⤷ Title: TryHackMe #107 | DFIR: An Introduction
════════════════════════
𐀪 Author: SiberYuk
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 22:17:45 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #cybersecurity
════════════════════════
𐀪 Author: SiberYuk
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 22:17:45 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #tryhackme #cybersecurity
Medium
TryHackMe #107 | DFIR: An Introduction
Introductory room for the DFIR module.
⤷ Title: HackTheBox — Cypher (Medium)
════════════════════════
𐀪 Author: wh1t3r4bb1t
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 22:57:12 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #ctf_writeup #hackthebox
════════════════════════
𐀪 Author: wh1t3r4bb1t
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 22:57:12 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #ctf_writeup #hackthebox
Medium
HackTheBox — Cypher (Medium)
Cypher is a medium-difficulty Linux machine that requires exploiting a cypher injection vulnerability on a login page.
⤷ Title: New Stealit Infostealer Abuses Node.js SEA Feature and Telegram C2 in Malware-as-a-Service Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:46:39 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #FortiGuard #Infostealer #Malware_as_a_Service #Node.js SEA #Stealit #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:46:39 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #FortiGuard #Infostealer #Malware_as_a_Service #Node.js SEA #Stealit #Telegram C2
Daily CyberSecurity
New Stealit Infostealer Abuses Node.js SEA Feature and Telegram C2 in Malware-as-a-Service Campaign
FortiGuard Labs identified a new Stealit malware variant abusing Node.js SEA for stealthy distribution. The campaign features a public C2 panel and uses Telegram for data exfiltration.
⤷ Title: Pro-Russian Hacktivist Group TwoNet Exposed for Fabricating Critical Infrastructure Attacks to Boost Reputation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:42:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Disinformation #False Flag #Forescout #Hacktivism #ICS #OT Security #Telegram #TwoNet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:42:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Disinformation #False Flag #Forescout #Hacktivism #ICS #OT Security #Telegram #TwoNet
Daily CyberSecurity
Pro-Russian Hacktivist Group TwoNet Exposed for Fabricating Critical Infrastructure Attacks to Boost Reputation
Forescout found pro-Russian hacktivist group TwoNet fabricated critical infrastructure attacks after compromising a honeypot, exploiting a default login, and pushing the false claim on Telegram.
⤷ Title: Critical Cherry Studio Flaw CVE-2025-61929 (CVSS 9.7) Allows One-Click RCE via Custom URL Protocol
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:40:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cherry Studio #Command Execution #Critical Vulnerability #Custom Protocol #CVE_2025_61929 #LLM Client #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:40:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cherry Studio #Command Execution #Critical Vulnerability #Custom Protocol #CVE_2025_61929 #LLM Client #rce
Daily CyberSecurity
Critical Cherry Studio Flaw CVE-2025-61929 (CVSS 9.7) Allows One-Click RCE via Custom URL Protocol
A Critical RCE flaw (CVE-2025-61929) in Cherry Studio allows attackers to execute arbitrary commands by exploiting a one-click weakness in its custom URL protocol handler.
⤷ Title: Payroll Piracy: Hackers Storm-2657 Exploit MFA Flaws to Hijack University Salary Payments via Workday
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:35:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Higher Education #MFA Bypass #Microsoft Threat Intelligence #Payroll Fraud #phishing #Storm_2657 #Workday
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:35:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Higher Education #MFA Bypass #Microsoft Threat Intelligence #Payroll Fraud #phishing #Storm_2657 #Workday
Daily CyberSecurity
Payroll Piracy: Hackers Storm-2657 Exploit MFA Flaws to Hijack University Salary Payments via Workday
Microsoft warns of Storm-2657, a financial crime group exploiting MFA flaws to hijack university employee accounts, rerouting salary payments through third-party HR platforms like Workday.
⤷ Title: Critical Auth Bypass (CVE-2025-61928) in Better Auth Allows Hackers to Steal User API Keys
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:30:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Key Theft #Authentication Bypass #Better Auth #Critical Vulnerability #CVE_2025_61928 #Next.js #TypeScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:30:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Key Theft #Authentication Bypass #Better Auth #Critical Vulnerability #CVE_2025_61928 #Next.js #TypeScript
Daily CyberSecurity
Critical Auth Bypass (CVE-2025-61928) in Better Auth Allows Hackers to Steal User API Keys
A Critical (CVSS 9.3) flaw (CVE-2025-61928) in Better Auth allows unauthenticated attackers to create/modify API keys for any user, risking full account compromise.
⤷ Title: Axis Communications Leaks Azure Credentials in Autodesk Plugin Via Hardcoded SAS Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:26:31 +0000
════════════════════════
⌗ Tags: #Data Leak #Autodesk Revit #Axis Communications #Azure #Credential Leak #SAS Token #Supply Chain #Trend Micro #ZDI_24_1181
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:26:31 +0000
════════════════════════
⌗ Tags: #Data Leak #Autodesk Revit #Axis Communications #Azure #Credential Leak #SAS Token #Supply Chain #Trend Micro #ZDI_24_1181
Daily CyberSecurity
Axis Communications Leaks Azure Credentials in Autodesk Plugin Via Hardcoded SAS Tokens
Trend Micro discovered that Axis Communications leaked hardcoded Azure SAS tokens in a signed DLL for its Autodesk Revit plugin, exposing three cloud storage accounts to unauthorized access.
⤷ Title: Homebrew Spoofing: Fake Installer Sites Use Clipboard Injection to Compromise macOS Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:21:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #clipboard injection #Homebrew #Kandji #macOS #Odyssey Stealer #spoofing #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:21:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #clipboard injection #Homebrew #Kandji #macOS #Odyssey Stealer #spoofing #supply chain attack
Daily CyberSecurity
Homebrew Spoofing: Fake Installer Sites Use Clipboard Injection to Compromise macOS Developers
A malware campaign is spoofing Homebrew installer websites to trick macOS developers. The sites use clipboard injection to hide a malicious payload alongside the install command.
⤷ Title: Massive RDP Botnet Unleashed: 100,000+ IPs in Coordinated Global Scanning Campaign Targeting US
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Coordinated #cyberattack #GreyNoise #Infrastructure #RDP #RDP Scanning #Remote Desktop Protocol
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Coordinated #cyberattack #GreyNoise #Infrastructure #RDP #RDP Scanning #Remote Desktop Protocol
Daily CyberSecurity
Massive RDP Botnet Unleashed: 100,000+ IPs in Coordinated Global Scanning Campaign Targeting US
GreyNoise warns of a massive, synchronized RDP botnet using 100,000+ IPs from over 100 countries for RDP scanning and enumeration, with US infrastructure as the primary target.
⤷ Title: New Rust Backdoor ChaosBot Uses Discord as Covert C2 Channel to Target Financial Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:18:03 +0000
════════════════════════
⌗ Tags: #Malware #C2 #ChaosBot #Command and Control #Discord #DLL Sideloading #eSentire #Financial services #Rust
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:18:03 +0000
════════════════════════
⌗ Tags: #Malware #C2 #ChaosBot #Command and Control #Discord #DLL Sideloading #eSentire #Financial services #Rust
Daily CyberSecurity
New Rust Backdoor ChaosBot Uses Discord as Covert C2 Channel to Target Financial Services
eSentire discovered ChaosBot, a Rust-based malware deployed via DLL sideloading that uses Discord channels as a covert C2 platform to perform reconnaissance and command execution.
⤷ Title: Cryptocurrency Drain Conspiracy: Single Alibaba Server Hosts Multi-Vector Scams, Hijacking Wallets via Fake Trust Wallet and MobileConfig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:14:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Drain #DomainTools #MedAI Genesis #Mobileconfig #phishing #scam #Trust Wallet #Wallet drainer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:14:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Drain #DomainTools #MedAI Genesis #Mobileconfig #phishing #scam #Trust Wallet #Wallet drainer
Daily CyberSecurity
Cryptocurrency Drain Conspiracy: Single Alibaba Server Hosts Multi-Vector Scams, Hijacking Wallets via Fake Trust Wallet and MobileConfig
DomainTools exposed a Cryptocurrency Drain Conspiracy using a single IP to host scams like MedAI Genesis. Attackers use copied CSS and malicious MobileConfig profiles to drain crypto wallets.
⤷ Title: Akira Ransomware Revives SonicWall Flaw CVE-2024-40766, Uses ‘UnPAC the Hash’ to Breach Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:09:24 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #Credential Theft #CVE_2024_40766 #Darktrace #SonicWall #UnPAC the Hash #VMware ESXi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:09:24 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #Credential Theft #CVE_2024_40766 #Darktrace #SonicWall #UnPAC the Hash #VMware ESXi
Daily CyberSecurity
Akira Ransomware Revives SonicWall Flaw CVE-2024-40766, Uses 'UnPAC the Hash' to Breach Networks
Akira ransomware is actively exploiting the unpatched/misconfigured SonicWall flaw (CVE-2024-40766) and using the rare "UnPAC the Hash" Kerberos technique for lateral movement.
⤷ Title: Apple Ups Bounty to $5 Million for Zero-Click Spyware Exploits Bypassing Lockdown Mode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:03:30 +0000
════════════════════════
⌗ Tags: #Technology #$5 Million #Apple #Lockdown Mode #rce #Security Bounty #spyware #Vulnerability Research #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:03:30 +0000
════════════════════════
⌗ Tags: #Technology #$5 Million #Apple #Lockdown Mode #rce #Security Bounty #spyware #Vulnerability Research #Zero_Click
Daily CyberSecurity
Apple Ups Bounty to $5 Million for Zero-Click Spyware Exploits Bypassing Lockdown Mode
Apple overhauled its Security Bounty program, offering a $2M base reward (up to $5M with bonuses) for zero-click exploits that match mercenary spyware attacks and bypass Lockdown Mode.
⤷ Title: UK CMA Designates Google with Strategic Market Status Over 90% Search Dominance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:01:17 +0000
════════════════════════
⌗ Tags: #Technology #AI Overviews #Antitrust #CMA #google #regulation #Search Advertising #SMS #Strategic Market Status
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:01:17 +0000
════════════════════════
⌗ Tags: #Technology #AI Overviews #Antitrust #CMA #google #regulation #Search Advertising #SMS #Strategic Market Status
Daily CyberSecurity
UK CMA Designates Google with Strategic Market Status Over 90% Search Dominance
The UK's CMA gave Google Strategic Market Status (SMS) over its 90% search dominance. The designation grants the regulator new powers to mandate changes in Google's search and AI services.
⤷ Title: Active Directory Hacking 101: Kerberoasting
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:31:46 GMT
════════════════════════
⌗ Tags: #kerberoast #ad_hacking #hacking #kerberoasting #active_directory
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:31:46 GMT
════════════════════════
⌗ Tags: #kerberoast #ad_hacking #hacking #kerberoasting #active_directory
Medium
Active Directory Hacking 101: Kerberoasting
Kerberoasting is a way of stealing and cracking service account password hashes offline.
⤷ Title: Setting Up SSH Remote Access on Kali Linux: A Step-by-Step Guide
════════════════════════
𐀪 Author: Ali bin azam
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:11:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #devops #ssh #hacking #ssh_tunnel
════════════════════════
𐀪 Author: Ali bin azam
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 00:11:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #devops #ssh #hacking #ssh_tunnel
Medium
Setting Up SSH Remote Access on Kali Linux: A Step-by-Step Guide
System Administration
⤷ Title: Return of the System Gods: Rootkits, Certificates and the Fall of the Trusted Kernel
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:06:37 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #rootkit #kernel #infosec
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:06:37 GMT
════════════════════════
⌗ Tags: #security #cybersecurity #rootkit #kernel #infosec
Medium
Return of the System Gods: Rootkits, Certificates and the Fall of the Trusted Kernel
When digital trust becomes the most dangerous vulnerability of the twenty-first century
⤷ Title: APIclypse Now: the Silent Collapse of API Control
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:03:59 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #api #infosec #security
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:03:59 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #api #infosec #security
Medium
APIclypse Now: the Silent Collapse of API Control
The Twilight of the Invisible Perimeter
⤷ Title: The Art of Staying: Advanced Persistence and the Battle for Digital Time
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:00:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #persistence #infosec #security_research
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:00:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #persistence #infosec #security_research
Medium
The Art of Staying: Advanced Persistence and the Battle for Digital Time
The invisible threads of control
⤷ Title: Catalysing High-Performance Computing Capacity in Africa: Key Outcomes and Lessons from the 3rd…
════════════════════════
𐀪 Author: Emmanuel Adetiba, Ph.D
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:41:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #hpc #computing #africa #highperformance_computing
════════════════════════
𐀪 Author: Emmanuel Adetiba, Ph.D
════════════════════════
ⴵ Time: Mon, 13 Oct 2025 01:41:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #hpc #computing #africa #highperformance_computing
Medium
Catalysing High-Performance Computing Capacity in Africa: Key Outcomes and Lessons from the 3rd FEDGEN-HPC Workshop
Authors: Emmanuel Adetiba, Boladele Akanle, Priscilla Ajayi, Comfort Lawal, Faith O. Sweetwilliams, John Wejin