tags: #Malware #Command and Control #Detour Dog #DNS TXT #Infoblox #malware #StarFish #Strela Stealer #Web Compromise
Penetration Testing Tools
Detour Dog: Stealthy DNS Malware Campaign Hijacks 30,000+ Websites to Deliver Strela Stealer
Infoblox uncovered the Detour Dog campaign, which compromises 30K+ websites and uses covert DNS TXT records for C2 to deliver the StarFish shell and Strela Stealer malware.
⤷ Title: OpenAI Turns ChatGPT Into a “Super App” with the New Apps SDK Integration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:18:11 +0000
════════════════════════
⌗ Tags: #Technology #AI Ecosystem #AI Integration #Apps SDK #Canva #ChatGPT #Developer Tools #OpenAI #Spotify #Super App #uber
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:18:11 +0000
════════════════════════
⌗ Tags: #Technology #AI Ecosystem #AI Integration #Apps SDK #Canva #ChatGPT #Developer Tools #OpenAI #Spotify #Super App #uber
Daily CyberSecurity
OpenAI Turns ChatGPT Into a “Super App” with the New Apps SDK Integration
OpenAI unveils the Apps SDK, transforming ChatGPT into a powerful “super app” where users can connect apps like Spotify, Canva, and Uber.
⤷ Title: OpenAI Partners with AMD, Adopting Instinct MI450 GPUs for a 6 GW AI Computing Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:13:27 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #AMD #Equity Stake #GPU #Instinct MI450 #OpenAI #Sam Altman #Strategic Alliance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:13:27 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #AMD #Equity Stake #GPU #Instinct MI450 #OpenAI #Sam Altman #Strategic Alliance
Daily CyberSecurity
OpenAI Partners with AMD, Adopting Instinct MI450 GPUs for a 6 GW AI Computing Infrastructure
OpenAI selected AMD as a "core strategic computing partner," adopting Instinct MI450 GPUs for a 6 GW AI infrastructure. OpenAI can acquire a 10% equity stake in AMD.
⤷ Title: ChatGPT Reaches 800 Million Weekly Users, Cementing Dominance in Generative AI Adoption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:08:16 +0000
════════════════════════
⌗ Tags: #Technology #AgentKit #Apps SDK #ChatGPT #DevDay #Generative AI #OpenAI #Sam Altman #Weekly Active Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:08:16 +0000
════════════════════════
⌗ Tags: #Technology #AgentKit #Apps SDK #ChatGPT #DevDay #Generative AI #OpenAI #Sam Altman #Weekly Active Users
Daily CyberSecurity
ChatGPT Reaches 800 Million Weekly Users, Cementing Dominance in Generative AI Adoption
OpenAI CEO Sam Altman announced at DevDay that ChatGPT now has 800 million weekly active users, making it the world's most dominant generative AI platform.
⤷ Title: Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:04:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_10729 #Denial of Service #Qt SVG #rce #SVG Parsing #use after free
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:04:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_10729 #Denial of Service #Qt SVG #rce #SVG Parsing #use after free
Daily CyberSecurity
Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
The Qt Group patched two critical flaws in Qt SVG: a UAF bug (CVE-2025-10729) that risks RCE, and recursive pattern element (CVE-2025-10728) leading to stack overflow DoS.
⤷ Title: Elastic Fixes Multiple High-Severity Vulnerabilities in Kibana and Elasticsearch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:27:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_25009 #Elastic #Elasticsearch #Kibana #security update #ssrf #vega #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:27:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_25009 #Elastic #Elasticsearch #Kibana #security update #ssrf #vega #XSS
Daily CyberSecurity
Elastic Fixes Multiple High-Severity Vulnerabilities in Kibana and Elasticsearch
Elastic patched five flaws in Kibana/Elasticsearch, including three Critical XSS issues (CVE-2025-25009) and credential leaks, urging immediate upgrades to v8.18.8+.
⤷ Title: Oracle EBS Zero-Day (CVE-2025-61882) Under Active RCE Exploitation by GRACEFUL SPIDER
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:11:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Clop #CrowdStrike #CVE_2025_61882 #cybersecurity #GRACEFUL SPIDER #Oracle EBS #rce #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:11:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Clop #CrowdStrike #CVE_2025_61882 #cybersecurity #GRACEFUL SPIDER #Oracle EBS #rce #zero_day
Daily CyberSecurity
Oracle EBS Zero-Day (CVE-2025-61882) Under Active RCE Exploitation by GRACEFUL SPIDER
CrowdStrike warns that the Critical RCE zero-day (CVE-2025-61882) in Oracle E-Business Suite is being actively exploited by GRACEFUL SPIDER (Clop affiliate) for corporate data theft. Patch immediately.