⤷ Title: DVWA Walkthrough: Reflected XSS (All Difficulties)
════════════════════════
𐀪 Author: Noman Chowdhury
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 22:24:56 GMT
════════════════════════
⌗ Tags: #dvwa #reflected_xss #xss_attack #web_security #xss_vulnerability
════════════════════════
𐀪 Author: Noman Chowdhury
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 22:24:56 GMT
════════════════════════
⌗ Tags: #dvwa #reflected_xss #xss_attack #web_security #xss_vulnerability
Medium
DVWA Walkthrough: Reflected XSS (All Difficulties)
Hello folks! It’s darksp1rit again with another walkthrough blog. Today we’ll go through the Damn Vulnerable Web Application’s Reflected…
⤷ Title: Microsoft Launches “Hey, Copilot” Voice Trigger and Visual AI Context to Transform Windows 11 Assistant
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:56:47 +0000
════════════════════════
⌗ Tags: #Windows #AI Assistant #Copilot #Copilot Actions #Microsoft #privacy #Visual AI #Voice Command #Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:56:47 +0000
════════════════════════
⌗ Tags: #Windows #AI Assistant #Copilot #Copilot Actions #Microsoft #privacy #Visual AI #Voice Command #Windows 11
Daily CyberSecurity
Microsoft Launches “Hey, Copilot” Voice Trigger and Visual AI Context to Transform Windows 11 Assistant
Microsoft rolls out “Hey, Copilot” voice activation and visual context features in Windows 11. The assistant can now analyze your screen and automate system actions with optional Copilot Actions.
⤷ Title: Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:51:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2025_41253 #security advisory #SpEL injection #Spring Cloud Gateway #Spring Framework #WebSocket
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:51:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2025_41253 #security advisory #SpEL injection #Spring Cloud Gateway #Spring Framework #WebSocket
Daily CyberSecurity
Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
Spring fixed two flaws: CVE-2025-41253 allows SpEL injection in Cloud Gateway to expose secrets, and CVE-2025-41254 allows STOMP CSRF to send unauthorized WebSocket messages. Update immediately.
⤷ Title: Critical ConnectWise Automate Flaw (CVE-2025-11492, CVSS 9.6) Allows RMM Agent Man-in-the-Middle Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:42:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise Automate #Critical Vulnerability #CVE_2025_11492 #Man in the Middle #mitm #RMM #Unencrypted Traffic
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:42:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise Automate #Critical Vulnerability #CVE_2025_11492 #Man in the Middle #mitm #RMM #Unencrypted Traffic
Daily CyberSecurity
Critical ConnectWise Automate Flaw (CVE-2025-11492, CVSS 9.6) Allows RMM Agent Man-in-the-Middle Attack
ConnectWise patched two high-severity flaws in Automate RMM. CVE-2025-11492 (CVSS 9.6) allows MiTM attack to intercept unencrypted agent communications and inject malicious updates. Update to 2025.9.
⤷ Title: North Korea’s Famous Chollima APT Uses Trojanized Node.js App to Deploy OtterCookie RAT for Crypto Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:30:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BeaverTail #Cryptojacking #Espionage #Famous Chollima #Node.js #North Korea APT #OtterCookie #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:30:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BeaverTail #Cryptojacking #Espionage #Famous Chollima #Node.js #North Korea APT #OtterCookie #Supply Chain
Daily CyberSecurity
North Korea’s Famous Chollima APT Uses Trojanized Node.js App to Deploy OtterCookie RAT for Crypto Theft
A new report from Cisco Talos has exposed a malware campaign linked to Famous Chollima, a North Korean threat group aligned with the Lazarus APT and known for its long-running job-themed espionage…
⤷ Title: Cisco Patches High-Severity CVE-2025-20350 DoS Flaw in Desk and IP Phones
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #cisco #CVE_2025_20350 #cybersecurity #dos #IP Phone #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #cisco #CVE_2025_20350 #cybersecurity #dos #IP Phone #XSS
Daily CyberSecurity
Cisco Patches High-Severity CVE-2025-20350 DoS Flaw in Desk and IP Phones
Cisco has released security updates to patch two vulnerabilities (CVE-2025-20350 and CVE-2025-20351) affecting multiple Cisco Desk Phone and IP Phone models, including the 9800, 7800, 8800, and 88…
⤷ Title: Operation Silk Lure: Chinese Espionage Targets FinTech with Malicious Resume LNK to Implant ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:16:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #cybersecurity #Espionage #FinTech #LNK File #Operation Silk Lure #Scheduled Task #ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:16:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #cybersecurity #Espionage #FinTech #LNK File #Operation Silk Lure #Scheduled Task #ValleyRAT
Daily CyberSecurity
Operation Silk Lure: Chinese Espionage Targets FinTech with Malicious Resume LNK to Implant ValleyRAT
Seqrite exposed Operation Silk Lure, a campaign using a malicious Chinese resume (.LNK) to implant ValleyRAT on FinTech systems. It achieves persistence via a “Security” scheduled task and uninstalls AV.
⤷ Title: Qilin Ransomware’s Resilience Exposed: Bulletproof Hosting Network Underpins Asahi Group Holdings Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Asahi Group #BPH #bulletproof hosting #Cybercrime #Qilin Ransomware #RaaS #russia #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Asahi Group #BPH #bulletproof hosting #Cybercrime #Qilin Ransomware #RaaS #russia #Supply Chain
Daily CyberSecurity
Qilin Ransomware's Resilience Exposed: Bulletproof Hosting Network Underpins Asahi Group Holdings Attack
Resecurity exposed Qilin RaaS's reliance on bulletproof hosting (BPH) in Russia/HK. The same network was linked to the Asahi Group Holdings ransomware attack that stole 27 GB of data.
⤷ Title: Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:06:23 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Fileless Malware #Maverick #Self_Propagation #UPI Fraud #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:06:23 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Fileless Malware #Maverick #Self_Propagation #UPI Fraud #WhatsApp #WPPConnect
Daily CyberSecurity
Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials
Kaspersky exposed Maverick, a sophisticated fileless banking Trojan targeting Brazil. It hijacks WhatsApp Web using WPPConnect for self-propagation and installs phishing overlays to steal UPI/banking data.
⤷ Title: Google Cloud Launches Gemini Enterprise: Unifying AI Agents and No-Code Workbench for Business Transformation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:03:18 +0000
════════════════════════
⌗ Tags: #Technology #Advantech #AI Agents #enterprise AI #Gemini Enterprise #Google Cloud #No_Code #Workflow Orchestration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:03:18 +0000
════════════════════════
⌗ Tags: #Technology #Advantech #AI Agents #enterprise AI #Gemini Enterprise #Google Cloud #No_Code #Workflow Orchestration
Daily CyberSecurity
Google Cloud Launches Gemini Enterprise: Unifying AI Agents and No-Code Workbench for Business Transformation
Google Cloud launched Gemini Enterprise, a platform unifying models, governance, and a no-code workbench. It empowers employees to build AI agents to optimize factories and supply chains.
⤷ Title: Zero-Click NTLM Leak Returns: New LNK Bypass (PoC Available) Bypasses Patch, Exposing Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:02:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Leak #LNK File #NTLM #NTLM Relay #patch bypass #Windows vulnerability #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:02:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Leak #LNK File #NTLM #NTLM Relay #patch bypass #Windows vulnerability #Zero_Click
Daily CyberSecurity
Zero-Click NTLM Leak Returns: New LNK Bypass (PoC Available) Bypasses Patch, Exposing Credentials
A new Zero-Click NTLM leak bypasses Microsoft's LNK patch, allowing unauthenticated NTLM hash theft on patched systems. The PoC works by exploiting UNC paths and the default shell32.dll icon reference.
⤷ Title: Meta to Invest $1.5 Billion in Massive 1-Gigawatt Texas Data Center for Next-Gen AI Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #AI Race #Capital Expenditure #Data Center #El Paso #Gigawatt #Mark Zuckerberg #Meta
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #AI Race #Capital Expenditure #Data Center #El Paso #Gigawatt #Mark Zuckerberg #Meta
Daily CyberSecurity
Meta to Invest $1.5 Billion in Massive 1-Gigawatt Texas Data Center for Next-Gen AI Infrastructure
Meta announced a $1.5B investment for a 1-gigawatt AI data center in El Paso, Texas, operational in 2028. It's part of a massive $72B CapEx plan to lead the global AI infrastructure race.
⤷ Title: Command Injections
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:59:19 GMT
════════════════════════
⌗ Tags: #hacking #command_injection #ctf
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:59:19 GMT
════════════════════════
⌗ Tags: #hacking #command_injection #ctf
Medium
Command Injections
Building OS command injection payloads to save time in a CTF environment
⤷ Title: The Economics of Cyber Hygiene: Why Small Improvements Drive Large Returns
════════════════════════
𐀪 Author: Owen Williams
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:55:33 GMT
════════════════════════
⌗ Tags: #technology #risk_management #cybersecurity
════════════════════════
𐀪 Author: Owen Williams
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:55:33 GMT
════════════════════════
⌗ Tags: #technology #risk_management #cybersecurity
Medium
The Economics of Cyber Hygiene: Why Small Improvements Drive Large Returns
Every breach starts with something small.
A missed patch. A link in an email. An unused control. A moment of inattention.
A missed patch. A link in an email. An unused control. A moment of inattention.
⤷ Title: Weaponizing Trust: How Attackers Exploit Valid Accounts After Phishing
════════════════════════
𐀪 Author: Shivam Kanodia
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:56:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitre_attack #phishing #artificial_intelligence
════════════════════════
𐀪 Author: Shivam Kanodia
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:56:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitre_attack #phishing #artificial_intelligence
Medium
Weaponizing Trust: How Attackers Exploit Valid Accounts After Phishing
Phishing (MITRE ATT&CK T1566) is one of the most dominant and versatile initial access vectors for cybercriminals to exploit. Attackers use…
⤷ Title: Key takeaways from leading my first Incident Response
════════════════════════
𐀪 Author: 0xPhelanLabs
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:40:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberattack #incident_response #ethical_hacking
════════════════════════
𐀪 Author: 0xPhelanLabs
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:40:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberattack #incident_response #ethical_hacking
Medium
Key takeaways from leading my first Incident Response
NOTE: In my past roles within Cyber Security, I assisted investigations / incident response initiatives where my role to provide some…
⤷ Title: Como não lidar com senhas expostas em repositórios
════════════════════════
𐀪 Author: njcholas
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:21:51 GMT
════════════════════════
⌗ Tags: #devops #security #appsec #devsecops #cybersecurity
════════════════════════
𐀪 Author: njcholas
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:21:51 GMT
════════════════════════
⌗ Tags: #devops #security #appsec #devsecops #cybersecurity
Medium
Como não lidar com senhas expostas em repositórios
Lidar com senhas expostas em repositórios é um problema evidente em (quase) todas as empresas que desenvolvem software. A dificuldade de…
⤷ Title: Why 83% of organization implemented Zero trust Model?
════════════════════════
𐀪 Author: Raviteja Mureboina
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:15:14 GMT
════════════════════════
⌗ Tags: #microsoft #report #cybersecurity #research #zero_trust
════════════════════════
𐀪 Author: Raviteja Mureboina
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:15:14 GMT
════════════════════════
⌗ Tags: #microsoft #report #cybersecurity #research #zero_trust
Medium
Why 83% of organization implemented Zero trust Model?
Cybersecurity has evolved from a protective measure into a strategic priority. A recent global study conducted in partnership with…
⤷ Title: HOW TO FIND STORED XSS IN GOOGLE ASSETS & XSS CHAINING TRICK IN CSP PROTECTED GOOGLE
════════════════════════
𐀪 Author: Azza0X1A
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:03:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #google_bug
════════════════════════
𐀪 Author: Azza0X1A
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:03:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #google_bug
Medium
HOW TO FIND STORED XSS IN GOOGLE ASSETS & XSS CHAINING TRICK IN CSP PROTECTED GOOGLE
🎯 KENAPA BANYAK HUNTER GAGAL DI GOOGLE
⤷ Title: PolarDNS Tool Enables Security Research by Generating Malformed and Non-Compliant DNS Responses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:47:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DNS Resolver #DNS Security #Penetration Testing #PolarDNS #Protocol Fuzzing #TCP #UDP #Vulnerability Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:47:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DNS Resolver #DNS Security #Penetration Testing #PolarDNS #Protocol Fuzzing #TCP #UDP #Vulnerability Research
Penetration Testing Tools
PolarDNS Tool Enables Security Research by Generating Malformed and Non-Compliant DNS Responses
PolarDNS is an open-source authoritative DNS server written in Python 3. It's designed for security testing of DNS resolvers/clients by creating malformed and non-compliant DNS responses over UDP/TCP.
⤷ Title: ScrapPY: generate wordlists that can be utilized by offensive security tools
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:41:22 +0000
════════════════════════
⌗ Tags: #Open Source Tool #generate wordlists #ScrapPY
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:41:22 +0000
════════════════════════
⌗ Tags: #Open Source Tool #generate wordlists #ScrapPY
Penetration Testing Tools
ScrapPY: generate wordlists that can be utilized by offensive security tools
ScrapPY is a Python utility for scraping manuals, documents, and other sensitive PDFs to generate targeted wordlists that can be utilized