⤷ Title: The Brash Attack: Single Webpage Freezes Chrome/Chromium Browsers in Seconds
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:14:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #Blink #browser security #chrome #Chromium #Denial of Service #document.title #DoS #Webkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:14:18 +0000
════════════════════════
⌗ Tags: #Vulnerability #Blink #browser security #chrome #Chromium #Denial of Service #document.title #DoS #Webkit
Penetration Testing Tools
The Brash Attack: Single Webpage Freezes Chrome/Chromium Browsers in Seconds
A flaw in the Blink engine (Chrome, Edge, Brave, etc.) lets a single webpage overload the main thread via rapid document.title updates, causing a total browser freeze.
⤷ Title: TEE.fail: New $1,000 Hardware Attack Bypasses Nvidia, AMD, & Intel Data Isolation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:12:40 +0000
════════════════════════
⌗ Tags: #Vulnerability #AMD SEV #cloud security #Confidential Compute #DDR5 #Hardware Attack #Intel SGX #TEE.fail
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:12:40 +0000
════════════════════════
⌗ Tags: #Vulnerability #AMD SEV #cloud security #Confidential Compute #DDR5 #Hardware Attack #Intel SGX #TEE.fail
Penetration Testing Tools
TEE.fail: New $1,000 Hardware Attack Bypasses Nvidia, AMD, & Intel Data Isolation
Researchers bypassed all modern TEEs (Intel, AMD, Nvidia) using a cheap physical attack targeting DDR5 systems, exposing a critical "security illusion" in hardware trust.
⤷ Title: SILENT HIJACK: Wear OS Flaw Lets Any App Send User’s Messages Without Permission
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:10:53 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12080 #Google Messages #Intent Abuse #Privacy Breach #Smartwatch Security #SMS Flaw #Wear OS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:10:53 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_12080 #Google Messages #Intent Abuse #Privacy Breach #Smartwatch Security #SMS Flaw #Wear OS
Penetration Testing Tools
SILENT HIJACK: Wear OS Flaw Lets Any App Send User's Messages Without Permission
CVE-2025-12080 in Google Messages on Wear OS allows any app to silently send SMS/MMS messages, bypassing permissions. Update immediately to prevent fraud.
⤷ Title: National Security Betrayal: Defense Contractor Sold 8 Zero-Days to Russian Broker for Crypto
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:07:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #Insider Threat #L3Harris #Operation Zero #Russia #trade secret #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:07:32 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Espionage #Insider Threat #L3Harris #Operation Zero #Russia #trade secret #zero_day
Penetration Testing Tools
National Security Betrayal: Defense Contractor Sold 8 Zero-Days to Russian Broker for Crypto
Ex-L3Harris contractor pleaded guilty to selling 8 US military zero-day exploits to Russia-linked broker Operation Zero for millions in crypto. Faces 9 years in prison.
⤷ Title: PhantomRaven Attack: New Malware Steals CI/CD Secrets via AI Slopsquatting on npm
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:06:02 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD #Credentials #Generative AI #npm #PhantomRaven #security #Slopsquatting #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:06:02 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD #Credentials #Generative AI #npm #PhantomRaven #security #Slopsquatting #Supply Chain
Penetration Testing Tools
PhantomRaven Attack: New Malware Steals CI/CD Secrets via AI Slopsquatting on npm
New PhantomRaven npm malware uses AI "slopsquatting" and invisible dynamic dependencies to steal GitHub, GitLab, and CI/CD tokens. Update vigilance now.
⤷ Title: HTTPS by Default: Chrome to Force Encrypted Connections on Public Sites in 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:04:00 +0000
════════════════════════
⌗ Tags: #Google #Chrome 154 #Encryption #Google Chrome #HTTP #HTTPS #security policy #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:04:00 +0000
════════════════════════
⌗ Tags: #Google #Chrome 154 #Encryption #Google Chrome #HTTP #HTTPS #security policy #web security
Penetration Testing Tools
HTTPS by Default: Chrome to Force Encrypted Connections on Public Sites in 2026
Google Chrome 154 (Oct 2026) will default to "Always use secure connections" for all public sites, eliminating the single biggest risk from unencrypted HTTP.
⤷ Title: Filter Evasion: Phishing Campaign Hides Invisible Characters in Email Subject Lines
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:02:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #email security #Filter Bypass #MIME #phishing #RFC 2047 #Soft Hyphen
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:02:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #email security #Filter Bypass #MIME #phishing #RFC 2047 #Soft Hyphen
Penetration Testing Tools
Filter Evasion: Phishing Campaign Hides Invisible Characters in Email Subject Lines
A new, sophisticated phishing campaign uses invisible soft hyphens () in email subject lines to bypass filter detection and steal user credentials. Learn how.
⤷ Title: Cyber War Escalation: Generative AI & VPN Flaws Fuel 90% of All Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:01:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Insurance #email security #Fortinet #Generative AI #MDR #phishing #ransomware #SASE #SonicWall #VPN
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:01:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Insurance #email security #Fortinet #Generative AI #MDR #phishing #ransomware #SASE #SonicWall #VPN
Penetration Testing Tools
Cyber War Escalation: Generative AI & VPN Flaws Fuel 90% of All Attacks
New report reveals AI-driven email fraud & compromised VPNs (83% of ransomware) cause 90% of cyber incidents. Ditch legacy SEGs & high-risk on-prem VPNs.
⤷ Title: Chinese APT BRONZE BUTLER Exploits LANSCOPE Zero-Day for SYSTEM Control
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:30:10 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #BRONZE BUTLER #CISA KEV #cyber_espionage #Endpoint Manager #Gokcpdoor #Motex #Tick #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:30:10 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #BRONZE BUTLER #CISA KEV #cyber_espionage #Endpoint Manager #Gokcpdoor #Motex #Tick #zero_day
Daily CyberSecurity
Chinese APT BRONZE BUTLER Exploits LANSCOPE Zero-Day for SYSTEM Control
Chinese APT BRONZE BUTLER exploited CVE-2025-61932 in Motex LANSCOPE Endpoint Manager to gain SYSTEM access. CISA added the actively exploited zero-day to KEV.
⤷ Title: CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:12:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CISA #CVE_2025_24893 #CVE_2025_41244 #KEV Catalog #privilege escalation #Remote Code Execution #VMware Aria Operations #VMware Tools #VulnCheck #XWiki
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:12:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CISA #CVE_2025_24893 #CVE_2025_41244 #KEV Catalog #privilege escalation #Remote Code Execution #VMware Aria Operations #VMware Tools #VulnCheck #XWiki
Daily CyberSecurity
CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
CISA adds XWiki (CVE-2025-24893) and VMware (CVE-2025-41244) to its KEV Catalog after confirming active exploitation in the wild.
⤷ Title: Netflix Experiments with Vertical Video and Podcasts, Redefining Mobile Entertainment
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:57:07 +0000
════════════════════════
⌗ Tags: #Technology #Elizabeth Stone #entertainment trends #mobile experience #Netflix #short_form content #Spotify partnership #streaming innovation #TikTok #vertical video
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:57:07 +0000
════════════════════════
⌗ Tags: #Technology #Elizabeth Stone #entertainment trends #mobile experience #Netflix #short_form content #Spotify partnership #streaming innovation #TikTok #vertical video
Daily CyberSecurity
Netflix Experiments with Vertical Video and Podcasts, Redefining Mobile Entertainment
Netflix explores vertical video and podcast integration, signaling a new era of mobile entertainment without mimicking TikTok’s model.
⤷ Title: Brash Attack: Critical Chromium Flaw Allows DoS via Simple Code Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:53:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Blink Engine #Brash #Chromium #dos #google chrome #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:53:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Blink Engine #Brash #Chromium #dos #google chrome #zero_day
Daily CyberSecurity
Brash Attack: Critical Chromium Flaw Allows DoS via Simple Code Injection
The Brash exploit leverages a missing rate limit on Chromium's document.title API to trigger a Denial-of-Service attack, crashing browsers in seconds.
⤷ Title: Samsung Internet Arrives on Windows, Pushing Forward Ambient AI Vision
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:47:06 +0000
════════════════════════
⌗ Tags: #Technology #Ambient AI #browser #Galaxy AI #Samsung Internet #Synchronization #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:47:06 +0000
════════════════════════
⌗ Tags: #Technology #Ambient AI #browser #Galaxy AI #Samsung Internet #Synchronization #windows
Daily CyberSecurity
Samsung Internet Arrives on Windows, Pushing Forward Ambient AI Vision
Samsung launched the Samsung Internet browser beta for Windows 10/11, featuring cross-device sync and Galaxy AI capabilities to advance its ambient AI ecosystem vision.
⤷ Title: Court Mandate: Google Play Opens to External Payments in the US
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:44:03 +0000
════════════════════════
⌗ Tags: #Technology #Antitrust #Developer Policy #Epic Games #Google Play #payments #US Court
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:44:03 +0000
════════════════════════
⌗ Tags: #Technology #Antitrust #Developer Policy #Epic Games #Google Play #payments #US Court
Daily CyberSecurity
Court Mandate: Google Play Opens to External Payments in the US
Google opened the US Play Store to external payment methods and alternative app downloads, a temporary measure following a US court mandate in the Epic Games antitrust case.
⤷ Title: CVE-2025-64095: Critical CVSS 10.0 Flaw in DNN Platform Allows Unauthenticated Website Overwrite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:39:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET #cms #Critical Vulnerability #CVE_2025_64095 #CVSS 10 #DNN #file upload #website defacement
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:39:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET #cms #Critical Vulnerability #CVE_2025_64095 #CVSS 10 #DNN #file upload #website defacement
Daily CyberSecurity
CVE-2025-64095: Critical CVSS 10.0 Flaw in DNN Platform Allows Unauthenticated Website Overwrite
Urgent! DNN Platform has a Critical CVSS 10.0 flaw allowing unauthenticated users to overwrite files, leading to site defacement & XSS. Update to 10.1.1.
⤷ Title: Magecart SMILODON Skimmer Infiltrates WooCommerce Via Rogue Plugin Hiding Payload in Fake PNG Image
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credit Card Skimmer #e_commerce #Fake PNG #Magecart #SMILODON #steganography #WooCommerce #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credit Card Skimmer #e_commerce #Fake PNG #Magecart #SMILODON #steganography #WooCommerce #wordpress
Daily CyberSecurity
Magecart SMILODON Skimmer Infiltrates WooCommerce Via Rogue Plugin Hiding Payload in Fake PNG Image
Wordfence exposed a Magecart campaign using a rogue WooCommerce plugin to hide skimmer code in a fake PNG image. The malware uses an AJAX backdoor to maintain access and steal customer cards.
⤷ Title: PhantomRaven: 126 Malicious npm Packages Steal Developer Tokens and Secrets Using Hidden Dependencies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Secrets #Credential Theft #npm #PhantomRaven #Remote Dynamic Dependency #Slopsquatting #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Secrets #Credential Theft #npm #PhantomRaven #Remote Dynamic Dependency #Slopsquatting #supply chain attack
Daily CyberSecurity
PhantomRaven: 126 Malicious npm Packages Steal Developer Tokens and Secrets Using Hidden Dependencies
Koi Security exposed PhantomRaven, an npm supply chain attack using 126 packages. It leverages Remote Dynamic Dependencies (RDD) and AI slopsquatting to steal GitHub/CI/CD secrets from 86,000+ downloads.
⤷ Title: XLab Unveils RPX_Client, the First Confirmed Relay Node in PolarEdge IoT ORB Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #china #IoT Malware #ORB Network #PolarEdge #Proxy_as_a_Service #Router Hack #RPX_Client #south korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #china #IoT Malware #ORB Network #PolarEdge #Proxy_as_a_Service #Router Hack #RPX_Client #south korea
Daily CyberSecurity
XLab Unveils RPX_Client, the First Confirmed Relay Node in PolarEdge IoT ORB Network
XLab exposed RPX_Client, a new PolarEdge malware that turns IoT/router devices into a global ORB proxy network. The ELF binary uses XOR to encrypt config and spreads across 40 countries.
⤷ Title: Nation-State Espionage: Airstalk Malware Hijacks VMware AirWatch (MDM) API for Covert C2 Channel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:19:12 +0000
════════════════════════
⌗ Tags: #Malware #Airstalk #C2 #Espionage #MDM #nation_state #powershell #supply chain attack #VMware AirWatch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:19:12 +0000
════════════════════════
⌗ Tags: #Malware #Airstalk #C2 #Espionage #MDM #nation_state #powershell #supply chain attack #VMware AirWatch
Daily CyberSecurity
Nation-State Espionage: Airstalk Malware Hijacks VMware AirWatch (MDM) API for Covert C2 Channel
Unit 42 exposed Airstalk, a suspected nation-state malware that abuses VMware AirWatch (MDM) APIs for a covert C2 dead drop. The tool is used to steal credentials and browser data in supply chain attacks.
⤷ Title: Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
Daily CyberSecurity
Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
Symantec exposed a Russian-aligned espionage campaign in Ukraine using LotL tactics. Attackers used a Sandworm-linked webshell (Localolive) and abused scheduled tasks to dump credentials and bypass Windows Defender.
⤷ Title: Progress Patches High-Severity Vulnerability in MOVEit Transfer AS2 Module (CVE-2025-10932)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AS2 Module #CVE_2025_10932 #dos #MOVEit Transfer #Progress Software #Uncontrolled Resource Consumption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AS2 Module #CVE_2025_10932 #dos #MOVEit Transfer #Progress Software #Uncontrolled Resource Consumption
Daily CyberSecurity
Progress Patches High-Severity Vulnerability in MOVEit Transfer AS2 Module (CVE-2025-10932)
Progress patched a High-severity DoS flaw (CVE-2025-10932) in MOVEit Transfer’s AS2 module. The vulnerability allows unauthenticated attackers to exhaust server resources. Patch to v2025.0.3 immediately.