⤷ Title: TryHackMe MD2PDF: SSRF Challenge Walkthrough
════════════════════════
𐀪 Author: Trixia Horner
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:50:52 GMT
════════════════════════
⌗ Tags: #ssrf #tryhackme #ctf #html #cybersecurity
════════════════════════
𐀪 Author: Trixia Horner
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:50:52 GMT
════════════════════════
⌗ Tags: #ssrf #tryhackme #ctf #html #cybersecurity
Medium
TryHackMe MD2PDF: SSRF Challenge Walkthrough
Step-by-step MD2PDF walkthrough showing how an HTML→PDF renderer can be abused for SSRF.
⤷ Title: Practicing PowerShell Automation in My SOC Analyst Lab
════════════════════════
𐀪 Author: Jenna S
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:40:18 GMT
════════════════════════
⌗ Tags: #blue_team #cybersecurity #homelab #powershell #wowenintech
════════════════════════
𐀪 Author: Jenna S
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:40:18 GMT
════════════════════════
⌗ Tags: #blue_team #cybersecurity #homelab #powershell #wowenintech
Medium
🧩 Practicing PowerShell Automation in My SOC Analyst Lab
Today I spent some time in my Windows Server lab building a small PowerShell automation script — something simple but practical.
⤷ Title: BREAKING : Wuzen Android RAT Source Code Leaked - Now Free on Telegram Channels
════════════════════════
𐀪 Author: REE-D-BLACK
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:22:30 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #decentralized_finance #cybersecurity #encryption #security
════════════════════════
𐀪 Author: REE-D-BLACK
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:22:30 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #decentralized_finance #cybersecurity #encryption #security
Medium
BREAKING : Wuzen Android RAT Source Code Leaked - Now Free on Telegram Channels
Cybersecurity Alert 2025 - Mass Distribution Underway
⤷ Title: الشبكات البين الحرية والرقابة: هل استخدام VPN قانوني في الدول العربية حقا؟
════════════════════════
𐀪 Author: Yehya Ahmed
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:13:56 GMT
════════════════════════
⌗ Tags: #انترنت #vpn #أمن_الشبكات #cybersecurity #internet
════════════════════════
𐀪 Author: Yehya Ahmed
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:13:56 GMT
════════════════════════
⌗ Tags: #انترنت #vpn #أمن_الشبكات #cybersecurity #internet
Medium
الشبكات البين الحرية والرقابة: هل استخدام VPN قانوني في الدول العربية حقا؟
في عصر تتقاطع فيه الخصوصية مع الأمن، لم يعد السؤال عن “كيفية استخدام الإنترنت” هو الأهم، بل “كيف نحمي أنفسنا أثناء استخدامه؟” وهنا يبرز…
⤷ Title: Let’s get some physical
════════════════════════
𐀪 Author: Pablo M
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:10:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #pentesting
════════════════════════
𐀪 Author: Pablo M
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:10:06 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_team #pentesting
Medium
Let’s get some physical
Lately, I’ve been diving into the world of evasion — not for a cert, not for a client gig, just because I realized something painful: if…
⤷ Title: X Warns Users With Security Keys: Re-Enroll or Get Locked Out
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 22:44:43 GMT
════════════════════════
⌗ Tags: #twitter #information_security #mfa #cybersecurity #ai
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 22:44:43 GMT
════════════════════════
⌗ Tags: #twitter #information_security #mfa #cybersecurity #ai
Medium
X Warns Users With Security Keys: Re-Enroll or Get Locked Out
In a major security update, X (formerly Twitter) has announced that users who rely on hardware security keys or passkeys for two-factor…
⤷ Title: Simple X Bonus Guide — October 2025
════════════════════════
𐀪 Author: Amelia
Chandler
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:03:41 GMT
════════════════════════
⌗ Tags: #rewards #guide #xs #crypto #bonus
════════════════════════
𐀪 Author: Amelia
Chandler
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:03:41 GMT
════════════════════════
⌗ Tags: #rewards #guide #xs #crypto #bonus
Medium
Simple X Bonus Guide — October 2025
A complete beginner-friendly roadmap to access bonuses and benefits from X.
⤷ Title: AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
Daily CyberSecurity
AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
ASEC exposed a flaw in Gunra Linux ransomware: its ChaCha20 keys are generated using an insecure time()/rand() seed, potentially allowing victims to brute-force decryption and recover files.
⤷ Title: Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:40:57 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #Anti_Fraud #Behavioral Biometrics #Brazil #Device Takeover #Herodotus #Italy #M_a_a_S
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:40:57 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #Anti_Fraud #Behavioral Biometrics #Brazil #Device Takeover #Herodotus #Italy #M_a_a_S
Daily CyberSecurity
Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems
Herodotus is a new Android banking Trojan that evades anti-fraud systems by simulating human input: it inserts randomized typing delays (300-3000ms) during remote-control attacks in Italy and Brazil.
⤷ Title: Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:33:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CI/CD security #Critical Vulnerability #CVE_2025_62725 #Docker Compose #OCI Artifacts #Path Traversal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:33:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CI/CD security #Critical Vulnerability #CVE_2025_62725 #Docker Compose #OCI Artifacts #Path Traversal
Daily CyberSecurity
Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts
A path traversal flaw (CVE-2025-62725) in Docker Compose lets attackers overwrite host files via remote OCI artifact annotations, triggered by read-only commands.
⤷ Title: BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI Social Engineering #APT #BlueNoroff #DownTroy #GhostCall #GhostHire #GPT_4o #macOS #SilentSiphon
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI Social Engineering #APT #BlueNoroff #DownTroy #GhostCall #GhostHire #GPT_4o #macOS #SilentSiphon
Daily CyberSecurity
BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings
Kaspersky exposed BlueNoroff's GhostCall/GhostHire campaigns, which use AI-enhanced lures (GPT-4o images) and trojanized apps to target executives and developers, deploying SilentSiphon spyware on macOS.
⤷ Title: Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:26:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Confused Deputy #CVE_2025_12080 #Google Messages #Intent Abuse #Smartwatch Security #SMS Injection #Wear OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:26:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Confused Deputy #CVE_2025_12080 #Google Messages #Intent Abuse #Smartwatch Security #SMS Injection #Wear OS
Daily CyberSecurity
Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available
A flaw (CVE-2025-12080) in Google Messages for Wear OS allows any installed app to send SMS/RCS messages without permission by abusing ACTION_SENDTO intents.
⤷ Title: Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Adobe Commerce #Critical RCE #CVE_2025_54236 #e_commerce security #Magento #SessionReaper
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Adobe Commerce #Critical RCE #CVE_2025_54236 #e_commerce security #Magento #SessionReaper
Daily CyberSecurity
Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE
Akamai warns of active exploitation of Magento's SessionReaper flaw (CVE-2025-54236). The critical (CVSS 9.8) vulnerability allows session hijacking and unauthenticated RCE via web shells.
⤷ Title: Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
Daily CyberSecurity
Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
AhnLab exposed Beast ransomware (Monster evolution) as a new RaaS threat, with 16+ victims by August 2025. It uses ChaCha20 encryption, deletes Shadow Copies, and features a hidden GUI control panel.
⤷ Title: Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:11:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Theft #Critical Vulnerability #CVE_2025_61481 #http #MikroTik #RouterOS #SwitchOS #WebFig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:11:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Theft #Critical Vulnerability #CVE_2025_61481 #http #MikroTik #RouterOS #SwitchOS #WebFig
Daily CyberSecurity
Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig
A Critical (CVSS 10.0) flaw (CVE-2025-61481) in MikroTik RouterOS/SwOS exposes the WebFig management interface over unencrypted HTTP by default, allowing remote credential theft via MitM.
⤷ Title: Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:06:06 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Brazil #fileless #IMAP C2 #powershell #Selenium #Water Saci #WhatsApp Worm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:06:06 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Brazil #fileless #IMAP C2 #powershell #Selenium #Water Saci #WhatsApp Worm
Daily CyberSecurity
Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking
Trend exposed the Water Saci worm, a self-propagating campaign that hijacks WhatsApp Web using Selenium/PowerShell. It uses a stealthy IMAP email C2 channel with HTTP fallback.
⤷ Title: Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
Daily CyberSecurity
Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
AhnLab exposed Rhadamanthys Infostealer hiding in games built with the Ren'Py engine. It uses a fake 1M-second loading screen to distract victims while injecting malware via a malicious Python script.
⤷ Title: CORS Vulnerability
════════════════════════
𐀪 Author: Fatimahasan
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:41:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #portswigger #pentesting #bug_bounty
════════════════════════
𐀪 Author: Fatimahasan
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:41:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #portswigger #pentesting #bug_bounty
Medium
CORS Vulnerability
To understand what a CORS vulnerability is, we first need to know what CORS means and why browsers use it.
⤷ Title: ParamSpider Essential Guide to URL Extraction
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #technology #bug_bounty #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #technology #bug_bounty #hacking
Medium
ParamSpider Essential Guide to URL Extraction
ParamSpider: Tool for passive recognition and extraction of URLs with parameters. Essential for discovering XSS, SQLi, and LFI.
⤷ Title: SOC274 — Palo Alto Networks PAN-OS Command Injection Vulnerability Exploitation (CVE-2024–3400)
════════════════════════
𐀪 Author: Brandon Love
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:51:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #blueteamlabs #letsdefendio
════════════════════════
𐀪 Author: Brandon Love
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:51:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #blueteamlabs #letsdefendio
Medium
SOC274 — Palo Alto Networks PAN-OS Command Injection Vulnerability Exploitation (CVE-2024–3400)
We are going to dive into the PAN OS Command Injection Vulnerability (CVE-2024–3400). This attack is a command injection resulting from an…
⤷ Title: GlassWorm: Self-Propagating Worm Compromises VSCode Extensions
════════════════════════
𐀪 Author: Wraith
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:40:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #worms
════════════════════════
𐀪 Author: Wraith
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:40:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #worms
Medium
GlassWorm: Self-Propagating Worm Compromises VSCode Extensions
Events Timeline