⤷ Title: AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:45:15 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Cryptographic Weakness #File Recovery #Gunra Ransomware #Linux ELF #RaaS #rand() flaw
Daily CyberSecurity
AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
ASEC exposed a flaw in Gunra Linux ransomware: its ChaCha20 keys are generated using an insecure time()/rand() seed, potentially allowing victims to brute-force decryption and recover files.
⤷ Title: Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:40:57 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #Anti_Fraud #Behavioral Biometrics #Brazil #Device Takeover #Herodotus #Italy #M_a_a_S
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:40:57 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #Anti_Fraud #Behavioral Biometrics #Brazil #Device Takeover #Herodotus #Italy #M_a_a_S
Daily CyberSecurity
Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems
Herodotus is a new Android banking Trojan that evades anti-fraud systems by simulating human input: it inserts randomized typing delays (300-3000ms) during remote-control attacks in Italy and Brazil.
⤷ Title: Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:33:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CI/CD security #Critical Vulnerability #CVE_2025_62725 #Docker Compose #OCI Artifacts #Path Traversal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:33:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CI/CD security #Critical Vulnerability #CVE_2025_62725 #Docker Compose #OCI Artifacts #Path Traversal
Daily CyberSecurity
Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts
A path traversal flaw (CVE-2025-62725) in Docker Compose lets attackers overwrite host files via remote OCI artifact annotations, triggered by read-only commands.
⤷ Title: BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI Social Engineering #APT #BlueNoroff #DownTroy #GhostCall #GhostHire #GPT_4o #macOS #SilentSiphon
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI Social Engineering #APT #BlueNoroff #DownTroy #GhostCall #GhostHire #GPT_4o #macOS #SilentSiphon
Daily CyberSecurity
BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings
Kaspersky exposed BlueNoroff's GhostCall/GhostHire campaigns, which use AI-enhanced lures (GPT-4o images) and trojanized apps to target executives and developers, deploying SilentSiphon spyware on macOS.
⤷ Title: Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:26:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Confused Deputy #CVE_2025_12080 #Google Messages #Intent Abuse #Smartwatch Security #SMS Injection #Wear OS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:26:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Confused Deputy #CVE_2025_12080 #Google Messages #Intent Abuse #Smartwatch Security #SMS Injection #Wear OS
Daily CyberSecurity
Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available
A flaw (CVE-2025-12080) in Google Messages for Wear OS allows any installed app to send SMS/RCS messages without permission by abusing ACTION_SENDTO intents.
⤷ Title: Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Adobe Commerce #Critical RCE #CVE_2025_54236 #e_commerce security #Magento #SessionReaper
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:21:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Adobe Commerce #Critical RCE #CVE_2025_54236 #e_commerce security #Magento #SessionReaper
Daily CyberSecurity
Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE
Akamai warns of active exploitation of Magento's SessionReaper flaw (CVE-2025-54236). The critical (CVSS 9.8) vulnerability allows session hijacking and unauthenticated RCE via web shells.
⤷ Title: Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:18:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASEC #Beast Ransomware #ChaCha20 #Monster Evolution #RaaS #ransomware #Shadow Copy Deletion #Windows Run Key
Daily CyberSecurity
Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
AhnLab exposed Beast ransomware (Monster evolution) as a new RaaS threat, with 16+ victims by August 2025. It uses ChaCha20 encryption, deletes Shadow Copies, and features a hidden GUI control panel.
⤷ Title: Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:11:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Theft #Critical Vulnerability #CVE_2025_61481 #http #MikroTik #RouterOS #SwitchOS #WebFig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:11:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Credential Theft #Critical Vulnerability #CVE_2025_61481 #http #MikroTik #RouterOS #SwitchOS #WebFig
Daily CyberSecurity
Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig
A Critical (CVSS 10.0) flaw (CVE-2025-61481) in MikroTik RouterOS/SwOS exposes the WebFig management interface over unencrypted HTTP by default, allowing remote credential theft via MitM.
⤷ Title: Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:06:06 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Brazil #fileless #IMAP C2 #powershell #Selenium #Water Saci #WhatsApp Worm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:06:06 +0000
════════════════════════
⌗ Tags: #Malware #botnet #Brazil #fileless #IMAP C2 #powershell #Selenium #Water Saci #WhatsApp Worm
Daily CyberSecurity
Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking
Trend exposed the Water Saci worm, a self-propagating campaign that hijacks WhatsApp Web using Selenium/PowerShell. It uses a stealthy IMAP email C2 channel with HTTP fallback.
⤷ Title: Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:01:24 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Fake Loading Screen #Gaming Malware #Infostealer #Python #Ren'Py #Rhadamanthys #Visual Novel
Daily CyberSecurity
Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
AhnLab exposed Rhadamanthys Infostealer hiding in games built with the Ren'Py engine. It uses a fake 1M-second loading screen to distract victims while injecting malware via a malicious Python script.
⤷ Title: CORS Vulnerability
════════════════════════
𐀪 Author: Fatimahasan
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:41:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #portswigger #pentesting #bug_bounty
════════════════════════
𐀪 Author: Fatimahasan
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:41:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #portswigger #pentesting #bug_bounty
Medium
CORS Vulnerability
To understand what a CORS vulnerability is, we first need to know what CORS means and why browsers use it.
⤷ Title: ParamSpider Essential Guide to URL Extraction
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #technology #bug_bounty #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #technology #bug_bounty #hacking
Medium
ParamSpider Essential Guide to URL Extraction
ParamSpider: Tool for passive recognition and extraction of URLs with parameters. Essential for discovering XSS, SQLi, and LFI.
⤷ Title: SOC274 — Palo Alto Networks PAN-OS Command Injection Vulnerability Exploitation (CVE-2024–3400)
════════════════════════
𐀪 Author: Brandon Love
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:51:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #blueteamlabs #letsdefendio
════════════════════════
𐀪 Author: Brandon Love
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:51:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #blueteamlabs #letsdefendio
Medium
SOC274 — Palo Alto Networks PAN-OS Command Injection Vulnerability Exploitation (CVE-2024–3400)
We are going to dive into the PAN OS Command Injection Vulnerability (CVE-2024–3400). This attack is a command injection resulting from an…
⤷ Title: GlassWorm: Self-Propagating Worm Compromises VSCode Extensions
════════════════════════
𐀪 Author: Wraith
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:40:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #worms
════════════════════════
𐀪 Author: Wraith
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:40:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #worms
Medium
GlassWorm: Self-Propagating Worm Compromises VSCode Extensions
Events Timeline
⤷ Title: Oracle EBS Runtime Interface Vulnerability Leads to Data Exposure (CVE-2025–61884)
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:33:04 GMT
════════════════════════
⌗ Tags: #oracle_ebs #cve_2025_61884 #cybersecurity #vulnerability #threat_intelligence
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:33:04 GMT
════════════════════════
⌗ Tags: #oracle_ebs #cve_2025_61884 #cybersecurity #vulnerability #threat_intelligence
Medium
Oracle EBS Runtime Interface Vulnerability Leads to Data Exposure (CVE-2025–61884)
CVE-2025–61884 has been disclosed for Oracle E-Business Suite (EBS). The affected component, Oracle Configurator Runtime UI, can be…
⤷ Title: 8 Types of Malware and How They Really Work in 2025
════════════════════════
𐀪 Author: Rizqi Mulki
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:23:13 GMT
════════════════════════
⌗ Tags: #malware #malware_analysis #cybersecurity #information_security #cyber_security_awareness
════════════════════════
𐀪 Author: Rizqi Mulki
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:23:13 GMT
════════════════════════
⌗ Tags: #malware #malware_analysis #cybersecurity #information_security #cyber_security_awareness
Medium
💻 8 Types of Malware and How They Really Work in 2025
What really happens when you click that one wrong link?
⤷ Title: Getting Started with Bash-Day 1 of My Cybersecurity Journey
════════════════════════
𐀪 Author: Sammy
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:06:36 GMT
════════════════════════
⌗ Tags: #information_technology #bash_script #linux #technology #cybersecurity
════════════════════════
𐀪 Author: Sammy
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:06:36 GMT
════════════════════════
⌗ Tags: #information_technology #bash_script #linux #technology #cybersecurity
Medium
Getting Started with Bash-Day 1 of My Cybersecurity Journey
As a self-paced cyber learner, I started to learn Bash before jumping to the vast Linux tool sets and technologies. By profession, I am a…
⤷ Title: The Role of Employee Training in Cybersecurity
════════════════════════
𐀪 Author: TRS Wireless
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:02:20 GMT
════════════════════════
⌗ Tags: #cybersecurity
════════════════════════
𐀪 Author: TRS Wireless
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 01:02:20 GMT
════════════════════════
⌗ Tags: #cybersecurity
Medium
The Role of Employee Training in Cybersecurity
Learn how employee cybersecurity awareness can safeguard your business from common cyber threats.
⤷ Title: Cybersecurity Meets Creativity: ISE 2026 Ushers in a New Era for the Audiovisual Industry
════════════════════════
𐀪 Author: Darknetsearch.com
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:07:42 GMT
════════════════════════
⌗ Tags: #ise2026 #cybersecurity_awareness #dark_web_monitoring #cyber_resilience #cybersecurity
════════════════════════
𐀪 Author: Darknetsearch.com
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:07:42 GMT
════════════════════════
⌗ Tags: #ise2026 #cybersecurity_awareness #dark_web_monitoring #cyber_resilience #cybersecurity
Medium
🔐 Cybersecurity Meets Creativity: ISE 2026 Ushers in a New Era for the Audiovisual Industry
In 2026, the Integrated Systems Europe (ISE) event in Barcelona will host a pivotal Cybersecurity Summit — and it’s more than just a tech…
⤷ Title: How a Dedicated Server helps protect Confidential information from Being Accessed
════════════════════════
𐀪 Author: Adella Pasos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:59:19 GMT
════════════════════════
⌗ Tags: #servers #data_breach #data_science #cybersecurity #data_privacy
════════════════════════
𐀪 Author: Adella Pasos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 23:59:19 GMT
════════════════════════
⌗ Tags: #servers #data_breach #data_science #cybersecurity #data_privacy
Medium
How a Dedicated Server helps protect Confidential information from Being Accessed
In today’s digital landscape, safeguarding your confidential information is paramount. As a business owner or IT professional, you…
⤷ Title: Step-by-Step X Rewards Guide — October 2025
════════════════════════
𐀪 Author: Logan
Fowler
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:34:07 GMT
════════════════════════
⌗ Tags: #xs #tutorial #rewards #crypto #blockchain
════════════════════════
𐀪 Author: Logan
Fowler
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 00:34:07 GMT
════════════════════════
⌗ Tags: #xs #tutorial #rewards #crypto #blockchain
Medium
✔️ How To Claim X Airdrop — Step By Step Guide [October 2025]
Follow our easy walkthrough to unlock exclusive X benefits.