⤷ Title: NetSupport RAT Campaign Abuses ClickFix to Infect Hosts; 3 Threat Clusters Use RMM for Covert Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EVALUSION #Multi_Cluster #NetSupport RAT #powershell #Remote Access Trojan #RMM Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EVALUSION #Multi_Cluster #NetSupport RAT #powershell #Remote Access Trojan #RMM Abuse
Daily CyberSecurity
NetSupport RAT Campaign Abuses ClickFix to Infect Hosts; 3 Threat Clusters Use RMM for Covert Access
eSentire exposed a surge in NetSupport RAT campaigns using the ClickFix social engineering tactic. Three threat clusters leverage a PowerShell loader to bypass AV and gain full remote access via the RMM tool.
⤷ Title: Critical Dell Storage Manager Flaw (CVE-2025-43995, CVSS 9.8) Allows Unauthenticated API Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:40:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ApiProxy.war #Authentication Bypass #Critical Vulnerability #CVE_2025_43995 #Dell Storage #DSM #Storage Center
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:40:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ApiProxy.war #Authentication Bypass #Critical Vulnerability #CVE_2025_43995 #Dell Storage #DSM #Storage Center
Daily CyberSecurity
Critical Dell Storage Manager Flaw (CVE-2025-43995, CVSS 9.8) Allows Unauthenticated API Bypass
Dell patched three flaws in Storage Manager, including a Critical (CVSS 9.8) Auth Bypass (CVE-2025-43995) that allows remote, unauthenticated access to the Data Collector’s APIProxy.war component.
⤷ Title: Agenda Ransomware Bypasses EDR by Deploying Linux Binary on Windows via Splashtop; Steals Veeam Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:37:15 +0000
════════════════════════
⌗ Tags: #Malware #Agenda Ransomware #BYOVD #Cross_Platform #EDR Bypass #Linux Binary #Qilin #Splashtop #Veeam Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:37:15 +0000
════════════════════════
⌗ Tags: #Malware #Agenda Ransomware #BYOVD #Cross_Platform #EDR Bypass #Linux Binary #Qilin #Splashtop #Veeam Credentials
Daily CyberSecurity
Agenda Ransomware Bypasses EDR by Deploying Linux Binary on Windows via Splashtop; Steals Veeam Credentials
⤷ Title: Google Exposes UNC6229 “Fake Career” Campaign Hacking Advertising Accounts with Fake Job Lures
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:34:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Account Takeover #Fake Career #Google Threat Intelligence #phishing #social engineering #UNC6229 #Vietnam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:34:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Ad Account Takeover #Fake Career #Google Threat Intelligence #phishing #social engineering #UNC6229 #Vietnam
Daily CyberSecurity
Google Exposes UNC6229 "Fake Career" Campaign Hacking Advertising Accounts with Fake Job Lures
Google exposed UNC6229, a Vietnam-based group running "Fake Career" phishing on job boards. They use fake lures to compromise digital advertising accounts and corporate credentials for profit.
⤷ Title: Ubiquiti Patches Critical CVSS 10 Flaw in UniFi Access That Exposed Management API Without Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:26:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #Critical Vulnerability #CVSS 10.0 #Door Management #Ubiquiti #UniFi Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:26:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #Critical Vulnerability #CVSS 10.0 #Door Management #Ubiquiti #UniFi Access
Daily CyberSecurity
Ubiquiti Patches Critical CVSS 10 Flaw in UniFi Access That Exposed Management API Without Authentication
Ubiquiti issued an urgent patch for a Critical Auth Bypass flaw in UniFi Access. Attackers with network access can fully take over door management systems.
⤷ Title: YouTube Ghost Network Exposed: Coordinated Channels Spread Infostealer Malware via Game/Software Cracks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:21:47 +0000
════════════════════════
⌗ Tags: #Malware #Check Point #Game Hacks #Infostealer #Lumma #Malware Distribution #Rhadamanthys #Software Cracks #YouTube Ghost Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:21:47 +0000
════════════════════════
⌗ Tags: #Malware #Check Point #Game Hacks #Infostealer #Lumma #Malware Distribution #Rhadamanthys #Software Cracks #YouTube Ghost Network
Daily CyberSecurity
YouTube Ghost Network Exposed: Coordinated Channels Spread Infostealer Malware via Game/Software Cracks
Check Point exposed the YouTube Ghost Network, a coordinated op using 3,000+ videos (Game/Software Cracks) to spread Rhadamanthys/Lumma infostealers via fake engagement and external file hosts.
⤷ Title: Smishing Triad Uncovered: 194,000+ Malicious Domains Power Global Phishing-as-a-Service Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:19:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Web Store #Domain Abuse #Global Fraud #PhaaS #smishing #Smishing Triad #Typosquatting #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:19:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Web Store #Domain Abuse #Global Fraud #PhaaS #smishing #Smishing Triad #Typosquatting #Unit 42
Daily CyberSecurity
Smishing Triad Uncovered: 194,000+ Malicious Domains Power Global Phishing-as-a-Service Campaign
Unit 42 exposed the Smishing Triad, a PhaaS network that registered 194K+ malicious domains for global smishing. The group impersonates postal/banking services and uses Telegram for its underground market.
⤷ Title: OpenWrt Patches ubusd RCE Flaw (CVE-2025-62526) and Kernel Memory Leak (CVE-2025-62525) in DSL Driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:14:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_62526 #DSL Driver #Heap Buffer Overflow #Kernel Memory #OpenWrt #rce #Ubusd
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:14:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_62526 #DSL Driver #Heap Buffer Overflow #Kernel Memory #OpenWrt #rce #Ubusd
Daily CyberSecurity
OpenWrt Patches ubusd RCE Flaw (CVE-2025-62526) and Kernel Memory Leak (CVE-2025-62525) in DSL Driver
OpenWrt released v24.10.4 to fix two high-severity flaws: CVE-2025-62526 allows RCE via a heap buffer overflow in ubusd, and CVE-2025-62525 leaks kernel memory via a DSL driver.
⤷ Title: China-Aligned APTs Launch “Premier Pass-as-a-Service,” Sharing Access in Coordinated Global Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:10:55 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT Collaboration #China APT #cyber_espionage #Earth Estries #Earth Naga #Premier Pass_as_a_Service #ShadowPad
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:10:55 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT Collaboration #China APT #cyber_espionage #Earth Estries #Earth Naga #Premier Pass_as_a_Service #ShadowPad
Daily CyberSecurity
China-Aligned APTs Launch "Premier Pass-as-a-Service," Sharing Access in Coordinated Global Espionage
Trend exposed "Premier Pass-as-a-Service," a model where Earth Estries (access broker) and Earth Naga (APT36) share compromised network access to deploy ShadowPad in a coordinated espionage campaign.
⤷ Title: Python RAT Disguised as Minecraft Client Uses Telegram Bot API for Cross-Platform Command & Control
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:05:09 +0000
════════════════════════
⌗ Tags: #Malware #Cross_Platform Malware #Discord Tokens #Infostealer #Minecraft #Nursultan Client #Python RAT #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:05:09 +0000
════════════════════════
⌗ Tags: #Malware #Cross_Platform Malware #Discord Tokens #Infostealer #Minecraft #Nursultan Client #Python RAT #Telegram C2
Daily CyberSecurity
Python RAT Disguised as Minecraft Client Uses Telegram Bot API for Cross-Platform Command & Control
Netskope exposed a Python RAT (Nursultan Client) disguised as a Minecraft tool. It uses the Telegram Bot API for C2 to steal Discord tokens, credentials, and capture screenshots on Windows, Linux, and macOS.
⤷ Title: HashiCorp Patches Vault Flaws: AWS Auth Bypass and Unauthenticated JSON DoS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #AWS Auth Method #Cloud Security #CVE_2025_11621 #Denial of Service #HashiCorp Vault #JSON Parsing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #AWS Auth Method #Cloud Security #CVE_2025_11621 #Denial of Service #HashiCorp Vault #JSON Parsing
Daily CyberSecurity
HashiCorp Patches Vault Flaws: AWS Auth Bypass and Unauthenticated JSON DoS
HashiCorp patched two flaws in Vault: CVE-2025-11621 allows AWS Auth Bypass via IAM role collision, and CVE-2025-12044 allows unauthenticated JSON DoS attack.
⤷ Title: How I Discovered an HTML Injection via a Signup Form
════════════════════════
𐀪 Author: Gehad Reda
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:08:12 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #bug_bounty #cybersecurity #web_development
════════════════════════
𐀪 Author: Gehad Reda
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:08:12 GMT
════════════════════════
⌗ Tags: #web_security #ethical_hacking #bug_bounty #cybersecurity #web_development
Medium
How I Discovered an HTML Injection via a Signup Form
First of all :السلام عليكم ورحمة الله وبركاته
⤷ Title: Proving Grounds - WallpaperHub
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:45:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #penetration_testing #provinggrounds #linux
════════════════════════
𐀪 Author: jniket
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:45:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #penetration_testing #provinggrounds #linux
Medium
Proving Grounds - WallpaperHub
Summary
⤷ Title: HTB — Learn the basics of the Penetration Testing: Starting Point [TIER 0]
════════════════════════
𐀪 Author: Faraam
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:33:27 GMT
════════════════════════
⌗ Tags: #hackthebox #beginner #hacking #cybersecurity #capture_the_flag
════════════════════════
𐀪 Author: Faraam
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:33:27 GMT
════════════════════════
⌗ Tags: #hackthebox #beginner #hacking #cybersecurity #capture_the_flag
Medium
HTB — Learn the basics of the Penetration Testing: Starting Point [TIER 0] — “Meow”
To begin with, I will first explain how I will organize the write-ups for each tier of the “Starting Point” module on learning the basics…
⤷ Title: Prompt Injection: The Invisible Threat in the Age of Artificial Intelligence
════════════════════════
𐀪 Author: Alican'ONI'Kaya
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:46:51 GMT
════════════════════════
⌗ Tags: #prompt_engineering #machine_learning #cybersecurity #ai_safety #artificial_intelligence
════════════════════════
𐀪 Author: Alican'ONI'Kaya
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:46:51 GMT
════════════════════════
⌗ Tags: #prompt_engineering #machine_learning #cybersecurity #ai_safety #artificial_intelligence
Medium
🚨 Prompt Injection: The Invisible Threat in the Age of Artificial Intelligence
AI models have become an integral part of our daily lives. Tools such as ChatGPT, Claude, Gemini, and Copilot, along with AI-powered…
⤷ Title: Dummy Interface for Nework Traffic Analysis
════════════════════════
𐀪 Author: Vilaysack Vorachack
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:01:54 GMT
════════════════════════
⌗ Tags: #network_security #cybersecurity #suricata
════════════════════════
𐀪 Author: Vilaysack Vorachack
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:01:54 GMT
════════════════════════
⌗ Tags: #network_security #cybersecurity #suricata
Medium
Dummy Interface for Nework Traffic Analysis
In the role of a cybersecurity professional, especially as a SOC Analyst, Incident Responder, Threat Hunter, or DFIR specialist. I believe…
⤷ Title: How Safe Game Boosting Works in 2025: Behind the Scenes of Skydy
════════════════════════
𐀪 Author: Skydy.com
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:57:38 GMT
════════════════════════
⌗ Tags: #mmorpg #cybersecurity #gaming #wow #destiny_2
════════════════════════
𐀪 Author: Skydy.com
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:57:38 GMT
════════════════════════
⌗ Tags: #mmorpg #cybersecurity #gaming #wow #destiny_2
Medium
How Safe Game Boosting Works in 2025: Behind the Scenes of Skydy
The term “game boosting” often brings mixed feelings — excitement for progress, but fear of bans or stolen accounts.
In 2025, that stigma…
In 2025, that stigma…
⤷ Title: RST TI Report Digest: 27 Oct 2025
════════════════════════
𐀪 Author: RST Cloud
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:56:42 GMT
════════════════════════
⌗ Tags: #cyber_threat_intelligence #cybersecurity #threat_intelligence #ti_report_digest
════════════════════════
𐀪 Author: RST Cloud
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:56:42 GMT
════════════════════════
⌗ Tags: #cyber_threat_intelligence #cybersecurity #threat_intelligence #ti_report_digest
Medium
RST TI Report Digest: 27 Oct 2025
Out of 65 threat intelligence articles published and processed last week, we’ve summarised 10 key ones for you, including IoCs.
⤷ Title: Plugin Governance in SOC Environments
════════════════════════
𐀪 Author: Pranjali Karve
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:46:27 GMT
════════════════════════
⌗ Tags: #security_operation_center #cybersecurity #security_operations
════════════════════════
𐀪 Author: Pranjali Karve
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:46:27 GMT
════════════════════════
⌗ Tags: #security_operation_center #cybersecurity #security_operations
Medium
Plugin Governance in SOC Environments
What Are Plugins? An Analogy
⤷ Title: Nothing to Something: Building My First Home Network
════════════════════════
𐀪 Author: Jarrielle Gathers
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:08:30 GMT
════════════════════════
⌗ Tags: #networking #cybersecurity #deep_learning #technology #information_technology
════════════════════════
𐀪 Author: Jarrielle Gathers
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 00:08:30 GMT
════════════════════════
⌗ Tags: #networking #cybersecurity #deep_learning #technology #information_technology
Medium
Nothing to Something: Building My First Home Network
Nothing to Something: Building My First Home Network While finishing my file storage server, I started a parallel project. Setting up my home network from scratch. The Plan I replaced my Xfinity …
⤷ Title: Toturial | For Beginner |
════════════════════════
𐀪 Author: Mosta
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:53:22 GMT
════════════════════════
⌗ Tags: #new_tryhackme #tryhackme #tutorial #thm #begginer
════════════════════════
𐀪 Author: Mosta
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 01:53:22 GMT
════════════════════════
⌗ Tags: #new_tryhackme #tryhackme #tutorial #thm #begginer
Medium
Toturial | For Beginner |
TryHackMe room