⤷ Title: Tryhackme | Smol | Türkçe Anlatım
════════════════════════
𐀪 Author: nightbird
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:07:02 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #smol_tryhackme
════════════════════════
𐀪 Author: nightbird
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:07:02 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #smol_tryhackme
Medium
Tryhackme | Smol | Türkçe Anlatım
Başlamadan önce odada ki yazılanları okuduğumuz “At the heart of Smol is a WordPress website,” eski ve arka kapı eklentilerini hedef alarak…
⤷ Title: AI agents, speed cameras, and the “DROP TABLE” plate
════════════════════════
𐀪 Author: Cloudperceptor
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:38:39 GMT
════════════════════════
⌗ Tags: #technology #genai #sql_injection #generative_ai_tools #ai
════════════════════════
𐀪 Author: Cloudperceptor
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:38:39 GMT
════════════════════════
⌗ Tags: #technology #genai #sql_injection #generative_ai_tools #ai
Medium
AI agents, speed cameras, and the “DROP TABLE” plate
AI agents, speed cameras, and the “DROP TABLE” plate A mock license plate that includes text like “'); DROP DATABASE …” is a joke about SQL injection: if a system reads plate text with OCR …
⤷ Title: ReconAIzer: leverages OpenAI to help bug bounty hunters optimize their recon process
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:58:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Burp Suite #OpenAI #ReconAIzer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:58:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Burp Suite #OpenAI #ReconAIzer
Penetration Testing Tools
ReconAIzer: leverages OpenAI to help bug bounty hunters optimize their recon process
ReconAIzer is a powerful Jython extension for Burp Suite that leverages OpenAI to help bug bounty hunters optimize their recon process.
⤷ Title: New Cache Smuggling Phishing Attack Delivers Malware via Browser Cache
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:51:57 +0000
════════════════════════
⌗ Tags: #Malware #Cache Smuggling #ClickFix #FileFix #Fortinet Lure #Malware Evasion #PowerShell #Security Advisory
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:51:57 +0000
════════════════════════
⌗ Tags: #Malware #Cache Smuggling #ClickFix #FileFix #Fortinet Lure #Malware Evasion #PowerShell #Security Advisory
Penetration Testing Tools
New Cache Smuggling Phishing Attack Delivers Malware via Browser Cache
A new phishing variant uses cache smuggling to hide a malicious ZIP in the browser cache. The FileFix lure then executes PowerShell to install malware without any downloads.
⤷ Title: Microsoft Teams: New Report Exposes How APTs and Ransomware Groups Weaponize Collaboration Features to Breach Enterprises
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:35:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cybersecurity #Entra ID #Microsoft Teams #Microsoft Threat Intelligence #ransomware #Social Engineering #TeamsPhisher
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:35:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cybersecurity #Entra ID #Microsoft Teams #Microsoft Threat Intelligence #ransomware #Social Engineering #TeamsPhisher
Penetration Testing Tools
Microsoft Teams: New Report Exposes How APTs and Ransomware Groups Weaponize Collaboration Features to Breach Enterprises
Microsoft Threat Intelligence details how APTs and ransomware groups abuse Teams and Entra ID integration for recon, malware distribution, persistence, and C2 through chat messages.
⤷ Title: China-Linked Hackers Weaponize Nezha Monitoring Tool and Log Poisoning to Deploy Gh0st RAT on 100+ Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:27:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #China_Nexus #Compromise #Gh0st RAT #Huntress #Log Poisoning #Nezha #phpMyAdmin #Web Shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:27:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #China_Nexus #Compromise #Gh0st RAT #Huntress #Log Poisoning #Nezha #phpMyAdmin #Web Shell
Penetration Testing Tools
China-Linked Hackers Weaponize Nezha Monitoring Tool and Log Poisoning to Deploy Gh0st RAT on 100+ Systems
Huntress exposed a China-linked campaign using log poisoning on vulnerable phpMyAdmin to deploy a web shell and the Nezha monitoring tool for delivering Gh0st RAT to over 100 victims.
⤷ Title: High-Severity Figma MCP Flaw CVE-2025-53967 Allows Remote Command Injection via Fallback Mechanism
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:24:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_53967 #DNS Rebinding #Figma #Imperva #MCP #Model Context Protocol #RCE
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:24:54 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #CVE_2025_53967 #DNS Rebinding #Figma #Imperva #MCP #Model Context Protocol #RCE
Penetration Testing Tools
High-Severity Figma MCP Flaw CVE-2025-53967 Allows Remote Command Injection via Fallback Mechanism
A High-severity flaw (CVE-2025-53967) in the Figma MCP server allows remote command injection. Attackers exploit a vulnerable curl fallback to execute code with server privileges.
⤷ Title: ClamAV 1.5.0 Released: Major Update Adds FIPS Mode Support and Switches Cache Hashing to SHA-256
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:22:22 +0000
════════════════════════
⌗ Tags: #Open Source Tool #antivirus #clamAV #Compliance #cryptography #FIPS #Freshclam #security update #SHA_256
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:22:22 +0000
════════════════════════
⌗ Tags: #Open Source Tool #antivirus #clamAV #Compliance #cryptography #FIPS #Freshclam #security update #SHA_256
Penetration Testing Tools
ClamAV 1.5.0 Released: Major Update Adds FIPS Mode Support and Switches Cache Hashing to SHA-256
ClamAV 1.5.0 introduces FIPS mode support for signature verification and upgrades clean file caching to SHA-256 to meet strict cryptographic compliance standards. Update now.
⤷ Title: Critical WordPress Flaw CVE-2025-5947 (CVSS 9.8) Under Active Exploitation for Admin Takeover
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:20:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication bypass #Critical Vulnerability #CVE_2025_5947 #Service Finder #Site Takeover #Wordfence #WordPress
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:20:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication bypass #Critical Vulnerability #CVE_2025_5947 #Service Finder #Site Takeover #Wordfence #WordPress
Penetration Testing Tools
Critical WordPress Flaw CVE-2025-5947 (CVSS 9.8) Under Active Exploitation for Admin Takeover
A Critical (CVSS 9.8) flaw (CVE-2025-5947) in the Service Finder Bookings plugin allows unauthenticated attackers to gain Admin access via cookie manipulation. Over 13,000 exploit attempts recorded.
⤷ Title: Gemini Nano Block: Google Locks On-Device AI Access for Smartphones with Unlocked Bootloaders
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:11:08 +0000
════════════════════════
⌗ Tags: #Android #AI #AI security #android #Bootloader #Gemini Nano #google #ML Kit #privacy #root access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:11:08 +0000
════════════════════════
⌗ Tags: #Android #AI #AI security #android #Bootloader #Gemini Nano #google #ML Kit #privacy #root access
Daily CyberSecurity
Gemini Nano Block: Google Locks On-Device AI Access for Smartphones with Unlocked Bootloaders
Google has confirmed that the Gemini Nano on-device AI model is blocked from running on Android devices with an unlocked bootloader, citing a feature not found error.
❤1
⤷ Title: CL0P Extortion: Google/Mandiant Expose Zero-Day RCE in Oracle E-Business Suite (CVE-2025-61882)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:56:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Cl0p #CVE_2025_61882 #Cyber Extortion #Google GTIG #Mandiant #Oracle EBS #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:56:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability Report #Cl0p #CVE_2025_61882 #Cyber Extortion #Google GTIG #Mandiant #Oracle EBS #rce
Daily CyberSecurity
CL0P Extortion: Google/Mandiant Expose Zero-Day RCE in Oracle E-Business Suite (CVE-2025-61882)
Google/Mandiant linked CL0P extortion to a Zero-Day RCE flaw (CVE-2025-61882) in Oracle E-Business Suite. Attackers exploited the bug since July to steal corporate data and deploy GOLDVEIN Java shells.
⤷ Title: Exploited Zero-Day: Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11371 #Gladinet #lfi #local file inclusion #rce #Triofox #ViewState Deserialization #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:42:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11371 #Gladinet #lfi #local file inclusion #rce #Triofox #ViewState Deserialization #zero_day
Daily CyberSecurity
Exploited Zero-Day: Gladinet/Triofox Flaw CVE-2025-11371 Allows RCE via LFI
A Zero-Day LFI flaw (CVE-2025-11371) in Gladinet/Triofox is being actively exploited. Attackers retrieve the Web.config machine key to chain into an unauthenticated RCE exploit.
⤷ Title: NVIDIA GPU Driver Patches Multiple High-Severity Flaws Risking RCE and Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:34:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23309 #GPU Driver #Linux #nvidia #privilege escalation #rce #security update #vGPU #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:34:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_23309 #GPU Driver #Linux #nvidia #privilege escalation #rce #security update #vGPU #windows
Daily CyberSecurity
NVIDIA GPU Driver Patches Multiple High-Severity Flaws Risking RCE and Privilege Escalation
NVIDIA released an urgent update for its GPU Display Driver, fixing multiple high-severity flaws including RCE via an uncontrolled DLL loading path (CVE-2025-23309). Update now.
⤷ Title: RondoDox Botnet Unleashed: New Malware Uses ‘Exploit Shotgun’ to Target 50+ Router and IoT Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:59:52 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Exploit Shotgun #IoT security #Loader_as_a_Service #Mirai #RondoDox #Router Vulnerability #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:59:52 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Exploit Shotgun #IoT security #Loader_as_a_Service #Mirai #RondoDox #Router Vulnerability #Trend Micro
Daily CyberSecurity
RondoDox Botnet Unleashed: New Malware Uses 'Exploit Shotgun' to Target 50+ Router and IoT Flaws
Trend Micro discovered RondoDox, a new botnet leveraging 50+ exploits (including the Pwn2Own TP-Link flaw) in an "exploit shotgun" approach to compromise routers, DVRs, and IoT globally.
⤷ Title: DFIR Tool Hijacked: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:50:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:50:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
Daily CyberSecurity
DFIR Tool Hijacked: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
Cisco Talos confirms Storm-2603 is abusing the DFIR tool Velociraptor for persistence and arbitrary code execution, deploying LockBit and Babuk ransomware against VMware and Windows servers.
⤷ Title: MediaTek Issues October 2025 Security Bulletin Addressing Multiple High-Severity Vulnerabilities Across Wi-Fi and GNSS Chipsets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:22:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #Chipset Security #CVE_2025_20712 #GNSS #IOT #MediaTek #stack overflow #WLAN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:22:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #Chipset Security #CVE_2025_20712 #GNSS #IOT #MediaTek #stack overflow #WLAN
Daily CyberSecurity
MediaTek Issues October 2025 Security Bulletin Addressing Multiple High-Severity Vulnerabilities Across Wi-Fi and GNSS Chipsets
MediaTek's October Security Bulletin discloses multiple High-severity flaws in its WLAN and GNSS chipsets, including buffer and stack overflows that risk RCE via memory corruption.
⤷ Title: Zero-Download Malware: New Cache Smuggling Phishing Attack Delivers Payload via Browser Cache
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:19:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cache Smuggling #ClickFix #Expel #Fortinet #Malware Evasion #phishing #powershell #Zero_Download
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:19:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cache Smuggling #ClickFix #Expel #Fortinet #Malware Evasion #phishing #powershell #Zero_Download
Daily CyberSecurity
Zero-Download Malware: New Cache Smuggling Phishing Attack Delivers Payload via Browser Cache
Expel uncovered a phishing attack using Cache Smuggling to deliver malware. The technique uses a fake Fortinet lure and PowerShell to execute a payload staged in the browser's cache, bypassing network detection.
⤷ Title: ClickFix Phishing: New Automated Kits Trick Users Into Manually Running Malware and Stealers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:11:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #cybersecurity #DeerStealer #IUAM Generator #Odyssey #Palo Alto Networks #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:11:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #cybersecurity #DeerStealer #IUAM Generator #Odyssey #Palo Alto Networks #phishing #social engineering
Daily CyberSecurity
ClickFix Phishing: New Automated Kits Trick Users Into Manually Running Malware and Stealers
⤷ Title: TP-Link Router Flaw CVE-2023-28760 Allows Root RCE via LAN, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:06:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer AX21 #buffer overflow #CVE_2023_28760 #Local Privilege Escalation #MiniDLNA #rce #Router Hack #TP_Link
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:06:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer AX21 #buffer overflow #CVE_2023_28760 #Local Privilege Escalation #MiniDLNA #rce #Router Hack #TP_Link
Daily CyberSecurity
TP-Link Router Flaw CVE-2023-28760 Allows Root RCE via LAN, PoC Available
A flaw (CVE-2023-28760) in TP-Link AX1800 routers allows unauthenticated attackers on the LAN to gain root RCE by manipulating the MiniDLNA service via a USB drive.
⤷ Title: Huntress Uncovers Log Poisoning Campaign Linking Nezha and Ghost RAT in Widespread Asian Cyber Intrusions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:01:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #Cybercrime #Ghost RAT #Huntress #Log Poisoning #Nezha #phpmyadmin #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:01:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #Cybercrime #Ghost RAT #Huntress #Log Poisoning #Nezha #phpmyadmin #Web Shell
Daily CyberSecurity
Huntress Uncovers Log Poisoning Campaign Linking Nezha and Ghost RAT in Widespread Asian Cyber Intrusions
Huntress exposed a covert campaign using log poisoning on exposed phpMyAdmin to deploy a web shell and the Nezha monitoring tool, ultimately delivering the Ghost RAT backdoor to 100+ victims in Asia.
⤷ Title: How I got my First Bounty from Chess.com
════════════════════════
𐀪 Author: Ayush
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 09:00:25 GMT
════════════════════════
⌗ Tags: #chess #cybersecurity #bug_bounty #programming #technology
════════════════════════
𐀪 Author: Ayush
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 09:00:25 GMT
════════════════════════
⌗ Tags: #chess #cybersecurity #bug_bounty #programming #technology
Medium
How I got my First Bounty from Chess.com
I found DoS by JS crash, disallowing anyone to view anyone’s profile and HTML Injection.