⤷ Title: Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
Daily CyberSecurity
Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
Elastic exposed Chinese threat actors exploiting public ASP.NET machine keys to deploy TOLLBOOTH IIS backdoor and HIDDENDRIVER kernel rootkit. The malware performs stealthy SEO cloaking.
⤷ Title: Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:20:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:20:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
Daily CyberSecurity
Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
Group-IB exposed MuddyWater using NordVPN to send phishing emails that deliver the Phoenix v4 backdoor. The malware steals credentials via a custom Chromium stealer disguised as a calculator.
⤷ Title: Critical NeuVector RCE Flaw (CVE-2025-54469, CVSS 10.0) Allows Command Injection via Unsanitized Environment Variables
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #container security #CVSS 10.0 #DevSecOps #Kubernetes #NeuVector #rce #SUSE Rancher
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #container security #CVSS 10.0 #DevSecOps #Kubernetes #NeuVector #rce #SUSE Rancher
Daily CyberSecurity
Critical NeuVector RCE Flaw (CVE-2025-54469, CVSS 10.0) Allows Command Injection via Unsanitized Environment Variables
SUSE patched a Critical RCE flaw (CVE-2025-54469, CVSS 10.0) in NeuVector Enforcer that allows attackers to inject commands via unsanitized environment variables, risking container root shell access.
⤷ Title: Major Threat: Vidar Stealer v2.0 Bypasses Chrome AppBound Encryption with Multithreaded Memory Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:11:07 +0000
════════════════════════
⌗ Tags: #Malware #AppBound Bypass #C# malware #Chrome Credentials #Infostealer #Memory injection #Multithreading #Vidar Stealer 2.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:11:07 +0000
════════════════════════
⌗ Tags: #Malware #AppBound Bypass #C# malware #Chrome Credentials #Infostealer #Memory injection #Multithreading #Vidar Stealer 2.0
Daily CyberSecurity
Major Threat: Vidar Stealer v2.0 Bypasses Chrome AppBound Encryption with Multithreaded Memory Injection
Vidar 2.0, fully rewritten in C, is a multithreaded infostealer that bypasses Chrome's AppBound encryption via memory injection to steal crypto wallets and credentials. Its adoption spikes as Lumma declines.
⤷ Title: CISA Warns: Critical Raisecom Router Flaw (CVE-2025-11534, CVSS 9.8) Allows Unauthenticated Root SSH Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:06:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Critical Vulnerability #CWE_288 #Raisecom #RAX701_GC #SSH Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:06:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CISA #Critical Vulnerability #CWE_288 #Raisecom #RAX701_GC #SSH Root Access
Daily CyberSecurity
CISA Warns: Critical Raisecom Router Flaw (CVE-2025-11534, CVSS 9.8) Allows Unauthenticated Root SSH Access
CISA issued an alert for a Critical (CVSS 9.8) Auth Bypass flaw (CVE-2025-11534) in Raisecom RAX701-GC routers, allowing unauthenticated root shell via SSH. The vendor has not yet responded with a patch.
⤷ Title: Lumma Infostealer MaaS Campaign Uses NSIS/AutoIt and MEGA Cloud to Steal Credentials via Pirated Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:14 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt #Credential Theft #Cybercrime #Lumma Infostealer #MaaS #MEGA Cloud #NSIS Installer #Process Hollowing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:01:14 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt #Credential Theft #Cybercrime #Lumma Infostealer #MaaS #MEGA Cloud #NSIS Installer #Process Hollowing
Daily CyberSecurity
Lumma Infostealer MaaS Campaign Uses NSIS/AutoIt and MEGA Cloud to Steal Credentials via Pirated Software
A sophisticated Lumma Infostealer MaaS campaign targets users with pirated software installers. It uses NSIS/AutoIt scripts, Process Hollowing, and MEGA cloud to steal credentials from browsers and crypto wallets.
⤷ Title: How I Found Two Role-Based Access Control (RBAC) Vulnerabilities
════════════════════════
𐀪 Author: Muhammad Wageh
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:03:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking
════════════════════════
𐀪 Author: Muhammad Wageh
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:03:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #hacking
Medium
How I Found Two Role-Based Access Control (RBAC) Vulnerabilities
First, I spent two days understanding the target and taking notes on things like:
❤2
⤷ Title: Cuban: 63,564 AIS Remesas Clients information was exposed on an unsecured server.
════════════════════════
𐀪 Author: chum1ng0
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:29:49 GMT
════════════════════════
⌗ Tags: #cuba #data_protection #infosec #privacy #cybersecurity
════════════════════════
𐀪 Author: chum1ng0
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:29:49 GMT
════════════════════════
⌗ Tags: #cuba #data_protection #infosec #privacy #cybersecurity
Medium
Cuban: 63,564 AIS Remesas Clients information was exposed on an unsecured server.
This entity exposed an unsecured server containing certified documents, passports, ID cards, and debit cards belonging to 63,564 customers.
⤷ Title: Port Security Setup
════════════════════════
𐀪 Author: Mersadi Freeman
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:53:27 GMT
════════════════════════
⌗ Tags: #cisco_packet_tracer #cybersecurity #port_security
════════════════════════
𐀪 Author: Mersadi Freeman
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:53:27 GMT
════════════════════════
⌗ Tags: #cisco_packet_tracer #cybersecurity #port_security
Medium
Port Security Setup
Cisco Packet Tracer
⤷ Title: Cómo se contruyó ‘TaSave’, una Plataforma de Hacking Ético, y el Tech Stack que Recomiendo para…
════════════════════════
𐀪 Author: FeCeSociety
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:25:47 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #ctf #nextjs #ciberseguridad
════════════════════════
𐀪 Author: FeCeSociety
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:25:47 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #ctf #nextjs #ciberseguridad
Medium
Cómo se contruyó ‘TaSave’, una Plataforma de Hacking Ético, y el Tech Stack que Recomiendo para…
Un deep dive en Next.js, Drizzle ORM y Docker para crear una experiencia de usuario inmersiva, segura y de alto rendimiento. Esta es la…
⤷ Title: Building Ransomware Resilience — Webinar
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:19:23 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #information_security #webinar
════════════════════════
𐀪 Author: Matthew.Rosenquist
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:19:23 GMT
════════════════════════
⌗ Tags: #ransomware #cybercrime #cybersecurity #information_security #webinar
Medium
Building Ransomware Resilience — Webinar
I am looking forward to a stellar discussion about ransomware!
⤷ Title: Sentinel Achieves SOC 2 Type II Certification
════════════════════════
𐀪 Author: Gold
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:18:25 GMT
════════════════════════
⌗ Tags: #blockchain #cybersecurity #web3 #solanas #cryptocurrency
════════════════════════
𐀪 Author: Gold
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:18:25 GMT
════════════════════════
⌗ Tags: #blockchain #cybersecurity #web3 #solanas #cryptocurrency
Medium
Sentinel Achieves SOC 2 Type II Certification
Phase Labs Team
22nd October 2025
22nd October 2025
⤷ Title: Burp Intruder — Attack Types
════════════════════════
𐀪 Author: Nathanael Praditya
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:13:53 GMT
════════════════════════
⌗ Tags: #writing_tips #cybersecurity #tutorial
════════════════════════
𐀪 Author: Nathanael Praditya
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 01:13:53 GMT
════════════════════════
⌗ Tags: #writing_tips #cybersecurity #tutorial
Medium
Burp Intruder — Attack Types
Haii! Ini cuma sekedar dokumentasi agar writer tidak lupa dengan fungsi Attack Type yang ada di Burp Intruder. Bassicaly ada 4, yaitu…
⤷ Title: Cybersecurity Certifications That Can Actually Make You Money
════════════════════════
𐀪 Author: The Reboot
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:25:04 GMT
════════════════════════
⌗ Tags: #certification #cybersecurity #education #college #jobs
════════════════════════
𐀪 Author: The Reboot
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:25:04 GMT
════════════════════════
⌗ Tags: #certification #cybersecurity #education #college #jobs
Medium
Cybersecurity Certifications That Can Actually Make You Money
Cybersecurity is an ever-growing field which will be around in some capacity or another for a very long time. There are a few main…
⤷ Title: Sysmon +Wazuh: The Defense-In-Depth Dynamic Duo
════════════════════════
𐀪 Author: Johnny Meintel
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:19:36 GMT
════════════════════════
⌗ Tags: #wazuh #cybersecurity #sysmon #siem #homelab
════════════════════════
𐀪 Author: Johnny Meintel
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:19:36 GMT
════════════════════════
⌗ Tags: #wazuh #cybersecurity #sysmon #siem #homelab
Medium
Sysmon +Wazuh: The Defense-In-Depth Dynamic Duo
We’ve got Wazuh up and running. Enter Sysmon — a highly granular and metadata-rich Windows system tool that provides the forensic detail…
⤷ Title: Why Minecraft Griefers Are Targetting Cracked Servers and Pirates. And Why Thats Good
════════════════════════
𐀪 Author: SupportiveFigure
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:10:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #gaming #minecraft #community #piracy
════════════════════════
𐀪 Author: SupportiveFigure
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:10:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #gaming #minecraft #community #piracy
Medium
Why Minecraft Griefers Are Targetting Cracked Servers and Pirates. And Why Thats Good
Minecraft remains one of the most cherished games available, but it has a significant issue to deal with. cracked servers allow players and…
⤷ Title: The SIM Swap Scam: How One Text Can Ruin Your Digital Identity
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:09:18 GMT
════════════════════════
⌗ Tags: #ai #sim_swap_attack #social_engineering #information_security #cybersecurity
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:09:18 GMT
════════════════════════
⌗ Tags: #ai #sim_swap_attack #social_engineering #information_security #cybersecurity
Medium
The SIM Swap Scam: How One Text Can Ruin Your Digital Identity
Imagine waking up to ‘No Service’ on your phone. Minutes later, your email, crypto wallet, and social accounts are gone. Someone else now…
⤷ Title: The Invisible Worm: GlassWorm Spreads Via VS Code Extensions and Blockchain C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:58:11 +0000
════════════════════════
⌗ Tags: #Malware #blockchain #cybersecurity #GlassWorm #malware #Supply Chain #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:58:11 +0000
════════════════════════
⌗ Tags: #Malware #blockchain #cybersecurity #GlassWorm #malware #Supply Chain #VS Code
Penetration Testing Tools
The Invisible Worm: GlassWorm Spreads Via VS Code Extensions and Blockchain C2
A new self-propagating worm, GlassWorm, hides code in VS Code extensions using invisible Unicode and uses Solana blockchain for its "unkillable" C2.
⤷ Title: The MFA Killer: How One Programmer’s Tool Became a $100M Cybercrime Weapon
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:54:49 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #Evilginx #MFA Bypass #phishing #Red Team #Scattered Spider
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:54:49 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #Evilginx #MFA Bypass #phishing #Red Team #Scattered Spider
Penetration Testing Tools
The MFA Killer: How One Programmer’s Tool Became a $100M Cybercrime Weapon
Evilginx, a security research tool designed to bypass MFA, was adopted by groups like Scattered Spider and used in the $100M MGM Resorts breach.
⤷ Title: irst Known Case: Feds Force OpenAI to Disclose ChatGPT User Identity
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:50:38 +0000
════════════════════════
⌗ Tags: #Data Leak #ChatGPT #CSAM #Homeland Security #Legal Precedent #OpenAI #privacy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:50:38 +0000
════════════════════════
⌗ Tags: #Data Leak #ChatGPT #CSAM #Homeland Security #Legal Precedent #OpenAI #privacy
Penetration Testing Tools
irst Known Case: Feds Force OpenAI to Disclose ChatGPT User Identity
Homeland Security issued the first known warrant compelling OpenAI to disclose a ChatGPT user's identity based on specific prompts in a CSAM investigation.
⤷ Title: The New E-Crime: AI-Driven Ransomware and Billion-Dollar Asian Underworlds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:48:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Asia_Pacific #cybercrime #fintech #ransomware #Underground Economy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 03:48:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Asia_Pacific #cybercrime #fintech #ransomware #Underground Economy
Penetration Testing Tools
The New E-Crime: AI-Driven Ransomware and Billion-Dollar Asian Underworlds
A new report details a surge in AI-driven ransomware (like FunkLocker) across APJ, fueled by Chinese underground services processing billions in illicit funds.