⤷ Title: The Hard Way: How One Repo Crash Taught Me More Than Any Linux Tutorial Ever Could
════════════════════════
𐀪 Author: David Zion
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 23:22:24 GMT
════════════════════════
⌗ Tags: #kali_linux #linux #cybersecurity
════════════════════════
𐀪 Author: David Zion
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 23:22:24 GMT
════════════════════════
⌗ Tags: #kali_linux #linux #cybersecurity
Medium
The Hard Way: How One Repo Crash Taught Me More Than Any Linux Tutorial Ever Could
Introduction: Learning Linux Without a Safety Net
⤷ Title: The E-Waste Black Market: Why Criminals Love Your Old Laptop
════════════════════════
𐀪 Author: Subramanimokkala
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 22:52:57 GMT
════════════════════════
⌗ Tags: #e_waste #data_security #technology #cybersecurity #data_privacy
════════════════════════
𐀪 Author: Subramanimokkala
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 22:52:57 GMT
════════════════════════
⌗ Tags: #e_waste #data_security #technology #cybersecurity #data_privacy
Medium
The E-Waste Black Market: Why Criminals Love Your Old Laptop
“Identity theft is not a JOKE, Jim!!!! Millions of families suffer every year.” — Dwight Kurt Schrute (The Office U.S.)
⤷ Title: Networking Basics for Security Folks: TCP/IP Without the Headache
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 22:37:15 GMT
════════════════════════
⌗ Tags: #tcp_ip #networking #basic_networking #cybersecurity #tcp
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 22:37:15 GMT
════════════════════════
⌗ Tags: #tcp_ip #networking #basic_networking #cybersecurity #tcp
Medium
Networking Basics for Security Folks: TCP/IP Without the Headache
I survived the OSI model wars, so you don’t have to. Here’s what actually matters.
⤷ Title: DJINN3 — Walkthrough (Proving Grounds Play)
════════════════════════
𐀪 Author: Maxwell Ferreira
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:53 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #oscp_preparation #ctf_walkthrough
════════════════════════
𐀪 Author: Maxwell Ferreira
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:53 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #oscp_preparation #ctf_walkthrough
Medium
DJINN3 — Walkthrough (Proving Grounds Play)
About this lab
⤷ Title: Jira Path Traversal Flaw (CVE-2025-22167) Allows Arbitrary File Write on Server/Data Center
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:53:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Atlassian #Critical Vulnerability #CVE_2025_22167 #Jira #Path Traversal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:53:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Atlassian #Critical Vulnerability #CVE_2025_22167 #Jira #Path Traversal
Daily CyberSecurity
Jira Path Traversal Flaw (CVE-2025-22167) Allows Arbitrary File Write on Server/Data Center
Atlassian patched a Critical (CVSS 8.7) Path Traversal flaw (CVE-2025-22167) in Jira Software/Service Management that allows attackers to perform arbitrary file writes. Immediate update is urged.
⤷ Title: Symantec Exposes Chinese APT Overlap: Zingdoor, ShadowPad, and KrustyLoader Used in Global Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:43:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #DLL Sideloading #Espionage #KrustyLoader #ShadowPad #Supply Chain #Zingdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:43:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Chinese APT #DLL Sideloading #Espionage #KrustyLoader #ShadowPad #Supply Chain #Zingdoor
Daily CyberSecurity
Symantec Exposes Chinese APT Overlap: Zingdoor, ShadowPad, and KrustyLoader Used in Global Espionage
Symantec exposed a complex Chinese APT network (Glowworm/UNC5221) deploying Zingdoor and ShadowPad across US/South American targets. The groups abuse DLL sideloading and PetitPotam for credential theft.
⤷ Title: Socket Uncovers Malicious NuGet Typosquat “Netherеum.All” Exfiltrating Wallet Keys via Solana-Themed C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:35:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET #crypto wallet theft #Homoglyph #Nethereum #NuGet #Supply Chain #Typosquatting #XOR Obfuscation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:35:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET #crypto wallet theft #Homoglyph #Nethereum #NuGet #Supply Chain #Typosquatting #XOR Obfuscation
Daily CyberSecurity
Socket Uncovers Malicious NuGet Typosquat “Netherеum.All” Exfiltrating Wallet Keys via Solana-Themed C2
A NuGet typosquat named Netherеum.All used a Cyrillic homoglyph to fool 11M+ downloads. The malicious package injected an XOR-decoded backdoor to steal crypto wallet and private key data.
⤷ Title: Critical WSUS Flaw (CVE-2025-59287, CVSS 9.8) Allows Unauthenticated RCE via Unsafe Cookie Deserialization, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AuthorizationCookie #BinaryFormatter #Critical Vulnerability #CVE_2025_59287 #Deserialization #Microsoft WSUS #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:30:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AuthorizationCookie #BinaryFormatter #Critical Vulnerability #CVE_2025_59287 #Deserialization #Microsoft WSUS #rce
Daily CyberSecurity
Critical WSUS Flaw (CVE-2025-59287, CVSS 9.8) Allows Unauthenticated RCE via Unsafe Cookie Deserialization, PoC Available
A Critical RCE flaw (CVE-2025-59287, CVSS 9.8) in WSUS allows unauthenticated attackers SYSTEM access via AuthorizationCookie deserialization. The issue was patched in the October update.
⤷ Title: Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
Daily CyberSecurity
Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
Elastic exposed Chinese threat actors exploiting public ASP.NET machine keys to deploy TOLLBOOTH IIS backdoor and HIDDENDRIVER kernel rootkit. The malware performs stealthy SEO cloaking.
⤷ Title: Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:20:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:20:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
Daily CyberSecurity
Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
Group-IB exposed MuddyWater using NordVPN to send phishing emails that deliver the Phoenix v4 backdoor. The malware steals credentials via a custom Chromium stealer disguised as a calculator.
⤷ Title: Critical NeuVector RCE Flaw (CVE-2025-54469, CVSS 10.0) Allows Command Injection via Unsanitized Environment Variables
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #container security #CVSS 10.0 #DevSecOps #Kubernetes #NeuVector #rce #SUSE Rancher
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #container security #CVSS 10.0 #DevSecOps #Kubernetes #NeuVector #rce #SUSE Rancher
Daily CyberSecurity
Critical NeuVector RCE Flaw (CVE-2025-54469, CVSS 10.0) Allows Command Injection via Unsanitized Environment Variables
SUSE patched a Critical RCE flaw (CVE-2025-54469, CVSS 10.0) in NeuVector Enforcer that allows attackers to inject commands via unsanitized environment variables, risking container root shell access.
⤷ Title: Major Threat: Vidar Stealer v2.0 Bypasses Chrome AppBound Encryption with Multithreaded Memory Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:11:07 +0000
════════════════════════
⌗ Tags: #Malware #AppBound Bypass #C# malware #Chrome Credentials #Infostealer #Memory injection #Multithreading #Vidar Stealer 2.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:11:07 +0000
════════════════════════
⌗ Tags: #Malware #AppBound Bypass #C# malware #Chrome Credentials #Infostealer #Memory injection #Multithreading #Vidar Stealer 2.0
Daily CyberSecurity
Major Threat: Vidar Stealer v2.0 Bypasses Chrome AppBound Encryption with Multithreaded Memory Injection
Vidar 2.0, fully rewritten in C, is a multithreaded infostealer that bypasses Chrome's AppBound encryption via memory injection to steal crypto wallets and credentials. Its adoption spikes as Lumma declines.
⤷ Title: CISA Warns: Critical Raisecom Router Flaw (CVE-2025-11534, CVSS 9.8) Allows Unauthenticated Root SSH Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:06:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Critical Vulnerability #CWE_288 #Raisecom #RAX701_GC #SSH Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:06:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Critical Vulnerability #CWE_288 #Raisecom #RAX701_GC #SSH Root Access
Daily CyberSecurity
CISA Warns: Critical Raisecom Router Flaw (CVE-2025-11534, CVSS 9.8) Allows Unauthenticated Root SSH Access
CISA issued an alert for a Critical (CVSS 9.8) Auth Bypass flaw (CVE-2025-11534) in Raisecom RAX701-GC routers, allowing unauthenticated root shell via SSH. The vendor has not yet responded with a patch.
⤷ Title: Lumma Infostealer MaaS Campaign Uses NSIS/AutoIt and MEGA Cloud to Steal Credentials via Pirated Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:14 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt #Credential Theft #Cybercrime #Lumma Infostealer #MaaS #MEGA Cloud #NSIS Installer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:14 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt #Credential Theft #Cybercrime #Lumma Infostealer #MaaS #MEGA Cloud #NSIS Installer #Process Hollowing
Daily CyberSecurity
Lumma Infostealer MaaS Campaign Uses NSIS/AutoIt and MEGA Cloud to Steal Credentials via Pirated Software
A sophisticated Lumma Infostealer MaaS campaign targets users with pirated software installers. It uses NSIS/AutoIt scripts, Process Hollowing, and MEGA cloud to steal credentials from browsers and crypto wallets.
⤷ Title: How I Found Two Role-Based Access Control (RBAC) Vulnerabilities
════════════════════════
𐀪 Author: Muhammad Wageh
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:03:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking
════════════════════════
𐀪 Author: Muhammad Wageh
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:03:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking
Medium
How I Found Two Role-Based Access Control (RBAC) Vulnerabilities
First, I spent two days understanding the target and taking notes on things like:
❤2
⤷ Title: Cuban: 63,564 AIS Remesas Clients information was exposed on an unsecured server.
════════════════════════
𐀪 Author: chum1ng0
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:29:49 GMT
════════════════════════
⌗ Tags: #cuba #data_protection #infosec #privacy #cybersecurity
════════════════════════
𐀪 Author: chum1ng0
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:29:49 GMT
════════════════════════
⌗ Tags: #cuba #data_protection #infosec #privacy #cybersecurity
Medium
Cuban: 63,564 AIS Remesas Clients information was exposed on an unsecured server.
This entity exposed an unsecured server containing certified documents, passports, ID cards, and debit cards belonging to 63,564 customers.
⤷ Title: Port Security Setup
════════════════════════
𐀪 Author: Mersadi Freeman
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:53:27 GMT
════════════════════════
⌗ Tags: #cisco_packet_tracer #cybersecurity #port_security
════════════════════════
𐀪 Author: Mersadi Freeman
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:53:27 GMT
════════════════════════
⌗ Tags: #cisco_packet_tracer #cybersecurity #port_security
Medium
Port Security Setup
Cisco Packet Tracer
⤷ Title: Cómo se contruyó ‘TaSave’, una Plataforma de Hacking Ético, y el Tech Stack que Recomiendo para…
════════════════════════
𐀪 Author: FeCeSociety
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:25:47 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #ctf #nextjs #ciberseguridad
════════════════════════
𐀪 Author: FeCeSociety
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:25:47 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #ctf #nextjs #ciberseguridad
Medium
Cómo se contruyó ‘TaSave’, una Plataforma de Hacking Ético, y el Tech Stack que Recomiendo para…
Un deep dive en Next.js, Drizzle ORM y Docker para crear una experiencia de usuario inmersiva, segura y de alto rendimiento. Esta es la…
⤷ Title: Building Ransomware Resilience — Webinar
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:19:23 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #information_security #webinar
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:19:23 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #information_security #webinar
Medium
Building Ransomware Resilience — Webinar
I am looking forward to a stellar discussion about ransomware!
⤷ Title: Sentinel Achieves SOC 2 Type II Certification
════════════════════════
𐀪 Author: Gold
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:18:25 GMT
════════════════════════
⌗ Tags: #blockchain #cybersecurity #web3 #solanas #cryptocurrency
════════════════════════
𐀪 Author: Gold
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:18:25 GMT
════════════════════════
⌗ Tags: #blockchain #cybersecurity #web3 #solanas #cryptocurrency
Medium
Sentinel Achieves SOC 2 Type II Certification
Phase Labs Team
22nd October 2025
22nd October 2025
⤷ Title: Burp Intruder — Attack Types
════════════════════════
𐀪 Author: Nathanael Praditya
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:13:53 GMT
════════════════════════
⌗ Tags: #writing_tips #cybersecurity #tutorial
════════════════════════
𐀪 Author: Nathanael Praditya
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:13:53 GMT
════════════════════════
⌗ Tags: #writing_tips #cybersecurity #tutorial
Medium
Burp Intruder — Attack Types
Haii! Ini cuma sekedar dokumentasi agar writer tidak lupa dengan fungsi Attack Type yang ada di Burp Intruder. Bassicaly ada 4, yaitu…