⤷ Title: SideWinder APT Shifts to PDF/ClickOnce Chain to Target South Asian Diplomacy with StealerBot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:56:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #ClickOnce #DLL Sideloading #Espionage #PDF Lure #SideWinder #South Asia #StealerBot
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:56:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #ClickOnce #DLL Sideloading #Espionage #PDF Lure #SideWinder #South Asia #StealerBot
Daily CyberSecurity
SideWinder APT Shifts to PDF/ClickOnce Chain to Target South Asian Diplomacy with StealerBot
Trellix exposed SideWinder APT's campaign against South Asian diplomacy. It uses PDF/ClickOnce lures with a signed MagTek binary to deploy StealerBot for deep intelligence collection.
⤷ Title: Apache Tomcat Patches URL Rewrite Bypass (CVE-2025-55752) Risking RCE and Console ANSI Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:43:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ANSI Escape #apache Tomcat #CVE_2025_55752 #Denial of Service #rce #URL Rewrite Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:43:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ANSI Escape #apache Tomcat #CVE_2025_55752 #Denial of Service #rce #URL Rewrite Bypass
Daily CyberSecurity
Apache Tomcat Patches URL Rewrite Bypass (CVE-2025-55752) Risking RCE and Console ANSI Injection
The Apache Software Foundation has released multiple security patches for Apache Tomcat, addressing three newly disclosed vulnerabilities — CVE-2025-55752, CVE-2025-55754, and CVE-2025-61795 — aff…
⤷ Title: Caminho Loader-as-a-Service Uses LSB Steganography to Hide .NET Payloads in Archive.org Images
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:16:51 +0000
════════════════════════
⌗ Tags: #Malware #.NET Payload #Archive.org #Brazilian Cybercrime #Caminho #Fileless Malware #LaaS #LSB_Steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:16:51 +0000
════════════════════════
⌗ Tags: #Malware #.NET Payload #Archive.org #Brazilian Cybercrime #Caminho #Fileless Malware #LaaS #LSB_Steganography
Daily CyberSecurity
Caminho Loader-as-a-Service Uses LSB Steganography to Hide .NET Payloads in Archive.org Images
Arctic Wolf exposed Caminho, a Brazilian Loader-as-a-Service that hides .NET payloads in images via LSB steganography. It operates filelessly and is deployed via phishing and legitimate Archive.org.
⤷ Title: GhostGrab Android Malware Combines Covert Monero Mining with Financial Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Banking Trojan #Cryptojacking #Firebase C2 #GhostGrab #Hybrid Threat #Monero mining #OTP Interception
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Malware #Android Malware #Banking Trojan #Cryptojacking #Firebase C2 #GhostGrab #Hybrid Threat #Monero mining #OTP Interception
Daily CyberSecurity
GhostGrab Android Malware Combines Covert Monero Mining with Financial Credential Theft
GhostGrab is a hybrid Android malware that steals banking credentials and OTPs via phishing WebView overlays while secretly running a Monero miner in the background to monetize the victim's device.
⤷ Title: RedTiger Infostealer Weaponizes Python Red-Teaming Tool to Hack Discord Accounts and Steal Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:07:16 +0000
════════════════════════
⌗ Tags: #Malware #Discord Tokens #Gamer Targets #GoFile C2 #Infostealer #Python RAT #Red_Teaming Tool Abuse #RedTiger
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:07:16 +0000
════════════════════════
⌗ Tags: #Malware #Discord Tokens #Gamer Targets #GoFile C2 #Infostealer #Python RAT #Red_Teaming Tool Abuse #RedTiger
Daily CyberSecurity
RedTiger Infostealer Weaponizes Python Red-Teaming Tool to Hack Discord Accounts and Steal Crypto Wallets
Netskope found the RedTiger Python tool repurposed as an infostealer targeting gamers. It uses Discord injection to steal tokens/payment data and GoFile for anonymous data exfiltration, spamming files/processes for evasion.
⤷ Title: Finally: iOS 26.1 Unlocks Seamless Background Photo Uploads for All Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:04:52 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Background Upload #cloud storage #iOS 26.1 #PhotoKit #privacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:04:52 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Background Upload #cloud storage #iOS 26.1 #PhotoKit #privacy
Daily CyberSecurity
Finally: iOS 26.1 Unlocks Seamless Background Photo Uploads for All Apps
iOS 26.1 introduces a new PhotoKit feature that allows third-party apps like Google Photos to upload media seamlessly in the background, even when the phone is locked.
⤷ Title: Bing Wallpaper Update Clicks the Desktop to Force-Launch Bing Search
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:01:52 +0000
════════════════════════
⌗ Tags: #Windows #bing search #Bing Wallpaper #Microsoft #privacy #User Experience #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:01:52 +0000
════════════════════════
⌗ Tags: #Windows #bing search #Bing Wallpaper #Microsoft #privacy #User Experience #windows
Daily CyberSecurity
Bing Wallpaper Update Clicks the Desktop to Force-Launch Bing Search
Microsoft’s latest Bing Wallpaper update covertly launches Bing Search when users click the desktop, appearing to artificially inflate the search engine’s traffic.
⤷ Title: When Your Bug Bounty Gets Stolen: A Guide to Reclaiming What’s Rightfully Yours
════════════════════════
𐀪 Author: Krystal
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:52:15 GMT
════════════════════════
⌗ Tags: #intellectual_property #bug_bounty #cybersecurity #this_happened_to_me #hacked
════════════════════════
𐀪 Author: Krystal
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:52:15 GMT
════════════════════════
⌗ Tags: #intellectual_property #bug_bounty #cybersecurity #this_happened_to_me #hacked
Medium
When Your Bug Bounty Gets Stolen: A Guide to Reclaiming What’s Rightfully Yours
When Your Bug Bounty Gets Stolen: A Guide to Reclaiming What’s Rightfully Yours The Dark Side of Cybersecurity Research Bug bounty programs were created to incentivize ethical hackers and security …
⤷ Title: Guía Esencial de ParamSpider para la Extracción de URLs
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:02:18 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #bug_bounty #cybersecurity #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:02:18 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #bug_bounty #cybersecurity #hacking
Medium
Guía Esencial de ParamSpider para la Extracción de URLs
ParamSpider: Herramienta para el reconocimiento pasivo y extracción URLs con parámetros. Esencial para descubrir XSS, SQLi y LFI
⤷ Title: Evidencias (The Hacker Labs)
════════════════════════
𐀪 Author: FeCeSociety
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:02:47 GMT
════════════════════════
⌗ Tags: #hacking #ctf #cybersecurity #writeup #ciberseguridad
════════════════════════
𐀪 Author: FeCeSociety
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:02:47 GMT
════════════════════════
⌗ Tags: #hacking #ctf #cybersecurity #writeup #ciberseguridad
Medium
Evidencias (The Hacker Labs)
Este informe detalla la secuencia de eventos que condujo al compromiso exitoso de la aplicación web alojada. El ataque combinó técnicas de…
⤷ Title: Are You Worried About Databases Hacked? And Benefits of Blackhatclique:
════════════════════════
𐀪 Author: Donley Mark
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:49:09 GMT
════════════════════════
⌗ Tags: #hacking #data_science #electronics #recovery #life_hacking
════════════════════════
𐀪 Author: Donley Mark
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:49:09 GMT
════════════════════════
⌗ Tags: #hacking #data_science #electronics #recovery #life_hacking
Medium
Are You Worried About Databases Hacked? And Benefits of Blackhatclique:
Are You Worried About Databases Hacked? And Benefits of Blackhatclique: Database hacking involves exploiting vulnerabilities in database systems to gain unauthorized access to sensitive data. Here's …
⤷ Title: Did DNS Really Take Down the Internet — or Was It Something Else?
════════════════════════
𐀪 Author: Lucky Nautiyal
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:44:17 GMT
════════════════════════
⌗ Tags: #ai #technology #cybersecurity #aws #internet
════════════════════════
𐀪 Author: Lucky Nautiyal
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:44:17 GMT
════════════════════════
⌗ Tags: #ai #technology #cybersecurity #aws #internet
Medium
Did DNS Really Take Down the Internet — or Was It Something Else? When AWS sneezed, the Internet caught a fever.
The Day the Cloud Went Dark
⤷ Title: ChatGPT Atlas vs. Chrome: Use It or Dump It?
════════════════════════
𐀪 Author: Nathaniel Niyazov
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:13:05 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #technology #productivity #future_of_work
════════════════════════
𐀪 Author: Nathaniel Niyazov
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:13:05 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #cybersecurity #technology #productivity #future_of_work
Medium
ChatGPT Atlas vs. Chrome: Use It or Dump It?
Excerpt:
⤷ Title: Unlocking Cybersecurity Excellence: My Journey with 591Lab’s CISSP Certification Guide.
════════════════════════
𐀪 Author: Al Beruni
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:07:46 GMT
════════════════════════
⌗ Tags: #certification #unlocking #591lab #cybersecurity #cissp
════════════════════════
𐀪 Author: Al Beruni
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:07:46 GMT
════════════════════════
⌗ Tags: #certification #unlocking #591lab #cybersecurity #cissp
Medium
Unlocking Cybersecurity Excellence: My Journey with 591Lab’s CISSP Certification Guide.
Using 591Lab’s CISSP Certification Guide to Unlock Excellence in Cybersecurity.
⤷ Title: Legal Protections Against Digital Gender-Based Violence
════════════════════════
𐀪 Author: Sophia Shalbey
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:04:52 GMT
════════════════════════
⌗ Tags: #feminisn #doxxing #cyberstalkers #women #cybersecurity
════════════════════════
𐀪 Author: Sophia Shalbey
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 01:04:52 GMT
════════════════════════
⌗ Tags: #feminisn #doxxing #cyberstalkers #women #cybersecurity
Medium
Legal Protections Against Digital Gender-Based Violence
As media becomes a more central focus in the lives of the newest generations, a visible trend regarding cyber security has arisen: a…
⤷ Title: The BLE Protocol Stack: A Security Analysis
════════════════════════
𐀪 Author: Irene A. Gil
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:57:58 GMT
════════════════════════
⌗ Tags: #bluetooth_low_energy #cybersecurity #software_development
════════════════════════
𐀪 Author: Irene A. Gil
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:57:58 GMT
════════════════════════
⌗ Tags: #bluetooth_low_energy #cybersecurity #software_development
Medium
The BLE Protocol Stack: A Security Analysis
The modern world runs on whispers. The constant, low-power data transmissions from our wearables, smart locks, and industrial sensors are…
⤷ Title: How I Set Up Sysmon and Splunk Without Losing My Sanity
════════════════════════
𐀪 Author: Udith Ragav
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:47:32 GMT
════════════════════════
⌗ Tags: #splunk #siem #cybersecurity #sysmon #windows_security
════════════════════════
𐀪 Author: Udith Ragav
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:47:32 GMT
════════════════════════
⌗ Tags: #splunk #siem #cybersecurity #sysmon #windows_security
Medium
How I Set Up Sysmon and Splunk Without Losing My Sanity
Let’s be honest — integrating Sysmon with Splunk sounds easy until you try it. Then suddenly you’re knee-deep in XML logs, forwarder…
⤷ Title: PaloAltoRCE Lab Write-Up | By BnHany
════════════════════════
𐀪 Author: BnHany
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:25:43 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #digital_forensics #ctf_writeup #network_security
════════════════════════
𐀪 Author: BnHany
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:25:43 GMT
════════════════════════
⌗ Tags: #vulnerability #cybersecurity #digital_forensics #ctf_writeup #network_security
Medium
PaloAltoRCE Lab Write-Up | By BnHany
⚠️ Disclaimer ⚠️ This write-up is for educational purposes only. It is meant to explain the thought process and steps taken to solve the…
⤷ Title: Sobre o IBSEC
════════════════════════
𐀪 Author: Wesley Paulow
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:06:33 GMT
════════════════════════
⌗ Tags: #avaliação #cybersecurity #certificações #critica
════════════════════════
𐀪 Author: Wesley Paulow
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:06:33 GMT
════════════════════════
⌗ Tags: #avaliação #cybersecurity #certificações #critica
Medium
Sobre o IBSEC
Ou sobre ter gasto meu tempo para você poupar o seu
⤷ Title: CSRF Lab Walkthrough: Exploiting Non-Session Cookie Token Binding
════════════════════════
𐀪 Author: CyberSec Xploit | Prasangam
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 03:38:23 GMT
════════════════════════
⌗ Tags: #websecurity_testing #bug_bounty #web_security #csrf
════════════════════════
𐀪 Author: CyberSec Xploit | Prasangam
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 03:38:23 GMT
════════════════════════
⌗ Tags: #websecurity_testing #bug_bounty #web_security #csrf
Medium
CSRF Lab Walkthrough: Exploiting Non-Session Cookie Token Binding
🔍 Lab Overview
⤷ Title: Man-in-the-Middle Attack Simulation Using Bettercap: An Ethical Hacking Case Study
════════════════════════
𐀪 Author: Leroyanand
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 03:56:59 GMT
════════════════════════
⌗ Tags: #knowledge #cybersecurity #ethical_hacking #hacking #mitm_attacks
════════════════════════
𐀪 Author: Leroyanand
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 03:56:59 GMT
════════════════════════
⌗ Tags: #knowledge #cybersecurity #ethical_hacking #hacking #mitm_attacks
Medium
Man-in-the-Middle Attack Simulation Using Bettercap: An Ethical Hacking Case Study
1. Introduction