⤷ Title: Romantyzacja “myślenia jak napastnik”
════════════════════════
𐀪 Author: Marcel Pewny
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:44:09 GMT
════════════════════════
⌗ Tags: #education #blue_team #cybersecurity #society #penetration_testing
════════════════════════
𐀪 Author: Marcel Pewny
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:44:09 GMT
════════════════════════
⌗ Tags: #education #blue_team #cybersecurity #society #penetration_testing
Medium
Romantyzacja “myślenia jak napastnik”
Określenie to jest sygnałem o niedojrzałości w budowaniu cyberbezpieczenstwa i zespołów defensywnych.
⤷ Title: Hackers Don’t Need Homework: Why Schools Are Easy Prey in the Digital Age
════════════════════════
𐀪 Author: CyberTalks
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:39:25 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #schools #cybersecurity #education #technology
════════════════════════
𐀪 Author: CyberTalks
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:39:25 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #schools #cybersecurity #education #technology
Medium
Hackers Don’t Need Homework: Why Schools Are Easy Prey in the Digital Age
Introduction: Classrooms have gone digital, but behind the glowing screens and smart boards lies a silent threat. Every click, every login…
⤷ Title: burpgpt: leverages the power of AI to detect security vulnerabilities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:10:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Burp Suite #Burp Suite OpenAI #OpenAI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:10:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Burp Suite #Burp Suite OpenAI #OpenAI
Penetration Testing Tools
burpgpt: leverages the power of AI to detect security vulnerabilities
burpgpt leverages the power of AI to detect security vulnerabilities that traditional scanners might miss. It sends web traffic
⤷ Title: Trojan on npm: Fake Utility Package Used to Deliver a Cobalt Strike Clone
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:05:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #cybersecurity #malware #npm #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:05:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #cybersecurity #malware #npm #supply chain attack
Penetration Testing Tools
Trojan on npm: Fake Utility Package Used to Deliver a Cobalt Strike Clone
A trojanized npm package, https-proxy-utils, was found installing AdaptixC2, an open-source Cobalt Strike clone, on developers' machines.
⤷ Title: Windows 11 Copilot Actions: The Power and Peril of AI Accessing Local Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:04:07 +0000
════════════════════════
⌗ Tags: #Microsoft #AI #Copilot #cybersecurity #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:04:07 +0000
════════════════════════
⌗ Tags: #Microsoft #AI #Copilot #cybersecurity #Windows 11
Penetration Testing Tools
Windows 11 Copilot Actions: The Power and Peril of AI Accessing Local Files
Microsoft is testing Copilot Actions in Windows 11, enabling AI to manage local files, but warns of risks like cross-prompt injection.
⤷ Title: Training Solo: New Spectre-v2 Attack Bypasses Kernel and Hypervisor Defenses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:59:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CPU #cybersecurity #kernel #Spectre_v2 #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:59:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #CPU #cybersecurity #kernel #Spectre_v2 #vulnerability
Penetration Testing Tools
Training Solo: New Spectre-v2 Attack Bypasses Kernel and Hypervisor Defenses
Researchers unveil "Training Solo," a new Spectre-v2 study showing attackers can bypass isolation to self-train branch predictors and steal kernel data.
⤷ Title: Zero-Day Alert: Attackers Exploit New Flaw to Bypass CentreStack RCE Patch
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:57:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #CentreStack #cybersecurity #RCE #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:57:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #CentreStack #cybersecurity #RCE #vulnerability #zero_day
Penetration Testing Tools
Zero-Day Alert: Attackers Exploit New Flaw to Bypass CentreStack RCE Patch
A new LFI zero-day (CVE-2025-11371) in CentreStack is actively exploited to bypass a previous RCE patch and steal credentials. Patch immediately.
⤷ Title: Microsoft Revokes 200+ Certificates Used to Disguise Rhysida Ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:55:18 +0000
════════════════════════
⌗ Tags: #Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:55:18 +0000
════════════════════════
⌗ Tags: #Malware
Penetration Testing Tools
Microsoft Revokes 200+ Certificates Used to Disguise Rhysida Ransomware
Microsoft revoked over 200 digital certificates abused by Rhysida ransomware to spread malware disguised as legitimate Microsoft Teams installers via SEO poisoning.
⤷ Title: Dark Web Alert: Massive Data Leak from Russian SMS Aggregators Threatens Global Accounts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:52:51 +0000
════════════════════════
⌗ Tags: #Data Leak #2FA #cybersecurity #data breach #Russia #SMS #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:52:51 +0000
════════════════════════
⌗ Tags: #Data Leak #2FA #cybersecurity #data breach #Russia #SMS #supply chain attack
Penetration Testing Tools
Dark Web Alert: Massive Data Leak from Russian SMS Aggregators Threatens Global Accounts
A dark web post claims 3TB of data from two Russian SMS aggregators has been stolen, posing a huge risk of mass account takeover via 2FA codes.
⤷ Title: Phishing Campaign Targets Master Passwords of Top Managers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:50:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #1Password #Bitwarden #cybersecurity #LastPass #Password Manager #phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:50:04 +0000
════════════════════════
⌗ Tags: #Cybercriminals #1Password #Bitwarden #cybersecurity #LastPass #Password Manager #phishing
Penetration Testing Tools
Phishing Campaign Targets Master Passwords of Top Managers
A new phishing campaign is impersonating LastPass, Bitwarden, & 1Password to trick users into installing malware & stealing their master passwords.
⤷ Title: The AI-Powered Threat: Microsoft Reveals Surge in Identity and Nation-State Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:37:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #cybersecurity #identity theft #Microsoft #phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:37:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #cybersecurity #identity theft #Microsoft #phishing
Penetration Testing Tools
The AI-Powered Threat: Microsoft Reveals Surge in Identity and Nation-State Attacks
Microsoft’s 2025 Digital Defense Report details a 32% rise in identity attacks, the weaponization of AI in phishing, and new state-sponsored tactics.
⤷ Title: Beyond Chatbots: Microsoft’s New Tool Measures if AI Can Think Like a Cyber Analyst
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:35:17 +0000
════════════════════════
⌗ Tags: #Microsoft #AI #cybersecurity #ExCyTIn_Bench #machine learning #SoC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:35:17 +0000
════════════════════════
⌗ Tags: #Microsoft #AI #cybersecurity #ExCyTIn_Bench #machine learning #SoC
Penetration Testing Tools
Beyond Chatbots: Microsoft's New Tool Measures if AI Can Think Like a Cyber Analyst
Microsoft's open ExCyTIn-Bench simulates a SOC center to measure AI's ability to investigate complex cyber incidents, going beyond simple knowledge tests.
⤷ Title: Critical Windows 11 Update Breaks Localhost HTTP/2 Connections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:32:48 +0000
════════════════════════
⌗ Tags: #Windows #bug #cybersecurity #developers #HTTP/2 #Microsoft #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:32:48 +0000
════════════════════════
⌗ Tags: #Windows #bug #cybersecurity #developers #HTTP/2 #Microsoft #Windows 11
Penetration Testing Tools
Critical Windows 11 Update Breaks Localhost HTTP/2 Connections
Windows 11 updates KB5066835 & KB5065789 broke local HTTP/2 connections on 127.0.0.1, causing critical failures for developers and services.
⤷ Title: CISA Warning: Critical Adobe Flaw Rated 10/10 Under Active Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #adobe #CISA #cybersecurity #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #adobe #CISA #cybersecurity #vulnerability #zero_day
Penetration Testing Tools
CISA Warning: Critical Adobe Flaw Rated 10/10 Under Active Attack
CISA adds a critical, actively exploited Adobe Experience Manager (AEM) RCE flaw (CVSS 10.0) to its KEV catalog, demanding immediate patching.
⤷ Title: Stealth Innovation: LinkPro Linux Rootkit Hides via eBPF and Activates with Magic TCP Packet on Kubernetes Nodes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:28:28 +0000
════════════════════════
⌗ Tags: #Malware #eBPF #Kubernetes #LinkPro #Linux Rootkit #Magic Packet #Stealth C2 #TCP #VShell #XDP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:28:28 +0000
════════════════════════
⌗ Tags: #Malware #eBPF #Kubernetes #LinkPro #Linux Rootkit #Magic Packet #Stealth C2 #TCP #VShell #XDP
Penetration Testing Tools
Stealth Innovation: LinkPro Linux Rootkit Hides via eBPF and Activates with Magic TCP Packet on Kubernetes Nodes
Synacktiv exposed LinkPro, an advanced Linux rootkit using eBPF to cloak activity on Kubernetes nodes. It is activated by a "magic" TCP packet (window size 54321) to establish covert remote control.
⤷ Title: Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:53:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_62168 #HTTP Credentials #Information Disclosure #Redaction Failure #Security Token #Squid Proxy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:53:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_62168 #HTTP Credentials #Information Disclosure #Redaction Failure #Security Token #Squid Proxy
Daily CyberSecurity
Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling
A Critical (CVSS 10.0) flaw in Squid proxy (CVE-2025-62168) leaks HTTP authentication credentials and security tokens through error messages.
⤷ Title: GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:40:52 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #GlassWorm #HVNC #Solana Blockchain #supply chain attack #Unicode Injection #VSCode #ZOMBI RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:40:52 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #GlassWorm #HVNC #Solana Blockchain #supply chain attack #Unicode Injection #VSCode #ZOMBI RAT
Daily CyberSecurity
GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
Koi Security exposed GlassWorm, the first VSCode worm that spreads autonomously, using invisible Unicode to hide malicious code. It uses Solana blockchain and Google Calendar for a resilient C2.
⤷ Title: SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:36:20 +0000
════════════════════════
⌗ Tags: #Malware #anti_vm #Banking Trojan #CAPI #Credential Theft #LNK File #russia #Scheduled Task #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:36:20 +0000
════════════════════════
⌗ Tags: #Malware #anti_vm #Banking Trojan #CAPI #Credential Theft #LNK File #russia #Scheduled Task #spear_phishing
Daily CyberSecurity
SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors
SEQRITE exposed CAPI, a .NET trojan targeting Russian FinTech with malicious LNK resumes. It uses rundll32 for execution and a hidden "Security" scheduled task for persistence.
⤷ Title: UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:32:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Blockchain #BNB Smart Chain #C2 #Decentralization #EtherHiding #Malware Distribution #Smart Contract #UNC5142
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:32:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Blockchain #BNB Smart Chain #C2 #Decentralization #EtherHiding #Malware Distribution #Smart Contract #UNC5142
Daily CyberSecurity
UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
Mandiant exposed UNC5142 for using EtherHiding—hiding malicious JavaScript in BNB Smart Chain smart contracts—to create a resilient C2 and distribute VIDAR/ATOMIC to 14,000+ sites.
⤷ Title: 131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:26:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Abuse #Automation #Chrome extension #DBX Tecnologia #Google Web Store #Spamware #WhatsApp Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:26:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Abuse #Automation #Chrome extension #DBX Tecnologia #Google Web Store #Spamware #WhatsApp Web
Daily CyberSecurity
131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme
A spamware network of 131 cloned Chrome extensions (YouSeller, Botflow) is abusing WhatsApp Web for automated messaging. The DBX Tecnologia reseller scheme affects 20K+ users.
⤷ Title: FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:21:00 +0000
════════════════════════
⌗ Tags: #Malware #APT #Cross_Regional Attack #DLL Sideloading #FortiGuard #HoldingHands #Malware Evasion #Task Scheduler Hijack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:21:00 +0000
════════════════════════
⌗ Tags: #Malware #APT #Cross_Regional Attack #DLL Sideloading #FortiGuard #HoldingHands #Malware Evasion #Task Scheduler Hijack
Daily CyberSecurity
FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection
FortiGuard exposed a cross-regional campaign that expanded to Malaysia using HoldingHands malware. The malware hijacks Task Scheduler via TimeBrokerClient.dll to achieve stealthy persistence.