⤷ Title: DFIR Tool Hijacked: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:50:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:50:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Babuk #cybersecurity #DFIR #LockBit #ransomware #Storm_2603 #Tool Abuse #Velociraptor
Daily CyberSecurity
DFIR Tool Hijacked: Ransomware Group Storm-2603 Abuses Velociraptor for Stealthy LockBit/Babuk Attacks
Cisco Talos confirms Storm-2603 is abusing the DFIR tool Velociraptor for persistence and arbitrary code execution, deploying LockBit and Babuk ransomware against VMware and Windows servers.
⤷ Title: MediaTek Issues October 2025 Security Bulletin Addressing Multiple High-Severity Vulnerabilities Across Wi-Fi and GNSS Chipsets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:22:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #Chipset Security #CVE_2025_20712 #GNSS #IOT #MediaTek #stack overflow #WLAN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:22:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #Chipset Security #CVE_2025_20712 #GNSS #IOT #MediaTek #stack overflow #WLAN
Daily CyberSecurity
MediaTek Issues October 2025 Security Bulletin Addressing Multiple High-Severity Vulnerabilities Across Wi-Fi and GNSS Chipsets
MediaTek's October Security Bulletin discloses multiple High-severity flaws in its WLAN and GNSS chipsets, including buffer and stack overflows that risk RCE via memory corruption.
⤷ Title: Zero-Download Malware: New Cache Smuggling Phishing Attack Delivers Payload via Browser Cache
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:19:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cache Smuggling #ClickFix #Expel #Fortinet #Malware Evasion #phishing #powershell #Zero_Download
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:19:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cache Smuggling #ClickFix #Expel #Fortinet #Malware Evasion #phishing #powershell #Zero_Download
Daily CyberSecurity
Zero-Download Malware: New Cache Smuggling Phishing Attack Delivers Payload via Browser Cache
Expel uncovered a phishing attack using Cache Smuggling to deliver malware. The technique uses a fake Fortinet lure and PowerShell to execute a payload staged in the browser's cache, bypassing network detection.
⤷ Title: ClickFix Phishing: New Automated Kits Trick Users Into Manually Running Malware and Stealers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:11:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #cybersecurity #DeerStealer #IUAM Generator #Odyssey #Palo Alto Networks #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:11:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFix #cybersecurity #DeerStealer #IUAM Generator #Odyssey #Palo Alto Networks #phishing #social engineering
Daily CyberSecurity
ClickFix Phishing: New Automated Kits Trick Users Into Manually Running Malware and Stealers
⤷ Title: TP-Link Router Flaw CVE-2023-28760 Allows Root RCE via LAN, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:06:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer AX21 #buffer overflow #CVE_2023_28760 #Local Privilege Escalation #MiniDLNA #rce #Router Hack #TP_Link
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:06:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Archer AX21 #buffer overflow #CVE_2023_28760 #Local Privilege Escalation #MiniDLNA #rce #Router Hack #TP_Link
Daily CyberSecurity
TP-Link Router Flaw CVE-2023-28760 Allows Root RCE via LAN, PoC Available
A flaw (CVE-2023-28760) in TP-Link AX1800 routers allows unauthenticated attackers on the LAN to gain root RCE by manipulating the MiniDLNA service via a USB drive.
⤷ Title: Huntress Uncovers Log Poisoning Campaign Linking Nezha and Ghost RAT in Widespread Asian Cyber Intrusions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:01:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #Cybercrime #Ghost RAT #Huntress #Log Poisoning #Nezha #phpmyadmin #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 00:01:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #Cybercrime #Ghost RAT #Huntress #Log Poisoning #Nezha #phpmyadmin #Web Shell
Daily CyberSecurity
Huntress Uncovers Log Poisoning Campaign Linking Nezha and Ghost RAT in Widespread Asian Cyber Intrusions
Huntress exposed a covert campaign using log poisoning on exposed phpMyAdmin to deploy a web shell and the Nezha monitoring tool, ultimately delivering the Ghost RAT backdoor to 100+ victims in Asia.
⤷ Title: How I got my First Bounty from Chess.com
════════════════════════
𐀪 Author: Ayush
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 09:00:25 GMT
════════════════════════
⌗ Tags: #chess #cybersecurity #bug_bounty #programming #technology
════════════════════════
𐀪 Author: Ayush
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 09:00:25 GMT
════════════════════════
⌗ Tags: #chess #cybersecurity #bug_bounty #programming #technology
Medium
How I got my First Bounty from Chess.com
I found DoS by JS crash, disallowing anyone to view anyone’s profile and HTML Injection.
⤷ Title: Linux for Hackers
════════════════════════
𐀪 Author: LinuxDev
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:13:21 GMT
════════════════════════
⌗ Tags: #security #hacking #cyber_sec #linux #pentesting
════════════════════════
𐀪 Author: LinuxDev
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:13:21 GMT
════════════════════════
⌗ Tags: #security #hacking #cyber_sec #linux #pentesting
Medium
Linux for Hackers
This comprehensive guide explores the pivotal role of Linux in advanced cybersecurity operations, detailing essential tools, attack…
⤷ Title: 3rd party PII Leak OSINT
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:37:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint_investigation #osint #google_dorking #google_dork
════════════════════════
𐀪 Author: Abhirup Konwar
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:37:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #osint_investigation #osint #google_dorking #google_dork
Medium
3rd party PII Leak OSINT
Advanced Google Dorks to find exposed sensitive information
⤷ Title: SHAMOS Malware: How a Single Terminal Command Can Steal Your Mac’s Secrets
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:31:53 GMT
════════════════════════
⌗ Tags: #shamos_malware #malvertising #malware_analysis #mac #cybersecurity
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:31:53 GMT
════════════════════════
⌗ Tags: #shamos_malware #malvertising #malware_analysis #mac #cybersecurity
Medium
SHAMOS Malware: How a Single Terminal Command Can Steal Your Mac’s Secrets
Macs have long carried a reputation for being the “safe” choice — sleek design, fewer viruses and a promise of reliability. But…
⤷ Title: Scale Your Security, Not Your Headaches: Why Augmenting Your IdP Beats Migration
════════════════════════
𐀪 Author: Sunil Gentyala
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:18:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #iam_roles #zero_trust #identity_security #idp
════════════════════════
𐀪 Author: Sunil Gentyala
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:18:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #iam_roles #zero_trust #identity_security #idp
Medium
Scale Your Security, Not Your Headaches: Why Augmenting Your IdP Beats Migration
For many startups and growing businesses, identity management begins with simple, cost-effective solutions like Google Workspace. As…
⤷ Title: OSINT Isn’t Just Skill — It’s Timing
════════════════════════
𐀪 Author: Sam Galope
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:18:04 GMT
════════════════════════
⌗ Tags: #productivity_tips #cybersecurity #full_stack_developer #osint #ethical_hacking
════════════════════════
𐀪 Author: Sam Galope
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:18:04 GMT
════════════════════════
⌗ Tags: #productivity_tips #cybersecurity #full_stack_developer #osint #ethical_hacking
Medium
OSINT Isn’t Just Skill — It’s Timing
Why mastering your timing matters more than mastering your tools.
⤷ Title: The Cyber Arms Race: From defensive postures to preemptive digital warfare
════════════════════════
𐀪 Author: Neil Singh
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:15:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #cyberwarfare_and_defense #government
════════════════════════
𐀪 Author: Neil Singh
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:15:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #cyberwarfare_and_defense #government
Medium
The Cyber Arms Race: From defensive postures to preemptive digital warfare
The Shift from Reaction to Action
⤷ Title: What You Need to Know About Tycoon 2FA
════════════════════════
𐀪 Author: Bloopworm
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:38:20 GMT
════════════════════════
⌗ Tags: #tycoon2fa #phishing #mfa_bypass #cybersecurity
════════════════════════
𐀪 Author: Bloopworm
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:38:20 GMT
════════════════════════
⌗ Tags: #tycoon2fa #phishing #mfa_bypass #cybersecurity
Medium
What You Need to Know About Tycoon 2FA
Exploring how attackers leverage Tycoon 2FA to capture credentials, bypass MFA, and gain unauthorized access to cloud services.
⤷ Title: Security Headers Made Simple: A Practical Guide
════════════════════════
𐀪 Author: Aanchalgoel
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:21:19 GMT
════════════════════════
⌗ Tags: #sec #interview #software_development #cybersecurity #interview_preparation
════════════════════════
𐀪 Author: Aanchalgoel
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:21:19 GMT
════════════════════════
⌗ Tags: #sec #interview #software_development #cybersecurity #interview_preparation
Medium
Security Headers Made Simple: A Practical Guide
When your web app goes live, the browser becomes your first line of defense.
⤷ Title: 專題:證監會數碼鑑證專家Henry Liu談AI、金融犯罪調查與國際賽事經驗
════════════════════════
𐀪 Author: KH Liu
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:10:26 GMT
════════════════════════
⌗ Tags: #sfc #digital_forensics #cybersecurity #ctf #financial_regulation
════════════════════════
𐀪 Author: KH Liu
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:10:26 GMT
════════════════════════
⌗ Tags: #sfc #digital_forensics #cybersecurity #ctf #financial_regulation
Medium
專題:證監會數碼鑑證專家Henry Liu談AI、金融犯罪調查與國際賽事經驗
2025年7月,香港證監會的數碼鑑證專家Henry Liu在“第二屆國際數碼法理鑑證挑戰賽”中獲得銅獎,該比賽由香港大學計算與數據科學學院,警方網絡安全及科技罪案調查科,國際刑警組織,以及領先的鑑證科技公司合辦和支持。我們邀請了Henry分享他的鑑證工作經驗。
⤷ Title: How Digital Forensics Powers SFC Enforcement: Insights from Award-Winning Investigator Henry Liu
════════════════════════
𐀪 Author: KH Liu
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:02:54 GMT
════════════════════════
⌗ Tags: #sfc #cybersecurity #financial_regulation #digital_forensics
════════════════════════
𐀪 Author: KH Liu
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:02:54 GMT
════════════════════════
⌗ Tags: #sfc #cybersecurity #financial_regulation #digital_forensics
Medium
How Digital Forensics Powers SFC Enforcement: Insights from Award-Winning Investigator Henry Liu
Meet our award-winning digital forensic specialist — Henry Liu! In July 2025, Henry won the bronze award at the 2nd International Digital…
⤷ Title: Inside the Dark Web: Myth vs. Reality
════════════════════════
𐀪 Author: The Bot Group
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:53:36 GMT
════════════════════════
⌗ Tags: #internet #technology #darkweb #privacy #cybersecurity
════════════════════════
𐀪 Author: The Bot Group
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 01:53:36 GMT
════════════════════════
⌗ Tags: #internet #technology #darkweb #privacy #cybersecurity
Medium
Inside the Dark Web: Myth vs. Reality
It’s not just for criminals. Learn how the same tech protects dissidents and enables a billion-dollar shadow economy.
⤷ Title: Building Magic AD
════════════════════════
𐀪 Author: Alan francis
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:07:07 GMT
════════════════════════
⌗ Tags: #active_directory #penetration_testing
════════════════════════
𐀪 Author: Alan francis
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 02:07:07 GMT
════════════════════════
⌗ Tags: #active_directory #penetration_testing
Medium
Building Magic AD
I wanted to share my experience with Tyler Ramsbey’s latest BAS (Breached Attack Scenario) machine — I’ve been a fan of his YouTube…
⤷ Title: msLDAPDump: LDAP enumeration tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 04:00:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #LDAP enumeration #msLDAPDump
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 04:00:31 +0000
════════════════════════
⌗ Tags: #Open Source Tool #LDAP enumeration #msLDAPDump
Penetration Testing Tools
msLDAPDump: LDAP enumeration tool
msLDAPDump simplifies LDAP enumeration in a domain environment by wrapping the lpap3 library from Python in an easy-to-use interface
⤷ Title: Linux Kernel TLS UAF Flaw Allows Local RCE via Async Decrypt – PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 04:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cryptd #Linux Kernel #privilege escalation #tls #UAF #use after free #Zero_Copy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 04:30:22 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cryptd #Linux Kernel #privilege escalation #tls #UAF #use after free #Zero_Copy
Daily CyberSecurity
Linux Kernel TLS UAF Flaw Allows Local RCE via Async Decrypt - PoC Available
A UAF flaw in the Linux kernel TLS subsystem allows a low-privileged user to gain RCE by exploiting memory corruption during asynchronous decryption.