⤷ Title: The AI-Powered Threat: Microsoft Reveals Surge in Identity and Nation-State Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:37:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #cybersecurity #identity theft #Microsoft #phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:37:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #cybersecurity #identity theft #Microsoft #phishing
Penetration Testing Tools
The AI-Powered Threat: Microsoft Reveals Surge in Identity and Nation-State Attacks
Microsoft’s 2025 Digital Defense Report details a 32% rise in identity attacks, the weaponization of AI in phishing, and new state-sponsored tactics.
⤷ Title: Beyond Chatbots: Microsoft’s New Tool Measures if AI Can Think Like a Cyber Analyst
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:35:17 +0000
════════════════════════
⌗ Tags: #Microsoft #AI #cybersecurity #ExCyTIn_Bench #machine learning #SoC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:35:17 +0000
════════════════════════
⌗ Tags: #Microsoft #AI #cybersecurity #ExCyTIn_Bench #machine learning #SoC
Penetration Testing Tools
Beyond Chatbots: Microsoft's New Tool Measures if AI Can Think Like a Cyber Analyst
Microsoft's open ExCyTIn-Bench simulates a SOC center to measure AI's ability to investigate complex cyber incidents, going beyond simple knowledge tests.
⤷ Title: Critical Windows 11 Update Breaks Localhost HTTP/2 Connections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:32:48 +0000
════════════════════════
⌗ Tags: #Windows #bug #cybersecurity #developers #HTTP/2 #Microsoft #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:32:48 +0000
════════════════════════
⌗ Tags: #Windows #bug #cybersecurity #developers #HTTP/2 #Microsoft #Windows 11
Penetration Testing Tools
Critical Windows 11 Update Breaks Localhost HTTP/2 Connections
Windows 11 updates KB5066835 & KB5065789 broke local HTTP/2 connections on 127.0.0.1, causing critical failures for developers and services.
⤷ Title: CISA Warning: Critical Adobe Flaw Rated 10/10 Under Active Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #adobe #CISA #cybersecurity #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #adobe #CISA #cybersecurity #vulnerability #zero_day
Penetration Testing Tools
CISA Warning: Critical Adobe Flaw Rated 10/10 Under Active Attack
CISA adds a critical, actively exploited Adobe Experience Manager (AEM) RCE flaw (CVSS 10.0) to its KEV catalog, demanding immediate patching.
⤷ Title: Stealth Innovation: LinkPro Linux Rootkit Hides via eBPF and Activates with Magic TCP Packet on Kubernetes Nodes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:28:28 +0000
════════════════════════
⌗ Tags: #Malware #eBPF #Kubernetes #LinkPro #Linux Rootkit #Magic Packet #Stealth C2 #TCP #VShell #XDP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 02:28:28 +0000
════════════════════════
⌗ Tags: #Malware #eBPF #Kubernetes #LinkPro #Linux Rootkit #Magic Packet #Stealth C2 #TCP #VShell #XDP
Penetration Testing Tools
Stealth Innovation: LinkPro Linux Rootkit Hides via eBPF and Activates with Magic TCP Packet on Kubernetes Nodes
Synacktiv exposed LinkPro, an advanced Linux rootkit using eBPF to cloak activity on Kubernetes nodes. It is activated by a "magic" TCP packet (window size 54321) to establish covert remote control.
⤷ Title: Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:53:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_62168 #HTTP Credentials #Information Disclosure #Redaction Failure #Security Token #Squid Proxy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:53:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_62168 #HTTP Credentials #Information Disclosure #Redaction Failure #Security Token #Squid Proxy
Daily CyberSecurity
Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling
A Critical (CVSS 10.0) flaw in Squid proxy (CVE-2025-62168) leaks HTTP authentication credentials and security tokens through error messages.
⤷ Title: GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:40:52 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #GlassWorm #HVNC #Solana Blockchain #supply chain attack #Unicode Injection #VSCode #ZOMBI RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 01:40:52 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #GlassWorm #HVNC #Solana Blockchain #supply chain attack #Unicode Injection #VSCode #ZOMBI RAT
Daily CyberSecurity
GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
Koi Security exposed GlassWorm, the first VSCode worm that spreads autonomously, using invisible Unicode to hide malicious code. It uses Solana blockchain and Google Calendar for a resilient C2.
⤷ Title: SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:36:20 +0000
════════════════════════
⌗ Tags: #Malware #anti_vm #Banking Trojan #CAPI #Credential Theft #LNK File #russia #Scheduled Task #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:36:20 +0000
════════════════════════
⌗ Tags: #Malware #anti_vm #Banking Trojan #CAPI #Credential Theft #LNK File #russia #Scheduled Task #spear_phishing
Daily CyberSecurity
SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors
SEQRITE exposed CAPI, a .NET trojan targeting Russian FinTech with malicious LNK resumes. It uses rundll32 for execution and a hidden "Security" scheduled task for persistence.
⤷ Title: UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:32:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Blockchain #BNB Smart Chain #C2 #Decentralization #EtherHiding #Malware Distribution #Smart Contract #UNC5142
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:32:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Blockchain #BNB Smart Chain #C2 #Decentralization #EtherHiding #Malware Distribution #Smart Contract #UNC5142
Daily CyberSecurity
UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
Mandiant exposed UNC5142 for using EtherHiding—hiding malicious JavaScript in BNB Smart Chain smart contracts—to create a resilient C2 and distribute VIDAR/ATOMIC to 14,000+ sites.
⤷ Title: 131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:26:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Abuse #Automation #Chrome extension #DBX Tecnologia #Google Web Store #Spamware #WhatsApp Web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:26:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Abuse #Automation #Chrome extension #DBX Tecnologia #Google Web Store #Spamware #WhatsApp Web
Daily CyberSecurity
131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme
A spamware network of 131 cloned Chrome extensions (YouSeller, Botflow) is abusing WhatsApp Web for automated messaging. The DBX Tecnologia reseller scheme affects 20K+ users.
⤷ Title: FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:21:00 +0000
════════════════════════
⌗ Tags: #Malware #APT #Cross_Regional Attack #DLL Sideloading #FortiGuard #HoldingHands #Malware Evasion #Task Scheduler Hijack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:21:00 +0000
════════════════════════
⌗ Tags: #Malware #APT #Cross_Regional Attack #DLL Sideloading #FortiGuard #HoldingHands #Malware Evasion #Task Scheduler Hijack
Daily CyberSecurity
FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection
FortiGuard exposed a cross-regional campaign that expanded to Malaysia using HoldingHands malware. The malware hijacks Task Scheduler via TimeBrokerClient.dll to achieve stealthy persistence.
⤷ Title: North Korea’s WaterPlum APT Deploys Node.js OtterCandy RAT for Crypto Theft with Anti-Forensic Module
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:17:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #anti_forensics #Contagious Interview #Crypto theft #Node.js #North Korea APT #OtterCandy #rat #WaterPlum
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:17:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #anti_forensics #Contagious Interview #Crypto theft #Node.js #North Korea APT #OtterCandy #rat #WaterPlum
Daily CyberSecurity
North Korea’s WaterPlum APT Deploys Node.js OtterCandy RAT for Crypto Theft with Anti-Forensic Module
NTT exposed WaterPlum APT's multi-platform OtterCandy RAT (v2), which uses Node.js for remote control, targets 7 browser extensions, and now includes anti-forensic trace deletion.
⤷ Title: Critical Moxa Flaw (CVE-2025-6950, CVSS 9.9) Allows Unauthenticated Admin Takeover via Hard-Coded JWT Secret
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:13:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_6950 #Hard_coded Credentials #ICS security #JWT #Moxa
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:13:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_6950 #Hard_coded Credentials #ICS security #JWT #Moxa
Daily CyberSecurity
Critical Moxa Flaw (CVE-2025-6950, CVSS 9.9) Allows Unauthenticated Admin Takeover via Hard-Coded JWT Secret
Moxa patched five critical flaws in its industrial routers, including a CVE-2025-6950 (CVSS 9.9) bug where hard-coded JWT credentials allow unauthenticated attackers to impersonate any user. Update to v3.21.
⤷ Title: Researcher Details Zero-Click RCE in Dolby Audio Decoder Affecting Android, iOS, and macOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:11:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #android #Audio Decoder #Dolby Digital Plus #integer overflow #ios #Project Zero #rce #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:11:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #android #Audio Decoder #Dolby Digital Plus #integer overflow #ios #Project Zero #rce #Zero_Click
Daily CyberSecurity
Researcher Details Zero-Click RCE in Dolby Audio Decoder Affecting Android, iOS, and macOS
Google Project Zero disclosed a zero-click RCE flaw (CVE-2025-54957, CVSS 7.0) in Dolby's Audio Decoder. The integer overflow can be triggered by a single audio file and affects Android, iOS, and macOS.
⤷ Title: North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:10:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Blockchain #C2 #Crypto theft #EtherHiding #InvisibleFerret #North Korea APT #Smart Contract #UNC5342
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:10:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Blockchain #C2 #Crypto theft #EtherHiding #InvisibleFerret #North Korea APT #Smart Contract #UNC5342
Daily CyberSecurity
North Korea's UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2
Google exposed UNC5342 (DPRK APT) using EtherHiding—hiding JADESNOW/INVISIBLEFERRET malware in BNB/Ethereum smart contracts—for a resilient, nation-state C2 infrastructure.
⤷ Title: Google Abandons Privacy Sandbox Initiative After 6 Years, Citing Low Adoption of New Ad Tech
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:08:56 +0000
════════════════════════
⌗ Tags: #Technology #ad tech #chrome #CMA #google #Privacy Sandbox #Termination #Third_Party Cookies #Topics API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:08:56 +0000
════════════════════════
⌗ Tags: #Technology #ad tech #chrome #CMA #google #Privacy Sandbox #Termination #Third_Party Cookies #Topics API
Daily CyberSecurity
Google Abandons Privacy Sandbox Initiative After 6 Years, Citing Low Adoption of New Ad Tech
Google officially terminated its Privacy Sandbox initiative due to low adoption of its new ad technologies (FLoC, Topics API). The decision marks the end of Google's plan to replace third-party cookies in Chrome.
⤷ Title: NVIDIA Unveils First Blackwell Wafer Made in US at TSMC Arizona Fab, Marking Production Milestone
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:05:29 +0000
════════════════════════
⌗ Tags: #Technology #AI chip #Arizona Fab #Blackwell #Jensen Huang #nvidia #semiconductor #Supply Chain Resilience #TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:05:29 +0000
════════════════════════
⌗ Tags: #Technology #AI chip #Arizona Fab #Blackwell #Jensen Huang #nvidia #semiconductor #Supply Chain Resilience #TSMC
Daily CyberSecurity
NVIDIA Unveils First Blackwell Wafer Made in US at TSMC Arizona Fab, Marking Production Milestone
NVIDIA recently announced a milestone of profound symbolic significance, as CEO Jensen Huang personally unveiled the first Blackwell wafer manufactured on U.S. soil during a celebratory event. Thi…
⤷ Title: Apple Secures Exclusive F1 Broadcasting Rights in the US Starting 2026; F1 TV Pro Included with Apple TV
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:02:14 +0000
════════════════════════
⌗ Tags: #Technology #Apple TV #Broadcasting Rights #F1 Exclusive #F1 TV Pro #Formula 1 #Motorsport #Sports Streaming
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:02:14 +0000
════════════════════════
⌗ Tags: #Technology #Apple TV #Broadcasting Rights #F1 Exclusive #F1 TV Pro #Formula 1 #Motorsport #Sports Streaming
Daily CyberSecurity
Apple Secures Exclusive F1 Broadcasting Rights in the US Starting 2026; F1 TV Pro Included with Apple TV
Apple has announced a landmark five-year exclusive broadcasting agreement with Formula 1’s parent company, Liberty Media, granting Apple TV the sole rights to stream all F1 races in the United Sta…
⤷ Title: Critical Keras 3 RCE Flaw (CVE-2025-49655, CVSS 9.8) Allows Code Execution on Model Load
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:01:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49655 #Deserialization #Keras 3 #ML Supply Chain #PyTorch #rce #Torch Backend
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:01:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49655 #Deserialization #Keras 3 #ML Supply Chain #PyTorch #rce #Torch Backend
Daily CyberSecurity
Critical Keras 3 RCE Flaw (CVE-2025-49655, CVSS 9.8) Allows Code Execution on Model Load
Researchers at HiddenLayer have disclosed a critical arbitrary code execution vulnerability in the Keras 3 deep learning framework (CVE-2025-49655, CVSS 9.8), which affects the Torch backend of Ke…
⤷ Title: Wikipedia Warns of Existential AI Threat as Page Views Fall 8% Due to Chatbot Summaries
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:00:25 +0000
════════════════════════
⌗ Tags: #Technology #AI Threat #Generative AI #Knowledge Ecosystem #Page Views #Volunteer Community #Wikimedia Foundation #Wikipedia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:00:25 +0000
════════════════════════
⌗ Tags: #Technology #AI Threat #Generative AI #Knowledge Ecosystem #Page Views #Volunteer Community #Wikimedia Foundation #Wikipedia
Daily CyberSecurity
Wikipedia Warns of Existential AI Threat as Page Views Fall 8% Due to Chatbot Summaries
The Wikimedia Foundation reported an 8% drop in page views, blaming AI chatbots and search summaries for siphoning traffic. It warns the decline threatens the sustainability of its volunteer community.
⤷ Title: Hacking for Good: How I Used ffuf to Secure a Government Website
════════════════════════
𐀪 Author: DevProgramming
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:48:30 GMT
════════════════════════
⌗ Tags: #government #vulnerability #pentesting #bug_bounty #tools
════════════════════════
𐀪 Author: DevProgramming
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 03:48:30 GMT
════════════════════════
⌗ Tags: #government #vulnerability #pentesting #bug_bounty #tools
Medium
Hacking for Good: How I Used ffuf to Secure a Government Website
My 4-Hour Fuzzing Process on a Government VDP: Wordlists, Recursion, and Filter Tricks to Bypass WAFs and Find Leaks.