⤷ Title: ISC Patches High-Severity Kea DHCPv4 DoS (CVE-2025-11232) Flaw, Allows Crash via Malformed Hostname
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:54:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11232 #Denial of Service #Hostname Validation #ISC #Kea DHCPv4 #Network Disruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:54:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_11232 #Denial of Service #Hostname Validation #ISC #Kea DHCPv4 #Network Disruption
Daily CyberSecurity
ISC Patches High-Severity Kea DHCPv4 DoS (CVE-2025-11232) Flaw, Allows Crash via Malformed Hostname
ISC warned of a High-severity DoS flaw (CVE-2025-11232) in Kea DHCPv4. A crafted DHCP packet can crash the server due to improper hostname validation, disrupting IP assignment. Patch to v3.0.2/3.1.3.
⤷ Title: Wordfence Warns of Active Exploits Targeting Critical Privilege Escalation Flaw in WP Freeio (CVE-2025-11533)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:48:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admin Takeover #CVSS 9.8 #cybersecurity #Plugin Vulnerability #privilege escalation #wordpress #WP Freeio
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:48:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Admin Takeover #CVSS 9.8 #cybersecurity #Plugin Vulnerability #privilege escalation #wordpress #WP Freeio
Daily CyberSecurity
Wordfence Warns of Active Exploits Targeting Critical Privilege Escalation Flaw in WP Freeio (CVE-2025-11533)
Urgent patch for WP Freeio plugin (v.< 1.2.22). Unauthenticated attackers can gain admin control instantly via a registration flaw. Update immediately to v.1.2.22.
⤷ Title: Google Rolls Out Chrome 142 Patching 20 Security Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:39:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #CVE_2025_12428 #cybersecurity #google chrome #High Severity #Patch Tuesday #V8 Engine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:39:57 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #browser security #CVE_2025_12428 #cybersecurity #google chrome #High Severity #Patch Tuesday #V8 Engine
Daily CyberSecurity
Google Rolls Out Chrome 142 Patching 20 Security Flaws
Google Chrome 142 desktop update fixes 20 security flaws, including critical V8 Type Confusion (CVE-2025-12428) and Race conditions. Update your browser now.
⤷ Title: npm Typosquat Campaign: 10 Malicious Packages Deliver PyInstaller Infostealer via Fake CAPTCHA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:55:50 +0000
════════════════════════
⌗ Tags: #Malware #CAPTCHA Lure #Credential Theft #Infostealer #npm #PyInstaller #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:55:50 +0000
════════════════════════
⌗ Tags: #Malware #CAPTCHA Lure #Credential Theft #Infostealer #npm #PyInstaller #supply chain attack #Typosquatting
Daily CyberSecurity
npm Typosquat Campaign: 10 Malicious Packages Deliver PyInstaller Infostealer via Fake CAPTCHA
Socket exposed an npm typosquat campaign using 10 fake packages (Netherеum.All). The malicious postinstall script deploys a 24MB PyInstaller stealer after prompting a fake CAPTCHA.
⤷ Title: Researcher Details Critical Authentication Bypasses in WSO2 API Manager and Identity Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:50:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Manager #Auth Bypass #Critical Vulnerability #CVE_2025_9152 #Identity Server #Regex Flaw #WSO2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:50:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Manager #Auth Bypass #Critical Vulnerability #CVE_2025_9152 #Identity Server #Regex Flaw #WSO2
Daily CyberSecurity
Researcher Details Critical Authentication Bypasses in WSO2 API Manager and Identity Server
WSO2 patched three Critical flaws (CVSS 9.8) in API Manager/Identity Server. Flaws in regex access control and case-sensitive HTTP methods allow unauthenticated administrative takeover.
⤷ Title: TEE.fail: Researchers Break Intel SGX/TDX and AMD SEV-SNP with Sub-$1,000 DDR5 Memory Bus Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:42:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Confidential Computing #DDR5 #SEV_SNP #SGX #side_channel attack #TDX #TEE #TEE.fail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:42:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Confidential Computing #DDR5 #SEV_SNP #SGX #side_channel attack #TDX #TEE #TEE.fail
Daily CyberSecurity
TEE.fail: Researchers Break Intel SGX/TDX and AMD SEV-SNP with Sub-$1,000 DDR5 Memory Bus Attack
A critical hardware attack, TEE.fail, uses low-cost DDR5 memory bus interposition to extract root attestation keys from Intel TDX and AMD SEV-SNP. The flaw affects core server-grade TEEs.
⤷ Title: Trigona Ransomware Attacks MS-SQL Servers Using Rust Scanner and BCP Utility to Deploy Payloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:34:42 +0000
════════════════════════
⌗ Tags: #Malware #AnyDesk #BCP Utility #CLR Shell #MS_SQL Server #RaaS #ransomware #Rust Scanner #Trigona
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:34:42 +0000
════════════════════════
⌗ Tags: #Malware #AnyDesk #BCP Utility #CLR Shell #MS_SQL Server #RaaS #ransomware #Rust Scanner #Trigona
Daily CyberSecurity
Trigona Ransomware Attacks MS-SQL Servers Using Rust Scanner and BCP Utility to Deploy Payloads
ASEC exposed Trigona RaaS attacking exposed MS-SQL servers via brute-force. The group uses CLR Shell, a new Rust-based scanner, and the BCP utility to store and execute malware from database tables.
⤷ Title: Stealthy Dual Malware Loader Uncovered: Executes TorNet & PureHVNC Simultaneously, Cloaked by MurmurHash2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:31:44 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #Cyberespionage #DLL Sideloading #IIJ #malware loader #MurmurHash2 #PureHVNC #TorNet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:31:44 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #Cyberespionage #DLL Sideloading #IIJ #malware loader #MurmurHash2 #PureHVNC #TorNet
Daily CyberSecurity
Stealthy Dual Malware Loader Uncovered: Executes TorNet & PureHVNC Simultaneously, Cloaked by MurmurHash2
IIJ exposed a novel loader that simultaneously deploys TorNet (TOR C2) and PureHVNC (RAT) via DLL sideloading. It uses MurmurHash2 for API hashing and injects into jsc.exe for stealth.
⤷ Title: Midnight Ransomware Decryption Flaw: Babuk Successor’s RSA Implementation Mistake Allows Free File Recovery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:24:15 +0000
════════════════════════
⌗ Tags: #Malware #Babuk #ChaCha20 #cryptography #decryptor #File Recovery #Midnight Ransomware #RaaS #RSA Flaw
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:24:15 +0000
════════════════════════
⌗ Tags: #Malware #Babuk #ChaCha20 #cryptography #decryptor #File Recovery #Midnight Ransomware #RaaS #RSA Flaw
Daily CyberSecurity
Midnight Ransomware Decryption Flaw: Babuk Successor’s RSA Implementation Mistake Allows Free File Recovery
A Babuk successor, Midnight ransomware, contains a critical flaw in its RSA key handling. Gen researchers created a free decryptor that bypasses the encryption, allowing victims to recover files.
⤷ Title: VSCode Supply Chain Compromise: 12 Malicious Extensions Steal Source Code and Open Remote Shells
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Malicious Extension #Ngrok #Remote Shell #Source Code Theft #supply chain attack #VSCode
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:20:37 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Malicious Extension #Ngrok #Remote Shell #Source Code Theft #supply chain attack #VSCode
Daily CyberSecurity
VSCode Supply Chain Compromise: 12 Malicious Extensions Steal Source Code and Open Remote Shells
HelixGuard exposed a VSCode supply chain attack using 12 malicious extensions. They steal source code, capture screenshots, and open reverse shells via Ngrok and AWS EC2 to compromise developers.
⤷ Title: Major Shift: Chrome 154 Will Default to “Always Use Secure Connections,” Warning Users Before Insecure HTTP Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:15:32 +0000
════════════════════════
⌗ Tags: #Technology #Chrome 154 #Default Security #google chrome #https #Man in the Middle #Secure Connections #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:15:32 +0000
════════════════════════
⌗ Tags: #Technology #Chrome 154 #Default Security #google chrome #https #Man in the Middle #Secure Connections #Web Security
Daily CyberSecurity
Major Shift: Chrome 154 Will Default to “Always Use Secure Connections,” Warning Users Before Insecure HTTP Sites
Google announced Chrome 154 (Oct 2026) will automatically enable “Always Use Secure Connections,” marking a major security push to combat MitM attacks by warning users before visiting unencrypted HTTP sites.
⤷ Title: Researcher Details Windows Cloud Files Mini Filter Driver Elevation of Privilege Flaw (CVE-2025-55680)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:06:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Cloud Files Minifilter #CVE_2025_55680 #race condition #TOCTOU #Windows LPE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:06:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #Cloud Files Minifilter #CVE_2025_55680 #race condition #TOCTOU #Windows LPE
Daily CyberSecurity
Researcher Details Windows Cloud Files Mini Filter Driver Elevation of Privilege Flaw (CVE-2025-55680)
⤷ Title: Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:33 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Banking Trojan #Bloatware #Brazil #ClickFix #Lampion Trojan #persistence #VBScript
Daily CyberSecurity
Lampion Banking Trojan Evolves: 700MB Bloatware DLL and ClickFix VBS Script Target Brazilian Users
BitSight uncovered a Lampion banking Trojan campaign using ClickFix lures and a 700MB bloatware DLL to evade AV. The VBScript loader establishes persistence via the Windows Startup folder.
⤷ Title: ☕ When a REST Route Spills the Beans: Finding an Author-enumeration Bug (CVE-2023–5561)
════════════════════════
𐀪 Author: AIwolfie
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:32:19 GMT
════════════════════════
⌗ Tags: #wordpress #cve_2023_5561 #ethical_hacking #cve #bug_bounty
════════════════════════
𐀪 Author: AIwolfie
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:32:19 GMT
════════════════════════
⌗ Tags: #wordpress #cve_2023_5561 #ethical_hacking #cve #bug_bounty
Medium
☕ When a REST Route Spills the Beans: Finding an Author-enumeration Bug (CVE-2023–5561)
There are two truths I live by: one, always keep coffee within arm’s reach; two, curiosity + an API = bad decisions that turn into CVEs…
⤷ Title: The Reconnaissance Lie You Keep Believing
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:39:03 GMT
════════════════════════
⌗ Tags: #hacking #technology #security #cybersecurity #osint
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:39:03 GMT
════════════════════════
⌗ Tags: #hacking #technology #security #cybersecurity #osint
Medium
The Reconnaissance Lie You Keep Believing
You scan once. You move on. You think you’re done……You’re not done. You’re just blind.
⤷ Title: Dynamic Trust Constellation (DTC): The Next Breakthrough in Zero Trust Architecture
════════════════════════
𐀪 Author: Nachiket Deshpande
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:07:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #network_security #security #zero_trust
════════════════════════
𐀪 Author: Nachiket Deshpande
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 01:07:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #network_security #security #zero_trust
Medium
Dynamic Trust Constellation (DTC): The Next Breakthrough in Zero Trust Architecture
Executive Summary
⤷ Title: DanaBot Lab — CyberDefenders Write-Up
════════════════════════
𐀪 Author: Johnathonsiganoff
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:11:29 GMT
════════════════════════
⌗ Tags: #technology #malware_analysis #defensive_security #cybersecurity #malware
════════════════════════
𐀪 Author: Johnathonsiganoff
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:11:29 GMT
════════════════════════
⌗ Tags: #technology #malware_analysis #defensive_security #cybersecurity #malware
Medium
DanaBot Lab — CyberDefenders Write-Up
After taking a short break from cybersecurity to focus on some life events, we’re back on CyberDefenders, solving a few of their free labs…
⤷ Title: Precision, Accountability, and Results
════════════════════════
𐀪 Author: Rhiannon Williams
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:52 GMT
════════════════════════
⌗ Tags: #security #tech #privacy #technology #cybersecurity
════════════════════════
𐀪 Author: Rhiannon Williams
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 00:01:52 GMT
════════════════════════
⌗ Tags: #security #tech #privacy #technology #cybersecurity
Medium
Precision, Accountability, and Results
The most effective cybersecurity programs are built by small, elite teams operating with clarity, purpose, and the right leader at the…
⤷ Title: SHELLSILO: The Tool Translating C Code to Syscall Shellcode for Hackers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 03:00:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Assembly #cybersecurity #red teaming #shellcode #SHELLSILO #Syscall
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 03:00:29 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Assembly #cybersecurity #red teaming #shellcode #SHELLSILO #Syscall
Information Security News
SHELLSILO: The Tool Translating C Code to Syscall Shellcode for Hackers
SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the process of constructing and utilizing structures, assigning vari…
⤷ Title: OpenVPN Flaw: RCE Bug Allows Command Injection via DNS Parameters
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:55:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #cybersecurity #Linux #macos #OpenVPN #RCE #VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:55:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Command Injection #cybersecurity #Linux #macos #OpenVPN #RCE #VPN
Penetration Testing Tools
OpenVPN Flaw: RCE Bug Allows Command Injection via DNS Parameters
A critical vulnerability (CVE-2025-10680) in OpenVPN beta builds allows an unauthenticated attacker to execute arbitrary commands on Linux/macOS clients via DNS parameter injection.
⤷ Title: BiDi Swap: New Phishing Trick Exploits Unicode to Forge Web Addresses
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:54:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BiDi Swap #browser security #phishing #RTL #Spoofing #Unicode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:54:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BiDi Swap #browser security #phishing #RTL #Spoofing #Unicode
Penetration Testing Tools
BiDi Swap: New Phishing Trick Exploits Unicode to Forge Web Addresses
The BiDi Swap attack exploits flaws in Unicode's bidirectional text rendering to make malicious URLs look legitimate, tricking users and bypassing browser security.