⤷ Title: Critical Sauter AG Flaw (CVE-2025-41723, CVSS 9.8) Allows Unauthenticated File Upload via SOAP Interface
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:30:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_41723 #Directory Traversal #Hard_coded Credentials #ICS #Sauter AG #SOAP Interface
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:30:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_41723 #Directory Traversal #Hard_coded Credentials #ICS #Sauter AG #SOAP Interface
Daily CyberSecurity
Critical Sauter AG Flaw (CVE-2025-41723, CVSS 9.8) Allows Unauthenticated File Upload via SOAP Interface
Sauter patched six flaws in modulo 6 devices. The Critical CVE-2025-41723 (CVSS 9.8) flaw allows unauthenticated file upload via the SOAP interface, risking RCE. Update to v3.2.0.
⤷ Title: PassiveNeuron Cyberespionage Resurfaces: APT Abuses MS SQL Servers to Deploy Stealthy Neursite Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Asia #Cyberespionage #MsSQL #NeuralExecutor #Neursite #PassiveNeuron #Phantom DLL Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:26:39 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Asia #Cyberespionage #MsSQL #NeuralExecutor #Neursite #PassiveNeuron #Phantom DLL Hijacking
Daily CyberSecurity
PassiveNeuron Cyberespionage Resurfaces: APT Abuses MS SQL Servers to Deploy Stealthy Neursite Backdoor
Kaspersky exposed the resurfaced PassiveNeuron campaign targeting Asia via MS SQL servers. The APT deploys custom Neursite and NeuralExecutor backdoors using Phantom DLL Hijacking for stealth persistence.
⤷ Title: Scattered LAPSUS$ Hunters Pivot to EaaS, Launch Insider Recruitment Campaign After Salesforce Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:20:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #EaaS #Extortion_as_a_Service #Insider Threat #ransomware #Scattered LAPSUS$ Hunters #Telegram #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:20:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #EaaS #Extortion_as_a_Service #Insider Threat #ransomware #Scattered LAPSUS$ Hunters #Telegram #Unit 42
Daily CyberSecurity
Scattered LAPSUS$ Hunters Pivot to EaaS, Launch Insider Recruitment Campaign After Salesforce Extortion
Unit 42 exposed Scattered LAPSUS$ Hunters pivoting to Extortion-as-a-Service (EaaS) after Salesforce leaks. The group is recruiting insiders and teasing SHINYSP1D3R ransomware on Telegram.
⤷ Title: Critical ABB Flaw (CVE-2025-9574, CVSS 9.9) Exposes EoL Load Controllers to Unauthenticated Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:16:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB #ALS_mini_S4/S8 #Critical Vulnerability #CVE_2025_9574 #EOL #ICS #Missing Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:16:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB #ALS_mini_S4/S8 #Critical Vulnerability #CVE_2025_9574 #EOL #ICS #Missing Authentication
Daily CyberSecurity
Critical ABB Flaw (CVE-2025-9574, CVSS 9.9) Exposes EoL Load Controllers to Unauthenticated Admin Access
ABB disclosed a Critical (CVSS 9.9) Missing Auth flaw (CVE-2025-9574) in EoL ALS-mini-S4/S8 load controllers, allowing unauthenticated remote config access. No patch will be released.
⤷ Title: Bitter APT Attacks China/Pakistan with WinRAR Zero-Day and New C# Backdoor via Office Macro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:11:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Bitter APT #C# Backdoor #china #cyber_espionage #Macro Attack #Pakistan #WinRAR Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:11:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Bitter APT #C# Backdoor #china #cyber_espionage #Macro Attack #Pakistan #WinRAR Vulnerability
Daily CyberSecurity
Bitter APT Attacks China/Pakistan with WinRAR Zero-Day and New C# Backdoor via Office Macro
Qianxin exposed Bitter APT using a WinRAR path traversal flaw and malicious Office macros to deploy a C# backdoor against military/FinTech targets in Asia. The attack sets up scheduled persistence.
⤷ Title: COLDRIVER APT Bounces Back: Deploys ‘ROBOT’ Malware Family Days After LOSTKEYS Exposure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:05:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #ClickFix #COLDRIVER #cyber_espionage #LOSTKEYS #malware evolution #NOROBOT #ROBOT Malware #Russian APT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:05:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #ClickFix #COLDRIVER #cyber_espionage #LOSTKEYS #malware evolution #NOROBOT #ROBOT Malware #Russian APT
Daily CyberSecurity
COLDRIVER APT Bounces Back: Deploys 'ROBOT' Malware Family Days After LOSTKEYS Exposure
Google exposed Russia's COLDRIVER APT deploying a new "ROBOT" malware family (NOROBOT, YESROBOT) just 5 days after its LOSTKEYS tool was disclosed. The multi-stage malware uses a ClickFix lure.
⤷ Title: Researcher Demonstrates Local Privilege Escalation in Legacy Windows Modem Driver Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:01:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Agere Modem Driver #Arbitrary Read/Write #BYOVD #Kernel Exploit #PoC #Windows EoP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:01:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Agere Modem Driver #Arbitrary Read/Write #BYOVD #Kernel Exploit #PoC #Windows EoP
Daily CyberSecurity
Researcher Demonstrates Local Privilege Escalation in Legacy Windows Modem Driver Exploited in the Wild
A Windows Agere Modem EoP flaw (CVE-2025-24990) under active exploit allowed arbitrary kernel R/W even when unused. Microsoft removed the driver in the October update. PoC is available.
⤷ Title: WSO2 Fixes Two Critical Access Control Vulnerabilities (CVE-2025-9804, CVE-2025-10611) Affecting API Manager and Identity Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:00:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control #API Manager #Auth Bypass #Critical Vulnerability #CVE_2025_10611 #Identity Server #WSO2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:00:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Control #API Manager #Auth Bypass #Critical Vulnerability #CVE_2025_10611 #Identity Server #WSO2
Daily CyberSecurity
WSO2 Fixes Two Critical Access Control Vulnerabilities (CVE-2025-9804, CVE-2025-10611) Affecting API Manager and Identity Server
The WSO2 project has released urgent security advisories addressing two critical access control vulnerabilities—CVE-2025-9804 and CVE-2025-10611—that affect multiple enterprise products, including…
⤷ Title: Learn how to use dnsrecon for Exhaustive DNS Enumeration and Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:03:03 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bug_bounty #hacking #technology
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:03:03 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #bug_bounty #hacking #technology
Medium
Learn how to use dnsrecon for Exhaustive DNS Enumeration and Bug Bounty
Dnsrecon: Tool for exhaustive enumeration of DNS records, AXFR detection, and infrastructure mapping in Bug Bounty.
⤷ Title: What The Boooomb? — The Fork Bomb Explained
════════════════════════
𐀪 Author: Joseph Mwangi
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:23:04 GMT
════════════════════════
⌗ Tags: #learning #linux_tutorial #ethical_hacking #linux #hacking
════════════════════════
𐀪 Author: Joseph Mwangi
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 00:23:04 GMT
════════════════════════
⌗ Tags: #learning #linux_tutorial #ethical_hacking #linux #hacking
Medium
What The Boooomb? — The Fork Bomb Explained
The classic one-liner that spawns processes until your system chokes. Learn how it works, how to detect it, and defensive measures every…
⤷ Title: Everyday Cyber Hygiene: Small Habits That Protect Big Data
════════════════════════
𐀪 Author: Wistkey
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:31:51 GMT
════════════════════════
⌗ Tags: #tech_trends #cybersecurity #cyber_awareness #data_protection #cyber_hygiene
════════════════════════
𐀪 Author: Wistkey
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:31:51 GMT
════════════════════════
⌗ Tags: #tech_trends #cybersecurity #cyber_awareness #data_protection #cyber_hygiene
Medium
Everyday Cyber Hygiene: Small Habits That Protect Big Data
It doesn’t take a hacker with fancy tools to breach your system. Sometimes, all it takes is a weak password. Or a quick click on a…
⤷ Title: Can You Really Stay Anonymous Online in 2025?
════════════════════════
𐀪 Author: Rabail Zaheer
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:30:11 GMT
════════════════════════
⌗ Tags: #technology #osint #tech #security #cybersecurity
════════════════════════
𐀪 Author: Rabail Zaheer
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:30:11 GMT
════════════════════════
⌗ Tags: #technology #osint #tech #security #cybersecurity
Medium
Can You Really Stay Anonymous Online in 2025?
Your new goal: practical obscurity.
⤷ Title: CYBER SECURITY CLASS REVIEW ON 21ST OF OCTOBER, 2025
General Kali commands:
CD
PWD
LS
Touch
/root…
════════════════════════
𐀪 Author: Ukaakachi
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:20:25 GMT
════════════════════════
⌗ Tags: #cybersecurity
General Kali commands:
CD
PWD
LS
Touch
/root…
════════════════════════
𐀪 Author: Ukaakachi
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:20:25 GMT
════════════════════════
⌗ Tags: #cybersecurity
Medium
CYBER SECURITY CLASS REVIEW ON 21ST OF OCTOBER, 2025 General Kali commands: CD PWD LS Touch /root…
CYBER SECURITY CLASS REVIEW ON 21ST OF OCTOBER, 2025 General Kali commands: CD PWD LS Touch /root /etc /Home /LIB Cat Mv rm Mkdir Whoami The command for steganography is Steghide(for encryption) and …
⤷ Title: In late August 2025, the State of Nevada faced one of its most serious cybersecurity crises to date.
════════════════════════
𐀪 Author: Akilnath Bodipudi
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:02:19 GMT
════════════════════════
⌗ Tags: #ai #nevada #cybersecurity #cyberattack #ransomware
════════════════════════
𐀪 Author: Akilnath Bodipudi
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:02:19 GMT
════════════════════════
⌗ Tags: #ai #nevada #cybersecurity #cyberattack #ransomware
Medium
Nevada’s Ransomware Crisis: A Wake-Up Call and an Opportunity for Cyber Resilience
While the full scope of the breach remains under investigation, state officials confirmed that some data was exfiltrated, though the…
⤷ Title: IAR: The Trading Platform That Builds Strength Through Recovery
════════════════════════
𐀪 Author: Racca Jane
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:02:04 GMT
════════════════════════
⌗ Tags: #bitcoin #cybersecurity #business #ethereum #cryptocurrency
════════════════════════
𐀪 Author: Racca Jane
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 01:02:04 GMT
════════════════════════
⌗ Tags: #bitcoin #cybersecurity #business #ethereum #cryptocurrency
Medium
IAR: The Trading Platform That Builds Strength Through Recovery
IAR: The Trading Platform That Builds Strength Through Recovery In the ever-changing world of online trading, success isn’t just about winning — it’s about bouncing back after setbacks …
⤷ Title: Fake Xubuntu Installer Found Stealing Crypto on Official Website
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:47:03 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #cybersecurity #Linux #malware #supply chain attack #Xubuntu
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:47:03 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #cybersecurity #Linux #malware #supply chain attack #Xubuntu
Penetration Testing Tools
Fake Xubuntu Installer Found Stealing Crypto on Official Website
A fake "Safe Downloader" on the official Xubuntu site contained a crypto clipper trojan, forcing the distribution to take its downloads page offline.
⤷ Title: XSS Exploitation Tool: the exploitation of Cross-Site Scripting vulnerabilities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:45:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #XSS Exploitation Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:45:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #XSS Exploitation Tool
Penetration Testing Tools
XSS Exploitation Tool: the exploitation of Cross-Site Scripting vulnerabilities
XSS Exploitation Tool is a penetration testing tool that focuses on the exploitation of Cross-Site Scripting vulnerabilities.
⤷ Title: Security Crisis: South Korea Confirms Major Hack of Government Document System
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:45:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cyber Espionage #cybersecurity #GPKI #National Security #Onnara #South Korea
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:45:14 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cyber Espionage #cybersecurity #GPKI #National Security #Onnara #South Korea
Penetration Testing Tools
Security Crisis: South Korea Confirms Major Hack of Government Document System
South Korea confirms a major cyberattack on the Onnara document system and GPKI certificates, two months after the breach was detected.
⤷ Title: CISA Urges Immediate Patching: Critical Windows SMB Flaw Under Active Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:41:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #cybersecurity #privilege escalation #SMB #vulnerability #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:41:59 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #cybersecurity #privilege escalation #SMB #vulnerability #windows
Penetration Testing Tools
CISA Urges Immediate Patching: Critical Windows SMB Flaw Under Active Attack
CISA warns that a critical Windows SMB flaw (CVE-2025-33073) is actively exploited, allowing authenticated attackers to gain SYSTEM privileges.
⤷ Title: Everest Ransomware Claims Responsibility for European Airport Chaos
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:34:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aviation #Collins Aerospace #cybersecurity #data breach #Everest #ransomware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:34:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aviation #Collins Aerospace #cybersecurity #data breach #Everest #ransomware
Penetration Testing Tools
Everest Ransomware Claims Responsibility for European Airport Chaos
The Everest ransomware group claimed the attack on Collins Aerospace, alleging theft of 50GB of data, following the airport check-in system failures in September.
⤷ Title: Legal Earthquake: US Court Permanently Bans NSO Group from Hacking WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:27:45 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #lawsuit #NSO Group #Pegasus #Spyware #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 03:27:45 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #lawsuit #NSO Group #Pegasus #Spyware #WhatsApp
Penetration Testing Tools
Legal Earthquake: US Court Permanently Bans NSO Group from Hacking WhatsApp
A US federal court granted a permanent injunction, banning NSO Group from all future attempts to access WhatsApp, concluding a 6-year legal battle.