⤷ Title: Chinese APT BRONZE BUTLER Exploits LANSCOPE Zero-Day for SYSTEM Control
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:30:10 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #BRONZE BUTLER #CISA KEV #cyber_espionage #Endpoint Manager #Gokcpdoor #Motex #Tick #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:30:10 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #BRONZE BUTLER #CISA KEV #cyber_espionage #Endpoint Manager #Gokcpdoor #Motex #Tick #zero_day
Daily CyberSecurity
Chinese APT BRONZE BUTLER Exploits LANSCOPE Zero-Day for SYSTEM Control
Chinese APT BRONZE BUTLER exploited CVE-2025-61932 in Motex LANSCOPE Endpoint Manager to gain SYSTEM access. CISA added the actively exploited zero-day to KEV.
⤷ Title: CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:12:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CISA #CVE_2025_24893 #CVE_2025_41244 #KEV Catalog #privilege escalation #Remote Code Execution #VMware Aria Operations #VMware Tools #VulnCheck #XWiki
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:12:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CISA #CVE_2025_24893 #CVE_2025_41244 #KEV Catalog #privilege escalation #Remote Code Execution #VMware Aria Operations #VMware Tools #VulnCheck #XWiki
Daily CyberSecurity
CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
CISA adds XWiki (CVE-2025-24893) and VMware (CVE-2025-41244) to its KEV Catalog after confirming active exploitation in the wild.
⤷ Title: Netflix Experiments with Vertical Video and Podcasts, Redefining Mobile Entertainment
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:57:07 +0000
════════════════════════
⌗ Tags: #Technology #Elizabeth Stone #entertainment trends #mobile experience #Netflix #short_form content #Spotify partnership #streaming innovation #TikTok #vertical video
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:57:07 +0000
════════════════════════
⌗ Tags: #Technology #Elizabeth Stone #entertainment trends #mobile experience #Netflix #short_form content #Spotify partnership #streaming innovation #TikTok #vertical video
Daily CyberSecurity
Netflix Experiments with Vertical Video and Podcasts, Redefining Mobile Entertainment
Netflix explores vertical video and podcast integration, signaling a new era of mobile entertainment without mimicking TikTok’s model.
⤷ Title: Brash Attack: Critical Chromium Flaw Allows DoS via Simple Code Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:53:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Blink Engine #Brash #Chromium #dos #google chrome #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:53:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Blink Engine #Brash #Chromium #dos #google chrome #zero_day
Daily CyberSecurity
Brash Attack: Critical Chromium Flaw Allows DoS via Simple Code Injection
The Brash exploit leverages a missing rate limit on Chromium's document.title API to trigger a Denial-of-Service attack, crashing browsers in seconds.
⤷ Title: Samsung Internet Arrives on Windows, Pushing Forward Ambient AI Vision
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:47:06 +0000
════════════════════════
⌗ Tags: #Technology #Ambient AI #browser #Galaxy AI #Samsung Internet #Synchronization #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:47:06 +0000
════════════════════════
⌗ Tags: #Technology #Ambient AI #browser #Galaxy AI #Samsung Internet #Synchronization #windows
Daily CyberSecurity
Samsung Internet Arrives on Windows, Pushing Forward Ambient AI Vision
Samsung launched the Samsung Internet browser beta for Windows 10/11, featuring cross-device sync and Galaxy AI capabilities to advance its ambient AI ecosystem vision.
⤷ Title: Court Mandate: Google Play Opens to External Payments in the US
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:44:03 +0000
════════════════════════
⌗ Tags: #Technology #Antitrust #Developer Policy #Epic Games #Google Play #payments #US Court
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 01:44:03 +0000
════════════════════════
⌗ Tags: #Technology #Antitrust #Developer Policy #Epic Games #Google Play #payments #US Court
Daily CyberSecurity
Court Mandate: Google Play Opens to External Payments in the US
Google opened the US Play Store to external payment methods and alternative app downloads, a temporary measure following a US court mandate in the Epic Games antitrust case.
⤷ Title: CVE-2025-64095: Critical CVSS 10.0 Flaw in DNN Platform Allows Unauthenticated Website Overwrite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:39:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET #cms #Critical Vulnerability #CVE_2025_64095 #CVSS 10 #DNN #file upload #website defacement
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:39:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.NET #cms #Critical Vulnerability #CVE_2025_64095 #CVSS 10 #DNN #file upload #website defacement
Daily CyberSecurity
CVE-2025-64095: Critical CVSS 10.0 Flaw in DNN Platform Allows Unauthenticated Website Overwrite
Urgent! DNN Platform has a Critical CVSS 10.0 flaw allowing unauthenticated users to overwrite files, leading to site defacement & XSS. Update to 10.1.1.
⤷ Title: Magecart SMILODON Skimmer Infiltrates WooCommerce Via Rogue Plugin Hiding Payload in Fake PNG Image
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credit Card Skimmer #e_commerce #Fake PNG #Magecart #SMILODON #steganography #WooCommerce #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credit Card Skimmer #e_commerce #Fake PNG #Magecart #SMILODON #steganography #WooCommerce #wordpress
Daily CyberSecurity
Magecart SMILODON Skimmer Infiltrates WooCommerce Via Rogue Plugin Hiding Payload in Fake PNG Image
Wordfence exposed a Magecart campaign using a rogue WooCommerce plugin to hide skimmer code in a fake PNG image. The malware uses an AJAX backdoor to maintain access and steal customer cards.
⤷ Title: PhantomRaven: 126 Malicious npm Packages Steal Developer Tokens and Secrets Using Hidden Dependencies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Secrets #Credential Theft #npm #PhantomRaven #Remote Dynamic Dependency #Slopsquatting #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:30:49 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Secrets #Credential Theft #npm #PhantomRaven #Remote Dynamic Dependency #Slopsquatting #supply chain attack
Daily CyberSecurity
PhantomRaven: 126 Malicious npm Packages Steal Developer Tokens and Secrets Using Hidden Dependencies
Koi Security exposed PhantomRaven, an npm supply chain attack using 126 packages. It leverages Remote Dynamic Dependencies (RDD) and AI slopsquatting to steal GitHub/CI/CD secrets from 86,000+ downloads.
⤷ Title: XLab Unveils RPX_Client, the First Confirmed Relay Node in PolarEdge IoT ORB Network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #china #IoT Malware #ORB Network #PolarEdge #Proxy_as_a_Service #Router Hack #RPX_Client #south korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:22:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #china #IoT Malware #ORB Network #PolarEdge #Proxy_as_a_Service #Router Hack #RPX_Client #south korea
Daily CyberSecurity
XLab Unveils RPX_Client, the First Confirmed Relay Node in PolarEdge IoT ORB Network
XLab exposed RPX_Client, a new PolarEdge malware that turns IoT/router devices into a global ORB proxy network. The ELF binary uses XOR to encrypt config and spreads across 40 countries.
⤷ Title: Nation-State Espionage: Airstalk Malware Hijacks VMware AirWatch (MDM) API for Covert C2 Channel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:19:12 +0000
════════════════════════
⌗ Tags: #Malware #Airstalk #C2 #Espionage #MDM #nation_state #powershell #supply chain attack #VMware AirWatch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:19:12 +0000
════════════════════════
⌗ Tags: #Malware #Airstalk #C2 #Espionage #MDM #nation_state #powershell #supply chain attack #VMware AirWatch
Daily CyberSecurity
Nation-State Espionage: Airstalk Malware Hijacks VMware AirWatch (MDM) API for Covert C2 Channel
Unit 42 exposed Airstalk, a suspected nation-state malware that abuses VMware AirWatch (MDM) APIs for a covert C2 dead drop. The tool is used to steal credentials and browser data in supply chain attacks.
⤷ Title: Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:07:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #credential dumping #Espionage #living_off_the_land #LotL #Russia APT #SANDWORM #Ukraine #webshell
Daily CyberSecurity
Russian APTs Exploit LotL Techniques in Ukraine Cyber Attacks, Deploying Sandworm-Linked Webshell and Credential Dumping
Symantec exposed a Russian-aligned espionage campaign in Ukraine using LotL tactics. Attackers used a Sandworm-linked webshell (Localolive) and abused scheduled tasks to dump credentials and bypass Windows Defender.
⤷ Title: Progress Patches High-Severity Vulnerability in MOVEit Transfer AS2 Module (CVE-2025-10932)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AS2 Module #CVE_2025_10932 #dos #MOVEit Transfer #Progress Software #Uncontrolled Resource Consumption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 00:01:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AS2 Module #CVE_2025_10932 #dos #MOVEit Transfer #Progress Software #Uncontrolled Resource Consumption
Daily CyberSecurity
Progress Patches High-Severity Vulnerability in MOVEit Transfer AS2 Module (CVE-2025-10932)
Progress patched a High-severity DoS flaw (CVE-2025-10932) in MOVEit Transfer’s AS2 module. The vulnerability allows unauthenticated attackers to exhaust server resources. Patch to v2025.0.3 immediately.
⤷ Title: All About Recon — Bug Bounty
════════════════════════
𐀪 Author: Monu Jangra
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:01:52 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #tech #hacking #learning
════════════════════════
𐀪 Author: Monu Jangra
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:01:52 GMT
════════════════════════
⌗ Tags: #technology #bug_bounty #tech #hacking #learning
Medium
All About Recon — Bug Bounty
Meta description: Become a sharper bug hunter. This professional guide by Monu Jangra (Certified Penetration Tester, LPT Master, CPENT…
⤷ Title: Web Cache Poisoning — Part 2: Weaponizing Headers & URL Discrepancies
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:39:08 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #infosec #bug_bounty_writeup #cybersecurity
════════════════════════
𐀪 Author: Abhishek meena
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:39:08 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #infosec #bug_bounty_writeup #cybersecurity
Medium
🔥🌵 Web Cache Poisoning — Part 2: Weaponizing Headers & URL Discrepancies
“Discovery is the jigsaw — exploitation is finishing the picture.”
⤷ Title: Your EXIF Is Showing: The Art of Leaving No Digital Trace
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:30:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #metadata #software_engineering #hacking #programming
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:30:34 GMT
════════════════════════
⌗ Tags: #cybersecurity #metadata #software_engineering #hacking #programming
Medium
Your EXIF Is Showing: The Art of Leaving No Digital Trace
The photo looks clean. You cropped it, tweaked the lighting, maybe ran a filter. You think it’s anonymous. You post it.
⤷ Title: Mengamankan Dunia Mobile: Mengapa “Jasa Pentest iOS” Jadi Pilar Baru Keamanan Digital Terkini?
════════════════════════
𐀪 Author: Genos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:09:05 GMT
════════════════════════
⌗ Tags: #pentest #mobile_security #ios #cybersecurity #infosec
════════════════════════
𐀪 Author: Genos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:09:05 GMT
════════════════════════
⌗ Tags: #pentest #mobile_security #ios #cybersecurity #infosec
Medium
Mengamankan Dunia Mobile: Mengapa “Jasa Pentest iOS” Jadi Pilar Baru Keamanan Digital Terkini?
Selama bertahun-tahun, banyak yang percaya bahwa iOS adalah sistem operasi paling aman di dunia mobile. Tapi apakah itu masih relevan di…
⤷ Title: The Importance of Financial Security in the Digital Era
════════════════════════
𐀪 Author: Nishitha
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:47:23 GMT
════════════════════════
⌗ Tags: #financial_security #online_banking #digital_finance #cybersecurity #fintech
════════════════════════
𐀪 Author: Nishitha
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:47:23 GMT
════════════════════════
⌗ Tags: #financial_security #online_banking #digital_finance #cybersecurity #fintech
Medium
💰 The Importance of Financial Security in the Digital Era
Protecting your money online has never been more important — here’s how to stay safe in the digital age.
⤷ Title: OneFlip: How a Single Bit Flip Could Backdoor Your AI Model
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:42:03 GMT
════════════════════════
⌗ Tags: #rowhammer #deep_learning #cybersecurity #ai_backdoor #oneflip
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 03:42:03 GMT
════════════════════════
⌗ Tags: #rowhammer #deep_learning #cybersecurity #ai_backdoor #oneflip
Medium
OneFlip: How a Single Bit Flip Could Backdoor Your AI Model
Artificial intelligence (AI) has always carried an aura of invincibility. We trust it to recognize faces, drive cars, filter spam, and even…
⤷ Title: OSINT Meets AI: How AI Supercharges Collection, Analysis, and Correlation
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:35:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybercrime #osint_investigation #osint_tool #osint
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:35:36 GMT
════════════════════════
⌗ Tags: #cybersecurity #cybercrime #osint_investigation #osint_tool #osint
Medium
OSINT Meets AI: How AI Supercharges Collection, Analysis, and Correlation
By: Travis Ray Caverhill
⤷ Title: From Cybersecurity to Generative AI: How I Discovered the Creative Side of Adversarial Learning
════════════════════════
𐀪 Author: KanishkAshra
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity
════════════════════════
𐀪 Author: KanishkAshra
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:35:32 GMT
════════════════════════
⌗ Tags: #cybersecurity
Medium
From Cybersecurity to Generative AI: How I Discovered the Creative Side of Adversarial Learning
“The skills I honed defending systems unexpectedly became my tools for creation.”