⤷ Title: Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:51:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2025_41253 #security advisory #SpEL injection #Spring Cloud Gateway #Spring Framework #WebSocket
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:51:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CSRF #CVE_2025_41253 #security advisory #SpEL injection #Spring Cloud Gateway #Spring Framework #WebSocket
Daily CyberSecurity
Spring Patches Two Flaws: SpEL Injection (CVE-2025-41253) Leaks Secrets, STOMP CSRF Bypasses WebSocket Security
Spring fixed two flaws: CVE-2025-41253 allows SpEL injection in Cloud Gateway to expose secrets, and CVE-2025-41254 allows STOMP CSRF to send unauthorized WebSocket messages. Update immediately.
⤷ Title: Critical ConnectWise Automate Flaw (CVE-2025-11492, CVSS 9.6) Allows RMM Agent Man-in-the-Middle Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:42:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise Automate #Critical Vulnerability #CVE_2025_11492 #Man in the Middle #mitm #RMM #Unencrypted Traffic
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:42:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ConnectWise Automate #Critical Vulnerability #CVE_2025_11492 #Man in the Middle #mitm #RMM #Unencrypted Traffic
Daily CyberSecurity
Critical ConnectWise Automate Flaw (CVE-2025-11492, CVSS 9.6) Allows RMM Agent Man-in-the-Middle Attack
ConnectWise patched two high-severity flaws in Automate RMM. CVE-2025-11492 (CVSS 9.6) allows MiTM attack to intercept unencrypted agent communications and inject malicious updates. Update to 2025.9.
⤷ Title: North Korea’s Famous Chollima APT Uses Trojanized Node.js App to Deploy OtterCookie RAT for Crypto Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:30:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BeaverTail #Cryptojacking #Espionage #Famous Chollima #Node.js #North Korea APT #OtterCookie #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:30:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BeaverTail #Cryptojacking #Espionage #Famous Chollima #Node.js #North Korea APT #OtterCookie #Supply Chain
Daily CyberSecurity
North Korea’s Famous Chollima APT Uses Trojanized Node.js App to Deploy OtterCookie RAT for Crypto Theft
A new report from Cisco Talos has exposed a malware campaign linked to Famous Chollima, a North Korean threat group aligned with the Lazarus APT and known for its long-running job-themed espionage…
⤷ Title: Cisco Patches High-Severity CVE-2025-20350 DoS Flaw in Desk and IP Phones
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #cisco #CVE_2025_20350 #cybersecurity #dos #IP Phone #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #cisco #CVE_2025_20350 #cybersecurity #dos #IP Phone #XSS
Daily CyberSecurity
Cisco Patches High-Severity CVE-2025-20350 DoS Flaw in Desk and IP Phones
Cisco has released security updates to patch two vulnerabilities (CVE-2025-20350 and CVE-2025-20351) affecting multiple Cisco Desk Phone and IP Phone models, including the 9800, 7800, 8800, and 88…
⤷ Title: Operation Silk Lure: Chinese Espionage Targets FinTech with Malicious Resume LNK to Implant ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:16:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #cybersecurity #Espionage #FinTech #LNK File #Operation Silk Lure #Scheduled Task #ValleyRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:16:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #cybersecurity #Espionage #FinTech #LNK File #Operation Silk Lure #Scheduled Task #ValleyRAT
Daily CyberSecurity
Operation Silk Lure: Chinese Espionage Targets FinTech with Malicious Resume LNK to Implant ValleyRAT
Seqrite exposed Operation Silk Lure, a campaign using a malicious Chinese resume (.LNK) to implant ValleyRAT on FinTech systems. It achieves persistence via a “Security” scheduled task and uninstalls AV.
⤷ Title: Qilin Ransomware’s Resilience Exposed: Bulletproof Hosting Network Underpins Asahi Group Holdings Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Asahi Group #BPH #bulletproof hosting #Cybercrime #Qilin Ransomware #RaaS #russia #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Asahi Group #BPH #bulletproof hosting #Cybercrime #Qilin Ransomware #RaaS #russia #Supply Chain
Daily CyberSecurity
Qilin Ransomware's Resilience Exposed: Bulletproof Hosting Network Underpins Asahi Group Holdings Attack
Resecurity exposed Qilin RaaS's reliance on bulletproof hosting (BPH) in Russia/HK. The same network was linked to the Asahi Group Holdings ransomware attack that stole 27 GB of data.
⤷ Title: Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:06:23 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Fileless Malware #Maverick #Self_Propagation #UPI Fraud #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:06:23 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Fileless Malware #Maverick #Self_Propagation #UPI Fraud #WhatsApp #WPPConnect
Daily CyberSecurity
Maverick Fileless Trojan Turns Infected Phones into WhatsApp Worms to Steal Banking and UPI Credentials
Kaspersky exposed Maverick, a sophisticated fileless banking Trojan targeting Brazil. It hijacks WhatsApp Web using WPPConnect for self-propagation and installs phishing overlays to steal UPI/banking data.
⤷ Title: Google Cloud Launches Gemini Enterprise: Unifying AI Agents and No-Code Workbench for Business Transformation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:03:18 +0000
════════════════════════
⌗ Tags: #Technology #Advantech #AI Agents #enterprise AI #Gemini Enterprise #Google Cloud #No_Code #Workflow Orchestration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:03:18 +0000
════════════════════════
⌗ Tags: #Technology #Advantech #AI Agents #enterprise AI #Gemini Enterprise #Google Cloud #No_Code #Workflow Orchestration
Daily CyberSecurity
Google Cloud Launches Gemini Enterprise: Unifying AI Agents and No-Code Workbench for Business Transformation
Google Cloud launched Gemini Enterprise, a platform unifying models, governance, and a no-code workbench. It empowers employees to build AI agents to optimize factories and supply chains.
⤷ Title: Zero-Click NTLM Leak Returns: New LNK Bypass (PoC Available) Bypasses Patch, Exposing Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:02:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Leak #LNK File #NTLM #NTLM Relay #patch bypass #Windows vulnerability #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:02:38 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Leak #LNK File #NTLM #NTLM Relay #patch bypass #Windows vulnerability #Zero_Click
Daily CyberSecurity
Zero-Click NTLM Leak Returns: New LNK Bypass (PoC Available) Bypasses Patch, Exposing Credentials
A new Zero-Click NTLM leak bypasses Microsoft's LNK patch, allowing unauthenticated NTLM hash theft on patched systems. The PoC works by exploiting UNC paths and the default shell32.dll icon reference.
⤷ Title: Meta to Invest $1.5 Billion in Massive 1-Gigawatt Texas Data Center for Next-Gen AI Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #AI Race #Capital Expenditure #Data Center #El Paso #Gigawatt #Mark Zuckerberg #Meta
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:00:07 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #AI Race #Capital Expenditure #Data Center #El Paso #Gigawatt #Mark Zuckerberg #Meta
Daily CyberSecurity
Meta to Invest $1.5 Billion in Massive 1-Gigawatt Texas Data Center for Next-Gen AI Infrastructure
Meta announced a $1.5B investment for a 1-gigawatt AI data center in El Paso, Texas, operational in 2028. It's part of a massive $72B CapEx plan to lead the global AI infrastructure race.
⤷ Title: Command Injections
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:59:19 GMT
════════════════════════
⌗ Tags: #hacking #command_injection #ctf
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:59:19 GMT
════════════════════════
⌗ Tags: #hacking #command_injection #ctf
Medium
Command Injections
Building OS command injection payloads to save time in a CTF environment
⤷ Title: The Economics of Cyber Hygiene: Why Small Improvements Drive Large Returns
════════════════════════
𐀪 Author: Owen Williams
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:55:33 GMT
════════════════════════
⌗ Tags: #technology #risk_management #cybersecurity
════════════════════════
𐀪 Author: Owen Williams
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:55:33 GMT
════════════════════════
⌗ Tags: #technology #risk_management #cybersecurity
Medium
The Economics of Cyber Hygiene: Why Small Improvements Drive Large Returns
Every breach starts with something small.
A missed patch. A link in an email. An unused control. A moment of inattention.
A missed patch. A link in an email. An unused control. A moment of inattention.
⤷ Title: Weaponizing Trust: How Attackers Exploit Valid Accounts After Phishing
════════════════════════
𐀪 Author: Shivam Kanodia
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:56:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitre_attack #phishing #artificial_intelligence
════════════════════════
𐀪 Author: Shivam Kanodia
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:56:04 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitre_attack #phishing #artificial_intelligence
Medium
Weaponizing Trust: How Attackers Exploit Valid Accounts After Phishing
Phishing (MITRE ATT&CK T1566) is one of the most dominant and versatile initial access vectors for cybercriminals to exploit. Attackers use…
⤷ Title: Key takeaways from leading my first Incident Response
════════════════════════
𐀪 Author: 0xPhelanLabs
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:40:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberattack #incident_response #ethical_hacking
════════════════════════
𐀪 Author: 0xPhelanLabs
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:40:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #cyberattack #incident_response #ethical_hacking
Medium
Key takeaways from leading my first Incident Response
NOTE: In my past roles within Cyber Security, I assisted investigations / incident response initiatives where my role to provide some…
⤷ Title: Como não lidar com senhas expostas em repositórios
════════════════════════
𐀪 Author: njcholas
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:21:51 GMT
════════════════════════
⌗ Tags: #devops #security #appsec #devsecops #cybersecurity
════════════════════════
𐀪 Author: njcholas
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:21:51 GMT
════════════════════════
⌗ Tags: #devops #security #appsec #devsecops #cybersecurity
Medium
Como não lidar com senhas expostas em repositórios
Lidar com senhas expostas em repositórios é um problema evidente em (quase) todas as empresas que desenvolvem software. A dificuldade de…
⤷ Title: Why 83% of organization implemented Zero trust Model?
════════════════════════
𐀪 Author: Raviteja Mureboina
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:15:14 GMT
════════════════════════
⌗ Tags: #microsoft #report #cybersecurity #research #zero_trust
════════════════════════
𐀪 Author: Raviteja Mureboina
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 00:15:14 GMT
════════════════════════
⌗ Tags: #microsoft #report #cybersecurity #research #zero_trust
Medium
Why 83% of organization implemented Zero trust Model?
Cybersecurity has evolved from a protective measure into a strategic priority. A recent global study conducted in partnership with…
⤷ Title: HOW TO FIND STORED XSS IN GOOGLE ASSETS & XSS CHAINING TRICK IN CSP PROTECTED GOOGLE
════════════════════════
𐀪 Author: Azza0X1A
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:03:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #google_bug
════════════════════════
𐀪 Author: Azza0X1A
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 01:03:00 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #bug_bounty_tips #google_bug
Medium
HOW TO FIND STORED XSS IN GOOGLE ASSETS & XSS CHAINING TRICK IN CSP PROTECTED GOOGLE
🎯 KENAPA BANYAK HUNTER GAGAL DI GOOGLE
⤷ Title: PolarDNS Tool Enables Security Research by Generating Malformed and Non-Compliant DNS Responses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:47:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DNS Resolver #DNS Security #Penetration Testing #PolarDNS #Protocol Fuzzing #TCP #UDP #Vulnerability Research
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:47:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DNS Resolver #DNS Security #Penetration Testing #PolarDNS #Protocol Fuzzing #TCP #UDP #Vulnerability Research
Penetration Testing Tools
PolarDNS Tool Enables Security Research by Generating Malformed and Non-Compliant DNS Responses
PolarDNS is an open-source authoritative DNS server written in Python 3. It's designed for security testing of DNS resolvers/clients by creating malformed and non-compliant DNS responses over UDP/TCP.
⤷ Title: ScrapPY: generate wordlists that can be utilized by offensive security tools
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:41:22 +0000
════════════════════════
⌗ Tags: #Open Source Tool #generate wordlists #ScrapPY
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:41:22 +0000
════════════════════════
⌗ Tags: #Open Source Tool #generate wordlists #ScrapPY
Penetration Testing Tools
ScrapPY: generate wordlists that can be utilized by offensive security tools
ScrapPY is a Python utility for scraping manuals, documents, and other sensitive PDFs to generate targeted wordlists that can be utilized
⤷ Title: Windows 10 EOL Sparks E-Waste Crisis: 400 Million PCs Lose Security Support, Fueling Obsolescence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:36:57 +0000
════════════════════════
⌗ Tags: #Technology #Windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:36:57 +0000
════════════════════════
⌗ Tags: #Technology #Windows
Penetration Testing Tools
Windows 10 EOL Sparks E-Waste Crisis: 400 Million PCs Lose Security Support, Fueling Obsolescence
Windows 10 support ended, leaving 400 million incompatible PCs without security patches. Critics warn the purely commercial decision risks a global e-waste crisis and a WannaCry-like attack surge.
⤷ Title: Operation ZeroDisco: Critical Cisco SNMP Flaw (CVE-2025-20352) Used to Implant Linux Rootkits and Inject “Disco” Password
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:33:31 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Cisco #Cisco Switches #CVE_2025_20352 #IOSd #rootkit #SNMP RCE #ZeroDisco
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 17 Oct 2025 02:33:31 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #Cisco #Cisco Switches #CVE_2025_20352 #IOSd #rootkit #SNMP RCE #ZeroDisco
Penetration Testing Tools
Operation ZeroDisco: Critical Cisco SNMP Flaw (CVE-2025-20352) Used to Implant Linux Rootkits and Inject "Disco" Password
Trend Micro exposed ZeroDisco, a sophisticated op exploiting Cisco SNMP RCE (CVE-2025-20352) to install Linux rootkits on switches, setting a volatile universal "disco" password and erasing logs.