⤷ Title: Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:04:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_10729 #Denial of Service #Qt SVG #rce #SVG Parsing #use after free
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:04:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_10729 #Denial of Service #Qt SVG #rce #SVG Parsing #use after free
Daily CyberSecurity
Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
The Qt Group patched two critical flaws in Qt SVG: a UAF bug (CVE-2025-10729) that risks RCE, and recursive pattern element (CVE-2025-10728) leading to stack overflow DoS.
⤷ Title: Elastic Fixes Multiple High-Severity Vulnerabilities in Kibana and Elasticsearch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:27:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_25009 #Elastic #Elasticsearch #Kibana #security update #ssrf #vega #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:27:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_25009 #Elastic #Elasticsearch #Kibana #security update #ssrf #vega #XSS
Daily CyberSecurity
Elastic Fixes Multiple High-Severity Vulnerabilities in Kibana and Elasticsearch
Elastic patched five flaws in Kibana/Elasticsearch, including three Critical XSS issues (CVE-2025-25009) and credential leaks, urging immediate upgrades to v8.18.8+.
⤷ Title: Oracle EBS Zero-Day (CVE-2025-61882) Under Active RCE Exploitation by GRACEFUL SPIDER
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:11:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Clop #CrowdStrike #CVE_2025_61882 #cybersecurity #GRACEFUL SPIDER #Oracle EBS #rce #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:11:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Clop #CrowdStrike #CVE_2025_61882 #cybersecurity #GRACEFUL SPIDER #Oracle EBS #rce #zero_day
Daily CyberSecurity
Oracle EBS Zero-Day (CVE-2025-61882) Under Active RCE Exploitation by GRACEFUL SPIDER
CrowdStrike warns that the Critical RCE zero-day (CVE-2025-61882) in Oracle E-Business Suite is being actively exploited by GRACEFUL SPIDER (Clop affiliate) for corporate data theft. Patch immediately.
⤷ Title: Critical Flaw CVE-2025-59159 (CVSS 9.7) in SillyTavern Allows Full Remote Control of Local AI Instances
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59159 #DNS Rebinding #LLM #Remote Access #security advisory #SillyTavern #WebUI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:48:07 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59159 #DNS Rebinding #LLM #Remote Access #security advisory #SillyTavern #WebUI
Daily CyberSecurity
Critical Flaw CVE-2025-59159 (CVSS 9.7) in SillyTavern Allows Full Remote Control of Local AI Instances
A Critical (CVSS 9.7) DNS rebinding flaw (CVE-2025-59159) in the SillyTavern LLM interface allows remote attackers to seize full control of local AI instances and steal API keys.
⤷ Title: Critical RCE (CVE-2025-10035) in GoAnywhere MFT Used by Medusa Ransomware Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:38:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #critical #cybersecurity #Deserialization #GoAnywhere MFT #Medusa Ransomware #rce #Storm_1175
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:38:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #critical #cybersecurity #Deserialization #GoAnywhere MFT #Medusa Ransomware #rce #Storm_1175
Daily CyberSecurity
Critical RCE (CVE-2025-10035) in GoAnywhere MFT Used by Medusa Ransomware Group
A Critical (CVSS 10.0) zero-day RCE flaw (CVE-2025-10035) in GoAnywhere MFT is being actively exploited by the Medusa ransomware group, Storm-1175. Patch immediately.
⤷ Title: Critical Flaw CVE-2025-36356 (CVSS 9.3) in IBM Security Verify Access Allows Root Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_36356 #IBM #Identity Access #privilege escalation #rce #security update #Security Verify Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 01:32:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_36356 #IBM #Identity Access #privilege escalation #rce #security update #Security Verify Access
Daily CyberSecurity
Critical Flaw CVE-2025-36356 (CVSS 9.3) in IBM Security Verify Access Allows Root Privilege Escalation
IBM patched a Critical (CVSS 9.3) LPE flaw (CVE-2025-36356) in Verify Access/Identity Access that allows locally authenticated users to escalate privileges to root. Update to v10.0.9.0-IF3 now.
⤷ Title: Rapid7 Details Cisco ASA Zero-Day Exploit Chain (CVE-2025-20362 & CVE-2025-20333)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #buffer overflow #cisco #CVE_2025_20333 #FTD #Rapid7 #rce #WebVPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ASA #buffer overflow #cisco #CVE_2025_20333 #FTD #Rapid7 #rce #WebVPN
Daily CyberSecurity
Rapid7 Details Cisco ASA Zero-Day Exploit Chain (CVE-2025-20362 & CVE-2025-20333)
Rapid7 exposed the unauthenticated RCE chain in Cisco ASA/FTD. CVE-2025-20362 bypasses auth to reach CVE-2025-20333, a buffer overflow in the WebVPN Lua script. Patch immediately.
⤷ Title: PoC Released for Linux Kernel Escalates Privileges Flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:15:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #Linux Kernel #Networking #privilege escalation #QFQ Scheduler #root #UAF #use after free
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:15:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #Linux Kernel #Networking #privilege escalation #QFQ Scheduler #root #UAF #use after free
Daily CyberSecurity
PoC Released for Linux Kernel Escalates Privileges Flaw
A critical UAF flaw in the Linux Traffic Control subsystem (CVE-2023-4921, CVSS 7.8) allows local privilege escalation to root. A fully detailed PoC exploit has been released.
⤷ Title: Chinese APT Launches Spearphishing Campaign, Using Fake Cloudflare Lure to Deliver PlugX Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:11:22 +0000
════════════════════════
⌗ Tags: #Cyber Security #Aviation Sector #Chinese APT #cloudflare #DLL Sideloading #Espionage #PlugX #Spearphishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:11:22 +0000
════════════════════════
⌗ Tags: #Cyber Security #Aviation Sector #Chinese APT #cloudflare #DLL Sideloading #Espionage #PlugX #Spearphishing
Daily CyberSecurity
Chinese APT Launches Spearphishing Campaign, Using Fake Cloudflare Lure to Deliver PlugX Malware
A Chinese APT used fake Cloudflare verification pages and malicious LNK files to inject PlugX via DLL sideloading into a Serbian aviation agency, aiming for long-term espionage.
⤷ Title: New Yurei Ransomware Emerges: Go-Based Variant Uses Advanced Anti-Forensics for Irreversible Double Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:10:12 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cyfirma #Double Extortion #Golang #lateral movement #Prince ransomware #ransomware #Yurei ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:10:12 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cyfirma #Double Extortion #Golang #lateral movement #Prince ransomware #ransomware #Yurei ransomware
Daily CyberSecurity
New Yurei Ransomware Emerges: Go-Based Variant Uses Advanced Anti-Forensics for Irreversible Double Extortion
CYFIRMA uncovered Yurei Ransomware, a sophisticated Go-based double-extortion threat that uses ChaCha20 encryption, anti-forensic wipes, and disguises itself as WindowsUpdate.exe to propagate over SMB.
⤷ Title: SideWinder APT Launches Operation SouthNet, Weaponizing Netlify and Pages.dev for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:05:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Credential Theft #Espionage #Maritime #Myanmar #Netlify #Operation SouthNet #phishing #SideWinder
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 00:05:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #Credential Theft #Espionage #Maritime #Myanmar #Netlify #Operation SouthNet #phishing #SideWinder
Daily CyberSecurity
SideWinder APT Launches Operation SouthNet, Weaponizing Netlify and Pages.dev for Espionage
APT SideWinder launched Operation SouthNet, targeting South Asia with over 50 malicious phishing portals hosted on Netlify and pages.dev to steal government and military credentials.
⤷ Title: 20. Common Payloads and Wordlists That Save Me Hours
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:52:24 GMT
════════════════════════
⌗ Tags: #medium #cybersecurity #infosec #bug_bounty #hacking
════════════════════════
𐀪 Author: Abhijeet kumawat
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:52:24 GMT
════════════════════════
⌗ Tags: #medium #cybersecurity #infosec #bug_bounty #hacking
Medium
20. Common Payloads and Wordlists That Save Me Hours
Targeted Lists, Faster Payouts — How Precision Beats Volume
⤷ Title: Google Launches Revolutionary AI Security Arsenal: CodeMender Leads the Charge Against Cyber…
════════════════════════
𐀪 Author: Techsankar
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:13:51 GMT
════════════════════════
⌗ Tags: #google #cybersecurity #bug_bounty #technology #tech
════════════════════════
𐀪 Author: Techsankar
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:13:51 GMT
════════════════════════
⌗ Tags: #google #cybersecurity #bug_bounty #technology #tech
Medium
Google Launches Revolutionary AI Security Arsenal: CodeMender Leads the Charge Against Cyber Threats
The tech giant unveils autonomous vulnerability patching, enhanced bug bounties, and ransomware protection in comprehensive security…
⤷ Title: Write-up PicoCTF: Web Exploitation ‘where are the robots’
════════════════════════
𐀪 Author: Muhammad Khairin
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:14:40 GMT
════════════════════════
⌗ Tags: #picoctf #ctf #cybersecurity #ctf_writeup #cyber_security_awareness
════════════════════════
𐀪 Author: Muhammad Khairin
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:14:40 GMT
════════════════════════
⌗ Tags: #picoctf #ctf #cybersecurity #ctf_writeup #cyber_security_awareness
Medium
Write-up PicoCTF: Web Exploitation ‘where are the robots’
Name Challenge: where are the robots
⤷ Title: Copenhagen, Oslo, Heathrow: Europe’s Airports Under Siege
════════════════════════
𐀪 Author: Vic Langston - Politics | Economy | Technology
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:02:00 GMT
════════════════════════
⌗ Tags: #europe #russia #drones #aviation #cybersecurity
════════════════════════
𐀪 Author: Vic Langston - Politics | Economy | Technology
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:02:00 GMT
════════════════════════
⌗ Tags: #europe #russia #drones #aviation #cybersecurity
Medium
Copenhagen, Oslo, Heathrow: Europe’s Airports Under Siege
Recent drone incursions in Copenhagen and Oslo, combined with ransomware attacks on major airports including Heathrow, reveal critical…
⤷ Title: Are you Leaking your Company secrets to AI?
════════════════════════
𐀪 Author: Varsha
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:50:30 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #coding #cybersecurity #deep_learning #software_development
════════════════════════
𐀪 Author: Varsha
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:50:30 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #coding #cybersecurity #deep_learning #software_development
Medium
Are you Leaking your Company secrets to AI?
🚨 The Most Dangerous Bug in Your Code Isn’t a Syntax Error
⤷ Title: What I’ve Learned From The ISC2’s Webinar Entitled: “From Shield to Spear: How AI is Reshaping…
════════════════════════
𐀪 Author: Martin L
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:37:47 GMT
════════════════════════
⌗ Tags: #threat_detection #cyberthreat_intelligence #cybersecurity #ai #incident_response
════════════════════════
𐀪 Author: Martin L
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 02:37:47 GMT
════════════════════════
⌗ Tags: #threat_detection #cyberthreat_intelligence #cybersecurity #ai #incident_response
Medium
What I’ve Learned From The ISC2’s Webinar Entitled: “From Shield to Spear: How AI is Reshaping…
linkedin
⤷ Title: Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 10:42:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 10:42:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: WPAxFuzz: full-featured open-source Wi-Fi fuzzer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 04:08:38 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Wi_Fi fuzzer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 04:08:38 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Wi_Fi fuzzer
Penetration Testing Tools
WPAxFuzz: full-featured open-source Wi-Fi fuzzer
WPAxFuzz is capable of fuzzing either any management, control or data frame of the 802.11 protocol or the SAE exchange.
⤷ Title: ARGUS: Autonomous Cyber-Physical Security Robot Merges AI Vision with Network Intrusion Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 04:04:09 +0000
════════════════════════
⌗ Tags: #Information Security #AI #Argus #Autonomous Robot #Cyber_Physical Security #Network Intrusion #Security Prototype #SLAM
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 04:04:09 +0000
════════════════════════
⌗ Tags: #Information Security #AI #Argus #Autonomous Robot #Cyber_Physical Security #Network Intrusion #Security Prototype #SLAM
Penetration Testing Tools
ARGUS: Autonomous Cyber-Physical Security Robot Merges AI Vision with Network Intrusion Detection
Romanian researchers unveiled ARGUS, an autonomous robot that detects hybrid threats by merging AI computer vision and network intrusion monitoring in a single mobile platform.
⤷ Title: China Sentences 16 to Death for Myanmar Fraud Syndicates and “Hidden Tiger Villa” Massacre
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 04:02:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China #cybercrime #Death Sentence #Four Great Families #Fraud #Myanmar #Transnational Crime #Wenzhou Court
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 04:02:11 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China #cybercrime #Death Sentence #Four Great Families #Fraud #Myanmar #Transnational Crime #Wenzhou Court
Penetration Testing Tools
China Sentences 16 to Death for Myanmar Fraud Syndicates and "Hidden Tiger Villa" Massacre
A Chinese court delivered a severe verdict against the Myanmar "Four Great Families," sentencing 16 to death for operating armed fraud enclaves along the border.